Skip to main content
LET'S TALK ABOUT YOUR BUSINESSLET'S TALK

Privacy Policy

Privacy policy and information on how the personal data of website users is protected.

Article 1. Controller

  1. The controller of personal data is Good One sp. z o.o., with its registered office in Wrocław, ul. Januszowicka 5/121, 53-135 Wrocław, NIP: 525-287-21-79; KRS: 0000914751; REGON: 389646858 (hereinafter the “Controller”), who attaches great importance to protecting the privacy and confidentiality of the personal data of its Clients and other natural persons whose data the Controller processes (hereinafter “Users”).
  2. The Controller can be contacted in writing at the Controller's registered address, by email at kontakt@goodone.co, or by completing the contact form available on the Controller's website.
  3. The Controller has not appointed a Data Protection Officer.

Article 2. Principles of processing personal data

  1. The Controller processes personal data to the minimum extent necessary to achieve the processing purposes clearly defined in this Privacy Policy.
  2. The Controller carefully selects and applies appropriate technical and organizational measures to protect the personal data it processes. Full access to the databases is held only by persons duly authorized by the Controller.
  3. The Controller secures personal data against disclosure to unauthorized persons, as well as against processing in breach of applicable law. When processing personal data, the Controller applies solutions matched to the scale and nature of the processing, ensuring data subjects the highest degree of protection resulting from both the technological and organizational solutions used.
  4. The following personal data will be processed: first and last name, email address, phone number.

Article 3. Legal basis for processing personal data

  1. The personal data provided by the User is processed in accordance with this Privacy Policy and applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR”).
  2. Providing personal data is voluntary; however, failure to provide it will make it impossible to conclude and perform a contract, send an inquiry, or carry out the requested actions.
  3. The legal basis for processing personal data is:
    • Art. 6(1)(a) GDPR – for personal data obtained on the basis of consent, on the terms set out in Art. 7 GDPR;
    • Art. 6(1)(b) GDPR – for data provided voluntarily in order to respond to any inquiries or requests submitted, and to conduct further correspondence or contact before concluding a contract, as well as to prepare and perform a Contract between the User and the Controller or an entity the Controller commissions to perform the Contract;
    • Art. 6(1)(f) GDPR – for data processed in connection with the pursuit of the Controller's legitimate interests.

    Providing data is voluntary but necessary to perform the Contract or to conduct correspondence with the Controller.

  4. The Controller may process third-party data made available by Users for the purpose of, or in connection with, the Controller's provision of services. When providing the Controller with third-party data, the User each time declares that they hold the appropriate consent of those third parties to transfer their data to the Controller.
  5. In the event of a change to the personal data referred to in this Privacy Policy, the User will inform the Controller without undue delay so that the personal data can be updated.
  6. The Controller does not apply profiling to Users within the meaning of Art. 4(4) GDPR.

Article 4. Data retention period

The User's data will be stored no longer than necessary, i.e.:

  • for correspondence – personal data will be stored for the period necessary to handle the inquiry, i.e. the duration of the correspondence justified by the type of inquiry (but no longer than 6 months from the end of the correspondence);
  • for performance of a contract – until the contract is completed, and thereafter for the period required by law or for the pursuit of any claims the Controller may raise or that may be raised against the Controller;
  • for fulfilling a legal obligation incumbent on the Controller – until it is fulfilled;
  • for the pursuit of legitimate interests by the Controller or a third party – until they are realized or until the User objects to the processing of personal data, unless there are legitimate grounds for further processing;
  • for processing carried out solely on the basis of consent – until the data is promptly deleted following a request submitted by the User.

Article 5. User rights

  1. In connection with the Controller's processing of personal data, the User has the right to:
    • request access to personal data – Art. 15 GDPR;

      At the User's request regarding access to their data, the Controller informs the User whether it processes their data and informs the User of the processing details in accordance with the GDPR, and also grants the User access to the data concerning them. Access to the data will be provided by sending a copy of the data electronically. Should a further copy of the data be requested in paper form, the Controller has the right to charge the User the costs of preparing it in that form and sending it, in accordance with Art. 15(3) GDPR.

    • rectify personal data – Art. 16 GDPR;

      The Controller rectifies incorrect data at the User's request.

    • request erasure of personal data – Art. 17 GDPR;

      This right applies insofar as erasure of the data does not conflict with regulations binding on the Controller.

    • restrict processing – Art. 18 GDPR;

      This right applies insofar as the Controller may restrict the processing of personal data in the context of the regulations binding on it and insofar as it does not infringe the Controller's right to pursue its claims against the User.

    • data portability – Art. 20 GDPR;

      At the User's request, the Controller provides – in a structured, commonly used, machine-readable format – or transfers to another entity, where possible, the data concerning the User that they provided in order to conclude or perform a Contract, or that is processed on the basis of consent.

    • object to processing – Art. 21 GDPR;

      If the User raises an objection to the processing of their data justified by their particular situation, and the data is processed by the Controller on the basis of the Controller's legitimate interest, the Controller will uphold the objection unless it has compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the person raising the objection, or grounds for the establishment, exercise, or defense of claims.

    • withdraw consent to the processing of data, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal – Art. 7(3) GDPR;
    • lodge a complaint with a supervisory authority – Art. 77 GDPR.
  2. If the Controller is unable to establish the content of the request or identify the person exercising the above rights based on the submitted request, it will ask the applicant for additional information.
  3. A response to requests will be provided within one month of receipt at the latest. Should it be necessary to extend this deadline, the Controller will inform the applicant of the reasons for the extension.

Article 6. Sharing personal data

  1. Personal data will be shared only with authorized entities, i.e. authorized employees of the Controller and other persons acting under the Controller's authorization, as well as other entities authorized to receive the User's data on the basis of relevant legal provisions, and entities providing IT services to the Controller. Users' personal data may be transferred to other entities – in cases not indicated by the Controller or the law – only with the User's consent.
  2. The Controller undertakes not to transfer Users' personal data to third countries or international organizations.
  3. The Controller will oblige any entity to which it entrusts the User's personal data to implement appropriate safeguards for that data.

Article 7. Cookies

  1. The website www.sociallama.pl (the “Website”) uses IT data stored on the end devices of Website users, i.e. in particular text files containing, among other things, the name of the website they come from, their storage time on the end device, and a unique number (“Cookies”).
  2. Under the Electronic Communications Law Act of 12 July 2024, storing information on, or gaining access to information already stored on, a User's end device requires that User's prior consent. The only exception is Cookies strictly necessary to deliver the service the User has requested.
  3. The Controller groups the Cookies it uses into two categories:
    • Necessary – required for the Website to work and to remember the User's decision about Cookies. Used without consent, under the exception described above.
    • Analytics – used to compile aggregate visit statistics. Used only once the User has given consent, and only until that consent is withdrawn.

The full list of Cookies used, together with the parties the corresponding data is shared with, the purpose of each Cookie and how long it is stored:

Consent and its withdrawal

  1. On a first visit the User is shown a banner offering to accept or reject all Cookies other than the necessary ones. Rejecting is exactly as easy as accepting and sits in the same place. No analytics Cookie is written until a choice is made.
  2. Consent may be withdrawn or changed at any time, without giving a reason, using the “Cookie settings” control in the footer of every page. Withdrawal does not affect the lawfulness of processing carried out before it.
  3. The User's decision is stored in the sl_consent Cookie for 12 months — for a refusal as well as for consent. After that the question is asked again. It is also asked again whenever the list of parties named in the table above changes.

Statistics without Cookies

The Website uses Vercel Web Analytics (Vercel Inc.), which writes no Cookies and no other data to the User's device and reads nothing back from it. Visitors are distinguished solely by a hash computed server-side from the incoming request and discarded after 24 hours. Because the tool never reaches the end device, the consent requirement described in point 2 of this Article does not apply to it — it therefore runs regardless of the choice made in the banner. The legal basis is the Controller's legitimate interest (Art. 6(1)(f) GDPR) in measuring Website traffic.

Browser settings

Separately from the above, the User may manage Cookies in their browser settings — deleting and blocking them. This is supporting information only: browser settings do not constitute consent to the use of Cookies and do not replace the choice made in the banner. Example options for editing settings in popular browsers: