Privacy Notice – Article 14 UK GDPR and Data Protection Act 2018

Privacy Notice concerning the processing of personal data (Article 14 GDPR, UK GDPR and Data Protection Act 2018)

This privacy notice is intended to provide information on the rules governing the processing of personal data by MACTRONIC GROUP sp. z o.o. in connection with the processing of personal data obtained via the Apollo.io platform, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), to the extent that it applies, and with the UK GDPR and the UK Data Protection Act 2018, to the extent that those laws apply.

1. Personal Data Controller

The Controller of your personal data is MACTRONIC GROUP sp. z o.o., entered in the Register of Entrepreneurs maintained by the District Court for Wrocław-Fabryczna in Wrocław, 9th Commercial Division of the National Court Register, under KRS number: 0000976373, NIP: 897-001-32-66, REGON: 931589124, with its permanent place of business at: ul. Stargardzka 4, 54-156 Wrocław, Poland.

2. Contact

The Controller may be contacted by e-mail at: bok@mactronic.pl or in writing at the following address: MACTRONIC GROUP sp. z o.o., ul. Stargardzka 4, 54-156 Wrocław, Poland.

3. Data Protection Officer

The data subject may also contact the Data Protection Officer appointed by the Controller directly by e-mail at: kasia@doradztwoprawne.org or in writing at the following address, marked for the attention of the “Data Protection Officer”: ul. Stargardzka 4, 54-156 Wrocław, Poland.

4. Purposes, Legal Bases and Data Retention Period

Personal data are processed for the purposes of establishing business contact, providing information about the Controller’s activities and the products and services it offers, and developing relationships with potential business partners.

To the extent that the GDPR applies, the legal basis for the processing is Article 6(1)(f) GDPR, namely the legitimate interest pursued by the Controller in taking steps to establish business relationships and develop its business operations.

To the extent that the UK GDPR applies, the legal basis for the processing is Article 6(1)(f) UK GDPR, namely the legitimate interest pursued by the Controller in taking steps to establish business relationships and develop its business operations.

The data will be processed until an effective objection to the processing is raised or until the activities relating to the establishment of business contact are concluded, whichever occurs first.

5. Categories of Personal Data Processed

The following categories of personal data are processed: first name, surname, job title, company name, business e-mail address and telephone number.

6. Source and Method of Obtaining the Data

Your personal data have not been obtained directly from you. They have been obtained via the Apollo.io platform, which collects data from publicly available business sources, such as company websites, business registers and professional social networking platforms, as well as from other business sources. The data have been obtained solely as contact details connected with your professional activity or the position you hold.

7. Recipients of Personal Data

Personal data may be disclosed to entities providing the Controller with IT, hosting, e-mail, marketing tool and cloud services, solely on the basis of data processing agreements and without the right to use such data for their own purposes.

8. Rights of Data Subjects

To the extent that the GDPR applies, you have the right to access your personal data, rectify or erase them, restrict their processing, exercise your right to data portability where applicable, object to their processing and lodge a complaint with the competent supervisory authority.

To the extent that the UK GDPR applies, you have the rights provided for under the UK GDPR and the Data Protection Act 2018, including, in particular, the right to access your personal data, rectify or erase them (the “right to be forgotten”), restrict their processing, object to their processing and lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO).

9. Transfers of Personal Data to Third Countries or International Organisations

Personal data may be transferred to recipients located outside the European Economic Area (EEA) or outside the United Kingdom, including to the United States of America (USA), where the use of technology service providers involves such a transfer.

Such transfers are made on the basis of adequacy decisions adopted by the European Commission or adequacy regulations made by the UK Secretary of State, including under the UK Extension to the EU-U.S. Data Privacy Framework, or on the basis of Standard Contractual Clauses (SCCs) together with the UK International Data Transfer Addendum (UK Addendum), or other appropriate safeguards provided for under applicable law.

10. Automated Decision-Making

Your personal data are not used for automated decision-making or profiling.