I. Name and address of the data controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection regulations of Member States, as well as other data protection regulations, is:
corporate benefits Poland Sp. z.o.o.
z siedzibą w Warszawie
ul. Inflancka 4
00-189 Warsaw
Poland
tel.: +48 22 257 53 90
e-mail: info@cb-pl.com
website: https://www.corporate-benefits.pl
II. Contact details of the data protection officer
Please note that the data protection officer indicated below at corporate benefits GmbH is responsible for the use of the https://getsix.benefitsatwork.pl portal. Information about the data protection officer Getsix can be found on the Company's website.
The data protection officer of corporate benefits GmbH can be contacted at:
TÜV Informationstechnik GmbH
Mr. Colin Simbach
Unternehmensgruppe TÜV NORD
IT Security, Business Security & Privacy
Langemarckstrasse 20
45141 Essen
Phone: 0201 - 8999-461
Fax: 0201 - 8999-666
Email: privacyguard@tuvit.de
III. General Information on data processing
1. Scope of personal data processing
We collect and use personal data of our users only to the extent necessary to ensure the functioning of the website and our content and services. The collection and use of personal data of our users is generally only carried out with the user's consent. Exceptions to this are cases in which prior consent cannot be obtained for factual reasons and data processing is permitted by law.
2. Legal basis for the processing of personal data
To the extent that we obtain the consent of the data subject to the processing of personal data, the legal basis for the processing of personal data is Article 6(1)(a) of the GDPR.
In the case of processing personal data necessary for the performance of a contract to which the data subject is party, the legal basis is Article 6(1)(b) of the GDPR. This also applies to processing operations that are necessary for taking steps to enter into a contract.
To the extent that the processing of personal data is necessary for compliance with a legal obligation to which our Company is subject, the legal basis is Article 6(1)(c) of the GDPR.
If processing is necessary for the purposes of the legitimate interests pursued by our Company or a third party, and if the interests, fundamental rights and freedoms of the data subject are not overriding, the legal basis for processing is Article 6(1)(f) of the GDPR.
3. Data deletion and storage period
The personal data of the data subject will be deleted or blocked as soon as the purpose for which it was stored no longer applies. Data may also be stored if this is provided for by European law in EU regulations, national law, statutes or other provisions to which the controller is subject.
The data will also be blocked or deleted after expiry of the storage period specified in the above-mentioned standards, unless there is a need for further storage of the data for the conclusion or fulfilment of the contract.
IV. Website sharing and log creation
1. Description and scope of data processing
Each time you visit our website, our system automatically collects data and information from the computer system accessing it.
The following data is collected:
- Information about the type and version of the browser used
- The user's operating system
- The user's IP address
- The date and time of access
- The websites accessed by the user's system via our website.
This data is also stored in our system's log files. This data is not stored together with other personal data of the user.
When generating the voucher code, we store the following personal data for 1 year to protect against misuse (e.g. commercial resale):
- Voucher code
- Offer
- Company portal where the voucher code is offered
- First name
- Last name
- Email address
- Time of generation (date and time)
- User's IP address.
2. Legal basis for data processing
The legal basis for the temporary storage of data and log files is Article 6(1)(f) of the GDPR.
3. Purposes of data processing
In order to deliver the website to your computer, it is necessary for our system to temporarily store your IP address. For this purpose, your IP address must remain stored for the duration of the session.
The data is stored in log files to ensure the functionality of the website. The data is also used to optimise the website and ensure the security of our information systems. In this context, the data is not used for marketing purposes.
These purposes also constitute our legitimate interest in processing the data in accordance with Article 6(1)(f) of the GDPR.
4. Storage period
The data is deleted as soon as it is no longer necessary for the purpose for which it was collected. In the case of data collection for the purpose of providing the website, this is the case after the end of the respective session.
Data may also be stored. In this case, the IP addresses of users are deleted or anonymised so that it is no longer possible to identify the individual user.
Log files relating to the generation of voucher codes are deleted after one year; they may be processed to prevent misuse of voucher codes.
5. Right to object and right to erasure
The collection of data for the provision of the website and the storage of data in log files is absolutely necessary for the operation of the website. Therefore, you have no right to object.
V. Use of cookies
a) Description and scope of data processing
Our website uses cookies. Cookies are text files that are stored in the web browser or on the user's computer via the web browser. When a user accesses a website, a cookie may be stored on the user's operating system. This cookie contains a characteristic string of characters that enables the browser to be uniquely identified when the website is accessed again.
We use cookies to make our website more user-friendly. Some elements of our website require that the accessing browser can be identified even after a page change.
The following data is stored and transmitted in cookies:
- An identifier to identify the user
We also use the services and cookies of Webtrekk GmbH on our website to collect statistical data on usage and to improve our offering accordingly. The data from Webtrekk is used to display the ‘5 best offers from partners’ on the company platform. Webtrekk GmbH is TÜV Saarland certified for data protection in the area of website monitoring software.
Each time you visit our portal website, certain information provided by your browser during the registration process is collected and analysed for network control purposes. The data is collected by a pixel embedded on each page. The following data is collected:
- Request (name of the requested file)
- Browser type/version (e.g. Internet Explorer 6.0)
- Browser language (e.g. English)
- Operating system used (e.g. Windows XP)
- Internal resolution of the browser window
- Screen resolution
- JavaScript enabled
- Java enabled/disabled
- Cookies enabled/disabled
- Colour depth
- URL of the referring page (previously visited page)
- Shortened IP address for geographical recognition
- Access time
- Clicks
Webtrekk stores the IP address only in abbreviated (anonymous) form and uses it exclusively for session recognition, geolocation and defence against cyber attacks. The IP address is then immediately deleted, making the collected data anonymous.
Webtrekk uses the following cookies:
- Session cookies (for session recognition, lifetime: one session)
Further information can be found on the website of Webtrekk GmbH, Robert-Koch-Platz 4, 10115 Berlin, http://www.webtrekk.com.
b) Legal basis for data processing
The legal basis for the processing of personal data using cookies is Article 6(1)(f) of the GDPR.
c) Purpose of data processing
The purpose of using technically necessary cookies is to facilitate the use of websites for users. Some features of our website cannot be offered without the use of cookies. For this purpose, it is necessary to recognise the browser even after a page change.
e) Storage duration, objection and deletion options
Cookies are stored on your computer and transmitted by your browser to our website. As a result, you have full control over the use of cookies. You can prevent the transmission of cookies or restrict your use of the website by changing the settings in your web browser. Cookies that have already been saved can be deleted at any time. You can also do this automatically. Disabling cookies on our website may result in the availability of some features being restricted.
VI. Use of a Content Delivery Network (CDN) and Security Services (MyraSecurity)
1. Description, Purpose and Scope of Data Processing
For optimizing loading times (performance), increasing reliability and protecting our IT infrastructure against malicious attacks (e.g. so-called DDoS attacks) we have implemented a content delivery network (CDN).
For this purpose, we use the services of Myra Security GmbH, Landsberger Straße 187, 80687 Munich, Germany ("MyraSecurity").
A CDN is a network of regionally distributed servers that helps making available content from our website to you faster and more securely – including but not limited to static files, such as images, JavaScript and CSS files. From a technical point of view, MyraSecurity serves as a so-called reverse proxy. This means that the traffic between your device and our servers is routed through MyraSecurity's infrastructure for speeding up delivery and analyzing and defending against potential threats.
Within such process, technical protocol data (so-called access logs) are processed. These include, but shall not be limited to:
- Your IP address
- Date and time of access
- The requested content (e.g. URL) and
- Information about your browser and operating system (e.g. user-agent)
The processing of this data is technically required to ensure the stability, performance and security of our website.
2. Legal basis for data processing.
The legal basis for the use of MyraSecurity is our legitimate interest in providing our platform securely, quickly and reliably in accordance with Art. 6 (1) (f) GDPR.
MyraSecurity acts for us solely as a technical service provider bound to our instructions. We have concluded a contract processing agreement with MyraSecurity in accordance with Art. 28 GDPR. This ensures that the data is processed only according to our instructions and not for MyraSecurity's own purposes. The data processing takes only place in data centres within the European Union (EU) or the European Economic Area (EEA). MyraSecurity does not use its own cookies for this service to analyze user behavior.
3. Duration of storage
The access logs containing your IP address are stored for a maximum period of 10 days to ensure stability and security and are automatically deleted or anonymized afterwards.
VII. Newsletter
1. Description and scope of data processing
You can subscribe to free newsletters on our website. You can subscribe to the monthly newsletter when you register. You can also subscribe to the newsletter at any time in the ‘My data’ section. If you subscribe to the newsletter when you register, the following data will be transmitted to us:
- Salutation
- Title
- First name and surname
- Date of birth
- Company postcode
- Company email address
- Password
- Date and time of registration
- Membership of distribution list (company platform)
In addition to the monthly newsletter, you can also subscribe to a special newsletter, which is sent at irregular intervals after successful registration and login.
Your consent to data processing is obtained during the registration process and includes a reference to this privacy policy.
In connection with the processing of data for the purpose of sending newsletters, the data is transferred to Mapp Digital Germany GmbH, Dachauer Straße 63, 80335 Munich. The data is used exclusively for sending the newsletter.
For the purpose of sending the newsletter, we transfer a data package containing the following personal data to Mapp Digital:
- Email address
- Salutation
- Surname
- Mailing list membership (company platform and newsletter type)
2. Legal basis for data processing
The legal basis for data processing after the user has registered for the newsletter is Article 6(1)(a) of the GDPR, if the user has given their consent.
3. Purpose of data processing
The purpose of collecting the user's email address is to deliver the newsletter.
The collection of other personal data during the registration process serves to prevent misuse of the services or the email address used.
4. Storage period
The data is deleted as soon as it is no longer necessary for the purpose for which it was collected. The user's email address is therefore stored for as long as the newsletter subscription is active.
5. Right to object and erasure
The newsletter subscription can be cancelled by the user at any time. For this purpose, each newsletter contains a corresponding link to the ‘My data’ section of the employee. Here, the employee can unsubscribe from the newsletter.
The ‘My data’ section provides clear information about the subscription or cancellation of the monthly newsletter or special newsletter.
VIII. Registration
1. Description and scope of data processing
On our website, we offer users the option of registering on our portal by providing personal data. The data is entered into a form, transmitted to us and stored. The data is not passed on to third parties. The following data is collected during the registration process:
- Salutation (mandatory field)
- Title (optional)
- First name and surname (mandatory field)
- Date of birth (optional)
- Postcode (optional)
- Email address (mandatory field)
- Date of birth (optional)
- Newsletter (optional)
- Date and time of registration
As part of the registration process, the user's consent to the processing of this data is obtained. We also store the following data:
- Language preferences for platforms with multiple languages
- Location (web browser, if the user has given their consent; the user can also specify the location manually)
- Registration expiry date
- Timestamp
- Registration code
- Registration for a monthly e-mail newsletter with timestamp
- Registration for a special newsletter with timestamp
- Acceptance of the terms of use and privacy policy
- Connected company platform
- Login with timestamp
- Use of iOS/Android app: yes/no
- Offers saved to watch list
- Coupon code generation
- Coupon storage
- Contact forms
- Callback form content
- User reviews of time-stamped offers
iOS and Android app:
- Access to location (automatic location detection / news - push notifications if a store from the watch list is nearby)
- Access to camera (QR code scanning)
- Receive push notifications - New offers: yes/no
- Receive push notifications - Expiring offers: yes/no
- Receive push notifications - Save from nearby watch list: yes/no
If this feature has been activated on the portal, the user can post classified ads. The following data can be entered to create an ad:
- Greeting and title
- First and last name
- Email address
- Telephone number
- Address
In order to ensure that only authorised users have access to the platform and that offers are used exclusively for individual private purposes, the administrator will process the digital fingerprint of the device or browser.
This is used to ensure compliance with the terms of use and to prevent unauthorised use and exploitation of your access data and the platform.
In addition, the fingerprint helps to prevent commercial use of offers, in particular the commercial purchase, commercial offering or commercial resale of goods or services purchased at a discount. The unauthorised transfer of access data or codes will be logged to prevent misuse by unauthorised persons.
2. Legal basis for data processing
The processing of data collected during subscription takes place due to different legal grounds:
- The legal basis for the processing of the data that is essential for providing access to the Portal and user administration (first name, last name, email address), shall be Art. 6 para. 1 lit. b GDPR (performance of contract).
- The legal basis for the processing of the optional data (e.g. title, date of birth, postal code) shall be Art. 6 (1) (a) GDPR if the user has provided his consent
- The legal basis for collecting the salutation is Art. 6 (1) (f) GDPR (legitimate interest). The details of our legitimate interest and the balancing of interests carried out can be found under Section 3.
- The legal basis with respect to the fingerprinting for access control and abuse prevention is Art. 6 para. 1 sentence 1 lit. f GDPR (legitimate interest).
3. Purpose of Data Processing Legitimate Interests
For making available certain content and services on our website the user needs to subscribe. With successful subscription, the user gains access to our platform for employee offers. [...] Collecting personal data within the subscription process serves to identify and address users, support requests, legal evidence, marketing and target group analyses and to display saved offers.
Justification of the legitimate interest in collecting the salutation (Art. 6 para. 1 lit. f GDPR):
The salutation is collected for safeguarding our legitimate interest in high-quality, addressee-oriented and professional communication. We consider appropriate communication in the context of support, system notifications, and general provision of information to be essential for ensuring the quality of service and maintain the relationship of trust with our users. In our opinion, your interests and fundamental rights do not outweigh our stated interest in the necessary balancing, as the use of a customary form of address ("Mr" or "Mrs") is a common and reasonably expected practice in business transactions. Our analysis has shown that our interest in a structured basis for professional communication outweighs the interest of the data subjects in these circumstances.
Justification of the legitimate interest for fingerprinting (Art. 6 para. 1 lit. f GDPR):
We process a fingerprint generated by your device or browser to safeguard our legitimate interests in ensuring platform integrity and preventing abuse. Our business model is based on granting exclusive benefits to authorized users only (employees of partner companies). This model is existentially endangered by the unauthorized disclosing of access data, automatically creating accounts and commercially using discounts.
Protecting your account only with username and password is not sufficient for this purpose, as access data can be easily shared. Fingerprinting is therefore necessary to detect and stop patterns of abuse and to ensure that the terms of use are respected. The affection of your rights is kept as low as possible: The fingerprint created is pseudonymous, is used exclusively for this security purpose, is not passed on to uninvolved third parties and is not used for advertising or tracking purposes beyond our platform. When balancing the interests, our compelling interest in protecting our service and the entire user community from fraud and abuse outweighs your interest in protecting this specific technical data, particularly with you as authorized user also having an interest in the exclusivity and security of the platform.
4. Storage period
The data will be deleted as soon as it is no longer required for the purpose for which it was collected. This applies to data collected during the registration process if the registration on our website is cancelled or changed.
5. Right to object and erasure
You have the right to cancel your registration at any time. The user data stored may be changed at any time. In the ‘My data’ tab, you can delete your account at any time using the ‘Delete access’ option and make changes in this area.
IX. Contact form and email contact
1. Description and scope of data processing
Our website contains a contact form that you can use to contact us electronically. If you use this option, the data you enter in the form will be sent to us and stored. This data is as follows:
- Salutation
- First name
- Your email address
- Subject of your message
- and the content of your message
- Browser version
- Operating system
The following data is also stored when you send a message:
- Your IP address
- Date and time of sending the email
Alternatively, you can contact us via the email address provided. In this case, the personal data you send with your email will be stored by the Company.
2. Legal basis for data processing
The legal basis for data processing is Article 6(1)(a) of the GDPR if you have given your consent.
The legal basis for the processing of data transmitted when sending an email is Article 6(1)(f) of the GDPR. If the email contact is for the purpose of concluding a contract, the additional legal basis for the processing is Article 6(1)(b) of the GDPR.
3. Purpose of data processing
We process personal data from the contact form solely for the purpose of responding to your enquiry. If you contact us by email, this also constitutes a legitimate interest in processing the data.
Other personal data processed during the sending process is used to prevent misuse of the contact form and to ensure the security of our information systems.
4. Storage period
The data is deleted as soon as it is no longer necessary for the purpose for which it was collected. In the case of personal data contained in the contact form and data sent by email, this is the case after the respective conversation with the user has ended. The conversation is ended when it can be inferred from the circumstances that the matter in question has been finally clarified.
5. Right to object and erasure
You have the right to withdraw your consent to the processing of your personal data at any time. If you contact us by email, you can object to the storage of your personal data at any time. In this case, the conversation cannot be continued.
In this case, all personal data stored during your contact with us will be deleted.
X. Disclosure of personal data to third parties
We use an external system provided by http://salesforce.com Germany GmbH (registered office: Munich, Munich District Court HRB, 158525, registered office: Erika-Mann-Straße 31-37 80636 Munich, Germany, managing directors: Joachim Wettermark, José Luiz Moura Neto) for the purpose of processing service requests sent by email or via forms on the service portal. The data is stored exclusively within the EU. We have concluded an order processing agreement with Salesforce and additional EU standard contractual clauses. Please also refer to Salesforce's data protection information: https://www.salesforce.com/eu/.
We store our portal data with our technical service provider mpex GmbH (hosting), Werner-Voß-Damm 62, 12101 Berlin.
In addition, data is transferred within the Group to corporate benefits IT solutions, Schiffbauerdamm 40, 10117 Berlin (formerly corporate benefits ventures GmbH) for the purpose of providing our services.
XI. Rights of the data subject
If your personal data is processed, you are a data subject within the meaning of the GDPR and have the following rights vis-à-vis the controller:
1. Right to information
You may request confirmation from the controller as to whether your personal data is being processed by us.
If such processing has taken place, you may request the following information from the controller:
(1) the purposes of the processing of personal data;
(2) the categories of personal data being processed;
(3) the recipients or categories of recipients to whom your personal data has been or will be disclosed;
(4) the planned period for which the personal data concerning the user will be stored or, if specific information on this is not possible, the criteria for determining the storage period;
(5) the existence of the right to rectify or erase personal data concerning the user, the right to restrict processing by the controller or the right to object to such processing;
(6) the existence of the right to lodge a complaint with a supervisory authority;
(7) any available information on the source of the data, if the personal data have not been collected from the data subject;
(8) the existence of automated decision-making, including profiling, in accordance with Article 22(1) and (4) of the GDPR and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
The user has the right to request information on whether their personal data is transferred to a third country or an international organisation. In this context, the user may request information on the appropriate safeguards pursuant to Article 46 of the GDPR in connection with the transfer.
2. Right to rectification
You have the right to request that the controller rectify or complete your personal data if the personal data processed concerning you is inaccurate or incomplete. In such cases, the controller shall rectify the data without undue delay.
3. Right to restriction of processing
The user may request the restriction of the processing of their personal data in the following cases:
(1) if the accuracy of the personal data concerning the user is contested, for a period enabling the controller to verify the accuracy of the personal data;
(2) when the processing is unlawful and the user opposes the erasure of personal data and requests the restriction of their processing instead;
(3) the controller no longer needs the personal data for the purposes of the processing, but they are required by the user for the establishment, exercise or defence of legal claims; or
(4) if the user has objected to the processing in accordance with Article 21(1) of the GDPR and it has not yet been determined whether the legitimate interests of the controller override those of the user.
If the processing of personal data concerning the user has been restricted, such data shall, with the exception of storage, only be processed with the user's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
If processing restriction has been applied in accordance with the above conditions, the user will be informed by the controller before the restriction is lifted.
4. Right to erasure
a) Obligation to erase
You have the right to request that the controller erase your personal data without undue delay, and the controller has the obligation to erase personal data without undue delay if one of the following circumstances applies:
(1) The personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed.
(2) The user has withdrawn the consent on which the processing was based in accordance with Article 6(1)(a) or Article 9(2)(a) of the GDPR and there is no other legal basis for the processing.
(3) The user objects to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing that override the interests, rights and freedoms of the data subject or the user objects to the processing pursuant to Article 21(2) of the GDPR.
(4) The personal data concerning the user has been processed unlawfully.
(5) The erasure of personal data concerning the user is necessary to comply with a legal obligation to which the controller is subject under Union law or the law of a Member State to which the controller is subject.
(6) The personal data concerning the user has been collected in relation to information society services offered in accordance with Article 8(1) of the GDPR.
b) Information provided to third parties
If the controller has made the personal data concerning the user public and is obliged to erase it in accordance with Article 17(1) of the GDPR, it shall take reasonable steps, including technical measures, taking into account the available technology and the cost of implementation, to inform the controllers processing the personal data that the user, as the data subject, has requested the erasure of all links to, or the erasure of or the blocking of access to, such personal data.
c) Exceptions
The right to erasure does not apply if processing is necessary for:
(1) exercising the right to freedom of expression and information;
(2) compliance with a legal obligation requiring processing under Union law or the law of a Member State to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(3) for reasons of public interest in the area of public health in accordance with Article 9(2)(h) and (i) and Article 9(3) of the GDPR;
(4) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of the GDPR, in so far as the right referred to in point (a) is likely to render impossible or seriously impair the achievement of the objectives of such processing; or
(5) for the establishment, exercise or defence of legal claims.
5. Right to be informed about rectification, erasure or restriction of processing
If the user has exercised their right to rectification, erasure or restriction of processing against the controller, the controller shall notify all recipients to whom the user's personal data have been disclosed of the rectification or erasure of the data or the restriction of processing, unless this proves impossible or involves disproportionate effort.
The user has the right to be informed by the controller about these recipients.
6. Right to data portability
The user has the right to receive personal data concerning him or her, which he or she has provided to the controller, in a structured, commonly used and machine-readable format. The user also has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
(1) processing is based on consent pursuant to Article 6(1)(a) of the GDPR, Article 9(2)(a) of the GDPR or on a contract pursuant to Article 6(1)(b) of the GDPR
and
(2) processing is carried out by automated means.
When exercising this right, you also have the right to have your personal data transferred directly from one controller to another, where technically feasible. This may not adversely affect the freedoms and rights of others.
The right to data portability does not apply to the processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
7. Right to object
You have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you based on Article 6(1)(e) or (f) of the GDPR, including profiling based on those provisions.
The controller shall no longer process the personal data concerning the user unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the user or for the establishment, exercise or defence of legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such marketing, including profiling to the extent that it is related to such direct marketing.
If you object to the processing of your data for direct marketing purposes, your personal data will no longer be processed for these purposes.
Notwithstanding Directive 2002/58/EC, you have the right to object to the use of information society services by means of automated processes using technical specifications.
8. Right to withdraw consent under data protection regulations
You have the right to withdraw your consent under data protection regulations at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
9. Automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This right does not apply if the profiling:
(1) is necessary for entering into or performing a contract between you and the controller;
(2) is authorised by Union law or the law of a Member State to which the controller is subject and which also lays down suitable measures to safeguard the user's rights and freedoms and legitimate interests; or
(3) is based on the user's explicit consent.
However, these decisions shall not be based solely on special categories of personal data referred to in Article 9(1) of the GDPR, unless Article 9(2)(a) or (g) applies and appropriate measures to safeguard the rights and freedoms and legitimate interests of the user have been taken.
In the cases referred to in paragraphs 1 and 3, the data controller shall implement appropriate measures to protect the rights and freedoms and legitimate interests of the user, including at least the right to obtain human intervention from the controller, to express his or her point of view and to contest the decision.
10. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, the user has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement, if he or she considers that the processing of personal data relating to him or her infringes the GDPR.
The supervisory authority to which the complaint has been lodged shall inform the complainant of the status and outcome of the complaint, including the possibility of judicial remedy in accordance with Article 78 of the GDPR.
In Poland, the competent authority is the President of the Personal Data Protection Office with its registered office in Warsaw, ul. Stawki 2, 00-193 Warsaw, hotline: 606 950 000, e-mail: kancelaria@uodo.gov.pl.
last updated: 07.2021
Last updated: 11.2025