This Privacy Policy describes how Xiwaze Demube, with its registered office at Słowiańska 8B, Koszalin, Poland ("we", "us", "our"), collects, uses, stores, and protects personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (the "General Data Protection Regulation" or "GDPR"), as supplemented by the Polish Act of 10 May 2018 on the Protection of Personal Data (Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych, Journal of Laws 2018, item 1000, as amended). By using this website, you acknowledge that you have read this Privacy Policy.
The controller of personal data collected through this website is Xiwaze Demube, Słowiańska 8B, Koszalin, Poland. You may contact us regarding data protection matters at: [email protected] or by telephone at +48 509 780 850. All requests relating to personal data will be handled by the person responsible for data protection within our organisation.
We collect the following categories of personal data through this website: (a) identification data, including your full name; (b) contact data, including your email address and telephone number; (c) communication content, including the subject and body of any message you submit through our contact form; (d) technical data, including your IP address, browser type and version, operating system, referring URL, and pages visited, which are collected automatically through standard web server logs and analytics tools; (e) cookie-related data as described in our Cookie Policy. We do not knowingly collect personal data from persons under the age of 16.
We process your personal data for the following purposes and on the following legal bases under Article 6 GDPR: (a) to respond to your enquiry submitted through the contact form, on the basis of Article 6(1)(b) GDPR (processing necessary for the performance of steps taken at the request of the data subject prior to entering into a contract); (b) to maintain records of communications for business administration purposes, on the basis of Article 6(1)(f) GDPR (legitimate interests pursued by the controller); (c) to analyse website usage through aggregated technical data for the purpose of improving the website, on the basis of Article 6(1)(f) GDPR; (d) to comply with applicable legal obligations, on the basis of Article 6(1)(c) GDPR. Where we rely on legitimate interests as a legal basis, we have assessed that our interests are not overridden by your interests, rights, or freedoms.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, unless a longer retention period is required or permitted by law. Contact form submissions are retained for a period of 24 months from the date of submission, after which they are securely deleted. Technical log data is retained for a period of 12 months. Data retained for compliance with legal obligations is held for the period required by the applicable law. When personal data is no longer required, we take reasonable steps to ensure it is securely erased or anonymised.
We do not sell, rent, or trade personal data to third parties. We may share personal data with the following categories of recipients where necessary: (a) email service providers who process email on our behalf, acting as data processors under a data processing agreement; (b) web hosting providers who store data on servers located within the European Economic Area; (c) competent public authorities, courts, or law enforcement bodies where we are required to disclose data by applicable law or a binding legal order. Any third-party processors are required to process data only in accordance with our instructions and in compliance with the GDPR.
We endeavour to store and process personal data within the European Economic Area. Where any transfer of personal data to a country outside the EEA is necessary, we will ensure that such transfer is subject to appropriate safeguards as required by Chapter V of the GDPR, including the use of standard contractual clauses approved by the European Commission, binding corporate rules, or reliance on an adequacy decision issued by the European Commission in respect of the recipient country.
Subject to the conditions and limitations set out in the GDPR and applicable Polish data protection law, you have the following rights in relation to your personal data: (a) the right of access under Article 15 GDPR, to obtain confirmation of whether we process your personal data and to receive a copy of that data; (b) the right to rectification under Article 16 GDPR, to request correction of inaccurate or incomplete personal data; (c) the right to erasure under Article 17 GDPR, to request deletion of your personal data in certain circumstances; (d) the right to restriction of processing under Article 18 GDPR; (e) the right to data portability under Article 20 GDPR, where processing is based on consent or contract and is carried out by automated means; (f) the right to object under Article 21 GDPR, to processing based on legitimate interests; (g) the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing prior to withdrawal. To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month of receipt, which may be extended by a further two months in complex cases.
If you consider that our processing of your personal data infringes the GDPR or applicable Polish data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, Poland, website: uodo.gov.pl. You may also lodge a complaint with the supervisory authority of the EU Member State in which you reside, work, or where the alleged infringement occurred.
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include the use of HTTPS encryption for data transmission, access controls limiting data access to authorised personnel, and regular review of our data security practices. No method of transmission over the internet or electronic storage is entirely secure; however, we take all reasonable precautions to protect the personal data we hold.
We do not engage in automated decision-making or profiling within the meaning of Article 22 GDPR that would produce legal effects concerning you or similarly significantly affect you.
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or for other operational reasons. The updated policy will be published on this page with a revised "Last Updated" date. We encourage you to review this Privacy Policy periodically. Continued use of this website following the publication of changes constitutes your acknowledgement of the updated policy.