Legal document
Privacy policy
This Privacy Policy describes how eConnect4U Sp. z o.o. collects, processes and protects your personal data in connection with your use of the econnect4u.pl website. Please read it carefully.
Data controller
The controller of your personal data is eConnect4U Sp. z o.o., with its registered office at ul. Krakusa 10, 41-200 Sosnowiec, Poland, entered in the Register of Entrepreneurs of the National Court Register under number KRS 0000552770, NIP (tax ID) 6443510370, REGON 361245466.
You can contact the Controller:
- by e-mail: [email protected]
- by telephone: +48 889 112 197
- in writing, at the Company's registered office address
What personal data we collect
Depending on how you use our website and services, we may collect the following categories of data:
We do not collect special categories of personal data (so-called sensitive data) within the meaning of Article 9 GDPR.
Purpose and legal basis of processing
Your personal data is processed solely for strictly defined purposes and on an appropriate legal basis:
- Handling enquiries and providing consultations - Article 6(1)(b) GDPR (necessity for the performance of a contract or in order to take steps prior to entering into a contract)
- Direct marketing - Article 6(1)(f) GDPR (the Controller's legitimate interest) or your consent - Article 6(1)(a) GDPR
- Website analytics and optimisation - Article 6(1)(f) GDPR (legitimate interest in improving our services)
- Compliance with legal obligations - Article 6(1)(c) GDPR (e.g. tax and accounting regulations)
- Sending the newsletter - your consent - Article 6(1)(a) GDPR and Article 10 of the Polish Act on Providing Services by Electronic Means; details in § 07
Consent to data processing may be withdrawn at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
Data retention period
- Contact form data - until your enquiry has been handled, and then for the limitation period for claims (as a rule, 3 years)
- Client / contractor data - for the duration of the business relationship and for the statutory record-keeping period (5 years from the end of the financial year)
- Marketing data - until consent is withdrawn or a valid objection is raised
- Technical logs - for a maximum of 12 months
Data recipients and transfers
Your data may be disclosed only to trusted entities that process it solely on our documented instructions and under appropriate data processing agreements:
- Infrastructure and hosting providers - servers located in the EEA (Poland / EU)
- Analytics tools (Google Analytics 4) - run only after consent is given in the cookie banner; data is pseudonymised, and transfers to the USA are covered by standard contractual clauses. As of the date of publication, analytics is not active.
- CRM and communication tools - systems for handling enquiries and correspondence; the ecChat assistant widget (an eConnect4U service, servers in the EU) - the content of conversations held in the demo widget
- Law firms and auditors - only to the extent necessary and on the basis of legal provisions
The Controller does not sell personal data to third parties and does not share it for advertising purposes without the user's explicit consent.
Your rights
Under the GDPR, you have the following rights in relation to the processing of your personal data:
- Right of access - you can obtain confirmation as to whether we process your data and, if so, access to that data (Article 15 GDPR)
- Right to rectification - you have the right to request that inaccurate data be corrected or incomplete data completed (Article 16 GDPR)
- Right to erasure - the so-called "right to be forgotten", in specific cases (Article 17 GDPR)
- Right to restriction of processing - you can request that the processing of your data be suspended in specific situations (Article 18 GDPR)
- Right to data portability - you can receive your data in a structured format (Article 20 GDPR)
- Right to object - you have the right to object to processing based on our legitimate interest (Article 21 GDPR)
- Right to lodge a complaint - you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl
To exercise any of the above rights, contact us at [email protected]. We will respond to your request without undue delay and no later than one month after receiving it.
Data security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss or destruction. The safeguards we use include:
- Encryption of data in transit using the TLS/SSL protocol
- Access control to systems and personal data (principle of least privilege)
- Regular staff training in data protection
- Information security policies and incident response procedures
- Regular security reviews and testing of our infrastructure
In the event of a personal data breach that may result in a risk to the rights and freedoms of natural persons, the Controller will notify the competent supervisory authority (UODO) within 72 hours of becoming aware of the breach. Data subjects will be informed without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
Changes to this Privacy Policy
The Controller reserves the right to amend this Privacy Policy. Any changes will be published on this page with the date of the last update shown in the document header.
In the case of significant changes affecting the way your data is processed, we will inform you in advance - by e-mail or by a clear notice on the website.
Contact regarding personal data
Please direct any questions, requests and enquiries concerning the processing of your personal data to: