This is an informational translation. In case of discrepancies, the Polish language version shall prevail.
Taking into account the right to the protection of personal data under Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC — GDPR (RODO) — we kindly inform you that:
1. General information
- This policy applies to the website operating at: hadynski.pl.
- The operator of the website and the controller of personal data is HI Sp. z o.o., ul. Powstańców Śląskich 7A, 53-332 Wrocław, NIP (tax ID): 8971869265 (hereinafter: the Controller or the Operator).
- The Controller can be contacted by e-mail at: biuro@hadynski.pl.
- For matters concerning the processing of personal data and the exercise of the rights of data subjects, please contact the Controller.
- The website processes personal data for the following purposes:
- handling enquiries submitted via the contact form,
- presenting offers or information,
- conducting direct marketing,
- transferring data to business partners to the extent necessary to provide services or handle enquiries,
- ensuring the security of the website and preventing abuse.
- The website obtains information about users and their activity in the following ways:
- through data voluntarily entered in forms, which is transferred to the Controller’s systems,
- by storing cookie files ("cookies") on end devices.
- The website may record information about connection parameters (timestamp, IP address), which serves to ensure the security and proper functioning of the website.
- In some cases, the website may record technical information that makes it easier to link the data entered in a form with the user’s e-mail address or phone number. In such situations, the e-mail address or phone number may appear in the URL of the page containing the form. This mechanism is used solely for the correct handling of the form.
2. Selected data protection methods used by the Operator
- The Controller applies technical and organisational measures ensuring a level of security appropriate to the risk, in accordance with Article 32 GDPR.
- Login areas and forms in which personal data is entered are protected by encryption of data transmission (SSL certificate). As a result, data sent from the user’s device is encrypted and can only be read by the target server.
- The Operator applies a policy of regularly changing passwords to administrative accounts and restricts access to data exclusively to authorised persons.
- An important element of data protection is the regular updating of the software used by the Operator, including server systems and application components, which ensures that vulnerabilities are removed on an ongoing basis and a high level of security is maintained.
3. Hosting
- The website is hosted (technically maintained) on the servers of the hosting provider LH.pl, whose services are used by the Operator.
- The hosting provider processes data solely on the basis of a data processing agreement.
4. Your rights and additional information on how data is used
- Your personal data may be processed for the following purposes and on the following legal bases:
- direct marketing — Article 6(1)(f) GDPR (legitimate interest of the Controller); in the case of sending marketing content electronically — Article 6(1)(a) GDPR (consent),
- providing free advisory services — Article 6(1)(a) GDPR (consent) and Article 6(1)(f) GDPR (legitimate interest of the Controller consisting in providing information and handling enquiries),
- presenting cooperation offers — Article 6(1)(a) GDPR (consent) and Article 6(1)(f) GDPR (legitimate interest of the Controller),
- issuing invoices and settlements — Article 6(1)(c) GDPR (legal obligation),
- handling complaints and reports — Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (legitimate interest of the Controller),
- contacting the user — Article 6(1)(f) GDPR,
- transferring data to business partners — Article 6(1)(a) GDPR,
- archiving and pursuing claims or defending against claims — Article 6(1)(f) GDPR,
- performance of a contract, including the provision of services to Users of the website — Article 6(1)(b) GDPR,
- pursuing the legitimate interest of the Controller, which consists in promoting the services of HI Sp. z o.o., enabling communication, integrating content, analysing website traffic and producing measurements and statistics — Article 6(1)(f) GDPR.
- If processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of the processing carried out before its withdrawal.
- The Controller may share your personal data only when:
- it is necessary for the performance of a contract or the handling of your request,
- it results from legal obligations incumbent on the Controller,
- you have consented to being contacted by a business partner of the Controller.
Data may be transferred only to the following categories of recipients:
- authorised employees and associates of the Controller,
- companies providing IT and hosting services,
- entities providing marketing services to the Controller,
- law firms and entities providing legal services,
- business partners cooperating with the Controller in handling reports and forms,
- state authorities and other entities authorised under the law.
In each case, data is shared only to the extent necessary to achieve the purpose.
- Data is stored for a period:
- necessary to achieve the purpose for which it was collected,
- resulting from legal provisions (e.g. 5 years for accounting documents),
- of up to 3 years from the last activity in the case of marketing activities.
Data processed on the basis of consent — until the consent is withdrawn.
- You have the right to request from the Controller: access to your data, rectification, erasure, restriction of processing, data portability, withdrawal of consent (if it was the basis for processing) and to object to the processing.
The Controller may refuse to fulfil a request if:
- legal provisions require further processing of the data,
- the data is necessary to establish, pursue or defend claims,
- other overriding legal grounds exist.
- The Controller processes debtors’ data only to the extent necessary to carry out the commissioned amicable debt collection activities. Legal bases:
- the legitimate interest of the Client — Article 6(1)(f) GDPR,
- the legitimate interest of the Controller consisting in carrying out the commissioned activities and protecting against claims — Article 6(1)(f) GDPR.
- A complaint against the Controller’s actions may be lodged with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
- Providing personal data is voluntary but necessary to use the website and to establish contact.
- Decisions concerning you may be made in an automated manner, including profiling, for the purpose of providing services under the concluded contract and conducting direct marketing.
- Data may be transferred outside the European Economic Area in connection with the use of IT service providers. The transfer takes place on the basis of:
- standard contractual clauses (SCC),
- adequacy decisions,
- certification under the Data Privacy Framework (DPF) — where applicable.
- The Controller does not obtain debtors’ data from sources other than publicly available data, in particular from public registers such as CEIDG or KRS, unless the data was provided by the Client in connection with commissioning debt collection activities.
5. Information in forms
- The website collects information provided voluntarily by the user, including personal data, if it is submitted via forms or during contact with the Controller.
- The scope of processed data may include: first and last name, address details, contact details, information concerning the request, information on the amount of the receivable, debtor data and other information voluntarily provided to the Controller in connection with handling an enquiry or providing services.
- Data provided in a form is processed in accordance with the function of that form, in particular for the purpose of handling a request, commercial contact, service registration, direct marketing or transferring data to business partners. In each case, the context and description of the form clearly indicate its purpose.
- Business partners process personal data on the basis of legitimate interest, consisting in seeking to establish a relationship with you or with the entity you represent within the scope of its business activity.
- Contact details of business partners are available here: Entities.
- Providing personal data is voluntary but necessary to present an offer.
6. Controller’s logs
Information about user activity on the website may be recorded in system logs. This data includes, among other things, timestamps, IP addresses, browser information and events related to the use of the website. Logs are used solely for the purpose of administering the website, ensuring its security and its proper functioning.
7. Significant marketing techniques
The Operator uses the Facebook Pixel tool. This technology allows Facebook (Meta Platforms Ireland Ltd. and Meta Platforms Inc. in the USA) to record the fact that a user registered on Facebook has visited the website. Facebook processes this information as a separate controller, based on the data it holds about its users. The Operator does not provide Facebook with any additional personal data beyond the information resulting from the operation of the pixel. The tool relies on the use of cookies stored on the user’s end device.
8. Information about cookies
- The website uses cookies.
- Cookies are IT data, in particular text files, stored on the user’s end device and used while browsing the website. Cookies usually contain the name of the domain they come from, their storage time and a unique identifier.
- The entity placing cookies on the user’s end device and accessing them is the Operator of the website.
- Cookies are used for the following purposes:
- maintaining the user’s session on the website (after logging in), so that the user does not have to re-enter their login and password on every subpage,
- pursuing the purposes described in the section "Significant marketing techniques", including the operation of analytical and marketing tools.
- The website uses two types of cookies:
- session cookies — temporary files stored until the user logs out, leaves the website or closes the browser,
- persistent cookies — stored on the end device for the time specified in the cookie parameters or until deleted by the user.
- Web browsing software (the browser) usually allows cookies to be stored by default. The user may change the browser settings, including deleting cookies or blocking their automatic storage. Detailed information can be found in the browser documentation.
- Restricting the use of cookies may affect some functionalities of the website.
- Cookies may also be used by entities cooperating with the Operator, in particular by:
- Google (Google LLC, USA),
- Meta/Facebook (Meta Platforms Inc., USA),
- Twitter/X (X Corp., USA).
- These entities may act as separate data controllers with regard to the data collected using their tools.
9. Managing cookies — how to give and withdraw consent in practice?
- If the user does not wish to receive cookies, they may change the browser settings. Please note that disabling cookies necessary for authentication, security and maintaining user preferences may make it difficult, and in extreme cases impossible, to use websites.
- To manage cookie settings, select the web browser you use from the list below and follow the instructions:
Mobile devices:
10. Changes to the privacy policy
- The Controller reserves the right to update this Privacy Policy.
- The current version of the policy is available on the website.
Business partners
Below is the current list of business partners to whom — with your consent — the data provided in the form may be transferred, for contact purposes in a situation where we are unable to help you with your request. The list is updated on an ongoing basis.
CASHFIX Sp. z o.o.
- NIP (tax ID): 7831794383
- REGON: 382035212
- KRS: 0000762428
- Address: ul. Pułaskiego 11, 63-400 Ostrów Wielkopolski, woj. wielkopolskie
- Effective from: 15.05.2026