GDPR Information Obligation
The following information is a concise, understandable, and clear summary of the information contained in Privacy Policy Regarding the Data Controller, the purpose and manner of processing personal data, and your rights in connection with this processing, in the form required to fulfill the GDPR information obligation. Details regarding the processing method and the entities involved in this process are available in the indicated policy.
Who is the data controller?
The Data Controller (hereinafter the Controller) is „Maxie Hill Sp. z o.o.”, operating at the address: Św. Marcin 29/8, 61-806 Poznań, with the tax identification number (NIP): 7831725809, National Court Register number (KRS): 0000556122, providing services electronically through the Service
How can I contact the data administrator?
You can contact the Administrator in one of the following ways
-
Mailing address Maxie Hill Sp. z o.o., Św. Marcin 29/8, 61-806 Poznań
-
Email address office@maxiedisc.com
-
Phone call – +48 570 490 040
-
Contact Form – available at: /contact
Did the Administrator appoint a Data Protection Officer?
On the basis of Art. 37 of the GDPR, the Controller did not appoint a Data Protection Officer.
In matters concerning data processing, including personal data, please contact the Administrator directly.
Where do we get personal data from, and what are its sources?
The data is obtained from the following sources:
- from data subjects
- in the case of registration using social media portals, with the expressed informed consent of those persons, from these social media portals
What is the scope of personal data we process?
The service processes personal data ordinary, voluntarily provided by the individuals concerned
(e.g., name, username, email address, phone number, IP address, etc.)
The detailed scope of data processed is available in Privacy Policy.
What are the purposes for which we process data?
Personal data voluntarily provided by Users are processed for one of the following purposes:
- Electronic service delivery:
- User account registration and maintenance services on the Website and related functionalities
- Newsletter Services (including transmission of advertising content with consent)
- Communication of the Administrator with Users regarding the Service and data protection
- Ensuring the Legally Justified Interest of the Data Controller
What are the legal bases for data processing?
The service collects and processes User data based on:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Art. 6(1)(a)
the data subject has given consent to the processing of their personal data for one or more specified purposes - Article 6(1)(b)
processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract - Art. 6 sec. 1 lit. f
processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party
- Art. 6(1)(a)
- Act of May 10, 2018, on the Protection of Personal Data (Journal of Laws 2018, item 1000)
- Act of July 16, 2004, Telecommunications Law (Journal of Laws 2004 No. 171 item 1800)
- Act of February 4, 1994, on Copyright and Related Rights (Journal of Laws 1994 No. 24 item 83)
What is the legitimate interest pursued by the Controller?
- For the purpose of potential establishment, investigation, or defense against claims – the legal basis for processing is our legitimate interest (Art. 6(1)(f) GDPR) in protecting our rights, including, but not limited to;
- To assess the risk of potential clients
- To evaluate planned marketing campaigns
- For the purpose of direct marketing
For what period do we process personal data?
As a rule, the indicated personal data are stored only for the period of service provision within the Administrator's service. They are deleted or anonymized within a period of up to 30 days from the date of service termination (e.g., deletion of a registered user account, unsubscribing from the Newsletter, etc.)
In exceptional situations, in order to secure a legally justified interest pursued by the Administrator, this period may be extended. In such a situation, the Administrator will store the indicated data from the time of the User's request for their deletion, for no longer than 3 years in the event of a breach or suspected breach of the service regulations by the person concerned.
Who is the recipient of the personal data in this personal data?
As a general rule, the sole recipient of the data is the Administrator.
However, data processing may be entrusted to other entities that provide services to the Data Controller for the purpose of maintaining the Service's operations.
Among others, the following entities can be included:
- Hosting companies providing hosting or related services to the Administrator
- Companies through which the Newsletter service is provided
Will your personal data be transferred outside the European Union?
Personal data will not be transferred outside the European Union, unless they are published as a result of the User's individual action (e.g., entering a comment or post), which will make the data available to anyone visiting the website.
Will personal data be the basis for automated decision-making?
Personal data will not be used in automated decision-making (profiling).
What are your rights regarding the processing of personal data?
-
Right to access personal data
Users have the right to access their personal data, which is exercised upon a request submitted to the Administrator. -
Right to rectification of personal data
Users have the right to request from the Controller the immediate correction of personal data that is inaccurate and/or the completion of incomplete personal data, to be exercised by a request submitted to the Controller. -
Right to erasure of personal data
Users have the right to request immediate deletion of personal data from the Administrator, exercised by submitting a request to the Administrator.When it comes to user accounts, data deletion means anonymizing data that allows for user identification.
For the Newsletter service, the User has the option to delete their personal data independently by using the link included in every email sent.
-
The right to restrict the processing of personal data
Users have the right to restrict the processing of personal data in cases specified in Article 18 of the GDPR, including disputing the accuracy of personal data, which is exercised upon a request made to the Administrator. -
Right to data portability
Users have the right to obtain from the Administrator personal data concerning the User in a structured, commonly used, machine-readable format, exercised upon request submitted to the Administrator. -
Right to object to the processing of personal data
Users have the right to object to the processing of their personal data in cases specified in Article 21 of the GDPR, exercised upon a request submitted to the Controller. -
Right to lodge a complaint
Users have the right to lodge a complaint with the supervisory authority responsible for data protection.