Privacy policy
ISON Care Sp. z o. o., ul. Sienna 73, 00-833 Warszawa, attaches particular importance to respecting the privacy of users visiting our website. The data collected in server logs is used only for the purposes of administering the website. We do not seek to identify website users.
Identification data is not associated with specific people browsing the ISON Care Sp. z o. o. website, with the exception of data provided by users in contact forms. To ensure the highest quality of the website, we occasionally analyze log files to determine which pages are visited most often, what web browsers are used, whether the website structure contains errors, etc.
Copyright
The content of the website is the property of ISON Care Sp. z o. o. All personal and proprietary copyrights to any elements of the website (text, graphics, page layout, etc.) are reserved.
The website and all its elements are protected by law, in particular the Act of 4 February 1994 on copyright and related rights (consolidated text, Journal of Laws 00.80.904, as amended), and the Act of 16 April 1993 on combating unfair competition (consolidated text, Journal of Laws 03.153.1503, as amended).
Personal data protection
Personal data means information relating to an identified or identifiable natural person
(“data subject”); an identifiable natural person is a person who can be identified,
directly or indirectly, in particular by an identifier such as name, identification number,
location data, an online identifier or one or more factors specific to the physical, physiological,
genetic, mental, economic, cultural or social identity of that natural person.
Users provide their personal data on the portal voluntarily.
Personal data controller
The controller (hereinafter the "Personal Data Administrator") is ISON Care Sp. z o. o., ul. Sienna 73, 00-833 Warsaw.
Data processing by the administrator
In connection with its business activity, the Administrator collects and processes personal data in accordance with applicable regulations,
in particular the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016
on the protection of natural persons with regard to the processing of personal data and on the free movement of such data,
repealing Directive 95/46/EC), and the data processing principles set out therein.
The Personal Data Administrator ensures transparency of data processing and always informs
about data processing at the time of collection, including the purpose and legal basis of processing —
e.g. when concluding a contract for the sale of goods or services. The Administrator ensures that data is collected only
to the extent necessary for the stated purpose and processed only for as long as necessary.
When processing data, the Administrator ensures its security, confidentiality and the data subject's access
to information about the processing. Should a personal data breach occur despite the security measures in place
(e.g. a data leak or loss), the Administrator will inform the affected data subjects in a manner consistent with the regulations.
How can you obtain further information about the processing of personal data?
For further information, please contact the Data Protection Officer (DPO) appointed by ISON Care. Contact details:
e-mail address: dane.info@isoncare.pl
postal address:
Data Protection Officer
ISON Care Sp. z o. o.
ul. Sienna 73
00-833 Warsaw
Data recipients
In connection with running a business that requires processing, personal data is disclosed to external entities,
in particular suppliers responsible for operating IT systems and equipment,
entities providing legal or accounting services, couriers, and marketing or recruitment agencies.
Data is also disclosed to entities related to the Administrator, including companies within its capital group.
The Administrator reserves the right to disclose selected information regarding a data subject
to competent authorities or third parties who request such information, based on an appropriate legal basis
and in accordance with applicable law.
Personal data processing period
The period of data processing by the Administrator depends on the type of service provided and the purpose of processing. The processing period may also result from legal provisions, where they constitute the basis for processing. Where processing is based on the Administrator's legitimate interest — e.g. for security reasons — data is processed for a period enabling the pursuit of that interest, or until an effective objection is raised. Where processing is based on consent, data is processed until consent is withdrawn. Where the basis for processing is the necessity to conclude and perform a contract, data is processed until the contract terminates.
The processing period may be extended where processing is necessary to establish or pursue claims, or to defend against claims, and thereafter only to the extent required by law. After the processing period ends, data is irreversibly deleted or anonymized.
Rights of data subjects
ISON Care Sp. z o.o. ensures that data subjects can exercise their rights under the GDPR.
Data subjects have the following rights:
- the right to information about the processing of personal data — on this basis the Administrator provides the requester with information about data processing, including in particular the purposes and legal basis of processing, the scope of data held, the entities to which it is disclosed, and the planned data deletion date.
- the right to obtain a copy of the data — on this basis the Administrator provides a copy of the processed data concerning the requester.
- the right to rectification — the Administrator is obliged to correct any inaccuracies or errors in the processed personal data and to complete it if incomplete.
- the right to erasure — on this basis you may request deletion of data whose processing is no longer necessary for any of the purposes for which it was collected.
- the right to restrict processing — upon such a request, the Administrator ceases to perform operations on the personal data (except for operations to which the data subject has consented) and stores it in accordance with the adopted retention rules, or until the reasons for restricting processing cease to exist.
- the right to data portability — to the extent that data is processed in connection with a concluded contract or given consent, the Administrator issues data provided by the data subject in a machine-readable format, and may transfer it to another entity where technically feasible.
- the right to object to processing for marketing purposes — the data subject may object at any time to the processing of personal data for marketing purposes, without needing to justify the objection.
- the right to object to other purposes of processing — the data subject may object to processing based on the Administrator's legitimate interest; the objection should include a justification.
- the right to withdraw consent — where data is processed on the basis of consent, the data subject may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
- the right to lodge a complaint — where processing is considered to infringe the GDPR or other data protection provisions, the data subject may lodge a complaint with the President of the Personal Data Protection Office.
Purposes and legal basis for processing
E-mail and traditional correspondence — where personal data is sent to the Administrator by e-mail or traditional correspondence unrelated to services provided to the sender or another contract concluded with them, the personal data contained in that correspondence is processed solely to communicate and resolve the matter it concerns.
Legal basis:
Article 6(1)(f) GDPR — the Administrator's legitimate interest in conducting correspondence addressed to it in connection with its business activity.
The Administrator processes only the personal data relevant to the matter concerned. All correspondence is stored
in a manner ensuring the security of the personal data (and other information) it contains, and is disclosed only to authorized persons.
Telephone contact — where the Administrator is contacted by telephone in matters unrelated to a concluded contract or services provided, the Administrator may request personal data only where necessary to handle the matter concerned.
Legal basis:
Article 6(1)(f) GDPR — the Administrator's legitimate interest in resolving the reported matter related to its business activity.
Telephone conversations may also be recorded — in such cases, appropriate information is provided at the start of the call. Calls are recorded to monitor service quality, verify consultants' work, and for statistical purposes. Recordings are available only to Administrator employees and hotline staff.
Personal data in the form of call recordings is processed:
- for purposes related to servicing customers and interested parties via the hotline, where the Administrator provides such a service — the legal basis is the necessity of processing to provide the service (Article 6(1)(b) GDPR);
- to monitor service quality and verify consultants' work, and for analytical and statistical purposes — the legal basis is the Administrator's legitimate interest (Article 6(1)(f) GDPR).
Recruitment
As part of recruitment processes, the Administrator expects personal data (e.g. in a CV) to be provided only to the extent specified in labour law provisions. Information should not be provided beyond that scope. Additional data submitted will not be used or taken into account in the recruitment process.
Personal data is processed:
- to fulfil obligations arising from legal provisions related to the employment process, in particular the Labour Code — the legal basis is a legal obligation imposed on the Administrator (Article 6(1)(c) GDPR);
- to carry out the recruitment process regarding data not required by law, and for future recruitment processes — the legal basis is consent (Article 6(1)(a) GDPR);
- to establish or pursue possible claims, or defend against such claims — the legal basis is the Administrator's legitimate interest (Article 6(1)(f) GDPR).
Collecting data in connection with the provision of services or performance of other contracts
Where data is collected for purposes related to performance of a specific contract, the Administrator provides the data subject with detailed information about the processing of their personal data at the time the contract is concluded.
Data security
To ensure the integrity, confidentiality and availability of data, the Administrator has implemented procedures (a Personal Data Processing Policy) allowing access to personal data only to authorized persons and only to the extent necessary for their tasks.
The Administrator also takes all necessary steps to ensure that its subcontractors and other cooperating entities guarantee appropriate security measures whenever they process personal data on the Administrator's behalf.
Profiling
Profiling means any form of automated processing of personal data used to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person's work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movement.
What is automated data processing?
We refer to automated data processing when data is processed exclusively by an algorithm (computer), i.e. without human involvement.
The Administrator is obliged to inform about automated processing, including profiling, where such processing produces legal effects or significantly affects a given natural person. The data subject has the right to object to automated processing, including profiling.
Cookies
What are cookies?
Cookies are small pieces of information sent by the website you visit and stored on your end device
(computer, laptop, smartphone) while browsing.
Almost every website uses cookie technology. During visits to our website, fragments of code storing user settings are saved on your device.
Given their lifespan, we use two basic types of these files:
- temporary session files stored on the user's device until logging out, leaving the website/application, or closing the browser;
- persistent files stored on the user's device for a period defined in the cookie's parameters, or until deleted by the user.
Depending on their purpose, we use the following types of cookies:
- necessary for the operation of our services and applications;
- used to ensure security, e.g. to detect authentication abuse;
- performance cookies, enabling us to collect information on how the website and applications are used;
- functional cookies, enabling us to remember settings selected by the user and personalize the user interface;
- advertising cookies, enabling delivery of advertising content better tailored to the user's interests;
- statistical cookies, used to compile statistics about the website and applications.
You may delete stored cookies, or block their placement, at any time using the options available in your web browser.
Managing and deleting cookies varies by browser. Detailed information can be found using your browser's Help function.
Transfer of data outside the EEA
The Administrator always informs about the intention to transfer personal data outside the EEA at the stage of its collection.