Privacy and Cookies Policy
(“Policy”)
Table of contents:
I. Definitions
II. General information
III. Policy amendments
I. Definitions
1. Controller: Agencja Rozwoju Przemysłu S.A. (“Branch in Mielec”)
with its registered office in Warsaw, ul. Nowy Świat 6/12, 00-400 Warsaw, entered in the Register of Entrepreneurs of the National Court Register under KRS number 0000037957, holding tax identification number (NIP): 526-030-02-75 and REGON number: 012123456.
2. GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L No 119, p. 1);
3. Policy: the Privacy Policy of Agencja Rozwoju Przemysłu S.A.;
4. Personal data: means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, including the IP address of a computer, location data, online identifier and information collected through cookies and similar technologies;
5. Processing: means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
6. Profiling: means any form of automated Processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
7. Website: the online service operated by the Controller at:
https://europark.arp.pl/, which is the main information website on the activities of Europark Mielec.
8. Service or Services – any online service operated by the Controller, separate from the Website, to which this Policy applies, including in particular the service available at: https://baza-inwestycji.arp.pl/.
9. User – any natural person visiting the Website, a Service or the Services, or using one or more of the services or functionalities specified in this Policy.
II. General information
1) Introduction
This Policy sets out the rules for Processing and the use of cookies in connection with the use of the Website or the Services.
The Website and the Services are operated by the Controller.
This Policy has been prepared in connection with the applicable provisions on personal data protection, in particular the GDPR and the Polish Act of 10 May 2018 on the protection of personal data.
The Controller exercises due care to ensure the protection of the privacy of Users visiting the Website and the Services and to guarantee transparency as to the methods, purposes and legal grounds of the Processing.
This Policy presents the key information on the rules for processing personal data and the use of cookies.
2) Controller
The Controller is responsible for Processing in accordance with the applicable legal provisions, including the GDPR, and for ensuring appropriate protection of the data processed.
For matters related to Processing, including the exercise of the rights to which they are entitled, the User may contact the Controller using the following contact details:
Contact details of the Data Protection Officer of Agencja Rozwoju Przemysłu S.A.:
Name of the DPO: Krzysztof Radtke
E-mail address: iod@arp.pl
3) Purposes and legal grounds of Processing
Users’ personal data are processed in accordance with the applicable legal provisions, in particular the GDPR, only to the extent necessary to achieve specific purposes related to the operation of the Website, the Service or the Services, communication with Users and the conduct of the Controller’s business activities.
3.1 Contact with the Controller
When contacting the Controller via a contact form, e-mail or telephone, the data provided by the User are processed, such as name, surname, e-mail address, telephone number and the content of the message.
This data is used to respond to the enquiry, conduct ongoing communication and, in justified cases, to archive correspondence for evidential purposes. The legal basis for Processing is the Controller’s legitimate interest (Article 6(1)(f) of the GDPR) consisting in handling enquiries.
3.2 Performance of contracts and cooperation
In the event of contact for the purpose of concluding a contract, including where it is necessary to take steps prior to its conclusion, in particular negotiations and analyses and/or the performance of existing cooperation, personal data are processed to the extent necessary for the performance of the Contract, including administrative handling, settlements and the fulfilment of obligations arising from legal provisions, in particular tax and accounting regulations.
The legal basis for Processing is the necessity to perform a contract (Article 6(1)(b) of the GDPR) and the legal obligations incumbent on the Controller (Article 6(1)(c) of the GDPR).
3.3 Marketing and commercial communication
Where the User has given consent, their contact details – in particular their e-mail address – may be used for marketing purposes, such as sending information on offers, services, events or other activities related to the Controller’s business.
The legal basis for Processing is the User’s consent (Article 6(1)(a) of the GDPR) given in accordance with the legal provisions, including those concerning the provision of electronic services and telecommunications law. This consent may be withdrawn at any time without affecting the lawfulness of Processing carried out before its withdrawal.
3.4 Analytics and statistics
The Controller uses analytical tools, including Google Analytics, which make it possible to analyse how the Website and the Services are used.
For this purpose, data on the User’s activity on the Website or within a Service are processed, such as the subpages visited, time spent on the Website, source of entry, as well as technical data, including IP address (subject to anonymisation), cookie identifiers and information about the device and browser.
This data is used solely for statistical purposes, to optimise the operation of the Website or the Services and for Profiling. Processing is carried out on the basis of the User’s consent given through the cookies mechanism (Article 6(1)(a) of the GDPR).
3.5 Pursuing claims and protecting legal interests
The Controller may process personal data to establish, pursue or defend against claims and to protect its legal interests.
The legal basis for Processing in this respect is the Controller’s legitimate interest (Article 6(1)(f) of the GDPR).
3.6 Ensuring the security and proper functioning of the Website and the Services
In connection with the use of the Website or the Services, technical data such as IP address, server logs or information about the User’s device or browser may be processed automatically.
This data is used to ensure the security of IT systems, prevent misuse and maintain the proper functioning of the Website or the Services. The legal basis for Processing in this respect is the Controller’s legitimate interest (Article 6(1)(f) of the GDPR).
3.7 Managing User consents and preferences
In connection with the use of cookies and similar technologies, the User’s data may be processed to remember their choices, manage the consents given and adapt the operation of the Website and the Service to their preferences.
For cookies other than those necessary for the proper functioning of the Website or the Service, the legal basis for Processing is the User’s consent, whereas for cookies necessary for the proper functioning of the Website or the Service, it is the Controller’s legitimate interest.
3.8 Profiling
Users’ data may be subject to Profiling, in particular to analyse how the Website or the Service is used and to tailor their functionalities and content.
Profiling is of a technical and statistical nature and does not produce legal effects.4) Scope of data processed
The Controller processes personal data only to the extent necessary to achieve the purposes indicated in this Policy. The scope of data processed depends on how the User uses the Website or the Service and on the form of contact with the Controller.
In particular, the following categories of data may be processed:
The provision of personal data is, as a rule, voluntary, but in some cases it may be necessary to use certain functionalities of the Website or the Service (e.g. to respond to an enquiry or to establish contact).
For certain data Processing activities (e.g. registration for events, newsletters), the Controller may provide Users with separate information clauses. In such cases, the provisions of these clauses complement this Policy for the relevant Processing activity.
5) Data recipients
Users’ personal data may be transferred to third parties only to the extent required by law or necessary to achieve the purposes indicated in this Policy and subject to appropriate security measures.
Depending on the nature of the Processing, data recipients may include:
Where tools provided by entities established outside the European Economic Area (e.g. in the United States) are used, data may be transferred to third countries. In such cases, the Controller ensures appropriate safeguards, in particular by using standard contractual clauses (SCC) approved by the European Commission.
The Controller exercises due care to ensure that data are transferred only to entities providing an adequate level of protection and in compliance with the applicable legal provisions, including the GDPR.
6) Google Analytics
The Website uses the analytical tool Google Analytics, provided by Google Ireland Limited, based in Ireland. This tool makes it possible to analyse how Users use the Website and the Service and supports the Controller in optimising them.
As part of Google Analytics, information on the User’s activity on the Website or within the Service is collected, in particular on the subpages visited, time spent on the Website or within the Service, source of entry and interactions with content. In addition, technical data may be processed, such as IP address (subject to anonymisation), type of device, operating system and type of web browser.
The information collected is used solely for statistical and analytical purposes, in particular to better understand Users’ needs, improve the functionality of the Website and the Service and support their further development. This data is not used to directly identify the User.
The legal basis for Processing in this respect is the User’s consent to the use of analytical cookies, given via the consent management mechanism (cookie banner), pursuant to Article 6(1)(a) of the GDPR. The Google Analytics tool is activated only after such consent has been obtained.
In connection with the use of Google services, data may be transferred outside the European Economic Area, in particular to the United States. The transfer of data takes place on the basis of an adequacy decision of the European Commission (EU–US Data Privacy Framework) or – where appropriate – on the basis of standard contractual clauses (SCC).
Data related to the analysis of traffic on the Website or within the Service are stored for up to 14 months, in line with the configuration of the Google Analytics tool, and are then automatically deleted or anonymised.
The User may withdraw consent to Processing for analytical purposes at any time. This can be done by changing the cookie settings available in the consent banner or by appropriately configuring the browser settings. In addition, it is possible to use the Google Analytics Opt-out tool made available by Google at: https://tools.google.com/dlpage/gaoptout
7) Data retention periods
Users’ personal data are stored for no longer than is necessary to achieve the purposes for which they were collected. The length of the storage period depends on the nature of the relationship with the User, the legal basis for Processing and the obligations arising from legal provisions.
In the case of contact with the Controller (e.g. via a contact form or e-mail), data are stored for the period necessary to provide a response and conduct further correspondence and may then be archived for a period justified by the need to secure potential claims.
Where a contract is concluded or cooperation is established, personal data are stored for the duration of the contract or cooperation and, after its termination, for the period required by legal provisions (e.g. tax and accounting regulations) and for the period necessary to pursue or defend against claims resulting from limitation periods.
Where data are processed on the basis of the User’s consent, in particular for marketing purposes, they are stored until such consent is withdrawn. After consent is withdrawn, data may be stored to a limited extent for the period necessary to demonstrate that the Controller’s actions complied with legal provisions.
Data processed for analytical purposes, including with the use of tools such as Google Analytics, are stored for the period resulting from the settings of these tools or until the User deletes cookies or withdraws consent to their use.
Notwithstanding the above, data may be stored for a longer period if this arises from legal obligations incumbent on the Controller or is necessary to establish, pursue or defend against claims.
8) User rights
Every person whose data are processed has certain rights related to the protection of personal data. The Controller ensures that these rights are respected in accordance with the applicable legal provisions.
In particular, the User has the right to obtain information as to whether their data are being processed and, if so, to gain access to that data and to information on the rules of Processing. At the User’s request, the Controller provides a copy of the data undergoing Processing.
Where data are inaccurate or incomplete, the User has the right to request their rectification.
The User may also request the erasure of data, in particular where they are no longer necessary for the purposes for which they were collected or where Processing is based on consent that has been withdrawn (the so-called “right to be forgotten”).
The User may also request restriction of Processing, for example where the accuracy of the data is contested or an objection to Processing has been lodged. In certain cases, the User also has the right to data portability, i.e. to receive the data in a structured format and to transmit it to another controller.
Where personal data are processed on the basis of the Controller’s legitimate interest, the User has the right to object to such Processing. Where data are processed for direct marketing purposes, the objection may be lodged at any time and is binding on the Controller.
Where Processing is based on consent, the User has the right to withdraw it at any time. Withdrawal of consent does not affect the lawfulness of Processing carried out before the withdrawal.
In relation to the use of cookies, the User may also change their preferences or withdraw consent to analytical cookies at any time, for example via the settings available in the cookies banner (consent banner).
To exercise their rights, the User may contact the Controller using the contact details provided by the Controller. Requests are handled without undue delay, and no later than within the time limits set out in legal provisions.
The User also has the right to lodge a complaint with a supervisory authority, which in Poland is the President of the Personal Data Protection Office, in particular if they consider that the processing of their data infringes legal provisions.
9) Cookies
The Website and the Services use cookies, i.e. small text files stored on the User’s end device (e.g. computer, tablet or smartphone) while using the Website or the Service. Cookies make it possible for the Website or the Service to function properly and support the analysis of how they are used and – depending on the settings – marketing activities.
9.1 Types of cookies used
Various types of cookies may be used on the Website and within the Services, depending on their function and mode of operation.
According to their purpose, the following categories are distinguished:
According to the storage period, cookies may be:
According to their origin, cookies are divided into:
9.2 Purposes of using cookies
Cookies are used to ensure the proper functioning of the Website or the Services and to improve the quality of the services provided.
In particular, they make it possible to:
9.3 Managing cookies
The use of cookies other than necessary cookies requires the User’s consent, which is given via the consent management mechanism (cookie banner).
The User can manage cookie settings at any time. In particular, they may:
Detailed information on managing cookies is available in the settings of the web browser used, in particular browsers such as Google Chrome, Mozilla Firefox, Safari or Microsoft Edge.
Please note that restricting the use of cookies may affect some of the functionalities available on the Website or within the Service.
10) Consent to cookies (Cookie banner)
The Website and the Services use a consent management mechanism for cookies (the so-called cookie banner), which enables the User to make an informed and voluntary decision on the scope of Processing related to the use of cookies.
During the first visit to the Website or within the Service, the User is shown a message through which they can consent to the use of specific categories of cookies. This mechanism ensures that consent is given by an active action, such as clicking an appropriate button (e.g. “Accept”), and that the User’s lack of response is not interpreted as consent.
The User can refuse the use of cookies other than necessary cookies, and the option to refuse is available in a way that is as easy as granting consent. In addition, the mechanism allows a detailed selection of individual categories of cookies, enabling the settings to be tailored to individual preferences.
Within the consent management mechanism, the following categories of cookies are distinguished:
The User may change their cookie settings or withdraw consent previously given at any time by using the consent management tool available on the Website or within the Service (e.g. by re-displaying the cookies banner), which may, however, affect the ability to use certain functionalities of the Website or the Services.
The consent mechanism has been designed to comply with the requirements of the GDPR and the provisions on privacy in electronic communications, in particular with regard to the voluntariness, specificity and unambiguous nature of the consent given.
11) Withdrawal of consent
The User may withdraw consent to Processing at any time where Processing is based on consent. Withdrawal of consent does not affect the lawfulness of Processing carried out before its withdrawal.
In relation to cookies, the User may change their preferences regarding their use at any time. This can be done, in particular, by again using the consent management mechanism available on the Website or within the Service (cookie banner), which makes it possible to modify settings previously selected.
Notwithstanding the above, the User may independently manage cookies through their web browser settings, including restricting them or completely deleting them from the device.
Where the User wishes to exercise the right to withdraw consent more broadly, they may also contact the Controller directly, using the contact details indicated in this Policy.
12) Data security
The Controller applies appropriate technical and organisational measures to protect personal data processed against loss, unauthorised access, disclosure, alteration or destruction. The scope of the safeguards applied is adapted to the nature of the data, the scale of Processing and the risk of infringement of the rights and freedoms of data subjects.
In particular, the Controller uses solutions that ensure the security of data transmission on the Internet, such as connection encryption using the SSL/TLS protocol, which protects data transmitted between the User’s device and the server.
Access to personal data is limited exclusively to authorised persons who are obliged to maintain confidentiality. The Controller uses access control mechanisms to ensure that data are processed only by persons holding appropriate authorisations and only to the extent necessary to achieve the purposes set out in this Policy.
In addition, IT system safeguards are applied, including protection against unauthorised access, system operation monitoring and regular software updates, which helps reduce the risk of security incidents.
The Controller also undertakes organisational measures, such as implementing appropriate internal procedures and training persons having access to data, in order to ensure that data are properly protected in accordance with the applicable legal provisions, including the GDPR.
13) Contact with the Controller
For matters relating to this Policy, please contact us by e-mail at: europark@arp.pl
III. Policy amendments
This Policy may be updated by the Controller. The current version of the Policy is always available on the Website and within the Services.