Privacy Policy and the GDPR
Find out how we protect your personal data.
Transparency and security are the cornerstones of Flowgres.
Information on the processing of personal data
1. Personal data controller details
The controller of the Customer's personal data is the Service Provider, i.e. ITMORE spółka z ograniczoną odpowiedzialnością with its registered office in Pruszcz Gdański, at ul. Jana Kochanowskiego 6A/4; 83-000 Pruszcz Gdański, entered into the register of entrepreneurs of the National Court Register kept by the District Court Gdańsk-Północ in Gdańsk, 7th Commercial Division of the National Court Register, under KRS number: 0000600881, NIP: 6040169091, REGON: 36369104600000. The Data Protection Officer (DPO) can be contacted at: office@flowgres.com.
2. Principles of personal data processing
Personal data is processed for the purpose and scope specified in the Act of 18 July 2002 on the Provision of Electronic Services (Journal of Laws No. 144, item 1204, as amended), for the purpose of performing the Service Agreement.
The collected data may also be processed for the purpose of pursuing potential claims, for tax purposes, and to ensure the highest possible quality of the Service.
The scope of entrusted data includes, among others, the following personal data of Users using the Services: first name, last name, billing address, email address, phone number, information on the use of the Service, IP address, and technical data of the Customer's devices. In order to perform the Agreement or carry out another legal transaction with the Customer, the Service Provider may process other data necessary due to the nature of the service provided or the manner of its billing.
While using the Service, in addition to data entered by the User, data regarding the User's IP address, browser type, and operating system type may also be collected automatically.
3. Legal basis for processing personal data
Personal data will be processed to enable the provision of the Service pursuant to Article 6(1)(b) of the GDPR. The legal basis for data processing is the Agreement. Failure to provide personal data may prevent the conclusion and performance of the Agreement. Data will be processed until the Agreement is performed (for the duration of the Service), and thereafter until claims become time-barred and in accordance with obligations arising from applicable law. After the Service ends, the Service Provider processes personal data necessary for billing the Service and pursuing claims for payment for use of the Service, necessary for advertising purposes, market research, and the study of Customers' behavior and preferences, with the results of such research used to improve the Services, subject to Customers' consent and on the terms set out in law.
Giving consent to the processing of data for marketing purposes enables the Customer to receive information about offers, promotions, and services offered by the Service Provider. The legal basis for processing data for marketing purposes is the Customer's consent, which may be withdrawn at any time. Data will be processed until consent is withdrawn. In certain cases, the personal data of visitors to the Service Provider's website may be processed on the basis of the data controller's legitimate interest.
4. Recipients of personal data
The Service Provider may transfer personal data to the following categories of entities:
- • companies providing services related to the supply of servers, and the maintenance and support of IT systems;
- • banks and the electronic payment processor;
- • entities providing legal and tax services in the case of providing legal advice and representing the Service Provider's interests, should such a need arise;
- • companies providing marketing services, if the Customer gives consent to the processing of data for marketing purposes.
5. Rights of data subjects
The Customer has the right to access the content of its data and the right to rectify, delete, and restrict its processing, the right to data portability, the right to object, and the right to withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal. The Customer has the right to lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.
6. Transfer of personal data outside the EEA or to an international organization
The Service Provider does not transfer processed data outside the EEA or to an international organization. In order to ensure the technical operation of the Flowgres Application and the durability of data, data may be copied, duplicated, and stored on servers located in data centers operated by third parties providing data storage and security services for the Service Provider, while all servers are located within the European Union.
7. Automated decision-making and profiling
If the Customer gives consent, the Service Provider may make automated decisions based on personal data obtained in connection with the provision of the Services, including carrying out profiling.
