Privacy Policy
1. Definitions
- User – a person using the Website.
- Website – the website located at redpill.com.pl and all its subpages.
- Form – a screen on the Website that allows the User to enter personal data for the purposes indicated therein, e.g. to subscribe to the newsletter, to contact the User, etc.
- Website Operator – Szymon Zioło, conducting business activity under the name RedPill Szymon Zioło, at ul. Szafirowa 43a, 04-954 Warsaw, Poland, Tax Identification: PL-9511838358.
- Cookies - IT data, in particular text files, which are stored on the Website User's end device.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
2. General
2.1 This policy applies to the Website operating at the URL: https://redpill.com.pl.
2.2 The Website Operator is the personal data controller.
2.3 The personal data controller has not appointed a Data Protection Officer (DPO) and performs the duties related to the processing of personal data independently.
2.4 The Administrator can be contacted at the following e-mail address:
2.5 The Website uses personal data for the following purposes:
- running a newsletter,
- running a comment system,
- conducting online chat conversations,
- handling enquiries via the form,
- providing the services ordered,
- presentation of offers or information,
- direct marketing.
2.6 The Website performs the functions of obtaining information about users and their behaviour in the following manner:
- through data voluntarily entered in the Forms, which are entered into the Website Operator's systems,
- by storing cookies (so-called ‘cookies’) on end devices.
2.7 The Website is hosted (technically maintained) on the servers of an external hosting company, Vipserv.org Jan Dembicki.
3. Selected data protection methods used by the Website Operator
3.1 The places where you log in and enter personal data are protected at the transmission layer (SSL certificate). This means that personal data and login details entered on the Website are encrypted on the user's computer and can only be read on the target server.
3.2 Personal data stored in the database is encrypted in such a way that only the Website Operator with the key can read it. This protects the data in the event of the database being stolen from the server.
3.3 User passwords are stored in hashed form. The hashing function is one-way – it cannot be reversed, which is currently the modern standard for storing user passwords.
3.4 The Website Operator periodically changes its administrative passwords.
3.5 To protect data, the Website Operator regularly makes backup copies.
3.6 An important element of data protection is the regular updating of all software used by the Website Operator to process personal data, which in particular means regular updates of software components.
4. Direct marketing
4.1 The Administrator conducts direct marketing to promote its activities, in particular:
- conducting training in information technology,
- IT consulting,
- conducting webinars, events and online conferences.
4.2 The Controller reaches out to new business opportunities via email or LinkedIn to enable future customers to contact the Controller. The Controller sends emails only to Users who have given their consent by entering their personal data in the appropriate Form.
4.3 In the scope of direct marketing, the Controller collects the following data:
- first name and surname,
- telephone number,
- e-mail addresses,
- profession/position.
4.4 The Administrator processes Users' personal data:
- on the basis of consent given by the User entering their personal data in the appropriate Form,
- within the legitimate interest of the Administrator, which is the right to establish contact (Article 6(a)(b) and (f) of the GDPR).
4.5 In order to provide services and develop, the Administrator engages other processors who ensure an adequate level of protection in accordance with Article 28 of the GDPR.
4.6 The data is not disclosed to third parties.
4.7 The period of storage of personal data is 3 years.
5. Relevant marketing techniques
5.1 The Website Operator uses statistical analysis of traffic on the Website through Google Analytics (Google Inc. based in the USA). The Website Operator does not transfer personal data to Google Analytics, only anonymised information. The service is based on the use of cookies on the user's end device. With regard to information about user preferences collected by the Google advertising network, the user can view and edit information resulting from cookies using the following tool: https://www.google.com/ads/preferences/
5.2 The Website Operator uses remarketing techniques to tailor advertising messages to the user's behaviour on the Website, which may give the impression that the user's personal data is being used to track them, but in practice no personal data is transferred from the Website Operator to advertising operators. The condition for such activities is that cookies are enabled.
5.3 The Website Operator uses a solution that automates the operation of the Website in relation to Users, e.g. sending an email to the user after visiting a specific subpage of the Website, provided that the user has consented to receiving correspondence from the Website Operator.
6. Processing of personal data using cookies
6.1 The Website uses cookies.
6.2 The entity placing cookies on the User's end device and accessing them is the Website Operator.
6.3 Cookies are used to implement the marketing techniques described in section 5.
6.4 Cookies placed on the User's end device may also be used by entities whose services are used by the Website Operator, in particular Google and LinkedIn.
6.5 If the User does not want to store cookies, they can change their web browser settings.
7. User rights
7.1 The User has the rights set out in Articles 15-21 of the GDPR, i.e.:
- the right to access their data,
- the right to transfer data,
- the right to correct data,
- the right to rectify data,
- the right to delete data if there are no grounds for processing it,
- the right to restrict processing if it has been carried out incorrectly or without legal basis,
- the right to object to data processing on the basis of the legitimate interest of the controller,
- the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (on the terms specified in the Personal Data Protection Act) if they consider that the processing of their data is not in accordance with the currently applicable data protection laws.
- the right to be forgotten if further processing is not provided for by the currently applicable provisions of law.
7.2 In order to exercise their rights, the User may contact the Controller via e-mail:
8. Other information on the use of personal data
8.1 Personal data is stored on the servers of the hosting company Vipserv.org Jan Dembicki.
8.2 Personal data may be disclosed to other recipients, such as tax authorities or law enforcement agencies, on the basis of legal provisions or decisions of competent authorities.
8.3 Personal data is not transferred to third countries.
8.4 The Administrator does not make automated decisions, including on the basis of profiling.