Privacy Policy/Cookies
WPBM „MÓJ DOM” S.A., pursuant to the Act of 14 June 2024 on the protection of whistleblowers, informs about the possibility of reporting legal violations in writing, electronically, via the dedicated email address: sygnalista@mdprefabrykacja.pl.
A report of a legal violation cannot be made anonymously. Anonymous reports will not be considered by WPBM „MÓJ DOM” S.A.
PRIVACY POLICY
Under what legal provisions are or may your personal data be processed?
The rules on the protection of personal data (hereinafter PDP) have been set out, among others, in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016[1] on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter GDPR), the Personal Data Protection Act of 10 May 2018 (hereinafter PDPA[2]) and in special laws (lex specialis) also under national law.
Key definitions
„Personal data” – means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person,
„Processing” – means an operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction,
„Controller” – or Data Controller – means a natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law,
„Joint controller” – pursuant to Art. 26 GDPR means two or more Data Controllers who jointly determine the purposes and means of processing personal data,
„Supervisory authority” means an independent public authority established by a Member State. The supervisory authority is the President of the Personal Data Protection Office (Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, contact: https://uodo.gov.pl/pl/p/kontakt),
„Recipient” – means a natural or legal person, public authority, agency, or other body to which the personal data are disclosed, whether a third party or not,
„Processor” – means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller,
„Third party” – means a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data,
„Third country” – an entity outside the EEA (European Economic Area) to which personal data are disclosed,
„Consent” – of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them,
„Privacy Policy” – this document, presenting information on the rules of personal data processing in accordance with the scope specified in Art. 13 GDPR – the information clause on personal data processing,
„Cookie Policy” – information on the use of cookies on the website operated by the Data Controller. The Cookie Policy is available on the Data Controller's website as a separate document,
„GDPR” – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation): https://uodo.gov.pl/pl/404
Who does this Privacy Policy apply to?
This Privacy Policy (hereinafter PP) concerns the processing of personal data of natural persons, natural persons running a sole proprietorship, and persons acting on behalf of legal entities, i.e. persons designated to represent a legal entity, proxies, employees, and/or associates acting on behalf of a legal entity.
Who is the Controller of personal data?
Pursuant to Art. 13 GDPR, i.e. the right to be informed, we inform you that the Data Controller is Wrocławskie Przedsiębiorstwo Budownictwa Mieszkaniowego „MÓJ DOM” S.A., ul. Jedności Narodowej 41/2, 50-260 Wrocław, KRS No. 0000071986.
Contact details for the Data Controller
Please direct inquiries regarding personal data protection directly to the Data Controller's address (by regular mail) or to the dedicated email address: odo@mdprefabrykacja.pl.
Data Protection Officer
We inform you that the Data Controller has not appointed a Data Protection Officer.
For what purposes are or may your personal data be processed?
Personal data are or may be processed for the following purposes:
2) Art. 6(1)(f) GDPR – legitimate interest pursued by the data controller
2) Art. 6(1)(f) GDPR – legitimate interest pursued by the data controller
2) Art. 6(1)(c) GDPR – processing is necessary for compliance with a legal obligation to which the controller is subject,
3) Art. 6(1)(f) GDPR – legitimate interest pursued by the data controller
Disclosure of personal data by the Data Controller
We inform you that personal data are or may be disclosed by the Data Controller: to recipients providing services to the Data Controller under Art. 28 GDPR – entrustment of personal data processing. Categories of recipients may include: IT infrastructure providers (software and hardware level), website hosting providers, and other entities to which the Data Controller has entrusted the processing of personal data. A list of entities to which the Data Controller has entrusted the processing of personal data is available upon request of the data subject; to recipients cooperating with the Data Controller. Categories of recipients to whom personal data may be disclosed include entities operating in the field of audits and law firms. We inform you that, once disclosed, the recipient of the data becomes the controller of the disclosed personal data. A list of entities to which the Data Controller has disclosed personal data is available upon request of the data subject; to recipients that are public/state authorities. Categories of such recipients may include authorities such as the Tax Office, Police, courts, the Personal Data Protection Office, or other entities to which the Data Controller discloses personal data under applicable law. We inform you that, once disclosed, the recipient of the data becomes the controller of the disclosed personal data. A list of entities to which the Data Controller has disclosed personal data is available upon request of the data subject.
Transfer of personal data to a third country (i.e. outside the EEA)
We inform you that personal data may be transferred to a third country, i.e. outside the EEA. Where personal data is transferred outside the European Economic Area, such transfer may only take place on the terms set out in Chapter V of the GDPR: pursuant to Art. 45 GDPR – transfer based on an adequacy decision, pursuant to Art. 46 GDPR – transfer subject to appropriate safeguards, including through the use of standard data protection clauses adopted by the European Commission. We inform you that transferring personal data outside the EEA may involve a risk of insufficient data protection. Where such a risk arises in connection with the transfer of personal data outside the EEA, the Data Controller provides this information in this Privacy Policy. We inform you that a list of entities outside the EEA to which the Data Controller discloses personal data is available upon request of the data subject. List of entities that may transfer personal data outside the EEA and that may not ensure a level of personal data protection sufficient under the GDPR:
For how long, in accordance with the storage-limitation principle, will personal data be processed?
We inform you that personal data are or may be processed for the following period:
2) Art. 6(1)(f) GDPR – legitimate interest pursued by the data controller
What rights does the data subject have?
We inform you of the right to request that the Data Controller exercise the following rights: the right of access to personal data concerning the data subject, the right to rectification of personal data, the right to erasure of personal data, the right to restriction of processing of personal data, the right to object to processing, the right to data portability, the right to receive a copy of one's personal data. We inform you that, due to the specific processing purposes listed in this Privacy Policy, the exercise of data subjects' rights may be wholly or partly limited, e.g. due to applicable legal provisions that require the Data Controller to process the data.
Who is the supervisory authority?
1. We inform you of the right to lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office (UODO), with its seat at ul. Stawki 2 in Warsaw, https://uodo.gov.pl/pl, https://uodo.gov.pl/pl/83/155,
2. In the case of joint controllership with Facebook Ireland Limited, we inform you that the supervisory authority is the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland (as amended): https://www.dataprotection.ie/.
In what circumstances is the provision of personal data a statutory or contractual requirement, or a condition for concluding a contract?
We inform you that the provision of personal data is:
Information on automated decision-making, including profiling
We inform you that by visiting the Data Controller's website, you are not subject to automated decision-making, including profiling. Information on the cookies used by the Data Controller is available in the Cookie Policy, published on the website as a separate document. We inform you that where the Data Controller operates a fanpage via platforms such as Facebook, Google, or YouTube, profiling may occur; information on such profiling by these entities is available in the privacy policies published on their respective websites:
Facebook: https://www.facebook.com/legal/terms
YouTube: https://www.youtube.com/t/terms
Google: https://policies.google.com/terms?hl=en&gl=beGoogle
Maps: https://www.google.com/intl/en_be/help/terms_maps/
What is the source of the data?
- Personal data may:
- come directly from the data subject,
not directly from the data subject: from entities cooperating with the data controller (real estate intermediaries, sales platforms, other sources),
- in the case of legal entities, the source of personal data may be the publicly available KRS and CEIDG registers, or the legal entity that provides the personal data of persons designated on its behalf to represent it or to perform the terms agreed between the parties.
What scope of personal data is processed?
The Data Controller processes ordinary personal data, to the extent necessary to achieve the purposes specified in the Privacy Policy, including first and last name, phone number and/or email address, registration data of the legal entity or sole proprietorship, correspondence details, bank account number, and other personal data. In accordance with the data-minimization principle, we process only the scope of personal data necessary to achieve the processing purpose or as required by currently applicable law.
How do we protect personal data?
We inform you that, in order to protect privacy and personal data, the Data Controller has implemented appropriate technical and organizational measures to ensure the security of personal data processing.
Processing of personal data using social media
We inform you that the Data Controller operates a Fanpage via social media platforms such as Facebook, YouTube, and Google. We inform you that where the Data Controller determines the purposes and means of processing, it becomes the Data Controller of that data and entrusts the processing of personal data to the social media platform. Where personal data is processed by social media platforms for purposes not determined by the Data Controller, the Data Controller is not responsible for such further processing, including tools such as cookies, profiling tools, statistics tools, and other purposes used by them, and is therefore not liable for the consequences of any breach of personal data processing security by the social media platforms. We inform you that, in connection with the Data Controller's Facebook Fanpage, personal data is transferred outside the EEA (to a third country) to entities that may not guarantee a sufficient level of personal data protection, privacy protection, or the exercise of the rights and/or freedoms of data subjects. Negative consequences of transferring personal data outside the EEA may include material or non-material damage, loss of control over one's data, and the inability to exercise rights or freedoms available under the GDPR. We inform you that the use of the FB Fanpage by natural persons is entirely voluntary and depends solely on the decision of the data subject. We further inform you that, based on Recital 75 of the GDPR, negative consequences for the protection of personal data and privacy of users of the Data Controller's Fanpage may include, among others: material or non-material damage, discrimination, identity theft, identity fraud, financial loss, damage to reputation, breach of confidentiality of personal data protected by professional secrecy, unauthorized reversal of pseudonymization, or any other significant economic or social harm, deprivation of rights and freedoms or of the ability to exercise control over one's personal data, and other material and non-material effects on the natural person. We remind you that every FB user may, under the rights currently available under applicable privacy and personal data protection law, independently request comprehensive information from the social media platform regarding the above-mentioned breach and pursue claims (Art. 80 and 82 GDPR). We inform you that Fanpage users may file a complaint directly with the UODO via the form available at: https://uodo.gov.pl/pl/.
Joint controllers and joint controllership of personal data
We inform you that, in connection with the Data Controller's operation of a Facebook Fanpage, a joint-controllership arrangement exists between the Data Controller and Facebook Ireland Limited, with its registered office at 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (a Data Controller). Pursuant to Art. 26 GDPR, we inform you that the above-mentioned joint controllers have made joint arrangements regarding their respective GDPR obligations. Information on the joint arrangements between the Joint Controllers is available at: https://www.facebook.com/legal/controller_addendum – effective date: 31 August 2020. We inform you that, due to the joint-controllership arrangement with Facebook Ireland Limited, FB may transfer personal data outside the EEA (to a third country), which may not provide sufficient protection of personal data, exercise of rights and/or freedoms of data subjects, or privacy protection. We inform you of the right to direct inquiries regarding the joint-controllership process to each joint controller individually. We inform you that the supervisory authority for Facebook Ireland Limited is the Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland (as amended): https://www.dataprotection.ie/.
Processing of personal data based on the consent of the data subject
We inform you that where personal data is processed based on the consent given by the data subject (Art. 6(1)(a) GDPR):
Processing of personal data based on the legitimate interest pursued by the Data Controller. We inform you that where personal data is processed based on the legitimate interest pursued by the Data Controller (Art. 6(1)(f) GDPR):
Information on the processing of personal data in connection with participation in the recruitment process
Pursuant to Art. 13 GDPR, we inform you that the Data Controller with respect to job applicants is Wrocławskie Przedsiębiorstwo Budownictwa Mieszkaniowego „MÓJ DOM” S.A., 50-260 Wrocław, ul. Jedności Narodowej 41/2, KRS No. 0000071986. Contact details for the Data Controller: odo@mdprefabrykacja.pl or by regular mail to the above address.
We inform you that no Data Protection Officer has been appointed.
We inform you that personal data are or may be processed for the following purposes:
a) to carry out the current recruitment process in connection with a job posting. The legal basis for processing personal data is the Act of 26 June 1974, the Labor Code, Art. 22¹ (Art. 6(1)(c) GDPR). We inform you that providing personal data is a statutory requirement arising from Art. 22¹ of the Labor Code,
b) in connection with the processing of personal data for planned (future) recruitment processes conducted by the Data Controller. If you consent to participate in future recruitment processes planned by the Data Controller, please include the following clause in your CV: “I consent to the processing of my personal data contained in the submitted documents for the purpose of participating in future recruitment processes conducted by the Data Controller.” The legal basis for processing personal data is the consent of the data subject to the processing of their personal data in recruitment processes planned by the Data Controller (Art. 6(1)(a) GDPR). We inform you that giving consent is voluntary, and the consent given may be withdrawn at any time without affecting other provisions arising from the recruitment process. If consent is withdrawn, the personal data will not be taken into account in future (planned) recruitment processes conducted by the Data Controller.
We inform you that the scope of personal data processed in the recruitment process results from Art. 22¹ § 1 of the Labor Code. Pursuant to Art. 22¹ § 1, the employer requires the job applicant to provide personal data including: first name(s) and last name, date of birth, contact details indicated by that person, education, professional qualifications, and employment history. The employer requires the provision of personal data including: first name(s) and last name, date of birth, contact details indicated by that person, education – where this is necessary for performing work of a specific type or in a specific position. In addition, the job applicant may, on their own initiative, provide the employer with a broader scope of data than that resulting from Art. 22¹ § 1 of the Labor Code, including:
a) special categories of data referred to in Art. 9 GDPR (special categories of personal data/particularly sensitive data are considered to be: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, sex life, or sexual orientation),
b) data in the form of a link or links to information about themselves provided by the job applicant (including links to social media or dedicated websites), whereby the provision of personal data to a greater extent is considered a voluntary expression of consent by the job applicant to its processing.
We inform you that where a job applicant, on their own initiative, provides personal data to a greater extent than specified in Art. 22¹ of the Labor Code, consent to its processing may be withdrawn at any time without negatively affecting the current or future recruitment process.
We inform you that personal data are or may be disclosed to recipients of personal data, state authorities solely pursuant to applicable law, or to third parties under Art. 28 GDPR – entrustment of personal data processing. Categories of recipients to whom personal data are disclosed include: external providers of recruitment services in the form of dedicated recruitment applications, external companies conducting the recruitment process on behalf of the Data Controller, and other entities providing services supporting the Data Controller's recruitment process. Upon request, the Data Controller will provide a list of all entities to which personal data are disclosed in the recruitment process.
We inform you that, in the recruitment process conducted, personal data are not transferred to a third country (i.e. outside the European Economic Area).
We inform you that personal data are or may be processed:
a) for the purpose of conducting the current recruitment – for a period of 6 months from the date of completion of the recruitment process,
b) for the purpose of processing personal data in connection with future recruitment processes planned by the Data Controller – for no longer than 24 months from the date of completion of the recruitment, or until consent to the processing of personal data in future (planned) recruitment processes is withdrawn. The Data Controller informs that the above processing period may change (be extended) depending on circumstances that may require such a change. In the event of a change to the above processing period, the Data Controller will inform persons participating in the recruitment process of such a change.
We inform you of the right to request from the Data Controller access to the personal data concerning the data subject, their rectification, erasure, or restriction of processing, or the right to object to processing, as well as the right to data portability.
We inform you of the right to lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office in Warsaw. Contact details for the supervisory authority: Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, or via the contact details available on the authority's website: https://uodo.gov.pl/pl/p/kontakt.
We inform you that personal data processed in connection with the current or future recruitment are not subject to profiling, automated profiling, or automated decision-making, including profiling.
We inform you that the Data Controller does not plan any other purpose of processing personal data than those indicated above. Should other purposes arise, the Data Controller will inform you of them in a separate communication.
We inform you that, in order to protect privacy and personal data, the Data Controller has implemented appropriate technical and organizational measures to ensure the security of personal data processing.
We inform you that the recruitment process may be based on personal data obtained directly from the data subject or from other sources, i.e. not directly from the data subject. Where personal data is obtained from sources other than directly from the job applicant, the Data Controller, pursuant to Art. 14(3) GDPR, informs the data subject about the processing of their personal data within a reasonable period after obtaining the data – at the latest within one month, and if the personal data is to be used for communication with the data subject – at the latest at the time of first such communication with the data subject.
Notifications of personal data breaches
We inform you that, pursuant to Art. 34 GDPR, in the event of a personal data breach likely to result in a high risk to the rights or freedoms of natural persons, the Data Controller shall notify the data subject of such a breach without undue delay. We inform you that, pursuant to Art. 34 GDPR, personal data may be processed in connection with the occurrence of the breach referred to above. We inform you that the legal basis for processing personal data is Art. 6(1)(c) GDPR. We inform you that, in the event of a personal data breach, the Data Controller will take all possible and available technical and organizational measures to comply with the requirements set out in Art. 33 and Art. 34 GDPR.
[1] GDPR: https://uodo.gov.pl/pl/404/224
[2] UODO: https://uodo.gov.pl/pl/395/1192
