Privacy policy
In order to fulfil the obligations imposed on personal data controllers under Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation, hereinafter "RODO" (GDPR)), we hereby inform you of the following matters.
I. General provisions
This privacy policy governs the rules for the processing of personal data of persons using the services offered via the website https://harta.agency or https://harta.com.pl (hereinafter: the Website).
The owner of the website and the Controller of the personal data processed via the Website is HARTA ONE sp. z o.o. with its registered office in Gorzów Wielkopolski, Plac Słoneczny 14/2, 66-400 Gorzów Wielkopolski, entered in the register of entrepreneurs of the Krajowy Rejestr Sądowy (National Court Register) kept by the Sąd Rejonowy Szczecin-Centrum w Szczecinie, XIII Wydział Gospodarczy KRS, under KRS number 0001247989, NIP 8522734969, share capital 5 000,00 zł (hereinafter: the Controller).
The Controller can be contacted by e-mail: kontakt@harta.agency and in writing, at the Controller's address: Plac Słoneczny 14/2, 66-400 Gorzów Wielkopolski.
II. Purposes and legal bases for the processing of personal data
The Controller processes your personal data for one or more of the following purposes:
- Responding to enquiries - in order to answer your enquiries, including those sent via the contact form (Article 6(1)(f) RODO).
- Newsletter - in order to send a newsletter containing offers, promotions, events and educational materials related to e-commerce (Article 6(1)(f) in conjunction with recital 47 of the preamble to RODO).
- Promotion of services - in order to pursue the Controller's legitimate interests, such as promoting its services (Article 6(1)(f) in conjunction with recital 47 of the preamble to RODO).
- Compliance with legal obligations - including issuing an invoice or a bill and retaining documentation for reporting and accounting purposes (Article 6(1)(c) RODO).
- Performance of a contract - to which you are a party as a natural person, or taking steps at your request prior to entering into it, in particular a contract for marketing services (Article 6(1)(b) RODO).
- Contact under a contract - in connection with the performance of a contract concluded by the Controller with your employer, your principal or the legal person you represent (Article 6(1)(f) RODO).
- Consent - if you have given the Controller your voluntary consent to the processing of data for any of the above purposes (Article 6(1)(a) RODO).
III. Requirements regarding the provision of personal data
Where your data is obtained for the purposes of:
- fulfilling a statutory obligation (e.g. an accounting one) - providing the data is a statutory requirement;
- performing a contract - providing the data is voluntary, but necessary for its performance, e.g. issuing invoices and settling payments;
- performing a contract with your employer, your principal or the legal person you represent - providing the data is voluntary, but necessary to ensure proper contact with the contracting party;
- responding to your enquiries - providing the data is voluntary, but necessary in order to reply.
IV. Recipients of personal data
The recipients of your personal data may be:
- the Controller, as well as its representatives, employees, associates and advisers;
- entities cooperating with the Controller, in particular those personally connected with it;
- entities providing services to the Controller (including accounting and IT services);
- entities supporting the Controller in the area of promotional, marketing and analytical services.
- the payment operator Stripe (Stripe Payments Europe Ltd.) - for processing online payments for orders placed on the website, including billing details provided at payment;
- the invoicing system provider (Fakturownia sp. z o.o.) - for issuing and sending invoices.
- In connection with the use of Stripe and of Google, Meta and Microsoft tools, data may be transferred outside the European Economic Area, in particular to the USA - on the basis of a European Commission adequacy decision (EU-U.S. Data Privacy Framework) or standard contractual clauses (Article 46 GDPR).
V. Expected period of processing of personal data
Your personal data will be stored until:
- the fulfilment of the legal obligation is completed - where the basis for processing is Article 6(1)(c) RODO;
- the claims arising from the contract concluded and performed become time-barred - where the basis is Article 6(1)(b) RODO;
- consent is withdrawn - where the basis is Article 6(1)(a) RODO;
- an objection is raised - where the basis is the Controller's legitimate interest (Article 6(1)(f) RODO).
- cancellation and deletion of data of unpaid orders (interrupted payments) - the order is cancelled automatically after 30 days and its data deleted after 12 months; data of completed orders and accounting documents are kept for the period required by tax and accounting regulations.
VI. Your rights related to the processing of data
You have the right to request access to your personal data, its rectification, erasure or restriction of processing, as well as the right to data portability.
If the processing is based on consent, you have the right to withdraw it at any time, without affecting the lawfulness of the processing carried out before the withdrawal.
If the basis for the processing is the Controller's legitimate interest, you have the right to object to the processing.
You have the right to lodge a complaint with the supervisory authority, which in Poland is the Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office) (ul. Stawki 2, Warszawa).
VII. Data safeguards applied by the Controller
In order to protect your personal data, the Controller applies, among others:
- an internal information flow control policy, based on the principle of limited trust towards third parties and on minimising the transfer of confidential data by electronic means;
- data protection systems within IT systems, ensuring, among others, that third parties have no access to the content and that complex, strong passwords are used.
- encryption of the data of orders placed on the website - the data is stored in encrypted form, and the encryption key is kept outside the database and its backups.
VIII. Automated processing of personal data
The Controller does not make decisions concerning you that are based solely on automated processing of personal data and that would produce legal effects or similarly significantly affect you. The Controller does, however, use analytics and advertising tools (including Facebook Pixel) which, based on cookies, may profile the content and ads displayed to groups of users with similar characteristics (e.g. age, location, browsing history).
The Controller may, however, use the cookies stored on your devices for analytical and statistical purposes. The detailed rules are described in the Cookie policy.