░░ legal
TUHIKIMI.APP WEBSITE PRIVACY POLICY
§ 1. DEFINITIONS
- Controller – Arkadiusz Janik, a sole trader conducting business under the business name Smarter Arkadiusz Janik, ul. Żelazna 51/53, 00‑841 Warsaw, Poland, Tax Identification No. (NIP) PL7342950754, to the extent that he determines the purposes and means of the processing of personal data.
- Policy – this Website Privacy Policy.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
- Website – the Tuhikimi website available at https://tuhikimi.app.
- User – a person using the Website.
§ 2. CONTROLLER AND SCOPE OF THE POLICY
- The controller of personal data processed in connection with the Website is Arkadiusz Janik, a sole trader conducting business under the business name Smarter Arkadiusz Janik, address disclosed in the Polish Central Register and Information on Economic Activity (CEIDG): ul. Żelazna 51/53, 00‑841 Warsaw, Poland, Tax Identification No. (NIP) PL7342950754.
- For matters concerning personal data protection, the Controller may be contacted at info@tuhikimi.app or via the contact form available at https://tuhikimi.app/#contact.
- This Policy applies solely to the processing of data in connection with use of the Website. The rules governing processing in connection with use of the Tuhikimi mobile application are described in the separate App Privacy Policy.
§ 3. CATEGORIES OF DATA PROCESSED
3.1. Technical data and Website logs
When the Website is used, the Controller or entities providing infrastructure services on its behalf may process technical data relating to the connection and use of the Website, in particular the IP address, browser and device information, the date and time of the request, the requested resource, and data concerning connection security.
3.2. Contact form and correspondence
- If a User uses the contact form or contacts the Controller by email, the Controller may process the data provided in the message, in particular the User’s name, email address, message content, and technical information necessary to transmit and secure the form.
- The scope of the data depends on the content and nature of the matter. Providing data is voluntary; however, an email address and the content of the message are necessary in order to provide a reply.
3.3. Website usage statistics
The Website uses Plausible Analytics in a configuration that does not use cookies to track Users. The tool is used to generate aggregate statistics concerning use of the Website.
§ 4. PURPOSES AND LEGAL BASES OF PROCESSING
| Purpose of processing | Legal basis |
|---|---|
| Ensuring the operation, security and diagnostics of the Website | Article 6(1)(f) GDPR – the Controller’s legitimate interest in ensuring the security, availability and proper operation of the Website |
| Handling the contact form, correspondence and enquiries | Article 6(1)(b) GDPR – where the contact concerns entering into or performing a contract; otherwise Article 6(1)(f) GDPR – the legitimate interest in conducting communications and handling enquiries |
| Generating aggregate statistics concerning use of the Website | Article 6(1)(f) GDPR – the Controller’s legitimate interest in analysing the operation and development of the Website |
| Compliance with legal obligations | Article 6(1)(c) GDPR – compliance with a legal obligation to which the Controller is subject |
| Establishment, exercise or defence of legal claims | Article 6(1)(f) GDPR – the Controller’s legitimate interest in protecting its rights |
§ 5. DATA RECIPIENTS AND WEBSITE SERVICE PROVIDERS
- To the extent necessary for operation of the Website, data may be processed by service providers used by the Controller, in particular: OVH – Website hosting and related technical logs; Bunny.net / BunnyWay d.o.o. – CDN, DNS, security and traffic protection; Formspark / Trampoline Software SRL (Belgium) – handling and delivery of contact-form submissions; Plausible Analytics – aggregate Website usage statistics.
- Service providers may act as processors on behalf of the Controller or, where this follows from the nature of a particular service, as independent controllers. The applicable rules of processing may also arise from the terms and privacy policies of those entities.
- Data may also be disclosed to professional advisers, in particular law firms or accounting service providers, as well as to public authorities and other entities entitled to receive data under applicable law.
§ 6. TRANSFERS OF DATA OUTSIDE THE EEA
- Some service providers may process data outside the European Economic Area or use infrastructure with a global reach, in particular in connection with Google Workspace services. Contact-form submissions are processed by Formspark on infrastructure located within the European Economic Area (Ireland and Germany).
- Where the Controller is responsible for a transfer of data outside the EEA, the transfer is carried out in accordance with Chapter V GDPR, in particular on the basis of a European Commission adequacy decision (including, where applicable, the EU-U.S. Data Privacy Framework) or using appropriate safeguards such as Standard Contractual Clauses. Information on the mechanism applicable to a specific transfer may be obtained by contacting the Controller.
§ 7. DATA RETENTION PERIODS
| Data category | Retention period or criterion |
|---|---|
| Correspondence, contact forms and submissions | for the period necessary to handle the matter and thereafter for a period justified by the need to document the course of correspondence or protect against claims |
| Technical data and Website logs | for the period necessary to ensure the operation, security and diagnostics of the Website, determined taking into account the configuration of the infrastructure used; once no longer necessary, the data is deleted or anonymised unless further retention is required by law or necessary for the protection of claims |
| Data used for aggregate statistics | in accordance with the configuration and rules of the tool used; the Controller uses Plausible in a configuration that does not use cookies to track Users |
| Data processed to comply with legal obligations or protect claims | for the period resulting from applicable law or until expiry of the applicable limitation period for claims |
§ 8. COOKIES AND SIMILAR TECHNOLOGIES
- The Website may use cookies and other similar technologies involving the storage of information on the User’s device or access to information already stored on that device.
- The Website does not use cookies or similar technologies for marketing or advertising purposes or to track Users across different websites.
- The Website uses Plausible Analytics in a configuration that does not use cookies to track Users. The tool is used to generate aggregate statistics concerning how the Website is used.
- The Website may use cookies or similar technologies that are necessary for the proper operation of the Website, ensuring its security, preventing abuse and the proper operation of the contact form. This applies in particular to security mechanisms used to protect the form against spam and automated submissions.
- To the extent that storing information on the User’s device or accessing information already stored on it is necessary to provide a service requested by the User or to transmit a communication over a public telecommunications network, such technologies may be used without the User’s prior consent. In other cases, such technologies will be used only after the consent required by law has been obtained.
- The User may also manage cookies through the settings of their web browser. Restricting certain technologies necessary for operation of the Website may, however, affect the availability of some of its functions.
§ 9. RIGHTS OF DATA SUBJECTS
- Subject to the conditions set out in the GDPR, the data subject has the rights of access, rectification, erasure, restriction of processing, data portability and the right to object to processing based on Article 6(1)(f) GDPR.
- Where processing is based on consent, the data subject may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
- The data subject has the right to lodge a complaint with the competent supervisory authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (https://uodo.gov.pl).
§ 10. PROVISION OF DATA AND AUTOMATED DECISION-MAKING
- Providing data through the contact form or correspondence is voluntary; however, failure to provide data enabling a reply may make it impossible to handle the submission.
- The Controller does not use personal data collected through the Website to make decisions concerning the User based solely on automated processing that produce legal effects or similarly significantly affect the User.
§ 11. DATA SECURITY
The Controller applies appropriate technical and organisational measures to protect personal data processed in connection with the Website, taking into account the nature of the data, the scope of processing and the related risk.
§ 12. CHANGES TO THE POLICY AND CONTACT
- This Policy may be updated in particular in connection with changes to the Website, services used, applicable law or the manner in which personal data is processed. The current version of the Policy is published at a permanent, publicly accessible address designated by the Controller.
- If a change to the Policy involves a material change in the manner in which personal data is processed, the Controller will provide data subjects with appropriate information to the extent and in the form required by law.
- For matters concerning this Policy or the processing of personal data, the Controller may be contacted via the contact form at https://tuhikimi.app/#contact.