Privacy Policy

Introduction

We appreciate your interest in VML (hereinafter "We", "Us") and that you visit our website.
With the following privacy policy, we would like to inform you about how we process your personal data in accordance with the European Data Protection Regulation (GDPR). This privacy policy applies to all processing of personal data carried out by us, both in the context of the provision of our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online offer").

1. Controller

Controller according to the GDPR is:

VMLY&R sp. z o.o., 03-736 Warszawa, plac Konesera 11, Poland
Email: pl-contact@vml.com

2. Data protection officer

You can reach our data protection officer as follows:

Paweł Piorun
Email: pawel.piorun@vml.com
Phone: +48 501 306 501

You can contact our data protection officer directly at any time with all questions and suggestions regarding data protection and the exercise of your rights.

3. Definition

This privacy policy is based on the terminology of the GDPR. For your convenience, we would like to explain some important terms in this context in more detail:

  • Personal Data: Personal data is any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • Data subject: The data subject is any identified or identifiable natural person whose personal data is processed by the controller.
  • Processing: Processing means any operation or set of operations which is performed upon personal data, whether by automatic means, such as collection, recording, organization, filing, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • Recipient: a recipient is a natural or legal person, public authority, agency or other body to whom personal data are disclosed, for example a third party. However, public authorities that may receive personal data in the context of a specific investigative task under Union or Member State law are not considered recipients.
  • Third party: a third party is a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor and the persons who, under the direct responsibility of the controller or the processor, are authorized to process the personal data.
  • Consent: Consent means any freely given indication of the data subject's wishes in an informed and unambiguous manner for the specific case in the form of a declaration or other unambiguous affirmative action by which the data subject indicates that he or she consents to the processing of personal data relating to him or her.

4. Origin of personal data

We may obtain personal information in the following ways:

4.1 Information provided by you

You can provide information (e.g. contact details) about yourself on our website.

4.2 Automatically collected and generated data

By using our website, data is automatically collected and generated.

4.3 Data collected by third parties

To the extent we maintain presences on social and professional networks, we may receive data from you through them (e.g., if you contact us through a social or professional network or respond to any of our content shared there). Scope, purpose, legal basis, storage period and, if applicable, recipients and third country transfer of the respective processing of personal data.

5. General information

5.1 Legal basis

In the following, we provide you with an overview of which personal data we process. For this purpose, we present to what extent, for what purposes and on what legal basis we process personal data.

We will not disclose your personal data to third parties without your consent, unless this is permitted by law (e.g., because it is necessary for the performance of the contract).

The processing of your personal data may be based in particular on the following legal bases:

  • Art. 6 (1) (a) GDPR serves as our legal basis for processing operations in which we obtain consent for a specific processing operation.
  • If the processing of personal data is necessary for the performance of a contract to which you are a party, the processing is based on Art. 6 (1) (b) GDPR. The same applies to such processing operations which are necessary for the performance of pre-contractual measures.
  • If we are subject to a legal obligation by which processing personal data becomes necessary, the processing is based on Art. 6 (1) (c) GDPR.
  • Furthermore, processing operations may be based on Art. 6 (1) (f) GDPR. Processing operations are based on this legal basis if the processing is necessary to protect a legitimate interest of ours, provided that the interests, fundamental rights and freedoms of the data subject do not override.

5.2 Data transfers to third countries

Among other things, we use services of companies that are based in third countries (e.g. in the USA). If these services are active, it is possible that data will be transferred to a third country and processed there. We would like to point out that no level of data protection comparable to that in the EU can be guaranteed in these countries.

US companies, for example, are obliged to hand over data to authorities or similar institutions, if necessary, without you as the data subject being able to take effective legal action against this, according to our legal understanding. We have no influence on such data transfer.

5.3 Erasure of data

The personal data processed by us will be deleted in accordance with the legal requirements as soon as your consents permitted for processing are revoked or other permissions cease to apply (e.g., if the purpose of processing this data has ceased to apply or it is not required for the purpose). If the personal data are not deleted because they are required for other and legally permissible purposes, their processing will be limited to these purposes. That is, the personal data is blocked and not processed for other purposes. This applies, for example, to personal data that must be retained for reasons of commercial or tax law or whose storage is necessary for the assertion, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person.

As far as our privacy policy contains further information on the retention and deletion of personal data, those have priority for the respective processing activities.

5.4 Security measures

We take appropriate technical and organizational measures in accordance with the legal requirements, taking into account the state of the art, the implementation costs and the nature, scope, circumstances and purposes of the processing, as well as the different probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, in order to ensure a level of protection appropriate to the risk.

The measures include safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access to the data as well as access to, input of, disclosure of, assurance of availability of and segregation of the data. Furthermore, we have established procedures to ensure the exercise of data subjects' rights, the deletion of data, and responses to data compromise. We take the protection of personal data into account as early as the development or selection of hardware, software and processes in accordance with the principle of data protection, through technology design and through data protection-friendly default settings.

5.5 Transmission of personal data

In the course of our processing of personal data, personal data may be transferred to or disclosed to other recipients. Recipients of this personal data may include, for example, service providers commissioned with IT tasks or providers of services and content that are integrated into a website. In such cases, we comply with the legal requirements and, in particular, conclude appropriate contracts or agreements that serve to protect your personal data with the recipients of your personal data.

6. Website in general

6.1 Provision of the website, server log files

If you use this website for purely informational purposes without otherwise transmitting data to us (e.g., by registering or using the contact form), we collect via server log files technically necessary data that are automatically transmitted to our server, including:

  • Date and time of access
  • IP address
  • Host name of the accessing computer
  • Website from which the website was accessed; websites accessed via the website
  • Visited page on our website; Amount of data transferred
  • Information about the browser type and version used
  • Operating system
  • Access status (e.g., whether the web page could be accessed without problems or whether you received an error message)
  • Use of website functions
  • Entered search terms
  • Access frequency of the individual web page
  • Data volume transferred
  • Other websites that you visit starting from this website, either by clicking on a link on this website or by directly entering the domain in the input bar in the same window of your browser

The temporary storage of data is necessary for the course of a website visit in order to display our website to you. This processing is technically necessary to ensure the functionality of the website and the security of the information technology systems. The legal basis of the processing is thus Art. 6 para. 1 p. 1 lit. f GDPR, in order to guarantee the provision, security and stability of our website.

The data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. In the case of the provision of the website, this is the case when the respective session has ended. The log files are stored maximum up to 24 hours directly and exclusively accessible to administrators. After that, they are only indirectly available via the reconstruction of backup tapes and are finally deleted after, maximum four weeks.

For the provision of our online offer, we use storage space, computing capacity and software that we rent or otherwise obtain from the server provider Webflow, Inc. 398 11th Street, 2nd Floor, San Francisco, CA 94103 (hereinafter: Webflow) (web host). The location of the cloud server is U.S. Personal data is transferred to the U.S.. There is an adequacy decision of the Commission pursuant to Art. 45(3) GDPR. The European Commission has adopted an adequacy decision pursuant to Art. 45(3) GDPR for the EU-U.S. Data Privacy Framework. Based on this decision, data transfers to organizations located in the U.S. that are certified under the EU-U.S. Data Privacy Framework are permitted, accordingly. Webflow is certified under the EU-U.S. Data Privacy Framework.

6.2 Use of cookies

Cookie banner

When you visit our website or a sub-website for the first time and it contains cookies, you will be shown a "cookie banner". There you will be informed about the individual cookies that we use. You can find out about each individual cookie with regard to the name, the provider, the purpose of the processing and the storage period.

With our cookie banner, we inform you about the cookies we specifically use. In addition, we give you the opportunity to decide whether you want to consent to the setting of cookies that are not necessary. Processed are:

  • Usage data (e.g., web pages visited, time of access)
  • Meta and communication data (e.g., IP address)

The legal basis for the use of the cookie banner is Art. 6(1) s. 1 lit. f GDPR. We have an overriding legitimate interest in using the cookie banner, which allows us to obtain the legally required consent for the use of cookies that are not necessary and to comply with our duty to provide information regarding cookies.

The cookie banner stores the preferences until you reset or customize them.

The cookie banner is provided via the provider Cookiebot by Usercentrics (hereinafter: Usercentrics). Provider is Usercentrics GmbH, Sendlinger Straße 7, 80331 München. Further information on data processing by Usercentrics can be found here.

Use of cookies - General information

We use cookies on our website. These are text files that are automatically created by your browser and stored on your IT system when you visit our site. Through cookies, certain information flows to the location setting the cookie. Through the use of cookies, it is not possible to execute programs or transfer viruses to your terminal device.

If you do not wish to use cookies, you can disable them under the settings.

In legal terms, a distinction must be made between necessary and non-necessary cookies.

  • Necessary cookies
    We use necessary cookies. These are cookies that are technically necessary to provide all the functions of our website. The legal basis for data processing is our legitimate interest within the meaning of Art. 6(1) s. 1 lit. f GDPR. We have an overriding legitimate interest in being able to offer our service in a technically flawless manner. The legal basis for the use of cookies vis-à-vis our contractual partners who make use of services contractually owed by us via our website is Art. 6(1) S. 1 lit. b GDPR, the provision of our contractual services.
  • Non-essential cookies
    We also use non-essential cookies (e.g., analysis and marketing cookies). These are cookies that are not technically necessary. We use them to understand your behavior on our website and to improve our offer. The legal basis for the data processing is your consent according to Art. 6(1) s. 1 lit. a GDPR. The cookies are only set after you have given your consent via our "cookie banner".

Storage period

With regard to the storage period, the following types of cookies are distinguished:

  • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user has left an online offer and closed his end device (e.g., browser or mobile application).
  • Permanent cookies: Permanent cookies remain stored even after the end device is closed. For example, the login status can be saved or preferred content can be displayed directly when the user visits a website again. Likewise, user data collected with the help of cookies can be used for reach measurement. Unless we provide users with explicit information about the type and storage duration of cookies (e.g., as part of obtaining consent), users should assume that cookies are permanent and that the storage period can be up to two years.

For more information, please refer to the information we provide in the Cookie Banner.

6.3 Contact options

Through our website you have the possibility to contact us via email. In the course of contacting, you and responding to your inquiry, we process the following personal data from you:

  • First and last name
  • E-mail address
  • Phone number
  • Date and time of the request
  • IP address
  • Communication content

If you contact us within the framework of an existing contractual relationship or contact us in advance for information about our range of services or our other services, the personal data you provide will be processed for the purpose of processing and responding to your contact request in accordance with Art. 6(1) s. 1 lit. b GDPR. Otherwise, for the protection of our legitimate interests pursuant to Art. 6(1) s. 1 lit. f GDPR to respond to customer/contact inquiries.

We delete your personal data as soon as they are no longer required to achieve the purpose for which they were collected. In the context of contact inquiries, this is generally the case when the circumstances indicate that the specific matter has been conclusively processed.

Your data will be forwarded to regional partners of ours who will contact you directly as part of the quotation preparation and installation process. In addition, your data will be passed on to a service provider for customer contact management as part of order processing to the extent necessary.

6.4 Social media presences

We maintain publicly accessible profiles on various social networks. Your visit to these profiles initiates a variety of data processing activities. In the following, we provide you with an overview of which of your personal data is collected, used and stored by us when you visit our profiles.

When you visit our profiles, your personal data is collected, used and stored not only by us, but also by the operators of the respective social network. This happens even if you do not have a profile in the respective social network. The individual data processing operations and their scope differ depending on the operator of the respective social network and they are not necessarily traceable for us. For details about the collection and storage of your personal data and about the type, scope and purpose of their use by the operator of the respective social network, please refer to the following statements.

Instagram

When you visit our Instagram profile, certain information about you is processed. We can only view the information stored in your public Instagram profile (such as your profile picture or information you share on a Facebook profile or on a public Instagram profile), and only if you have such a profile and are logged into it while visiting our Instagram page.

In addition, the operator of the platform, Meta Platforms Ireland Limited, Serpentine Avenue, Block J, Dublin 4 Ireland (Meta), provides us with anonymized statistics and insights for our Facebook/Instagram page, which help us gain insights into the types of actions people take on our page (Page Insights). These Page Insights are created based on certain information about people who have visited our page.

The processing of your personal data in connection with the operation of our Instagram profile is carried out on the basis of a balance of interests pursuant to Art. 6(1), s.1 lit. f GDPR in order to offer you a timely and supportive information and interaction option with and about us. Furthermore, the processing serves our legitimate interest to evaluate the types of actions taken on our Instagram profile and to improve our profile based on these findings. The legal basis for this processing is therefore Art. 6(1) s. 1 lit. f GDPR. If the contact aims at the conclusion of a contract, the legal basis for the processing is Art. 6(1) s.lit. b GDPR.

Processing of Page Insights is carried out by Meta and us as joint controllers. We cannot attribute the information obtained via Page Insights to individual Instagram profiles that interact with our Instagram profile. We have entered into a joint controller agreement with Meta, which sets out the allocation of data protection obligations between us and Meta. Details about the processing of personal data to create Page Insights and the agreement entered into between us and Meta are available here. In relation to this data processing, you have the option of asserting your data subject rights (see "Your rights as a data subject") against Meta as well. Further information on this can be found in Meta's Privacy Policy. Meta offers the possibility to object to data processing; you can find information on this and opt-out options here in your account.

Please note that according to the meta data protection regulations, user data is also processed in the U.S. or other third countries. The European Commission has issued an adequacy decision pursuant to Art. 45(3) GDPR for the EU-U.S. Data Privacy Framework. Based on this decision, data transfers to organizations located in the U.S. that are certified accordingly are permitted. Meta is certified under the EU-U.S. Data Privacy Framework.

LinkedIn

When you visit our LinkedIn company profile, certain information about you is processed. In the case of direct messages to us or comments on our LinkedIn company profile or under our posts, we receive the message, the comments and your username.

In addition, the operator of the platform, LinkedIn Ireland Unlimited Company, Wilton Place,Dublin 2, Ireland (LinkedIn), processes personal data when you visit our LinkedIn company profile, follow this page or engage with the page, to provide us with statistics and insights in anonymized form. This provides us within sights into the types of actions that people take on our site (Page Insights). For this purpose, LinkedIn processes in particular such data that you have already provided to LinkedIn via the information in your profile, such as data on function, country, industry, seniority, company size and employment status. In addition, LinkedIn will process information about how you interact with our LinkedIn company profile, such as whether you are a follower of our LinkedIn company profile. With the page insights, LinkedIn does not provide us with any personal data about you. We only have access to the aggregated Page Insights. It is also not possible for us to draw conclusions about individual members using the information in the Page Insights.

The processing of your personal data in connection with the operation of our LinkedIn company profile is carried out on the basis of a balancing of interests pursuant to Art. 6(1) s. 1 lit. f GDPR in order to offer you an up-to-date and supportive information and interaction option with and about us. The processing serves our legitimate interest to evaluate the types of actions taken on our LinkedIn company profile and to improve our company profile based on these findings.

This processing of personal data in the context of Page Insights is carried out by LinkedIn and us as joint controllers. We have reached an agreement with LinkedIn on processing as joint controllers, which specifies the distribution of data protection obligations between us and LinkedIn. The agreement is available here. Accordingly, the following applies:

  • LinkedIn and we have agreed that LinkedIn is responsible for exercising your rights under the GDPR. You can contact LinkedIn to do so online via following link or reach LinkedIn via the contact details in the Privacy Policy. You can contact the Data Protection Officer at LinkedIn via the following link. You may also contact us at our provided contact details to exercise your rights in connection with the processing of personal data in the context of the Page Insights. In such a case, we will forward your request to LinkedIn.
  • LinkedIn and we have agreed that the Irish Data Protection Commission is the lead supervisory authority overseeing processing for Page Insights. You always have the right to lodge a complaint with the Irish Data Protection Commission (see here) or any other supervisory authority.

In addition, LinkedIn processes your data as a user for the provision of services, communication, further development of services and research as well as for purposes of advertising, customer support, analysis and security. LinkedIn is the sole controller for the processing of personal data when visiting our LinkedIn company profile. The categories of personal data that LinkedIn processes in this context are described in LinkedIn's data policy. Further information about the processing of personal data by LinkedIncan be found here.

Please note that in accordance with the LinkedIn Privacy Policy, personal data may also be processed by LinkedIn in the U.S. or other third countries.

6.5 Plugins and embedded functions and content

We use social plugins from various social media platform providers (providers) on our website. When you call up one of our websites that contains such a plugin, your browser establishes a direct connection with the servers of the provider in question. The content of the plugin is transmitted by the provider directly to your browser and integrated by it into the website.

By integrating the plugins, the provider receives the information that you have accessed the corresponding page of our website. In the process, various usage data (such as the URL called up and the IP number of the user) are forwarded to the third-party provider and the latter may set cookies that identify the user. If you are logged in to the respective provider, the provider has the possibility to assign this information to your account. Based on this data, content or advertising can be offered tailored to you. Information on this and on the available setting options can be found on the following websites:

The legal basis for the processing of the data is your consent pursuant to Art. 6(1) lit. a. GDPR. We integrate the plugin in each case via the so-called "two-click solution". When you visit our website, no personal data is transferred to the plugin owner. Only when you give your consent via the integrated pre-switch button, a data flow from our website to the respective provider starts.

6.6 Website Analytics

Google Analytics

We use Google Analytics from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as an analysis service for the statistical evaluation of our online offer. This includes, for example, the number of views of our online offering, sub-pages visited and the length of stay of visitors. Google Analytics uses cookies and other browser technologies to evaluate user behaviour and recognise users. This information is used, among other things, to compile reports on website activity.

We process data with the help of Google Analytics for the purpose of optimising our website and for marketing purposes on the basis of your consent pursuant to Art. 6 para. 1 lit. a. DSGVO.

The specific storage period of the processed data cannot be influenced by us, but is determined by Google Ireland Limited. Further information can be found in the Privacy Policy for Google Analytics.

7. Your rights

As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR. If you wish to exercise any of your rights, please contact us via the contact addresses provided above or our data protection officer.

7.1 Right of objection

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1) lit. e or lit. f GDPR; this also applies to profiling based on these provisions. If the personal data concerning you is processed for the purpose of direct marketing, you have the right to object at any time to the processing of personal data concerning you for the purpose of such marketing; this also applies to profiling insofar as it is related to such direct marketing. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

7.2 Right of access to your personal data

You have the right to request confirmation as to whether personal data in question is being processed and to information about this personal data, as well as further information and a copy of the personal data in accordance with the legal requirements.

7.3 Right to rectification

In accordance with the legal requirements, you have the right to request that the personal concerning you be completed or that incorrect personal data concerning you be corrected.

7.4 Right to erasure and restriction of processing

You have the right to demand that personal data concerning you be deleted immediately if one of the reasons provided for by law applies and insofar as the processing or storage is not necessary.

7.5 Restriction of processing

You have the right to demand that we restrict processing if one of the legal requirements is met.

7.6 Right to data portability

You have the right to receive personal data concerning you, which you have provided to us, in a structured, common and machine-readable format in accordance with the legal requirements, or to request that it be transferred to another controller.

7.7 Right of withdrawal for consents

You have the right to revoke any consent you have given at any time.

7.8 Withdrawal of consent under data protection law

You have the right to withdraw your consent to the processing of personal data at any time with effect for the future.

7.9 Complaint to a supervisory authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the requirements of the GDPR.

8. Changes of the data protection information

This privacy notice is currently valid and has the following status: March 2024.

We adapt the privacy policy as soon as the changes in the data processing carried out by us make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g., consent) or other individual notification

If we further develop our website and our offers or if legal or regulatory requirements change, it may be necessary to amend this data protection notice. You can access the current data protection information at any time here.