Privacy Policy
I. PERSONAL DATA CONTROLLER
The controller of your personal data is Fonia Telecom spółka z ograniczoną odpowiedzialnością with its registered office in Warsaw, at the following address: ul. Zwycięzców 2, 03-941 Warsaw, Poland, REGON number: 388645503, NIP number: 1133031081, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under KRS number 0000890861, hereinafter referred to as the „Data Controller”.
The Data Controller fulfils the information obligations arising from Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, hereinafter referred to as the „GDPR”, as well as the Act of 10 May 2018 on the Protection of Personal Data, hereinafter referred to as the „Act”, and other applicable provisions on personal data protection.
The Data Controller undertakes to maintain the security and confidentiality of the personal data obtained from you. All employees have been properly trained in the processing of personal data, and as the Data Controller we have implemented appropriate safeguards as well as technical and organisational measures to ensure the highest level of personal data protection. We have implemented personal data protection procedures and policies compliant with the GDPR and the Act, which ensure the lawfulness and reliability of data processing processes, as well as the enforceability of all rights you have as a data subject. In addition, where necessary, we cooperate with the supervisory authority in the Republic of Poland, namely the President of the Personal Data Protection Office.
This Privacy Policy sets out the principles for collecting, processing and using personal data, as well as the terms of using devices and other data originating from persons who have provided personal data for processing by the Data Controller.
II. LEGAL BASIS FOR PROCESSING
Your personal data are processed for the following purposes, based on the following provisions of the GDPR:
Purpose of processing:
Direct marketing and profiling (contact by telephone, e-mail, SMS/MMS)
Legal basis under the GDPR:
Article 6(1)(a) (consent of the data subject), in conjunction with Article 10 of the Act on Providing Services by Electronic Means and Article 172 of the Electronic Communications Law.
Storage period:
Until consent is withdrawn or an objection is raised.
Purpose of processing:
Sharing data with the Data Controller’s Partners and Contractors for their own direct marketing purposes.
Legal basis under the GDPR:
Article 6(1)(a) (consent of the data subject).
Storage period:
Until the data are made available to the Client, and subsequently for documentation purposes and for defence against claims, for no less than 3 years.
Purpose of processing:
Proper performance of the agreement, for example contact regarding a submitted inquiry or handling a contact form.
Legal basis under the GDPR:
Article 6(1)(b) (necessity for the performance of a contract).
Storage period:
For the time necessary to provide the service.
Purpose of processing:
Establishing, pursuing or defending against claims.
Legal basis under the GDPR:
Article 6(1)(f) (legitimate interest of the Data Controller).
Storage period:
For the limitation period for claims, for no less than 3 years.
Purpose of processing:
Fulfilling legal obligations, for example handling GDPR rights or storing accounting documentation.
Legal basis under the GDPR:
Article 6(1)(c) (legal obligation).
Storage period:
For the period required by law, for example tax law or GDPR provisions.
III. SCOPE OF DATA PROCESSING
Identification data: first name, surname.
Contact details: e-mail address, telephone number.
Transactional data: information about the consents you have granted, including the date, time and content of the consent, as well as the source from which the data were obtained.
IV. RECIPIENTS OF PERSONAL DATA
Your data may be transferred outside the EEA, which includes the EU, Norway, Liechtenstein and Iceland, in the manner specified by applicable regulations, namely:
a) on the basis of a European Commission decision confirming an adequate level of protection, for example in the third country to which we transfer the data, or
b) provided that appropriate safeguards are ensured, such as:
binding corporate rules, as defined in Article 47 of the GDPR;
standard data protection clauses adopted by the European Commission or the competent supervisory authority for personal data, Article 46(2)(c) or (d) of the GDPR;
an approved code of conduct, Article 46(2)(e) of the GDPR;
an approved certification mechanism, Article 46(2)(f) of the GDPR;
contractual clauses authorised by the supervisory authority, Article 46(3) of the GDPR;
as well as in cases necessary due to the legitimate interests of the Data Controller, provided that the requirements of Article 49(1), second subparagraph, of the GDPR are met.
The data obtained are not disclosed to third parties, except in specific situations where the recipients of such data are:
entities enabling data verification or identity identification;
entities operating ICT systems or providing us with ICT tools;
advertising agencies cooperating with the Data Controller and other entities intermediating in the sale of our services or the organisation of marketing campaigns;
subcontractors of the Data Controller who support us or will support us in providing telecommunications services or other services ordered by you, handling correspondence or customer service processes;
entities operating and maintaining our telecommunications network;
entities providing us with advisory, consulting, audit, legal, tax and accounting services, as well as research agencies acting on our behalf;
entities that commission marketing services from us and to whom we disclose data on the basis of your consent. After disclosure, the Client becomes a separate Data Controller;
entities affiliated with the Data Controller, meaning other entities with which the Data Controller cooperates for marketing purposes;
business partners of the Controller and their Clients, including SELECTIVV sp. z o.o. and others.
The Controller uses tools provided by Google Ireland Ltd, including Google Ads, Google Tag Manager, Google Analytics and Google DoubleClick, OneSignal, Inc., including OneSignal, Microsoft Clarity and Microsoft Advertising. As a rule, data processed as part of the use of these tools are processed on servers located within the EEA. However, the entities providing these tools may be required to transfer data to third countries if such an obligation is imposed on them by law or if it is necessary due to the nature of the services provided, such as SaaS or hosting. The scope of personal data transferred in this respect relates only to potential personal data contained in cookies. The legal basis for processing the personal data referred to in the previous sentence is indicated in point 5(d) and (e) of this Policy. The transfer of personal data to the United States takes place on the basis of the European Commission Decision of 10 July 2023 on the adequate level of protection provided by the EU-US Data Privacy Framework, Article 45(1) of the GDPR. Our personal data importers, namely Google LLC, Meta Platforms, Inc., OneSignal, Inc., Microsoft Clarity and Microsoft Advertising, which meet the criteria of the decision and participate in the Data Privacy Framework programme, are listed at: https://www.dataprivacyframework.gov/s/participant-search. Google Ireland Ltd and Meta Platforms Ireland Ltd may transfer data to third countries on the basis of the Standard Contractual Clauses adopted by these entities.
V. METHOD OF DATA COLLECTION
The Data Controller obtains information through:
a) your entry of data in advertising forms;
b) storing cookie files, so-called „cookies”, on end devices.
You are fully responsible for completing the data in the forms referred to above correctly and in accordance with the legal and factual situation.
Providing personal data is voluntary, but necessary for us to send commercial and marketing information and, in certain cases, is a condition for concluding an agreement with the Data Controller.
The consequence of your failure to provide personal data will be the inability to receive commercial and marketing information from us and the inability to continue performing the agreement with the Data Controller.
VI. DATA PROFILING
Your personal data may be processed in an automated manner, including profiling. Profiling is carried out for the purpose of:
Adapting offers and marketing content of the Data Controller and its partners, including advertisements on platforms such as Meta, Google and others, to your preferences and predicting your potential interest in the services of the Data Controller and its partners.
Selecting and segmenting data subjects who are most likely to respond to a given marketing campaign, in order to optimise and measure the effectiveness of marketing services.
VII. RIGHTS OF DATA SUBJECTS
In accordance with the GDPR, every person whose personal data we process as the Data Controller has the right to:
a) be informed about the processing of personal data, as referred to in Article 12 of the GDPR;
b) access their personal data, as referred to in Article 15 of the GDPR;
c) correct, supplement, update and rectify personal data, as referred to in Article 16 of the GDPR;
d) erase data, the right to be forgotten, as referred to in Article 17 of the GDPR;
e) restrict processing, as referred to in Article 18 of the GDPR;
f) data portability, as referred to in Article 20 of the GDPR;
g) object to the processing of personal data, as referred to in Article 21 of the GDPR;
h) withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal;
i) not be subject to profiling, as referred to in Article 22 in conjunction with Article 4(4) of the GDPR;
j) lodge a complaint with the supervisory authority, namely the President of the Personal Data Protection Office, address: ul. Stawki 2, 00-193 Warsaw, Poland, as referred to in Article 77 of the GDPR;
k) subject to the rules for exercising and implementing these rights arising from the provisions of the GDPR.
In each case, you may contact the Data Controller with questions and requests for clarification. The contact details are provided below.
VIII. FINAL PROVISIONS
Providing personal data is voluntary, but it is necessary for the provision of marketing services and for sharing data with the Data Controller’s partners.
Taking into account the fundamental principles of the GDPR, in particular the principle of purpose limitation, storage limitation and data minimisation, we process your personal data only for a period no longer than is necessary to achieve the purposes of processing and as permitted by law. Once the purpose of processing has been achieved, your personal data will be deleted, provided that the law allows it. Depending on the legal basis for processing your personal data, different data storage periods may apply.
In all matters, including matters concerning personal data, you may contact us in writing at the registered office address of the Data Controller, namely ul. Zwycięzców 2, 03-941 Warsaw, Poland, or electronically via e-mail at: dpo@fonia.app