Data Pal Book Free Consultation

Legal

Privacy Policy.

Version 2.0 · May 2026

General Provisions

This privacy policy of the Website available at www.data-pal.eu (hereinafter referred to as: "Website") is for informational purposes, which means that it does not constitute a basis for obligations for users of the Website. The privacy policy primarily contains the rules regarding the processing of personal data by the Controller on the Website, including the basis, purposes and period of personal data processing and the rights of data subjects, as well as information on the use of cookies and analytical tools on the Website.

The Controller of the personal data collected via the Website shall be the company DATA PAL SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (limited liability company) based in Kraków, Poland, registered in the register of entrepreneurs of National Court Registry under the number: 0001040916; register court which holds the company's documentation: District Court for Kraków – Śródmieście in Kraków, XI Commercial Department of National Court Registry; HQ address and office address: Lipowa 3D, 30-702 Kraków, Poland; share capital in the amount of: 5 000,00 PLN; tax ID no. NIP/VAT UE: PL6793268946, National Economy Register No. REGON 525518963; e-mail address: contact@data-pal.eu and telephone number: +48 514 005 859 (the call is charged as for a regular phone call, according to the Owner's tariff package) – hereinafter referred to as "Controller" and being simultaneously the Owner of the Website.

How to quickly contact us:

Personal data on the Website shall be processed by the Controller in accordance with the binding legal regulations, in particular the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as "GDPR" or "GDPR Regulation". The official text of the GDPR Regulation: eur-lex.europa.eu.

Using the Website is voluntary. Similarly, providing personal data by the service user using the Website is voluntary, with an exception, that failure to provide the personal data necessary for the use of electronic services on the Website (i.e., contact form) shall result in no possibility of using such services by the user. Providing personal data in such a case is required for the purposes resulting from the legitimate interests of the Controller and if the data subject is willing to use the contact form and receive the response for their request from the Controller, they shall be obligated to provide the required data. The scope of the data required to use the Website's electronic services is each time specified in advance on the Website by the Controller (e.g. before filling out the contact form).

The Controller assures due diligence to protect the interest of persons being data subjects, in particular being responsible and liable for and assuring that the data collected are: (1) processed in accordance with the law, including in particular the GDPR Regulation; (2) collected for specified, lawful purposes and not subjected to further processing incompatible with those purposes; (3) correct as regards the subject matter and adequate as regards the purpose of the processing; (4) stored in a form making it possible to identify the people they apply to, no longer than it proves necessary to attain the purpose of processing and (5) processed in a manner ensuring security of the personal data, including the protection against illicit or illegal processing or accidental loss, damage or destruction, with the use of appropriate technical and organisational measures.

Taking into account the nature, scope, context and purpose of processing as well as the risk of breaching the rights or freedoms of natural persons with varied likelihood and degree of threat, the Controller is implementing appropriate technical and organisational measures so that the processing takes place pursuant to the GDPR Regulation and it is possible to show it. The measures are reviewed and updated, as necessary. The Controller applies technical measures preventing the acquisition and modification of personal data sent electronically by unauthorised persons.

Legal Disclaimer

This Website is for informational purposes, it allows you to get acquainted with the products or services of the Website Owner and contact him by submitting an inquiry using the contact form. A newsletter may also be available on the Website, the subject of which will be to inform about the Website Owner's activities, news and new products and services of the Website Owner. The applicable law for the Website and these Terms and Conditions and the agreements concluded on their basis is the Polish law.

The Website is not an online store and it is not possible to conclude a sales contract through it (this means that advertisements, price lists and other product information posted on the Website should not be treated as an offer, or possibly as an invitation to conclude a contract). The conclusion of a sales agreement may take place as a result of an inquiry addressed to the Website Owner and only after the parties have agreed on the detailed terms and conditions of such an agreement – the conclusion and terms of such an agreement are regulated, however, by a separate sales agreement or separate general terms and conditions of sale of products by the Website Owner, which will be made available by the Website Owner.

Basis for the Processing of Data

The Controller is authorised to process the personal data in cases, and to the extent, when at least one of the following conditions is met: (1) the data subject consented to the processing of their data to one or more specified ends; (2) processing is necessary for contract performance the data subject is a party to, or to take actions to the request of the data subject, prior to contract conclusion; (3) processing is necessary to meet the legal obligation of the Controller; or (4) processing is necessary for the needs resulting from the legally justified interests of the Controller or third party, except for situations when the interests or basic rights and freedoms of the data subject override such interests and they require personal data protection, especially when the data subject is a child.

The processing of personal data by the Controller each time requires having at least one basis indicated above. Specific bases for processing personal data of the service users of the Website by the Controller are specified in the following point of the privacy policy – as regards the specific goal of processing personal data by the Controller.

Purpose, Basis, and Period of Processing Data

Each time, the purpose, basis, period, and scope as well as the recipients of personal data being processed by the Controller result from actions undertaken by a given data subject (in particular: a service user of the Website or a candidate in a recruitment process). The Controller may process the personal data on the Website for the purposes, on the bases and within the periods as follows:

Purpose of data processingLegal basis for processing the dataPeriod of data storage
Executing a contract for the provision of Electronic Services or acting at the request of a data subject, before concluding a contractArticle 6(1)(b) of the GDPR Regulation (performance of the contract) – processing is necessary to perform the contract to which the data subject is a party or to take action at the request of the data subject before concluding the contractThe data shall be stored for the period necessary for the performance, termination, or expiry of the contract for the performance of services concluded with the Controller.
Direct marketingArticle 6(1)(f) of the GDPR Regulation (legitimate interest of the Controller) – the processing is required for achieving the goals based on the legitimate interest of the Controller which includes upholding interests and strengthening reputation of the Controller and the Website as well as aiming to sell services and productsThe data shall be stored for the period of the legitimate interest of the Controller, however no longer than the period of limitation of claims as regards the data subject under the business activity of the Controller. The period of limitation shall be specified by legal provisions, in particular the Civil Code (the basic limitation period for claims related to running a business is three years, and for a sales contract two years). The Controller may not process the data for the needs of direct marketing in the case of expressing clear objection in this field by the data subject.
MarketingArticle 6(1)(a) of the GDPR Regulation (consent) – the data subject expressed the consent to process its personal data for marketing purposes by the ControllerThe data are stored until the data subject withdraws the consent to further process their data to that end.
Determining, pursuing or defence of claims on the side of the Controller, or ones that may arise as regards the ControllerArticle 6(1)(f) of the GDPR Regulation – the processing is required for the purposes resulting from the legitimate interests of the Controller which includes determining, pursuing or defence of claimsThe data shall be stored for the period of the legitimate interest of the Controller, however no longer than the period of limitation of claims against the Controller. The period of limitation shall be specified by legal provisions, in particular the Civil Code (the basic period of limitation in the case of claims against the Controller amounts to six years).
Use of the Website and ensuring its proper functioningArticle 6(1)(f) of the GDPR Regulation (legitimate interest of the Controller) – the processing is required for the purposes resulting from the legitimate interests of the Controller which includes operating and maintenance of the WebsiteThe data shall be stored for the period of the legitimate interest of the Controller, however no longer than the period of limitation of claims as regards the data subject under the business activity of the Controller (the basic period in the case of claims related to business activity amounts to three years).
Preparing statistics and analysing the manner of the data subject conduct on the WebsiteArticle 6(1)(f) of the GDPR Regulation (legitimate interest of the Controller) – the processing is required for the purposes resulting from the legitimate interests of the Controller which includes preparing statistics and analysing conduct on the Website in order to improve its functioningThe data shall be stored for the period of the legitimate interest of the Controller, however no longer than the period of limitation of claims as regards the data subject under the business activity of the Controller (the basic period amounts to three years).
Conducting the recruitment process for a specific positionArticle 6(1)(b) of the GDPR Regulation (steps prior to entering into a contract) and, in the case of recruitment for employment under a contract of employment, Article 22(1) of the Polish Labour Code (Act of 26 June 1974, as amended), in the scope of data specified therein, in particular: first and last name, date of birth, contact details, education, professional qualifications and employment historyThe data shall be stored until the recruitment process is closed, however no longer than 6 months from its closure.
Processing of additional personal data provided voluntarily by the candidate, beyond the scope of Article 22(1) of the Polish Labour Code or beyond the data necessary to take steps prior to entering into a contract, in particular: LinkedIn profile, photograph, additional contact details, references and other materials voluntarily attached to the applicationArticle 6(1)(a) of the GDPR Regulation (consent of the data subject, expressed by submitting the application or otherwise providing such data to the Controller)The data shall be stored until the recruitment process is closed, however no longer than 6 months from its closure, or until the consent is withdrawn, whichever occurs first.

In the case of recruitment processes (rows above), the provision of personal data by the candidate is voluntary. However, failure to provide the data specified in Article 22(1) of the Polish Labour Code (in the case of recruitment for employment) or the data necessary to take steps prior to entering into a contract (in the case of other forms of engagement) shall result in no possibility for the candidate to participate in the recruitment process. The provision of additional voluntary data (in particular: LinkedIn profile and other materials beyond the statutory scope) shall not affect the candidate's participation in the recruitment.

Data Recipients

For the needs of proper Website functioning, it shall be necessary for the Controller to make use of external companies' services (e.g., software provider). The Controller uses solely the services of such processing entities which ensure sufficient guarantee to implement appropriate technical and organisational measures so that the processing meets the requirements set out in the GDPR Regulation and protects the rights of data subjects.

Providing data by the Controller does not take place in every case and not to all the recipients or categories of recipients defined in the privacy policy – the Controller provides the data only in the case it proves necessary to attain a given purpose of personal data processing and solely within the necessary scope.

The Controller may provide personal data to a third country, while the Controller ensures that it shall only be a third country which is considered to provide an adequate level of protection in accordance with the GDPR Regulation, and in the case of other countries that the transfer will take place on the basis of standard data protection clauses. The Controller ensures that the data subject has a right to get a copy of their data. The Controller provides personal data to a third country only in the case and scope necessary to execute a certain purpose of data processing consistent with this privacy policy.

Personal data of the Website users may be provided to the following recipients or categories of recipients:

Profiling on the Website

The GDPR Regulation requires the Controller to inform about the automated decision-making process, including profiling referred to in Article 22(1) and (4) of the GDPR Regulation, and – at least in those cases – the vital information concerning the decision-making process as well as the meaning and foreseeable consequences of processing for the person being the data subject. Bearing in mind the above, the Controller specifies in this point of the privacy policy the information concerning the possible profiling.

The Controller may use profiling on the Website for direct marketing purposes, yet the decisions made on its basis by the Controller do not concern the conclusion or rejection to conclude the contract, or the possibility to make use of electronic services.

Profiling on the Website consists in automatic analysis or forecast of the conduct of a given person on the Website, e.g., by viewing the page of a specific service on the Website. The condition for such profiling is for the Controller to have the personal data of the person, so that they can later send them e.g. a discount code.

The data subject shall have the right not to depend on the decision, which is only based on automated processing, including profiling, and has some legal effects on the person or similarly affects them. The Controller does not make decisions concerning candidates in recruitment processes based solely on automated processing, including profiling.

The Rights of the Data Subject

The right to access, rectify, restrict, erase or transmit – the data subject shall have the right to demand the Controller to have access to their personal data, rectify, erase ("the right to be forgotten") or restrict the processing and shall have the right to object to the processing and transmit their data. Detailed conditions of the above rights shall be indicated in Articles 15 to 22 of the GDPR Regulation.

The right to withdraw the consent at any time – the person whose data are being processed by the Controller on the basis of the consent given (pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR Regulation) shall have the right to withdraw their consent at any time without any impact on the lawfulness of processing carried out based on the consent prior to the withdrawal.

The right to lodge a complaint with a supervisory body – the person whose data are being processed by the Controller shall have the right to lodge a complaint with a supervisory body in a manner and mode specified in the provisions of the GDPR Regulation and the Polish law, in particular the Personal Data Protection Act. The supervisory body in Poland shall be the President of the Office for Personal Data Protection.

The right to object – the data subject shall have the right, at any time, to object – for reasons related to their particular situation – to the processing of their personal data based on Article 6(1)(e) (public interest or official authority) or (f) (legitimate interest of the Controller), including profiling based on these provisions. The Controller in such a case must stop processing the personal data, unless they show the existence of legally significant and justified bases for the processing, overriding the interests, rights and freedoms of the data subject, or the bases for determining, pursuing, or defending the claims.

The right to object as regards direct marketing – in the case the personal data are being processed for the needs of direct marketing, the data subject shall have the right, at any time, to object to the processing of their personal data for the needs of such marketing, including profiling, to the extent to which the processing is related to direct marketing.

To perform the rights mentioned in this point of the privacy policy, one may contact the Controller by sending an appropriate message in writing or via e-mail to the address of the Controller indicated at the beginning of the privacy policy.

Cookies on the Website and Analytics

Cookies are small pieces of text files sent by the server and saved on the side of the person visiting the Website (e.g., on the hard disk of a computer, laptop, or smartphone's memory card – depending on the type of device used by the Website's visitor). Detailed information on cookies as well as the history of their origin can be found e.g. at: en.wikipedia.org/wiki/HTTP_cookie.

The Controller may provide a tool on the Website for easy and active management of cookies, available after first entering the Website and then available in the Website footer. Active management allows, among other things, to check what cookies are or can be saved when using the Website, as well as to select and later change the scope and purposes of using cookies in relation to the device and the person visiting the Website. When starting to use the Website, the visitor will be asked to select cookie settings. They can be changed later by changing the settings in this tool available on the Website, and if it is not available, read the information below regarding, among others, managing cookies from the browser level.

Cookies which can be sent via the Website can be divided into several types, according to the following criteria:

By providerBy retention period on the deviceBy purpose of use
(1) own (created by the Controller's Website) and (2) belonging to other persons / third parties (other than the Controller)(1) session cookies (stored until the moment of closing the Website or a browser) and (2) persistent cookies (having an expiration period defined by the parameters of each file or until they are removed by hand)(1) strictly necessary cookies (enabling proper functioning of the Website); (2) functional / preferential cookies (enabling adjustment of the Website to the visitor's preferences); (3) analytical and performance cookies (collecting information on the use of the Website); (4) marketing, advertising and social media cookies (collecting information about a person visiting the Website in order to display advertisements, personalize them, measure effectiveness and conduct other marketing activities, including on websites separate from this Website)

The Controller may process information contained in cookies during visits to the Website for the following particular purposes:

As a standard, most internet browsers on the market accept saving cookies by default. Every person has the possibility to specify the conditions of using cookies in the browser settings. It means that one may, e.g., partially restrict (e.g. temporarily) or fully disable saving cookies – in the latter case it may have an impact on some functionalities of the Website. The browser settings concerning cookies are essential as regards the consent to use cookies by the Website – in accordance with the law, such consent may also be expressed in the browser settings. Detailed information concerning the change in cookies settings and their individual removal in the most common browsers (Chrome, Firefox, Internet Explorer, Opera, Safari, Microsoft Edge) is available in the help section of the relevant browser. Independent of the browser used, you can apply tools available e.g. at: cookiemetrix.com or cookie-checker.com.

The Controller may use Google Analytics and Google Ads services on the Website, which are provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). The services help the Controller to analyse the frequency of visits to the Website. The data collected are processed in order to generate statistics helpful while administering the Website. The data are of a collective nature. Using the above services, the Controller collects such data as the sources and medium of acquiring visitors, the manner of their conduct on the Website, information concerning their devices and browsers, IP and domain, geographical data and demographic data (age, sex) and interests.

It is possible to easily block sharing information with Google Analytics as regards the activity on the Website – install to that end an opt-out add-on made available by Google Ireland Ltd., available here: tools.google.com/dlpage/gaoptout. Full information on the principles of data processing of visitors to the Website by Google Ireland Ltd. is included in the privacy policy of Google services available at: policies.google.com/technologies/partner-sites.

External Links

The Website may contain links to other websites. The Controller encourages you to read the regulations and privacy policy established there after going to other websites. These regulations apply only to this Website.

Contact Us

In case of any issues or questions regarding the use of our Website or any other questions, please contact the Owner of the Website: