Privacy policy
We take care of your data. Below we explain what information we collect through the website, what we use it for and what rights you have.
This privacy policy has been adopted in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (Official Journal of the European Union No. L 119/1 of 4 May 2016; hereinafter: the GDPR). The purpose of this policy is in particular to fulfil the information obligation referred to in Articles 13 and 14 of the GDPR.
I. Definitions
The following terms are used throughout this policy:
- the Website - the website operated by Creotec at https://creotec.com.pl.
- We, Creotec, the Controller - CREOTEC spółka z ograniczoną odpowiedzialnością, with its registered office in Katowice at Aleja Wojciecha Korfantego 55/33, 40-161 Katowice, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court Katowice-Wschód in Katowice, 8th Commercial Division of the National Court Register, under KRS number 0000926020, VAT ID (NIP): 6343002220, REGON: 520186746, e-mail address: biuro@creotec.com.pl, tel. +48 604 147 536.
- You, the Customer - individuals whose personal data is processed by Creotec in connection with the use of the Website.
II. Who is the data controller?
A data controller is the entity that determines the purposes and means of processing personal data. The controller of your personal data is Creotec.
III. Whose personal data do we process?
In connection with our business we process in particular the personal data of Website users, of people contacting us about an offer, and of job applicants. The scope of the data processed is in each case adequate to the purposes of processing.
IV. What data do we collect through the Website and what do we use it for?
The scope of the data we collect and the purposes of processing depend on which features of the Website you use, as follows:
IV.I Browsing the Website
1. What data do we collect?
Data recorded in server logs, in which the user is identified by a URL. This data includes:
- the time the request was received,
- the time the response was sent,
- the client station name - identified via the HTTP protocol,
- information about any errors that occurred during the HTTP transaction,
- the URL of the page previously visited by the user (referrer link) - where the user reached the Website via a link,
- information about the user's browser,
- information about the IP address.
2. What do we process the data for?
To administer the server hosting the Website, to keep it secure, and to analyse Website traffic statistically.
3. Do you have to provide your data?
Providing the data is voluntary, but it is a condition of using the Website properly.
4. On what legal basis do we process your data?
On the basis of:
- the contract for the electronic service consisting in making the Website available (Article 6(1)(b) of the GDPR), and
- our legitimate interest (Article 6(1)(f) of the GDPR) - consisting in being able to make the Website available to third parties and in ensuring that it displays correctly.
5. Who may we share your data with?
Personal data may be disclosed to third parties only where we are required or entitled to do so under the law. Recipients of the data may in particular be:
- those who service our infrastructure or IT systems,
- those who provide data hosting,
- subcontractors involved in performing contracts concluded with you.
6. How long will we process your data?
For as long as is necessary to perform the contracts concluded, or for as long as our legitimate interest in processing the data lasts - in any event no shorter than the duration of your visit to the Website.
Please note that where the basis for processing is a legitimate interest, you may object to further processing of the data, in accordance with section VIII below.
IV.II The "Request a quote" form
1. What data do we collect?
Your full name, company name and position, e-mail address and telephone number, together with any project information you choose to give us: project type, location, expected scope of services, estimated value, planned delivery date and the content of your message (project description).
2. What do we process the data for?
To respond to your enquiry, in particular to correspond with you by any known means, including post, e-mail or other methods of communication, to inform you about our offer and to prepare a quotation or a proposed scope of delivery. In addition, to pass your contact details (name, surname, e-mail address, telephone number) to entities cooperating with the Controller, including consortium partners and subcontractors, so that they can contact you about your enquiry or present their own offer, where delivery of the project requires their involvement.
3. Do you have to provide your data?
Providing the data is voluntary, but it is a condition of us replying to your enquiry. Your name, e-mail address and project description are required to submit the form; the remaining fields are at your discretion.
4. On what legal basis do we process your data?
On the basis of your consent to the processing of data (Article 6(1)(a) of the GDPR), given by ticking the checkbox containing the consent clause. A separate, optional checkbox covers consent to being contacted by telephone and e-mail about an offer; not giving it does not prevent you from submitting the enquiry.
Please note that you have the right to withdraw your consent at any time (for example by sending an e-mail to: biuro@creotec.com.pl), without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
The consent referred to above also covers passing your contact details to entities cooperating with the Controller so that they can present their offer or contact you about your enquiry - no additional, separate consent is required for this purpose.
5. Who may we share your data with?
Personal data may be disclosed to third parties only where we are required or entitled to do so under the law. Recipients of the data may in particular be:
- those who service our infrastructure or IT systems,
- those who provide data hosting and the e-mail delivery provider through which your submission is sent,
- subcontractors through whom we may handle contact regarding your enquiry,
- entities cooperating with the Controller, including consortium partners, to whom - on the basis of the consent you have given - we may pass your contact details so that they can present their offer or contact you about your enquiry.
6. How long will we process your data?
Until you withdraw your consent to being contacted.
IV.III Recruitment forms
1. What data do we collect?
Your full name, e-mail address, telephone number and the data contained in the application document (CV) you send us, together with the content of your message if you add one. This applies both to applications for a specific position and to submissions sent without reference to a particular vacancy.
2. What do we process the data for?
To carry out the recruitment process for the position stated in the vacancy notice and, in the case of speculative applications, to assess your candidacy and contact you when a matching vacancy arises.
3. Do you have to provide your data?
Providing the data is voluntary, but it is a condition of taking part in the recruitment process. Please do not include in your application documents any special categories of data referred to in Article 9(1) of the GDPR (for example health data), or data going beyond what is necessary to conduct the recruitment.
4. On what legal basis do we process your data?
As regards the data specified in labour law - on the basis of Article 6(1)(c) of the GDPR in conjunction with Article 221 of the Polish Labour Code. As regards the remainder, including data provided on your own initiative in the application documents - on the basis of consent (Article 6(1)(a) of the GDPR), given by ticking the checkbox containing the consent clause and submitting the application.
Please note that you have the right to withdraw your consent at any time (for example by sending an e-mail to: biuro@creotec.com.pl), without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
5. Who may we share your data with?
Recipients of the data may be those who service our infrastructure or IT systems, those who provide data hosting, and the e-mail delivery provider. The data is not passed to cooperating entities for offer-related purposes.
6. How long will we process your data?
Until the end of the recruitment process for which it was collected and, in the case of speculative applications and consent to take part in future recruitment, no longer than 12 months from the date the application was submitted, unless you withdraw your consent earlier.
IV.IV Cookies
The cookie policy forms Annex 1 to this Privacy Policy.
V. May the data be processed through automated decision-making, including "qualified" profiling?
We currently carry out no operations involving automated decision-making that produces legal effects concerning the data subject or similarly significantly affects them. Should we introduce such processing operations in the future, we will ensure they comply with the applicable regulations, including Article 22 of the GDPR.
VI. May your personal data be transferred outside the European Economic Area (EEA)?
Yes. The Website and the handling of forms rely on services provided by suppliers based in the United States, and data may therefore be transferred outside the EEA. This applies in particular to:
- the provider of the hosting and infrastructure on which the Website is made available,
- the e-mail delivery provider through which form submissions are sent,
- providers of resources loaded by the browser when the Website is displayed (typefaces and software libraries), who may in that respect gain access to the user's IP address,
- providers of the analytics tools referred to in Annex 1.
Transfers take place with the safeguards required by generally applicable law, in particular on the basis of standard contractual clauses approved by the European Commission (SCCs) or on the basis of a European Commission adequacy decision (the Data Privacy Framework), where the supplier concerned participates in that programme.
VII. What rights do you have in connection with the processing of your data?
You may in particular submit a request to us for:
- access to the data we process (including information about our processing or a copy of the data),
- rectification (correction) of the data,
- restriction of processing (suspending operations on the data or not erasing it),
- erasure of the data (the "right to be forgotten"),
- transfer of the data to another controller.
Such requests may be sent in particular in the manner set out in section XI below, and will be considered in accordance with the applicable regulations, including Articles 15-20 of the GDPR.
VIII. Right to object
Regardless of the above, you have the right to object to the processing of your data carried out on the basis of our legitimate interest. In that case:
- if the personal data is processed for marketing purposes, we will cease such processing immediately;
- if the processing is based on an interest of another kind, we will cease such processing unless we demonstrate: a) that the interest in question overrides your interests, rights and freedoms, or b) that there are grounds for the establishment, exercise or defence of legal claims.
The right to object may be exercised in particular by sending an appropriate statement in the manner set out in section XI below.
IX. Complaint to the supervisory authority
If you consider that the processing of your data infringes the applicable regulations, you have the right to lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office (PUODO). Contact details for PUODO are available in particular at https://uodo.gov.pl/pl/p/kontakt.
X. Where the privacy policy is published and how it is updated
This privacy policy may be amended from time to time. The current version will at all times be available on our website at: https://creotec.com.pl/polityka-prywatnosci.
XI. How can you contact us?
If you have any questions about how we use your personal data, you can contact us by telephone, e-mail or post at the following numbers and addresses:
CREOTEC sp. z o.o.Aleja Wojciecha Korfantego 55/33
40-161 Katowice
- marked: "personal data protection"
tel. +48 604 147 536, e-mail: biuro@creotec.com.pl
Annex 1 to the Privacy Policy - COOKIE Policy for the website https://creotec.com.pl
§1
- This Policy sets out the rules under which the Controller stores information on, and accesses information already stored on, the Customer's Devices in the form of Cookies.
- All terms defined in the Privacy Policy retain their meaning under this Cookie Policy. In addition, the following terms have the meanings set out below:
- Cookies - means IT data, in particular small text files, saved and stored on the devices through which the Customer uses the pages of the Website. Cookies usually contain the name of the website they come from, how long they are stored on the end device, and a unique number.
- First-party Cookies - means Cookies placed by the Controller in connection with the electronic services provided by the Controller through the Website.
- Third-party Cookies - means Cookies placed by third parties through the Website.
- the Policy - this Cookie Policy, forming Annex 1 to the Privacy Policy.
- Device - means the electronic device through which the Customer accesses the Website.
§2
- Using Cookies, the Controller stores information on the Customer's Device or accesses information already stored there, under the rules set out in this Policy.
- The Controller uses the following types of Cookies:
- Session Cookies : stored on the Customer's Device and remaining there until the browser session ends. The stored information is then permanently deleted from the Device's memory.
- Persistent Cookies : stored on the Customer's Device and remaining there for the period specified in the file parameters or until they are deleted. Ending the browser session or switching off the Device does not remove this type of Cookie from the Device.
- The Controller's use of Cookies does not cause any configuration changes to the Customer's Device or to the software installed on it.
§3
- The Controller uses First-party Cookies to adapt the content of the Website to the User's preferences and needs, in particular taking into account the type of Device through which the User accesses the Website. Cookies of this kind include:
- "strictly necessary" cookies, enabling the use of services available on the Website, e.g. authentication cookies used for services requiring authentication on the Website;
- cookies used to ensure security, for example to detect authentication abuse on the Website;
- "performance" cookies, enabling the collection of information about how the pages of the Website are used;
- "functional" cookies, enabling the User's chosen settings to be remembered and the User interface to be personalised, e.g. the selected language or the User's region, font size, website appearance, etc.;
- "marketing" cookies, enabling advertising content better matched to Users' interests to be delivered.
- The Controller uses Third-party Cookies to produce aggregate statistics and analyses monitoring how Users use the Website, which makes it possible to adapt it as closely as possible to Users' needs. For this purpose the Controller uses the services of:
- Microsoft Clarity - which produces maps of User behaviour and their activity history on the Website, allowing activity on the Website to be tracked. Detailed information on data processing is available on the Microsoft website (https://www.microsoft.com/pl-pl/privacy/privacystatement);
- Google Analytics - under which, when the Website is opened, information about the origin of users identified on the basis of their IP address is read, recorded and sent to a secure Google server. Detailed information is available on the Google website (https://policies.google.com/technologies/types?hl=pl).
- In connection with the use of cookies, the Controller collects only statistical data relating to browsing history. Other data (such as first name, surname, address, etc.) is not recorded in any way.
§4
- The Third-party Cookies referred to in §3(2) are activated only after the Customer has given consent through the banner displayed on the first visit to the Website. Until consent is given, the Website uses only Cookies strictly necessary for it to function. Consent may be changed or withdrawn at any time using the "Cookie settings" link in the Website footer - withdrawing consent is just as easy as giving it.
- The Customer may restrict or disable Cookie access to their Device in their browser settings or by configuring the service - in particular so as to block automatic handling of Cookies or to be informed each time a Cookie is placed on the Customer's Device. Instructions on how to do this can be found on the manufacturers' websites, e.g.:
- Mozilla Firefox: instructions,
- Google Chrome: instructions,
- Microsoft Edge: instructions.
- The Customer may delete Cookies at any time.
- Restricting the use of Cookies may affect some of the functionality available on the Website.
