1. General information
1. This policy applies to the Website operating under the url address: HTTPS://GRAYLABS.PL
2. The website operator and personal data administrator is: Graylabs Sp. z o.o.
Będzin 42-500, ul. Gzichowska 115, NIP 625 247 59 58, REGON 38770515
3. The operator’s e-mail contact address is: firstname.lastname@example.org
4. The Operator is the Administrator of your personal data in relation to the data provided voluntarily on the Website.
5. The website uses personal data for the following purposes:
- Newsletter service
- Running a comment system
- Online chat conversations
- Query handling by the form
- Implementation of ordered services
- Presentation of the offer or information:
6. The website gathers information about users and their behavior in the following ways:
1. Through data voluntarily entered in forms that are entered into the Operator’s systems.
2. By saving cookies in end devices (so-called “cookies”).
2. Selected methods of data protection used by the Operator
1. The places of logging in and entering personal data are protected in the transmission layer (SSL certificate). Thanks to this, personal data and login data entered on the website are coded on the user’s computer and can be read only on the target server.
2. The operator periodically changes its administrative passwords.
3. An important element of data protection is the regular update of all software used by the Operator to process personal data, which in particular means regular updates of programming components.
1. The website is hosted (technically maintained) on the operator’s server: home.pl
2. Registration details of the hosting company: H88 S.A. z siedzibą w Poznaniu, Franklina Roosevelta 22, 60-829 Poznań, wpisana do Krajowego Rejestru Sądowego przez Sąd Rejonowy Poznań – Nowe Miasto i Wilda w Poznaniu, Wydział VIII Gospodarczy Krajowego Rejestru Sądowego pod nr KRS 0000612359, REGON 364261632, NIP 7822622168, kapitał zakładowy 210.000,00 zł w pełni wpłacony.
4. Hosting company:
- uses measures to protect against data loss (e.g. disk arrays, regular backups),
- applies adequate measures to protect processing locations in the event of a fire (e.g. special fire extinguishing systems),
- applies adequate measures to protect processing systems in the event of a sudden power failure (e.g. dual power lines, aggregates, UPS voltage backup systems),
- applies physical security measures to access to data processing sites (e.g. access control, monitoring),
- applies measures to ensure appropriate environmental conditions for servers as elements of the data processing system (e.g. control of environmental conditions, specialized air-conditioning systems),
- applies organizational solutions to ensure the highest possible level of protection and confidentiality (training, internal regulations, password policies, etc.),
- appointed a Data Protection Officer.
5. The hosting company maintains server-level logs to ensure technical reliability. Registration may be subject to:
- resources specified by URL identifier (addresses of requested resources – pages, files),
- time of receipt of the inquiry,
- response time,
- name of the client station – identification carried out by the HTTP protocol,
- information about errors that occurred during the implementation of the HTTP transaction,
- URL address of the page previously visited by the user (referrer link) – if the Website was accessed via a link,
- information about the user’s browser,
- information about the IP address,
- diagnostic information related to the process of self-ordering services via recorders on the website,
- information related to the handling of electronic mail addressed to the Operator and sent by the Operator.
4. Your rights and additional information on how to use the data.
- In some situations, the Administrator has the right to transfer your personal data to other recipients, if it is necessary to perform the contract concluded with you or to fulfill the obligations incumbent on the Administrator. This applies to such groups of recipients:
- hosting company based on entrustment
- comment system operators
- operators of online chat solutions
- authorized employees and associates who use data to achieve the purpose of the site
- companies providing marketing services to the Administrator
2. Your personal data processed by the Administrator no longer than necessary to perform the related activities specified in separate regulations (e.g. on accounting). With regard to marketing data, the data will not be processed for more than 3 years.
3. You have the right to request from the Administrator:
- access to personal data concerning you,
- correcting them,
- processing restrictions,
- and data transfer.
4. You have the right to object to the processing indicated in point 3.3 c) to the processing of personal data for the purpose of exercising legitimate interests pursued by the Administrator, including profiling, however, the right to object cannot be exercised if there are valid legitimate grounds for the processing of interests, rights and freedoms overriding you, in particular the determination, exercise or defense of claims.
5. The Administrator’s actions may be appealed to the President of the Office for Personal Data Protection, ul. Stawki 2, 00-193 Warsaw.
6. Providing personal data is voluntary, but necessary to operate the Website.
7. In relation to you, actions may be taken involving automated decision making, including profiling to provide services under the concluded contract and for direct marketing by the Administrator.
8. Personal data is not transferred from third countries within the meaning of the provisions on the protection of personal data. This means that we do not send them outside the EU.
5. Information on forms
1. The website collects information provided voluntarily by the user, including personal data, if they are provided.
2. The website may save information about connection parameters (time, IP address).
3. In some cases, the website may save information that makes it easier to link data in the form to the email address of the user completing the form. In this case, the user’s email address appears inside the url of the page containing the form.
4. The data provided in the form are processed for the purpose resulting from the function of a specific form, e.g. to process the service request or business contact, service registration, etc. Each time the context and description of the form clearly indicates what it is used for.
6. Administrator logs
1. Information on user behavior on the website may be subject to login. These data are used to administer the site.
7. Important marketing techniques
2. The operator uses remarketing techniques that allow adverts to be adapted to the user’s behavior on the website, which may give the illusion that the user’s personal data is used to track him, but in practice no personal data from the operator to the advertising operators is transferred. The technological condition for such activities is cookies enabled.
4. The Operator applies a solution that automates the operation of the Website in relation to users, e.g. that can send an email to the user after visiting a specific subpage, provided that he has agreed to receive commercial correspondence from the Operator.
8. Information about cookies
2. Cookie files (so-called “cookies”) are IT data, in particular text files, which are stored on the Website User’s end device and are intended for using the Website’s pages. Cookies usually contain the name of the website from which they originate, their storage time on the end device and a unique number.
3. The entity placing cookies on the Website User’s end device and accessing them is the Website operator.
4. Cookies are used for the following purposes:
a) maintaining the Website user’s session (after logging in), thanks to which the user does not have to re-enter the login and password on each subpage of the Website;
b) achieving the objectives set out above in the section ‘Important marketing techniques’;
5. The Website uses two basic types of cookies: “session” cookies and “persistent” cookies. Session cookies are temporary files that are stored on the User’s end device until logging out, leaving the website or turning off the software (web browser). Persistent cookies are stored on the User’s end device for the time specified in the cookie parameters or until they are deleted by the User.
6. Software for browsing websites (web browser) usually by default allows storing cookies on the User’s end device. Website Users can change the settings in this area. The web browser allows you to delete cookies. It is also possible to automatically block cookies. Detailed information on this subject is provided in the help or documentation of the web browser.
8. Cookies placed on the Website User’s end device may also be used by entities cooperating with the Website operator, in particular the following companies: Google (Google Inc. based in the USA), Facebook (Facebook Inc. based in the USA), Twitter (Twitter Inc. with headquarters in the USA).
9. Managing cookie files – how to give and withdraw consent in practice?
1. If the user does not want to receive cookies, he can change the browser settings. We reserve that disabling cookies necessary for authentication processes, security, maintaining user preferences may make it difficult, and in extreme cases may prevent the use of websites
2. To manage cookie settings, select the web browser you use from the list below and follow the instructions: