- General provisions
- This document entitled “Personal Data Protection Policy” (hereinafter referred to as the Policy) is intended to provide a map of the requirements, rules and regulations for the protection of personal data at the company “Psychoterapia Ewa Żupnik”, doing business at the following address: Lubelska 4/1 Street, 30-003 Krakow, with assigned tax identification number (NIP): 6772482309.
- This Policy is a data protection policy within the meaning of RODO – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27.04.2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (Official Journal of the EU L 119, p. 1).
- The administrator of the personal data is the company “Psychoterapia Ewa Żupnik”, conducting business at the address: Lubelska 4/1 Street, 30-003 Krakow, with assigned tax identification number (NIP): 6772482309. The administrator can be contacted at 4/1 Lubelska Street, 30-003 Kraków; tel. no. +48 880 33 22 35; e-mail address: yourself.krakow@gmail.com.
- Abbreviations and definitions
- Policy means this Data Protection Policy, unless otherwise
is clear from the context. - RODO means Regulation (EU) 2016/679 of the European Parliament and of the Council of
04.2016 on the protection of individuals with regard to the processing of
personal data and on the free flow of such data and repealing Directive
95/46/EC (General Data Protection Regulation) (Official Journal of the EU L 119, p. 1). - Data means personal data, unless the context clearly indicates otherwise. Personal data also includes personal data (including sensitive data) of a child , of which the person is a parent or legal guardian.
- Person means the person whose personal data is processed (and the personal data of his/her child,including sensitive personal data), unless the context clearly indicates otherwise.
- Processor means an organization or person to whom the company has entrusted
with the processing of personal data. - RCPD or Register means the Register of Personal Data Processing Activities.
- Company means “Psychoterapia Ewa Żupnik”, doing business at the address: 4/1 Lubelska Street, 30-003 Krakow, with assigned tax identification number (NIP): 6772482309, unless the context clearly indicates otherwise.
- Cabinet means the main place of business, i.e. Lubelska Lubelska 4/1, 30-003 Kraków, unless the context clearly indicates otherwise.
- Website, service – means the Company’s website – https://yourself-psychoterapia.pl/
- Policy means this Data Protection Policy, unless otherwise
- Protection of Personal Data – general principles
- Pillars of personal data protection in the Company: Legality – the company cares about privacy and processes data in accordance with the law. Security – the company ensures an adequate level of data security by constantly taking measures in this regard. Rights of the Individual – the company enables individuals whose data it processes to exercise their rights and legally realizes them. Accountability – the company documents how it meets its obligations so that compliance can be demonstrated at any time.
- The company processes personal data in accordance with the following principles: on a legal basis and in accordance with the law (legalism), fairly and honestly (fairness), transparently to the data subject (transparency), for specific purposes and not “for backup” (minimization), not more than necessary (adequacy); with care for the accuracy of the data (correctness), not longer than necessary (timeliness), ensuring adequate data security (security).
- Data protection system
- The company shall develop, maintain and keep a Register of Personal Data Processing Activities (Register). The Register is a tool for accounting for the company’s data protection compliance.
- Handling of individual’s rights. The company fulfills its information obligations to the individuals
whose data it processes and ensures the handling of their rights by fulfilling the requests received in this regard, including:- Information obligations. The company shall provide persons with the legally required information when collecting data and in other situations, and shall organize and ensure documentation of the fulfillment of these obligations.
- Ability to execute requests. The company verifies and ensures the ability of itself and its processors to effectively execute each type of request.
- Handling of requests. The Company shall ensure that appropriate inputs and procedures are in place to ensure that requests from individuals are handled within the timeframes and in the manner required by the RODO and documented.
- Breach notification. The company has procedures in place to determine the need to notify those affected by an identified data breach.
- Security. The company ensures an adequate level of data security, including:
- conducts risk analyses for data processing activities or categories of data;
- Conducts data protection impact assessments where the risk of violating people’s rights and freedoms is high;
- Adapts data protection measures to the established risks;
- Has an information security management system.
- Processing of personal data – general principles
- Personal data is processed:
- In accordance with data protection regulations;
- In accordance with the implemented Privacy Policy;
- to the extent and for the purpose necessary for psychological and speech therapy, to obtain online counseling, to obtain counseling at the Company’s office and any services provided by the Company;
- to the extent and for the purpose necessary for the fulfillment of legitimate interests (legally justified purposes), and the processing does not violate the rights and freedoms of the data subject;
- to the extent and for the purpose in accordance with the terms and conditions of online consultation available on the company’s website (https://yourself-psychoterapia.pl/),consented to by the person if he or she contacted the company via the Internet or telephone for online consultation and advice.
- to the extent and for the purpose in accordance with the consent of the person who contacted the company via the Internet or telephone for an in-person consultation at the company’s office.
- Each Data Subject (if the company is the data controller) provides data on a voluntary basis and has the right to access, rectify, delete or restrict processing, the right to object, the right to lodge a complaint with a supervisory authority.
- The company retains personal data for no longer than 12 months after the termination of the Agreement.
- The Company reserves the right to process a person’s data after termination of the Agreement or withdrawal of consent only to the extent for the purpose of pursuing possible claims before a court of law or if national or EU regulations or international law oblige us to retain the data.
- The company has the right to share personal data of a Person with entities authorized under applicable laws (e.g. law enforcement agencies).
- The deletion of personal data may occur as a result of withdrawal of consent or filing a legally permissible objection to the processing of personal data. For this purpose, please contact the Personal Data Administrator.
- The company does not share personal data with other entities than those authorized under applicable law.
- Personal data is processed only by persons authorized by the Company, with whom it works closely. These include: accounting office, hosting company, google analytics, wordpress.
- The company identifies instances where it profiles processed data and maintains mechanisms to ensure that this process is lawful. If cases of profiling and automated decision-making are identified. The Company follows the adopted rules in this regard.
- Personal data is processed:
- Register of Data Processing Activities
- The RCPD is a form of documenting data processing activities, acts as
a map of data processing, and is one of the key elements enabling
the implementation of the fundamental principle on which the entire
personal data protection system is based, namely the principle of accountability. - The company maintains a Register of Data Processing Activities, in which it inventories and
monitors how it uses personal data. - The register is one of the basic tools that enable the Company to account
for most of its data protection obligations. - In the Register, for each data processing activity that the Company has deemed
separate for the purposes of the Register, the Company shall record at least: name of processing activity, organizational unit, purpose of processing, categories of persons, categories of data, source of data, planned deletion dates, name of co-controllers, name of processor and contact information, categories of recipients, name of system or software, general technical description and organization of security measures in accordance with Article 32 Law 1, DPIA, transfer to a third country or international organization.
- The RCPD is a form of documenting data processing activities, acts as
- How to handle individual rights and information obligations
- The company cares about the readability and style of the information provided and communication with the people
whose data it processes. - The Company facilitates people to exercise their rights through various activities, including:
posting on the Company’s website information or references (links) to
information about people’s rights, how to exercise them at the Company, including
identification requirements, methods of contacting the Company for this purpose. - The company takes care to meet legal deadlines for fulfilling its obligations to
people. - The company implements adequate methods of identifying and authenticating individuals for
the needs of fulfilling individual rights and information obligations. - In order to realize the rights of the individual, the Company provides procedures and mechanisms
to identify the data of specific individuals processed by the Company,
integrate this data, make changes to it and delete it in an integrated manner. - The company documents the handling of information obligations, notifications and requests
people.
- The company cares about the readability and style of the information provided and communication with the people
- Safety – general principles
- The Company shall ensure a degree of security corresponding to the risk of violation of the rights and freedoms of individuals as a result of the Company’s processing of personal data.
- The company has procedures in place to identify, assess and report an identified data breach to the Data Protection Authority within 72 hours of identifying the breach.
- The company applies security measures established as part of its risk analyses and adequacy of security measures and data protection impact assessments. Personal data security measures are part of the company’s information security and cyber security assurance measures and are further described in the procedures adopted by the company for these areas.
- Risk analysis and adequacy of security measures
- The company conducts and documents analyses of the adequacy of personal data security measures. To this end:
- The company ensures adequate state of the art information security,
cyber security and business continuity – either internally or with the support of
specialized entities. - The company categorizes data and processing activities according to the risks they present
- The company conducts risk analyses of violations of the rights or freedoms of individuals for data processing activities or categories of data.
- The company analyzes possible situations and scenarios of a personal data breach taking into account the nature, scope, context and purposes of the processing, the risk of violation of the rights or freedoms of individuals with different probability of occurrence and severity of the threat.
- The company determines feasible organizational and technical measures
security and evaluates the cost of implementing them, including The company determines the suitability and uses such measures and approaches as:- cyber security measures comprising the ability to continuously ensure the confidentiality, integrity, availability and resilience of processing systems and services.
- business continuity and disaster prevention measures, i.e. the ability to quickly restore the availability of and access to personal data in the event of a physical or technical incident.
- The company ensures adequate state of the art information security,
- The company conducts and documents analyses of the adequacy of personal data security measures. To this end:
- Cookies – information
- The https://yourself-psychoterapia.pl/ website uses cookies. These are small text files sent by a web server and stored by the browser’s computer software. When the browser reconnects to the site, the site recognizes the type of device from which the user is connecting. The parameters allow only the server that created them to read the information they contain. Cookies thus facilitate the use of previously visited sites.
- The information collected relates to IP address, type of browser used, language, type of operating system, ISP, time and date information, location, and information sent to the site via the contact form.
- The data collected is used to monitor and see how users are using the site in order to improve the site by providing a more efficient and seamless navigation. Monitoring of user information is done through the Google Analytics tool, which records user behavior on the site.
- Cookies identify the user, allowing the content of the site he uses to be tailored to his needs. By remembering his or her preferences, it makes it possible to appropriately tailor advertisements directed to him or her. The company uses cookies to guarantee the highest standard of service convenience, and the collected data are used only within the Company to optimize operations.
- The following cookies are used on the site:
- “necessary” cookies to enable the use of services available on the site, such as authentication cookies used for services that require authentication on the site;
- cookies used for security purposes, e.g. used to detect misuse of the site’s authentication;
- “performance” cookies, which enable the collection of information about the use of the website’s pages;
- “functional” cookies, which allow “remembering” the user’s selected settings and personalizing the user’s interface, e.g. with regard to the user’s chosen language or region of origin, font size, website design, etc;
- “advertising” cookies, allowing to provide users with advertising content more tailored to their interests.
- The user has the ability to disable or restore the option of collecting cookies at any time by changing the settings in the web browser. Instructions for managing cookies are available at: http://www.allaboutcookies.org/manage-cookies
- Additional personal data, such as e-mail address, is collected only where the user, by filling out the form, has expressly consented to it. The above data is retained and used by the Company only for the needs necessary to perform the function.
- The Company reserves the right to change its privacy policy. Persons visiting the website or using the Company’s services are always bound by the current version of the policy, available on this website.