§1Personal Data Controller
- 1.The controller of personal data collected through the website available at aiform.pl (the “Website”) is AIForm - Pawel Sobocinski, with its registered office in Warsaw (ul. Chmielna 2/31, 00-020 Warsaw, Poland), Tax ID (NIP): 8792503470, National Business Registry Number (REGON): 340900499 (the “Controller”).
- 2.To contact the Controller about personal data protection matters, email: biuro@aiform.pl, or write to: ul. Chmielna 2/31, 00-020 Warsaw, Poland.
- 3.The Controller has not appointed a data protection officer.
§2Scope, purposes and legal bases for processing personal data
- 1.Contact form. Data processed: name, email address, message content and any other data provided voluntarily in the message. Purpose: responding to the enquiry and handling correspondence. Legal basis: Article 6(1)(f) of the GDPR — the Controller’s legitimate interest in communicating with people who submit enquiries; and, where the processing is necessary to take steps prior to entering into a contract, Article 6(1)(b) of the GDPR.
- 2.Email correspondence. Data of individuals sending messages to the Controller’s email addresses — the purpose and legal basis are the same as in point 1 above.
- 3.Server logs. IP address, date and time of the request, URL, browser information and operating system information — recorded automatically by the server. Purpose: ensuring the security and proper operation of the Website and diagnosing errors. Legal basis: Article 6(1)(f) of the GDPR.
- 4.Establishment, exercise and defence of legal claims. Legal basis: Article 6(1)(f) of the GDPR.
§3Voluntary provision of data
Providing personal data is voluntary, but necessary to use the contact form or receive a response to an enquiry. If you do not provide the data, we will be unable to contact you.
§4Recipients of data
- 1.Personal data may be processed on the Controller’s behalf by data processors, solely to the extent necessary for them to provide their services. These may include providers of hosting and server infrastructure, providers of email services used in the course of business, and other technical service providers — solely to the extent that they actually process personal data in connection with the operation of the Website.
- 2.Personal data is not sold or disclosed to third parties for marketing purposes.
- 3.Personal data may be disclosed to authorised public authorities where required by law.
§5Transfers of data outside the EEA
Personal data is not transferred outside the European Economic Area.
§6Data retention period
- 1.Personal data is retained for the duration of the correspondence and subsequently for as long as necessary to establish, exercise or defend legal claims, but no longer than three years after the correspondence has ended.
- 2.Server logs are retained for the period determined by the configuration of the hosting service, but no longer than necessary to ensure the security of the Website, diagnose errors and establish, exercise or defend legal claims.
- 3.Data processed on the basis of consent is retained until that consent is withdrawn.
§7Rights of data subjects
- 1.Every data subject has the right to: access their personal data (Article 15 of the GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), data portability (Article 20), and object to processing based on legitimate interests (Article 21). Where processing is based on consent, the data subject also has the right to withdraw consent at any time without affecting the lawfulness of processing carried out before its withdrawal.
- 2.To exercise your rights, submit a request to: biuro@aiform.pl.
- 3.Every data subject has the right to lodge a complaint with the supervisory authority: President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl.
§8Automated decision-making and profiling
The Controller does not make decisions concerning users that are based solely on automated processing, including profiling, and that produce legal effects.
§9Cookies
- 1.In its current version, the Website does not store cookies or use other similar technologies on users’ devices for any purpose, including analytics or marketing.
- 2.If cookies are introduced in the future, particularly in connection with new Website functionality, the Controller will update this Policy and implement the mechanisms required by law to inform users and, where necessary, obtain their consent.
§10Data security
The Controller applies technical and organisational measures appropriate to the level of risk, including transmission encryption (TLS/SSL), access controls for systems and regular software updates.
§11Changes to this Privacy Policy
The Controller reserves the right to update this Policy, particularly if the functionality of the Website or the applicable law changes. The current version, together with the date of the latest update, is always available on the Website.