This Privacy and Cookies Policy provides information on the processing of personal data that you may disclose to the Controller while using the Service, as well as on the use of cookies. The Controller reserves the right to amend this Privacy Policy. Reasons for changes may include amendments to applicable law, the development of internet technologies, the Controller’s use of new tools, and other objective circumstances. The publication date of the current Privacy and Cookies Policy is shown at the top of this page.
I. DEFINITIONS
- Controller - The data controller is the entity that determines the purposes and means of processing personal data. Details of the processing are always provided at the time of collection, e.g., in contracts concluded with you or in announcements. The Controller implementing this Policy is Arlena Hamdi, conducting sole proprietorship under the business name HAMDI COLLECTIVE Sp. z o. o., ul. Bednarska 19/19a unit 13, 00-321 Warsaw, NIP 5253058328, REGON: 542533426, KRS 0001190314.
- Personal data – Information relating to an identified or identifiable natural person, identifiable directly or indirectly by reference to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person, including the device IP address, location data, online identifiers, and information collected via cookies and similar technologies.
- Policy – This Privacy Policy containing information on the processing of Personal Data and the use of cookies and similar tracking technologies within the Service.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC.
- Personal Data Protection Act – The Polish Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws of 2018, item 1000, as amended).
- Service – The website operated by the Controller at https://animatria.pl via web browsers, together with all its subpages and all services provided within the domain.
- User – A natural person visiting the Service or using one or more services or functionalities described in this Policy.
- Device – An electronic device through which the User accesses the website.
II. WHO IS THE PERSONAL DATA CONTROLLER?
- The Controller of personal data is Arlena Hamdi, conducting sole proprietorship under the business name HAMDI COLLECTIVE Sp. z o. o., ul. Bednarska 19/19a, unit 13, 00-321 Warsaw, NIP: 5242742009, REGON: 366495179, KRS 000119031.
- You can contact the Controller at the above address, by e-mail: arlena@animatria.pl , or by phone: +48 572 450 107.
- By contacting the Controller via e-mail, contact form, or social media, you provide your personal data (e.g., name and e-mail address).
- The Controller attaches great importance to the security and lawfulness of processing Users’ personal data. Personal data are processed in accordance with the GDPR and other currently applicable data protection laws.
III. WHAT PERSONAL DATA ARE PROCESSED IN CONNECTION WITH USING THE SERVICE?
- The Service enables the User to contact the Controller and provide identification and contact data, as well as data contained in the content of the message.
- The Controller collects data related to Users’ activity, such as time spent on the site, search queries, number of subpages viewed, date and source of visits.
- If the User contacts the Controller, the data are provided directly by the User.
- If the User’s data are provided in connection with a matter handled on the User’s behalf by another person, the source of the data is that person. In such case, the Controller receives identification, address and case- related data (e.g., case description).
- In connection with the User’s use of the Service, the Controller collects data to the extent necessary to provide specific services offered (e.g., first name, last name, residential address, e-mail address).
- Detailed rules and purposes of processing personal data collected while using the Service are set out below.
IV. PURPOSES AND LEGAL BASES OF PROCESSING
- Personal data of all persons using the Service are processed by the Controller for the following purposes:
- Analysis of web traffic, ensuring Service security, and content customisation – based on the Controller’s legitimate interests (Article 6(1)(f) GDPR).
- Responding to correspondence and sending requested offers, conducting correspondence – based on consent and/or the Controller’s legitimate interests (Article 6(1)(a) and (f) GDPR).
- Delivering and displaying content on the Service – the Controller collects personal data such as IP address and cookies; processing is based on the Controller’s legitimate interests (Article 6(1)(f) GDPR).
- Establishment, exercise, and defence of legal claims – based on the Controller’s legitimate interests (Article 6(1)(f) GDPR), consisting in protecting its rights.
- Posting User reviews of the Controller’s services and conducting opinion surveys – based on consent (Article 6(1)(a) GDPR).
- Use of cookies on the Service and its subpages – based on consent (Article 6(1)(a) GDPR).
- Analytics and statistics – conducting analyses of Users’ activity in the Service to improve functionalities; based on the Controller’s legitimate interests (Article 6(1)(f) GDPR).
- Contact via electronic contact form – using the form requires providing personal data necessary to establish contact. The User may also provide other data to facilitate contact or handling of the enquiry. Providing data marked as required is necessary to accept and handle the enquiry; failure to provide them will prevent processing. Providing other data is voluntary. Personal data are processed to identify the sender and handle the enquiry submitted via the form – the legal basis is the necessity to perform a contract for the provision of the service (Article 6(1)(b) GDPR); for optional data, the legal basis is consent (Article 6(1)(a) GDPR).
- The user may also provide other data to facilitate contact or handling of the inquiry. Providing data marked as mandatory is required in order to accept and handle the inquiry, and failure to provide such data will result in the inability to handle the inquiry. Providing other data is voluntary. Personal data is processed for the purpose of identifying the sender and handling their inquiry sent via the form provided – the legal basis for processing is the necessity of processing for the performance of a service contract (Article 6(1)(b) of the GDPR); with regard to optional data, the legal basis for processing is consent (Article 6(1)(a) of the GDPR).
V. HOW DOES THE CONTROLLER OBTAIN PERSONAL DATA?
- “Personal data” means any information that can be used to identify a specific person directly or indirectly. This definition includes personal data collected online via the Controller’s website and corporate pages on external platforms.
- When contacting the Controller, you may be asked to provide your personal data. The Controller may share your personal data with, and use them together with, companies affiliated with the Controller by capital or by personnel, in a manner consistent with this Privacy Notice. The Controller may also combine them with other information to improve its content.
- The Controller collects personal data from various sources, including:
- Data provided directly – e.g., information on how you use the site, such as the types of content you view or engage with, and the frequency and duration of your activities.
- Data collected automatically – the Controller also receives and stores certain types of personal
data whenever you interact online. For example, the Controller uses cookies and tracking
technologies to obtain personal data when your web browser accesses the website and other
content delivered on other websites. Personal data are also collected during searches and when
posting content.
Examples include IP address, device identifier, location data, and information about the computer and connection (browser type and version, time zone setting, browser plug-in types and versions, operating system).
VI. USERS’ RIGHTS IN RELATION TO THEIR PERSONAL DATA
- Under the GDPR, Users have the following rights in relation to the processing of personal data:
- right of access to personal data and to receive a copy of the data;
- right to rectification/correction of personal data;
- right to erasure (“right to be forgotten”);
- right to restriction of processing;
- right to object to processing of personal data;
- right to withdraw consent;
- right to data portability;
- right to data portability;
- right to lodge a complaint with the President of the Personal Data Protection Office (PUODO).
- Not all of these rights will apply to the User in every circumstance; this depends on the nature of the legal provisions and the context of processing.
VII. DATA RETENTION PERIOD
- The period for which the Controller processes the User’s personal data depends on the type of service provided and the purpose of processing.
- Personal data will be stored until consent is withdrawn or until the matter is resolved.
- Data related to web traffic analysis collected via cookies and similar technologies may be stored until the cookie expires. Some cookies never expire; therefore, the storage period will equal the time necessary for the Controller to achieve the purposes for which the data are collected, such as ensuring security and analysing historical traffic data.
- The processing period may be extended if processing is necessary for the establishment, exercise or defence of legal claims, and thereafter only if and to the extent required by law. After the processing period expires, the data are irreversibly deleted or anonymised.
VIII. DATA SECURITY
- The User’s personal data are stored and protected with due care in accordance with the Controller’s internal procedures.
- The Controller processes User information with appropriate technical and organisational measures that meet the requirements of generally applicable law, in particular data protection legislation. These measures are designed primarily to protect Users’ personal data against unauthorised access. In particular, access is granted only to authorised persons who are obliged to keep the data confidential.
- At the same time, the User should exercise due care in securing personal data transmitted over the Internet, in particular by not disclosing login data to third parties, using antivirus protection, and keeping software up to date.
IX. DISCLOSURE OF DATA TO THIRD PARTIES
- The User’s personal data may be disclosed to third parties whose services the Controller uses in connection with operating the Service.
- Due to the use of services provided by Google or Facebook, Users’ personal data may be transferred to the United States of America (USA), Canada, and other countries. These entities ensure an adequate level of personal data protection as required by European regulations.
- Processors within the European Economic Area (EEA):
- Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02 X525, Ireland (formerly Facebook Ireland Limited).
- MailerLite Limited, Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593, Ireland – newsletter delivery platform.
- Facebook and Instagram – particularly with respect to advertising tools.
- Facebook Ireland Ltd. – use of Meta Platforms (Facebook) advertising tools and processing within Custom Audiences.
- Other contractors or subcontractors engaged for technical or administrative support or to provide legal assistance to the Controller and its clients, e.g., accounting, IT, graphic design, copywriting, debt collection companies, lawyers, and authorities such as the tax office – to fulfil legal and tax obligations related to settlements and accounting.
- Processors outside the EEA:
- Google Analytics by Google LLC – tools protecting the Service and analytical/statistical tools (Google Analytics).
- As part of the Administrator's activities, social media plugins have also been embedded on the website. The purpose and scope of data collection and its further processing and use by service providers are described in the privacy policies indicated below: Facebook – https://www.facebook.com/privacy/explanation, Instagram- https://help.instagram.com/519522125107875?helpref=page_content. Translated with DeepL.com (free version)
X. COOKIES AND TRACKING TECHNOLOGIES
- This website uses cookies.
- On your first visit to the site, you are shown information about the use of cookies. If you do not change your browser settings, you consent to their use.
- The Service allows information to be collected about the User via cookies and similar technologies, which typically involves installing a tool on the User’s Device.
- This information is used to remember the User’s decisions (e.g., font choice, contrast, acceptance of the policy), maintain the User’s session (e.g., after logging in), remember passwords (with consent), and collect information about the User’s Device and visit to ensure security, as well as for visit analytics and content customisation. Information obtained via cookies and similar technologies is not combined with other Service User data and is not used by the Controller to identify Users.
- Cookies are short text information stored on the Device you use when browsing websites. They may be read by the Controller (“first-party cookies”, used to ensure the correct operation of this site) and by systems belonging to other entities whose services the Controller uses (“third-party cookies”).
- The user has the right to change cookie settings from their browser or to delete them.
- The User has the right to change cookie settings in the browser or to delete them. The User can also use the site in so-called incognito mode, which blocks the collection of data about the visit.
- This website uses the following tracking technologies: social plug-ins such as Facebook and Instagram; and analytical and marketing tools such as Google Analytics and Facebook Pixel.
XI. SERVER LOGS
- Using the website involves sending queries to the server on which the website is located.
- Every request sent to the server is recorded in server logs, which include, for example: IP address, server date and time, information about the web browser and operating system you are using.
- The data stored in the server logs is not associated with specific individuals using the website and is used as supporting material for administrative purposes.
- The contents of server logs are not disclosed to anyone other than those authorized to administer the server.
XII. SOCIAL MEDIA
- The Controller maintains profiles on the Facebook and Instagram social networks (the “fan pages”). Content, offers, and product recommendations are regularly published and shared on these fan pages. Social network administrators record user behaviour using cookies and other similar technologies with every interaction with our fan pages and other sites on Facebook and Instagram.
- Social network administrators have access to aggregate statistics on the interests and demographics (such as age, gender, place of residence) of users visiting the fan pages. When using social networks, the scope and purposes of processing on those platforms are determined by their respective administrators.
XIII. CHANGES TO THIS PRIVACY POLICY
- The policy is reviewed on an ongoing basis and updated as necessary.
- This Policy is reviewed on an ongoing basis and updated as necessary. The Controller will update this Privacy Notice when required. When changes are published, the “last updated” date will also be changed. Earlier versions of this Privacy Notice will be kept in an archive.
- Your rights under this Privacy Notice will not be limited without your consent.