Privacy Policy

In this Privacy and Cookie Policy, we explain what personal data we collect, use, and disclose.

Personal data refers to any information concerning an identified or identifiable natural person whose identity can be determined directly or indirectly based on such data. Personal data may include information such as name, contact details, identification data (online), online identifiers, or other characteristics specific to that natural person.

This Privacy and Cookie Policy applies when you visit the greensearch.pl website.

For the purposes of this privacy policy, the following terms shall have the meanings set forth below:

  1. Website – the website available at https://greensearch.pl
  2. User – any entity that uses the Website.

Information regarding the processing of personal data

1. Personal Data Administrator

The Personal Data Administrator is greensearch Spółka z ograniczoną odpowiedzialnością, with its registered office in Radom 26-600 at ul. Kazimierza Pułaskiego 6/10, entered into the Register of Entrepreneurs of the National Court Register under KRS number 0001144714, NIP 7963033623, REGON 54042805600000.

The Administrator has not appointed a data protection officer.

2. Administrator's Contact Details

For matters concerning the processing of personal data, the User may contact the Administrator as follows:

3. Methods of Personal Data Transfer

The User may provide their personal data to the Administrator by sending an e-mail to the address provided on the Website, by completing a contact form, or by contacting via telephone.

By contacting via e-mail, the User provides the Administrator with their first name, last name, telephone number, and e-mail address as the sender's address. Additionally, other personal data may be included in the message content. In such a case, the legal basis for processing the User's personal data is the consent resulting from initiating contact with the Administrator. Personal data provided by the User via e-mail contact is processed solely for the purpose of handling the inquiry. The content of the correspondence may be archived in accordance with the provider's server security policy.

4. Legal Basis and Purpose of Personal Data Processing by the Administrator

The legal basis for processing personal data is constituted by the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (OJ EU L, No. 119, item 1, as amended, hereinafter referred to as "GDPR"), and the Act of 10 May 2018 on the protection of personal data (Journal of Laws of 2019, item 1781, as amended, hereinafter referred to as "u.o.d.d.").

The Administrator will process the entrusted data for the purpose of:

  • the performance of contracts concluded with the User or taking steps prior to entering into such a contract, as well as responding to inquiries submitted to the Administrator in person, by post, e-mail, or via the contact form on the Administrator's website, including sending information about the launch of the platform by the Administrator or within the Administrator's newsletter, to which the User voluntarily subscribes (Article 6(1)(b) GDPR);
  • fulfilling legal obligations incumbent upon the Administrator pursuant to Article 6(1)(c) GDPR, arising from the provisions of EU law or Polish law;
  • based on the legitimate interest pursued by the Administrator (Article 6(1)(f) GDPR), which the Administrator considers to include, in particular: the establishment, exercise, or defense of legal claims, fraud prevention, ensuring ICT security, archival purposes, and providing services to the User in situations where the User's interest is overriding the interests, rights, and freedoms of the data subjects;
  • telephone or e-mail contact related to the services provided and ongoing business activities, including contract performance and informing about services (legal basis Article 6(1)(f) GDPR).

5. Period of Personal Data Processing

The Administrator processes personal data for the period necessary to achieve legally justified purposes. If the basis for data processing is the User's consent, the Administrator will cease processing the User's personal data immediately upon withdrawal of that consent. In the case of personal data processed by the Administrator in connection with the performance of contracts, this data will be processed until the expiration of the limitation periods for any potential claims. In each of the aforementioned cases, this will not exceed 6 years.

6. Categories of Data Recipients

The User's personal data may be disclosed to third parties in connection with the Administrator's provision of services to the User, and to entities with whom the Administrator cooperates, particularly employees and service providers, including IT and accounting services. These service providers will process data solely based on data processing agreements concluded with the Administrator, for the purpose specified by the Administrator, with the obligation to adequately secure them. To the extent required by law, the User's personal data may be transferred to public administration bodies upon their prior request. The User's personal data is not transferred to countries located outside the European Union or the European Economic Area.

The Administrator does not engage in the trade of personal data.

7. No Profiling

The User's personal data is not subject to profiling as a form of automated personal data processing.

8. Rights Related to Personal Data Processing

The User is entitled to the following rights related to personal data processing:

  • the right to access their data and to receive a copy thereof;
  • the right to rectification (correction) or completion of their data;
  • the right to erasure of personal data, unless data processing is necessary for compliance with a legal obligation, in the exercise of public authority, or is essential for the establishment, exercise, or defense of legal claims; the right to restriction of data processing;
  • the right to data portability of personal data provided to the Administrator, i.e., the right to receive them in a structured, commonly used format and to transmit them to another controller. This right can only be exercised where processing is based on consent or a contract and is carried out by automated means;
  • the right to object, if the processing is carried out for purposes arising from the legitimate interests pursued by the controller or a third party, pursuant to Article 6(1)(f) of the GDPR;
  • the right to lodge a complaint with a supervisory authority – the President of the Personal Data Protection Office (at the address of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw);
  • to the extent that the processing of personal data is based on consent given pursuant to GDPR provisions, the User has the right to withdraw such consent. The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

9. Voluntariness of Providing Personal Data

Regarding the processing of personal data for the purpose of fulfilling legal obligations incumbent upon the personal data Administrator pursuant to Article 6(1)(c) of the GDPR, arising from Union or Polish law, the User's obligation to provide their data is a statutory requirement. However, in cases where data is processed for the purpose of concluding or performing contracts (Article 6(1)(b) of the GDPR), based on the legitimate interest pursued by the data Administrator or a third party (Article 6(1)(f)), or for telephone or email contact related to services rendered and ongoing activities, including contract fulfillment and service information (legal basis Article 6(1)(f) of the GDPR), the provision of personal data by the User is voluntary. Nevertheless, refusal to provide personal data may – depending on the context in which such data is processed – prevent the Administrator from entering into an agreement with the User, affect the scope of services the Administrator can provide to the User, or hinder the Administrator's ability to contact the User, particularly regarding information about the Administrator's products and services.

Cookies

  1. Cookies are divided into "persistent" and "session" types. A persistent cookie consists of a text file sent by a server to a browser, which will be stored by the browser until a set expiry date (unless the user deletes it before the said date). In contrast, a session cookie is a temporary file that expires at the end of the user's current session, upon closing the browser.
    Session cookies are used on the Website. The table below lists the cookies used on the website.
CookiesUse of Cookies
Session Cookies

Session cookies are used to store session information. These files ensure the correct configuration of selected website functions, particularly enabling the verification of browser session authenticity. Session cookies are deleted upon session expiry.

The session cookie mechanism does not allow for the retrieval of any personal data or any confidential information from the user's device.

Persistent CookieA file stored on the user's device upon acceptance of cookie information. This ensures that the user does not have to accept the privacy policy every time they visit the website. Duration - 365 days.
  1. The Administrator hereby informs the User that it is possible to configure their web browser to prevent the storage of cookies on the User's end device. In such a situation, the User's use of the Website may be hindered.
  2. The Administrator hereby indicates that cookies, once stored by the Administrator, can be deleted by the User using appropriate web browser functions, dedicated programs, or relevant tools available within the operating system used by the User.

Server Logs

  1. Use of the Website involves sending requests to the server where the Website is hosted.
  2. Every request directed to the server is recorded in the server logs. These logs include, among other data, the User's IP address, server date and time, and information regarding the web browser and operating system utilized by the User.
  3. Logs are recorded and stored on the server.
  4. Data recorded in server logs are not associated with specific individuals utilizing the Website and are not employed by the Administrator for User identification purposes.
  5. Server logs serve solely as auxiliary material for Website administration, and their content is not disclosed to anyone other than personnel authorized to administer the server.
PARP Logo