The privacy policy contains information on the processing of personal data and cookies used in connection with the use of the website, available at:https://bhpinvest.pl/, run by Jakub Hab operating under the name JAKUB HAB BHP INVEST.
Additionally, the Privacy Policy contains information on the processing of personal data of persons contacting the Administrator by phone or e-mail.
If an agreement is concluded with the Administrator or the Administrator starts providing services, the Administrator provides detailed information regarding the processing of personal data that is not covered by the Privacy Policy.
Personal data are processed by the Administrator in accordance with the law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as: "GDPR". The website uses an SSL certificate to ensure secure communication.
The following definitions have been adopted in the Privacy Policy:
- Administrator – Jakub Hab running a business under the name JAKUB HAB BHP INVEST, whose permanent place of business and address for delivery is ul. Jana Karola Chodkiewicza 9/4, 31-532 Kraków, NIP: 6821761536, REGON: 368096207;
- Privacy Policy – this privacy policy;
- Website – website run by the Administrator, available at: https://bhpinvest.pl/;
- User (and in the plural Users, used interchangeably) – a natural person using the Website.
1. Personal data administrator
The administrator of personal data is Jakub Hab running a business under the name JAKUB HAB BHP INVEST, whose data has been indicated above, defined as: "Administrator".
Contact with the Administrator in all matters related to the processing of personal data is possible:
- by correspondence at Jan Karola Chodkiewicza 9/4, 31-532 Kraków;
- via e-mail, at the e-mail address: administrator@bhpinvest.pl.
Due to the scope and type of the Administrator's activities, the Administrator decided not to appoint a personal data protection officer.
2. Scope of personal data processing, purposes of processing, legal basis for processing, period during which personal data is processed
The scope of personal data processed, the purposes of processing, the legal basis for processing and the period during which personal data are processed have been defined separately for each type of User's activities.
2.1 Use of the Website – server logs
The use of the Website (like any other website) is carried out by sending queries to the server on which the Website is stored. Such queries remain saved in the server logs. As a consequence, technical data automatically sent by the web browser is processed (including, among others: date and time of using the Website, operating system, information about the web browser, IP address). The data stored in the server logs are not subject to connection and association with a specific person or User data processed in accordance with the principles specified below. Only people managing the server have access to server logs. The server on which the Website is stored is located in Poland.
The data contained in the server logs may potentially constitute Users' personal data, which is why information about them is included in the Privacy Policy. The purpose of processing such data is to enable the use of the Website and to ensure the correct and stable operation of the Website (legitimate interest of the Administrator - Article 6(1)(f) of the GDPR). The data is processed for the period required for technical reasons.
2.2. Users contacting the Administrator, including by phone and e-mail
When contacting the Administrator by phone, the User provides the data that he voluntarily discloses during the conversation and his telephone number. Providing data is voluntary, but in the case of a telephone number it is necessary to contact the Administrator.
When contacting the Administrator via e-mail, the User provides the data that he voluntarily includes in his message and his e-mail address. Providing data is voluntary, but in the case of an e-mail address it is necessary to contact the Administrator.
The data is processed in order to take action on behalf of the User before concluding a contract, if the User is interested in concluding a contract with the Administrator or otherwise cooperating with the Administrator (Article 6(1)(b) of the GDPR). Additionally, data is processed in order to establish or maintain contact with the User and for archival and statistical purposes (legitimate interest of the Administrator - Article 6(1)(f) of the GDPR), as well as for the possible establishment, defense or pursuit of claims (legitimate interest Administrator – Article 6(1)(f) of the GDPR).
The data is processed for the period necessary to contact the User. Additionally, the data is processed for the period necessary to secure the Administrator's interests, i.e. for the possible determination, defense or pursuit of claims and for the period of their use by the Administrator for archival and statistical purposes, as well as for the period of any actions taken before concluding the contract.
2.3. Users contacting the Administrator via the contact form available on the Website
When contacting the Administrator via the contact form available on the Website, the User provides his name and e-mail address, as well as other data that he voluntarily includes in his message. Providing data is voluntary, but in the case of name and e-mail address it is necessary to contact us via the contact form.
The data is processed in order to take action for the User before concluding a contract, if the User is interested in concluding a contract with the Administrator or otherwise cooperating with the Administrator (Article 6(1)(b) of the GDPR). Additionally, data is processed in order to establish or maintain contact with the User and for archival and statistical purposes (legitimate interest of the Administrator - Article 6(1)(f) of the GDPR), as well as for the possible establishment, defense or pursuit of claims (legitimate interest Administrator – Article 6(1)(f) of the GDPR).
The data is processed for the period necessary to contact the User and for the Administrator to respond to the User's message. Additionally, the data is processed for the period necessary to secure the Administrator's interests, i.e. for the possible determination, defense or pursuit of claims and for the period of their use by the Administrator for archival and statistical purposes, as well as for the period of any actions taken before concluding the contract.
3. Sources of personal data
Users' personal data are received directly from Users, partly transferred automatically in connection with the Users' use of the Website or undertaking particular activities on the Website.
4. Security of personal data
Personal data is collected and stored with due care, in accordance with the provisions governing the protection of personal data, while maintaining the necessary technical and legal measures.
5. Transfer of personal data
Personal data may be disclosed and transferred to entities providing various services to the Administrator, such as, among others: hosting, IT, HR and payroll services, legal, personal data processing, archiving, statistical, courier and postal services as well as the Administrator's employees and collaborators.
All such entities process data on the basis of contracts concluded with the Administrator and in a manner consistent with the provisions governing the protection of personal data.
6. Transfer of personal data to third countries
The administrator uses, among others: from services provided by Microsoft (Microsoft Corporation), Dropbox (Dropbox International Unlimited Company), Apple (Apple Distribution International Ltd.), Miradore (Miradore Limited) and Canva (Canva Pty Limited), which may process data outside the European Economic Area, declaring that the processing of personal data is in accordance with the GDPR. Data transfer is based on standard contractual clauses. Except for the use of indicated services, data is not transferred outside the European Economic Area.
7. Automated decision-making, including profiling
The processed personal data are not subject to automated decision-making, including profiling.
8. Rights of persons whose personal data are processed
Users whose personal data are processed generally have the following rights:
- the right to information about data processing and access to data;
- the right to rectify data;
- the right to delete data;
- the right to limit data processing;
- the right to object to data processing;
- the right to transfer data;
- the right to withdraw consent to data processing, within the scope of the consent given;
- the right to lodge a complaint with the supervisory authority.
The rights are described in detail in Art. 16-21 GDPR. It is necessary to pay attention to the following issues:
- not all of the above rights are absolute,
- The user always has the right to lodge a complaint with the supervisory authority, which is the President of the Personal Data Protection Office,
- Withdrawal of consent to the processing of personal data does not affect the lawfulness of the processing carried out on the basis of consent before its withdrawal,
- In case of any doubts as to the User's data being processed or the purposes of such processing, it is possible to contact the Administrator, in accordance with the data provided at the beginning of the Privacy Policy.
9. Cookies
Cookies are IT data - text files, saved on Users' end devices (e.g. computer, smartphone, tablet) when visiting websites. Cookies do not interfere with the integrity of Users' devices.
The website uses its own cookies to ensure proper functioning and third-party cookies, described below. The use of third-party cookies results from the use of services provided by third parties. By using cookies, especially third-party cookies, the Administrator may have access to information about Users, such as: information about the operating system and web browser, viewed subpages, time spent on the Website, clicks on links, age range. User, User's gender, approximate location of the User, User's interests. The data obtained through the use of cookies is not linked or associated with a specific person or Users' data processed in accordance with the principles set out above and is anonymous. However, they may potentially constitute Users' personal data.
Given that the information contained in cookies is collected by third parties, it is processed by these entities in accordance with the principles they apply, specified in their regulations and privacy policies.
The purpose of processing data obtained by the Administrator through the use of cookies is to ensure the correct and stable operation of the Website and statistical analysis of data (legitimate interest of the Administrator - Article 6(1)(f) of the GDPR).
The website uses two types of cookies:
- session cookies, which are temporary files stored on the end device until you leave the website or turn off the web browser,
- persistent cookies, which are stored on the end device for the time specified in the cookie parameters or until they are deleted.
The Administrator uses cookies based on the consent expressed by the User, with the exception of cookies necessary for the proper operation of the Website. During the first visit to the Website, a message is displayed asking for consent to the use of cookies and providing a mechanism for consenting to the use of individual cookies or their types. Cookies - with the exception of cookies necessary for the proper operation of the Website - remain blocked until the User consents to their use. Restricting the use of cookies may make it difficult to use the Website.
It is also possible to manage cookies within the web browser settings. Most browsers automatically allow the use of cookies, but it is usually possible to delete them using the browser settings. Below are links to websites containing information on cookie settings in the most popular web browsers:
- Mozilla Firefox: mozilla.org/pl/kb/usuwanie-cococzek;
- Internet Explorer: microsoft.com/kb/278835/pl;
- Microsoft Edge: https://support.microsoft.com/pl-pl/microsoft-edge/usuwanie-plik%C3%B3w-cookie-w-przegl%C4%85darce-microsoft- edge-63947406-40ac-c3b8-57b9-2a946a29ae09;
- Google Chrome: google.com/chrome/bin/answer.py? hl=pl&answer=95647;
- Safari: apple.com/pl-pl/HT201265;
- Safari (Desktop): apple.com/pl-pl/guide/safari/sfri11471/ mac;
- Opera: opera.com/pl/latest/security-and-privacy/ .
The Website uses cookies from Google LLC or Google Ireland Limited due to the use of the Invisible ReCAPTCHA plug-in. Cookies are automatically sent to Google servers, which may be located around the world (outside the European Economic Area), especially in the United States of America.
Google Analytics
The Administrator uses the Google Analytics service (web analytics system) provided by Google LLC to collect and analyze information about the Website. Google Analytics automatically collects information about the use of the Website by using cookies and sending it to Google servers, which may be located around the world, especially in the United States of America.
Google generally excludes the transmission of information enabling the identification of a given User. In addition, the IP address anonymization function has been activated, as a result of which Users' IP addresses are shortened within the European Economic Area. However, in special cases it is possible to transmit the full IP address to Google servers located outside the European Economic Area. The anonymized IP address transmitted by the User's browser as part of Google Analytics is generally not combined with other Google data.
Because Google uses technical infrastructure located in the US, it uses compliance mechanisms such as standard contractual clauses. Google Analytics and Google Analytics 360 are certified by the independent security standard ISO 27001.
As part of Google Analytics, the Administrator has access only to anonymous information, such as information about the User's operating system and web browser, time spent on the website, User's gender, approximate age of the User, approximate location of the User, etc.
To disable Google Analytics, please use the information available at: tools.google.com/dlpage/gaoptout and the add-on available there. More information about Google Analytics can be found at: www.google.com/analytics/.
Google's privacy policy is available: https://policies.google.com/privacy?hl=pl# infochoices.