Privacy Policy
This Privacy Policy sets out the rules for processing personal data collected through the website katarzynazielant.com, hereinafter referred to as the “Website.”
The owner of the Website and the Data Controller is Katarzyna Zielant, hereinafter referred to as the “Controller.”
Personal data collected by the Controller through the Website is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR).
The Controller takes special care to respect the privacy of Clients visiting the Website.
1. Types of Processed Data, Purposes, and Legal Basis
The Controller collects information regarding natural persons performing legal acts not directly related to their business activity, natural persons conducting business or professional activity on their own behalf, and natural persons representing legal entities or organizational units without legal personality, which have legal capacity under applicable law and conduct business or professional activity on their own behalf, hereinafter collectively referred to as “Clients.”
Clients’ personal data are collected in the case of:
Using the contact form service on the Website for the purpose of performing an electronic service agreement. Legal basis: necessity for the performance of a contract for providing the contact form service (Art. 6(1)(b) GDPR).
When using the contact form service, Clients provide the following data:
Email address
First name
Phone number
While using the Website, additional information may be collected, including: IP address assigned to the Client’s computer or external IP of the Internet provider, domain name, browser type, access time, and operating system type.
Navigation data may also be collected from Clients, including information about links and references clicked or other actions taken on the Website. Legal basis: legitimate interest (Art. 6(1)(f) GDPR), aimed at facilitating the use of electronic services and improving their functionality.
Providing personal data to the Controller is voluntary.
2. Data Recipients and Storage Period
Clients’ personal data are shared with service providers used by the Controller in managing the Website. Depending on contractual arrangements and circumstances, these service providers either act on the Controller’s instructions regarding the purposes and methods of data processing (processors) or determine the purposes and methods of processing themselves (independent controllers).
2.1. Processors
The Controller uses providers who process personal data solely on the Controller’s instructions. These include hosting providers, accounting service providers, marketing systems, web traffic analysis systems, and marketing campaign performance analysis systems.
2.2. Independent Controllers
The Controller also uses providers who independently determine the purposes and methods of using Clients’ personal data. These include electronic payment and banking service providers.
Location: Service providers are primarily located in Poland and other countries within the European Economic Area (EEA).
Clients’ personal data are stored as follows:
Consent-based processing: Personal data are processed as long as consent has not been withdrawn, and after withdrawal for the period corresponding to the statute of limitations of claims the Controller may raise or may be subject to. Unless otherwise provided, the limitation period is six years; for claims regarding periodic services or business-related claims – three years.
Contract-based processing: Personal data are processed as long as necessary to perform the contract, and after that for the period corresponding to the statute of limitations of claims. Unless otherwise provided, the limitation period is six years; for claims regarding periodic services or business-related claims – three years.
Upon request, the Controller provides personal data to authorized state authorities, including the Prosecutor’s Office, Police, President of the Personal Data Protection Office, President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.
3. Cookies and IP Address
The Website uses small files called cookies, stored on the visitor’s device if the browser allows it. Cookies usually contain the domain name, expiration time, and a unique randomly generated number. Information collected via cookies helps customize products offered by the Controller to the individual preferences and needs of Website visitors.
3.1. Types of cookies
Session cookies: Deleted after the browser session ends or the device is turned off. Session cookies do not collect personal or confidential information.
Persistent cookies: Stored on the Client’s device until deleted or expired. Persistent cookies do not collect personal or confidential information.
3.2. Purpose of cookies
Own cookies: Used for analysis, research, and traffic auditing, including creating anonymous statistics to understand how Clients use the Website and improve its structure and content.
Third-party cookies: For example, to display a map showing the Controller’s office location via maps.google.com (external cookie administrator: Google Inc., USA).
Cookies are safe for Clients’ devices. They do not allow viruses or malicious software to enter. Clients can limit or disable cookies in their browsers, though some Website functions may not work properly.
The Controller may collect Clients’ IP addresses for technical troubleshooting, statistical analysis (e.g., identifying regions with the most visits), Website administration, security, and identifying undesirable automated programs.
4. Data Subject Rights
Right to withdraw consent (Art. 7(3) GDPR)
Clients may withdraw any consent at any time.
Withdrawal is effective immediately and does not affect processing done legally before withdrawal.
Withdrawal does not result in negative consequences but may limit access to services requiring consent.
Right to object to processing (Art. 21 GDPR)
Clients may object to processing for reasons related to their specific situation, including profiling, when processing is based on legitimate interest (e.g., marketing, usage statistics, satisfaction surveys).
Opting out of marketing emails constitutes an objection to processing for these purposes.
Valid objections require the Controller to cease processing and delete related data.
Right to erasure (“right to be forgotten”) (Art. 17 GDPR)
Clients may request deletion of all or part of their personal data.
This applies if data are no longer necessary, consent is withdrawn, objection to marketing is made, data are unlawfully processed, compliance with legal obligation is required, or data were collected in connection with online services.
Certain data may be retained for claim verification, defense, or legal obligations.
Right to restriction of processing (Art. 18 GDPR)
Clients may request restriction of processing, temporarily disabling certain functionalities.
Applicable in cases of data inaccuracy, unlawful processing instead of deletion, data no longer needed but required for claims, or objection under specific circumstances.
Right of access (Art. 15 GDPR)
Clients may request confirmation of data processing, access to personal data, information about processing purposes, categories, recipients, storage period, rights under GDPR, source of data, automated decision-making including profiling, and data transfer safeguards outside the EU.
Clients may request a copy of their personal data.
Right to rectification (Art. 16 GDPR)
Clients may request immediate correction of inaccurate data and completion of incomplete data.
Right to data portability (Art. 20 GDPR)
Clients may receive personal data in a machine-readable format (e.g., CSV) and transfer it to another controller.
Requests are fulfilled or refused within one month, extendable by two months in complex cases. Clients may submit complaints or inquiries regarding their data. They may also file a complaint with the President of the Personal Data Protection Office.
5. Changes to the Privacy Policy
The Privacy Policy may change, and the Controller is not obliged to notify users.
Questions regarding the Privacy Policy should be sent to k.zielant@gmail.com.
Last modified: December 18, 2023
Dołącz do newslettera i otrzymuj praktyczne wskazówki i inspiracje, które wspierają rozwój Twojej kariery.
Bezpłatny WORKBOOK pobierzesz od razu po zapisie. W 15 minut sprawdzisz, gdzie obecnie jest Twoja kariera, co działa, a który obszar wymaga uwagi.
Sprawmy, aby najbliższe lata Twojej kariery były pełne satysfakcji i sensu, oraz na Twoich zasadach.
Copyright © 2025 KATARZYNA ZIELANT | Privacy Policy | Created by Atwi.pl