Data Protection

1. Data Protection in Brief


General Notes

The following information provides a simple overview of what happens with user's personal data when visiting this website. Personal data includes any information that can identify a user. For detailed information about data protection, please refer to our privacy policy mentioned below this text.


Data Collection on this Website

Data processing on this website is carried out by the website operator. The contact details of the website operator can be found in the "Information about the Data Controller" section in this data protection statement.

On one hand, user data is collected when users provide it to us. This could, for example, be data entered in a contact form.
Other data is automatically collected or with the user's consent by our IT systems when visiting the website. This primarily includes technical data (e.g., internet browser, operating system, or time of page display). This data is collected automatically upon entering the website. 

Some data is collected to ensure the proper functioning of the website. Other data may be used to analyze user behavior.

The user has the right to receive, at any time and free of charge, information about the origin, recipient, and purpose of stored personal data. The user also has the right to request the correction or deletion of this data. If the user has given consent for data processing, they can revoke it at any time for the future. The user also has the right to request the restriction of processing their personal data under certain circumstances. Furthermore, the user has the right to lodge a complaint with the relevant supervisory authority. 

The user has the right to receive, at any time and free of charge, information about the origin, recipient, and purpose of stored personal data. The user also has the right to request the correction or deletion of this data. If the user has given consent for data processing, they can revoke it at any time for the future.
 

The user also has the right to request the restriction of processing their personal data under certain circumstances. Furthermore, the user has the right to lodge a complaint with the relevant supervisory authority.
 

You can contact us at any time regarding this and other questions related to data protection.


2. Hosting


The content of our website is hosted by the following provider:


External Hosting 

This website is hosted externally. Personal data collected on this website is stored on the servers of the host provider(s). This may include, among other things, IP addresses, contact requests, metadata and communication data, contractual data, contact details, names, access to the website, and other data generated through the website.

External hosting is carried out for the purpose of fulfilling the contract with our potential and current clients (Art. 6(1)(b) GDPR) and for the interest of secure, fast, and efficient delivery of our online offerings by a professional provider (Art. 6(1)(b) GDPR). If appropriate consent is requested, processing is carried out exclusively based on Art. 6(1)(b) GDPR, as long as the consent includes the storage of cookies or access to information on the user's end device (e.g., device fingerprint) as defined by the GDPR. Consent can be revoked at any time.

Our hosting service providers will process user data only to the extent necessary to fulfill their obligations and follow our instructions with respect to such data.


We use the following hosting service provider:
united-domains AG
Gautinger Street 10
82319 Starnberg
Germany

We have concluded a data processing agreement (DPA) with the above-mentioned provider. This is a legally required agreement ensuring that the provider processes personal data of visitors to our website only in accordance with our instructions and in compliance with the GDPR. 


3. General Notes and Mandatory Information


Data Protection 

The operators of these pages take the protection of users' personal data very seriously. User's personal data is treated confidentially and in accordance with statutory data protection regulations and this data protection statement.

When using this website, various personal data is collected. Personal data includes data that can be used for personal identification. This privacy policy explains what data we collect and how we use it. It also explains how and for what purpose this is done.

Please note that data transmission over the Internet (e.g., communication via email) may have security vulnerabilities. Complete protection of data from access by third parties is not possible.


Note Regarding the Data Controller 

The data controller for this website is:
HN Experts SP. z o.o.
ul. Złota 59
00-120 Warszawa

Telefon: +48 605 509 540
E-Mail: privacy@hn-experts.pl

A data protection administrator is a natural or legal person who independently or jointly with others determines the purposes and methods of processing personal data (such as names, email addresses, etc.). 



Retention Period 

Unless a more specific retention period is specified in this privacy policy, user personal data will remain with us until the purpose of their processing is fulfilled. If a user submits a justified request to delete data or withdraws consent for their processing, their data will be deleted, unless we have other legally permissible reasons for retaining their personal data (such as retention periods according to tax or commercial law); in this latter case, the data will be deleted after these reasons cease to exist


General Information about the Legal Basis for Data Processing on this Website 

If a user has given consent for data processing, we process their personal data based on Art. 6(1)(a) of the GDPR or Art. 9(2)(a) of the GDPR, if special categories of data are processed in accordance with Art. 9(1) of the GDPR. In the case of explicit consent for the transfer of personal data to third countries, data processing also occurs based on Art. 49(1)(a) of the GDPR. If a user has consented to storing cookies or allowing access to information on their terminal device, this consent can be revoked at any time. If a user's data is required to fulfill a contract or implement pre-contractual measures, we process the user's data based on Art. 6(1)(b) of the GDPR. Furthermore, if a user's data is required to fulfill a legal obligation, we process it based on Art. 6(1)(c) of the GDPR. Additionally, data processing can occur based on our legitimate interest according to Art. 6(1)(f) of the GDPR. Information about the appropriate legal basis in each individual case is provided in the subsequent sections of this data protection statement.


Note Regarding Data Transfer to the USA and Other Third Countries 

We use tools from companies based in the USA or other third countries that are not safe in terms of data protection regulations. If these tools are active, user personal data may be transferred to these third countries and processed there. Please note that these countries may not guarantee a level of data protection comparable to that in the EU. For instance, U.S. companies are obliged to transfer personal data to security authorities without the user, as the data subject, being able to take legal steps. Therefore, it is possible that U.S. authorities (e.g., intelligence agencies) process, evaluate, and permanently store user data located on servers in the USA for monitoring purposes. We have no influence over these data processing activities.


Withdrawal of Consent for Data Processing

Many data processing operations are only possible with the user's explicit consent. Given consent can be revoked at any time. The withdrawal of consent does not affect the lawfulness of data processing that occurred before consent was withdrawn.


Right to Object to Data Collection in Special Cases and Direct Advertising (Art. 21 GDPR) 

If data processing is carried out based on Art. 6(1)(e) or (f) of the GDPR, the user has the right to object at any time for reasons arising from their particular situation; this also applies to profiling based on these provisions. The relevant legal basis for processing can be found in this data protection statement. If a user objects, their personal data will no longer be processed, unless we can demonstrate compelling legitimate grounds for the processing that override the user's interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims (objection based on Art. 21(1) of the GDPR). If a user's personal data is processed for direct marketing purposes, the user has the right to object at any time to the processing of their personal data for such marketing; this also applies to profiling insofar as it is related to such direct marketing. If a user objects, their personal data will no longer be used for direct marketing purposes (objection based on Art. 21(2) of the GDPR).


Right to Lodge a Complaint with the Supervisory Authority 

In the event of a breach of the GDPR, data subjects have the right to lodge a complaint with the supervisory authority, particularly in the member state of their habitual residence, place of work, or place of the alleged infringement. The right to lodge a complaint does not affect any other administrative or judicial remedy.


Right to Data Portability 

The user has the right to have data, which we process automatically based on their consent or in fulfillment of a contract, handed over to themselves or to a third party in a commonly used, machine-readable format. If the user requests the direct transfer of data to another data controller, this will be done only to the extent that it is technically feasible.


Information, Deletion, and Correction 

Under applicable legal provisions, the user has the right to obtain free information about stored personal data, its origin, recipient, and purpose of data processing, as well as, where appropriate, the right to correct or delete this data. The user can contact us for this purpose at any time and in case of further questions regarding personal data.


Right to Restrict Processing

The user has the right to request the restriction of processing of their personal data. To exercise this right, the user can contact us at any time. The right to restrict processing exists in the following cases:

  • • If the user disputes the accuracy of their personal data stored by us, we usually need time to verify this. During the verification period, the user has the right to request the restriction of processing their personal data.
  • • If the processing of the user's personal data is unlawful, but the user opposes its erasure and requests the restriction of its use instead.
  • • If we no longer need the user's personal data, but the user needs it for the establishment, exercise, or defense of legal claims, they have the right to request the restriction of processing their personal data instead of its erasure.
  • • If the user has objected to processing pursuant to Art. 21(1) of the GDPR, a balance must be struck between their interests and ours. As long as it is not yet clear whose interests prevail, the user has the right to request the restriction of processing their personal data.

If the user has restricted the processing of their personal data, such data may – apart from being stored – only be processed with the user's consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or a member state.


SSL or TLS Encryption 

For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the website operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data you transfer to us cannot be read by third parties.


4. Data collection on this website


Cookies

Our websites use so-called "cookies." Cookies are small data packets that do not cause any harm to the user's terminal device. They are either stored temporarily for the duration of a session (session cookies) or permanently (persistent cookies) on the user's terminal device. Session cookies are automatically deleted after the end of the visit. Permanent "cookies" remain stored on the user's terminal device until they are deleted by the user or are automatically deleted by the internet browser.

In some cases, cookies from third-party companies may also be stored on the user's terminal device after entering our site (third-party cookies). They allow us or the user to use certain services of the third-party company (e.g., cookies for processing payment services).
Cookies serve various purposes. Many cookies are technically necessary because certain functions of the website would not work without them (e.g., shopping cart function or displaying videos). Other cookies are used to evaluate user behavior or display advertisements.
Cookies that are necessary to carry out the electronic communication process or to provide certain functions requested by the user (e.g., for the shopping cart function) or to optimize the website (e.g., cookies for measuring website traffic) (necessary cookies) are stored on the basis of Art. 6(1)(f) of the GDPR, unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimized provision of its services. If consent to the storage of cookies and comparable technologies is requested, processing is carried out exclusively on the basis of this consent (Art. 6(1)(a) of the GDPR); consent can be revoked at any time.

The user can configure their browser to be informed about cookie settings and to allow cookies only in specific cases, exclude the acceptance of cookies for certain cases, or generally, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.
Insofar as cookies are used by third-party companies or for analytical purposes, we will inform the user separately within the scope of this data protection statement and, if necessary, request their consent. 


Server Log Files 

The website provider automatically collects and stores information in what are known as server log files, which the user's browser automatically transmits to us. These are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address

These data are not merged with other data sources. These data are collected on the basis of Art. 6(1)(f) of the GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website – for this purpose, server log files must be recorded.


Contact Form

These data are not merged with other data sources. The collection of this data is based on Art. 6(1)(f) of the GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website – for this purpose, server log files must be recorded.


Inquiries Sent by Email, Phone, or Fax

If the user contacts us by email, phone, or fax, their inquiry, including all personal data resulting from it (name, inquiry), will be stored and processed by us for the purpose of processing the user's inquiry. We do not pass on this data without the user's consent. Processing of these data is based on Art. 6(1)(b) of the GDPR, if the user's inquiry is related to the performance of a contract or is necessary for the implementation of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective processing of the inquiries sent to us (Art. 6(1)(f) of the GDPR) or on the user's consent (Art. 6(1)(a) of the GDPR), if this has been requested; the consent can be revoked at any time.

Data transmitted to us via contact requests will be stored by us until the user requests deletion, revokes their consent for storage, or the purpose for data storage no longer applies (e.g., after processing of the user's inquiry has been completed). Mandatory statutory provisions – in particular statutory retention periods – remain unaffected.


5. Plugins and Tools


Vimeo without Tracking (Do-Not-Track) 

This website uses plugins from the video portal Vimeo. The provider is Vimeo Inc, 555 West 18th Street, New York, New York 10011, USA. When a user visits one of our pages with embedded Vimeo videos, a connection to Vimeo's servers is established. Through this connection, Vimeo's server knows which of our pages the user has visited. Vimeo also obtains the user's IP address. However, we have configured Vimeo in a way that it won't track user activity and won't set any cookies. The use of Vimeo serves the purpose of presenting our online offers attractively. This constitutes a legitimate interest in accordance with Art. 6(1)(f) of the GDPR. If appropriate consent has been obtained, processing is based solely on Art. 6(1)(a) of the GDPR; consent can be revoked at any time. Data transfer to the USA is based on the standard contractual clauses of the EU Commission and, according to Vimeo, on "legitimate business interests".
Details can be found here: https://vimeo.com/privacy For more information about user data processing, please refer to Vimeo's privacy policy at: https://vimeo.com/privacy.



Xing Plugin

Our website uses features of the XING network. The provider is XING AG, Dammtorstraße 29-32, 20354 Hamburg, Germany.
Every time one of our pages containing XING features is accessed, a connection to XING's servers is established.
As far as we know, no personal data is stored in this process. In particular, no IP addresses or user behavior are stored. More information about data protection and the XING Share button can be found in XING's privacy policy at:  https://privacy.xing.com/de/datenschutzerklaerung


LinkedIn Plugin

Our website uses features of the LinkedIn network. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland.

Whenever one of our pages containing LinkedIn features is visited, a connection to LinkedIn's servers is established. As far as we know, no personal data is stored in this process. In particular, no IP addresses or user behavior are stored.

More information about data protection and the LinkedIn Share button can be found in LinkedIn's data protection statement at: 
https://www.linkedin.com/legal/privacy-policy


Google Fonts (local Hosting)

Ta witryna korzysta z tak zwanych czcionek Google Fonts, które są dostarczane przez Google w celu jednolitego wyświetlania czcionek. Czcionki Google Fonts są instalowane lokalnie. Nie ma połączenia z serwerami Google.
Więcej informacji na temat czcionek Google Fonts można znaleźć na stronie https://developers.google.com/fonts/faq oraz w oświadczeniu Google o ochronie danych: https://policies.google.com/privacy?hl=pl.


Google Maps

This site uses the Google Maps service. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. To use Google Maps features, it is necessary to save the user's IP address. This information is typically transmitted to Google's servers in the USA and stored there. The provider of this website has no influence on this data transmission. In the case of Google Maps activation, Google may use Google Fonts for consistent font display. When Google Maps is called up, the browser loads the required web fonts into the browser's cache to properly display texts and fonts. The use of Google Maps is for the purpose of presenting our online offers attractively and facilitating the easy location of places indicated on our website. This constitutes a legitimate interest in accordance with Art. 6(1)(f) of the GDPR. If appropriate consent has been obtained, processing is based solely on Art. 6(1)(a) of the GDPR, provided that the consent includes storing cookies or accessing information on the user's end device (e.g., fingerprint scanning). Consent can be revoked at any time. Data transfer to the USA is based on the standard contractual clauses of the EU. Details can be found here:  https://privacy.google.com/businesses/gdprcontrollerterms/ and https://privacy.google.com/businesses/gdprcontrollerterms/sccs/.
For more information about user data processing, please refer to Google's privacy policy: https://policies.google.com/privacy?hl=pl


HN Experts Sp. z o.o.
ul. Złota 59
00-120 Warszawa
+48 605 509 540
This site uses cookies to provide a more enjoyable browsing experience.

Privacy policy and use of cookies