Privacy Policy

Your privacy is of utmost importance to us. We make every effort to ensure that your personal data is processed in a fair, transparent manner and in compliance with applicable laws, in particular Regulation (EU) (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: GDPR). The personal data provided to us is used only to the extent necessary to achieve clearly defined and lawful processing purposes.  
     
  1. Definitions
    1. Data Controller – POLARYS POLSKA sp. z o.o., with its registered office in Kraków, 31-511 Kraków, ul. Rakowicka 1/20-21, entered in the National Court Register (KRS) maintained by the District Court for Kraków-Śródmieście in Kraków, 11th Commercial Division, under KRS number: 0000680468, Tax Identification Number (NIP): 675-15-95-669. Contact phone numbers for POLARYS POLSKA sp. z o.o.: (+48) 789 189 061.
    2. Personal data — any information relating to an identified or identifiable natural person based on one or more specific factors that define the person’s physical, physiological, genetic, mental, economic, cultural, or social identity, including an image, a voice recording, contact information, location data, information contained in correspondence, and information collected through recording devices or other similar technologies.
    3. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
    4. Data Subject – a natural person to whom the personal data processed by the Controller relates, e.g., a person using the Controller’s services, providing services to the Controller, or submitting an inquiry to the Controller in writing, by traditional mail, or electronically.
     
  2. Legal Basis for the Processing of Personal Data
    1. POLARYS POLSKA sp. z o.o., acting as the Data Controller, processes your personal data exclusively when at least one of the following conditions is met:
      1. the data subject has consented to the processing of their personal data for one or more specific purposes;
      2. processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract;
      3. the processing is necessary to comply with a legal obligation to which the Controller is subject;
      4. the processing is necessary to protect the vital interests of the data subject or another natural person;
      5. processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
       
  3. Contacting the Data Controller
    1. You can contact the Data Controller via email at dpo.pl@polarysgroup.com or by mail at: POLARYS POLSKA sp. z o.o., ul. Rakowicka 1/20-21, 31-511 Kraków. You may also contact the Data Controller by phone at the number provided in Section 1.1.
     
  4. Security of Personal Data
    1. To ensure the integrity and confidentiality of data, the Controller has implemented procedures that restrict access to personal data solely to authorized persons and only to the extent necessary to perform the duties entrusted to them. The Controller employs both organizational and technical measures to ensure that all operations involving personal data are logged and performed only by authorized persons. The Controller takes all necessary steps to ensure that its subcontractors and other partners with whom it collaborates implement appropriate security measures when processing personal data on its behalf. The controller regularly assesses the risks associated with the processing of personal data and monitors the effectiveness of the security measures in place. If necessary, the controller implements additional measures to strengthen data protection.
     
  5. Purposes of Personal Data Processing
    1.  
      1. Correspondence (email, postal mail)
      2. If contact with the Controller is made electronically or by mail, and the matter is not related to a concluded contract or the services provided, the personal data contained in such correspondence is processed solely for the purpose of communicating and resolving the reported matter. The legal basis for processing is the Controller’s legitimate interest (Article 6(1)(f) of the GDPR), which consists of handling incoming correspondence as part of its business operations. The Controller processes only the data necessary to handle the matter, and all correspondence is stored in a manner that ensures data security and is made available only to authorized persons.  
      3. Contact by Phone
      4. If you contact the Controller by phone regarding matters unrelated to a concluded contract or services provided, the Controller may request that you provide personal data only to the extent necessary to handle your inquiry. The legal basis for processing is the Controller’s legitimate interest (Article 6(1)(f) of the GDPR), which consists in effectively resolving the reported matter.
      5. Contact Forms
      6. The Controller provides the option to contact it via electronic forms available on its websites. Providing personal data is required only to the extent necessary to respond to and handle the inquiry. The data is processed to identify the sender and properly address the inquiry. For inquiries related to a concluded contract or services provided, the legal basis for processing is the necessity for the performance of the contract (Article 6(1)(b) of the GDPR). For matters not related to a contract, the legal basis is the Controller’s legitimate interest (Article 6(1)(f) of the GDPR), which consists of responding to the inquiry.  
      7. Data Processing in Connection with the Provision of Services or the Performance of Other Contracts
      8. Data collected for the purpose of entering into or performing a contract is processed only to the extent necessary to carry out these activities. The Controller provides the data subject with detailed information about the processing of their personal data at the time the contract is concluded or when the data is collected; in the case of actions taken by the Controller at the data subject’s request, this information is provided prior to the conclusion of the contract. The legal basis for processing is the necessity to perform a contract to which the data subject is a party, or to take action at the request of the data subject (Article 6(1)(b) of the GDPR).  
      9. Recruitment
      10. In recruitment processes, the Controller processes candidates’ personal data solely to the extent specified by law, including the Labor Code. For candidates who are not Polish citizens, the legality of their stay and eligibility for employment are verified (Article 6(1)(c) of the GDPR). If a position requires a certificate of no criminal record or proof of specific psychophysical fitness, data processing is carried out in accordance with applicable law and, in the case of sensitive data, pursuant to Article 9(2)(h) of the GDPR. Candidates may voluntarily provide additional information beyond the required scope, which will be possible only after they have given their consent (Article 6(1)(a) of the GDPR; Article 9(2)(a) of the GDPR for special categories of data). Data not relevant to the recruitment process will not be used or processed. Detailed information on the processing of personal data in recruitment processes conducted by the Controller can be found in the “Careers” tab.  
      11. The Controller’s Legal Obligations
      12. The Controller also processes personal data to fulfill the legal obligations incumbent upon the Controller, in particular obligations arising from tax and accounting laws, obligations related to combating fraud and irregularities under anti-corruption regulations, as well as preventing fraud and conflicts of interest in business processes or other provisions arising from the specific nature of the contract being performed.  
  6. Data Recipients
    1. In connection with conducting business activities that require the processing of personal data, your personal data may be disclosed by the Controller to entities with which it cooperates (recipients), including entities within the SILAMIR Capital Group (based on agreements for joint data control, service provision, and cooperation), entities involved in procurement processes, entities providing IT, accounting, receivables management, mail and package delivery, occupational health and safety, consulting, legal, archiving, and debt collection services. Personal data may be disclosed by the Controller to entities with which it cooperates if this is necessary to achieve the processing purposes referred to in Section 5, based on the agreements entered into. The Controller reserves the right to disclose data to relevant authorities or other entities that request such information, solely on the basis of a valid legal basis and in accordance with applicable law.
     
  7. Transfer of Data to Third Countries
    1. As a general rule, the Data Controller does not transfer personal data outside the European Economic Area (EEA). In situations where such a transfer proves necessary, it takes place only after ensuring an adequate level of data protection, in accordance with applicable law. This may include cooperation with entities operating in countries recognized by the European Commission as providing an adequate level of data protection, the use of standard contractual clauses adopted by the European Commission, the use of binding corporate rules approved by the relevant supervisory authorities, and, in the case of data transfers to the United States — cooperation with entities certified under the EU-U.S. Data Privacy Framework, which are recognized as providing an adequate level of data protection. The controller informs the data subject of the intention to transfer data outside the EEA at the time of collection or, if the data was not obtained directly from the data subject, within the timeframe specified in Article 14(3) of the GDPR.
     
  8. Scope of Processed Data
    1. The scope of personal data processed by the Controller depends on the scope and subject matter of the cooperation as well as the individual’s role and may include data such as:
      1. first and last name,
      2. job title,
      3. role,
      4. work phone number,
      5. work email address,
      6. contact information,
      7. home address,
      8. company name and mailing address,
      9. date and place of birth,
      10. information about licenses and qualifications held.
       
  9. Period of Personal Data Processing
    1. The duration of data processing by the Controller depends on the type of services provided and the purpose of processing, and may also result from legal obligations forming the basis for processing. In the case of data processed on the basis of the Controller’s legitimate interest—e.g., for security reasons—such data is processed for the period necessary to fulfill that interest or until a valid objection is raised. Data processed on the basis of consent remains in circulation until such consent is withdrawn, while data processed in connection with the conclusion and performance of a contract is retained until the contract is terminated. The processing period may be extended if it is necessary to establish or pursue claims, and upon its expiration, the data is irreversibly deleted or anonymized.
     
  10. Rights Related to the Processing of Personal Data
    1. In connection with the processing of personal data, you have the following rights:
      1. the right to access your personal data,
      2. the right to rectify the personal data provided,
      3. the right to erasure,
      4. the right to restrict the processing of personal data,
      5. the right to data portability,
      6. the right to object to processing,
      7. the right to access the key agreements between joint controllers,
      8. the right to obtain information about the results of the balancing of interests test, if the processing is based on the Controller’s legitimate interest.
        You also have the right to file a complaint with the supervisory authority—the President of the Personal Data Protection Office. If data is processed based on consent, you may withdraw your consent at any time, without affecting the lawfulness of the processing carried out prior to its withdrawal.
     
  11. Submitting Requests Related to the Exercise of Rights
    1. Requests regarding the exercise of data subjects’ rights, including requests to delete personal data, may be submitted in writing to the Controller’s mailing address: POLARYS POLSKA sp. z o.o., ul. Rakowicka 1/20-21, 31-511 Kraków, marked “Personal Data Protection,” or by email to: dpo.pl@polarysgroup.com If there are difficulties in identifying the person submitting the request, the Data Controller may ask for additional information necessary to verify the person’s identity; failure to provide such information may prevent the request from being fulfilled. The response will be provided in the same form in which the request was received by the Controller, unless the person submitting the request has expressed a preference for a different form of contact; if a written response is not possible, the Controller may provide it electronically. Information regarding the submitted request and the person making it is retained for the purpose of demonstrating compliance with regulations and for establishing, pursuing, or defending any potential claims.
     
  12. Automated Decision-Making and Profiling
    1. When processing your personal data, we do not rely on automated processing to make specific decisions that would have legal effects on you or significantly affect you. Profiling may be used solely for the purpose of direct marketing of products and services offered by the Controller and involves tailoring the content of communications to your interests and preferences.
     
  13. Cookies
    1. By visiting our website, you may consent to the use of cookie technology, which enables our website to function properly and allows us to analyze information about how it is used. We process this data to improve the quality of our website, tailor content to visitors’ interests, and continuously enhance its performance. Some cookies also allow us to carry out marketing activities related to our products and services on our website. The legal basis for the use of cookies and similar technologies is your consent, unless the use of cookies is necessary for the operation of our website, in which case we rely, as appropriate, on a legal provision (Article 173(3)(2) of the Telecommunications Act) and our legitimate interest (Article 6(1)(f) of the GDPR).