Privacy Policy
This Privacy Policy sets out the rules for the processing of personal data obtained through the website piotrpro.nl, hereinafter referred to as: “Website”.
The owner of the website and at the same time the controller is Quick and Safe Transport attn. Piotr Skrzypczak, VAT number: 87390663, hereinafter referred to as Controller.
The personal data collected by the Data Controller through the Website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as GDPR.
The Data Controller takes special care to respect the privacy of customers who visit the Website.
§ 1 Type of data processed, purposes and legal basis
The Controller collects information about natural persons who enter into a legal transaction not directly related to their activity, natural persons who exercise a trade, business or professional activity in their own name, and natural persons representing legal persons or organizational units without legal personality, to whom legal capacity is granted by law, who exercise a trade, business or professional activity in their own name, hereinafter collectively referred to as Customers.
Personal data of Customers are collected in the event of:
use of the contact form service on the Website for the purpose of performing an electronically provided service. Legal basis: necessity for the performance of the contract for the provision of the contact form service (Art. 6 para. 1 lit. b GDPR)When using the contact form service, the Customer provides the following data:
email address
name
telephone number
When using the Website, additional information may be collected, in particular: the IP address assigned to the Customer’s computer or the external IP address of the Internet service provider, domain name, browser type, access time, type of operating system.
Customers may also collect navigation data, including information about links and references they decide to click on or other actions taken on the Website. Legal basis – legitimate interest (Art. 6 para. 1 lit. f GDPR), consisting of facilitating the use of electronically provided services and improving the functionality of these services.
The provision of personal data to the Data Controller is voluntary.
§ 2To whom is data provided or entrusted and how long is it retained?
The Customer’s personal data will be transferred to service providers used by the Controller in the management of the Website. Service providers to whom personal data are transferred will, depending on contractual arrangements and circumstances, either be subject to the Controller’s instructions regarding the purposes and methods of data processing (processors), or determine the purposes and methods of their processing themselves (controllers).
1.1. Processors. The Controller uses suppliers who process personal data solely on the instructions of the Controller. These include suppliers who provide hosting services, accounting services, marketing systems, systems for website traffic analysis and systems for analyzing the effectiveness of marketing campaigns.
1.2. Controllers. The Controller uses suppliers who do not act solely on instructions and who themselves determine the purposes and methods for using Customers’ personal data. They provide electronic payment and banking services.
Location. Service providers are primarily located in Poland and other countries of the European Economic Area (EEA).
The personal data of Customers are stored:
3.1. In the event that the legal basis for the processing of personal data is consent, the Customer’s personal data will be processed by the Controller until the consent is withdrawn, and after the withdrawal of consent for a period corresponding to the limitation period of claims that the Controller may assert and that may be asserted against it. Unless a specific provision provides otherwise, the limitation period is six years, and for claims for periodic payments and claims in connection with the exercise of a business activity – three years.
3.2. In the event that the legal basis for processing data is the performance of a contract, the Customer’s personal data will be processed by the Controller for as long as necessary for the performance of the contract, and thereafter for a period corresponding to the limitation period for claims. Unless a specific provision provides otherwise, the limitation period is six years, and for claims for periodic payments and claims in connection with the exercise of a business activity – three years.
Upon request, the Controller shall provide personal data to competent public authorities, in particular to units of the Public Prosecution Service, the Police, the President of the Data Protection Authority, the President of the Consumer Protection and Competition Authority or the President of the Electronic Communications Authority.
§ 3 Cookies mechanism, IP address
The Website uses small files called cookies. These are stored by the Data Controller on the end device of the person visiting the Website, if the Internet browser allows this. A cookie file usually contains the name of the domain from which it comes, the “expiry time” and a unique, randomly selected number that identifies this file. The information collected via this type of file helps to adapt the products offered by the Data Controller to the individual preferences and real needs of the visitors to the Website.
The Data Controller uses two types of cookies:
2.1. Session cookies: after the browser session is terminated or the computer is turned off, the stored information is deleted from the device’s memory. The mechanism of session cookies does not allow the collection of personal data or confidential information from Customers’ computers.
2.2.Persistent cookies: these are stored in the memory of the Customer’s terminal device and remain there until they are deleted or expire. The mechanism of persistent cookies does not allow the collection of personal data or confidential information from the Customer’s computers.
The Data Controller uses its own cookies for the following purposes:
3.1. analytics and research and audience audits, in particular to create anonymous statistics that help understand how Customers use the Website, which can improve its structure and content.
The Data Controller uses third-party cookies for the following purposes:
4.1.presenting a map indicating the location of the Data Controller’s office on the information pages of the Website, using the maps.google.com internet service (third-party cookie manager: Google Inc. based in the USA)
The cookie mechanism is safe for the computers of Customers who visit the Website. In particular, it is not possible for viruses or other unwanted software or malicious software to enter the computers of Customers via this route. Nevertheless, Customers have the option in their browsers to limit or disable the access of cookies to their computers. If this option is used, the use of the Website will be possible, except for functions that naturally require cookies.
The Controller may collect IP addresses from Customers. The IP address is the number assigned to the computer of the person visiting the Website by the Internet Service Provider. The IP address enables access to the Internet. In most cases, it is assigned dynamically to the computer, i.e. it changes each time it connects to the Internet and is therefore generally considered non-personal identification information. The IP address is used by the Controller to help diagnose technical problems with the server, to perform statistical analyses (e.g. to determine from which regions we record the most visits), as useful information in managing and improving the Website, and for security purposes and possible identification of unwanted automated programs for viewing the content of the Website that are loading the server.
§ 4 Rights of data subjects
Right to withdraw consent – legal basis: Art. 7 para. 3 GDPR.
1.1. The Customer has the right to withdraw any given consent
1.2. The withdrawal of consent takes effect from the moment of withdrawal.
1.3. The withdrawal of consent does not affect the processing that the Controller lawfully carried out before the withdrawal.
1.4. The withdrawal of consent does not have any negative consequences for the Customer, but may make it impossible to continue using services or functionalities that the Controller can only provide with consent according to the law.
Right to object to data processing – legal basis: Art. 21 GDPR.
2.1. The Customer has the right at any time – for reasons related to his particular situation – to object to the processing of his personal data, including profiling, if the Controller processes the data on the basis of a legitimate interest, for example marketing of the Controller’s products and services, keeping statistics on the use of certain functionalities of the Website and facilitating the use of the Website, as well as satisfaction surveys.
2.2. Unsubscribing in the form of an e-mail message from receiving marketing communications regarding products or services will be considered as an objection by the Customer to the processing of his personal data, including profiling for these purposes.
2.3. If the Customer’s objection proves to be justified and the Controller has no other legal basis for processing personal data, the Customer’s personal data to which the objection has been made will be deleted.
Right to erasure of data (“right to be forgotten”) – legal basis: Art. 17 GDPR.
3.1. The Customer has the right to request the deletion of all or certain personal data.
3.2. The Customer has the right to request the deletion of personal data if:
3.2.1. the personal data are no longer necessary for the purposes for which they were collected or otherwise processed
3.2.2. he has withdrawn specific consent, insofar as the personal data were processed on the basis of his consent
3.2.3. he has objected to the use of his data for marketing purposes
3.2.4. the personal data have been unlawfully processed
3.2.5. the personal data must be erased in order to comply with a legal obligation under Union or Member State law to which the Controller is subject
3.2.6. the personal data have been collected in connection with the provision of information society services
3.3. Despite the request for erasure of personal data, in connection with objection or withdrawal of consent, the Controller may retain certain personal data insofar as the processing is necessary for the establishment, exercise or defence of legal claims, as well as for compliance with a legal obligation requiring processing under Union or Member State law to which the Controller is subject. This concerns in particular personal data including: name, surname, e-mail address, which are stored for the purpose of handling complaints and claims in connection with the use of services of the Controller, or additional residential/correspondence address, order number, which are stored for the purpose of handling complaints and claims in connection with concluded sales contracts or provision of services.
Right to restriction of processing – legal basis: Art. 18 GDPR.
4.1. The Customer has the right to request the restriction of the processing of his personal data. Submitting a request, until the moment of processing, prevents the use of certain functionalities or services, the use of which would involve the processing of the data to which the request relates. The Controller will also not send messages, including marketing messages.
4.2. The Customer has the right to request the restriction of the use of personal data in the following cases:
4.2.1. when the Customer contests the accuracy of his personal data – the Controller will restrict its use for the time necessary to verify the accuracy of the data, but no longer than 7 days
4.2.2. when the processing of data is unlawful and the Customer, instead of deleting the data, requests the restriction of its use
4.2.3. when the personal data are no longer necessary for the purposes for which they were collected or used, but the Customer needs them to establish, exercise or defend legal claims
4.2.4. where the Customer has objected to the use of his data – then the limitation of the time necessary to consider whether – given the particular situation – the protection of the interests, rights and freedoms of the Customer outweighs the interests pursued by the Controller when processing the Customer’s personal data follows.
Right of access – legal basis: Art. 15 GDPR.
5.1. The Customer has the right to obtain confirmation from the Controller as to whether or not personal data are being processed, and where that is the case, the Customer has the right to:
5.1.1. access their personal data
5.1.2. obtain information on the purposes of the processing, the categories of personal data processed, the recipients or categories of recipients of such data, the intended retention period of the Customer’s data or the criteria used to determine that period (where it is not possible to specify the planned processing period of the data), on the rights the Customer has under the GDPR and on the right to lodge a complaint with a supervisory authority, on the source of such data, on automated decision-making, including profiling, and on the safeguards applied in connection with the transfer of such data outside the European Union
5.1.3. obtain a copy of their personal data.
Right to rectification – legal basis: art. 16 GDPR.
6.1. The Customer has the right to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning him. Taking into account the purposes of the processing, the Customer has the right to obtain the completion of incomplete personal data, including by providing a supplementary statement, by sending a request to the e-mail address according to §6 of the Privacy Policy.
Right to data portability – legal basis: Art. 20 GDPR.
7.1. The Customer has the right to receive his personal data, which he has provided to the Controller, and to transmit it to another controller of his choice. The Customer also has the right to request that the personal data be transmitted directly by the Controller to that other controller, if this is technically possible. In that case, the Controller will transmit the Customer’s personal data in the form of a file in csv format, which is a commonly used format, suitable for machine reading and which allows the received data to be transmitted to another controller.
In the event that the Customer exercises any of the above-mentioned rights, the Controller shall comply with the request or refuse to comply with it without undue delay, but no later than within one month of receipt. However, if – due to the complexity of the request or the number of requests – the Controller is not able to comply with the request within one month, it shall comply with it within the following two months and inform the Customer within one month of receipt of the request of the intended extension of the term and the reasons therefor.
The Customer may submit complaints, questions and requests to the Data Controller regarding the processing of his personal data and the exercise of his rights.
The Customer has the right to lodge a complaint with the President of the Dutch Data Protection Authority regarding the violation of his rights to the protection of personal data or other rights granted to him under the GDPR.
§ 5 Changes to the Privacy Policy
The Privacy Policy may be changed, of which the Controller is not obliged to provide information.
- Questions regarding the Privacy Policy can be sent to: piotr1982@live.com
Date last modified: 15.03.2025