The following Privacy Policy sets out the principles for storing and accessing data on Users’ devices used to access the Service for the purpose of electronic provision of services by the Controller, as well as the principles for collecting and processing Users’ personal data provided by them personally and voluntarily through the tools available in the Service.
The following Privacy Policy is an integral part of the Terms of Use of the Service, which define the rules, rights, and obligations of Users of the Service.
§1 Definitions
Service – the “squirrelgear.eu” website, available at https://squirrelgear.eu/en
External Service – websites of partners, service providers, or customers cooperating with the Controller
Controller of the Service / Data – the Controller of the Service and the Data Controller (hereinafter: Controller) is the company “SQUIRREL GEAR Sp. z o.o.” with its registered office at: ul. Czereśniowa 22, 63-500 Potaśnia, NIP: 5140367571, REGON: 543524180, KRS: 0001212365, providing electronic services through the Service
User – a natural person for whom the Controller provides electronic services through the Service.
Device – an electronic device with software through which the User accesses the Service
Cookies – text data stored as files on the User’s Device
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC
Personal Data – any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more specific factors relating to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person
Processing – any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction
Restriction of Processing – the marking of stored personal data with the aim of limiting its future processing
Profiling – any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements
Consent – any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, in the form of a statement or other clear affirmative action, by which the data subject signifies agreement to the processing of personal data relating to them
Personal Data Breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to personal data transmitted, stored, or otherwise processed
Pseudonymization – the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures ensuring that the personal data is not attributed to an identified or identifiable natural person
Anonymization – data anonymization is an irreversible data processing operation in which “personal data” is destroyed or overwritten in such a way that identification or assignment of a dataset to a specific User or natural person becomes impossible.
§2 Data Protection Officer
Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.
In matters concerning data processing, including personal data, the Controller should be contacted directly.
§3 Types of Cookies
Internal Cookies – files stored and read from the User’s Device by the IT system of the Service
External Cookies – files stored and read from the User’s Device by the IT systems of External Services. Scripts of External Services that may place cookies on the User’s Device have been intentionally embedded in the Service through scripts and services made available and installed in the Service
Session Cookies – files stored and read by the Service on the User’s Device during a session of the given Device. After the session ends, the files are deleted from the User’s Device.
Persistent Cookies – files stored and read by the Service on the User’s Device until they are manually deleted. The files are not automatically deleted after the Device session ends, unless the configuration of the User’s Device is set to delete cookies after the session ends.
§4 Data Storage Security
Mechanisms for storing and reading cookies – The mechanisms for storing, reading, and exchanging data between cookies stored on the User’s Device and the Service are implemented through the built-in functions of web browsers and do not allow other data from the User’s Device or data from other websites visited by the User, including personal or confidential data, to be read. The transfer of viruses, Trojan horses, and other worms to the User’s Device is also practically impossible.
Internal Cookies – The cookies used by the Controller are safe for Users’ Devices and do not contain scripts, content, or information that could endanger the security of personal data or the Device used by the User.
External Cookies – The Controller takes all possible measures to verify and select Service partners with regard to User security. The Controller cooperates with well-known, large partners trusted worldwide. However, the Controller does not have full control over the content of cookies from external partners. The Controller is liable for the security of cookies, their content, and their use in accordance with licenses by scripts of External Services installed in the Service only to the extent permitted by law. The list of partners is provided later in this Privacy Policy.
Cookie control
The User may independently change the settings for storing, deleting, and accessing data stored in cookies for each website at any time.
Information on how to disable cookies in the most popular desktop browsers can be found at: How to disable cookies or with one of the following providers:
The User may at any time delete all previously stored cookies using the tools of the Device through which they use the Service.
Risks on the User’s side – The Controller applies all possible technical measures to ensure the security of data stored in cookies. However, it should be noted that the security of this data depends on both parties, including the User’s behavior. The Controller is not liable for the interception of this data, impersonation of the User’s session, or deletion of such data as a result of the User’s intentional or unintentional actions, viruses, Trojan horses, and other spyware with which the User’s Device may be or may have been infected. To protect against these risks, Users should follow the rules for safe internet use.
Storage of personal data – The Controller declares that it makes every effort to ensure that personal data voluntarily entered by Users is secure, access to it is restricted, and processing is carried out in accordance with its purpose and processing objectives. The Controller further declares that it makes every effort to protect the data in its possession from loss by applying appropriate physical and organizational safeguards.
§5 Purposes for Which Cookies Are Used
- Improving and facilitating access to the Service
- Personalizing the Service for Users
- Enabling login to the Service
- Marketing and remarketing in External Services
- Advertising delivery services
- Affiliate services
- Creating statistics: Users, number of visits, device types, connections, etc.
- Providing social services
§6 Purposes of Personal Data Processing
Personal data voluntarily provided by Users is processed for one of the following purposes:
- Provision of electronic services:
- service of registering and maintaining the User account in the Service and related functionalities
- Communication between the Controller and Users in matters related to the Service and data protection
- Protection of the Controller’s legitimate interest
Anonymous and automatically collected data about Users is processed for one of the following purposes:
- Creating statistics
- Remarketing
- Displaying advertisements in accordance with Users’ preferences
- Handling affiliate programs
- Protection of the Controller’s legitimate interest
§7 Cookies of External Services
The Controller uses JavaScript scripts and web components from partners in the Service, which may place their own cookies on the User’s Device. Please note that in your browser settings you can decide which cookies may be used by individual websites. Below is a list of partners or their services implemented in the Service that may place cookies:
- Statistics:
The services provided by third parties are outside the Controller’s control. These entities may change their terms of service, privacy policies, purposes of data processing, and methods of using cookies at any time.
§8 Types of Data Collected
The Service collects data about Users. Some data is collected automatically and anonymously, while other data is personal data provided voluntarily by Users when signing up for individual services offered by the Service.
Automatically collected anonymous data:
- IP address
- Browser type
- Screen resolution
- Approximate location
- Visited subpages of the Service
- Time spent on a given subpage of the Service
- Operating system type
- Address of the previous subpage
- Referring page address
- Browser language
- Internet connection speed
- Internet service provider
Data collected during registration:
- First name / last name / pseudonym
- Login
- E-mail address
- IP address, collected automatically
Data collected when subscribing to the newsletter
- First name / last name / pseudonym
- E-mail address
- IP address, collected automatically
Data collected when posting a comment
- First and last name / pseudonym
- E-mail address
- Website address
- IP address, collected automatically
Some data, excluding identifying data, may be stored in cookies. Some data, excluding identifying data, may be transferred to a statistics service provider.
§9 Access to Personal Data by Third Parties
As a rule, the Controller is the only recipient of the personal data provided by Users. Data collected as part of the services provided is not transferred or sold to third parties.
Access to the data, usually on the basis of a data processing agreement, may be granted to entities responsible for maintaining the infrastructure and services necessary for the operation of the Service, i.e.:
- hosting companies providing hosting or similar services to the Controller
Entrusting the processing of personal data – hosting, VPS, or dedicated server services
For the operation of the Service, the Controller uses the services of an external provider of hosting, VPS, or dedicated server services – LH.pl. All data collected and processed in the Service is stored and processed in the service provider’s infrastructure located in Poland. Access to the data may occur as a result of maintenance work carried out by the service provider’s personnel. Access to this data is regulated by an agreement concluded between the Controller and the service provider.
§10 Method of Personal Data Processing
Personal data voluntarily provided by Users:
- Personal data is not transferred outside the European Union unless it has been made public as a result of an individual action by the User, such as adding a comment or post, making it accessible to anyone visiting the Service.
- Personal data is not used for automated decision-making, including profiling.
- Personal data is not sold to third parties.
Automatically collected anonymous data, excluding personal data:
- Anonymous data, excluding personal data, is transferred outside the European Union.
- Anonymous data, excluding personal data, is not used for automated decision-making, including profiling.
- Anonymous data, excluding personal data, is not sold to third parties.
§11 Legal Bases for Personal Data Processing
The Service collects and processes User data on the basis of:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC
- Article 6(1)(a)
the data subject has given consent to the processing of their personal data for one or more specific purposes - Article 6(1)(b)
processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract - Article 6(1)(f)
processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party
- Article 6(1)(a)
- Act of 10 May 2018 on the Protection of Personal Data
- Telecommunications Law of 16 July 2004
- Act of 4 February 1994 on Copyright and Related Rights
§12 Duration of Personal Data Processing
Personal data voluntarily provided by Users:
As a rule, the provided personal data is stored only for the duration of the service provided by the Controller within the Service. It is deleted or anonymized within 30 days after the end of the service provision, e.g. deletion of a registered User account, unsubscribing from the newsletter, etc.
An exception applies where the Controller’s legitimate purposes require further processing of this data. In such a case, the Controller stores the provided data from the moment of the User’s deletion request for no longer than 3 years if the User has violated, or is suspected of having violated, the provisions of the Terms of Use of the Service.
Automatically collected anonymous data, excluding personal data:
Anonymous statistical data that does not constitute personal data is stored by the Controller indefinitely for the purpose of creating Service statistics.
§13 Users’ Rights Related to Personal Data Processing
The Service collects and processes User data on the basis of:
Right of access to personal data
Users have the right to access their personal data upon request submitted to the ControllerRight to rectification of personal data
Users have the right to request that the Controller immediately rectify inaccurate personal data and/or complete incomplete personal data, upon request submitted to the ControllerRight to erasure of personal data
Users have the right to request that the Controller immediately erase personal data, upon request submitted to the Controller. In the case of User accounts, erasure of data consists of anonymizing the data that enables identification of the User. The Controller reserves the right to postpone the fulfillment of an erasure request in order to protect the Controller’s legitimate interest, e.g. if the User has violated the Terms of Use or the data was collected as a result of correspondence.
In the case of the newsletter service, the User may delete their personal data independently via the link included in each e-mail.Right to restriction of personal data processing
Users have the right to request restriction of personal data processing in the cases referred to in Article 18 of the GDPR, including where the accuracy of personal data is contested, upon request submitted to the ControllerRight to data portability
Users have the right to receive from the Controller the personal data concerning them in a structured, commonly used, and machine-readable format, upon request submitted to the ControllerRight to object to personal data processing
Users have the right to object to the processing of their personal data in the cases referred to in Article 21 of the GDPR, upon request submitted to the ControllerRight to lodge a complaint
Users have the right to lodge a complaint with the supervisory authority responsible for personal data protection.
§14 Contact with the Controller
The Controller may be contacted in one of the following ways:
Postal address – SQUIRREL GEAR Sp. z o.o., ul. Czereśniowa 22, 63-500 Potaśnia
- Phone number: +48 695 910 440
E-mail address – hello@squirrelgear.eu
Contact form – available at: /kontakt
§15 Service Requirements
Restricting the storage of and access to cookies on the User’s Device may result in some functions of the Service not working properly.
The Controller is not liable for improperly functioning features of the Service if the User in any way restricts the ability to store and read cookies.
§16 External Links
The Service may contain links to external websites in articles, posts, entries, or User comments with which the owner of the Service does not cooperate. These links, and the pages or files provided through them, may be dangerous for your Device or may pose a security risk to your data. The Controller is not liable for content located outside the Service.
§17 Changes to the Privacy Policy
The Controller reserves the right to change this Privacy Policy at any time without informing Users, insofar as this concerns the use of anonymous data or the use of cookies.
The Controller reserves the right to change this Privacy Policy in the area of personal data processing at any time. Users with a User account or Users subscribed to the newsletter will be informed by e-mail within 7 days of any change to the provisions. Continued use of the services means that you have read and accepted the changes made to the Privacy Policy. If the User does not agree to the changes, they are obliged to delete their account in the Service or unsubscribe from the newsletter.
Changes made to the Privacy Policy will be published on this subpage of the Service.
Changes made enter into force upon their publication.