Privacy
Policy

Privacy policy

Personal data at Asseco Data Systems S.A. is processed on the basis of applicable laws, in particular the European Parliament and the Council (EU) 2016/679 of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free flow of such data and repealing Directive 95/46/EC (hereinafter: "RODO") and the Law of May 10, 2018 on the Protection of Personal Data (hereinafter: "the Law").

This Privacy Policy sets out the rules for the processing of personal data in Asseco Data Systems S.A., as well as the rules for the processing of data in the Websites operated by Asseco Data Systems S.A..

PERSONAL DATA CONTROLLER

  1. The administrator of the Personal Data processed in the company for various purposes related to the company's business activities is Asseco Data Systems S.A., seated in Gdańsk, ul. Jana z Kolna 11, 80 - 864 Gdańsk, entered in the Register of Entrepreneurs of the National Court Register under the number KRS 0000421310, kept by the District Court of Gdańsk - North in Gdańsk, VII Commercial Department of the National Court Register, NIP 517-03594-58, REGON 180853177, whose share capital amounts to PLN 120,002,940.00 (paid in full);
  2. You can contact us:
  • by letter (snail mail), writing to the address indicated above,
  • via email at [email protected],
  • By phone at +48 58 550 95 00.
  1. Data Protection Officer
    We have appointed a Data Protection Officer whom you can contact:
  • by letter (snail mail), writing to: Asseco Data Systems S.A., Office in Lodz, 136 Narutowicza St., 90-146 Lodz,
  • via e-mail at: [email protected],
  • By phone at +48 42 675 63 60.
  1. Asseco Data Systems S.A. complies with all privacy and processing rules set forth in the RODO also with respect to data entrusted by other Administrators or Entrustors.

WHAT IS PERSONAL DATA AND ACCORDING TO WHAT PRINCIPLES DO WE PROCESS IT?

  1. Personal data - all information about a natural person identified or identifiable by one or more specific factors that determine physical, physiological, genetic, mental, economic, cultural or social identity, including device IP, location data, Internet ID and information collected through cookies and other similar technology.
  2. The Personal Data Administrator processes data in accordance with the following principles:
  3. Reliability and lawfulness - meaning that data will be processed fairly, in accordance with correctly identified, RODO-compliant legal bases that are adequate for each processing activity. The Personal Data Controller identifies and determines the appropriate legal basis for each processing activity.
  4. Transparency - meaning that data subjects are informed in a transparent, accessible and understandable manner about who will process their data, on what basis, for what purpose, to what extent and for how long. Data subjects are further informed about: the recipients of the data, their rights and how to exercise them, and whether the data will be transferred to countries outside the EU and whether the data will be subject to automated decision-making and, if so, what impact this will have on the data subject. The Personal Data Controller ensures that the information obligation will be fulfilled:
  • in the case of collection of data from the data subject - at the latest at the time of collection,
  • in the case of collection of data from a source other than the data subject - no later than within 30 days of their acquisition;
  • Purpose limitation - meaning that personal data is collected and processed for specific, explicit and legitimate purposes and that it is not further processed in a manner incompatible with those purposes.
  • Data minimization - meaning that data is adequate and limited to what is necessary to achieve the purpose for which it is processed.
  • Correctness - meaning that the processed data are correct, truthful and are subject to updates when necessary.
  • Storage limitations - meaning that data will be stored in a way that allows the data subject to be identified for no longer than necessary to fulfill the purposes for which the data are processed.
  • Integrity and confidentiality - which means that the data are processed in a manner that ensures their adequate security and, in particular, in a manner that ensures protection against: accidental or unauthorized loss, modification, damage or destruction. The Personal Data Administrator shall ensure data security through the use of adequate technical and organizational measures. The Personal Data Controller shall develop a personal data protection system taking into account the risks defined in his organization to which the processed data are exposed (risk-based approach). A description of the measures used is included in this document.
  • Accountability - meaning that the Personal Data Controller processes personal data in a manner that ensures compliance with the provisions of the RODO in connection with their processing operations, and that it will be able to demonstrate the implementation of organizational and technical measures to ensure data processing in accordance with applicable laws. Demonstration of the implementation of these measures will take place in particular through the implementation of appropriate rules, procedures and policies describing the rules of conduct for data processing.
    The Data Controller strives to ensure that every process, solution or business idea, as early as in the design phase, should be analyzed for the use of personal data in that solution and take into account the protection of that data. This analysis should be carried out further, including already during the processing itself (privacy by design).

WHAT PERSONAL INFORMATION MAY BE COLLECTED BY THE INTERNET WEBSITE.

USE OF COOKIE MECHANISMS AND OTHER MARKETING TOOLS

  1. During the User's visit to the Website, information about the Users of the Websites may be collected automatically through the use of services provided by modern marketing tools suppliers, including cookies files. Such information may constitute personal data.
  2. Cookies are small text files created by the Website, stored on the user's device, and can only be used by the browser through which they were created. The use of Internet Services thus involves the use of the following types of cookies:
    1. Necessary cookies – allow us to browse the website and use its functions. These may be authentication files or files providing security.
    2. Analytical cookies – primarily serve to improve a given website. They collect user data in such a way as to ensure their complete anonymity. Thanks to them, we know which pages have been visited and whether any unwanted complications have occurred during the visit. Based on them, we cannot identify the user.
    3. Preference cookies – enable the collection of information about the choices users make when visiting websites. Thanks to these cookies, it is possible to personalize the website - displaying the appropriate language and advanced customization of content and selected options.
    4. Marketing cookies - these are files oriented towards promotional activities, and thanks to them, it is possible to target ads tailored to the user, as well as measure the effectiveness of implemented advertising campaigns.
  3. A detailed description of the tools used, including cookies files, containing the scope, purposes, and period of storing information collected through them, is provided below.
Tool Purpose of information collection Scope of information collected Data retention period (from the date of collection)
GA4 Traffic analytics, understanding user behaviors, tracking conversions and goals, user segmentation, measuring return on marketing investment Events, Custom Variables, Conversions 14 months
Google Ads Evaluation of advertising campaign effectiveness Advertising data, Demographic and geographic data, Conversion data, Conversion tracking data 90 days / permanent
Linkedin Tracking profile performance, evaluating content effectiveness, understanding the audience, monitoring advertising campaigns Profile statistics, content statistics, audience demographic data, behavioral data 6 months
Piwik User behavior analysis, effectiveness evaluation, audience segmentation Session information, User behavior permanent
Salesmanago Marketing personalization, audience segmentation, marketing automation Contact data, Behavioral data 1 year / permanent
go.pl Improving site usage, personalizing content IP addresses, device information, demographics session / 1 month
Hotjar Analysis of user behavior, Evaluation of site performance, Testing and optimization User session recordings (excluding data entered into forms), browser type information, operating system type, country of login based on IP (without visible IP), maps of most frequent clicks session / 1 year / 30 minutes
Crazy Egg Analysis of user behavior, Evaluation of site performance, Testing and optimization Heat maps, scroll maps, click maps, A/B testing, visual analysis session / 1 month / 1 year
Freshmail Building a list of subscribers, Tracking campaign effectiveness Email addresses, Demographics, Activity history 1 year
Complianz Managing cookie consents User IP address, Type of user device, User's browser version, Date and time of the user's visit to the online store, Information about cookies to which the user has consented. 1 year
Finsweet Managing cookie consents User IP address, Type of user device, User's browser version, Date and time of the user's visit to the online store, Information about cookies to which the user has consented. 6 months
Cookiebot Managing cookie consents User IP address, Type of user device, User's browser version, Date and time of the user's visit to the online store, Information about cookies to which the user has consented. 1 year
PlumRocket Managing cookie consents User IP address, Type of user device, User's browser version, Date and time of the user's visit to the online store, Information about cookies to which the user has consented. 1 year
Cookie-law-info Managing cookie consents Recording of cookie preferences 1 year
Cloudflare Domain security Filtering machine requests 30 min
Google reCAPTCHA Spam Prevention Filtering of machine requests / Spam protection session
WP_Darkmode Preference settings Preference data 1 day
WPML Language preference settings Data on the language used session
Polylang Language preference settings Data on the language used 1 year
cerber_groove Protection against malware IP and behavioral data 1 year
Twitter (X) Twitter integration and social media sharing capabilities Profile statistics, content statistics, audience demographic data, behavioral data 1 year
Facebook Tracking website visits Profile statistics, content statistics, audience demographic data, behavioral data 3 monthe
Gemius Marketing effectiveness analytics IP addresses, device information, demographics, user activity on the site 13 months
Smart AdServer Optimizes ad display based on user traffic IP addresses, device information, demographics, user activity on the site 1 year
Adform Optimizes ad display based on user traffic IP addresses, device information, demographics, user activity on the site session
YouTube Content personalization User behavior data, Technical data session
Microsoft Clarity Analysis of user behavior, recording user behavior Load and site metadata. Event data on the site 30 days
  1. The user of the Service has the option to choose which types of cookies will be used during their visit to the Service, whereby necessary cookies may be and are used regardless of the User's consent, while for other cookies, they are used with the User's consent. The user will be asked to express consent to the use of individual types of cookies when visiting the Service. Before giving consent, the Administrator provides access to this Privacy Policy and recommends reading it.
  2. Due to the nature of cookies and the fact that they are stored on the user's device, the Administrator may only ensure the withdrawal of consent to the use of cookies by recommending changes to the settings of the web browser. Changes to the settings can be made by selecting the "Privacy and Security" tab in the browser options. In any case, direct contact with the Administrator is also possible in order to exercise the User's rights related to the processing of their data.
  3. Cookies do not modify other data stored in the user's device's mass memory and do not affect the proper operation of the operating system.
  4. Some of the tools used on the Website may result in automated decision-making regarding the User (especially profiling) within the scope of a given Internet Website. The consequence of such action may be, in particular, the display of ads for certain products and services offered by the Administrator. The User has the right to request the Administrator to have the automated decision reviewed by a human. To do so, the User should contact the Administrator as specified in the "Exercise of data subjects' rights" section.
  5. None of the marketing tools used by the Administrator are used for the direct identification of users of the Internet Website.

CONTACT FORMS, RECRUITMENT FORMS, AND ORDER FORMS

  1. To ensure maximum transparency, in cases where the Website utilizes a form in which the User provides data directly identifying them, information about the data controller, purpose of processing, legal basis, recipients, storage duration, and other information required by applicable law are provided to the User at the moment of collecting data through the respective form.

PRINCIPLES OF SHARING AND ENTRUSTING PERSONAL DATA

  1. The Personal Data Administrator shares (including entrusts) personal data with other entities (data recipients) on the basis of:
  2. legislation in force
  3. Business decisions on outsourcing selected parts of the business.
  4. In the case of sharing data with entities to which the Personal Data Controller subcontracts services in its name and on its behalf, a written entrustment agreement is required. The decision to entrust is preceded by an analysis of the credibility and reliability of the entity.
  5. Any decision to outsource services, requires it to be analyzed by the Personal Data Controller also in terms of entering into an entrustment agreement for processing.

IMPLEMENTATION OF THE RIGHTS OF DATA SUBJECTS

Asseco Data Systems, in its role as a controller of personal data, ensures that the rights of the persons whose data it processes can be realized. Requests arising from the rights of data subjects can be realized:

PROVIDING INFORMATION TO DATA SUBJECTS

Asseco Data Systems S.A., as controller, provides each individual with information about the processing of his/her personal data. The Data Controller, upon the request of an individual, shall respond whether it processes his/her personal data. If he/she processes his/her data, he/she grants access to personal data and provides information about:

  • person and contact information of the administrator,
  • Person and contact information of the Personal Data Inspector,
  • purpose of processing,
  • The legal basis for processing,
  • information about the recipients or categories of recipients to whom the data will be disclosed,
  • The planned period of storage of personal data,
  • The right to request rectification, erasure or restriction of data processing, data portability, and to object to such processing (the rights due to data subjects depend on the basis of processing applied in a given case),
  • The right to lodge a complaint with the supervisory authority for the protection of personal data,
  • information about the intention to transfer data outside the EU,
  • Information about the obligation to provide data and the consequences thereof,
  • information about whether the data will be processed by automated means and whether it will be subject to profiling,
  • the categories of data involved and the source from which the person's data was obtained - in case it did not come directly from the person.

The information specified above is, in accordance with the implementation of the principle of transparency, provided to data subjects in information clauses.

DATA SECURITY

Asseco Data Systems makes every effort to ensure that the data processed in its enterprise are protected to the highest standards. It conducts a risk analysis for the processing activities for which it is the administrator and for the processing of data it has been entrusted with in order to select optimal technical and organizational means by which to ensure confidentiality, integrity and availability of personal data.

The Personal Data Administrator will regularly test, measure and evaluate the effectiveness of technical and organizational measures to ensure the security of processing and adjust security measures according to the results of the measurements.

Asseco Data Systems regularly conducts internal audits and undergoes independent assessments by external auditing firms for standards: ISO 9001, ISO 27001, ISO 22301.

News

We develop software, services and solutions for the digitisation of business and central and local government.

Asseco's achievements in Africa recognized by international research institutes

Code Signing – trusted providers sign their applications

Asseco tops the "ITWiz Best100" report for 2022

Automatic e-sealing

Trusted Economy Forum 2023: trust is key in sports and business

Asseco supports digital transformation of Democratic Republic of Congo

Trusted Economy Forum 2023: Business can't choose between user experience and security

UN Commission for Africa will use experience of Asseco-trained experts

Asseco has launched a cybersecurity agency in Togo

Asseco won in 14 categories of the "ITwiz Best100" report

Asseco with "Investor in Human Capital" certificate

LEO System® 4.0 the best software for financial institutions according to Gazeta Finansowa

The solution developed by Asseco Data Systems for leasing companies has been included in the "Best Software for Financial Institutions" list prepared by Gazeta Finansowa. According to the editors, the awarded systems take into account the specific needs that companies in the financial sector have.

Asseco to support Botswana's digital transformation

Simply Sign and Mobile Touch by Asseco the best products for companies according to Gazeta Finansowa

Rzeszów with the Smart City title

Asseco's qualified electronic signature for Santander Bank Polska's customers

The latest trends in information technology for business already on 12 May 2016 in Gdańsk

Asseco will support digitization of postal services in Zambia

Asseco continues cooperation with KRUS on the development of the Workflow system

Asseco joins the Cyber Science research and didactic consortium

The new IT system for Sieradz from Asseco allows to handle official matters without leaving home

Asseco invests in Pirios, a leader in digital solutions for customer communication

Developing cyber security in Africa

Interactive Cultural Institution "Rzeszów Cellars" in multimedia form with support of Asseco

Asseco has implemented an intelligent parking system in Rzeszów

Asseco has implemented digital signature on tablets in Plus points of sale

Asseco has implemented a civic budget management system at the Zabrze City Hall

Asseco Cloud will have its headquarters in Szczecin

Asseco Data Systems in the top ten of the IT@Bank ranking

Asseco Poland creates Asseco Cloud and develops cloud services

Asseco implements e-signing of financing agreements at BNP Paribas Leasing Solutions Polska

EFL Group and Asseco create digital solutions for SMEs

Asseco has implemented a modern remote customer service system at ZWIK Grodzisk Mazowiecki

Asseco has implemented the Electronic Storage Medium at the Cooperative Bank in Lubaczów

2021 a year of paperless and digital customer communication

Asseco receives Smart City Poland Award

Żabka's franchisees submitted over 60,000 e-signatures via Asseco platform

Asseco is the partner of Smart City Forum

Asseco will implement the first smart city parking system

Cloud by Asseco - a new brand on the Polish cloud market is to be launched

Inperly app users gain SimplySign e-signature capability