Skip to content

Privacy policy

Definitions

  1. Administrator – SAAS GLOBAL Spółka z ograniczoną odpowiedzialnością, entered into the Register of Entrepreneurs of the National Court Register (KRS) kept by the District Court in Rzeszów, 12th Commercial Division of the National Court Register under KRS number: 0001034941, NIP (Tax ID): 8133897453, REGON: 525251425, address: ul. Krakowska 284, 35-213 Rzeszów, Poland;
  2. Personal Data – any information relating to an identified or identifiable natural person. This data identifies a natural person directly or indirectly with respect to their name, email address, telephone number, or other data that, in combination with the above, can identify the User;
  3. Privacy Policy – this Privacy Policy;
  4. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation);
  5. Online Store Website – the website through which the Seller operates the Online Store, operating in the domain saasglobal.pl;
  6. Sales Agreement – a distance sales agreement concluded under the terms specified in the Terms and Conditions of the Online Store Website, between the User and the Administrator;
  7. Electronic Service – a service provided electronically by the owner of the Website to the User via the Online Store Website;
  8. User – any person using the Online Store Website.

I. General Provisions

This Privacy Policy sets out the rules for the processing and protection of Personal Data of Users using the Website available at the domain: www.saasglobal.pl.

The Privacy Policy constitutes the fulfillment of the information obligation resting on the Administrator pursuant to Art. 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

II. Personal Data Controller

The Personal Data Controller of the Users of the Online Store Website is SAAS GLOBAL Spółka z ograniczoną odpowiedzialnością, entered into the Register of Entrepreneurs of the National Court Register (KRS) kept by the District Court in Rzeszów, 12th Commercial Division of the National Court Register under KRS number: 0001034941, NIP (Tax ID): 8133897453, REGON: 525251425, address: ul. Krakowska 284, 35-213 Rzeszów, Poland (hereinafter: “Administrator”).

Contact with the Administrator is possible by post at the following address: ul. Krakowska 284, 35-213 Rzeszów, Poland, or by email at: info@saasglobal.pl.

III. Principles of Personal Data Processing

The Administrator processes the Personal Data of the Website Users in accordance with GDPR regulations.

The Administrator applies the technical and organizational measures required by EU law to ensure the protection of the processed Personal Data and to secure the Personal Data against access by unauthorized persons, seizure by unauthorized persons, processing in violation of the law, as well as alteration, loss, or destruction. The Administrator will inform the User of any incident related to the processing of their Personal Data if it determines that it creates a high risk of violating the User’s rights and freedoms.

The Administrator declares that the provision of Personal Data marked on the Online Store Website by its Users is voluntary, but necessary for the use of certain Electronic Services available within the Website, such as the order form and contact form, as well as for the conclusion and performance of the Sales Agreement.

IV. Purposes and Legal Bases for the Processing of Personal Data, Data Retention Period, and Scope of Personal Data Processing

Users’ Personal Data will be processed for the following purposes:

  1. Execution of Sales Agreements or agreements for the provision of Electronic Services, or taking action at the request of the data subject prior to entering into a contract via the Online Store Website (legal basis: Article 6(1)(b) of the GDPR). The data is stored for the period necessary to perform, terminate, or otherwise expire the concluded agreement. Maximum scope of processed personal data: first name, last name, email address, contact phone number, delivery address, residential/business address, bank account number. In the case of entrepreneurs, the Administrator may additionally process the company name and NIP (Tax ID).
  2. Marketing (legal basis: Article 6(1)(a) of the GDPR). The data is stored until consent is withdrawn by the data subject for further processing of their data for this purpose. Scope of processed personal data: first name/company name, email address.
  3. Expressing an opinion by the User regarding the concluded Sales Agreement (legal basis: Article 6(1)(a) of the GDPR). The data is stored until consent is withdrawn by the data subject for further processing of their data for this purpose. Scope of processed personal data: email address.
  4. Establishing, pursuing, or defending claims that may be raised by the Administrator or raised against the Administrator (legal basis: Article 6(1)(f) of the GDPR). The data is stored for the duration of the legitimate interest pursued by the Administrator, but no longer than until the expiration of the limitation period for claims against the data subject arising from the business activity conducted by the Administrator. The retention period is determined by legal provisions, in particular the Civil Code. Scope of processed personal data: first name, last name, email address, contact phone number, delivery address, residential/business address, bank account number. In the case of entrepreneurs, the Administrator may additionally process the company name and NIP (Tax ID).
  5. Maintaining tax records (legal basis: Article 6(1)(c) of the GDPR). The data is stored for the period required by statutory provisions obligating the Administrator to retain tax records. Scope of processed personal data: first name and last name, residential/business address, company name, NIP (Tax ID).

V. Recipients of Personal Data

For the proper functioning of the Online Store Website, it is necessary for the Administrator to use the services of external entities, such as in particular:

  1. software provider;
  2. hosting provider;
  3. mailing system provider;
  4. invoicing system provider;
  5. technical support providers;
  6. payment processor.

The Administrator uses only the services of such processors who provide sufficient guarantees to implement appropriate technical and organizational measures so that the processing meets the requirements of the GDPR Regulation and protects the rights of the data subjects.

The transfer of Personal Data by the Administrator does not take place in every case and not to all recipients or categories of recipients specified in the Privacy Policy – the Administrator transfers Personal Data only when it is necessary to achieve a given purpose of processing Personal Data and only to the extent necessary to achieve it.

The Administrator enters into appropriate data processing agreements/disclosure agreements with the entities to which it entrusts the Users’ Personal Data.

If it becomes necessary for the Administrator to seek legal assistance, the User’s Personal Data may also be disclosed to a legal counsel or an attorney-at-law obligated to maintain professional secrecy with respect to the Personal Data entrusted to them.

In addition, Users’ personal data may also be transferred to tax offices and other authorities and institutions authorized to obtain access to Personal Data pursuant to applicable legal provisions, such as police services, security services, courts, and prosecutors’ offices.

VI. Place of Personal Data Storage

Users’ Personal Data is stored and secured on servers located in Poland.

VII. Users' Rights in Connection with the Processing of Personal Data

Users are guaranteed the execution of the rights indicated below. A user may exercise their rights by submitting a request via email to the Website owner’s email address: info@saasglobal.pl or by post to the address: ul. Krakowska 284, 35-213 Rzeszów.

  1. Right of access, rectification, restriction, erasure, or data portability – the data subject has the right to request from the Controller access to their personal data, as well as the right to data portability. The detailed conditions for exercising these rights are specified in Articles 15 – 21 of the GDPR.
  2. Right to withdraw consent at any time – a person whose data is processed by the Controller on the basis of given consent (Article 6(1)(a) or Article 9(1)(a) of the GDPR) has the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  3. Right to lodge a complaint with a supervisory authority – a person whose data is processed by the Controller has the right to lodge a complaint with a supervisory authority in the manner and mode specified in the provisions of the GDPR and Polish law, in particular the Personal Data Protection Act. The supervisory authority in Poland is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw.
  4. Right to object – the data subject has the right to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them based on Article 6(1)(e) or (f) of the GDPR, including profiling based on those provisions. In such a case, the Controller shall no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims.
  5. Right to object to direct marketing – where personal data is processed for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning them for such marketing, which includes profiling to the extent that it is related to such direct marketing.

VIII. Implementation for end users

If the User submits a request to the Controller in the exercise of the rights mentioned above, the request will be fulfilled or a refusal will be issued without undue delay, and in any event no later than one month after its receipt by the Controller. The time limit for fulfilling the User’s request may be extended by a further two months if the request is complex or if the User submits a large number of requests.

IX. Requests

The User may submit inquiries to the Administrator regarding the processing of their Personal Data and the exercise of their rights.

X. Automated decision-making and profiling

Users are not subject to decisions based on automated processing and profiling.

XI. Transfer of users' personal data to third countries

Users’ personal data are not transferred to third countries.

XII. Changes to the Privacy Policy

The Administrator may make changes to the Privacy Policy, particularly if necessitated by technological advancements or changes in legal regulations.