Personal data protection

Purpose of the Document

This page presents the principles applied by HAIAP Sp. z o.o. regarding the protection of personal data in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and other applicable law, including Polish national legislation.

Data Controller

The data controller is HAIAP Sp. z o.o., headquartered in Nosówko, NIP: 6722084759, e-mail: info@systems4you.com, phone: +48 94 717 38 49.

Basic Data Protection Principles

  • Data is processed lawfully, fairly, and transparently for the individuals concerned.
  • Data is collected only for specific, explicit, and legitimate purposes.
  • The scope of processed data is limited to what is necessary to achieve the intended purposes.
  • Data is accurate and updated when necessary.
  • Data is stored only for the period necessary to fulfill the purposes or legal obligations.
  • Data is secured against unauthorized access, loss, or destruction.

Rights of Data Subjects

Individuals whose data is processed by HAIAP Sp. z o.o. have the right to:

  • access their personal data,
  • rectify inaccurate data,
  • erase data (“right to be forgotten”),
  • restrict processing,
  • transfer data to another controller,
  • object to data processing,
  • file a complaint with the President of the Personal Data Protection Office (PUODO) in Poland.

Security Measures

To protect data, we implement appropriate technical and organizational measures, including:

  • data transmission encryption (SSL),
  • access control and authentication systems,
  • regular backup creation,
  • monitoring of IT systems,
  • employee training on personal data protection.

Data Sharing

Data may be shared with cooperating entities (e.g., IT service providers, accounting, payment, logistics) only based on data processing agreements ensuring compliance with GDPR.

Data Transfer Outside the EEA

As a rule, we do not transfer personal data outside the European Economic Area. In cases where service providers may process data outside the EEA, appropriate legal safeguards are applied (e.g., standard contractual clauses).

Data Breaches

In the event of a personal data breach, procedures are implemented to mitigate the impact, and the competent supervisory authority (PUODO) and affected individuals are notified if required by law.

Updating the Policy

The personal data protection policy is regularly reviewed and may be updated to comply with changes in legislation or technology. The current version of the document is published on aquabara.com.

Contact

Any questions regarding personal data protection can be addressed via e-mail: info@systems4you.com or by phone: +48 94 717 38 49.