Raise Your Sales
Get a free consultation

Privacy Policy

PRIVACY POLICY

www.rysagency.com

§ 1 General provisions

(1) The administrator of the personal data of the users of the website located under the domain www.rysagency.com is RYS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, based in Bielsko-Biała, at ul. Podwale 47, 43-300 Bielsko-Biała, entered in the National Register of Entrepreneurs kept by the District Court in Bielsko-Biała, VIII Economic Department of the National Court Register under KRS number: 0001006923, NIP: 5472234742, REGON: 523865502, share capital PLN 5,000.00 paid in full (hereinafter: “Administrator”).

(2) Contact with the Administrator is possible:
(1) by e-mail: hello@rysagency.com
(2) in writing, to the Administrator’s address: 47 Podwale Street, 43-300 Bielsko-Biała.

(3) The purpose of the Policy is to define the activities undertaken with regard to personal data collected through the Administrator’s website and related services and tools used by its users, as well as in the activity of concluding and executing contracts in contact outside the website.

(4) If necessary, the provisions of this Policy may be changed. The change will be communicated to users by announcing the new content of the Policy, and in the case of the base of persons who have agreed to the processing of data by e-mail or have provided e-mail data in the execution of contracts, they will also be notified of the change by e-mail.

§ 2 Basis for processing, purposes and storage of personal data

(1) Users’ personal data shall be processed in accordance with the General Data Protection Regulation, the Personal Data Protection Act of 10.05.2018 and the Electronic Services Act of 18.07.2002. Together with subsequent amendments of the above.

(2) The administrator may collect the following data for the following purposes:

Purpose of data processing

Legal basis for processing and data retention period

Data retention period

Scope of data processing

Performance of a contract with the Client or taking action at the request of the data subject before concluding the aforementioned contracts

Article 6(1)(b) of the GDPR (contract performance).

  • for the duration of the aforementioned contract until the expiration of the legal obligation related to accounting
  • data will be processed until the expiration of the period during which claims can be pursued
  • first name and last name;
  • email address;
  • phone number;
  • address (street, house number,
  • apartment number,
  • postal code,
  • city, country),
  • company name,
  • Tax ID

Direct marketing

Article 6(1)(f) of the GDPR (legitimate interest of the controller).

The Controller may process data for direct marketing purposes only after obtaining consent and in the absence of objection from the data subject.

  • until consent is withdrawn – remember, you can withdraw your consent at any time. Data processing until your consent is withdrawn remains lawful.
  • data will be processed until the expiration of the period during which claims can be pursued
  • email address;
  • phone number;

Marketing

Article 6(1)(a) of the GDPR (consent)

  • until consent is withdrawn – remember, you can withdraw your consent at any time. Data processing until your consent is withdrawn remains lawful.
  • data will be processed until the expiration of the period during which claims can be pursued
  • until unsubscribing from the newsletter.
  • first name and last name;
  • email address;
  • phone number;
  • address (street, house number, apartment number, postal code, city, country),

Client
feedback

Article 6(1)(a) of the GDPR

  • if no opinion is expressed, for a period of 30 days from your purchase or until an objection to processing is considered;
  • if an opinion is expressed – until its removal or until an objection to processing is considered
  • data will be processed until the expiration of the period during which claims can be pursued
  • first name and last name;
  • email address;
  • phone number;

Accounting

Article 6(1)(c) of the GDPR in conjunction with Article 86 § 1 of the Tax Ordinance of January 17, 2017 (Journal of Laws of 2017, item 201) or Article 74(2) of the Accounting Act of January 30, 2018 (Journal of Laws of 2018, item 395).

  • data will be processed until the expiration of the period during which claims can be pursued
  • data is stored for the period required by law for keeping tax records (until the expiration of the tax liability limitation period, unless tax laws state otherwise) or accounting records (5 years, counting from the beginning of the year following the financial year to which the data relates).
  • first name and last name;
  • email address;
  • phone number;
  • address (street, house number, apartment number, postal code, city, country),
  • Tax Identification Number (NIP);
  • company name;

Processing refunds

Performance of the Contract or taking action at the request of the data subject before concluding the Contract (Article 6(1)(b) of the GDPR).

  • 5 years after the termination of business relations with the Client
  • first name and last name;
  • email address;
  • phone number;
  • PESEL (Polish National Identification Number);
  • address (street, house number, apartment number, postal code, city, country),
  • business entity data.

Establishing, pursuing, or defending claims that the Controller may raise or that may be raised against the Controller

Article 6(1)(f) of the GDPR

  • data is stored for the period of our legitimate interest, but no longer than the limitation period for claims against the data subject arising from business activities.
  • first name and last name;
  • email address;
  • phone number;
  • address (street, house number, apartment number, postal code, city, country),
  • Tax Identification Number (NIP);
  • company name;

Conducting research and analysis to improve the operation of available services

Article 6(1)(f) of the GDPR

  • data will be processed until the expiration of the period during which claims can be pursued
  • until the expiration or deletion of cookies used for analytical purposes
  • company name;
  • email address;
  • phone number;
  • address (street, house number, apartment number, postal code, city, country),
  • computer hardware,
  • settings,
  • installed software.

Client account registration

Performance of the Contract or taking action at the request of the data subject before concluding the Contract (Article 6(1)(b) of the GDPR)

  • 5 years after the termination of business relations with the Client
  • first name and last name;
  • email address;
  • phone number;
  • PESEL (Polish National Identification Number);
  • address (street, house number, apartment number, postal code, city, country),
  • business entity data.

Sending notifications to the Client

Performance of the Contract or taking action at the request of the data subject before concluding the Contract (Article 6(1)(b) of the GDPR)

Fulfillment of a legal obligation incumbent on the Controller (Article 6(1)(c) of the GDPR)

  • 5 years after the termination of business relations with the Client
  • first name and last name;
  • email address;
  • phone number;
  • PESEL (Polish National Identification Number);
  • address (street, house number, apartment number, postal code, city, country),
  • business entity data.

Providing customer support

Performance of the Contract or taking action at the request of the data subject before concluding the Contract (Article 6(1)(b) of the GDPR)

  • 5 years after the termination of business relations with the Client
  • 2 years after the last update of the Client’s inquiry
  • first name and last name;
  • email address;
  • phone number;
  • address (street, house number, apartment number, postal code, city, country),
  • business entity data,

Proper functioning of the service

Maintaining the efficiency of the Service and its improvement (Article 6(1)(f) of the GDPR)

  • 5 years after the termination of business relations with the Client
  • As in the cell above,
  • Information on activities performed in the service (button clicks, visit duration, read notifications, other information depending on the specific business case).

Tracking website visits for security reasons

Protection and security of the service, interests of Clients, ensuring Client safety (Article 6(1)(f) of the GDPR)

  • 3 years
  • User ID,
  • IP address,
  • Browser,
  • Content and URLs accessed by the User,
  • Date and time of connections.

Protecting Clients from the use of a disclosed login password

Protection and security of the service, interests of Clients, ensuring Client safety (Article 6(1)(f) of the GDPR)

  • Time necessary for the Controller to verify the password
  • User ID,
  • Client password.

Enabling the Client to reset their password

Protection and security of the service, interests of Clients, ensuring Client safety (Article 6(1)(f) of the GDPR)

  • 5 years after the termination of business relations with the Client
  • first name and last name;
  • email address;
  • business entity data,
  • Client password,
  • User ID.

Monitoring compliance with regulations, contracts, privacy policy

Protection and security of the service, interests of Clients, ensuring Client safety (Article 6(1)(f) of the GDPR)

  • 5 years after the termination of business relations with the Client
  • transaction data,
  • business entity data.

Processing requests regarding personal data,

Article 6(1)(c) of the GDPR

  • The period of existence of the Controller’s legitimate interest, but no longer than the limitation period for claims against the data subject arising from business activities.
  • first name and last name;
  • email address;
  • phone number;
  • address (street, house number, apartment number, postal code, city, country),
  • Tax Identification Number (NIP);
  • company name.

Providing information to law enforcement agencies and other state institutions,

Article 6(1)(c) of the GDPR

  • The period of existence of the Controller’s legitimate interest, but no longer than the limitation period for claims against the data subject arising from business activities.
  • first name and last name;
  • email address;
  • phone number;
  • address (street, house number, apartment number, postal code, city, country),
  • Tax Identification Number (NIP);
  • company name.

(3) Users’ personal data shall be stored for no longer than necessary to achieve the purpose of processing, i.e. until the withdrawal of consent if processing is based on such consent, until the statute of limitations for claims of the Administrator and the other party for the performance of concluded contracts (in the case of sales contracts/service contracts, 2 years, counting to the end of the year), and until the execution of an inquiry directed by e-mail or until the completion of the processing of complaints.

(4) The Administrator may use profiling for direct marketing purposes, but decisions made on its basis by the Administrator do not relate to the conclusion or refusal of a contract or the possibility of using electronic services.

(5) To the extent necessary for the proper functioning of the website, its functionality, the website may, during the use of the website by the User, collect other information, including but not limited to:
a) IP address;
b) device, hardware and software information, such as hardware identifiers, mobile device identifiers (e.g. Apple Identifier for Advertising [“IDFA”] or advertising identifier on an Android device [“AAID”]),
c) type of platform,
d) browser data, including browser type and preferred language;

(6) Taking into account the nature, scope, context and purposes of the processing and the risk of violation of the rights or freedoms of natural persons of varying probability and severity, the Administrator shall implement appropriate technical and organizational measures to ensure that the processing is carried out in accordance with the Regulation and to be able to demonstrate this. These measures shall be reviewed and updated as necessary. The Administrator shall apply technical measures to prevent unauthorized persons from obtaining and modifying, personal data sent electronically.

§ 3 Data sharing

(1) The administrator shall ensure that any personal data collected is used to fulfill obligations to users. This information will not be shared with third parties except:
a) with the prior express consent of the subjects to do so, or
b) if the obligation to provide such data is or will be based on applicable laws, such as law enforcement agencies.

(2) In addition, personal data of service recipients and customers may be transferred to the following recipients or categories of recipients:

  • service providers supplying the Administrator with technical, IT and organizational solutions that enable the Administrator to conduct its business, including the website and electronic services provided through it (in particular, computer software providers, marketing agencies, e-mail and hosting providers, software providers for managing the company and providing technical assistance to the Administrator and product delivery operator) – the Administrator shall make the collected personal data of the Customer available to the selected provider acting on its behalf only in the case and to the extent necessary to realize the given purpose of data processing in accordance with this Privacy Policy.
  • Providers of accounting, legal and advisory services providing accounting, legal or advisory support to the Administrator (in particular, an accounting office, law firm or debt collection company) – the Administrator shall make the collected personal data of the Client available to the selected provider acting on its behalf only in the case and to the extent necessary to realize the given purpose of data processing in accordance with this Privacy Policy.
  • Albacross (registered office: Warszawska 20, 31-155 Kraków, Poland) for the purposes of analytical tools for analyzing Web site statistics and tracking activities performed by users on the Web site;
  • Fakturownia Sp. z o.o. (registered office: 6/8 Juliana Smulikowskiego St., 00-389 Warsaw, KRS: 0000572426, NIP: 5213704420) to assist the Administrator in handling invoices and financial documents;
  • Woodpecker.co S.A. (registered office: 29D Krakowska St., 50-424 Wroclaw, KRS: 0000896179, NIP: PL 8992769178) for tools for sending and receiving mailings and e-mails;
  • Smarthost Sp. z o.o. (Headquarters: Partyzantów 1, 42-217 Częstochowa) for the purpose of hosting the website.

(3) The Administrator may share anonymized data (i.e., data that does not identify specific Users) with third-party service providers in order to better identify the attractiveness of advertisements and services to Users, and in this regard, due to the location of software providers, data may be transferred – subject to the principles of their protection – to third countries, however, providing standard contractual provisions approved by the European Commission for the processing of personal data or having the appropriate authority to do so on the basis of bilateral data processing entrustment agreements between the European Union and the third country in question, while not being a member of the European Economic Area. These entities in the case of the Administrator are:

  • Google LLC. (registered office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) for Google Analytics tools used to analyze website statistics, Google Tag manager: used to manage scripts by easily adding code snippets to a website or application, and to track actions performed by users on a website, Google Ads used to display sponsored links in Google search results and on Google AdSense collaborative sites, Google Workspace allowing comprehensive editing of a website and coordination of people working on it (including Google Drive, Gmail, Google Sheets, Google Forms, Google Looker studio);
  • Meta Platforms, Inc. (Headquarters: 1601 Willow Road Menlo Park, CA 94025, USA) for Facebook pixel used to track conversions from Facebook ads, optimize them based on collected data and statistics, and build a targeted audience list for future ads.
  • LinkedIn Ireland Unlimited Company (headquartered at Wilton Plaza, Wilton Place, Dublin 2, Ireland) for the purpose of tracking conversions from LinkedIn ads, optimizing them based on collected data and statistics, and building a targeted audience list for future advertising.
  • Todoist (Doist Inc.) (Headquarters: 2100 Geng Road, Suite 210, Palo Alto, CA 94303, USA) for the purposes of workflow tools of the website supervisors and for technical support.
  • PowerMyAnalytics (headquartered at 100 Candace Dr, Suite 100, Maitland, FL 32751, USA) for analytical tools to analyze Web site statistics and track users’ activities on the Web site;
  • Hotjar Limited (registered office: Dragonara Business Centre 5th Floor, Dragonara Road, Paceville St Julian’s STJ 3141 Malta) for the purposes of analytical tools to analyze Web site statistics and track users’ activities on the Web site;
  • Zapier Inc. (Headquarters: 548 Market St. #62411 San Francisco, CA 94104-5401, USA) for tools used by the Administrator to automate functions and perform tasks on the Website;
  • Pipedrive Inc. (Headquarters: 530 5th Avenue, Suite 802, New York, NY 100361600, USA) for data related to the operation and delivery of the CRM system for the Administrator;
  • BitWarden Inc. (Headquarters: 1 North Calle Cesar Chavez, Suite 102, Santa Barbara, CA 93103, USA) for the purpose of protecting user passwords and ensuring the security of the connection between the site and the user;
  • If the user consents to marketing cookies, after the contact form is submitted the Administrator transfers to Google LLC versions of the user's e-mail address and telephone number encrypted with the SHA-256 hash function. Google uses them to match conversions from Google Ads advertisements (so-called enhanced conversions) and to build conversion-based customer lists (Customer Match), which allow the Administrator to show its advertisements to the user or to exclude the user from their audience. Google does not receive this data in plain text. If the enquiry turns into a qualified business contact or a collaboration, the Administrator may transfer this information to Google LLC together with the date, the ad click identifier and the encrypted data described above, in order to measure the effectiveness of Google Ads advertisements.

(4) The controller shall always inform about the intention to transfer personal data outside the EEA at the stage of collection.

(5) The Administrator shall, on an ongoing basis, conduct a risk analysis to ensure that personal data is processed by him in a secure manner – ensuring, first and foremost, that only authorized persons have access to the data and only to the extent necessary for their tasks. The Administrator ensures that all operations on personal data are recorded and performed only by authorized employees and associates.

(6) The Administrator shall take all necessary measures to ensure that its subcontractors and other cooperating entities also provide guarantees to apply appropriate security measures whenever they process personal data on behalf of the Administrator.

(7) The Administrator’s website may use the functionality of Google Analytics, a web audience analysis service provided by Google, LLC. (“Google”). Google Analytics uses cookies to help website operators analyze how visitors use the website. The information generated by the cookie about visitors’ use of the website is generally transmitted to and stored by Google on servers in the United States. In accordance with current IT standards, the IP addresses of users visiting the Administrator’s website are abbreviated. Only in exceptional cases is the complete IP address transferred to a Google server in the United States and shortened there. On behalf of the Administrator, Google will use this information to evaluate the website for its users, to compile reports on website traffic and to provide other services related to website traffic and Internet usage for website operators. In doing so, Google will not associate the IP address submitted as part of Google Analytics with any other data in its possession. For more information on how Google Analytics collects and uses data, please visit Google’s official website at: www.google.com/policies/privacy/partners. In addition, any User can prevent Google from collecting and processing data about their use of the website by downloading and installing a browser plug-in at the following link: http://tools.google.com/dlpage/gaoptout.

(8) The Administrator, when sharing data with third parties, shall make every effort to ensure that this is done only with entities that meet the criteria and requirements indicated under Article 46 or 49 of the RODO. Where applicable, the Administrator will rely on EU standard contractual clauses and other safeguards to enable transfers outside the EEA. In accordance with the decision of the Court of Justice of the European Union of July 16, 2020, the Administrator shall continue to assess the legal regime of the countries to which data is transferred and, where necessary, update measures to ensure adequate levels of protection.
9. With respect to data transferred to the United States, the Administrator, when sharing data with third parties, shall make every effort to ensure that this is done, in accordance with the decision of the European Commission of July 10, 2023, only to entities and organizations in the United States that ensure compliance with the new “EU-US Data Privacy Framework.” A list of these organizations has been published by the US Department of Commerce. Transfers of personal data from the EEA to organizations that have joined the “EU-US Data Privacy Framework” program and are on this list are possible without the need for additional authorizations or the use of such legal instruments as standard contractual clauses or binding corporate rules. However, in cases where a particular data importer in the US has not joined the “EU-US Data Protection Framework” program, transfers of personal data to it are possible and will take place upon compliance with the conditions set forth in Article 46 or 49 of the RODO. In such cases, the Administrator will rely on EU standard contractual clauses and other safeguards to enable transfers outside the EEA.

§ 4 User rights

(1) A user whose personal data is processed has the right to:
a) access, rectification, restriction, erasure or portability – a data subject has the right to request from the Administrator access to his/her personal data, rectification, erasure (“right to be forgotten”) or restriction of processing, and has the right to object to processing, and has the right to portability of his/her data. The detailed conditions for exercising the rights indicated above are indicated in Articles 15-21 of the RODO Regulation.
b) withdrawal of consent at any time – a person whose data are processed by the Administrator on the basis of expressed consent (pursuant to Article 6(1)(a) or Article 9(2)(a) of the RODO Ordinance), then he/she has the right to withdraw consent at any time without affecting the legality of the processing performed on the basis of consent before its withdrawal.
c) lodge a complaint to a supervisory authority – a person whose data is processed by the Administrator has the right to lodge a complaint to a supervisory authority in the manner and mode specified in the provisions of the RODO Ordinance and Polish law, in particular the Personal Data Protection Act. The supervisory authority in Poland is the President of the Office for Personal Data Protection in Warsaw.
(d) Objection – The data subject has the right to object at any time – on grounds relating to his or her particular situation – to the processing of personal data concerning him or her based on Article 6(1)(e) (public interest or tasks) or (f) (legitimate interest of the controller), including profiling under these provisions. In such a case, the controller shall no longer be allowed to process such personal data, unless the controller demonstrates the existence of compelling legitimate grounds for the processing overriding the interests, rights and freedoms of the data subject, or grounds for establishing, asserting or defending claims.
(e) objection to direct marketing – if personal data are processed for the purposes of direct marketing (based on the legitimate interests of the Controller, not on the basis of the data subject’s consent), the data subject has the right to object at any time to the processing of personal data concerning him or her for the purposes of such marketing, including profiling, to the extent that the processing is related to such direct marketing.

(2) Exercise of the above rights is based on the user’s request sent to the e-mail address hello@rysagency.com. Such a request should include the user’s name.

(3) You shall ensure that the data you provide or publish on the site is correct.

§ 5 Cookies

(1) “Cookies” should be understood as IT data, in particular text files, stored on the users’ terminal devices (usually on the computer’s hard drive or mobile device) for the purpose of saving certain settings and data by the user’s browser in order to use the websites. These cookies allow to recognize the user’s device and display the website accordingly, providing comfort during its use. The storage of “cookies” therefore allows the website and the offer to be properly prepared for the user’s preferences – the server recognizes the user and remembers preferences such as visits, clicks, previous actions, among others.

“Cookies” include, in particular, the domain name of the website from which they originate, the time they are stored on the terminal device and a unique number used to identify the browser from which the connection to the website is made.

3. cookies are used for the following purposes:
a. adapting the content of the websites to the user’s preferences and optimizing the use of the websites,
b. creating anonymous statistics which, by helping to determine how the user uses the websites, make it possible to improve their structure and content,
c. providing website users with advertising content tailored to their interests.
Cookies are not used to identify the user, and the user’s identity is not established from them.

(4) The main division of “cookies” is their distinction into:
a) “Cookies” of an essential nature – they are absolutely necessary for the proper functioning of the website or the functionality you want to use, because without them we could not provide many of the services we offer. Some of them also ensure the security of the services we provide electronically.
b) Functional “cookies” – are important for the operation of the website due to the fact that:
– they serve to enrich the functionality of the websites; without them the website will work properly, but will not be adjusted to the user’s preferences,
– they serve to ensure a high level of functionality of the websites; without them the level of functionality of the website may decrease, but their absence should not prevent the complete use of the website,
– they serve most of the functionality of the websites; blocking them will result in selected functions not working properly.
c) Business “cookies” – enable the business model on the basis of which the website is provided; blocking them will not make all functionality unavailable, but may reduce the level of service provision due to the website owner’s inability to realize revenues that subsidize its operation. This category includes, for example, advertising “cookies”.
d) Website configuration “cookies” – allow setting functions and services on websites.
e) Website security and reliability “cookies” – allow verifying authenticity and optimizing website performance.
f) Authentication “cookies” – allow you to be informed when you are logged in, so that the website can show you relevant information and features.
g) Session research “cookies” – allow you to record information about how users use the website. They may relate to the most frequently visited pages or possible error messages displayed on certain pages. “Session state” cookies help to improve services and enhance the browsing experience.
h) “Cookies” that examine the processes occurring on the site – allow the smooth operation of the website and the functions available on it.
(i) Advertising cookies – allow ads to be displayed that are more interesting to users and more valuable to publishers and advertisers; cookies can also be used to personalize advertising, as well as to display ads outside of websites.
j) Location-accessing “cookies” – allow you to customize the information displayed to your location.
k) Analytics, research or audience auditing cookies – allow the website owner to better understand the preferences of its users and, through analysis, improve and develop products and services. Typically, the website owner or research company collects information anonymously and processes trend data without identifying the personal data of individual users.

(5) The use of “cookies” to customize the content of the websites to the user’s preferences does not imply, in principle, the collection of any information that allows the user to be identified, although this information may sometimes have the nature of personal data, i.e. data that allow the attribution of certain behaviors to a specific user. Personal data collected using “cookies” may be collected solely for the purpose of performing certain functions for the user. Such data is encrypted in a way that prevents unauthorized access to it.

(6) Cookies used by this site are not harmful either to the user or to the terminal device used by the user, so in order for the site to function properly it is recommended not to disable them in browsers. In many cases, web browsing software (web browser) allows by default to store information in the form of “cookies” and other similar technologies on the user’s terminal device. The user can change the browser’s use of “cookies” at any time. To do this, change the browser settings. How to change the settings varies depending on the software (web browser) you use. You will find relevant instructions on the subpages, depending on the browser you use.

(7) As part of its cookie technology, the Administrator may use tracking pixels or pure GIF files to collect information about how users use its services and how they respond to marketing messages sent by email. A pixel is a software code that allows an object, usually an image the size of a pixel, to be embedded on a page, which provides the ability to track user behavior on the web pages where it is deployed. When the appropriate consent is given, the browser automatically establishes a direct connection to the server that stores the pixel, so the processing of data collected by the pixel is done within the framework of the data protection policy of the partner that administers the aforementioned server.

(8) The Administrator may use Internet log files (which contain technical data such as your IP address) to monitor traffic on its services, troubleshoot technical problems, detect and prevent fraud, and enforce the User Agreement.

(9) The Administrator informs you that the website does not respond to Do Not Track (DNT) signals; however, you may disable certain forms of online tracking, including certain analytics and personalized advertising, by changing the cookie settings in your browser or using our cookie consent tools (if applicable).

(10) detailed information on how to change the settings for cookies and how to delete them yourself in the most popular web browsers is available in the help section of your web browser and on the following sites (just click on the link):
a) Google Chrome
b) Mozilla Firefox
c) Microsoft Edge
d) Opera
e) Safari macOS
f) Safari iOS/iPad OS

(11) Detailed information about the management of cookies on a cell phone or other mobile device should be found in the user manual of the mobile device.

(12) Together with the contact form, the Administrator receives information about the page from which the enquiry was sent and about the source of the current visit (e.g. search engine, link from another website, advertising campaign). With consent to statistical cookies, the Administrator stores in the user’s browser memory (localStorage and sessionStorage) the source of the first visit and the most recently visited pages and, with consent to marketing cookies, also the Google ad click identifier (for 90 days); this information is attached to the submitted form. Withdrawing consent removes it from the browser.