PRIVACY POLICY OF THE WEBSITE CATCHSHIFT.COM
GENERAL PROVISIONS
This privacy policy of the website available at the internet address www.catchshift.com (hereinafter referred to as: the “Website” or the “Site“) is informational in nature, which means that it is not a source of obligations for users of the Website. The privacy policy primarily contains rules concerning the processing of personal data by the Controller on the Website, including the legal bases, purposes, and periods of processing of personal data, as well as the rights of data subjects, and also information regarding the use of cookies and analytical tools on the Website.
The controller of personal data collected via the Website is the company CATCHSHIFT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ with its registered office in Wolsztyn, entered into the register of entrepreneurs of the National Court Register under number 0000715971, the registry court where the company’s documentation is kept: Sąd Rejonowy Poznań-Nowe Miasto i Wilda w Poznaniu, IX Wydział Gospodarczy Krajowego Rejestru Sądowego, registered office address and address for service: ul. Przemysłowa 2, 64-200 Wolsztyn, NIP (Tax ID) 9231720420, REGON (Statistical ID) 69338871, share capital amount: PLN 5,100, e-mail address: kontakt@catchshift.com, telephone number: +48 68 347 58 57 – hereinafter referred to as the “Controller” and being at the same time the Owner of the Website.
Quick contact with us:
- by e-mail: kontakt@catchshift.com
- chat available on the Site
- by phone: +48 68 347 58 57
- in person at the address: ul. Przemysłowa 2, 64-200 Wolsztyn or ul. Kameralna 17, 05-074 Wielgolas Duchnowski
Personal data on the Website are processed by the Controller in accordance with applicable law, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as “GDPR” or the “GDPR Regulation“. Official text of the GDPR Regulation: http://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX%3A32016R0679.
Use of the Website is voluntary. Likewise, the provision of personal data by a user of the Website in connection therewith is voluntary, except in cases where it is necessary in order to use certain functionalities of the Website, including, for example, the contact form. Failure to provide, in the cases and to the extent required, the personal data necessary to use a given functionality of the Site results in the inability to use that functionality. In each case, the scope of data required to use a functionality of the Site is indicated by the Controller on the Website (e.g. before completing the quotation request form).
The Controller exercises particular diligence to protect the interests of the data subjects whose personal data it processes, and in particular is responsible for, and ensures, that the data it collects are: (1) processed lawfully; (2) collected for specified, lawful purposes and not further processed in a manner incompatible with those purposes; (3) substantively correct and adequate in relation to the purposes for which they are processed; (4) kept in a form which permits identification of the data subjects for no longer than is necessary for the purposes for which the data are processed; and (5) processed in a manner ensuring appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.
Taking into account the nature, scope, context, and purposes of processing, as well as the risk of a breach of the rights or freedoms of natural persons of varying likelihood and severity, the Controller implements appropriate technical and organisational measures to ensure that processing is carried out in accordance with the GDPR Regulation and to be able to demonstrate this. These measures are reviewed and updated as necessary. The Controller applies technical measures to prevent unauthorised persons from acquiring or modifying personal data transmitted electronically.
All words, expressions, and acronyms appearing in this privacy policy and beginning with a capital letter should be understood in accordance with their meaning as set out in this document.
LEGAL DISCLAIMER
The Site is informational in nature; it allows visitors to become acquainted with the products and services of the Owner of the Site and to contact the Owner, among other things by submitting an inquiry via the contact form or the inquiry configurator. A newsletter may also be available on the Site, the subject of which will be to inform recipients about the activities of the Owner of the Site, news, and new products and services of the Owner of the Site. The Site, the products and services available on it, and the terms and conditions are addressed exclusively to entrepreneurs, i.e. the Site is not addressed to consumers. The law applicable to the Site and to these terms and conditions and to agreements concluded on their basis is Polish law.
The Site is not an online shop, and it is not possible to conclude a contract of sale for the products and services of the Owner of the Site by means of the Site (this means, among other things, that advertisements, price lists, and other information about products and services posted on the Site should not be treated as an offer, but at most as an invitation to conclude a contract). A contract of sale may be concluded as a result of an inquiry directed to the Owner of the Site, and only after the parties have agreed on the detailed terms of such a contract – the conclusion and terms of such a contract are, however, governed by a separate contract of sale or separate general terms and conditions of sale of products by the Owner of the Site, which will be made available by the Owner.
The Owner makes every effort to ensure that the data presented on the Site are current and correspond to the actual state of affairs. At the same time, the Owner reserves that all content available on the Site is of a purely informational nature.
LEGAL BASES FOR THE PROCESSING OF DATA
The Controller is entitled to process personal data in cases where – and to the extent that – at least one of the following conditions is met: (1) the data subject has given consent to the processing of their personal data for one or more specified purposes; (2) processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract; (3) processing is necessary for compliance with a legal obligation to which the Controller is subject; or (4) processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
The processing of personal data by the Controller requires, in each case, the existence of at least one of the legal bases indicated above. The specific legal bases for the processing of personal data of users of the Website by the Controller are indicated in the next section of the privacy policy – with respect to the given purpose of processing of personal data by the Controller.
PURPOSE, LEGAL BASIS, AND PERIOD OF DATA PROCESSING ON THE WEBSITE
In each case, the purpose, legal basis, scope, and recipients of the personal data processed by the Controller result from the actions taken by the given user on the Website.
The Controller may process personal data on the Website for the following purposes, on the following bases, for the following periods, and to the following extent:
| Purpose of data processing | Legal basis for data processing | Data retention period |
| Performance of a contract or taking steps at the request of the data subject prior to entering into a contract | Article 6(1)(b) of the GDPR Regulation (contract) – processing is necessary for the performance of a contract (e.g. a service agreement or a contract of sale) to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract (e.g. preparing an offer) | Data are stored for the period necessary for the performance, termination, or other expiry of the concluded agreement for the provision of electronic services with the Controller. |
| Direct marketing | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller) – processing is necessary for the purposes of the legitimate interests of the Controller – consisting in safeguarding the Controller’s interests and good image and pursuing the sale of services and products | Data are stored for the period during which the legitimate interest pursued by the Controller exists, but no longer than the limitation period for claims against the data subject arising from the business activity conducted by the Controller. The limitation period is determined by law, in particular by the Civil Code (the basic limitation period for claims connected with the conduct of business activity is three years). The Controller may not process data for direct marketing purposes if the data subject has effectively objected to such processing. |
| Marketing | Article 6(1)(a) of the GDPR Regulation (consent) – the data subject has given consent to the processing of their personal data for marketing purposes by the Controller | Data are stored until the data subject withdraws their consent to further processing of their data for this purpose. |
| Establishment, pursuit, or defence of claims which the Controller may raise or which may be raised against the Controller | Article 6(1)(f) of the GDPR Regulation (legitimate interest) – processing is necessary for the purposes of the legitimate interests of the Controller – consisting in the establishment, pursuit, or defence of claims which the Controller may raise or which may be raised against the Controller | Data are stored for the period during which the legitimate interest pursued by the Controller exists, but no longer than the limitation period for claims against the data subject arising from the business activity conducted by the Controller. The limitation period is determined by law, in particular by the Civil Code (the basic limitation period for claims connected with the conduct of business activity is three years). |
| Use of the Website and ensuring its proper functioning | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller) – processing is necessary for the purposes of the legitimate interests of the Controller – consisting in running and maintaining the Website | Data are stored for the period during which the legitimate interest pursued by the Controller exists, but no longer than the limitation period for claims of the Controller against the data subject arising from the business activity conducted by the Controller. The limitation period is determined by law, in particular by the Civil Code (the basic limitation period for claims connected with the conduct of business activity is three years). |
| Compiling statistics and analysing traffic on the Website | Article 6(1)(f) of the GDPR Regulation (legitimate interest of the controller) – processing is necessary for the purposes of the legitimate interests of the Controller – consisting in compiling statistics and analysing traffic on the Website in order to improve the functioning of the Website | Data are stored for the period during which the legitimate interest pursued by the Controller exists, but no longer than the limitation period for claims of the Controller against the data subject arising from the business activity conducted by the Controller. The limitation period is determined by law, in particular by the Civil Code (the basic limitation period for claims connected with the conduct of business activity is three years). |
RECIPIENTS OF DATA ON THE WEBSITE
For the proper functioning of the Website, it is necessary for the Controller to use the services of external entities (such as, for example, a software provider). The Controller uses only the services of such processors that provide sufficient guarantees of implementing appropriate technical and organisational measures so that processing meets the requirements of the GDPR Regulation and protects the rights of data subjects.
The transfer of data by the Controller does not occur in every case and not to all recipients or categories of recipients indicated in the privacy policy – the Controller transfers data only when it is necessary to achieve a given purpose of the processing of personal data, and only to the extent necessary to achieve it.
Personal data may be transferred by the Controller to a third country, whereby the Controller ensures that in such a case this will take place with regard to a country ensuring an adequate level of protection – in accordance with the GDPR Regulation, and in the case of other countries, that the transfer will take place on the basis of standard data protection clauses. The Controller ensures that the data subject has the possibility of obtaining a copy of their data. The Controller transfers the collected personal data only in the case of, and to the extent necessary for, achieving a given purpose of data processing consistent with this privacy policy.
The personal data of users of the Website may be transferred to the following recipients or categories of recipients:
- service providers supplying the Controller with technical, IT, and organisational solutions enabling the Controller to conduct its business activity, including the Website and the electronic services provided by means of it (in particular providers of computer software for running the Website, providers of e-mail and hosting services, and providers of software for company management and technical support for the Controller) – the Controller makes the collected personal data of a user of the Site available to a selected provider acting on its behalf only in the case of, and to the extent necessary for, achieving a given purpose of data processing consistent with this privacy policy.
- providers of legal and advisory services providing the Controller with accounting, legal, or advisory support (in particular a law firm) – the Controller makes the collected personal data of a user of the Site available to a selected provider acting on its behalf only in the case of, and to the extent necessary for, achieving a given purpose of data processing consistent with this privacy policy.
- providers of social plugins, scripts, and other similar tools placed on the Website enabling the browser of a person visiting the Website to download content from the providers of the aforementioned plugins (e.g. watching a video, liking, sharing) and, for this purpose, to transfer the personal data of the visitor to those providers, including in particular:
- Meta Platforms Ireland Ltd. – the Controller may use the social plugins of Facebook or Instagram and/or the advertising pixels of Facebook and Instagram, and in connection therewith collect and share device or user data from the Site with Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) to the extent and in accordance with the privacy policy available here: https://www.facebook.com/about/privacy/ and https://privacycenter.instagram.com/policy (this data includes information about activities on the Site – including information about the device, the websites visited, the advertisements displayed, and the manner of using the services – regardless of whether the person using the Site has a Facebook / Instagram account and whether they are logged in to their Facebook / Instagram account).
- Google Ireland Ltd. – the Controller may use Google plugins and/or Google advertising pixels on the Site, and in connection therewith collect and share device or user data from the Site with Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) to the extent and in accordance with the privacy policy available here: https://policies.google.com/privacy?hl=en (this data includes information about activities on the Site – including information about the device, the websites visited, the advertisements displayed, and the manner of using the services) – regardless of whether the person using the Site has a Google account and whether they are logged in to their Google account.
PROFILING ON THE SITE
The GDPR Regulation imposes on the Controller an obligation to inform about automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR Regulation, and – at least in those cases – meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. With this in mind, the Controller provides in this section of the privacy policy information regarding possible profiling.
The Controller may use profiling on the Site for direct marketing purposes, but the decisions made on this basis by the Controller do not concern the conclusion or refusal to conclude a contract, or the possibility of using electronic services. The effect of the use of profiling on the Site may be, for example, granting a given person a discount, sending them a discount code, sending them a product proposal that may correspond to that person’s interests or preferences, or proposing better terms compared to the standard offer. Despite profiling, it is the data subject who freely decides whether they wish to make use of a discount or better terms obtained in this way and to make a purchase.
Profiling on the Site consists of an automatic analysis or forecast of the behaviour of a given person on the Site, for example by browsing the page of a specific Product on the Site. A condition for such profiling is that the Controller possesses the personal data of the given person, in order to be able to subsequently send them, for example, a discount code.
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
RIGHTS OF THE DATA SUBJECT
Right of access, rectification, restriction, erasure, or portability – the data subject has the right to request from the Controller access to their personal data, its rectification, erasure (“the right to be forgotten”), or restriction of processing, and has the right to object to processing, as well as the right to data portability. The detailed conditions for exercising the above rights are set out in Articles 15–21 of the GDPR Regulation.
Right to withdraw consent at any time – a person whose data are processed by the Controller on the basis of given consent (on the basis of Article 6(1)(a) or Article 9(2)(a) of the GDPR Regulation) has the right to withdraw their consent at any time, without affecting the lawfulness of processing carried out on the basis of consent prior to its withdrawal.
Right to lodge a complaint with a supervisory authority – a person whose data are processed by the Controller has the right to lodge a complaint with a supervisory authority in the manner and procedure specified in the provisions of the GDPR Regulation and Polish law, in particular the Act on the Protection of Personal Data. The supervisory authority in Poland is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
Right to object – the data subject has the right, at any time, on grounds relating to their particular situation, to object
to the processing of their personal data based on Article 6(1)(e) (public interest or the exercise of official authority) or (f) (legitimate interest of the controller), including profiling on the basis of those provisions. In such a case, the Controller shall no longer be permitted to process such personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or grounds for the establishment, exercise, or defence of legal claims.
Right to object with respect to direct marketing – where personal data are processed for the purposes of direct marketing, the data subject has the right to object, at any time, to the processing of their personal data for the purposes of such marketing, including profiling, to the extent that the processing is related to such direct marketing.
In order to exercise the rights referred to in this section of the privacy policy, you may contact the Controller by sending an appropriate message in writing or by e-mail to the Controller’s address indicated at the beginning of the privacy policy.
COOKIES ON THE WEBSITE AND ANALYTICS, REMARKETING
Cookies are small pieces of text information in the form of text files, sent by a server and stored on the side of the person visiting the Website (e.g. on the hard drive of a computer, laptop, or on the memory card of a smartphone – depending on the device used by the visitor to our Website). Detailed information on cookies, as well as the history of their creation, can be found, among other places, here: https://en.wikipedia.org/wiki/HTTP_cookie.
The Controller provides on the Site a tool for the easy and active management of cookies – available on first entering the Site, and subsequently available in the footer of the Site. Active management allows, among other things, checking which cookies are or may be stored while using the Site, as well as selecting and subsequently changing the scope and purposes of the use of cookies with respect to the device and the person visiting the Site. When beginning to use the Site, the visitor will be asked to select settings regarding cookies. These settings may be changed later by changing the settings within this tool available on the site.
In the privacy policy, the Controller provides a range of information regarding the use of cookies on the Site, their types and purposes of use, and their management using, for example, web browser settings and the cookie management tool available on the Site. The Controller encourages the use of the cookie management tool available on the Site, which makes it easy to actively manage cookies while using the Site.
Cookies that may be sent by the Website can be divided into various types, according to the following criteria:
| By their provider: 1) own (created by the Controller’s Website) and 2) belonging to third parties (other than the Controller) | By the period for which they are stored on the device of the person visiting the Website: 1) session cookies (stored until the Website is left or the web browser is closed) and 2) persistent cookies (stored for a specified time, defined by the parameters of each file, or until manually deleted) | By the purpose of their use: 1) necessary (enabling the proper functioning of the Website), 2) functional/preference (enabling the Website to be adapted to the preferences of the person visiting the site), 3) analytical and performance (collecting information about how the Website is used), 4) marketing, advertising, and social (collecting information about the person visiting the Website in order to display advertisements to that person, personalise them, measure their effectiveness, and carry out other marketing activities, including also on websites other than this Site, such as social media platforms or other websites belonging to the same advertising networks as the Website) |
The Controller may process data contained in cookies while visitors use the Website for the following specific purposes:
| Purposes of the use of cookies on the Website of the Controller | remembering data entered into completed forms (necessary and/or functional/preference cookies) |
| adapting the content of the Website to the individual preferences of the user (e.g. regarding colours, font size, page layout) and optimising the use of the Website (functional/preference cookies) | |
| compiling anonymous statistics showing how the Website is used (analytical and performance cookies) | |
| displaying and rendering advertisements, limiting the number of times advertisements are displayed, and ignoring advertisements that the user does not wish to view, measuring the effectiveness of advertisements, and also personalising advertisements, i.e. examining the behavioural characteristics of visitors to the Website through anonymous analysis of their actions (e.g. repeated visits to specific pages, keywords, etc.) in order to create a profile of them and provide them with advertisements tailored to their anticipated interests, also when they visit other websites within the advertising network of Google Ireland Ltd. and Facebook, i.e. Meta Platforms Ireland Ltd. (marketing, advertising, and social cookies) |
Checking, in the most popular web browsers, which cookies (including the operating period of the cookies and their provider) are currently being sent by the Website is possible as follows:
| In the Chrome browser: (1) click the padlock icon on the left side of the address bar, (2) go to the “Cookies” tab. | In the Firefox browser: (1) click the shield icon on the left side of the address bar, (2) go to the “Allowed” or “Blocked” tab, (3) click the “Cross-site tracking cookies”, “Social media trackers”, or “Tracking content” field | In the Internet Explorer browser: (1) click the “Tools” menu, (2) go to the “Internet Options” tab, (3) go to the “General” tab, (4) go to the “Settings” tab, (5) click the “View files” field |
| In the Opera browser: (1) click the padlock icon on the left side of the address bar, (2) go to the “Cookies” tab. | In the Safari browser: (1) click the “Preferences” menu, (2) go to the “Privacy” tab, (3) click the “Manage Website Data” field | Regardless of the browser, using tools available, for example, at: https://www.cookiemetrix.com/ or: https://www.cookie-checker.com/ |
By default, most web browsers available on the market accept the storage of cookies by default. Everyone has the option of determining the conditions for the use of cookies through the settings of their own web browser. This means that it is possible, for example, to partially restrict (e.g. temporarily) or completely disable the storage of cookies – in the latter case, however, this may affect certain functionalities of the Website.
Web browser settings regarding cookies are relevant from the point of view of consent to the use
of cookies by our Website – in accordance with applicable law, such consent may also be expressed through web browser settings. Detailed information on changing cookie settings and deleting cookies yourself in the most popular web browsers is available in the help section of the given web browser and on the following pages (simply click the relevant link):
- in the Chrome browser
- in the Firefox browser
- in the Internet Explorer browser
- in the Opera browser
- in the Safari browser
- in the Microsoft Edge browser
The Controller may use Google Analytics and Universal Analytics services on the Website, provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). These services help the Controller compile statistics and analyse traffic on the Website. The data collected are processed within the above services to generate statistics helpful in administering the Website and analysing traffic on the Website. This data is aggregate in nature. By using the above services on the Website, the Controller collects data such as the source and medium by which visitors reach the Website and how they behave on the Website, information about the devices and browsers from which they visit the site, IP address and domain, geographic data, and demographic data (age, gender) and interests.
It is possible to easily block the sharing with Google Analytics of information about a given person’s activity on the Website – for this purpose, you can, for example, install a browser add-on provided by Google Ireland Ltd., available here: https://tools.google.com/dlpage/gaoptout?hl=en
In connection with the Controller’s potential use, on the Website, of services provided by Google Ireland Ltd., the Controller indicates that full information on the principles governing the processing of the data of persons visiting the Website (including information stored in cookies) by Google Ireland Ltd. is available in the Google services privacy policy available at the following internet address: https://policies.google.com/technologies/partner-sites
The Controller may use the Facebook Pixel and/or Instagram service on the Site, provided by Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland). This service helps the Controller measure the effectiveness of advertisements and analyse the actions taken by visitors to the Site, as well as display tailored advertisements to those persons. Remarketing lists are created on the basis of cookies collected by the Facebook Pixel within the Facebook or Instagram panel. Data collected or shared by the Facebook Pixel may include information about activities on the Site – including information about the device, the websites visited, purchases, advertisements displayed, visits to the Site, and the manner of using the services, as well as information regarding any interaction outside the Site with the Controller’s social media accounts, and interactions with the Controller’s advertisements displayed outside the Site. Detailed information on how the Facebook and Instagram Pixel works can be found at the following internet address: https://www.facebook.com/business/help/742478679120153?helpref=page_content and https://en-gb.facebook.com/business/tools/meta-pixel
Managing the operation of the Facebook Pixel (advertising preferences) is possible by changing the advertisement settings in your account on Facebook.com:
LINKS
The Site may contain links to other websites. The Controller encourages visitors, after navigating to other websites, to review the terms and conditions and privacy policy established there. This privacy policy applies only to this Site.
CONTACT US
In the event of any problems or questions related to the use of the Site, or any other questions, please contact the Owner of the Site:
- by e-mail: kontakt@catchshift.com
- chat available on the Site
- by phone: +48 68 347 58 57
- in writing to the address: ul. Przemysłowa 2, 64-200 Wolsztyn
- in person at the address: ul. Przemysłowa 2, 64-200 Wolsztyn or ul. Kameralna 17, 05-074 Wielgolas Duchnowski