Privacy Policy
Definitions
Controller – KP Krzysztof Piórkowski, Tax ID (NIP): 7123457574, ul. Relaksowa 12/25, 20-819 Lublin, Poland.
Personal data – information relating to a natural person who is identified or identifiable by reference to one or more specific factors determining physical, physiological, genetic, mental, economic, cultural or social identity, including device IP, location data, online identifier and information collected through cookies and other similar technologies.
Policy – this Privacy Policy.
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
Website – the website operated by the Controller, available at https://rymatic.pl/.
User – any natural person who visits the Website or uses one or more of the services or functionalities described in the Policy.
Processing of data in connection with the use of the Website
When the User uses the Website, the Controller collects data necessary to provide the offered services and records information about the User's activity on the Website. Below are the detailed rules and purposes of processing Personal data collected while the User uses the Website.
Use of the Website
Personal data of Website users, including IP addresses or other identifiers and data collected via cookies and other similar technologies, are processed by the Controller for the following purposes:
- providing services by electronic means, including access to content collected on the Website, which is necessary for the performance of a contract (Art. 6(1)(b) GDPR);
- analytical and statistical purposes, including analysing the activity and preferences of Users in order to improve functionality and services, which constitutes the legitimate interest of the Controller (Art. 6(1)(f) GDPR);
- establishing and pursuing claims or defending against claims, which is also the legitimate interest of the Controller (Art. 6(1)(f) GDPR) and serves to protect its rights;
- the Controller's marketing activities, which are described in detail in the MARKETING section.
The User's activity on the Website and their personal data are recorded in system logs (special software used to store a chronological record of information about events related to the IT system). Information collected in the logs is processed primarily for the purpose of providing services. In addition, the Controller processes this data for technical and administrative purposes, to ensure the security of the IT system and manage it, as well as for analytical and statistical purposes, where the legal basis is the legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Contact forms
When using the contact form available on the Website, depending on the subject of the enquiry, the controller of Users' personal data is KP Krzysztof Piórkowski, Tax ID (NIP): 7123457574, ul. Relaksowa 12/25, 20-819 Lublin, Poland. Each Controller provides the possibility of contact via an electronic contact form. Using the form requires providing personal data necessary to contact the User and respond to the enquiry. The User may provide additional data to facilitate handling of the enquiry. Providing data marked as mandatory is necessary to consider and handle the enquiry; failure to provide it makes handling the enquiry impossible. Providing additional data is optional. Personal data is processed:
- in order to identify the sender and handle their enquiry submitted via the form – the legal basis is the necessity of processing for the performance of a service contract (Art. 6(1)(b) GDPR); for data provided voluntarily, the legal basis is consent (Art. 6(1)(a) GDPR);
- for analytical and statistical purposes – the legal basis is the legitimate interest of the Controllers (Art. 6(1)(f) GDPR), consisting in analysing statistics of enquiries submitted by Users via the Website in order to improve its functionality.
Marketing
The Controller processes Users' personal data for marketing purposes, which include:
- carrying out direct marketing activities, including sending commercial information by electronic means and conducting telemarketing activities.
Direct marketing
The User's personal data may be used by the Controller to deliver marketing content through various channels, such as e-mail, MMS/SMS or by phone, provided that the User has given consent, which may be withdrawn at any time.
The Controller may also conduct direct marketing by traditional post. Users will be informed separately about such marketing activities. The User has the right to object to marketing carried out by traditional post.
Cookies and similar technology
Cookies are small text files installed on the device of a User browsing the Website. Cookies collect information that facilitates navigation on the website – for example, by remembering the User's visits to the Website and their actions.
"Service" cookies
The Controller uses so-called service cookies primarily to provide electronic services and improve the quality of those services. Therefore, the Controller and other entities providing analytical and statistical services use cookies, storing information or accessing information already stored on the User's end device (computer, phone, tablet, etc.). The cookies used include:
- cookies with data entered by the User (session ID) for the duration of the session (user input cookies);
- authentication cookies used for services requiring authentication, for the duration of the session (authentication cookies);
- security cookies, e.g. used to detect authentication abuse (user centric security cookies);
- multimedia player session cookies (e.g. flash player cookies) for the duration of the session (multimedia player session cookies);
- persistent cookies used to personalize the User interface, for the duration of the session or slightly longer (user interface customization cookies).
Analytical and marketing tools used by the Controller's partners
The Controller, together with its Partners, uses a variety of technologies and tools for analytics and marketing. Below is general information about these tools. More details can be found in the privacy policies of the individual partners.
Google Analytics
Google Analytics cookies are files used by Google to analyse how the User uses the Website and to create statistics and reports on the operation of the Website. Google does not use the collected data to identify the User, nor does it combine this information in a way that would enable identification. Detailed information on the scope and rules of data collection by this service is available at:
Managing cookie settings
Using cookies to collect data, including access to data stored on the User's device, requires the User's consent. The User may withdraw this consent at any time. Cookies may be used without consent only when they are necessary to provide a telecommunications service, e.g. data transmission necessary to display content. Consent to the use of cookies can be withdrawn by changing browser settings. Detailed information on this subject is available at the following links:
The User can check the current privacy settings for the browser they use at:
Personal data processing period
The period of processing personal data by the Controller depends on the type of service offered and the purpose of processing. As a rule, data is processed for the duration of the service or order fulfilment, until the consent given is withdrawn or an effective objection is raised in cases where the processing is based on the legitimate interest of the Controller.
The processing period may be extended if necessary to establish, pursue or defend against potential claims. After this period, data may only be processed to the extent and for the time required by law. After this time, data is irreversibly deleted or anonymized.
User rights
The User has the right to access their data, rectify it, delete it, restrict its processing, transfer the data and object to its processing. The User also has the right to lodge a complaint with the supervisory authority responsible for the protection of personal data.
If the processing of the User's data is based on consent, it can be withdrawn at any time by contacting the Controller by e-mail at kontakt@rymatic.pl or by traditional post to the address indicated above.
The User may also object to the processing of their data for marketing purposes if the data is processed on the basis of the Controller's legitimate interest. The User also has the right to object on grounds relating to their particular situation in other cases where the legal basis for processing is the legitimate interest of the Controller, for example for analytical and statistical purposes.
Data recipients
As part of the provision of services, Users' personal data will be disclosed to external entities, including primarily IT system providers, banks and payment operators, accounting firms, couriers (for order fulfilment), marketing agencies (for the provision of marketing services) and companies affiliated with the Controller, including companies belonging to its capital group. Data of Users using training services will be transferred to providers of educational tools.
The Controller also reserves the right to disclose specific information about the User to competent authorities or third parties who request such information based on an appropriate legal basis and in accordance with applicable law.
Transfer of data outside the EEA
The level of personal data protection outside the European Economic Area (EEA) differs from the standards set by European law. For this reason, the Controller transfers personal data outside the EEA only when necessary and always with an adequate level of protection, which is ensured by:
- cooperating with entities processing personal data in countries for which the European Commission has issued a decision confirming an adequate level of personal data protection;
- using standard contractual clauses prepared by the European Commission;
- applying binding corporate rules approved by the competent supervisory authority.
The Controller informs about the intention to transfer personal data outside the EEA already at the stage of its collection.
Personal data security
The Controller systematically carries out risk analysis to ensure that personal data is processed securely. Above all, this guarantees that only authorized persons have access to the data, and only to the extent necessary to perform their duties. The Controller also ensures that all operations on personal data are recorded and performed only by authorized employees and associates.
In addition, the Controller takes all necessary steps to ensure that its subcontractors and other cooperating entities also apply appropriate security measures whenever they process personal data on behalf of the Controller.
Contact details
The Controller can be contacted at the e-mail address kontakt@rymatic.pl.
Changes to the privacy policy
The Policy is regularly reviewed and updated as needed. The current version of the Policy was adopted and has been in force since 2024.