Privacy Policy Firmao Mobile Application
Privacy Policy of the CRM Firmao Mobile Application
This Privacy Policy sets out the rules adopted by:
Firmao Polska Sp. z o.o., with its registered office in Łódź (90-368), at Al. Marsz. Józefa Piłsudskiego 3, entered in the National Court Register under KRS number 0000440920, holding the following identification numbers: NIP 7252063825 and REGON 101503556, for the processing of personal data collected from users of the mobile application, hereinafter referred to as the “Application.”
The Privacy Policy document reflects the company’s concern for the rights of persons visiting the Application available within the company’s domains and using the services offered through it.
This Privacy Policy is Appendix No. 3 and constitutes an integral part of the main Terms and Conditions.
This document fulfills the information obligation arising from Article 13 of the GDPR. It also reflects the care taken to ensure the security of personal data of Users using the services offered by the Application.
It also fulfills the information obligation arising from:
Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC – General Data Protection Regulation, OJ EU L119 of 4 May 2016, p. 1 – hereinafter referred to as the GDPR.
1. Personal Data
- Personal data – in accordance with Article 4(1) of the GDPR – means any information relating to an identified or identifiable natural person, the “data subject.” An identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as name and surname, an identification number, location data, an online identifier, or one or more specific factors determining the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
2. Personal Data Controller
- The Controller of the personal data of Application Users is:
Firmao Polska Sp. z o.o., with its registered office in Łódź (90-368), at Al. Marsz. Józefa Piłsudskiego 3, entered in the National Court Register under KRS number 0000440920, NIP 7252063825, REGON 101503556.Correspondence address: Łódź (90-368), Al. Marsz. Józefa Piłsudskiego 3
Tel.: UK (+44) 2034685372
Email: contact@firmao.io
3. Legal Basis, Purpose, and Scope of Processing
- The Data Controller declares that it processes users’ personal data in accordance with Article 6(1)(b) of the GDPR, meaning that processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract; or in accordance with Article 6(1)(a), meaning on the basis of the data owner’s consent in the case of marketing use.
- The Data Controller processes personal data for the purpose of performing the contract, namely providing access to the system, or for the purpose indicated in the consent. The Data Controller processes data only to the extent necessary for these purposes and for the period necessary to perform the contract, or until the user withdraws consent. Data is processed at system.firmao.pl and system.firmao.net, depending on the language of the Application.
Call history and phone contact data are collected in order to enable the call history function in the Application. These data are collected only with the user’s consent to enable this function.
Photos and video recordings are used only for sharing with other Users of the Application. They are not collected automatically, but only through direct actions taken by the user. - The following personal data of users are collected in the Controller’s Application named CRM Firmao:
– first name and surname,
– email address,
– telephone number,
– identifiers associated with a specific device,
– phone call history and contacts, including phone number, contact name, contact photo, call direction, start time, end time, duration — only with the user’s
– consent to enable specific application functions,
– photos and video recordings – only with the user’s consent to enable specific application functions. - The recipients, meaning processors entrusted with the personal data, will be: the entity providing application maintenance services and entities providing IT support services for Firmao Polska Sp. z o.o., including entities located within the European Economic Area.
- The personal data of Application Users are not made available to third parties, except where such disclosure results from applicable provisions of law obliging the Personal Data Controller to provide them to authorized entities. The collected data may be made available to other Users of the Application, but only with the user’s consent and only to the extent necessary to implement the application functionality in the context of which the user has consented to data sharing.
- The Controller collects Application logs; however, it does not link them in any way with personal data. Statistics may be generated on the basis of log files to assist with administration. Aggregate summaries in the form of such statistics do not contain any features identifying individuals.
4. Users’ Rights. Right of Access to Data
In accordance with Articles 15–22 of the GDPR, every user has the following rights:
- Right of access to data — Article 15 GDPR
The data subject has the right to obtain from the Controller confirmation as to whether personal data concerning them are being processed and, where this is the case, the right to access such data. In accordance with Article 15, the Controller shall provide the data subject with a copy of the personal data undergoing processing. - Right to rectification — Article 16 GDPR
The data subject has the right to request that the Controller promptly rectify inaccurate personal data concerning them. - Right to erasure — “right to be forgotten” — Article 17 GDPR
The data subject has the right to request that the Controller promptly erase personal data concerning them, and the Controller is obliged to erase personal data without undue delay where one of the following circumstances applies:
a) the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
b) the data subject has withdrawn the consent on which the processing is based;
c) the data subject objects to the processing pursuant to Article 21(1), and there are no overriding legitimate grounds for the processing. - Right to restriction of processing — Article 18 GDPR
The data subject has the right to request that the Controller restrict processing in the following cases:
a) where the data are inaccurate — for the period necessary to correct them;
b) where the data subject has objected to processing pursuant to Article 21(1) — until it is determined whether the legitimate grounds of the Controller override the grounds of objection of the data subject;
c) where the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead. - Right to data portability — Article 19 GDPR
- Right to object
Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning them for such marketing, including profiling, to the extent that the processing is related to such direct marketing. - The User may exercise their rights by sending an appropriate request to kontakt@firmao.pl. For proper identification, the request should be sent from the email address used for registration. This implements Article 12(6) of the GDPR. A request may also be submitted by post — by sending a registered letter containing such a request to the correspondence address of the company operated by the Data Controller.
- In accordance with the law, the Controller shall respond to the person submitting the request within one month regarding the actions taken. If the Controller does not take such actions, it shall inform the person submitting the request of this fact.
- The data subject has the right to lodge a complaint against the Controller’s actions with the supervisory authority.
5. Security Measures
- The Application is equipped with security measures aimed at protecting personal data under the Controller’s control against loss, misuse, and modification. The Controller also has appropriate documentation and has implemented appropriate procedures related to the protection of personal data within the company.
- The Controller ensures that it protects all disclosed information in accordance with applicable laws and security protection standards, in particular:
a) Personal data collected by the Data Controller may be directly accessed, in accordance with Article 29 of the GDPR, only by authorized employees or associates of the Data Controller and authorized persons handling the Application who have been granted appropriate powers of attorney.
b) The Controller declares that when commissioning services from other entities, it requires partners, in accordance with Article 28 of the GDPR, to ensure appropriately high standards of protection for entrusted personal data, to sign appropriate data processing agreements in which partners confirm the application of such standards, and to accept the right to audit the compliance of these entities’ activities with those standards.
c) In order to ensure adequate protection of services provided electronically, the Application Controller applies a high level of security, including cryptographic protection of personal data transmission — SSL protocol — in accordance with Part C of the Regulation of the Minister of Internal Affairs and Administration of 29 April 2004 on documentation of personal data processing and the technical and organizational conditions that should be met by devices and IT systems used for processing personal data, Journal of Laws No. 100, item 1024.
d) Due to the public nature of the Internet, the use of electronically provided services may involve risks, regardless of whether the Data Controller exercises due diligence.
6. Changes to the Privacy Policy
- The Application Controller reserves the right to change the above Privacy Policy at any time and place, while undertaking to immediately publish the new Privacy Policy and inform all registered Users of this fact.
- The Data Controller reserves the right to introduce changes, withdraw or modify the functions or properties of the Application, as well as to undertake any legal actions permitted by applicable law.