PRIVACY POLICY
REALVEST ESTATE PROJECT 4 Sp. z o.o.
§ 1. General Provisions
This Privacy Policy sets out the rules for the processing of personal data of persons using the website, contact forms and other communication channels operated by REALVEST ESTATE PROJECT 4 Sp. z o.o., with its registered office in Warsaw.
The purpose of this Privacy Policy is to provide data subjects with the information required under Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”), in particular regarding the data controller, the purposes and legal bases of processing, recipients of the data, the storage period and the rights of data subjects.
This Privacy Policy applies to personal data obtained:
through the Controller’s website,
in connection with contact by e-mail, telephone or contact forms,
in connection with marketing and sales activities,
in connection with business, investment, recruitment and contractual relationships.
§ 2. Data Controller
The controller of your personal data is REALVEST ESTATE PROJECT 4 Sp. z o.o., with its registered office in Warsaw, ul. L. Idzikowskiego 16, 00-710 Warsaw, NIP: 5214058732, REGON: 527876514, hereinafter referred to as the “Controller”.
The Controller may be contacted:
in writing – at the Company’s registered office address,
by e-mail – at: umowy@realvestestate.pl,
by telephone – at: +48 793 970 670.
§ 3. Data Protection Contact
The Controller has appointed a contact person for matters related to the processing of personal data.
In all matters concerning the processing of personal data, including the exercise of data subject rights, contact is possible via e-mail at: umowy@realvestestate.pl.
§ 4. Purposes and Legal Bases for the Processing of Personal Data
The Controller processes personal data in particular for the following purposes:
1. Contact with the website user
In the case of contact via a contact form, e-mail, telephone or any other communication channel, personal data are processed for the purpose of:
responding to the submitted inquiry,
presenting information about the Controller’s offer or projects carried out by the Controller or its partners,
conducting further communication related to interest in the offer.
The legal basis for processing personal data is:
Article 6(1)(b) GDPR – to the extent that processing is necessary to take steps at the request of the data subject prior to entering into a contract,
Article 6(1)(f) GDPR – to the extent of the Controller’s legitimate interest consisting in handling correspondence, responding to inquiries, conducting communication, and establishing, pursuing or defending claims,
Article 6(1)(a) GDPR – if the data subject has given consent to be contacted for a specified purpose, including marketing purposes.
2. Presentation of an investment, sales or commercial offer
Personal data may be processed for the purpose of presenting an offer concerning real estate projects, investment apartments, premises, advisory services or other products offered by the Controller or entities cooperating with the Controller.
The legal basis for processing personal data is:
Article 6(1)(b) GDPR – if the processing is necessary to take steps prior to entering into a contract,
Article 6(1)(f) GDPR – the Controller’s legitimate interest consisting in carrying out sales activities, maintaining business relationships and presenting offers to interested persons,
Article 6(1)(a) GDPR – if prior consent is required by law, in particular for marketing contact by means of electronic communication or terminal telecommunications equipment.
3. Direct marketing
Personal data may be processed for the purpose of direct marketing of the Controller’s products and services or those of entities cooperating with the Controller.
The legal basis for processing personal data is:
Article 6(1)(f) GDPR – the Controller’s legitimate interest consisting in carrying out direct marketing,
Article 6(1)(a) GDPR – where applicable law requires prior consent, in particular for sending commercial information by electronic means or using terminal telecommunications equipment for direct marketing purposes.
4. Analyses, statistics and optimisation activities
Website user data may be processed for the purpose of analysing website activity, compiling statistics, ensuring service security, improving website functionality and optimising marketing activities.
The legal basis for processing personal data is:
Article 6(1)(f) GDPR – the Controller’s legitimate interest consisting in analysing website traffic, ensuring security and improving services,
Article 6(1)(a) GDPR – to the extent that processing takes place using cookies or similar technologies to which the user has consented.
5. Conclusion and performance of contracts
Personal data are processed for the purpose of concluding and performing contracts entered into with clients, investors, lenders, contractors, suppliers and other business partners.
The legal basis for processing personal data is:
Article 6(1)(b) GDPR – performance of a contract or taking steps prior to entering into a contract,
Article 6(1)(c) GDPR – compliance with legal obligations binding on the Controller,
Article 6(1)(f) GDPR – the Controller’s legitimate interest, in particular in the establishment, exercise or defence of claims.
6. Recruitment
Personal data of job or cooperation candidates are processed for the purpose of conducting the recruitment process and, in the case of separate consent, also future recruitment processes.
The legal basis for processing personal data is:
Article 6(1)(b) GDPR – taking steps prior to entering into a contract,
Article 6(1)(c) GDPR – to the extent of obligations arising from labour law provisions,
Article 6(1)(a) GDPR – in the case of consent to participate in future recruitment processes or to provide data beyond the scope required by law,
Article 9(2)(a) GDPR – in the case of voluntary provision of special categories of personal data.
§ 5. Scope of Processed Data
The Controller may process in particular the following categories of personal data:
identification data, including first name and surname,
contact data, including telephone number, e-mail address and correspondence address,
data concerning interest in the offer or planned cooperation,
data contained in forms, e-mails, correspondence or telephone conversations,
data concerning activity on the website, including IP address, internet identifiers, end-device data, browser data, and data collected using cookies and similar technologies.
The scope of processed data depends on the purpose for which the data were provided or obtained.
§ 6. Data Recipients
Personal data may be transferred to entities cooperating with the Controller only to the extent necessary to achieve the purposes of processing.
Recipients of the data may include in particular:
providers of IT, hosting, system maintenance and e-mail services,
providers of CRM systems, analytical tools and marketing automation tools,
entities providing legal, accounting, tax, audit and advisory services,
entities handling advertising campaigns and online analytics,
payment operators, banks, postal and courier service providers,
business or investment partners – only if necessary to achieve the purpose of the contact or on the basis of the separate consent of the data subject,
public authorities and other entities authorised to obtain data under the law.
The Controller ensures that entities entrusted with personal data provide appropriate guarantees of implementing technical and organisational measures compliant with the GDPR.
§ 7. Data Retention Period
Personal data shall be stored for the period necessary to achieve the purpose for which they were collected.
In particular:
data processed for the purpose of handling an inquiry or contact – for the period necessary to conduct correspondence and resolve the matter, and then for the limitation period of any claims,
data processed in connection with marketing activities – until an objection is raised or consent is withdrawn, depending on the legal basis of processing,
data processed in connection with the conclusion or performance of a contract – for the duration of the contract and thereafter for the period required by law, in particular tax and accounting law, and for the limitation period of claims,
candidate data – for the duration of a given recruitment process, and in the event of consent for future recruitment processes – until such consent is withdrawn, but no longer than for the period justified by the recruitment purpose,
data processed on the basis of consent – until consent is withdrawn, unless further processing is permitted on another legal basis.
§ 8. Source of Data
As a rule, personal data are obtained directly from the data subject.
In specific cases, data may also be obtained:
from an entity that indicated the person as a contact person, representative or proxy,
from publicly available registers and sources,
from business, commercial or marketing partners – provided that there is an appropriate legal basis for the transfer.
§ 9. Rights of Data Subjects
The data subject is entitled to the rights provided for in the GDPR, in particular:
the right of access to data,
the right to rectification of data,
the right to erasure of data,
the right to restriction of processing,
the right to data portability,
the right to object to the processing of data,
the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before its withdrawal,
the right to lodge a complaint with the President of the Personal Data Protection Office.
In order to exercise their rights, the data subject may contact the Controller using the contact details indicated in this Privacy Policy.
The right to object applies in particular to processing based on Article 6(1)(f) GDPR, including for direct marketing purposes.
§ 10. Information on the Voluntary Provision of Data
Provision of personal data is generally voluntary; however, it may be necessary in order to:
respond to an inquiry,
present an offer,
conclude or perform a contract,
conduct further communication,
participate in a recruitment process.
Failure to provide data may result in the inability to achieve the above purposes.
§ 11. Automated Decision-Making and Profiling
Personal data may be used for analyses, statistics, audience segmentation and tailoring marketing content and advertising, provided that the data subject has consented where such consent is required by law.
The Controller does not make decisions concerning data subjects that produce legal effects or similarly significantly affect them based solely on automated processing of personal data.
§ 12. Cookies and Similar Technologies
The Controller’s website uses cookies and similar technologies.
Cookies are used in particular for the purpose of:
ensuring the proper functioning of the website,
maintaining the user’s session,
analysing website traffic,
measuring the effectiveness of marketing activities,
tailoring advertising content to user interests.
The website may use:
necessary cookies,
analytical cookies,
functional cookies,
marketing cookies.
The Controller may use tools provided by third parties, in particular in the field of online analytics, advertising campaigns, remarketing, user behaviour analysis and conversion measurement.
To the extent that the use of certain cookies requires the user’s consent, the legal basis for their use is the consent granted via the cookie consent management tool.
The user may at any time change cookie settings via browser settings or the consent management tool available on the website; however, restricting the use of cookies may affect certain website functionalities.
§ 13. Transfer of Data Outside the European Economic Area
In connection with the Controller’s use of IT, analytical, advertising or cloud tools provided by third parties, personal data may be transferred outside the European Economic Area.
In such a case, the Controller ensures that the transfer of data is carried out in accordance with applicable law, in particular on the basis of an adequacy decision, standard contractual clauses or other mechanisms provided for in the GDPR.
Information on the safeguards applied may be made available upon request of the data subject.
§ 14. Data Security
The Controller applies appropriate technical and organisational measures to ensure the protection of processed personal data, adequate to the nature, scope, context and purposes of the processing and the risk of infringement of the rights or freedoms of natural persons.
The Controller continuously carries out risk analysis and monitors the adequacy of the safeguards applied.
§ 15. Final Provisions
This Privacy Policy is of an informational nature.
The Controller reserves the right to amend this Privacy Policy, in particular in the event of:
changes in legal regulations,
technological changes,
changes in the methods of processing personal data,
changes in the functionality of the website or the scope of services provided.
The current version of the Privacy Policy is published on the Controller’s website.