
Privacy Policy
Privacy Policy – tiedot.info
1. Controller and contact details
The controller of personal data described in this Privacy Policy is:
Tiedot sp. z o.o. with its registered office in Warsaw, ul. Grzybowska 87, 00-844 Warszawa, entered in the register of entrepreneurs of the National Court Register under KRS number 0001200096, kept by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Division of the National Court Register, NIP 5273187224, share capital 5 000 zł Email: polska@tiedot.info
("Tiedot", "we"). Questions and requests concerning personal data can be sent to polska@tiedot.info.
Tiedot sp. z o.o. belongs to the Tiedot Yhtiöt Oy group (Finland). The other language versions of the Website are operated by Tiedot Yhtiöt Oy, which acts as the controller for its own processing under a separate privacy policy.
2. Scope
2.1 This Privacy Policy explains how we process personal data when you visit the Polish-language version of the website tiedot.info (the "Website"), contact us, or sign in to our services as a user.
2.2 The processing of personal data within Tiedot's services after signing in (the "Services") is also governed by the agreement between Tiedot (or another company in the Tiedot group) and the customer (the "Customer Agreement") and, where applicable, a data processing agreement. Where Tiedot processes personal data on behalf of a customer, the customer is the controller of that data, and this Privacy Policy does not apply to that processing.
2.3 The use of cookies and similar technologies is described in our separate Cookie Policy.
3. What personal data we process
Depending on how you interact with us, we may process the following categories of personal data:
- Contact details: name, email address, phone number, company and job title.
- Account and user data: username, credentials (stored in protected form), user role, the customer organisation you represent, and account settings.
- Communications: messages, enquiries, feedback and complaints you send us, and related correspondence.
- Usage and technical data: IP address, browser and device information, log data such as time of access and pages visited, sign-in events and security logs.
- Customer relationship data: information relating to the Customer Agreement, orders, invoicing and customer service, to the extent it concerns individual contact persons.
We do not ask you to provide special categories of personal data through the Website.
4. Purposes and legal bases of processing
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing and securing the Website and the sign-in area | Legitimate interest (Art. 6(1)(f)) |
| Creating and managing user accounts and providing access to the Services | Performance of a contract (Art. 6(1)(b)) where you are the contracting party; otherwise our and our customer's legitimate interest (Art. 6(1)(f)) |
| Responding to enquiries and customer service | Legitimate interest (Art. 6(1)(f)) or steps prior to entering into a contract (Art. 6(1)(b)) |
| Managing customer relationships, invoicing and accounting | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| B2B marketing and communications to business contacts | Legitimate interest (Art. 6(1)(f)); consent (Art. 6(1)(a)) where required by law |
| Developing the Website and Services and producing statistics | Legitimate interest (Art. 6(1)(f)) |
| Preventing misuse, ensuring information security and establishing, exercising or defending legal claims | Legitimate interest (Art. 6(1)(f)) |
| Complying with statutory obligations | Legal obligation (Art. 6(1)(c)) |
Where processing is based on legitimate interest, we have assessed that our interest is not overridden by your interests or rights. Where processing is based on consent, you may withdraw your consent at any time.
5. Sources of data
We collect personal data primarily directly from you. User data may also be provided to us by the customer organisation you represent (for example when an administrator creates an account for you). Technical data is generated automatically when you use the Website or the Services.
6. Recipients of data
6.1 We do not sell personal data. We may share personal data with:
- Service providers acting on our behalf, such as providers of hosting, cloud, email, customer relationship management, analytics, payment, accounting and IT support services. They process personal data only under our instructions and subject to appropriate data processing agreements.
- Tiedot group companies, including Tiedot Yhtiöt Oy (Finland), for administration, customer service and provision of the Services.
- Authorities and other parties, where required by law, or where necessary to establish, exercise or defend legal claims.
- Parties to a transaction, such as a potential buyer or investor, in connection with a merger, acquisition or reorganisation, subject to confidentiality obligations.
7. Transfers of data outside the EEA
We primarily process personal data within the European Union / European Economic Area. If personal data is transferred outside the EEA, we ensure an adequate level of protection, for example on the basis of a European Commission adequacy decision (including the EU–U.S. Data Privacy Framework) or standard contractual clauses adopted by the European Commission, together with supplementary measures where necessary.
8. Data retention period
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, for example:
- user account data for as long as the account is active under the Customer Agreement, and thereafter until the limitation period for any claims expires;
- enquiries and related correspondence for up to two (2) years after the last contact, unless a customer relationship is established;
- accounting and invoicing records for the periods required by accounting and tax legislation;
- security and log data for a limited period, typically no longer than twelve (12) months, unless needed to investigate an incident.
When the retention period expires, personal data is deleted or anonymised.
9. Your rights
Subject to the conditions of data protection law, you have the right to:
- access your personal data;
- have inaccurate data rectified;
- have your data erased;
- restrict processing;
- object to processing based on legitimate interest, and at any time to direct marketing;
- data portability, where processing is based on consent or contract and carried out by automated means;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
Requests can be sent to polska@tiedot.info. We may ask you to confirm your identity before responding. If your data has been provided by a customer organisation that is its controller, we may refer your request to that organisation.
10. Right to lodge a complaint
If you consider that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or place of the alleged infringement. In Poland, the supervisory authority is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, www.uodo.gov.pl.
11. Automated decision-making
We do not use personal data for decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
12. Security
We protect personal data with appropriate technical and organisational measures, such as access control, encryption of data in transit, secure credential storage, logging and restricting access to personnel who need the data for their work.
13. Changes to the Privacy Policy
We may update this Privacy Policy from time to time. The current version is always available on the Website with its effective date. We will inform users of material changes by appropriate means.