We understand the importance of privacy to the users of our Website. When using personally identifiable information, Compliant Product complies with all the applicable data privacy regulations (GDPR in particular) and is committed to safeguarding your privacy online. This privacy policy (“Policy”) describes the rules for the processing of information about you, including personal data and cookies.
1.General information
The Policy applies to the website operating at url: compliantproduct.com (“Website”)
The Website operator and the data controller is: COMPLIANT PRODUCT Zuzanna Wiśniewska (“Operator” or “we”), operating under the Polish law, registered with
Polish Commercial Register under no. 363825481, with a seat and
business address at: 1B Spiralna, 02-984 Warsaw, Poland, reachable at
e-mail contact address: office@compliantproduct.com
The Operator is the controller of your personal data in relation to the data provided voluntarily on the Website.
We collect and process your personal data to facilitate your use of the Website and its full functionalities, as well as to provide you the Services. To be more precise, we collect information about Website’s users through the forms (data voluntarily entered: name, email address) and by saving cookie files in end devices (“Cookies”). We use personal data for the following purposes:
-
- Handling inquiries received via the form
- Presentation of the offer or information
- Implementation of ordered services
- Notification on the new posts published on the blog.
You voluntarily place enquiry through the Website, thus providing us with your personal data. If you do not wish to provide us with above data, do not place post’s comments nor enquiries through the Website. Providing the data is voluntary as a rule, but, within indicated scope related to the cookies, necessary to operate the Website.
2. Data retention
Your personal data is processed by the Operator for no longer than it is necessary to perform the related activities specified in separate regulations (e.g. on accounting). When not indicated by separate legal provisions, the data will not be processed for more than 3 years (website enquiries).
-
-
- Data collected through contact form enquiry are processed by default for 6 months from the last e-mail correspondence, unless the nature and the content of the correspondence gives ground and legitimate interest to process (store) the data longer.
- Data collected through subscription form are processed until the user unsubscribes from the notification service.
- If you leave a comment, the comment and its metadata are retained indefinitely.
-
3. Additional information on how the data may be processed (forms, comments and subscriptions)
-
- The Website may save information about connection parameters (time stamp, IP address).
- The Website, in some cases, may save information facilitating the linking of data in the form with the e-mail address of the user filling in the form. In this case, the user’s e-mail address appears inside the url of the page containing the form. The data provided in the form is processed for the purpose resulting from the function of a specific form, e.g. to process the inquiry or service request. The context and description of the form clearly informs what it is used for.
- The blog site of the Website saves the data provided in the Website’s blog post comment section. When users leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection. An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/ . After approval of your comment, your profile picture is visible to the public in the context of your comment. This data is used solely for the documentation purpose of the discussion taking place in relation to the given post. If you leave a comment you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser. When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
We collect information about visitors who comment on Sites with the aid of Akismet anti-spam service. The information we collect depends on how the User sets up Akismet for the Site, but typically includes the commenter’s IP address, user agent, referrer, and Site URL (along with other information directly provided by the commenter such as their name, username, email address, and the comment itself). The Akismet privacy policy is available here: https://akismet.com/privacy/ - The blog site of the Website saves the data provided in the subscription form (e-mail address) for the purpose of sending notification to the user on any new blog posts published on the Website.
4. Media content embedded from third party sites
The Website includes media content embedded from other websites (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website. These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
5. Sharing the data with third parties
In some situations, the Operator has the right to transfer your personal data to other recipients if it is necessary to perform the contract concluded with you or to fulfill the obligations incumbent on the Operator. This applies to such groups of recipients: (i) hosting company on an entrustment basis, (ii) authorized employees and associates who use the data to achieve the purpose of the Website, (iii) governmental bodies and agencies within the scope of specific regulation and processes execution.
The Operator shares the data also with its service providers, i.e.
-
- The Gravatar service for WordPress commenting tools – privacy policy.
- Akismet service for anti-spam purposes – privacy policy
- YouTube for its plugin service – privacy policy
- Google for its fonts delivery – privacy policy
6. Specific content plugins and services
-
-
- The Website uses plugins from YouTube, which is operated by Google. The operator of the pages is YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. If you visit one of our pages featuring a YouTube plugin, a connection to the YouTube servers is established. Here the YouTube server is informed about which of our pages you have visited.
If you’re logged in to your YouTube account, YouTube allows you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your YouTube account. YouTube is used to help make our website appealing. This constitutes a justified interest pursuant to Art. 6 (1) (f) GDPR. Further information about handling user data, can be found in the data protection declaration of YouTube under https://policies.google.com/privacy?hl=en&gl=en. - For uniform representation of fonts, the Website uses web fonts provided by Google. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly. For this purpose your browser has to establish a direct connection to Google servers. Google thus becomes aware that our Website was accessed via your IP address. The use of Google Web fonts is done in the interest of a uniform and attractive presentation of our plugin. This constitutes a justified interest pursuant to Art. 6 (1) (f) GDPR. If your browser does not support web fonts, a standard font is used by your computer.
Further information about handling user data, can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy at https://www.google.com/policies/privacy/.
- The Website uses plugins from YouTube, which is operated by Google. The operator of the pages is YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. If you visit one of our pages featuring a YouTube plugin, a connection to the YouTube servers is established. Here the YouTube server is informed about which of our pages you have visited.
-
7. Hosting
The website is hosted (technically maintained) on the Operator’s servers: zenbox.pl
8. Selected data protection methods used by the Operator
The places of logging in and entering personal data are protected in the transmission layer (SSL certificate). As a result, personal data and login data entered on the website are encrypted on the user’s computer and can only be read on the target server. An important element of data protection is regular updating of all software used by the Operator to process personal data, which in particular means regular updates of programming components.
9. Your rights
You have the right to request from the Operator:
-
- access to your personal data,
- rectifying them,
- deletion,
- processing restrictions,
- and data portability.
The right to object may not be exercised if there are valid, legally justified grounds for processing of yours or the Operator’s interests, rights and freedoms, in particular establishing, investigating or defending claims.
The Operator’s actions may be appealed against to the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.
10. Relevant marketing techniques
-
-
- The Operator uses statistical analysis of website traffic through Google Analytics (Google Inc. based in the USA). The Operator does not provide personal data to the operator of this service, but only anonymised information. The service is based on the use of cookies on the user’s end device. In terms of information about user preferences collected by the Google advertising network, the user can view and edit the information resulting from cookies using the tool: https://www.google.com/ads/preferences/
- The operator uses the Facebook pixel. This technology means that Facebook (Facebook Inc. based in the USA) knows that a given person registered in it uses the Website. In this case, it is based on data for which he is the administrator himself, the Operator does not provide any additional personal data to Facebook. The service is based on the use of cookies on the user’s end device.
-
11. Information about cookies
The Website uses Cookies, i.e. IT data, in particular text files, which are stored on the Website user’s end device and are intended for using the Website’s pages. Cookies usually contain the name of the website they come from, the storage time on the end device and a unique number.
-
- The entity that places cookies on the Website user’s end device and obtains access to them is the Operator.
- The Cookies that are used are either:
- First party cookies – Cookies set by the Website (only the Website can read them)
- Third party cookies, used by the Website’s external service providers.
- Cookies are used for achieving the goals set out above in the section “Relevant marketing techniques”;
- The Website uses persistent types of cookies. Persistent cookies are cookies saved on your computer and that are not deleted automatically when you quit your browser, unlike a session cookie, which is deleted when you quit your browser. Persistent cookies are stored on the user’s end device for the time specified in the cookie file parameters or until they are deleted by the user. Software for browsing websites (web browser) usually allows cookies to be stored on the user’s end device by default. The Website users can change the settings in this regard. The web browser allows you to delete cookies. It is also possible to automatically block cookies. Detailed information on this subject can be found in the help or documentation of the web browser.
- Restrictions on the use of cookies may affect some of the functionalities available on the Website pages.
- Cookies placed on the Website user’s end device may also be used by entities cooperating with the Website operator, in particular the following companies: Google (Google Inc. based in the USA), Facebook (Facebook Inc. based in the USA), Linkedin (Linkedin Inc. based in the USA).
12. Managing cookies
Most web browsers accept cookies by default. You can change your settings so that Cookies are blocked or that you are alerted that they are being sent to your devices. There are many ways to manage cookies. Please refer to your browser’s instructions or show help to learn how to adjust or change your browser settings.
If you withdraw consent that you already gave before, the Operator will no longer use the relevant Cookies and will delete the first-party cookies. If you block Cookies used by the Website, it may affect your visiting experience. If you use various devices to browse the Website (e.g. computer, tablet or smartphone), you must make sure that each browser on each device is properly matched to your preferences. The Operator can’t delete third-party Cookies. If you wish to delete them, you must do it through your browser settings.
In order to manage cookie settings, follow the applicable instructions published for the web browser you use: Google Chrome, Mozilla, other browsers.
13. List of cookies
Type | Name | Owner / Service | Function | Duration |
necessary | __sharethis_cookie_test__ | compliantproduct.com | This cookie determines whether the browser accepts cookies | session |
test_cookie | doubleclick.net | This cookie determines whether the browser accepts cookies | 1 day | |
CONSENT | youtube.com | Used to detect if the visitor has accepted the marketing category in the cookie ban n er. This cookie is necessary for GDPR-compliance of the website | 2 years | |
statistics | _ga | compliantproduct.com | Registers a unique ID that is used to generate statistical data on how the visitor uses the website | 2 years |
_gat | compliantproduct.com | Used by Google Analytics to throttle request rate | 1 day | |
_gid | compliantproduct.com | Registers a unique ID that is used to generate statistical data on how the visitor uses the website | 1 day | |
YSC | youtube.com | Registers a unique ID to keep statistics of what videos from Youtube the user has seen | session | |
yt.innertube::nextId | youtube.com | Registers a unique ID to keep statistics of what videos from Youtube the user has seen | persistent | |
yt.innertube::requests | youtube.com | Registers a unique ID to keep statistics of what videos from Youtube the user has seen | persistent | |
collect | google-analytics.com | Used to send data to Google Analytics about the visitor’s device and behavior. Tracks the visitor across devices and marketing channels | session | |
marketing | _fbp | compliantproduct.com | Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers | 3 months |
IDE | doubleclick.net | Used by Google Dou bleClick to register and report the website u ser’s actions after view in g or clicking one of the advertiser’s ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user | 1 year | |
pagead/1p-conversion/# | google.com | Used to measure ads conversion | session | |
pagead/viewthroughconversion/945228805 | doubleclick.net | Used to measure ads conversion | session | |
st_samesite | consensu.org | Used by ShareThis to track visitor’s website navigation and preferences – This is used for internal statistics and marketing | session | |
st_samesite_v2 | compliantproduct.com | Used to track visitor’s website navigation and preferences – This is used for internal statistics and marketing | session | |
tr | facebook.com | Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers. | session | |
Statistical features and user preferences | VISITOR_INFO1_LIVE | youtube.com | Tries to estimate the users’ bandwidth on pages with integrated Youtube videos | 179 days |
yt-remote-cast-available | youtube.com | Stores the user’s video player preferences using embedded Youtube video | session | |
yt-remote-cast-installed | youtube.com | Stores the user’s video player preferences using embedded Youtube video | session | |
yt-remote-connected-devices | youtube.com | Stores the user’s video player preferences using embedded Youtube video | persistent | |
yt-remote-device-id | youtube.com | Stores the user’s video player preferences using embedded Youtube video | persistent | |
yt-remote-fast-check-period | youtube.com | Stores the user’s video player preferences using embedded Youtube video | session | |
yt-remote-session-app | youtube.com | Stores the user’s video player preferences using embedded Youtube video | session | |
yt-remote-session-name | youtube.com | Stores the user’s video player preferences using embedded Youtube video | session |
14. Transfer of data outside the European Union
Personal data is not transferred from or to third countries within the meaning of GDPR. This means that we do not send them outside the European Union.
For any queries you may have on our processing of your personal data, please contact office@compliantproduct.com.