Privacy Policy

PRIVACY POLICY OF THE WWW.ASTRAFOX.COM WEBSITE

Dear User,

We place great emphasis on protecting your personal data and processing it in accordance with the relevant legal provisions. Our aim is to provide you with full information about the processing of your data by us.

Below we present information on how we process your personal data in connection with the use of our website.

BASIC INFORMATION
1.1. This privacy policy describes the principles of handling personal data of users using the https://astrafox.com website (hereinafter referred to as “Website”).

1.2. The data controller for personal data collected via the Website is

Astrafox Sp. z o.o. with its headquarters in Warsaw,
Poloneza 93 St., 02-826 Warsaw,
KRS: 0000193522, NIP: 525-21-71-560, REGON: 016263968,
hereinafter referred to as “Administrator” or “We”.

1.3. You can contact us by phone at: +48 22 355 21 60, by email at: office@astrafox.pl, or by traditional mail at the Administrator’s headquarters address.

1.4. Every entity using the Website is its “User”.

1.5. We process your personal data in accordance with the applicable legal provisions, in particular in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as “GDPR”.

1.6. The Administrator has appointed a Data Protection Officer (DPO) with whom you can contact on all matters related to the processing and protection of personal data by writing to the e-mail address: iod@astrafox.pl.

PURPOSES AND LEGAL BASIS FOR DATA PROCESSING
2.1. “Contact Us” form

2.1.1. If you write to us via the “Contact Us” form, we will process your personal data to respond to your question and address the matter you raise using the contact details you provide in the form. The legal basis for processing your personal data is the legitimate interest of the Administrator, which consists of responding to the User’s messages and communicating with the User (Article 6(1)(f) of the GDPR).

2.1.2. If you contact us with a request to provide a commercial offer, we will process your personal data for this purpose based on Article 6(1)(b) of the GDPR, i.e. taking actions at the request of the data subject before concluding a contract (if you will be a party to the contract) or based on our legitimate interest in presenting the ordered offer (Article 6(1)(f) of the GDPR) if you represent a legal entity.

2.1.3. [Marketing consents] If, when sending a message using the Contact form, you voluntarily check the optional consents located under the form (for email marketing or telephone marketing), your personal data, depending on the consents given and the data provided, will be processed for the purposes of:

a. sending marketing and commercial content related to our offer by Astrafox Sp. z o.o. electronically to the e-mail address you provided in the form in the future;
b. contacting you by phone in the future to present you with marketing and commercial content related to our offer to the phone number you provided in the form.

2.1.4. We would like to point out that contact from our side for marketing purposes will certainly not be intrusive and will occur, for example, when we have a new product, functionality, or service to present to you.

2.1.5. Remember that you can withdraw your marketing consents at any time.

2.1.6. The legal basis for processing personal data for the marketing purposes described in point 2.1.3 above is the legitimate interest of the Administrator (Article 6(1)(f) of the GDPR in connection with the given marketing consents), which consists of marketing and promoting its services, products, and activities.

2.2. “Free Consultation” form

2.2.1. We will process the personal data provided via the “Free Consultation” form to select an appropriate consultant for you depending on the challenge you present to us, to contact you to arrange a free consultation, and then to conduct it.

2.2.2. The legal basis for processing your data for the above purposes is our legitimate interest (Article 6(1)(f) of the GDPR) in conducting the free consultation you ordered, discussing your needs, and selecting appropriate solutions.

2.2.3. [Marketing consents] If, when ordering a Free Consultation, you voluntarily check the optional consents located under the form (for email marketing or telephone

USER RIGHTS
3.1. Based on the principles described in GDPR, you have the following rights regarding your data submitted through our Website:

3.1.1. The right to access the content of your data and request a copy of it (Article 15 of GDPR);

3.1.2. The right to request the correction of your personal data (Article 16 of GDPR);

3.1.3. The right to request data deletion (Article 17 of GDPR);

3.1.4. The right to request data processing restriction (Article 18 of GDPR);

3.1.5. The right to data portability i.e., to receive from the Administrator personal data in a structured, commonly used, machine-readable format, to the extent that the data is processed based on consent or for the conclusion and execution of a contract in an automated manner (Article 20 of GDPR);

3.1.6. The right to object to the processing of personal data based on a legitimate interest, including for marketing purposes (Article 21 of GDPR);

3.1.7. The right to withdraw consent – if the data is processed based on expressed consent, the User has the right to withdraw it at any time, which does not affect the legality of the processing carried out before its withdrawal;

3.1.8. The right to withdraw consent to email or phone marketing – if you gave consent to be contacted for marketing and trade purposes to the email or phone number you provided in the form, you have the right to withdraw such consent at any time.

3.1.9. You also have the right to lodge a complaint with the President of the Personal Data Protection Office if you believe that the processing of your personal data violates the provisions of the GDPR.

3.2. How to exercise your rights?

3.2.1. To exercise your rights, please send a request with your demand to the email address: office@astrafox.com, or to the email address iod@astrafox.pl.

3.2.2. If you do not receive a response from us within 14 days (sometimes emails do not get through, or they go to spam), please call: + 48 22 355 21 60 or +48 500 492 209.

3.2.3. When receiving marketing and commercial emails, you always have the option to unsubscribe (cancel the subscription) and thus withdraw your marketing consent by clicking on the link available at the bottom of the message.

DATA RECIPIENTS
4.1. For the proper functioning of our Company and Website, it is necessary for us to use the services of external entities. The Administrator uses only the services of those entities that provide sufficient guarantees of implementing appropriate technical and organizational measures so that the processing meets the requirements of the GDPR and protects the rights of the persons whose data relates to.

4.2. Users’ personal data may be transferred to the following recipients or categories of recipients: service providers supplying the Administrator with IT, technical, and organizational solutions enabling the Administrator to conduct the company’s activities, including the website and electronic services provided through it (in particular, computer software providers for running the Website, email and server hosting providers, and software providers for company management and providing technical support to the Administrator) and legal and advisory service providers providing the Administrator with appropriate support (law firm or debt collection company).

DATA RETENTION PERIOD
5.1. Personal data processed based on a legitimate interest (Article 6(1)(f) of GDPR) will be processed for the duration of this interest or until an effective objection to data processing is made.

5.2. Data processed for marketing contact purposes will be processed until an objection to processing for this purpose is made or until consent for contact for marketing purposes is withdrawn.

5.3. Data processed based on a contract (Article 6(1)(b) of GDPR) will be processed for its duration and then for the period of limitation of mutual claims.

INFORMATION ON THE REQUIREMENT/VOLUNTARINESS OF DATA PROVISION
6.1. Providing personal data is voluntary but may be necessary to achieve a specific processing purpose.

6.2. Required fields on the forms available on the Website have been marked with an asterisk. Entering other data into the forms is voluntary.

INFORMATION ABOUT THE LACK OF PROFILING AND NON-TRANSFER OF DATA OUTSIDE THE EEA
The personal data of Users will not be subjected to automated decision-making, including profiling, nor will they be transferred outside the European Economic Area.

Privacy Policy dated 14.11.2022.