1. Data controller
The controller of personal data is M3M, with its registered office in Warsaw, ul. Wolska 88, 01-141 Warsaw, Tax ID (NIP): 837-164-19-50 (hereinafter: the “Controller” or “Service Provider”), operator of the website available at https://useviaz.com (hereinafter: the “Website”).
As there is no formal requirement to do so, the Controller has not appointed a Data Protection Officer; nevertheless, in all matters concerning personal data you may contact us by writing to the email address: privacy@useviaz.com or in writing to the Controller’s registered address.
2. Scope and purposes of processing
The Controller processes the personal data of Website users for the following purposes:
- Scheduling presentations (demos) and proposing services: full name, email address, company name and the content of the message, in order to respond to the inquiry, carry out a product presentation and take steps toward concluding a contract. Legal basis: Art. 6(1)(b) GDPR.
- Handling the contact form: full name, email address, company name and the content of the message, in order to handle the contact form and respond to the inquiry. Legal basis: Art. 6(1)(f) GDPR, i.e. the legitimate interest of the Controller and the data subject.
- Email and traditional correspondence: data contained in messages sent to the Controller’s addresses, in order to conduct correspondence. Legal basis: Art. 6(1)(f) GDPR, i.e. the legitimate interest of the Controller and the data subject.
- Website statistics and analytics: data on how the Website is used, collected via Google Analytics 4 (online identifiers, approximate location, device and browser data, visited subpages). Legal basis: Art. 6(1)(a) GDPR, i.e. consent given by the user through the cookie settings.
- Marketing and remarketing: data collected via advertising tools (Google Ads, LinkedIn Insight Tag, Meta Pixel) in order to target ads and measure their effectiveness. Legal basis: Art. 6(1)(a) GDPR, i.e. consent given by users through the cookie settings and consent given on the basis of the delegation under Art. 398 of the Electronic Communications Law.
- Establishing, pursuing or defending claims: data necessary to achieve the processing purpose. Legal basis: Art. 6(1)(f) GDPR, i.e. the legitimate interest of the Controller.
Providing data in order to arrange a presentation (demo) and to order services, as well as providing data in the contact form, is voluntary but necessary for the Controller to take action and to prepare and send a response to the inquiry. Data provided to the Controller for the purposes indicated in this point is used solely for the Controller to take action in line with the user’s (client’s) business needs and to prepare and send a response regarding the given inquiry, and is not added to any mailing lists or newsletter.
3. Data retention period
- data contained in service agreements: for the duration of the agreement and then until the limitation period for any claims expires, no longer than 6 years from the end of the agreement;
- data from the contact form and correspondence: for the duration of the correspondence and then until the limitation period for any claims expires, no longer than 3 years from the last contact;
- analytics and marketing data: for the periods applicable to the individual cookies (up to 24 months) or until consent is withdrawn;
- data processed on the basis of consent: until it is withdrawn;
- data processed on the basis of a legitimate purpose related to establishing, pursuing or defending claims: until the limitation period for any claims expires, and thereafter in accordance with the requirements of the applicable law in this respect.
4. Data recipients
Personal data may be shared with entities that process it on the Controller’s behalf, in particular providers of hosting, email and IT tools, as well as providers of analytics and marketing tools: Google Ireland Ltd. (Google Analytics 4, Google Ads), LinkedIn Ireland Unlimited Company (LinkedIn Insight Tag) and Meta Platforms Ireland Ltd. (Meta Pixel). These entities process the data under data processing agreements or as separate controllers, in accordance with their own privacy policies.
Data may be disclosed to public authorities solely on the basis of applicable law.
5. Transfers of data outside the EEA
In connection with the use of Google, LinkedIn and Meta tools, data may be transferred to third countries, in particular to the USA. Transfers take place on the basis of a European Commission adequacy decision (the EU-U.S. Data Privacy Framework) with respect to providers holding DPF certification, and otherwise on the basis of standard contractual clauses (Art. 46(2)(c) GDPR).
6. Rights of data subjects
Every person whose data is processed has the right to:
- access their data and obtain a copy of it (Art. 15 GDPR);
- rectify their data (Art. 16 GDPR);
- erase their data (Art. 17 GDPR);
- restrict processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- object to processing based on legitimate interest (Art. 21 GDPR);
- withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;
- lodge a complaint with the President of the Personal Data Protection Office (more information: www.uodo.gov.pl).
To exercise the above rights, please contact the Controller at privacy@useviaz.com or at the correspondence address indicated in point 1 above.
8. Profiling and automated decisions
The Controller does not make decisions about users based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them. Marketing tools may carry out profiling in order to select the ads displayed, solely on the basis of the user’s consent.
9. Data security
The Controller applies technical and organizational measures appropriate to the risk, including transmission encryption (TLS), access control, minimization of the scope of collected data, the principle of adequacy of the processed data, and procedures meeting the requirements set out in Art. 5(1) GDPR.
10. Changes to the privacy policy
The Controller may update this policy, in particular in the event of changes to the tools used or to the law. The current version is always available on the Website together with the date of the last update (the version marking is at the top of the Privacy Policy).