Legal
GDPR information
Information required when we collect personal data through gotopl.com.
Controller
The controller is PLAN GROUP sp. z o.o., Al. Grunwaldzka 413, 80-309 Gdańsk, Poland, KRS 0000971382, NIP 5842817738, REGON 522004318. Privacy contact: hello@plangroup.pl.
Purposes and legal bases
We process data submitted in an enquiry to respond, assess potential cooperation and, where relevant, take steps before entering into a contract (Article 6(1)(b) GDPR). We may also process business correspondence on the basis of our legitimate interests in relationship management, communication continuity, website security and the establishment, exercise or defence of legal claims (Article 6(1)(f) GDPR). Optional analytics or marketing processing is carried out only where the relevant technology is configured and a valid consent is required and given.
Providing data
Providing data in the contact form is voluntary, but the fields marked as required are necessary for us to respond effectively to your enquiry.
Recipients
Data may be processed by providers supporting hosting, email, IT administration and security, only to the extent necessary to provide those services. Optional analytics or advertising providers receive data only where the relevant service is configured and lawfully activated.
Retention
We keep enquiry data for the period necessary to handle the enquiry and potential business relationship. Where no cooperation follows, correspondence may generally be retained for up to 24 months for communication continuity, unless a shorter period is appropriate. Data required for contracts, accounting, legal obligations or claims may be kept for the periods required by law or until claims expire.
Your rights
You may have the right to access, rectify or erase your data, restrict processing, receive portable data and object to processing based on legitimate interests. Where processing is based on consent, you can withdraw consent at any time. You also have the right to lodge a complaint with the competent supervisory authority, including the President of the Personal Data Protection Office in Poland.
Transfers outside the EEA
Where a service provider processes data outside the EEA, we use an applicable lawful transfer mechanism, such as an adequacy decision, a recognised data privacy framework or Standard Contractual Clauses, depending on the provider and production configuration.
Automated decision-making
We do not make decisions producing legal effects or similarly significant effects solely by automated means on the basis of data collected through the website.
For the full rules, including cookies and optional technologies, see the Privacy policy and Cookie policy.
