Skip to content
    GDPR

    Data protection.

    At Zwyrtek Group, personal data protection is the foundation of the trust placed in us by our Clients, Employees and Partners. We act in accordance with the GDPR and national data protection legislation.

    This document provides a compendium of information on how we fulfil our obligations as a controller and on the rights available to the persons whose data we process.

    1

    Information clauses

    Transparency is essential to us. We inform data subjects about the processing of their personal data in a clear and understandable manner at the time of collection. Our information clauses differ depending on the relationship we have with you:

    • For Clients and ContractorsInformation on data processing for the performance of contracts (legal, tax, advisory), invoicing and maintaining business relationships.
    • For Job CandidatesDetails on data processing in recruitment processes carried out by the group's companies.
    • For Website UsersInformation on data collected via the zwyrtek.pl website (e.g. contact forms, cookies).
    • For Employees and ContractorsRules for processing data in the context of employment and HR & payroll administration.

    All current clauses are available for inspection at our registered office and are sent electronically when the cooperation is established.

    2

    Controller's obligations

    As Controllers of data within Zwyrtek Group, we take full responsibility for the security of the information entrusted to us. Our key obligations include:

    • Data minimisationWe process only the data necessary to achieve a specific, lawful purpose.
    • Technical securityWe apply advanced encryption, access control systems and regularly updated IT safeguards.
    • Professional confidentialityWe pay particular attention to protecting data covered by legal professional privilege and tax adviser confidentiality.
    • Risk managementWe regularly carry out risk analyses and data protection impact assessments (DPIAs) for processing operations presenting a high risk to rights and freedoms.
    • Incident responseWe have implemented breach management procedures enabling swift response and, where necessary, notification of supervisory authorities and data subjects.
    3

    Rights of data subjects

    Under the GDPR, every person whose data we process has a number of rights. We ensure their effective exercise:

    • Right of accessYou may ask what data we hold about you and receive a copy of it.
    • Right to rectificationIf your data is incorrect or out of date, we will promptly correct it.
    • Right to erasureThe “right to be forgotten” — in certain situations (e.g. when the data is no longer needed) you may request its erasure.
    • Right to restriction of processingYou may request that we suspend operations on your data in specific cases.
    • Right to data portabilityYou may receive your data in a structured, machine-readable format.
    • Right to objectYou have the right to object to processing based on our “legitimate interest” (e.g. for marketing purposes).
    • Right to withdraw consentIf processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before its withdrawal.
    4

    Exercising rights and contact

    To exercise your rights or obtain further clarification, please contact our designated contact point:

    We handle requests concerning the exercise of rights without undue delay, and in any event within one month of receipt. In particularly complex cases, this period may be extended by a further two months, of which we will inform you.

    Supervisory authority

    Every person also has the right to lodge a complaint with the supervisory authority:

    President of the Personal Data Protection Office (UODO – the Polish Personal Data Protection Office)
    ul. Stawki 2, 00-193 Warszawa, Poland.