GDPR Information Obligation
The following information constitutes a concise, intelligible, and transparent summary of the information contained in the Privacy Policy regarding the Data Controller, the purpose and methods of processing personal data, and your rights in connection with such processing, provided in the form required to fulfill the GDPR information obligation. Details concerning the methods of processing and the entities involved in this process are available in the aforementioned policy.
Who is the data controller?
The Personal Data Controller (hereinafter the Controller) is the company "Rafał Kubik Kancelaria Radcy Prawnego", conducting business operations at the address: ul. Miklaszewskiego 14 lok 42a 02-776 Warszawa, with the assigned Tax Identification Number (NIP): 9512114987, providing electronically supplied services via the Website.
How can you contact the data controller?
The Controller can be contacted through one of the following methods:
Postal address - Rafał Kubik Kancelaria Radcy Prawnego, ul. Miklaszewskiego 14 lok 42a 02-776 Warszawa, Poland
Email address - rafal.kubik@kancelariakubik.eu
Telephone - +48 505 874 744
Contact form - available at: /kontakt
Has the Controller appointed a Data Protection Officer?
Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.
In matters regarding the processing of data, including personal data, you should contact the Controller directly.
Where do we obtain personal data from and what are its sources?
Data is obtained from the following sources:
- from the data subjects directly
What is the scope of the personal data processed by us?
The website processes ordinary personal data, provided voluntarily by the data subjects
(e.g., name and surname, login, email address, telephone number, IP address, etc.)
A detailed scope of the processed data is available in the Privacy Policy.
What are the purposes of data processing by us?
Personal data voluntarily provided by Users is processed for one of the following purposes:
- Provision of electronic services;
- Communication between the Controller and the Users regarding matters related to the Website and data protection;
- Ensuring the legitimate interest of the Controller.
What are the legal bases for data processing?
The Website collects and processes Users' data on the basis of:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Article 6(1)(a)
the data subject has given consent to the processing of his or her personal data for one or more specific purposes - Article 6(1)(b)
processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract - Article 6(1)(f)
processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party
- Article 6(1)(a)
- The Polish Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws 2018, item 1000);
- The Polish Act of 16 July 2004 – Telecommunications Law (Journal of Laws 2004, No. 171, item 1800);
- The Polish Act of 4 February 1994 on Copyright and Related Rights (Journal of Laws 1994, No. 24, item 83).
What is the legitimate interest pursued by the Controller?
- For the purpose of potentially establishing, exercising, or defending against legal claims – the legal basis for processing is our legitimate interest (Article 6(1)(f) of the GDPR) consisting in the protection of our rights, including but not limited to;
- For the purpose of risk assessment of potential clients;
- For the purpose of assessing planned marketing campaigns;
- For the purpose of conducting direct marketing.
For how long do we process personal data?
As a rule, the specified personal data is stored exclusively for the period of service provision within the website run by the Controller. It is deleted or anonymized within 30 days from the moment the provision of services is terminated (e.g., deletion of a registered user account, unsubscribing from the Newsletter list, etc.).
In exceptional situations, in order to secure a legitimate interest pursued by the Controller, this period may be extended. In such an event, the Controller will store the specified data from the time the User requests its deletion for a period no longer than 3 years in the event of a breach or suspected breach of the website regulations by the data subject.
Who is the recipient of the data, including personal data?
As a rule, the Controller is the sole recipient of the data.
However, the processing of data may be entrusted to other entities performing services for the Controller in order to maintain the operations of the Website.
Such entities may include, among others:- Hosting companies providing hosting or related services to the Controller;
- Companies through which the Newsletter service is provided;
- IT support and service companies performing maintenance or responsible for the upkeep of the IT infrastructure.
Will your personal data be transferred outside the European Union?
Personal data will not be transferred outside the European Union, unless it has been published as a result of an individual action by the User (e.g., entering a comment or a post), which will make the data available to any person visiting the website.
Will personal data be used as a basis for automated decision-making?
Personal data will not be used for automated decision-making (profiling).
What are your rights regarding the processing of personal data?
Right of access to personal data
Users have the right to obtain access to their personal data, exercised upon request submitted to the Controller.Right to rectification of personal data
Users have the right to request from the Controller the immediate rectification of inaccurate personal data and/or the completion of incomplete personal data, exercised upon request submitted to the Controller.Right to erasure of personal data ("right to be forgotten")
Users have the right to request from the Controller the immediate erasure of personal data, exercised upon request submitted to the Controller.
In the case of user accounts, the erasure of data consists in the anonymization of data that enables the identification of the User.
In the case of the Newsletter service, the User has the option to independently remove their personal data using the link provided in every email sent.Right to restriction of processing of personal data
Users have the right to restrict the processing of personal data in cases specified in Article 18 of the GDPR, including contesting the accuracy of personal data, exercised upon request submitted to the Controller.Right to data portability
Users have the right to receive from the Controller the personal data concerning them in a structured, commonly used, and machine-readable format, exercised upon request submitted to the Controller.Right to object to the processing of personal data
Users have the right to object to the processing of their personal data in cases specified in Article 21 of the GDPR, exercised upon request submitted to the Controller.Right to lodge a complaint
Users have the right to lodge a complaint with a supervisory authority dealing with personal data protection (in Poland: Prezes Urzędu Ochrony Danych Osobowych - PUODO).