Privacy Policy

The following Privacy Policy sets out the rules for storing and accessing data on Users’ Devices using the Service for the purpose of providing electronic services by the Administrator, as well as the rules for collecting and processing Users’ personal data that they have personally and voluntarily provided via tools available in the Service.

§1 Definitions

  • Service – the “inChange.pl” website operating at https://inchange.pl

  • External Service – websites of partners, service providers, or service recipients cooperating with the Administrator

  • Service/Data Administrator – The Service and Data Administrator (hereinafter referred to as the Administrator) is “inChange Katarzyna Żurek,” identified by tax identification number (NIP): 5542392482, providing electronic services via the Service

  • User – a natural person for whom the Administrator provides electronic services through the Service

  • Device – an electronic device with software through which the User gains access to the Service

  • Cookies – text data collected in the form of files placed on the User’s Device

  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

  • Personal Data – information about an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person

  • Processing – any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction

  • Restriction of Processing – marking of stored personal data to limit their future processing

  • Profiling – any form of automated processing of personal data involving the use of personal data to evaluate certain personal aspects of a natural person, in particular, to analyze or predict aspects concerning that natural person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements

  • Consent – the freely given, specific, informed, and unambiguous indication of the data subject’s wishes, by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them

  • Personal Data Breach – a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed

  • Pseudonymization – processing of personal data in such a way that they can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person

  • Anonymization – an irreversible process of modifying data that destroys or replaces “personal data,” making it impossible to identify or link a given record to a specific User or natural person

§2 Data Protection Officer

Based on Article 37 of the GDPR, the Administrator has not appointed a Data Protection Officer.

For matters related to data processing, including personal data, please contact the Administrator directly.

§3 Types of Cookies

  • Internal Cookies – files placed and read from the User’s Device by the Service’s IT system

  • External Cookies – files placed and read from the User’s Device by IT systems of External Services. The scripts of External Services that may place Cookies on the User’s Devices have been deliberately placed on the Service via scripts and services made available and installed in the Service

  • Session Cookies – files placed and read from the User’s Device by the Service during a single session of that Device. After the session ends, the files are deleted from the User’s Device

  • Persistent Cookies – files placed and read from the User’s Device by the Service until they are manually deleted. The files are not automatically deleted after the session ends unless the User’s Device settings are configured to delete Cookies at the end of the Device session

§4 Data Storage Security

The Administrator takes all possible technical measures to ensure the security of personal data voluntarily provided by Users. Access to personal data is limited and carried out in accordance with their purpose and processing objectives. The Administrator also ensures that all efforts are made to secure the stored data against loss by applying appropriate physical and organizational safeguards.

§5 Purposes for Using Cookies

  • Improving and facilitating access to the Service

  • Personalizing the Service for Users

  • Marketing, remarketing in external services

  • Conducting statistics (users, number of visits, device types, connection, etc.)

  • Providing multimedia services

§6 Purposes of Personal Data Processing

Personal data voluntarily provided by Users is processed for one of the following purposes:

  • Provision of electronic services:

    • Newsletter services (including sending advertising content with consent)

    • Sharing content from the Service on social networks or other websites

    • Communication between the Administrator and Users regarding the Service and data protection

    • Ensuring the legally justified interest of the Administrator

Automatically and anonymously collected User data is processed for one of the following purposes:

  • Conducting statistics

  • Ensuring the legally justified interest of the Administrator

§7 External Service Cookies

The Administrator uses JavaScript scripts and web components from partners that may place their own Cookies on the User’s Device. Users can decide on the permitted Cookies in their browser settings. Below is a list of partners or their services implemented in the Service that may place Cookies:

  • Multimedia Services

  • Newsletter Services: MailerLite

  • Statistics Services: Google Analytics

Services provided by third parties are beyond the Administrator’s control. These entities may change their terms of service, privacy policies, data processing purposes, and Cookie usage at any time.

Here’s the translation of the provided text:

§8 Types of Data Collected

The service collects data about users. Some data is collected automatically and anonymously, while some personal data is voluntarily provided by users when signing up for specific services offered by the service.

Automatically Collected Anonymous Data:

• IP Address

• Browser Type

• Screen Resolution

• Approximate Location

• Pages Visited on the Service

• Time Spent on a Specific Page of the Service

• Operating System Type

• Previous Page URL

• Referring URL

• Browser Language

• Internet Connection Speed

• Internet Service Provider

Data Collected When Signing Up for the Newsletter Service:

• First Name / Last Name / Nickname

• Email Address

• IP Address (collected automatically)

Some data (without identifying information) may be stored in cookies. Some data (without identifying information) may be passed to a statistical service provider.

§9 Access to Personal Data by Third Parties

As a rule, the only recipient of personal data provided by users is the Administrator. Data collected as part of the services provided is not shared or sold to third parties.

Access to data (usually based on a data processing agreement) may be granted to entities responsible for maintaining infrastructure and services necessary for running the service, such as:

• Hosting companies providing hosting or related services to the Administrator

• Companies providing the Newsletter service

• Service and IT support companies responsible for maintenance or IT infrastructure upkeep

Data Processing Delegation – Newsletter Service

To provide the Newsletter service, the Administrator uses a third-party service, Mailerlite. Data entered in the newsletter sign-up form is passed, stored, and processed by this external service provider.

Please note that the specified partner may modify the privacy policy without the Administrator’s consent.

Data Processing Delegation – Hosting, VPS, or Dedicated Server Services

To run the service, the Administrator uses an external hosting, VPS, or dedicated server service provider – SiteGround Spain S.L. All data collected and processed on the service is stored and processed within the infrastructure of the service provider located within the European Union. There is a possibility of access to data during service maintenance by the service provider’s staff. Access to this data is governed by the agreement between the Administrator and the service provider.

Data Processing Delegation – Website Service Management

To manage the service, the Administrator uses the external services of haps!. The staff of this entity has access to the data entered by users during account registration and editing and/or data related to the Newsletter service. Access to this data is governed by the agreement between the Administrator and the service provider.

§10 Method of Processing Personal Data

Personal Data Voluntarily Provided by Users:

• Personal data will not be transferred outside the European Union unless published due to individual user action (e.g., posting a comment or entry), making the data accessible to any visitor of the service.

• Personal data will not be used for automated decision-making (profiling).

• Personal data will not be sold to third parties.

Automatically Collected Anonymous Data (without personal data):

• Anonymous data (without personal data) may be transferred outside the European Union.

• Anonymous data (without personal data) will not be used for automated decision-making (profiling).

• Anonymous data (without personal data) will not be sold to third parties.

§11 Legal Grounds for Processing Personal Data

The service collects and processes user data based on:

• Regulation (EU) 2016/679 of the European Parliament and Council of April 27, 2016, regarding the protection of natural persons with regard to the processing of personal data and the free movement of such data, and the repeal of Directive 95/46/EC (General Data Protection Regulation)

• Article 6, section 1, letter a: the data subject has consented to the processing of their personal data for one or more specific purposes.

• Article 6, section 1, letter b: processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract.

• Article 6, section 1, letter f: processing is necessary for the purposes of the legitimate interests pursued by the administrator or a third party.

• Act of May 10, 2018, on the protection of personal data (Journal of Laws 2018, item 1000)

• Act of July 16, 2004, Telecommunications Law (Journal of Laws 2004, no. 171, item 1800)

• Act of February 4, 1994, on copyright and related rights (Journal of Laws 1994, no. 24, item 83)

§12 Data Retention Period

Personal Data Voluntarily Provided by Users:

• As a rule, the specified personal data is stored only for the period during which the service is provided by the Administrator. It is deleted or anonymized within 30 days of the end of the service (e.g., removal of registered user accounts, unsubscribe from the Newsletter, etc.).

• An exception applies if legally justified purposes for further processing of these data by the Administrator require it. In such cases, the Administrator will store the data for up to 3 years from the request for its deletion in the event of a breach or suspected breach of the service’s terms by the user.

Automatically Collected Anonymous Data:

• Anonymous statistical data, which does not constitute personal data, is stored by the Administrator to maintain the service statistics for an indefinite period.

§13 Users’ Rights Related to Personal Data Processing

Users have the following rights regarding their personal data:

• Right of access to personal data: Users have the right to obtain access to their personal data upon request to the Administrator.

• Right to rectify personal data: Users have the right to request that the Administrator promptly rectify inaccurate or incomplete personal data.

• Right to delete personal data: Users have the right to request that the Administrator promptly delete personal data. In the case of user accounts, deleting data means anonymizing data that allows identifying the user. The Administrator reserves the right to withhold data deletion in order to protect the legitimate interests of the Administrator (e.g., if the user violated the terms of service or the data was obtained through correspondence).

• In the case of the Newsletter service, the user can independently delete their personal data using the unsubscribe link in every email.

• Right to restrict processing of personal data: Users have the right to request the restriction of processing personal data in certain cases as specified in Article 18 of the GDPR.

• Right to data portability: Users have the right to request their personal data in a structured, commonly used, machine-readable format.

• Right to object to processing of personal data: Users have the right to object to the processing of their personal data in cases specified in Article 21 of the GDPR.

• Right to lodge a complaint: Users have the right to lodge a complaint with the supervisory authority responsible for data protection.

§14 Contact with the Administrator

The Administrator can be contacted in the following ways:

• Email: kontakt@inchange.pl

• Contact form: available at https://inchange.pl/kontakt/

§15 Service Requirements

Limiting the saving and access to cookies on the user’s device may cause some service functions to malfunction. The Administrator is not responsible for malfunctioning service functions if the user restricts the ability to save and read cookies in any way.

§16 External Links

The service may include links to external websites in articles, posts, user comments, or entries, with which the service owner is not affiliated. These links and the pages or files they point to may be harmful to your device or pose a security risk to your data. The Administrator is not responsible for the content outside the service.

§17 Changes to the Privacy Policy

The Administrator reserves the right to modify this Privacy Policy without notifying users about the application and use of anonymous data or cookies. The Administrator also reserves the right to modify this Privacy Policy regarding personal data processing, notifying users with accounts or subscribed to the newsletter via email within 7 days of any changes. Continued use of the services means acceptance of the changes made to the Privacy Policy. If a user does not agree with the changes, they must delete their account or unsubscribe from the Newsletter service.

Changes to the Privacy Policy will be published on this subpage of the service. The changes will take effect as soon as they are published.