BLUENATIONWORK.COM WEB APPLICATION
PRIVACY POLICY
TABLE OF CONTENTS:
1. GENERAL PROVISIONS
2. GROUNDS FOR DATA PROCESSING
3. PURPOSE, LEGAL BASIS AND PERIOD OF DATA PROCESSING IN THE WEB APPLICATION
4. DATA RECIPIENTS IN THE WEB APPLICATION
5. PROFILING IN THE WEB APPLICATION
6. RIGHTS OF THE DATA SUBJECT
7. COOKIES IN THE WEB APPLICATION AND ANALYTICS
8. FINAL PROVISIONS
1) GENERAL PROVISIONS
1. This Web Application Privacy Policy is for information purposes, which means that it does not create
obligations for Service Recipients of the Web Application. In particular, the Privacy Policy sets out the
principles governing the processing of personal data by the Controller in the Web Application, including
the legal grounds, purposes and periods of personal data processing, the rights of data subjects, and
information concerning the use of Cookies and analytical tools in the Web Application.
2. The controller of personal data collected through the Web Application is EAST WAVE CULTURE SPÓŁKA Z
OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office in Gliwice (registered-office and
correspondence address: ul. Piwna 8A, 44-100 Gliwice), entered in the Register of Entrepreneurs of the
National Court Register under KRS number 0000975732; registration court keeping the company records:
District Court in Gliwice, 10th Commercial Division of the National Court Register; share capital: PLN
40,000.00; Tax Identification Number (NIP): 6312705386; National Business Registry Number (REGON):
522233438; email address: info@bluenation.pl; telephone number: +48 32 307 07 40 hereinafter
referred to as the “Controller, and at the same time acting as the Service Provider of the Web Application.
3. Personal data in the Web Application is processed by the Controller in accordance with applicable law, in
particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the
protection of natural persons with regard to the processing of personal data and on the free movement of
such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to
as the “GDPR” or the “GDPR Regulation”. The official text of the GDPR Regulation is available at:
http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679.http://eur-lex.europa.eu/legal
-content/PL/TXT/?uri=CELEX%3A32016R0679
4. Use of the Web Application, including making purchases, is voluntary. Likewise, the provision of personal
data by a Service Recipient using the Web Application is voluntary, subject to two exceptions: (1)
conclusion and performance of a contract where a Service Recipient wishes to use Electronic Services
provided by the Controller, failure to provide, in the cases and to the extent indicated in the Web
Strona 1 z 9
Application, the Terms and Conditions and this Privacy Policy, personal data necessary to conclude a
contract for the use of an Electronic Service (e.g. data required to register an Account or purchase a paid
service) will prevent the Service Recipient from using that service. In such a case, providing personal data
is a contractual requirement and, where the data subject wishes to conclude a contract for the use of an
Electronic Service provided by the Controller, they are required to provide the requested data; (2)
statutory obligations where a Service Recipient concludes a paid contract with the Controller, providing
personal data may be a statutory requirement resulting from generally applicable laws imposing on the
Controller an obligation to process personal data for accounting purposes.
5. The Controller exercises particular care to protect the interests of persons whose personal data it
processes and, in particular, is responsible for and ensures that the data it collects is: (1) processed
lawfully; (2) collected for specified, lawful purposes and not further processed in a manner incompatible
with those purposes; (3) accurate and adequate in relation to the purposes for which it is processed; (4)
kept in a form permitting identification of data subjects for no longer than is necessary for the purposes of
the processing; and (5) processed in a manner ensuring appropriate security of personal data, including
protection against unauthorised or unlawful processing and against accidental loss, destruction or
damage, using appropriate technical or organisational measures.
6. Taking into account the nature, scope, context and purposes of processing, as well as the risk of
infringement of the rights or freedoms of natural persons of varying likelihood and severity, the Controller
implements appropriate technical and organisational measures to ensure that processing is carried out in
accordance with the GDPR Regulation and to be able to demonstrate such compliance. These measures
are reviewed and updated where necessary. The Controller applies technical measures to prevent
unauthorised persons from obtaining or modifying personal data transmitted electronically.
7. All words, expressions and acronyms used in this Privacy Policy and beginning with a capital letter (e.g.
Service Provider, Web Application, Electronic Service) shall be understood in accordance with their
definitions set out in the Terms and Conditions of the Web Application available within the Web
Application.
2) GROUNDS FOR DATA PROCESSING
1. The Controller is entitled to process personal data where and to the extent that at least one of the
following conditions is met: (1) the data subject has given consent to the processing of their personal data
for one or more specified purposes; (2) processing is necessary for the performance of a contract to which
the data subject is party, or in order to take steps at the request of the data subject prior to entering into a
contract; (3) processing is necessary for compliance with a legal obligation to which the Controller is
subject; or (4) processing is necessary for the purposes of the legitimate interests pursued by the
Controller or by a third party, except where such interests are overridden by the interests or fundamental
rights and freedoms of the data subject requiring protection of personal data, in particular where the data
subject is a child.
2. Each instance of personal data processing by the Controller requires the existence of at least one of the
grounds indicated in section 2.1 of this Privacy Policy. The specific grounds for the Controllers processing
of the personal data of Service Recipients of the Web Application are indicated in the next section of the
Privacy Policy in relation to each purpose of personal data processing by the Controller.
3) PURPOSE, LEGAL BASIS AND PERIOD OF DATA PROCESSING IN THE WEB
APPLICATION
1. In each case, the purpose, legal basis, processing period and recipients of personal data processed by the
Controller result from the actions taken by the relevant Service Recipient in the Web Application.
2. The Controller may process personal data in the Web Application for the following purposes, on the
following legal grounds and for the following periods:
Strona 2 z 9
Purpose of data
processing
Legal basis for data processing
Data retention period
Conclusion and
performance of a contract
for the use of Electronic
Services or another
contract concluded with
the Controller, including
maintaining an Account
and Service Recipient
Profile and enabling the
use of related functions
and resources
Article 6(1)(b) of the GDPR Regulation
(contract) processing is necessary for
the conclusion and performance of a
contract for the use of Electronic Services
to which the data subject is party, or in
order to take steps at the request of the
data subject prior to entering into a
contract
Data is retained for the period necessary
to perform, terminate or otherwise
expire the contract concluded with the
Controller.
Making a Candidate or
Employer Profile available
to other Service Recipients
or where the relevant
privacy settings are
selected to publicly
accessible users of the
Application or the Internet
Article 6(1)(a) of the GDPR Regulation
(consent) the Service Recipient
independently selects the visibility level
of their Profile and thereby consents to
the processing of data to that extent
Data remains available while the Profile
is active. After the privacy settings are
changed or the Account is deleted,
public visibility is disabled immediately.
Processing of data within
the ratings and evaluation
system between Service
Recipients (Candidates and
Employers)
Article 6(1)(f) of the GDPR Regulation
(legitimate interest of the Controller)
processing is necessary to ensure the
reliability and transparency of the
recruitment platform and to enable
Service Recipients to make informed
decisions
Ratings and evaluations are retained
while the Account of the rated Service
Recipient remains active. After the
Account is deleted, ratings may be
retained in anonymised form for
statistical purposes, but for no longer
than 3 years.
Processing of data within
the ranking and
popularity-status system
for Service Recipients
Article 6(1)(f) of the GDPR Regulation
(legitimate interest of the Controller)
processing is necessary for the proper
functioning of the platform and to
increase its usefulness to Service
Recipients
Data used for the ranking system is
retained while the Account remains
active. The Service Recipient has the
right to object to the processing of data
for this purpose.
Generation of a CV by a
Candidate in the
Application
Article 6(1)(b) of the GDPR Regulation
(contract) processing is necessary to
provide the CV-generation service at the
Candidate’s request
Data necessary to generate a CV is
processed only during the
document-generation session and is not
stored separately by the Controller
outside the Candidate’s Profile data. The
generated CV document is available for
download only by the Candidate.
Marketing of goods and
services of the Controller
or its partners
(e.g. sending commercial
information, including
direct marketing, using
telecommunications
terminal equipment such
as email and telephone, or
automated calling systems)
Article 6(1)(f) of the GDPR Regulation
(legitimate interest of the Controller)
processing is necessary for the purposes
of legitimate interests pursued by the
Controller or by a third party (e.g. its
partners), including direct marketing,
which consists in protecting the interests
and good reputation of the Controller
and its Web Application and promoting
the provision of its services – for example
where the data subject has previously
consented (e.g. when subscribing to a
Data is retained for the duration of the
legitimate interest pursued by the
Controller, but no longer than the
limitation period for the Controllers
claims against the data subject arising
from the Controllers business activity.
Limitation periods are prescribed by law,
in particular the Civil Code (the basic
limitation period for claims related to
business activity is three years).
The Controller may not process data for
direct-marketing purposes where the
Strona 3 z 9
newsletter) to receiving commercial
information using telecommunications
terminal equipment such as email or
telephone, depending on the scope of
the consent given
data subject has effectively objected to
such processing.
Additionally, where processing is based
on consent to receiving commercial
information, including direct marketing,
using telecommunications terminal
equipment, data is retained until the
data subject withdraws consent to
further processing for that purpose,
without affecting the lawfulness of
processing based on consent before its
withdrawal.
Maintaining accounting
records
Article 6(1)(c) of the GDPR Regulation
(legal obligation) in conjunction with
Article 74(2) of the Accounting Act,
consolidated text of 30 January 2018
(Journal of Laws of 2018, item 395, as
amended) processing is necessary for
compliance with a legal obligation to
which the Controller is subject
Data is retained for the period required
by laws obliging the Controller to retain
accounting records (5 years, counted
from the beginning of the year following
the financial year to which the data
relates).
Establishment, exercise or
defence of claims that may
be brought by the
Controller or against the
Controller
Article 6(1)(f) of the GDPR Regulation
(legitimate interest of the Controller)
processing is necessary for the purposes
of legitimate interests pursued by the
Controller, consisting in the
establishment, exercise or defence of
claims that may be brought by the
Controller or against the Controller
Data is retained for the duration of the
legitimate interest pursued by the
Controller, but no longer than the
limitation period for claims that may be
brought against the Controller (the basic
limitation period for claims against the
Controller is six years).
Use of the Web
Application and ensuring
its proper operation
Article 6(1)(f) of the GDPR Regulation
(legitimate interest of the Controller)
processing is necessary for the purposes
of the legitimate interests pursued by the
Controller, consisting in operating and
maintaining the Web Application
Data is retained for the duration of the
legitimate interest pursued by the
Controller, but no longer than the
limitation period for the Controllers
claims against the data subject arising
from the Controllers business activity.
Limitation periods are prescribed by law,
in particular the Civil Code (the basic
limitation period for claims related to
business activity is three years).
Compilation of statistics
and analysis of traffic in
the Web Application
Article 6(1)(f) of the GDPR Regulation
(legitimate interest of the Controller)
processing is necessary for the purposes
of the legitimate interests pursued by the
Controller, consisting in compiling
statistics and analysing traffic in the Web
Application in order to improve the
operation of the Web Application and
increase the reach of the Electronic
Services provided
Data is retained for the duration of the
legitimate interest pursued by the
Controller, but no longer than the
limitation period for the Controllers
claims against the data subject arising
from the Controllers business activity.
Limitation periods are prescribed by law,
in particular the Civil Code (the basic
limitation period for claims related to
business activity is three years).
4) DATA RECIPIENTS IN THE WEB APPLICATION
1. For the proper functioning of the Web Application, including the proper provision of Electronic Services by
the Controller, it is necessary for the Controller to use the services of external entities (such as a software
Strona 4 z 9
provider or payment service provider). The Controller uses only processors that provide sufficient
guarantees of implementing appropriate technical and organisational measures so that processing meets
the requirements of the GDPR Regulation and protects the rights of data subjects.
2. Personal data may be transferred by the Controller to a third country. In such a case, the Controller
ensures that the transfer will be made to a country providing an adequate level of protection in
accordance with the GDPR Regulation, or, in the case of other countries, on the basis of standard data
protection clauses. The Controller ensures that the data subject may obtain a copy of their data. The
Controller transfers collected personal data only where and to the extent necessary to achieve a specific
processing purpose consistent with this Privacy Policy.
3. The Controller does not transfer data in every case or to all recipients or categories of recipients indicated
in this Privacy Policy. The Controller transfers data only where this is necessary to achieve a specific
purpose of personal data processing and only to the extent necessary to achieve that purpose.
4. Personal data of Service Recipients of the Web Application may be transferred to the following recipients
or categories of recipients:
a. entities handling electronic or card payments where a Service Recipient purchases paid
Electronic Services in the Web Application and uses an electronic or card payment, the Controller
discloses the collected personal data of the Service Recipient to the selected entity handling such
payments in the Application on behalf of the Controller, to the extent necessary to process the
payment made by the Service Recipient.
b. service providers supplying the Controller with technical, IT and organisational solutions enabling
the Controller to conduct its business, including operating the Web Application and providing
Electronic Services through it (in particular, providers of computer software used to operate the
Web Application, email and hosting providers, and providers of business-management software
and technical support for the Controller) – the Controller discloses the collected personal data of
the Service Recipient to the selected provider acting on its behalf only where and to the extent
necessary to achieve a specific processing purpose consistent with this Privacy Policy.
c. providers of accounting, legal and advisory services supporting the Controller in accounting, legal
or advisory matters (in particular an accounting office, law firm or debt collection company) – the
Controller discloses the collected personal data of the Service Recipient to the selected provider
acting on its behalf only where and to the extent necessary to achieve a specific processing
purpose consistent with this Privacy Policy.
d. other Service Recipients of the Application to the extent resulting from the Profile visibility
level selected by the Service Recipient (privacy settings) or from the functionality of the
Application, in particular the ratings and evaluation system, ranking system, private messages
and chat. In such a case, the Service Recipient (Employer or Candidate) becomes a controller,
independent of the Controller, of the personal data obtained from other Service Recipients and is
required to comply independently with the resulting legal obligations;
e. third parties without an Account in the Application – only where a Service Recipient (Candidate)
has selected a public visibility level for their Profile, or an Employer has shared a link to the
Candidate’s Profile with third parties and the Candidate has selected a setting allowing access to
the Profile without logging in. The scope of the data disclosed is limited to content entered by the
Candidate in their Profile;
f. public authorities and law-enforcement authorities data may be disclosed only in cases
provided for by generally applicable law or on the basis of decisions of competent authorities for
the purposes of proceedings conducted by them.
5) PROFILING IN THE WEB APPLICATION
1. The GDPR Regulation requires the Controller to provide information about automated decision-making,
including profiling referred to in Article 22(1) and (4) of the GDPR Regulation, and – at least in those cases
meaningful information about the logic involved, as well as the significance and envisaged consequences
of such processing for the data subject. With this in mind, the Controller provides information on possible
profiling in this section of the Privacy Policy.
Strona 5 z 9
2. The Controller may use profiling in the Web Application for direct-marketing purposes, but decisions taken
by the Controller on the basis of such profiling do not concern the conclusion or refusal to conclude a
contract with the Controller or the ability to use Electronic Services in the Web Application. Profiling in the
Web Application may result, for example, in a reminder about unfinished activities in the Application, the
sending of a discount or an offer for a service that may correspond to the interests or preferences of a
particular person, or the proposal of better terms than those in the standard Web Application offer.
Despite profiling, the person concerned freely decides whether they wish to use, for example, an offer or
discount received in this way from the Controller.
3. Profiling in the Web Application consists of the automated analysis or prediction of a person’s behaviour in
the Web Application, for example by analysing their previous purchase history, pages viewed or other
actions taken in the Web Application. Such profiling requires the Controller to possess the personal data of
the person concerned in order subsequently to send them, for example, an offer or discount.
4. The data subject has the right not to be subject to a decision based solely on automated processing,
including profiling, which produces legal effects concerning that person or similarly significantly affects
them.
5. The Controller also uses candidate-and-employer matching algorithms and a ranking and popularity-status
system for Service Recipients in the Application, in accordance with the rules set out in the Terms and
Conditions of the Application. These algorithms analyse data contained in a Service Recipients Profile,
their activity in the Application, ratings given to other Service Recipients and their history of using
Electronic Services. The results of the algorithms may affect the visibility of a given Service Recipient in
search results and their position in Application rankings. The matching and ranking mechanism consists of
the automated analysis of data contained in the Profile (e.g. skills, experience, location and employment
preferences) and comparison of that data with the requirements of Job Offers published by Service
Recipients – Employers. The result of this algorithm does not constitute an autonomous decision excluding
a Service Recipient from using the Application or its Electronic Services.
6) RIGHTS OF THE DATA SUBJECT
1. Right of access, rectification, restriction, erasure or portability – the data subject has the right to request
from the Controller access to their personal data, rectification or erasure (“right to be forgotten”) of
such data, or restriction of processing, and has the right to object to processing as well as the right to
data portability. Detailed conditions for exercising the above rights are set out in Articles 15–21 of the
GDPR Regulation.
2. Right to withdraw consent at any time where the Controller processes data on the basis of consent
(under Article 6(1)(a) or Article 9(2)(a) of the GDPR Regulation), the data subject has the right to
withdraw consent at any time, without affecting the lawfulness of processing based on consent before
its withdrawal.
3. Right to lodge a complaint with a supervisory authority a person whose data is processed by the
Controller has the right to lodge a complaint with a supervisory authority in the manner and according
to the procedure specified in the GDPR Regulation and Polish law, in particular the Personal Data
Protection Act. The supervisory authority in Poland is the President of the Personal Data Protection
Office.
4. Right to object the data subject has the right, on grounds relating to their particular situation, to
object at any time to the processing of personal data concerning them based on Article 6(1)(e) (public
interest or public tasks) or Article 6(1)(f) (legitimate interests of the controller), including profiling based
on those provisions. In such a case, the Controller may no longer process the personal data unless the
Controller demonstrates compelling legitimate grounds for the processing which override the interests,
rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal
claims.
5. Right to object to direct marketing where personal data is processed for direct-marketing purposes,
the data subject has the right to object at any time to the processing of personal data concerning them
for such marketing, including profiling to the extent that it is related to such direct marketing.
Strona 6 z 9
6. To exercise the rights referred to in this section of the Privacy Policy, the data subject may contact the
Controller by sending an appropriate message in writing or by email to the Controllers address indicated
at the beginning of this Privacy Policy.
7) COOKIES IN THE WEB APPLICATION AND ANALYTICS
1. Cookies are small pieces of textual information in the form of text files sent by a server and stored on the
device of a person visiting the Web Application (e.g. on the hard drive of a computer or laptop, or on a
smartphone memory card, depending on the device used by the visitor). Detailed information about
Cookies, including their history, can be found, among other places, at:
https://en.wikipedia.org/wiki/HTTP_cookie.https://pl.wikipedia.org/wiki/HTTP_cookie
6. The Controller may make available in the Web Application a tool enabling easy and active management of
Cookies. The tool is available upon the first visit to the website and, once closed, remains accessible in the
bottom corner of the website. Active management makes it possible, among other things, to check which
Cookies are or may be stored while using the website and to select and subsequently change the scope
and purposes for which Cookies are used in relation to the device and the person visiting the website.
When beginning to use the website, the visitor will be asked to select Cookie settings. These settings may
later be changed using the tool available on the website.
7. Below, the Controller provides information concerning the use of Cookies in the Web Application, their
types and purposes, and their management using, for example, browser settings and/or the
Cookie-management tool available on the Website. The Controller encourages the use of the
Cookie-management tool available on the Website, which makes it easy to actively manage Cookies while
using the Website. Where that tool is unavailable, the Controller encourages visitors to read the
information below concerning, among other things, the management of Cookies through browser settings.
8. Cookies that may be sent by the Web Application can be divided into different types according to the
following criteria:
By provider:
1) first-party Cookies (created by
the Controller’s Web
Application); and
2) third-party Cookies (belonging
to persons/entities other than
the Controller)
By retention period on the device
of the person visiting the Web
Application:
1) session Cookies (stored until
the person logs out of the Web
Application or closes the web
browser); and
2) persistent Cookies (stored for a
specified period defined by the
parameters of each Cookie or
until manually deleted)
By purpose:
1) strictly necessary Cookies
(enabling the Web Application to
function properly);
2) functional/preference Cookies
(enabling the Web Application to be
adapted to the preferences of the
website visitor);
3) analytical and performance
Cookies (collecting information on
how the Web Application is used);
4) marketing, advertising and
social-media Cookies (collecting
information about the person visiting
the Web Application in order to
display and personalise
advertisements and conduct other
marketing activities, including on
websites separate from the Web
Application, such as social-media
services or other websites belonging
to the same advertising network as
the Web Application)
9. The Controller may process data contained in Cookies while visitors use the Web Application for the
following specific purposes:
Strona 7 z 9
Cele stosowanie plików Cookies
w Aplikacji Internetowej
Administratora
identifying Service Recipients as logged in to the Web Application and
indicating that they are logged in (strictly necessary Cookies)
remembering data entered in forms or surveys, or login details for the Web
Application (strictly necessary and/or functional/preference Cookies)
adapting the content of the Web Application to the Service Recipient’s
individual preferences (e.g. colours, font size and page layout) and
optimising the use of Web Application pages (functional/preference
Cookies)
compiling anonymous statistics showing how the Web Application is used
(analytical and performance Cookies)
displaying and rendering advertisements, limiting the number of times
advertisements are displayed and ignoring advertisements a person does
not wish to see, measuring advertising effectiveness, and personalising
advertisements, i.e. analysing the characteristics of the behaviour of
persons visiting the Web Application through anonymous analysis of their
actions (e.g. repeated visits to particular pages, keywords, etc.) in order to
create a profile and provide advertisements matching their predicted
interests, including when they visit other websites in the advertising
networks of Google Ireland Ltd. or Meta Platforms Ireland Ltd. (marketing,
advertising and social-media Cookies)
10. It is possible to check which Cookies are currently being sent by the Web Application, regardless of the
browser used, by using tools available, for example, at: https://www.cookiemetrix.com/ or
https://www.cookie-checker.com/.https://www.cookiemetrix.com/https://www.cookie-checker.com/
11. By default, most web browsers available on the market accept the storage of Cookies. Every person may
define the conditions for the use of Cookies through their browser settings. This means, for example, that
it is possible to partially restrict (e.g. temporarily) or completely disable the storage of Cookies. In the
latter case, however, this may affect certain functions of the Web Application.
12. Browser settings concerning Cookies are relevant to consent to the use of Cookies by our Web Application.
Under applicable law, such consent may also be expressed through browser settings. Detailed information
on changing Cookie settings and deleting Cookies manually in the most popular web browsers is available
in the browsers help section and on the following pages (click the relevant link):
w przeglądarce Chromein the Chrome browser
w przeglądarce Firefoxin the Firefox browser
w przeglądarce Internet Explorerin the Internet Explorer browser
w przeglądarce Operain the Opera browser
w przeglądarce Safariin the Safari browser
w przeglądarce Microsoft Edgein the Microsoft Edge browser
13. The Controller may use Google Analytics and Universal Analytics services in the Web Application, provided
by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). These services help the
Controller compile statistics and analyse traffic in the Web Application. Data collected through these
services is processed to generate statistics useful for administering the Application and analysing traffic in
the Web Application. The data is aggregated. When using these services in the Web Application, the
Controller collects data such as the source and medium through which visitors reached the Web
Application, their behaviour in the Web Application, information about the devices and browsers used to
visit the website, IP address and domain, geographical and demographic data (age and gender), and
interests.
14. A person may easily prevent information about their activity in the Web Application from being shared
with Google Analytics, for example by installing the browser add-on provided by Google Ireland Ltd.,
available at:
https://tools.google.com/dlpage/gaoptout?hl=en.https://tools.google.com/dlpage/gaoptout?hl=pl
Strona 8 z 9
15. In connection with the Controllers possible use in the Web Application of advertising and analytical
services provided by Google Ireland Ltd., the Controller states that full information on the rules governing
the processing by Google Ireland Ltd. of data relating to visitors to the Web Application (including
information stored in Cookies) is available in Google’s privacy policy at:
https://policies.google.com/technologies/partner-sites.https://policies.google.com/technologies/partner-
sites
16. Where the Application is used on a mobile device running iOS or Android, the rules concerning Cookies
and activity tracking may additionally be governed by the system settings of the mobile device, including
the application privacy and permission settings. The Controller encourages Service Recipients to review
the privacy settings of the operating system of the device they use.
8) FINAL PROVISIONS
1. The Web Application may contain links to other websites. After following such links, the Controller
recommends reviewing the privacy policy applicable on the relevant website. This Privacy Policy applies
only to the Controllers Web Application.
2. This Privacy Policy may be updated by the Controller. The Controller will inform Service Recipients of each
amendment to the Privacy Policy by publishing an updated version of the Privacy Policy in the Application
and, in the case of Service Recipients holding an Account, also by sending appropriate information to the
email address assigned to the Account sufficiently in advance of the amendments taking effect.
Strona 9 z 9