Privacy policy

I. Definitions

The purpose of this Privacy Policy is to explain the principles on which your personal data is processed and to set out the rights to which you are entitled in connection with such processing. The Controller attaches particular importance to protecting the privacy and confidentiality of the data of persons with whom it maintains professional relationships, as well as of users of its website.

The terms used in this Policy have the following meanings:

  • Controller — Regulatory Advisers Kancelaria Radcy Prawnego Bartosz Bacia (Bartosz Bacia Attorney-at-Law Firm), with its registered office in Warsaw (00-029), at ul. Nowy Świat 33/13;
  • GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation);
  • Client — an entity to which the Controller provides legal assistance or advisory services;
  • Website — the website operated by the Controller at regulatoryadvisers.pl;
  • User — a natural person using the Website;
  • Policy — this privacy policy.
II. Data Controller

The controller of personal data is Regulatory Advisers Kancelaria Radcy Prawnego Bartosz Bacia, ul. Nowy Świat 33/13, 00-029 Warsaw, Poland, Tax ID (NIP): 1132101052, Business Registry No. (REGON): 540203570

For any matters relating to the processing of personal data, you may contact the Controller by e-mail at info@regulatoryadvisers.pl, or in writing at the registered office address indicated above.

Personal data is processed in accordance with data protection law, including the GDPR and the Polish Act of 10 May 2018 on the Protection of Personal Data. The Controller keeps personal data confidential and protects it against unauthorised third-party access, applying technical and organisational measures appropriate to the nature of its legal practice.

III. Purposes and legal bases for processing

The Controller processes personal data for the following purposes and on the following legal
bases:

  • to provide legal assistance and advisory services to Clients and to perform concluded agreements — pursuant to Article 6(1)(b) GDPR and, to the extent of the professional obligations of an attorney-at-law, Article 6(1)(c) GDPR;
  • to establish and maintain business relationships, including ongoing contact with persons acting on behalf of Clients, contractors and suppliers — based on the Controller's legitimate interest (Article 6(1)(f) GDPR); 
  • to handle enquiries submitted by e-mail or via the contact form on the Website and to conduct related correspondence — based on the Controller's legitimate interest in responding to such enquiries (Article 6(1)(f) GDPR);
  • to market the Controller's own services, including informing about events and publications and sending legal alerts and the newsletter — based on the Controller's legitimate interest and, for commercial communications sent electronically, on consent (Article 6(1)(a) and (f) GDPR);
  • to conduct recruitment processes and to handle candidates' applications — based on a legal obligation and on the candidate's consent (Article 6(1)(c) and (a) GDPR);
  • to comply with the Controller's legal obligations, including tax and accounting obligations and obligations arising from anti-money laundering and counter-terrorist financing law — pursuant to Article 6(1)(c) GDPR;
  • to establish, pursue or defend claims, and to ensure the IT security of the Website — based on the Controller's legitimate interest (Article 6(1)(f) GDPR). Providing personal data is voluntary; however, depending on the circumstances, refusal to provide it or a request for its erasure may make it impossible to establish contact, send requested information, or perform a service.

Providing personal data is voluntary; however, depending on the circumstances, refusal to provide it or a request for its erasure may make it impossible to establish contact, send requested information, or perform a service.
IV. Retention period

The period of processing depends on the purpose for which the data is processed. Data is processed, respectively: for the duration of the service or business relationship; until an effective objection is raised or consent is withdrawn — where processing is based on the Controller's legitimate interest or on consent; for the period required by law — with respect to legal obligations, including tax obligations and those arising from anti-money laundering law; and, after the principal purpose has ceased, for the period necessary to establish, pursue or defend claims, until the relevant limitation periods expire. After those periods, the data is deleted.

V. Recipients of personal data

Recipients of personal data may be entities providing services to the Controller under data processing agreements or as separate controllers, in particular: providers of IT services and tools (including hosting and cloud computing), accounting and audit service providers, postal and courier service providers, and — in justified cases and subject to professional secrecy — cooperating lawyers and law firms. Data may also be disclosed to public authorities, courts and other authorised bodies where required by law. Entities processing data on the Controller's behalf are obliged to keep it confidential and to process it solely in accordance with the Controller's instructions and applicable law.

VI. Transfers outside the European Economic Area

As a rule, personal data is not transferred to third countries outside the European Economic Area (EEA) or to international organisations. Should a transfer outside the EEA become necessary, the Controller will ensure the appropriate safeguards required by the GDPR, in particular on the basis of an adequacy decision of the European Commission or standard contractual clauses, and data subjects will be able to obtain a copy of the safeguards applied.

VII. Rights of data subjects

Within the limits set out in data protection law, every person whose data is processed has the following rights:

  • the right of access to the data and to obtain a copy thereof;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of processing;
  • the right to data portability — to the extent that the data is processed on the basis of consent or a contract by automated means;
  • the right to object to processing based on the Controller's legitimate interest, including the right to object to processing for direct marketing purposes;
  • the right to withdraw consent at any time, whereby withdrawal does not affect the lawfulness of processing carried out prior to such withdrawal.

The Controller notes that some of the above rights may be subject to limitations to the extent that the data is processed in the course of providing legal assistance and is covered by the professional secrecy of an attorney-at-law (radca prawny).

VIII. Right to lodge a complaint

A data subject has the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw — if they consider that the processing of their personal data infringes data protection law.

IX. Cookies

The Website uses cookies, i.e. small text files stored on the User's terminal device. The information collected by means of cookies may include data on the use of the Website, including the date and time of the visit. Cookies are used to ensure the proper functioning of the Website, to improve it and to tailor content to Users' preferences, as well as for analytical and statistical purposes. The User may change cookie settings in their browser at any time, including disabling cookies for a selected website or for all websites visited; restricting the use of cookies may, however, affect certain functionalities of the Website.

X. Automated decision-making and profiling

Personal data is not used for automated decision-making, including profiling that produces legal effects concerning the data subject or similarly significantly affects them.

XI. Changes to the Privacy Policy

The Controller may update this Policy, in particular in connection with changes in the law or in the scope of its activities. The current version of the Policy is published on the Website. Periodic review of its content is recommended.