The Controller of the personal data collected via the Site shall be the company Pierson Export based in France (office address and correspondence address: 55 Boulevard Bineau, 92200 Neuilly-sur-Seine, France) entered into the trade and companies register (RCS) conducted by the Nanterre Commercial Court under the number 390737054 – hereinafter referred to as “Controller” and being simultaneously the owner of the Site.
Personal data in the Site shall be processed by the Controller in accordance with the binding legal regulations, in particular the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) hereinafter referred to as “GDPR” or “GDPR Regulation”. The official text of the GDPR Regulation: http://eur-lex.europa.eu/legal-content/ENG/TXT/?uri=CELEX%3A32016R0679.
Using the Site is voluntary. Similarly, providing personal data by the service user using the Site is voluntary, subject to two exceptions: (1) entering into contracts with the Controller – failure to provide the personal data necessary for the conclusion and performance of an agreement or for the provision of electronic services by the Controller in the cases and within the scope required to enter into the contract. Providing personal data is a contractual requirement in such a case and if the data subject is willing to enter into the contract with the Controller, they shall be obligated to provide the required data. The scope of the data required to enter into the contract is each time specified by the Controller; (2) statutory obligations of the Controller – specifying the personal data is a statutory requirement resulting from the commonly binding legal regulations (e.g. processing data for purpose of tax settlements) obligating the Controller to process the personal and failure to specify the data will render it impossible for the Controller to perform the obligations.
The Controller assures due diligence to protect the interest of persons being data subjects, in particular being responsible and liable for and assuring that the data collected are: (1) processed in accordance with the law regulations; (2) collected for specific, legal purposes and not subject to further processing inconsistent with the purposes; (3) correct as regards the subject matter and adequate as regards the purpose of the processing; (4) stored in a form making it possible to identify the people they apply to, no longer than it proves necessary to attain the purpose of processing and (5) processed in a manner ensuring security of the personal data, including the protection against illicit or illegal processing or accidental loss, damage or destruction, with the use of appropriate technical and organisational measures.
Taking into account the nature, scope, context and purpose of processing as well as the risk of breaching the rights or freedoms of natural persons with varied likelihood and degree of threat, the Controller is implementing appropriate technical and organisational measures so that the processing takes place pursuant to the Regulation and it is possible to show it. The measures are reviewed and updated, as necessary. The Controller applies technical measures preventing the acquisition and modification of personal data sent electronically by unauthorised persons.
BASIS FOR THE PROCESSING OF DATA
The Controller is authorised to process the personal data in cases, and to the extent, when at least one of the following conditions is met: (1) the data subject consented to the processing of their data to one or more specified ends; (2) processing is necessary for contract performance the data subject is a party to, or to take actions to the request of the data subject, prior to contract conclusion; (3) processing is necessary to meet the legal obligation of the Controller; or (4) processing is necessary for the needs resulting from the legally justified interests of the Controller or third party, except for situations when the interests or basic rights and freedoms of the data subject override such interests and they require personal data protection, especially when the data subject is a child.
PURPOSE, BASIS AND PERIOD OF PROCESSING DATA ON THE SITE
Each time, the purpose, basis, period and scope as well as the recipients of personal data being processed by the Controller result from actions undertaken by a given service user in the Site.
The Controller may process the personal data in the Site for the purposes, on the bases and within the periods as follows:
DATA RECIPIENTS ON THE SITE
For the needs of proper Site functioning, it shall be necessary for the Controller to make use of external companies’ services (e.g. software provider). The Controller uses solely the services of such processing entities which ensure sufficient guarantee to implement appropriate technical and organisational measures so that the processing meets the requirements set out in the GDPR Regulation and protects the rights of data subjects.
Personal data of the Site service users may be provided to the following recipients or categories of recipients:
- service providers rendering for the Controller technical, IT or organisational solutions, making it possible for the Controller to conduct a business, inclusive of the Site and electronic services provided via it (in particular computer software providers for the Site, e-mail companies and hosting providers as well as software providers for company management and technical aid for the Controller) – the Controller makes the collected personal data of the service user available to the selected provider operating to their order only in the case and to the extent necessary for attaining a given purpose of data processing in accordance herewith.
- accounting, legal and counselling services providers rendering for the Controller accounting, legal or counselling services (in particular an accounting agency, law firm or debt collection company) – the Controller makes the collected personal data of the service user available to the selected provider operating to their order only in the case and to the extent necessary for attaining a given purpose of data processing in accordance herewith.
THE RIGHTS OF THE DATA SUBJECT
The right to access, rectify, restrict, erase or transmit – the data subject shall have the right to demand the Controller to have access to their personal data, rectify, erase (“the right to be forgotten”) or restrict the processing and shall have the right to object to the processing and transmit their data. Detailed conditions of the above rights shall be indicated in Articles 1522 of the GDPR Regulation.
The right to withdraw the consent at any time – the person whose data are being processed by the Controller on the basis of the consent given (pursuant to Article 6, par. 1, point a) or Article 9, par. 2, point a) of the GDPR Regulation), they shall have the right to withdraw their consent at any time without any impact on the compatibility with the right to process made based on the consent prior to the withdrawal.
The right to lodge a complaint with a supervisory body – the person whose data are being processed by the Controller shall have the right to lodge a complaint with a supervisory body in a manner and mode specified in the provisions of the GDPR Regulation and the French law.
The right to object – the data subject shall have the right, at any time, to lodge a complaint – for reasons related to their particular situation – as regards the processing of their personal data based on Article 6, par. 1, point e) (public interest or official authority) or f) (legitimate interest of the controller) in the case of profiling based on the provisions. The Controller in such a case must stop processing the personal data, unless they show the existence of legally significant and justified bases for the processing, overriding the interests, rights and freedoms of the data subject, or the bases for determining, pursuing or defending the claims.
The right to object as regards direct marketing – in the case the personal data are being processed for the needs of direct marketing, the data subject shall have the right, at any time, to lodge a complaint as regards the processing of their personal data for the needs of such marketing, including profiling, to the extent to which the processing is related to direct marketing.
COOKIES IN THE SITE AND ANALYTICS
Cookies are small pieces of text files sent by the server and saved at the visitor’s of the Site (e.g. on the hard disk of a computer, laptop, or smartphone’s memory card – depending on the type of device used by the Site’s visitor). Detailed information on Cookies as well as the history of their origin can be found e.g. at: https://en.wikipedia.org/wiki/HTTP_cookie.
Cookies, which can be sent via the Site, can be divided into various types, according to the following criteria:
The Controller may process information contained in Cookies during visiting of the Site for the following particular reasons:
Checking in the most popular internet browsers, which Cookie files (including the expiry period of Cookies and their provider) are being sent in a given moment by the Site can be done, as follows:
As a standard, most internet browsers on the market accept saving Cookies by default. Every person has the possibility to specify the conditions of using Cookies in the browser settings. It means that one may, e.g. partially restrict (e.g. temporarily) or fully disable saving Cookies – in the latter case it may have an impact on some functionalities of the Site.
The Controller may use Google Analytics services on the Site, which are provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). The services help the Controller to analyse the frequency of visits on the Site. The data collected are processed in order to generate statistics helpful while administering the Site. The data are of collective nature. Using the above services on the Site, the Controller collects such data as the sources and medium of acquiring visitors of the Site and the manner of their conduct on the website of the Site, information concerning their devices and browsers used to visit the website, IP and domain, geographical data and demographic data (age, sex) and interests.
It is possible to easily block sharing information with Google Analytics as regards the activity on the Site – install to that end an opt-out add-on made available by Google Inc. available at: https://tools.google.com/dlpage/gaoptout?hl=pl.