Privacy Policy
The following Privacy Policy sets out the rules for saving and accessing data on Users’ Devices used to access the Service for the purpose of providing electronic services by the Administrator, as well as the rules for collecting and processing Users’ personal data provided by them personally and voluntarily through the tools available in the Service.
§1 Definitions
- Service – the website “East-Gallery” operating at https://east-gallery.com/
- External Service – websites of partners, service providers, or clients cooperating with the Administrator
- Service / Data Administrator – the Administrator of the Service and the Data Administrator (hereinafter referred to as the Administrator) is the company ” t13dg Tomasz Tarasewicz”, conducting business at: Kościuszki 40-40B/2A, 81702 Sopot, with tax identification number (NIP): 669 204 12 18, providing electronic services through the Service
- User – a natural person for whom the Administrator provides electronic services through the Service.
- Device – an electronic device together with software through which the User accesses the Service
- Cookies – text data collected in the form of files stored on the User’s Device
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Personal data – means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name and surname, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person
- Processing – means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;
- Restriction of processing – means the marking of stored personal data with the aim of limiting their processing in the future
- Profiling – means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements
- Consent – the consent of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her
- Personal data breach – means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored, or otherwise processed
- Pseudonymisation – means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person
- Anonymisation – Data anonymisation is an irreversible process of operations on data that destroys / overwrites “personal data” making it impossible to identify or link a given record to a specific user or natural person.
§2 Data Protection Officer
Pursuant to Art. 37 of the GDPR, the Administrator has not appointed a Data Protection Officer.
In matters concerning data processing, including personal data, please contact the Administrator directly.
§3 Types of Cookies
- Internal Cookies – files placed and read from the User’s Device by the ICT system of the Service
- External Cookies – files placed and read from the User’s Device by the ICT systems of External Services. Scripts of External Services that may place Cookies on Users’ Devices have been knowingly placed in the Service through scripts and services made available and installed in the Service
- Session Cookies – files placed and read from the User’s Device by the Service during one session of a given Device. After the session ends, the files are deleted from the User’s Device.
- Persistent Cookies – files placed and read from the User’s Device by the Service until they are manually deleted. The files are not automatically deleted after the Device session ends unless the User’s Device configuration is set to delete Cookies after the Device session ends.
§4 Data storage security
- Mechanisms for storing and reading Cookie files – The mechanisms for storing, reading, and exchanging data between Cookies saved on the User’s Device and the Service are implemented through built-in mechanisms of web browsers and do not allow other data to be downloaded from the User’s Device or data from other websites visited by the User, including personal data or confidential information. Transferring viruses, Trojan horses, and other worms to the User’s Device is also practically impossible.
- Internal Cookies – the Cookies used by the Administrator are safe for Users’ Devices and do not contain scripts, content, or information that could threaten the security of personal data or the security of the Device used by the User.
- External Cookies – the Administrator makes every possible effort to verify and select service partners in the context of Users’ security. The Administrator chooses well-known, large partners with global public trust for cooperation. However, the Administrator does not have full control over the content of Cookies originating from external partners. To the extent permitted by law, the Administrator shall not be responsible for the security of Cookies, their contents, and their licensed use by scripts installed in the service originating from External Services. The list of partners is included later in this Privacy Policy.
- Cookie control
- The User may at any time independently change the settings regarding saving, deleting, and access to data stored in Cookies by each website
- Information on how to disable Cookies in the most popular desktop browsers is available on the following page: how to disable cookies or from one of the listed providers:
- The User may at any time delete all previously saved Cookies using the tools of the User’s Device through which the User uses the Service.
- Threats on the User’s side – the Administrator uses all possible technical measures to ensure the security of data placed in Cookies. However, it should be noted that ensuring the security of this data depends on both parties, including the User’s actions. The Administrator is not responsible for the interception of this data, impersonation of the User’s session, or its deletion as a result of the User’s conscious or unconscious actions, viruses, Trojan horses, and other spyware with which the User’s Device may be or may have been infected. In order to protect themselves against these threats, Users should take care of their Cybersecurity while using the Internet..
- Storage of personal data – the Administrator ensures that every effort is made to keep personal data voluntarily entered by Users secure, that access to them is limited and carried out in accordance with their intended purpose and processing objectives. The Administrator also ensures that every effort is made to protect the data held against loss by applying appropriate physical and organisational safeguards.
§5 Purposes for which Cookies are used
- Improving and facilitating access to the Service
- Personalising the Service for Users
- Marketing, Remarketing in external services
- Keeping statistics (users, number of visits, types of devices, connection, etc.)
- Providing social services
§6 Purposes of personal data processing
Personal data voluntarily provided by Users are processed for one of the following purposes:
- Provision of electronic services:
- Communication between the Administrator and Users in matters related to the Service and data protection
- Ensuring the legitimate interest of the Administrator
Data about Users collected anonymously and automatically are processed for one of the following purposes:
- Keeping statistics
- Remarketing
- Ensuring the legitimate interest of the Administrator
§7 Cookies of External Services
The Administrator uses JavaScript scripts and web components of partners in the Service, which may place their own Cookies on the User’s Device. Remember that in your browser settings, you can decide for yourself which Cookies may be used by individual websites. Below is a list of partners or their services implemented in the Service that may place Cookies:
- Social / integrated services: (Registration, Login, content sharing, communication, etc.)
- Keeping statistics:
Services provided by third parties are beyond the Administrator’s control. These entities may change their terms of service, privacy policies, data processing purposes, and methods of using Cookies at any time.
§8 Types of collected data
The Service collects data about Users. Some data are collected automatically and anonymously, while some data are personal data voluntarily provided by Users when subscribing to individual services offered by the Service.
Anonymous data collected automatically:
- IP address
- Browser type
- Screen resolution
- Approximate location
- Opened subpages of the service
- Time spent on the relevant subpage of the service
- Type of operating system
- Address of the previous subpage
- Referring page address
- Browser language
- Internet connection speed
- Internet service provider
Data collected during registration:
- Email address
- IP address (collected automatically)
Data collected when subscribing to the Newsletter service
- Email address
Some data (excluding identifying data) may be stored in Cookies. Some data (excluding identifying data) may be transferred to the provider of statistical services.
§9 Access to personal data by third parties
As a rule, the only recipient of personal data provided by Users is the Administrator. Data collected as part of the services provided are not transferred or resold to third parties.
Access to data (most often on the basis of a Data Processing Agreement) may be held by entities responsible for maintaining the infrastructure and services necessary to operate the service, i.e.:
- Hosting companies providing hosting or related services for the Administrator
Entrusting the processing of personal data – Hosting, VPS or Dedicated Server services
In order to operate the service, the Administrator uses the services of an external provider of hosting, VPS, or Dedicated Servers – LH.pl Sp. z o.o. All data collected and processed in the service are stored and processed in the infrastructure of the service provider located in Poland. There is a possibility of access to data as a result of service works carried out by the service provider’s personnel. Access to these data is regulated by an agreement concluded between the Administrator and the Service Provider.
§10 Method of processing personal data
Personal data voluntarily provided by Users:
- Personal data will not be transferred outside the European Union unless they have been published as a result of the User’s individual action (e.g. entering a comment or post), which will make the data available to any person visiting the service.
- Personal data will not be used for automated decision-making (profiling).
- Personal data will not be resold to third parties.
Anonymous data (without personal data) collected automatically:
- Anonymous data (without personal data) will be transferred outside the European Union.
- Anonymous data (without personal data) will not be used for automated decision-making (profiling).
- Anonymous data (without personal data) will not be resold to third parties.
§11 Legal bases for the processing of personal data
The Service collects and processes Users’ data on the basis of:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Art. 6(1)(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes
- Art. 6(1)(b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract
- Art. 6(1)(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party
- Act of 10 May 2018 on the protection of personal data (Journal of Laws 2018 item 1000)
- Act of 16 July 2004 Telecommunications Law (Journal of Laws 2004 No. 171 item 1800)
- Act of 4 February 1994 on Copyright and Related Rights (Journal of Laws 1994 No. 24 item 83)
§12 Period of personal data processing
Personal data voluntarily provided by Users:
As a rule, the indicated personal data are stored only for the period of providing the Service within the Service by the Administrator. They are deleted or anonymised within up to 30 days from the termination of service provision (e.g. deletion of a registered user account, unsubscribing from the Newsletter list, etc.)
An exception is a situation that requires securing the legally justified purposes of further processing of these data by the Administrator. In such a situation, the Administrator will store the indicated data, from the time of the User’s request for their deletion, for no longer than 3 years in the event of a violation or suspected violation of the service regulations by the User
Anonymous data (without personal data) collected automatically:
Anonymous statistical data, which do not constitute personal data, are stored by the Administrator for the purpose of keeping service statistics for an indefinite period
§13 Users’ rights related to the processing of personal data
The Service collects and processes Users’ data on the basis of:
- Right of access to personal data Users have the right to obtain access to their personal data, exercised upon request submitted to the Administrator
- Right to rectify personal data Users have the right to request that the Administrator immediately rectify personal data that are incorrect and / or complete incomplete personal data, exercised upon request submitted to the Administrator
- Right to erasure of personal data Users have the right to request that the Administrator immediately erase personal data, exercised upon request submitted to the Administrator. In the case of user accounts, erasure of data consists in anonymising data enabling identification of the User. The Administrator reserves the right to withhold the execution of the request for data erasure in order to protect the legitimate interest of the Administrator (e.g. when the User has breached the Regulations or the data were obtained as a result of correspondence conducted). In the case of the Newsletter service, the User may independently remove their personal data by using the link included in each email message sent.
- Right to restriction of processing of personal data Users have the right to restrict the processing of personal data in cases indicated in Art. 18 GDPR, including questioning the accuracy of personal data, exercised upon request submitted to the Administrator
- Right to data portability Users have the right to obtain from the Administrator personal data concerning the User in a structured, commonly used format suitable for machine reading, exercised upon request submitted to the Administrator
- Right to object to the processing of personal data Users have the right to object to the processing of their personal data in cases specified in Art. 21 GDPR, exercised upon request submitted to the Administrator
- Right to lodge a complaint Users have the right to lodge a complaint with the supervisory authority dealing with the protection of personal data.
§14 Contact with the Administrator
The Administrator may be contacted in one of the following ways
- Postal address – t13dg Tomasz Tarasewicz, Kościuszki 40-40B/2A, 81702 Sopot
- Email address – tomek@east-gallery.com
- Telephone contact – +48 501 062 203
- Contact form – available at: /kontakt
§15 Service requirements
- Restricting the saving and access to Cookies on the User’s Device may cause some functions of the Service to work improperly.
- The Administrator shall not be liable for improperly functioning features of the Service if the User restricts in any way the possibility of saving and reading Cookies.
§16 External links
The Service – in articles, posts, entries, or Users’ comments – may contain links to external websites with which the Service Owner does not cooperate. These links and the pages or files indicated under them may be dangerous to Your Device or pose a threat to the security of Your data. The Administrator is not responsible for content located outside the Service.
§17 Changes to the Privacy Policy
- The Administrator reserves the right to change this Privacy Policy at any time without informing Users with regard to the use and application of anonymous data or the use of Cookies.
- The Administrator reserves the right to change this Privacy Policy at any time with regard to the processing of Personal Data, of which Users who have user accounts or are subscribed to the Newsletter service will be informed by email within 7 days of the changes. Continued use of the services means that the User has read and accepted the changes introduced to the Privacy Policy. If the User does not agree with the changes introduced, they are obliged to delete their account from the Service or unsubscribe from the Newsletter service.
- The introduced changes to the Privacy Policy will be published on this subpage of the Service.
- The introduced changes enter into force upon their publication.