Privacy policy

1. General information

  1. This Privacy Policy sets out the rules governing the processing of personal data of users of the profidesk.io website, hereinafter referred to as the “Website”, operated by Superlativa Sp. z o.o., with its registered office in Lublin, ul. Agatowa 17/37, 20-571 Lublin, NIP: 9452183819, KRS: 0000553701, hereinafter referred to as the “Controller”.
  2. The Controller makes every effort to ensure that the processing of users’ personal data is carried out in accordance with applicable law, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).

2. Scope of data collected

  1. The Controller collects the following personal data from users:
    • First name and surname: required to identify the user and personalise services.
    • Email address: used to communicate with the user, including to send notifications and information relating to the operation of the website.
    • Telephone number: used to contact the user in matters requiring a prompt response.

3. Purposes of data processing

  1. Users’ personal data is processed for the following purposes:
    • the conclusion and performance of a contract – pursuant to Article 6(1)(b) of the GDPR – including contracts relating to our products or services, covering in particular the provision of educational services:
      • enabling access to multimedia textbooks and exercises,
      • managing the user’s account,
      • enabling interaction with teaching materials;
    • to fulfil legal obligations, e.g. tax obligations and the retention of records – pursuant to Article 6(1)(c) of the GDPR;
    • arising from a legitimate interest – pursuant to Article 6(1)(f) of the GDPR – including for the purpose of:
      • Communication with users: responding to enquiries, notifying users of changes to the terms and conditions or privacy policy, and sending newsletters (if the user has given their consent).
      • Analysis and statistics: collecting data on the use of the website in order to optimise it and improve its functionality.
      • Security: monitoring activity on the website to prevent misuse and ensure the security of users’ data;
    • providing information about our services via electronic means of communication (email, text message) or by telephone – on the basis of consent granted, i.e. Article 6(1)(a) of the GDPR.

4. Legal basis for data processing

  1. The processing of personal data is carried out on the following legal bases:
    • Article 6(1)(a) of the GDPR – the user’s consent to data processing.
    • Article 6(1)(b) of the GDPR – the necessity of data processing for the performance of a contract to which the user is a party.
    • Article 6(1)(c) of the GDPR – the necessity to comply with a legal obligation.
    • Article 6(1)(f) of the GDPR – the Controller’s legitimate interests, such as analysis and statistics, and ensuring the security of the website.

5. Recipients of data

  1. Users’ personal data may be disclosed to the following recipients:
    • Entities providing hosting and IT services to the Controller, in order to ensure the proper functioning of the website.
    • Entities providing analytical and marketing services, in order to analyse traffic on the Website and optimise marketing activities.
    • Law enforcement agencies, courts and other public authorities, where there is a legal obligation arising from statutory provisions.

6. Transfer of data outside the EEA

  1. Users’ personal data is not transferred outside the European Economic Area (EEA).

7. Data retention period

  1. Where the basis for processing is a contract, data is retained for the period required by law for the retention of accounting and tax records; where the contract relates solely to the maintenance of an account, data is retained until the account is deleted; in any event, however, for no less than the duration of any proceedings aimed at enforcing claims or defending against them.
  2. Where the basis for processing is our legitimate interest – the data is retained until the data subject lodges a valid objection.
  3. Where the basis for data processing is consent, the data shall be retained until such consent is withdrawn.
  4. In the cases referred to in points 7.2 and 7.3, the law specifies the period for which the data must be retained.

8. Users’ rights

  1. Users have the following rights:
    • Right of access to data: the user has the right to obtain confirmation as to whether their data is being processed and to access that data.
    • Right to rectification: the user has the right to request the rectification of their personal data that is inaccurate or incomplete.
    • Right to erasure: the user has the right to request the erasure of their personal data in the cases specified in Article 17 of the GDPR.
    • Right to restriction of processing: the user has the right to request the restriction of the processing of their personal data in the cases specified in Article 18 of the GDPR.
    • Right to data portability: the user has the right to receive their personal data in a structured, commonly used format and to request that such data be transferred to another controller.
    • Right to object: the user has the right to object to the processing of their personal data on the basis of Article 6(1)(f) of the GDPR.
    • Right to withdraw consent: the user has the right to withdraw their consent to the processing of personal data at any time; this does not affect the lawfulness of the processing carried out prior to the withdrawal.

    The user also has the right to lodge a complaint with the supervisory authority, i.e. the President of the Office for Personal Data Protection.

  2. To exercise the above rights, the user may contact the Controller via email at: hello@profidesk.io.

9. Cookies and other technologies

  1. Through the use of cookies and similar technologies (local storage), information regarding activity on websites and mobile applications – including logins and session durations – is collected automatically. This serves to monitor the use of our services, solely for our statistical purposes and to improve their quality and functionality, as well as to prevent misuse.

10. No automated decision-making

  1. The Controller does not make automated decisions, including profiling, that produce legal effects concerning data subjects or similarly significantly affect them.

11. Voluntary provision of data

  1. The provision of personal data is voluntary; however, it is necessary for the conclusion of a contract or for the full use of our services.

12. Changes to the privacy policy

  1. The Controller reserves the right to make changes to this privacy policy. Users will be informed of any changes via the website at least 7 days before they come into effect.

13. Contact

  1. Should users have any queries regarding the privacy policy, they may contact the Controller via email at: hello@profidesk.io, by telephone on +48 534 134 050, or in writing to the Controller’s registered office at: Superlativa Sp. z o.o., ul. Agatowa 17/37, 20-571 Lublin. Opening hours: Mon–Fri 08:00–17:00.