Privacy and Personal Data Protection Policy

1. DEFINITIONS
1.1. Administrator – Tomasz Chęciński, conducting business activity under the name: Kancelaria Radcy Prawnego Tomasz Chęciński, with its registered office in Poznań, ul. Sofoklesa 61, 60-461 Poznań, NIP 9721152360, REGON 301279199, email: t.checinski@krptch.pl.
1.2. Personal Data – all information about an identified or identifiable natural person, especially by reference to one or more specific identifiers including physical, physiological, genetic, mental, economic, cultural, or social identity, such as image, voice recordings, contact details, information contained in correspondence, IP address, location data, online identifier, and data collected via cookies or similar technologies.
1.3. Policy – this Privacy and Personal Data Protection Policy.
1.4. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
1.5. Website – the website operated by the Administrator at https://www.krptch.pl/.
1.6. User – any natural person visiting the Website or using one or more services or functionalities described in the Policy.
1.7. Data Subject – any natural person whose personal data are processed by the Administrator, e.g., a person visiting the Administrator's premises, sending an inquiry via email, or a User.

2. DATA PROCESSING BY THE ADMINISTRATOR
2.1. In connection with its business activity, the Administrator collects and processes personal data in compliance with applicable regulations, including in particular the GDPR, and according to the principles specified therein.
2.2. The Administrator ensures transparency of data processing, especially by informing at the time of data collection about the purposes and legal basis for processing – e.g., when concluding a service or sales contract. Data is collected only to the extent necessary and processed only for the duration required.
2.3. The Administrator ensures the security and confidentiality of the data and provides access to information about the processing to the data subjects. In the event of a breach of personal data protection (e.g., data leak or loss), affected persons will be notified in accordance with the law.
2.4. When using the Website, the Administrator collects data necessary to provide specific services and information about User activity on the Website. Detailed rules and purposes of data processing during Website use are described below.
3. PURPOSES AND LEGAL BASES OF DATA PROCESSING
EMAIL AND TRADITIONAL CORRESPONDENCE

3.1. Personal data included in correspondence not related to services or contracts is processed solely for the purpose of communication and resolving the matter.
3.2. Legal basis: the Administrator’s legitimate interest (Art. 6(1)(f) GDPR).
3.3. Only relevant data is processed, and correspondence is secured and disclosed only to authorized persons.

TELEPHONE CONTACT

3.4. For calls not related to existing contracts or services, personal data is collected only if necessary. Legal basis: legitimate interest of the Administrator (Art. 6(1)(f) GDPR).

USE OF THE WEBSITE

3.5. Personal data (e.g., IP address, cookies):
• 3.5.1. To provide online content – legal basis: performance of a contract (Art. 6(1)(b) GDPR);
• 3.5.2. For analytics and statistics – legal basis: legitimate interest (Art. 6(1)(f) GDPR);
• 3.5.3. To assert or defend against claims – legal basis: legitimate interest (Art. 6(1)(f) GDPR).

NEWSLETTER

3.6. Email address is provided voluntarily for receiving information; consent may be withdrawn at any time.
3.7. Legal basis: legitimate interest of the Administrator (Art. 6(1)(f) GDPR), linked to consent for receiving the newsletter.

SOCIAL MEDIA

3.8. The Administrator processes data of Users visiting its social media profiles (LinkedIn, Twitter, Facebook) to inform and promote services – legal basis: legitimate interest (Art. 6(1)(f) GDPR).

RECRUITMENT

3.9.–3.10.3. Personal data in recruitment processes is processed to the extent required by labor law, based on:
• legal obligation (Art. 6(1)(c) GDPR),
• consent (Art. 6(1)(a) GDPR),
• legitimate interest (Art. 6(1)(f) GDPR).

SERVICE PROVISION OR CONTRACT EXECUTION

3.11. When collecting data for contract execution, relevant information is provided at the time of contract conclusion.
OTHER CASES
3.12.–3.13. Personal data may be collected at business meetings for contact purposes – legal basis: legitimate interest (Art. 6(1)(f) GDPR).

4. COOKIES AND SIMILAR TECHNOLOGIES
4.1.–4.2.6. Cookies are used to improve service quality, authenticate users, ensure security, remember settings, and analyze website traffic. Tools include Google Analytics. Full details: Google Privacy Policy
5. DATA RETENTION PERIOD
5.1.–5.2. Data is retained based on purpose, legal basis, and applicable laws. Once the purpose is fulfilled or legal grounds expire, data is deleted or anonymized.
6. DATA SUBJECT RIGHTS
6.1.–6.10. The data subject has the right to:
• access, rectify, delete, or restrict data;
• data portability and objection;
• file complaints with the supervisory authority;
• withdraw consent at any time;
• receive a response within one month.
Requests can be sent by mail (ul. Sofoklesa 61, 60-461 Poznań, Poland) or email (t.checinski@krptch.pl).
Certain requests (e.g., second data copy or excessive frequency) may incur administrative fees (PLN 20–50).

7. PERSONAL DATA BREACHES
7.1.–7.13. The Administrator follows a defined procedure for reporting and documenting data breaches. Breaches likely to pose a risk to rights and freedoms are reported to the supervisory authority within 72 hours and to the affected data subjects if high risk is determined. A confidential Breach Register is maintained.

8. DATA RECIPIENTS
8.1.–8.2. Data may be disclosed to IT service providers, accounting firms, couriers, and recruitment agencies. Public authorities may also access data if permitted by law.

9. DATA TRANSFERS OUTSIDE THE EEA
9.1.–9.2. Personal data may be transferred outside the EEA only with adequate safeguards, such as EC adequacy decisions, standard contractual clauses, or participation in the Privacy Shield program.

10. DATA SECURITy
10.1.–10.3. The Administrator ensures only authorized personnel have access to data and uses appropriate security measures. Subcontractors are also required to implement data protection safeguards.
11. CONTACT DETAILS
11.1. Contact the Administrator at:
• Email: t.checinski@krptch.pl
• Address: ul. Sofoklesa 61, 60-461 Poznań, Poland
12. CHANGES TO THE PRIVACY POLICY
12.1. This Policy is regularly reviewed and updated as needed. The current version is effective as of November 1, 2019.
tomasz chęciński © 2025
PRIVACY POLICY