Privacy Policy
This Cookie Policy sets out the rules for storing and accessing data on the Devices of Users who use the Website for the purpose of electronic services provided by the Administrator, as well as the rules for collecting and processing Users’ personal data that they have provided personally and voluntarily using the tools available on the Website.
This Privacy Policy is an integral part of the Website Terms and Conditions, which set out the rules, rights and obligations of Users using the Website.
This English version is provided for information purposes. In the event of any discrepancy, the Polish version prevails.
§1 Definitions
- Website – the “zmbcapital.pl” website available at https://zmbcapital.pl
- External website – websites of partners, service providers or customers cooperating with the Administrator
- Website / Data Administrator – the Administrator of the Website and the Data Controller (hereinafter the Administrator) is “ZMB Capital Sp. z o.o.”, with its registered address at ul. Jelenica 72, 43-450 Ustroń, Poland, tax identification number (NIP): 5482689349, providing electronic services via the Website
- User – a natural person to whom the Administrator provides electronic services via the Website
- Device – an electronic device with software through which the User accesses the Website
- Cookies – text data collected in the form of files placed on the User’s Device
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Personal data – any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
- Processing – any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction
- Restriction of processing – the marking of stored personal data with the aim of limiting their processing in the future
- Profiling – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements
- Consent – any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her
- Personal data breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed
- Pseudonymisation – the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person
- Anonymisation – an irreversible data operation that destroys / overwrites “personal data”, making it impossible to identify or link a given record to a specific user or natural person
§2 Data Protection Officer
Pursuant to Article 37 of the GDPR, the Administrator has not appointed a Data Protection Officer.
In matters concerning data processing, including personal data, please contact the Administrator directly.
§3 Types of cookies
- First-party cookies – files placed on and read from the User’s Device by the Website’s IT system
- Third-party cookies – files placed on and read from the User’s Device by the IT systems of External websites. Scripts of External websites that may place Cookies on Users’ Devices have been deliberately embedded in the Website through scripts and services made available and installed on the Website
- Session cookies – files placed on and read from the User’s Device by the Website during a single session of a given Device. After the session ends, the files are deleted from the User’s Device
- Persistent cookies – files placed on and read from the User’s Device by the Website until they are manually deleted. The files are not deleted automatically after the Device session ends, unless the User’s Device is configured to delete Cookies at the end of the session
§4 Security of data storage
- Cookie storage and reading mechanisms – the mechanisms for storing, reading and exchanging data between Cookies saved on the User’s Device and the Website are implemented through built-in web browser mechanisms and do not allow other data to be retrieved from the User’s Device or data from other websites visited by the User, including personal data or confidential information. Transferring viruses, Trojan horses or other worms to the User’s Device is also practically impossible.
- First-party cookies – the Cookies used by the Administrator are safe for Users’ Devices and do not contain scripts, content or information that could threaten the security of personal data or of the Device used by the User.
- Third-party cookies – the Administrator takes all possible steps to verify and select the Website’s partners with regard to Users’ security. The Administrator chooses well-known, large partners enjoying global public trust. However, the Administrator does not have full control over the content of Cookies originating from external partners. To the extent permitted by law, the Administrator is not responsible for the security of Cookies, their content or their licence-compliant use by Scripts installed on the Website originating from External websites. The list of partners is provided later in this Privacy Policy.
- Cookie control
- The User may at any time change the settings for saving, deleting and accessing data stored in Cookies by any website.
- Information on how to disable Cookies is available in the settings and help pages of the most popular browsers: Chrome, Opera, Firefox, Edge, Safari.
- The User may at any time delete all Cookies saved so far using the tools of the Device through which the User uses the Website’s services.
- Risks on the User’s side – the Administrator applies all possible technical measures to ensure the security of data stored in Cookies. Please note, however, that the security of this data depends on both parties, including the User’s actions. The Administrator is not responsible for the interception of this data, impersonation of the User’s session or its deletion as a result of the User’s conscious or unconscious actions, viruses, Trojan horses and other spyware with which the User’s Device is or has been infected. To protect themselves against these threats, Users should follow the recommendations for safe use of the internet.
- Storage of personal data – the Administrator ensures that it makes every effort to keep the personal data voluntarily provided by Users secure, to restrict access to it and to process it in accordance with its purpose. The Administrator also ensures that it makes every effort to protect the data it holds against loss by applying appropriate physical and organisational safeguards.
§5 Purposes for which Cookies are used
- Improving and facilitating access to the Website
- Personalising the Website for Users
- Keeping statistics (users, number of visits, device types, connection, etc.)
§6 Purposes of personal data processing
Personal data voluntarily provided by Users are processed for one of the following purposes:
- Provision of electronic services
- Communication between the Administrator and Users on matters related to the Website and data protection
- Pursuing the Administrator’s legitimate interest
Data about Users collected anonymously and automatically are processed for one of the following purposes:
- Keeping statistics
- Pursuing the Administrator’s legitimate interest
§7 Cookies of External websites
The Administrator uses JavaScript scripts and web components of partners on the Website, who may place their own cookies on the User’s Device. Remember that in your browser settings you can decide which cookies may be used by individual websites. Below is a list of partners or their services implemented on the Website that may place cookies:
- Statistics: Google Analytics
Services provided by third parties are beyond the Administrator’s control. These entities may change their terms of service, privacy policies, purpose of data processing and use of cookies at any time.
§8 Types of data collected
The Website collects data about Users. Some data is collected automatically and anonymously, and some data is personal data provided voluntarily by Users when signing up for individual services offered by the Website.
Anonymous data collected automatically:
- IP address
- Browser type
- Screen resolution
- Approximate location
- Website subpages visited
- Time spent on a given subpage
- Operating system
- Address of the previous subpage
- Referring website address
- Browser language
- Internet connection speed
- Internet service provider
Data collected during registration:
- E-mail address
- IP address (collected automatically)
Data collected when subscribing to the Newsletter:
- E-mail address
- IP address (collected automatically)
Some data (without identifying data) may be stored in cookies. Some data (without identifying data) may be transferred to the provider of statistical services.
§9 Access to personal data by third parties
As a rule, the only recipient of personal data provided by Users is the Administrator. Data collected as part of the services provided are not transferred or resold to third parties.
Access to the data (usually on the basis of a data processing agreement) may be granted to entities responsible for maintaining the infrastructure and services necessary to run the website, i.e.:
- Hosting companies providing hosting or related services to the Administrator
- Companies through which the Newsletter service is provided
Entrusting personal data processing – hosting, VPS or dedicated server services
To run the website, the Administrator uses the services of an external hosting, VPS or dedicated server provider – OVH sp. z o.o. All data collected and processed on the website are stored and processed in the provider’s infrastructure located in Poland. The data may be accessed as a result of maintenance work carried out by the provider’s staff. Access to this data is governed by an agreement between the Administrator and the Service Provider.
§10 How personal data is processed
Personal data voluntarily provided by Users:
- Personal data will not be transferred outside the European Union unless it has been published as a result of the User’s individual action (e.g. posting a comment or entry), which will make the data available to anyone visiting the website.
- Personal data will not be used for automated decision-making (profiling).
- Personal data will not be resold to third parties.
Anonymous data (without personal data) collected automatically:
- Anonymous data (without personal data) will be transferred outside the European Union.
- Anonymous data (without personal data) will not be used for automated decision-making (profiling).
- Anonymous data (without personal data) will not be resold to third parties.
§11 Legal basis for processing personal data
The Website collects and processes Users’ data on the basis of:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation):
- Art. 6(1)(a) – the data subject has given consent to the processing of his or her personal data for one or more specific purposes
- Art. 6(1)(b) – processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract
- Art. 6(1)(f) – processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party
- Polish Personal Data Protection Act of 10 May 2018 (Journal of Laws 2018, item 1000)
- Polish Telecommunications Law of 16 July 2004 (Journal of Laws 2004 No. 171, item 1800)
- Polish Act on Copyright and Related Rights of 4 February 1994 (Journal of Laws 1994 No. 24, item 83)
§12 Personal data retention period
Personal data voluntarily provided by Users:
As a rule, such personal data are stored only for the period during which the Administrator provides the Service on the Website. They are deleted or anonymised within 30 days of the end of the service (e.g. deletion of a registered user account, unsubscribing from the Newsletter, etc.).
An exception is a situation that requires securing the Administrator’s legitimate purposes for further processing of this data. In such a situation, the Administrator will store the data, from the time the User requests its deletion, for no longer than 3 years in the event of a breach or suspected breach of the website terms and conditions by the User.
Anonymous data (without personal data) collected automatically:
Anonymous statistical data that do not constitute personal data are stored by the Administrator for the purpose of keeping website statistics for an indefinite period.
§13 Users' rights related to the processing of personal data
- Right of access to personal data – Users have the right to access their personal data, exercised upon request submitted to the Administrator.
- Right to rectification of personal data – Users have the right to request that the Administrator promptly rectify inaccurate personal data and/or complete incomplete personal data, exercised upon request submitted to the Administrator.
- Right to erasure of personal data – Users have the right to request that the Administrator promptly erase their personal data, exercised upon request submitted to the Administrator. In the case of user accounts, erasure consists of anonymising the data that make it possible to identify the User. The Administrator reserves the right to withhold the erasure request in order to protect its legitimate interest (e.g. where the User has breached the Terms and Conditions or the data were obtained through correspondence). In the case of the Newsletter service, the User can delete their personal data themselves using the link included in every e-mail sent.
- Right to restriction of processing – Users have the right to restrict the processing of their personal data in the cases set out in Article 18 of the GDPR, including when contesting the accuracy of personal data, exercised upon request submitted to the Administrator.
- Right to data portability – Users have the right to receive from the Administrator the personal data concerning them in a structured, commonly used and machine-readable format, exercised upon request submitted to the Administrator.
- Right to object to processing – Users have the right to object to the processing of their personal data in the cases set out in Article 21 of the GDPR, exercised upon request submitted to the Administrator.
- Right to lodge a complaint – Users have the right to lodge a complaint with the supervisory authority responsible for personal data protection.
§14 Contacting the Administrator
You can contact the Administrator in one of the following ways:
- Postal address – ZMB Capital Sp. z o.o., ul. Jelenica 72, 43-450 Ustroń, Poland
- E-mail – sekretariat@zmbcapital.pl
- Contact form – available in the Contact section of the home page
§15 Website requirements
- Restricting the saving of and access to Cookies on the User’s Device may cause some Website functions to work incorrectly.
- The Administrator accepts no responsibility for Website functions that do not work correctly if the User restricts in any way the ability to save and read Cookies.
§16 External links
The Website – in articles, posts, entries or Users’ comments – may contain links to external websites with which the Website owner does not cooperate. These links and the pages or files they point to may be dangerous for your Device or pose a threat to the security of your data. The Administrator is not responsible for content located outside the Website.
§17 Changes to the Privacy Policy
- The Administrator reserves the right to change this Privacy Policy at any time without notifying Users with regard to the use of anonymous data or the use of Cookies.
- The Administrator reserves the right to change this Privacy Policy at any time with regard to the processing of Personal Data, of which it will inform Users with user accounts or subscribed to the newsletter by e-mail within 7 days of the change. Continued use of the services means that the User has read and accepted the changes to the Privacy Policy. If the User does not agree with the changes, they must delete their account from the Website or unsubscribe from the Newsletter.
- Changes to the Privacy Policy will be published on this page of the Website.
- Changes take effect upon publication.