PRIVACY POLICY
- GENERAL INFORMATION
1.1. The purpose of this Privacy Policy (the “Policy”) is to provide information regarding the processing of Personal Data (as defined below) in connection with the business activities conducted by the company LOUD DATA spółka z ograniczoną odpowiedzialnością with its registered office in Warsaw.
1.2. Personal data shall be understood as information relating to an identified or identifiable natural person (“Personal Data”). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name and surname, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person, including device IP, location data, an online identifier, and information collected via cookies and other similar technology.
1.3. This Policy is for informational purposes only. This means that it does not constitute a source of obligations for you.
1.4. We wish to inform you that we attach great importance to the issues of security and legal compliance of the processing of your Personal Data. Therefore, we always process your Personal Data in accordance with applicable laws, in particular, but not limited to, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (“GDPR”). For this reason, we commit to exercising the utmost diligence to protect your Personal Data, primarily through the application of high-quality technical security measures protecting such data against unauthorized access by third parties.
- PERSONAL DATA CONTROLLER
2.1. The controller of your Personal Data is the company operating under the name LOUD DATA sp. z o.o. with its registered office in Warsaw, address: Dywizjonu 303 149B/52, 01-471 Warsaw, Poland, entered into the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register under KRS number 0001002233, REGON: 52365836400000, NIP: 5252931025 (“Controller” or “We”).
2.2. We have not appointed a Data Protection Officer. In all matters related to the processing of your Personal Data, you may contact us in the following manner:
2.2.1. by post to the address: LOUD DATA sp. z o.o. with its registered office in Warsaw, address: ul. Dywizjonu 303 149B/52, 01-471 Warsaw, Poland;
2.2.2. by telephone at the number: +48 696 756 139; or
2.2.3. via e-mail: hello@louddata.com
- SOURCE OF PERSONAL DATA
3.1. We obtain your Personal Data: (a) directly from you, (b) from your employer / the entity you represent, (c) from publicly available registers (CEIDG – Central Registration and Information on Business, KRS – National Court Register) and business information databases – for the purpose of contractor verification. Data categories: first name, last name, position, business e-mail address and telephone number, company details.
- PURPOSES OF PROCESSING YOUR PERSONAL DATA
4.1. Your Personal Data may be processed for various purposes and on various legal bases. Below you will find the purposes, legal bases, and retention periods for the processing of your Personal Data:
PURPOSE LEGAL BASIS RETENTION PERIOD
|
Providing services by electronic means in terms of making content collected on the website in the louddata.com domain available |
Art. 6(1)(b) GDPR – performance of a contract |
For the duration of providing services by electronic means |
|
Collecting analytical and statistical data generated in connection with your use of the website in the louddata.com domain |
Art. 6(1)(f) GDPR – legitimate interest of the Controller |
For a period of 3 (three) years |
|
Identifying the sender and handling their inquiry sent via the form provided on the website in the louddata.com domain, by e-mail, by telephone, or by traditional post |
Art. 6(1)(f) GDPR – legitimate interest of the Controller |
For a period of 1 (one) year |
|
Providing the newsletter distribution service (commercial information) |
Art. 6(1)(b) GDPR – performance of a contract |
For the duration of providing the newsletter service |
|
Providing services in the field of conducting conferences, workshops, webinars, and training sessions Assessing your qualifications, abilities, and skills for work in the position for which you are applying |
Art. 6(1)(b) GDPR – performance of a contract. The legal basis for data processing is also our legitimate interest in organizing the event, including ensuring the participation of participants. Art. 22(1) § 1 of the Labor Code – processing necessary to conclude an employment contract; Art. 6(1)(f) GDPR – legitimate interest of the Controller (regarding data collected during the interview); Art. 6(1)(a) GDPR – your consent to the processing of data for the purposes of future recruitment. |
For a period of 1 (one) year from the end of the event Until the end of the recruitment process for the position you are applying for; if you have given separate consent for future recruitments, we will store your data for 2 (two) years from the moment of collection. |
|
Conclusion and performance of a contract concluded between the Controller and the entity with which you cooperate or work – if you are a person designated by that entity as a contact person or a representative of such an entity being a legal person |
Art. 6(1)(f) GDPR – legitimate interest of the controller, which is the performance of the contract between the controller and another entity, protection of rights, pursuit of claims, and defense against claims |
The period of performing contractual obligations and the limitation period for claims resulting from regulations |
|
Archiving to the extent necessary to perform legal obligations, in particular tax and accounting regulations |
Art. 6(1)(c) GDPR – performance of an obligation imposed by law |
For the period resulting from these regulations |
|
Establishing and pursuing claims or defending against claims, including the sale of receivables |
Art. 6(1)(f) GDPR – realization of the legitimate interest of the controller in the form of |
For the duration of the proceedings and the limitation period for potential claims |
|
establishing and pursuing claims and defending against claims |
||
|
Verifying the quality of services provided by us, the quality of service, and customer satisfaction |
Art. 6(1)(f) GDPR – realization of the legitimate interest of the controller in the form of determining the quality of services, quality of service, and customer satisfaction |
For the duration of the cooperation and for no longer than 24 months after its termination, for the purpose of conducting customer satisfaction surveys and assessing the quality of services |
- PERSONAL DATA RETENTION PERIODS
5.1. The duration of your Personal Data processing:
5.1.1. If the processing of Personal Data is carried out for the purpose of presenting Our commercial information (e.g., newsletter), including Our offers – the Personal Data will be stored until you opt out of receiving commercial information.
5.1.2. If the processing of Personal Data is based on voluntarily given consent, the Personal Data will be stored until the withdrawal of consent for the processing of Personal Data for specific, explicit, and legitimate purposes. Consent for the processing of Personal Data may be withdrawn at any time. Withdrawal of consent for the processing of Personal Data is performed by contacting the Controller in the manner indicated in section 2.2 above. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
5.1.3. If the processing of Personal Data is necessary for the performance of a contract or to take steps at your request prior to entering into a contract, the Personal Data will be processed for the duration of the contract, and after that period, for the limitation period for potential claims resulting from generally applicable provisions of law.
5.1.4. If the processing is necessary to fulfill a legal obligation incumbent on the Controller, the Personal Data will be processed for the period resulting from generally applicable provisions of law.
5.1.5. If the processing is necessary for purposes resulting from the legitimate interests pursued by the Controller, the Personal Data will be processed for a period no longer than is necessary for the purposes for which the Personal Data are processed, or until an objection is lodged against the processing of Personal Data within the scope of processing for these purposes, for reasons related to your particular situation, unless the Controller demonstrates the existence of compelling legitimate grounds for processing that override your interests, rights, and freedoms, including grounds related to the establishment, exercise, or defense of claims.
5.2. In each case, the longer period of Personal Data processing shall prevail.
6. MANDATORY AND VOLUNTARY PROVISION OF PERSONAL DATA
6.1. If Personal Data are processed based on your consent, providing Personal Data is voluntary. Failure to provide data will result in the inability to fulfill a given purpose if consent is a condition for its fulfillment.
6.2. If personal data are processed for purposes necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract, providing Personal Data is voluntary but necessary to conclude the contract with the Controller.
6.3. If the processing of Personal Data is necessary to fulfill a legal obligation incumbent on the Controller, providing Personal Data is a statutory requirement.
6.4. If Personal Data are processed for purposes resulting from the legitimate interests pursued by Us, providing Personal Data is voluntary but necessary for the realization of these purposes.
- YOUR RIGHTS
7.1. You have the following rights related to Our processing of your Personal Data:
7.1.1. Right of access to Personal Data – on this basis, the Controller provides the person making the request with information about the processing of data, including, above all, the purposes and legal bases of processing, the scope of data held, entities to which they are disclosed, and the planned date of data erasure;
7.1.2. Right to obtain a copy of the data – on this basis, the Controller provides a copy of the processed data concerning the natural person making the request;
7.1.3. Right to rectification – on this basis, the Controller is obliged to remove any inconsistencies or errors in the processed personal data and to supplement them if they are incomplete;
7.1.4. Right to erasure (right to be forgotten) – on this basis, you may request the erasure of data whose processing is no longer necessary to fulfill any of the purposes for which they were collected;
7.1.5. Right to restriction of processing – if such a request is made, the Controller ceases to perform operations on personal data – except for operations to which you have consented – and their storage, in accordance with adopted retention principles or until the reasons for restricting data processing cease to exist (e.g., a decision of a supervisory authority is issued allowing for further data processing);
7.1.6. Right to object to data processing – you may object to the processing of personal data at any time, without the need to justify such an objection;
7.1.7. Right to data portability – on this basis, to the extent that the data are processed in an automated manner in connection with a concluded contract or given consent, the Controller issues the data provided by the data subject in a computer-readable format. It is also possible to request that these data be sent to another entity, provided, however, that technical possibilities exist in this regard on the part of both the Controller and the indicated entity;
7.1.8. Right to lodge a complaint – if you consider that the processing of your personal data violates the provisions of the GDPR or other provisions regarding the protection of personal data, you may lodge a complaint with the authority supervising the processing of personal data, competent for your place of habitual residence, your place of work, or the place of the alleged infringement. In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
- RECIPIENTS OF YOUR PERSONAL DATA
8.1. The anticipated recipients of your Personal Data are:
8.1.1. other controllers who process personal data in their own name:
(a) public authorities,
(b) entities that cooperate with us in handling bookkeeping, accounting, tax, and legal matters – to the extent they become data controllers;
8.1.2. entities that process personal data on our behalf:
(a) entities affiliated with the Controller within the meaning of Article 11a(1)(4) of the Corporate Income Tax Act,
(b) entities that support Us in providing services to you,
(c) entities that operate ICT systems and provide IT services,
(d) entities that provide us with advisory, consulting, auditing, legal, tax, and accounting assistance services,
(e) entities that provide document archiving services,
(f) our subcontractors, i.e., entities that perform a service for us or provide goods,
to the extent necessary to achieve the purposes of processing your personal data.
9. TRANSFER OF PERSONAL DATA OUTSIDE THE EUROPEAN ECONOMIC AREA
9.1. As a rule, Personal Data will not be transferred outside the European Economic Area (“EEA”). However, taking into account the provision of services by our subcontractors in the performance of support for ICT services and IT infrastructure, the Controller may commission specific IT activities or tasks to recognized subcontractors operating outside the EEA, which may result in the transfer of your data outside the EEA. According to the decision of the European Commission, the recipient countries outside the EEA to which your personal data may be transferred must ensure an adequate level of personal data protection consistent with EEA standards.
9.2. In connection with the above, as part of our use of tools supporting our day-to-day activities, your Personal Data may be transferred to a country outside the European Economic Area where the entity cooperating with us maintains tools used for processing Personal Data.
9.3. In the case of recipients in the territory of countries not covered by a decision of the European Commission, in order to ensure an adequate level of such protection, we will fulfill the obligations incumbent upon Us so that such transfer of Personal Data takes place in accordance with the law.
- PROFILING
10.1. The Controller uses profiling, which consists of analyzing the User’s activity within the Website in order to present a personalized marketing offer. Such profiling does not lead to automated decision-making that produces legal effects or similarly significantly affects the User within the meaning of Art. 22 of the GDPR. The User has the right to an unconditional objection to profiling for the purpose of direct marketing.
- COOKIES AND SIMILAR TECHNOLOGY
11.1. What are cookies?
11.1.1. Cookies are small text files installed on your device when you browse the Website.
11.1.2. Cookies collect information that facilitates the use of the website – for example, by remembering visits and actions performed by you.
11.2. What data of yours do we use?
11.2.1. We may process data regarding the manner in which you use the Website via a computer, phone, tablet, or any other device through which you access websites. Some of this data, in combination with other information, may constitute personal data. Through the applied internet technologies, we may process, for example:
(a) the name of the website from which the cookies originate, their storage period on the terminal device, and their unique number;
(b) device data (e.g., device type/model, unique device identifiers, MAC address, IP address, operating system, operating system version and device settings, language settings, screen resolution, browser type and version);
(c) events (e.g., time of website use, last visit to the website, duration of the visit, types of pages and subpages visited, the specific step reached by the user during the shopping process);
(d) location data (e.g., IP address, information about your location obtained through various positioning technologies);
(e) other data: information on the use of the websites (e.g., referral source, the advertising campaign from which you accessed the site, links clicked, advertisements viewed, and consents granted via the cookie banner).
11.3. How we collect and use cookies:
11.3.1. The Controller collects and uses the following cookies:
(a) Strictly necessary cookies
(i) The Controller uses strictly necessary cookies primarily to provide you with the services and functionalities of the Website that you wish to use. Strictly necessary cookies may only be installed by the Controller via the Website.
(ii) The legal basis for processing data in connection with the use of strictly necessary cookies is the necessity of processing for the performance of a contract (Art. 6(1)(b) of the GDPR) and the Controller’s legitimate interest in ensuring the operation of the Website.
(b) Functional cookies
(i) Functional cookies are used to remember and adapt the Website to your choices and may be installed by the Controller and its partners via the Website.
(ii) The legal basis for processing Personal Data in connection with the use of functional cookies by the Controller is a consent granted by the user (Art. 6(1)(a) of the GDPR).
(iii) The processing of Personal Data in connection with the use of functional cookies is subject to obtaining your consent for the use of (separately) functional and analytical cookies. This consent may be withdrawn at any time via this platform.
(c) Analytical cookies
(i) Analytical cookies enable the acquisition of information such as the number of visits and traffic sources on the Website. They are used to determine which pages are more or less popular and to understand how you navigate the Website by maintaining statistics on Website traffic. The data is processed in order to improve the performance of the Website and may be installed by the Controller and its partners via the Website.
(ii) The legal basis for processing Personal Data in connection with the use of analytical cookies by the Controller is a consent granted by the user (Art. 6(1)(a) of the GDPR).
(iii) The processing of Personal Data in connection with the use of analytical cookies is subject to obtaining your consent for the use of (separately) analytical cookies. This consent may be withdrawn at any time via this platform.
(d) Marketing cookies
(i) Advertising (marketing) cookies allow for the adjustment of displayed advertising content to your interests within and outside the Website. You are profiled based on the information from these cookies and your activity. Advertising cookies may be installed by the Controller and its partners via the Website.
(ii) The legal basis for processing Personal Data in connection with the use of advertising cookies by the Controller for this purpose is its legitimate interest (Art. 6(1)(f) of the GDPR).
(iii) The processing of Personal Data using cookies is possible after obtaining consent, which may be withdrawn at any time.
11.4. Analytical and marketing tools used by the Controller’s partners
11.4.1. The Controller and its partners employ various solutions and tools for analytical and marketing purposes. Basic information regarding these tools is provided below.
Detailed information in this regard can be found in the privacy policy of the respective partner.
(a) Consent Management Mechanism (Cookie Banner)
(i) To provide you with full control over your privacy, we have implemented a consent management tool.
(ii) This tool stores a cookie on your device solely to remember your preferences regarding consents for other cookies (e.g., analytical cookies). As a result, we do not need to ask for your choice every time the page reloads.
(iii) Necessary cookies (you cannot disable them, as we would otherwise be unable to respect your choices).
(b) Google Analytics 4 (GA4) with Google Consent Mode v2
(i) We aim to develop our website to be as useful to you as possible. To this end, we use the Google Analytics 4 analytical tool provided by Google LLC.
(ii) This tool allows us to analyze website traffic – we monitor, among other things, which articles are read most frequently, how much time you spend on the site, and the sources from which you arrive. We have implemented Google Consent Mode v2. This means that Google Analytics collects full data about your visit only if you grant explicit consent via our cookie banner. If you refuse, the tool will operate in a strictly limited mode, without storing cookies on your device and collecting only fully anonymized signals that do not allow for identification.
(iii) Analytical cookies (activated only with your consent).
(c) Google Tag Manager (GTM)
(i) We use Google Tag Manager for the efficient management of all scripts on the website.
(ii) GTM is a tool that, in itself, typically does not collect personal data or store its own tracking cookies. It serves solely for the controlled activation of other tools (such as Google Analytics) strictly according to the rules dictated by your choices in the consent banner.
11.5. Managing cookie settings
11.5.1. The use of cookies to collect data through them, including gaining access to data stored on your device, requires your consent. This consent may be withdrawn at any time.
11.5.2. Consent is not required only for cookies whose use is essential for providing a telecommunication service (data transmission for the purpose of displaying content). Disabling technical cookies may affect your user experience on the Website. Without their acceptance, we cannot guarantee the full stability of the Website or the correct functioning of your individual settings. In extreme cases, this may prevent you from placing an order or using your Customer account.
11.5.3. Consent for the use of cookies may be withdrawn via your browser settings. You can verify the status of your current privacy settings for the browser you are using at any time by utilizing the tools available at the following links: http://www.youronlinechoices.com/pl/twojewybory or http://optout.aboutads.info/?c=2&lang=EN.
Below you will find links to official instructions for managing cookies in the most popular browsers:
Google Chrome: Clear, allow and manage cookies in Chrome
Mozilla Firefox: Cookies – Information that websites store on your computer
Safari (macOS): Manage cookies and website data in Safari on Mac
Microsoft Edge: Delete and manage cookies
11.6. How long will the information collected by cookies be stored?
11.6.1. The storage period for cookies on your terminal device depends on whether the cookies are “persistent” or “session-based.”
11.6.2. Persistent cookies – these are not deleted upon closing the browser and remain on your device for a specified period or indefinitely, depending on the website’s settings.
11.6.3. Session cookies – these are placed for the duration of the browser use (the session) and are deleted upon closing the browser.
11.6.4. Part of the Personal Data may be stored for a longer period in the event that you have any claims against the Controller, or for the purpose of the Controller pursuing claims or defending against claims (including those of third parties), for the limitation period specified by law, in particular the Civil Code.
11.6.5. More information regarding the processing of personal data can be found above.
12. HOW DO WE SECURE YOUR DATA?
12.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Controller implements appropriate technical and organizational measures to ensure a level of security appropriate to the risks and the categories of data protected. In particular, the Controller safeguards data against unauthorized disclosure, acquisition by an unauthorized person, processing in violation of applicable regulations, as well as against alteration, loss, damage, or destruction. Disclosing information regarding the technical and organizational measures used to protect processing externally may undermine their effectiveness, thereby compromising the proper protection of Personal Data.
- CHANGES TO THE POLICY
13.1. The Controller may amend this Policy in the future. In each such case, information regarding the change will be posted on the Website. With every amendment, a new version of the Policy will appear with a new date.
13.2. This Policy is effective as of May 1, 2026.