Privacy & cookie policy

I. General Provisions and Controller Information

1. This Privacy and Cookie Policy sets forth the rules for the processing of personal data of individuals using the website www.https://www.jarkop.com.pl/ (hereinafter: the “Website”) and of individuals with whom the Data Controller has established contact on its own initiative or in response to a contact request.
2. The controller of personal data is JARKOP, a limited liability company with its registered office in Zofiówka, at Zofiówka 1, 63-020 Zaniemyśl, entered in the Register of Entrepreneurs of the National Court Register, maintained by the District Court for Poznań – Nowe Miasto and Wilda in Poznań, 9th Commercial Division of the National Court Register, under KRS number 0000501171, Tax ID (NIP) 7861699927, Statistical Identification Number (REGON) 302669407, share capital of 1,503,000.00 PLN, email: biuro@jarkop.com.pl (hereinafter: “Controller”).
3. You can contact the Controller:
a) by mail: at the registered office address,
b) by email: at biuro@jarkop.com.pl,
c) by phone: at +48 577 004 657
4. Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: “GDPR”)

II. Categories of Individuals, Purposes, Legal Bases, and Data Retention Periods
To ensure full transparency, the Controller processes personal data as part of clearly defined processes:

1. Website Users
This applies to individuals who visit and browse the Website, including those who have interacted with the cookie management banner (e.g., accepted or rejected specific categories of cookies).
1. Purposes and legal bases for processing: Ensuring the proper functioning of the Website: processing of data necessary for the Website to function (essential cookies) – legal basis: the Controller’s legitimate interest (Article 6(1)(f) of the GDPR). Analyzing how users interact with the Website to optimize its performance—legal basis: the user’s voluntary consent expressed via the cookie banner (Article 6(1)(a) of the GDPR). Delivering personalized ads, measuring the effectiveness of advertising campaigns, and reaching people who have previously visited the Website – legal basis: the user’s voluntary consent expressed via the cookie banner (Article 6(1)(a) of the GDPR).
2. Retention period: For cookies and analytical/marketing data—until the user withdraws consent (by changing cookie settings on the website or in the browser) or until the relevant cookie expires (in accordance with the duration described in the section on cookies below).
3. Scope of data: IP address, unique cookie identifiers (cookie IDs), device identifier, subpages viewed, time spent on the website, referral source (e.g., from Google Search, from a Facebook ad), clicked elements, screen resolution, browser and operating system type, status of granted or withdrawn consents for individual cookies along with a timestamp.

Granting consent to analytical and marketing cookies (Google Analytics, Google Ads, Meta Pixel) is entirely voluntary. You may change your preferences or withdraw your consent at any time by clicking on the cookie banner or by changing the privacy settings in your web browser.

2. Individuals who contact the Controller (by phone, mail, through a form, or by email)
This applies to individuals who initiate contact to obtain information about the Controller’s offerings or activities, or with other general inquiries.
4. Purpose of processing: Handling inquiries, responding to correspondence, and maintaining ongoing communication.
5. Legal basis: The Controller’s legitimate interest (Article 6(1)(f) of the GDPR) in building relationships and responding to current questions or requests.
6. Retention period: For the time necessary to handle the inquiry and conclude the correspondence, and subsequently for up to 3 years for evidentiary purposes and to defend against potential allegations.
7. Scope of data: When using the contact form on the website, the Controller processes your first and last name / company name, email address, and the content of the message (including any other data voluntarily provided in the inquiry), as well as your IP address and the timestamp of the message’s transmission (collected automatically). In the case of telephone contact, the phone number and all other data voluntarily provided during the conversation are processed. In the case of email contact, the email address, first and last name, and all other data provided in the body of the email are processed. In the case of written correspondence, the first name, last name, or company name, physical address, and any other data provided in the body of the correspondence are processed.

3. Contractors who are natural persons
This applies to individuals with whom the Controller has entered into a contract.
1. Purposes and legal bases for processing:
a) Conclusion and performance of the contract (Article 6(1)(b) of the GDPR);
b) Compliance with legal obligations incumbent upon the Controller, including those related to issuing invoices, maintaining accounting records, and tax settlements (Article 6(1)(c) of the GDPR in conjunction with tax law provisions);
c) Establishing, pursuing, or defending claims arising from the concluded contract (Article 6(1)(f) of the GDPR)—the legitimate interest is the protection of the Controller’s rights and the pursuit of its claims.
2. Retention period: For the duration of the contract, and after its termination—for the period required by tax laws (5 years from the end of the tax year), but no longer than until the expiration of the statute of limitations for any claims in accordance with the provisions of the Civil Code.
3. Scope of data: The Controller processes first and last name, company name (the name under which business is conducted), Tax Identification Number (NIP), REGON number, address of the principal place of business or for service of process, email address, phone number, bank account number, transaction and settlement history, data contained in invoices and accounting documents, contract text, terms regarding the subject matter of the order, and contract performance history.

4. Representatives and Contact Persons of Business Partners
Applies to representatives of business partners cooperating with the Controller.
1. Purpose of processing: Efficient performance of the contract with the entity these individuals represent, verification of their authority, and ongoing communication regarding the cooperation.
2. Legal basis: The Controller’s legitimate interest (Article 6(1)(f) of the GDPR), which is to ensure efficient and proper cooperation with business partners.
3. Source of data: The data is obtained directly from the entity on whose behalf these individuals act (e.g., an employer, client, or principal) or from publicly available registers (e.g., KRS, CEIDG).
4. Retention period: For the duration of the contract with the relevant business partner, and after its termination, no longer than the statute of limitations period for any claims arising from that contract (in accordance with the time limits set forth in the Civil Code).
5. Scope of data: The controller processes only the basic data necessary for contact and verification of representation, i.e.:
a) identification data (first and last name, job title, position held, name of the represented entity);
b) contact information (work email address, work phone number);
c) data regarding authority (scope of authorization/power of attorney, data from an extract from the National Court Register (KRS) or Central Registration and Information on Business (CEIDG)).

5. Users of the Administrator’s social media profiles (Facebook, LinkedIn, Instagram)
1. Purpose of processing: Maintaining official profiles to promote the Administrator’s activities, provide information about its offerings and operations, and interact with users (comments, likes, private messages).
2. Legal basis: The Administrator’s legitimate interest (Article 6(1)(f) of the GDPR), consisting of maintaining the Administrator’s brand image and facilitating contact with interested parties.
3. Retention period: For as long as the user follows the profile (until the “like” or subscription is withdrawn) or until the user deletes their comments or messages.
4. Scope of data: username (first and last name or nickname), profile picture (avatar), and other information published by the user as public on their profile; the content of comments, likes, shares, reactions to posts; and the content of private messages sent to the Administrator.

6. Recipients of the Administrator’s newsletter
Applies to individuals who have voluntarily subscribed to the Administrator’s newsletter.

1. Purpose of processing: Sending commercial and marketing information, as well as updates regarding the Administrator’s offerings, services, and activities.
2. Legal basis: Voluntarily granted consent to receive commercial information at the provided email address (Article 6(1)(a) of the GDPR).
3. Retention period: Until consent is withdrawn (unsubscribing from the newsletter).
4. Scope of data: The Controller processes the email address necessary to send the newsletter, as well as activity data (e.g., information about opening messages or clicking on links contained in the newsletter—if the mailing system collects such statistics).

Providing data to receive the newsletter is voluntary but necessary to receive the newsletter. The data subject has the right to withdraw consent or unsubscribe at any time (e.g., by clicking the unsubscribe link located in the footer of each newsletter). Withdrawal of consent does not affect the lawfulness of processing carried out prior to such withdrawal.

III. Data Recipients
Your data may be disclosed only to trusted third parties to the extent necessary to achieve the purposes of processing:
1. IT service providers (hosting providers, email and cloud service providers, providers of analytics, marketing, and social media tools, providers of cookie consent management tools, and newsletter distribution service providers).
2. Entities providing legal and advisory services.
3. Postal operators and courier companies (for the purpose of sending letters or goods).
4. Judicial enforcement authorities, general courts, and public administration bodies.
Your data is not used for automated decision-making that would produce legal effects on you or similarly significantly affect you. The controller may use profiling for direct marketing purposes (e.g., via Google Ads or Meta Pixel). This profiling involves the automatic analysis of your activity on the website in order to display personalized ads and marketing messages tailored to your preferences. This profiling does not result in any negative legal or financial consequences for you.

IV. Transfer of Data Outside the EEA
Your data may be transferred outside the European Economic Area (EEA) in connection with the Controller’s use of global IT solutions and social media. Data transfers are based on the European Commission Decision of July 10, 2023, recognizing an adequate level of protection for personal data (EU-US Data Privacy Framework) for providers holding an active certificate of compliance with this program, and additionally on the Standard Contractual Clauses approved by the European Commission. You have the right to obtain a copy of these safeguards by contacting the Data Controller.

V. Information on the Voluntary or Mandatory Nature of Data Provision and the Consequences of Non-Disclosure
1. Website Users (Visitors to the Site): The provision of data collected automatically by essential cookies is necessary for the proper display and functioning of the website and to ensure its security. Providing data or consenting to the collection of data via analytics or marketing cookies is entirely voluntary. Withholding consent does not affect your ability to browse the website’s content; it merely prevents us from collecting anonymous statistics and displaying personalized ads to you.
2. Individuals contacting the Data Controller: Providing data (e.g., email address, phone number) is entirely voluntary but necessary for us to respond to your inquiry and communicate with you. Without this data, we will not be able to contact you.
3. Contractors who are natural persons: Providing data is voluntary, but it is a necessary condition for entering into and performing the contract. Furthermore, providing certain data (e.g., tax identification number, address, bank account number) is a statutory requirement under applicable law. Failure to provide this data will result in the inability to enter into the contract.
4. Representatives and contact persons of business partners: The provision of your contact and identification information by your principal/employer is a contractual requirement necessary for the proper performance of the contract and ongoing cooperation with the Data Controller. Failure to provide this information will prevent us from establishing direct business contact with you.
5. Social media users: Interacting with our profiles (liking, commenting) is entirely voluntary. Failure to provide data (e.g., by blocking your profile) will only result in your inability to view our content or interact with our posts.
6. Newsletter subscribers: Providing your email address (and, optionally, your first name) is entirely voluntary but necessary to receive our newsletter. If you do not provide this information or withdraw your consent, we will be unable to send you information about our news, offers, and promotions.

VI. Rights of Data Subjects
You have the following rights:
1. The right to access your data and receive a copy of it (Article 15 of the GDPR). You have the right to obtain confirmation from us as to whether we are processing your personal data. If so, you may request access to it and receive information regarding, among other things, the purposes of processing, the categories of data, the recipients, and the planned retention period. You also have the right to receive the first copy of your data free of charge.
2. Right to Rectification and Completion of Data (Article 16 of the GDPR). We ensure that the data we process is up-to-date and accurate. If you notice that your data is incorrect, incomplete, or has changed, you have the right to request that it be rectified or completed without delay.
3. Right to erasure (Article 17 of the GDPR). You may request the erasure of your personal data if: the data is no longer necessary for the purposes for which it was collected; you have withdrawn the consent on which the processing was based (and there is no other legal basis); you have objected to the processing on the grounds of a legitimate interest, or the data was processed unlawfully. This right is not absolute. The controller will not be able to delete your data if its processing is necessary to comply with legal obligations (e.g., tax or accounting obligations) or to establish, exercise, or defend legal claims.
4. The right to restrict processing (Article 18 of the GDPR). You have the right to request that we restrict the processing of your data (i.e., to store it only, while suspending other operations), for example, when: you contest the accuracy of the data—for the time it takes us to verify it; the processing is unlawful, but you object to its erasure, we no longer need the data but you need it to establish, exercise, or defend your legal claims, or you have objected to the processing—until it is determined whether our legitimate interests override your rights.
5. Right to Object (Article 21 of the GDPR). You have the right to object at any time to the processing of your data based on our legitimate interest (Article 6(1)(f) of the GDPR). Your objection must be based on your specific situation. In such a case, we will cease processing your data unless we demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or we demonstrate that the data is necessary for us to establish, exercise, or defend legal claims.
6. Right to data portability (Article 20 of the GDPR). You have this right only if the processing is carried out by automated means on the basis of a contract (Article 6(1)(b) of the GDPR) or your consent (Article 6(1)(a) of the GDPR). In such cases, you may request to receive your data in a structured, commonly used, machine-readable format (e.g., XML or CSV file) or to have it transmitted directly to another controller.
7. Right to Withdraw Consent. If we process your data based on your consent, you have the right to withdraw that consent at any time. However, withdrawing consent does not affect the lawfulness of processing carried out on the basis of that consent prior to its withdrawal.
8. To lodge a complaint with the supervisory authority—the President of the Personal Data Protection Office, based in Warsaw—if you believe that the Controller’s processing of your personal data violates the provisions of the GDPR.

VII. Third-Party Services
1. The Website contains links to our social media profiles (Facebook, LinkedIn) and to Google Maps. Clicking on a social media icon takes the user directly to the Administrator’s social media profile, at which point a connection is established with the servers of the respective social media platform.
2. Clicking on a given icon or link is your voluntary decision and causes you to leave the Website and be redirected to external sites.
3. The Administrator has no control over the scope, manner, purpose, or legality of the processing of personal data by the operators of these external websites (e.g., Meta Platforms, LinkedIn Corporation, Google LLC). Upon navigating to an external website, you become a user of that website, and the processing of your data is governed by the terms set forth by its owner.
4. The Controller is not responsible for the privacy policies, terms of service, or the use of cookies by these entities. We encourage you to review the privacy policies directly on these providers’ websites before using their services:
1. Meta: https://www.facebook.com/privacy/policy/
2. LinkedIn: https://www.linkedin.com/legal/privacy-policy
3. Google: https://policies.google.com/privacy

VIII. Cookies
Cookies are small text files sent to the user’s device (computer, tablet, smartphone) by the websites they visit. They do not cause any changes to the device’s configuration.

The Website may use the following types of cookies:
– Session cookies – these are deleted when you close your web browser;
– Persistent cookies – these remain on the user’s device and are deleted after their expiration date or when the user deletes them.
– Essential cookies, which are necessary for the proper functioning and security of the website. They are used based on the Administrator’s legitimate interest. The user is not required to consent to them.
– Analytical and marketing cookies: used to analyze website traffic and display targeted ads. They are installed only after the user voluntarily consents via the cookie banner.

You have the right to change your preferences or withdraw your consent to cookies at any time by clicking on the cookie settings on the banner or by changing the settings in your browser. Web browsers have cookie support enabled by default. You can change these settings to block cookies entirely or partially, or to have your web browser notify you when cookies are stored on your device.

Cookies typically contain the name of the domain they come from, their storage duration on the device, and an assigned value. Below is a table with a detailed description of the cookies used by our website:

On this website, we use:

1. Google Analytics (https://policies.google.com/privacy and https://policies.google.com/technologies/partner-sites), which is used to analyze website traffic and user behavior. This tool collects data on user behavior, such as the number of visits, time spent on the site, traffic sources, and interactions with content. This information helps us optimize the Website and tailor content to users’ needs. The tool collects information about the user’s device type, operating system, web browser, screen resolution, and approximate location.
2. Google Ads (https://policies.google.com/technologies/ads): used to run advertising campaigns, measure their effectiveness, and perform remarketing.
3. Meta Pixel / Facebook Pixel (https://www.facebook.com/privacy/policy): a tracking code used to measure the effectiveness of ads on Facebook and Instagram and to deliver personalized ads to people who have visited the website. We use the Meta Pixel to track conversions. It allows us to track users’ activities on the Website after they interact with ads on Facebook. This tool enables us to measure the effectiveness of advertising campaigns, analyze conversions, and conduct remarketing activities. The Pixel collects information such as IP address, browser and operating system type, resolution, browser language, and cookie identifiers.
4. Cookiebot for managing cookie consent requests. Cookiebot automatically scans the Website, classifies cookies, and allows users to consciously grant or withdraw consent for specific categories of cookies. To this end, Cookiebot processes an anonymous consent identifier (Cookiebot ID) and the consent status.
5. Google Tag Manager (https://policies.google.com/privacy): a tag management system on the Website. This tool is used exclusively for the technical management and implementation of other scripts and tools (such as Google Analytics, Google Ads, or Meta Pixel). Google Tag Manager merely facilitates the activation of the appropriate analytics and marketing tags based on the consents granted by the Website user.
6. Looker Studio and Google Search Console (https://policies.google.com/privacy) – for internal reporting, aggregate analytics, and optimizing the Website’s visibility in search results. These tools are used to visualize aggregated analytical and statistical data (including data collected from Google Analytics) and do not allow for the direct identification of individual Users.

In the newsletter messages sent, the Administrator may use so-called tracking pixels (invisible images) and unique links. These allow the Administrator to determine whether a message was opened, which links were clicked, and what device was used. This data is processed based on the Administrator’s legitimate interest in analyzing the effectiveness of mailings and improving the newsletter’s content. The User may block this tracking by disabling image loading in their email client or by unsubscribing from the newsletter.

IX. Changes to the Privacy Policy
The Administrator reserves the right to make changes to this privacy policy. The current version of the policy is published on the Website and is effective as of the date of its publication.

Policy dated August 5, 2026

 
Scroll to Top