Privacy Policy

PRIVACY POLICY

eTOP Website Privacy Policy

This Privacy Policy sets out the rules governing the processing of personal data and the use of cookies and similar technologies on websites operated by eTOP sp. z o.o. The Policy is for information purposes and fulfils the obligations arising from personal data protection laws and regulations concerning the storage of information or gaining access to information stored on the User’s terminal device.

1. DEFINITIONS

1.1. Controller – eTOP sp. z o.o., with its registered office in Warsaw, al. Jerozolimskie 200, 02-222 Warsaw, Poland.

1.2. Personal Data – information relating to an identified or identifiable natural person.

1.3. EEA – European Economic Area.

1.4. Customer – an entity using services provided by the Controller pursuant to an agreement, terms and conditions, an order or another commercial arrangement.

1.5. Policy – this Privacy Policy.

1.6. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

1.7. Website – a website operated by the Controller, in particular under the domains etop.pl, datahouse.pl, datahouse.net and hostilla.pl.

1.8. User – a natural person using the Website, contacting the Controller through the Website or using functionalities made available on the Website.

2. SCOPE OF THE POLICY

2.1. The Policy applies to Personal Data processed in connection with the use of the Website, in particular data provided through contact forms, order forms, user accounts, by e-mail or telephone, as well as technical data generated while using the Website.

2.2. The Policy does not govern the processing of data entrusted to the Controller by Customers as part of infrastructure services, such as colocation, hosting, servers, cloud services, e-mail, domains, service administration or other technical services. In this respect, the rules governing data processing arise from agreements, service terms and conditions, data processing agreements or separate arrangements with the Customer.

2.3. Where a Customer independently uses third-party tools, accounts, services or providers, the rules governing the processing of data by such providers arise from the relationship between the Customer and the relevant provider and not from this Policy.

3. CONTROLLER AND CONTACT DETAILS

3.1. The controller of Personal Data covered by this Policy is eTOP sp. z o.o., with its registered office in Warsaw.

3.2. The Controller may be contacted by e-mail at etop@etop.pl or in writing at the address of the Controller’s registered office.

3.3. The Controller has appointed a Data Protection Officer, who may be contacted by e-mail at iod@etop.pl.

3.4. The Data Protection Officer should be contacted in matters concerning the protection of Personal Data, including the exercise of data subject rights.

4. PURPOSES, SCOPE AND LEGAL BASES OF PROCESSING

4.1. Making the Website available, ensuring its proper operation, maintaining sessions, supporting basic technical functions and ensuring the security of the Website are carried out on the basis of the Controller’s legitimate interest in operating and securing the Website and, where required, on the basis of applicable law.

4.2. Enquiries submitted through forms, by e-mail or by telephone are handled for the purpose of providing a response, conducting correspondence and dealing with the matter to which the contact relates. The legal basis is the Controller’s legitimate interest and, where the contact is intended to lead to the conclusion or performance of an agreement, also the necessity to take steps prior to entering into an agreement or to perform an agreement.

4.3. Creating and managing an account, accepting an order, preparing an offer, concluding and performing an agreement, providing a service and processing payments are carried out to the extent necessary to take steps prior to entering into an agreement, to conclude an agreement or to perform it.

4.4. Compliance with accounting, tax, telecommunications, archiving, complaint-handling and other obligations arising from applicable law is based on a legal obligation incumbent on the Controller.

4.5. Pursuing claims, defending against claims, documenting arrangements, handling complaints, preventing abuse, maintaining service security and analysing incidents are carried out on the basis of the Controller’s legitimate interests.

4.6. Marketing the Controller’s own services, insofar as permitted by applicable law or carried out with the User’s consent, is based, as applicable, on the Controller’s legitimate interest or the User’s consent.

4.7. Cookies and similar technologies other than those strictly necessary are used after obtaining the User’s consent where such consent is required by law. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.

4.8. Where the Website enables the submission of job applications, candidates’ Personal Data are processed to the extent provided for under employment law for the purpose of conducting the recruitment process, on the basis of a legal obligation, steps taken prior to entering into an agreement, the candidate’s consent or the Controller’s legitimate interest, depending on the type of data and the stage of the recruitment process.

5. CATEGORIES OF DATA PROCESSED

5.1. The Controller processes data that are adequate for the purpose for which they were collected. Such data may include, in particular: first and last name, company name, e-mail address, telephone number, correspondence address, billing information, account identification data, order information, data contained in correspondence, technical data relating to the use of the Website, IP address, cookie identifiers and data stored in system logs.

5.2. Providing data is voluntary; however, in certain cases it is necessary in order to handle an enquiry, conclude an agreement, provide a service, create an account, settle payments for a service or comply with a legal obligation.

5.3. The User should not provide the Controller with excessive data, in particular special categories of Personal Data, unless this is necessary in order to handle the relevant matter.

6. COOKIES AND SIMILAR TECHNOLOGIES

6.1. The Website uses cookies and similar technologies to ensure the proper operation of the Website, maintain security, support selected functions and, where the User has given appropriate consent, for analytical, measurement, functional or marketing purposes.

6.2. Strictly necessary cookies are used to the extent required for the operation of the Website, session maintenance, remembering privacy choices, ensuring security and supporting basic functions.

6.3. Cookies other than strictly necessary cookies are used only where the User has given consent, insofar as such consent is required. Refusing consent may limit the operation of certain additional functions but should not prevent access to the basic content of the Website.

6.4. The User may manage consents through the mechanism available on the Website and through the settings of their web browser. Changes to browser settings may affect the operation of certain Website functions.

6.5. The current scope of technologies other than strictly necessary technologies should correspond to the tools actually enabled, the consent configuration and the notices presented to the User on the Website. The Controller should not activate technologies requiring consent before such consent has been obtained.

7. THIRD-PARTY TOOLS AND SOCIAL MEDIA

7.1. The Website may use services provided by third-party providers for technical purposes, security, analytics, measuring the effectiveness of communications or protection against abuse, provided that such services are actually enabled and comply with the consent settings applicable on the Website.

7.2. The scope of data processed by third-party providers depends on the type of tool and its configuration. Such data may include, in particular, technical data, cookie identifiers, information about the device and browser, IP address and information about how the Website is used.

7.3. The Controller does not obtain access to Users’ private accounts maintained by third-party providers where Users use such accounts independently of the Website.

7.4. Where the Controller maintains profiles on social media platforms, it processes the data of persons interacting with those profiles for the purposes of communication, handling messages, publishing information about the Controller’s activities and protecting the Controller’s rights. The operator of the relevant social media platform processes data in accordance with its own privacy documentation.

8. CUSTOMER DATA PROCESSED AS PART OF SERVICES

8.1. As part of infrastructure services, the Controller may process data entrusted by the Customer solely to the extent arising from an agreement, terms and conditions, an order, a data processing agreement or the Customer’s instructions.

8.2. Content, databases, accounts, files, correspondence, configurations, Customer end-user data and other data maintained within the Customer’s services are not covered by the general rules governing the use of the Website described in this Policy, unless a separate document expressly provides otherwise.

8.3. The Controller does not determine the purposes and means of processing data that the Customer places or maintains within the services as part of its own activities, unless a specific agreement or applicable law provides for a different status of the Controller.

8.4. The Customer is responsible for the lawfulness, scope and legal bases of processing data that it independently collects, enters, maintains or transmits using the Controller’s services.

9. RECIPIENTS OF DATA

9.1. Personal Data may be made available to persons authorised by the Controller, its associates and entities providing the Controller with services necessary for conducting its business activities, including, in particular, IT, hosting, administrative, accounting, legal, auditing, security, postal, payment and communication support services.

9.2. Data may also be made available to public authorities, courts, authorised institutions or other entities where such disclosure is required by law.

9.3. The Controller does not sell Users’ Personal Data.

10. TRANSFERS OF DATA OUTSIDE THE EEA

10.1. As a general rule, the Controller processes Personal Data within the EEA.

10.2. Data entrusted by Customers as part of infrastructure services are not transferred by the Controller outside the EEA unless such transfer results from a separate agreement, a documented instruction from the Customer, applicable law or an agreed model for the provision of a specific service.

10.3. Where the Website actually uses a third-party tool whose operation involves the transfer of data outside the EEA, such transfer may take place only in compliance with the requirements of the GDPR, in particular the appropriate mechanisms provided for in Articles 44–49 of the GDPR, and after the User has been provided with the required information.

10.4. The User’s use of third-party services, accounts or tools outside the Website does not in itself constitute a transfer of data by the Controller.

11. DATA RETENTION PERIOD

11.1. Data processed for the purpose of handling an enquiry are retained for the period necessary to provide a response and conclude the matter, and thereafter for the period required to protect against claims or demonstrate the course of correspondence.

11.2. Data relating to the conclusion and performance of an agreement are retained for the duration of the agreement and thereafter for the period resulting from applicable law, limitation periods for claims, and accounting, tax, complaint-handling and archiving obligations.

11.3. Data processed on the basis of consent are retained until the consent is withdrawn, unless further retention is necessary to demonstrate that consent was given, its scope, its withdrawal or to protect against claims.

11.4. Data processed on the basis of the Controller’s legitimate interest are retained until an effective objection is raised or the purpose of processing ceases to exist, taking into account the need to protect the Controller’s rights.

11.5. System logs and technical data are retained for a period justified by the need to administer the Website, ensure security, detect abuse, analyse incidents and document technical activities.

12. DATA SUBJECT RIGHTS

12.1. The data subject has the right to access their Personal Data, obtain a copy of the data, rectify the data, erase the data, restrict processing, data portability, object to processing and withdraw consent where processing is based on consent.

12.2. The scope and availability of individual rights depend on the legal basis, purpose of processing and type of data concerned.

12.3. Requests concerning the exercise of rights may be submitted to the Controller or the Data Protection Officer using the contact details specified in this Policy.

12.4. The data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) if they consider that the processing of their Personal Data infringes applicable personal data protection laws.

13. AUTOMATED DECISION-MAKING AND PROFILING

13.1. The Controller does not make decisions concerning Users that produce legal effects or similarly significantly affect the User based solely on automated processing.

13.2. Where analytical, measurement or marketing tools are used on the Website, they may be used to assess the effectiveness of communications or customise content, but they do not constitute automated decision-making within the meaning of Article 22 of the GDPR.

14. DATA SECURITY

14.1. The Controller implements technical and organisational measures designed to protect Personal Data against unauthorised access, loss, alteration, disclosure, destruction or unlawful processing.

14.2. The scope of the measures applied is determined taking into account the nature of the data, the risk of infringement of the rights or freedoms of natural persons, the type of services and the current state of technical knowledge.

14.3. Access to data is granted solely to persons and entities for whom such access is necessary to perform specific tasks, comply with legal obligations or provide services to the Controller.

15. CHANGES TO THE POLICY

15.1. The Policy may be updated in the event of changes in applicable law, changes in the operation of the Website, changes in the technologies used, changes in the scope of services or the need to clarify information provided to Users.