Warsaw, 1 March 2025

PRIVACY POLICY AND COOKIE POLICY

This Privacy Policy and Cookie Policy contains information regarding the processing of personal data that you may provide to the Controller when using the Website and the use of Cookies. The Controller reserves the right to make changes to this Privacy Policy. Changes may be introduced due to changes in applicable law, developments in internet technology, the use of new tools by the Controller, or other objective reasons. The publication date of the current Privacy Policy and Cookie Policy is displayed at the top of the page.

I. DEFINITIONS:

  • Controller – SAGARTO spółka z ograniczoną odpowiedzialnością, with its registered office in Warsaw at ul. Aleje Jerozolimskie 200, 02-486 Warsaw, entered in the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 12th Commercial Division of the National Court Register, under KRS number: 0000592549, NIP: 7010529390, REGON: 36326718200000, contact: szkody@sagarto.pl
  • Personal Data – information relating to an identified or identifiable natural person through one or more specific factors determining their physical, physiological, genetic, psychological, economic, cultural or social identity, including the device IP address, location data, online identifier, and information collected through cookies and other similar technologies.
  • Policy – this Privacy Policy, containing information on the processing of Personal Data and the use of cookies and similar tracking technologies within the Website.
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, repealing Directive 95/46/EC.
  • Personal Data Protection Act – the Act of 10 May 2018 on the protection of personal data.
  • Website – the website operated by the Controller at www.sagarto.pl through web browsers and all of its subpages, including all services provided under the domain, such as the contact form.
  • User – a natural person visiting the Website or using one or more of the services or functionalities described in the Policy.
  • Device – an electronic device through which the User accesses the Website.

II. WHO IS THE CONTROLLER OF PERSONAL DATA?

  1. The Controller of personal data is SAGARTO spółka z ograniczoną odpowiedzialnością, with its registered office in Warsaw at ul. Aleje Jerozolimskie 200, 02-486 Warsaw, entered in the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 12th Commercial Division of the National Court Register, under KRS number: 0000592549, NIP: 7010529390, REGON: 36326718200000.
  2. The Controller may be contacted at the above address and by email at: szkody@sagarto.pl.
  3. When contacting the Controller by email, you provide your personal data, such as your name and email address.
  4. The Controller places great importance on the security and legal compliance of the process of processing Users’ personal data. Users’ personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 concerning the protection of natural persons with regard to the processing of personal data and the free movement of such data, hereinafter referred to as the “GDPR”, as well as other currently applicable data protection laws.

III. WHAT PERSONAL DATA IS PROCESSED BY THE CONTROLLER IN CONNECTION WITH THE USE OF THE WEBSITE?

  1. The Website enables the User to contact the Controller and provide identification and contact details, as well as information relating to the content of the message.
  2. The Controller collects data relating to Users’ activity, such as time spent on the Website, search terms, number of subpages viewed, date and source of visits.
  3. If the User contacts the Controller, the data has been provided directly by the User.
  4. If the User’s data has been provided in connection with a matter handled by a person who referred that matter to the Controller, that person is the source of the data. In such a case, the Controller receives identification and address details as well as information relating to the matter, such as a description of the case.
  5. In connection with the User’s use of the Website, the Controller collects data necessary to provide individual services offered, such as first name, surname, residential address and email address.
  6. The detailed rules and purposes for processing personal data collected while using the Website are described below.

IV. PURPOSE AND LEGAL BASIS FOR THE PROCESSING OF DATA BY THE CONTROLLER

  1. The Controller processes the personal data of all persons using the Website for the following purposes:
  • analysing network traffic, ensuring security within the Website and adapting content (Article 6(1)(f) GDPR);
  • responding to correspondence, providing requested offers and conducting correspondence (Article 6(1)(a) and (f) GDPR);
  • providing and displaying content on the Website – for this purpose, the Controller collects personal data in the form of IP addresses and cookies; the data is processed on the basis of Article 6(1)(f) GDPR;
  • establishing, defending and pursuing claims – the legal basis for processing is the Controller’s legitimate interest (Article 6(1)(f) GDPR) in protecting its rights;
  • publishing User reviews of services (Article 6(1)(a) GDPR);
  • using cookies on the Website and its subpages (Article 6(1)(a) GDPR);
  • for analytical and statistical purposes – involving the analysis of User activity on the Website in order to improve the functionalities used (Article 6(1)(f) GDPR);
  • contacting the Controller – the Controller provides the possibility of contacting it using an electronic contact form. Using the form requires providing personal data necessary to establish contact;
  • for direct marketing purposes (including marketing commissioned by advertisers) or promotion of its own services, the Controller may process information about the User’s activity on the Website (e.g. submitted forms, viewed content and advertisements). Such information may be combined with other information relating to the User (e.g. information about previous activity on the Website, other websites or applications) or similar persons. This information is used to create or improve a profile relating to the User. Such data, for marketing purposes, including the creation of interest profiles, is processed on the basis of voluntary consent. Providing such consent is voluntary, and the User does not have to provide it and will not lose access to the Controller’s services if consent is not provided. The User may also limit, change the scope of or withdraw consent at any time at the bottom of this page using the “Manage Your Privacy” button.
  1. The User may also provide other data to facilitate contact or handling of an inquiry. Providing data marked as mandatory is required to accept and process the inquiry; failure to provide such data will make it impossible to process the inquiry. Providing other data is voluntary. Personal data is processed to identify the sender and handle their inquiry submitted through the available form. The legal basis for processing is the necessity of processing for the performance of the service agreement (Article 6(1)(b) GDPR); for optionally provided data, the legal basis is consent (Article 6(1)(a) GDPR).

V. HOW DOES THE CONTROLLER OBTAIN PERSONAL DATA?

  1. Personal data means any information that can be used to identify a specific person directly or indirectly. This definition includes personal data collected online through the Controller’s Website and company pages on external platforms.
  2. When contacting the Controller, you may be asked to provide your personal data. Data Controllers may share your personal data with each other and with other companies affiliated with the Controller by capital or personal relationships and may use it in accordance with this Privacy Policy. The Controller may also combine it with other information in order to improve its content.
  3. The Controller collects personal data from various sources. These include:
  • Personal data provided directly – the Controller collects information about how you use the Website, such as the types of content you view or interact with and the frequency and duration of your activities.
  • Personal data collected automatically – the Controller also receives and stores certain types of personal data whenever you contact the Controller online. For example, cookies and tracking technologies are used to obtain personal data when your web browser accesses the Controller’s Website and other content provided on other websites. Personal data is also collected when searching and publishing posts. Examples of the types of personal data collected include IP address, device identifier, location data, and computer and connection information, such as browser type and version, time zone settings, browser plug-in types and versions, and operating system.
  1. A User of the Website may request a commercial offer for products or services offered by the Controller using the form available on the Website. The Controller collects personal data through the form, such as first and last name, telephone number and email address.

VI. USER RIGHTS RELATING TO THE PROCESSING OF THEIR PERSONAL DATA

  1. The GDPR grants the following rights in connection with the processing of personal data:
  • the right to access personal data and receive a copy thereof;
  • the right to rectify or correct personal data;
  • the right to erasure of personal data, the right to be forgotten;
  • the right to restriction of processing of personal data;
  • the right to object to the processing of personal data;
  • the right to withdraw consent;
  • the right to object to the processing of personal data;
  • the right to data portability;
  • the right to lodge a complaint with the President of the Personal Data Protection Office.
  1. Not all of these rights will always be available to the User in every situation. This is due to the nature of the applicable legal provisions.

VII. RETENTION PERIOD FOR PERSONAL DATA

  1. The period for which the Controller processes the User’s personal data depends on the type of service provided and the purpose of processing.
  2. The User’s personal data will be stored until consent is withdrawn or until the matter has been resolved.
  3. Data relating to network traffic analysis collected through cookies and similar technologies may be stored until the cookie expires. Some cookies never expire; therefore, the data retention period will correspond to the time necessary for the Controller to achieve the purposes related to data collection, such as ensuring security and analysing historical data concerning Website traffic.
  4. The data processing period may be extended if processing is necessary to establish and pursue potential claims or defend against claims, and thereafter only where and to the extent required by law. Once the processing period has expired, the data is irreversibly deleted or anonymised.

VIII. DATA SECURITY

  1. The User’s personal data is stored and protected with due diligence, in accordance with the Controller’s implemented internal procedures.
  2. The Controller processes information about the User using appropriate technical and organisational measures that meet the requirements of generally applicable laws, in particular data protection regulations. These measures are primarily intended to protect Users’ personal data against unauthorised access. In particular, only authorised persons who are obliged to keep such data confidential have access to Users’ personal data.
  3. At the same time, the User should exercise due care in securing their personal data transmitted over the Internet, in particular by not disclosing login details to third parties, using antivirus protection and keeping software up to date.

IX. TRANSFER OF DATA TO THIRD PARTIES

  1. The User’s personal data may be transferred to third parties whose services the Controller uses in connection with operating the Website.
  2. Due to the use of Google or Facebook services, Users’ personal data may be transferred to the United States of America (USA), Canada and other countries. These entities guarantee an appropriate level of personal data protection required by European regulations.
  3. Entities processing data made available within the European Economic Area:
  • Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02X525, Ireland (formerly Facebook Ireland Limited).
  • Facebook or Instagram, particularly with regard to advertising tools.
  • Facebook Ireland Ltd. – with regard to the use of Meta Platforms (Facebook) advertising tools and the entrustment of data within the group of custom audiences.
  • Other contractors or subcontractors engaged in technical or administrative support or in providing legal assistance to the Controller and its clients, as well as foreign employment agencies with which the Controller cooperates in recruitment processes and, for example, accounting, IT, graphic design and copywriting service providers, debt collection companies, lawyers and public authorities, such as the tax office – for the purpose of fulfilling legal and tax obligations related to settlements and accounting.
  1. Entities processing data made available outside the European Economic Area:
  • Google Analytics by Google LLC – an entity providing a tool securing the Website and a statistical analysis tool (Google Analytics).
  1. As part of the Controller’s activities, social media plugins have also been embedded on the Website. The purpose and scope of data collection and its further processing and use by service providers are described in the privacy policies indicated below:

Facebook – https://www.facebook.com/privacy/explanation
Instagram – https://help.instagram.com/519522125107875?helpref=page_content

X. COOKIES

  1. Cookies are small files saved and stored on the electronic device you use when visiting this Website. These files contain, among other things, information about the website from which they originate, the lifespan of the files and a randomly generated unique number used to identify the browser.
  2. When visiting the Website for the first time, Users have the opportunity to customise their Cookie consent settings. It is also possible to configure the web browser so that cookies cannot be stored on the end device. However, please note that restricting or disabling cookies may affect the functionality of the Website.
  3. First-party cookies are files belonging to the website being visited, which the Controller can read. We also use the services of third parties (indicated in this document), some of which may read certain cookies for their own purposes, such as optimising Website performance, personalising content or adjusting advertisements.
  4. The Website uses session (temporary) cookies and persistent cookies. Session cookies are stored on the device until the website is closed or the web browser is turned off. Persistent cookies are stored for a specified period indicated in the parameter contained in the cookie.
  5. The Website uses cookies to optimise and ensure the proper functioning of the Website’s features, handle visitor sessions, and for promotional and statistical purposes. We also use Google Analytics tracking technology to monitor visitor traffic.
  6. The User may also manually delete all or selected cookies. Detailed information about cookie management is available on the websites of the most popular web browsers listed below:

XI. GOOGLE ANALYTICS

  1. The Controller uses Google Analytics provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, for analytical and statistical purposes. Google Analytics analyses online services and activities for marketing purposes. Information collected through Google Analytics indicates how the User navigates the Website, the browser and operating system used, the type of device, the time spent on the Website, the subpages visited and whether any irregularities occurred while using the Website. However, the collection of this data does not allow the identification of specific individuals. Details regarding this service can be found here: https://analytics.google.com/analytics/web/provision/?hl=en#/provision
  2. Personal data for analytical and statistical purposes is collected automatically when visiting and browsing the Website. Google Analytics uses cookies. The Google Analytics Cookie Policy can be found here: https://policies.google.com/technologies/cookies?hl=en#types-of-cookies
  3. Google Analytics and Google Analytics 360 provide an appropriate level of protection for personal data that may be transferred to and stored on Google’s servers in the USA. Google states that it uses data protection and security mechanisms provided for by European regulations. Details regarding Google’s use of data from websites and applications that use Google services are available at: https://policies.google.com/technologies/partner-sites

XII. META PIXEL

  1. Meta Pixel is provided by Meta Platforms Ireland Limited, with its registered office at 4 Grand Canal Square, Dublin 2, Ireland.
  2. Meta Pixel is a piece of code placed on a website that enables the measurement and optimisation of advertising campaigns and the creation of audience groups. When a website is loaded, the code is activated and sends information about User activity back to servers also located in the USA. This information is anonymous and may include data such as pages visited, time spent on the Website and actions taken by the User (e.g. clicks and purchases).
  3. Based on the Controller’s legitimate interest in its own marketing, Meta Pixel allows us to monitor User behaviour on the Website, analyse the effectiveness of advertising campaigns, personalise advertisements and optimise the User experience.
  4. A detailed, user-friendly description of how Meta Pixel works is available here: https://www.facebook.com/business/tools/meta-pixel

XIII. SERVER LOGS

  1. Use of the Website involves sending requests to the server on which the Website is hosted.
  2. Each request sent to the server is recorded in server logs, which may include, for example, the IP address, server date and time, information about the web browser and operating system you use.
  3. Data recorded in server logs is not associated with specific individuals using the Website and is used as supporting material for administrative purposes.
  4. The contents of server logs are not disclosed to anyone other than persons authorised to administer the server.

XIV. SOCIAL MEDIA

  1. The Controller maintains profiles on Facebook and Instagram (referred to as “fan pages”). Content, offers and product recommendations are regularly published and shared on these fan pages. Social media service administrators record User behaviour using cookies and other similar technologies whenever Users interact with our fan pages and other Facebook and Instagram websites.
  2. Social media service administrators have access to general statistics regarding the interests and demographic data (such as age, gender and place of residence) of Users visiting the fan pages. Within the framework of using social media services, the scope and purposes of data processing on social media are determined by the administrators of those services.

XV. CHANGES TO THE PRIVACY POLICY

  1. The Policy is regularly reviewed and updated where necessary.
  2. We will update this Privacy Policy when necessary. When changes to this statement are published, we will also change the date of the latest update. We will also retain previous versions of this Privacy Policy in an archive.
  3. We will not restrict your rights under this Privacy Policy without your consent.