Privacy Policy

1. general information

  1. This policy applies to the Website, operating at the url: gepa.pl
  2. The operator of the service and the administrator of personal data is: GEPA - Ewa Musik ul. Stanisława Chudoby 95L, 03-287 Warszawa
  3. Contact e-mail address of the operator: [email protected]
  4. The Operator is the Administrator of your personal data with regard to the data you voluntarily provide on the Website.
  5. The Service uses personal data for the following purposes:
    • Operation of the newsletter
    • Handling of enquiries via the form
    • Provision of the services ordered
    • Presentation of an offer or information
  6. The Service performs functions to obtain information about users and their behaviour in the following ways:
    1. Through the data voluntarily entered in the forms, which are entered into the Operator's systems.
    2. By storing cookies (so-called "cookies") on terminal equipment.

2. Selected data protection methods applied by the Operator

  1. The login and entry points for personal data are protected in the transmission layer (SSL certificate). This ensures that the personal and login data entered on the website are encrypted on the user's computer and can only be read on the target server.
  2. The personal data stored in the database are encrypted in such a way that only those holding the Operator's key can read them. In this way, the data is protected in case the database is stolen from the server.
  3. User passwords are stored in hashed form. The hash function works unidirectionally - it is not possible to reverse its operation, which is now the modern standard for storing user passwords.
  4. The Service uses two-factor authentication, which is an additional form of protection for logging into the Service.
  5. The operator periodically changes its administrative passwords.
  6. The Operator shall make regular backups for data protection purposes.
  7. An important element of data protection is the regular updating of all software used by the Operator to process personal data, which in particular means regular updates of programming components.

3. hosting

  1. The service is hosted (technically maintained) on the server of the operator: cyberFolks.pl

4. your rights and further information on how your data will be used

  1. In certain situations, the Administrator has the right to transfer your personal data to other recipients if this is necessary for the performance of a contract concluded with you or for the fulfilment of obligations incumbent on the Administrator. This applies to such groups of recipients:
    • couriers
    • postal operators
    • payment operators
    • operators of online chat solutions
    • authorised employees and associates who use the data to fulfil the purpose of the site
    • companies providing marketing services to the Administrator
  2. Your personal data will be processed by the Administrator no longer than it is necessary for the performance of the related activities specified in separate regulations (e.g. on accounting). With regard to marketing data, the data will not be processed for longer than 3 years.
  3. You have the right to request from the Administrator:
    • access to personal data concerning you,
    • their rectification,
    • deletions,
    • to restrict processing,
    • and data portability.
  4. You have the right to object, with regard to the processing indicated under 3.3 c), to the processing of personal data for the purposes of pursuing the legitimate interests pursued by the Controller, including profiling, whereby the right to object will not be exercisable where there are valid legitimate grounds for the processing which override your interests, rights and freedoms, in particular the establishment, assertion or defence of claims.
  5. The Administrator's actions may be complained about to the President of the Office for Personal Data Protection, ul. Stawki 2, 00-193 Warsaw.
  6. The provision of personal data is voluntary, but necessary to operate the Website.
  7. Activities involving automated decision-making, including profiling, may be undertaken in relation to you for the purpose of providing services under the contract concluded and for the purpose of direct marketing by the Administrator.
  8. Personal data is not transferred from third countries as defined by data protection legislation. This means that we do not send them outside the European Union.

5. information on the forms

  1. The Service collects information provided voluntarily by the user, including personal data where provided.
  2. The service can save information about the connection parameters (time stamp, IP address).
  3. The website may, in some cases, save information that makes it easier to associate the data in the form with the e-mail address of the user filling in the form. In such a case the user's e-mail address shall appear inside the url of the page containing the form.
  4. Data provided in the form are processed for the purpose resulting from the function of a particular form, e.g. for the purpose of processing a service request or business contact, service registration, etc. Each time the context and description of a form informs in a clear way what it is used for.

6 Administrator logs

  1. Information on user behaviour on the website may be subject to logging. This data is used for the administration of the website.

7 Important marketing techniques

  1. The operator uses statistical analysis of the website traffic via Google Analytics (Google Inc., USA). The operator does not transmit personal data to the operator of this service, only anonymised information. The service is based on the use of cookies on the user's terminal device. With regard to the information on user preferences collected by the Google advertising network, the user can view and edit the information resulting from the cookies using the following tool: https://www.google.com/ads/preferences/.
  2. The operator uses the Facebook pixel. This technology allows Facebook (Facebook Inc., USA) to know that a person registered with it is using the Website. The Operator does not transmit any additional personal data to Facebook. The service is based on the use of cookies on the user's terminal device.

8 Information on cookies

  1. The website uses cookies.
  2. Cookies (so-called "cookies") are IT data, in particular text files, which are stored in the Service User's terminal equipment and are intended for use on the Service's websites. Cookies usually contain the name of the website from which they come, the time of storing them on the terminal equipment and a unique number.
  3. The operator of the Website is the entity placing cookies on the Website User's terminal equipment and accessing them.
  4. Cookies are used for the following purposes:
    1. maintaining a session of the Service user (after logging in), thanks to which the user does not have to re-enter login and password on each subpage of the Service;
    2. to achieve the objectives set out above under "Essential marketing techniques";
  5. There are two main types of cookies used on the Website: "session" (session cookies) and "permanent" (persistent cookies). Session" cookies are temporary files that are stored in the final device of the User until logging out, leaving the website or switching off software (web browser). "Permanent" cookies are stored in the User's terminal equipment for the time specified in the parameters of cookies or until they are deleted by the User.
  6. Web browsing software (internet browser) usually allows the storage of cookies in the User's terminal equipment by default. Users of the Website may change their settings in this respect. Internet browser allows to delete cookies. It is also possible to block cookies automatically. Detailed information on this subject is contained in the help or documentation of the Internet browser.
  7. Restrictions on the use of cookies may affect some of the functionality available on the Website.
  8. Cookies placed in the Service User's end device may also be used by entities cooperating with the Service Operator, in particular these companies: Google (Google Inc. based in the USA), Facebook (Facebook Inc. based in the USA), Twitter (Twitter Inc. based in the USA).

9. cookie management - how to give and withdraw consent in practice?

  1. If you do not wish to receive cookies, you can change your browser settings. We stipulate that disabling cookies necessary for authentication processes, security, maintenance of user preferences may hinder, and in extreme cases may make it impossible to use websites
  2. To manage your cookie settings, select the web browser you are using from the list below and follow the instructions:

    Mobile devices:

en_GBEnglish