Privacy Policy
1. Definitions
1.1. Controller – Dariusz Lockau, Wilmersdorfer Str. 142, 10585 Berlin, Germany.
1.2. Personal data – information relating to an identified or identifiable natural person, including the device IP address, location data, online identifier, and information collected through cookies and other similar technologies.
1.3. Policy – this Privacy Policy.
1.4. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC.
1.5. Website – the website operated by the Controller at https://ksiegowy.de.
1.6. User – any natural person visiting the Website or using one or more of the services or functionalities described in this Policy.
2. Processing of data in connection with the use of the Website
2.1. In connection with the User's use of the Website, the Controller collects data necessary to provide the individual services offered, as well as information about the User's activity on the Website. The detailed rules and purposes for processing Personal Data collected while the User uses the Website are described below.
3. Purposes and legal bases for processing data on the Website
Use of the Website
3.1. The personal data of all persons using the Website (including IP addresses or other identifiers and information collected through cookies or similar technologies) are processed by the Controller:
3.1.1. for the purpose of providing electronic services involving access to content available on the Website – the legal basis is the necessity of processing for the performance of a contract (Art. 6(1)(b) GDPR);
3.1.2. for analytical and statistical purposes – the legal basis is the legitimate interest of the Controller (Art. 6(1)(f) GDPR), consisting of analysing User activity and preferences in order to improve the functionalities used and the services provided;
3.1.3. for the possible establishment and pursuit of claims or defence against claims – the legal basis is the legitimate interest of the Controller (Art. 6(1)(f) GDPR), consisting of protecting its rights.
3.2. The User's activity on the Website, including Personal Data, is recorded in system logs. The information collected in the logs is processed primarily for purposes related to the provision of services, as well as for technical and administrative purposes, to ensure the security and management of the IT system, and for analytical and statistical purposes (Art. 6(1)(f) GDPR).
4. Mechanisms and methods of data processing
Contact forms
4.1. The Controller provides the possibility of contacting it through electronic contact forms (the website form and the “call me back” widget) or via chat. Providing data marked as mandatory is required to receive and process an enquiry. Failure to provide such data means that a response cannot be provided.
4.2. Personal data are processed for the purpose of identifying the sender and handling their enquiry submitted through the available form – the legal basis is the necessity of processing for the performance of a service contract or for taking steps prior to entering into such a contract (Art. 6(1)(b) GDPR).
5. Marketing
5.1. The Controller processes Users' Personal Data for marketing purposes, which may include displaying marketing content (contextual advertising) and, where the User provides separate consent, sending notifications about relevant offers or content (newsletter service, see below).
Contextual advertising
5.2. The Controller processes Users' Personal Data for marketing purposes in connection with displaying advertisements to Users (including through Meta Ads). Processing is based on the legitimate interest of the Controller (Art. 6(1)(f) GDPR). Where cookies are used for this purpose, they are used only with the User's consent given through the cookie banner.
Newsletter
5.3. The Controller does not currently operate a newsletter service. If such a service is introduced in the future, it will only be provided to persons who voluntarily provide their email address and give their consent. This Policy will then be updated with detailed rules concerning the processing of data for this purpose.
6. Social media
6.1. The Controller processes Personal Data of Users who visit the Controller's profiles on social media (Facebook, Instagram) for the purpose of informing them about the Controller's activities and promoting its services and products. The legal basis is the legitimate interest of the Controller (Art. 6(1)(f) GDPR) in promoting its own brand. The processing of data by the social media platforms themselves is governed by their respective privacy policies.
8. Retention period for personal data
8.1. The period for which the Controller processes data depends on the type of service provided and the purpose of processing. As a rule, data are processed for the duration of the service, until consent is withdrawn or an effective objection is submitted.
8.2. The processing period may be extended where necessary to establish and pursue potential claims or defend against claims. After the processing period has expired, the data are permanently deleted or anonymised.
9. User rights
9.1. The User has the right to access their data and request its rectification, deletion or restriction of processing, the right to data portability and the right to object to the processing of their data, as well as the right to lodge a complaint with a supervisory authority.
9.2. Where the User's data are processed on the basis of consent, that consent may be withdrawn at any time by contacting the Controller or, in the case of cookies, by using the settings available on the Website.
9.3. To exercise the above rights, the User may contact the Controller by email at info@ksiegowy.de.
10. Data recipients
10.1. In connection with the provision of services, Personal Data may be disclosed to external entities, in particular providers responsible for IT systems and hosting, banks and payment operators, as well as providers of analytics and marketing tools listed in §7 (Google, Meta).
11. Transfer of data outside the EEA
11.1. Some of the providers listed in §7 (e.g. Google, Meta) may process data outside the European Economic Area (EEA). The Controller transfers data outside the EEA only while ensuring an appropriate level of protection, including through standard contractual clauses issued by the European Commission.
12. Security of personal data
12.1. The Controller continuously conducts risk assessments to ensure that Personal Data are processed securely, ensuring that access to data is granted only to authorised persons and only to the extent necessary for the performance of their duties.
13. Contact details
13.1. The Controller can be contacted at info@ksiegowy.de or by post at Wilmersdorfer Straße 142, 10585 Berlin, Germany.
14. Changes to the Privacy Policy
14.1. This Policy is continuously reviewed and updated when necessary, in particular when new analytics or marketing tools are introduced. The current version is always available at this address.