Privacy Policy

 

  1. This Privacy Policy defines the principles of processing personal data collected through the website nikaparo.com, hereinafter referred to as the “Website.”

  2. The owner of the website and the Data Controller is PAROL Mateusz Parol, 05-825 Kraśnicza Wola, ul. Kraśnicza Wola 56, NIP: 5262613522, hereinafter referred to as the Administrator.

  3. The personal data collected by the Administrator through the Website are processed in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also known as GDPR.

  4. The Administrator takes special care to respect the privacy of the Clients visiting the Website.

§ 1 Type of Data Processed, Purposes, and Legal Basis

  1. The Administrator collects information concerning individuals performing legal activities not directly related to their business, individuals conducting business or professional activity in their own name, and individuals representing legal persons or organizational units not having legal personality, which are granted legal capacity under the law, conducting business or professional activity on their own behalf, hereinafter collectively referred to as Clients.

  2. The Administrator processes the personal data of Clients for the use of the contact form service on the Website for the purpose necessary to perform the contract or take action before its conclusion – legal basis for processing: Article 6(1)(b) of the GDPR.

  3. When using the contact form service, the Client provides the following data:

  • Email address

  • Name

  • Phone number

  1. While using the Website, additional information may be collected, in particular: IP address assigned to the Client’s computer or the external IP address of the Internet service provider, domain name, type of browser, access time, type of operating system. The Administrator may also collect navigational data, including information about links and references the Client decides to click on or other actions performed on the Website related to the provision of services, as well as for technical, administrative, analytical, and statistical purposes – for this purpose, the legal basis for processing is also Article 6(1)(f) of the GDPR, i.e., the necessity for the purposes arising from the legitimate interest of the Administrator, which is ensuring the IT security and managing the Website, as well as improving the functionality of the Website and services provided.

§ 2 Data Recipients

  1. The Client’s personal data is transferred to service providers used by the Administrator in running the Website. Service providers to whom personal data is transferred, depending on contractual arrangements and circumstances, either follow the Administrator’s instructions regarding the purposes and methods of data processing (processors) or independently determine the purposes and methods of processing (controllers).

1.1. Processors. The Administrator uses providers who process personal data exclusively on the Administrator’s instructions. These include, among others, hosting service providers, accounting services, marketing system providers, systems for analyzing website traffic, and systems for analyzing marketing campaign effectiveness.

1.2. Controllers. The Administrator uses providers who do not act exclusively on instructions and determine the purposes and methods of using personal data of Clients. They provide electronic payment and banking services.

  1. Location. Service providers are primarily located in Poland and other countries of the European Economic Area (EEA).

  2. In the event of a request, the Administrator may provide personal data to authorized state authorities, particularly to the Prosecutor’s Office, Police, the President of the Office for Personal Data Protection, the President of the Office for Competition and Consumer Protection, or the President of the Office for Electronic Communications.

§ 3 Data Retention Period

  1. The personal data of Clients is retained:

1.1. If the legal basis for processing personal data is consent, the personal data of the Client will be processed by the Administrator until the consent is withdrawn, and after the consent is withdrawn, for a period corresponding to the limitation period for claims that the Administrator may raise and those that may be raised against the Administrator. Unless a special provision states otherwise, the limitation period is six years, and for claims related to periodic benefits and business activity – three years.

1.2. If the legal basis for processing the data is the performance of a contract, the personal data of the Client will be processed by the Administrator as long as necessary to perform the contract, and after that, for the period corresponding to the limitation period for claims. Unless a special provision states otherwise, the limitation period is six years, and for claims related to periodic benefits and business activity – three years.

§ 4 Cookies Mechanism, IP Address

  1. The Website uses small files called cookies. These are saved by the Administrator on the device of the person visiting the Website, provided the web browser allows it. A cookie usually contains the domain name from which it originates, its “expiry time,” and an individual, randomly selected number identifying the file. The information collected through such files helps the Administrator adjust the products offered to the individual preferences and actual needs of the visitors to the Website.

  2. The Administrator uses two types of cookies:

2.1. Session cookies: once the session of a given browser is over or the computer is turned off, the saved information is deleted from the device memory. The session cookies mechanism does not allow the collection of personal data or confidential information from Clients’ computers.

2.2. Persistent cookies: these are stored in the memory of the Client’s device and remain there until they are deleted or expire. The persistent cookies mechanism does not allow the collection of personal data or confidential information from the Client’s computer.

  1. The Administrator uses own cookies for:

3.1. Analysis and research, as well as audit of viewership, and in particular to create anonymous statistics that help understand how Clients use the Website, which enables the improvement of its structure and content.

  1. The Administrator uses external cookies for:

4.1. Displaying on the informational pages of the Website, a map showing the location of the Administrator’s office, through the online service maps.google.com (administrator of external cookies: Google Inc. based in the USA).

  1. The cookie mechanism is safe for the Clients’ computers visiting the Website. In particular, it is not possible for viruses or other unwanted software or malicious software to enter the Clients’ computers. However, Clients have the option to limit or disable the access of cookies to their computers in their browsers. If they use this option, the use of the Website will still be possible, except for functions that inherently require cookies.

  2. The Administrator may collect IP addresses of Clients. An IP address is a number assigned to the computer of the person visiting the Website by the internet service provider. The IP number allows access to the Internet. In most cases, it is assigned dynamically to the computer, i.e., it changes with each connection to the Internet, and is therefore generally treated as impersonal information identifying the device. The IP address is used by the Administrator for diagnosing technical issues with the server, creating statistical analyses (e.g., determining from which regions most visits are recorded), as useful information for managing and improving the Website, as well as for security purposes and the potential identification of unwanted automated programs burdening the server while browsing the Website.

§ 5 Rights of Data Subjects

Individuals whose data are processed have the right to:

  1. The right to withdraw consent to data processing at any time:

1.1. The Client has the right to withdraw any consent previously given.
1.2. Withdrawal of consent is effective from the moment it is withdrawn.
1.3. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
1.4. Withdrawal of consent does not entail any negative consequences for the Client, but it may prevent the continued use of services or functionalities that, according to the law, can only be provided with the Client’s consent.

  1. The right to object to data processing:

2.1. The Client has the right to object at any time, on grounds relating to their particular situation, to the processing of their personal data based on Article 6(1)(e) or (f) of the GDPR, including profiling based on these provisions. The Administrator may no longer process the personal data unless it demonstrates the existence of compelling legitimate grounds for processing that override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims.
2.2. Opting out of receiving marketing communications about products or services will be considered as an objection to the processing of personal data, including profiling for those purposes.

  1. The right to erasure of data (“right to be forgotten”):

3.1. The Client has the right to request the deletion of all or some of their personal data.
3.2. The Client may request the deletion of personal data if:
3.2.1. The personal data are no longer necessary for the purposes for which they were collected or processed.
3.2.2. The Client has withdrawn their consent, to the extent that personal data were processed based on their consent.
3.2.3. The Client has objected to processing under Article 21(1) of the GDPR, and there are no overriding legitimate grounds for processing, or they have objected under Article 21(2) of the GDPR.
3.2.4. The personal data have been processed unlawfully.
3.2.5. The personal data must be erased in order to comply with a legal obligation under Union or Member State law to which the Administrator is subject.
3.2.6. The personal data were collected in relation to the offering of information society services.
3.3. Despite the request for the deletion of personal data, the Administrator may retain certain personal data if processing is necessary for the establishment, exercise, or defense of legal claims, as well as to comply with a legal obligation requiring processing under Union or Member State law. This includes personal data such as name, surname, email address, retained for the purpose of handling complaints or claims related to the use of the Administrator’s services.

  1. The right to restriction of processing:

4.1. The Client has the right to request the restriction of processing of their personal data. Until the request is processed, the use of certain functionalities or services requiring the processing of the requested data will not be possible. The Administrator will also not send any messages, including marketing ones.
4.2. The Client has the right to request the restriction of the use of their personal data in the following cases:
4.2.1. When the accuracy of their personal data is contested – the Administrator will restrict its use until the accuracy of the data is verified, but no longer than for 7 days.
4.2.2. When the processing is unlawful, and instead of deleting the data, the Client requests its restriction.
4.2.3. When personal data are no longer necessary for the purposes for which they were collected or used but are needed by the Client for the establishment, exercise, or defense of legal claims.
4.2.4. When the data subject has objected to the processing of their data – until it is determined whether the legitimate grounds for processing override the objections of the data subject.

  1. The right to access and receive a copy of personal data:

5.1. The Client has the right to obtain from the Administrator confirmation as to whether or not personal data is being processed, and if so, the Client has the right to:
5.1.1. Access their personal data.
5.1.2. Obtain information about the purposes of processing, categories of personal data processed, recipients or categories of recipients of the data, the planned period for which the personal data will be stored or the criteria used to determine this period (if the planned period for processing data is not determined), rights available to the Client under the GDPR, and the right to lodge a complaint with a supervisory authority.
5.1.3. Obtain a copy of their personal data. The right to obtain a copy shall not adversely affect the rights and freedoms of others.

  1. The right to rectification (correction) of data:

6.1. The Client has the right to request the Administrator to promptly rectify any personal data concerning them that is inaccurate. Depending on the purpose of processing, the Client has the right to request the completion of incomplete personal data, including by providing a supplementary statement.

  1. The right to data portability:

7.1. The Client has the right to receive their personal data provided to the Administrator and send it to another data controller. The Client also has the right to request that their personal data be sent directly to another controller by the Administrator, if technically feasible. In this case, the Administrator will send the Client’s personal data in CSV format, which is a widely used, machine-readable format allowing for the transfer of the data to another data controller.

  1. The right to lodge a complaint with a supervisory authority:

8.1. The Client has the right to lodge a complaint with the President of the Personal Data Protection Office regarding the violation of their rights to personal data protection or other rights granted under the GDPR.

  1. In the event that the Client exercises their rights under the provisions above, the Administrator will promptly comply with the request or refuse to comply with it, but no later than one month after receiving the request. If the request is complex or numerous, the Administrator will fulfill it within the following two months, informing the Client in advance within one month of receiving the request about the intended extension of the deadline and its reasons.

  2. The Client may submit complaints, inquiries, and requests regarding the processing of their personal data and the exercise of their rights.

§ 6 Changes to the Privacy Policy

  1. The Privacy Policy may be changed, and the Administrator is not obliged to inform about it.

  2. Questions related to the Privacy Policy should be directed to the email address: Paroldominika@gmail.com

  3. Date of last modification: 16.12.2025


This is a full, accurate translation of the provided text. Let me know if you need any further modifications!