Privacy Policy
Last updated: 3 August 2026 · Version: 2.0
1. General information
- This privacy policy sets out the rules for processing and protecting the personal data of persons using the website available at chronologis.pl (the “Website”).
- The controller of personal data is Chronologis sp. z o.o., with its registered office at Kopytów 44C, 05-870 Błonie, Poland, entered in the Register of Entrepreneurs of the National Court Register (KRS) under number 0000658807, NIP (tax ID): 1182136383, REGON: 366353893 (the “Controller”).
- The Controller can be contacted on all matters relating to personal data by e-mail at kontakt@chronologis.pl or in writing at the registered office address.
- The Controller has not appointed a data protection officer. All matters relating to the processing of personal data should be directed as set out in point 3.
- The Controller takes particular care to protect the privacy of persons using the Website and the data they provide. Data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”), the Polish Act of 10 May 2018 on the Protection of Personal Data, and the Polish Act of 12 July 2024 – Electronic Communications Law (Prawo komunikacji elektronicznej, the “PKE”).
2. Scope of data collected
The Website does not sell products or services through the site and does not process payment data. Personal data may be collected in the following situations:
- newsletter subscription – e-mail address, as well as data relating to engagement with the messages (e.g. information about whether a message was opened and whether links within it were clicked – see point 4);
- contact via the contact form or e-mail – name, e-mail address, and possibly other data provided voluntarily in the content of the message;
- data collected automatically while using the Website – e.g. IP address, device and browser information, information stored and read in cookies (see point 5).
Providing data is voluntary; however, failure to provide the data marked as required makes it impossible to, respectively, subscribe to the newsletter or receive a reply to a submitted enquiry.
3. Purposes and legal bases of processing
| Purpose of processing | Legal basis |
|---|---|
| Replying to enquiries sent via the contact form or e-mail and conducting further correspondence | Art. 6(1)(f) GDPR – the Controller’s legitimate interest in handling correspondence addressed to it |
| Sending the newsletter (processing of the e-mail address and engagement data) | Art. 6(1)(a) GDPR – consent; with respect to using e-mail to send commercial information – Art. 398 PKE |
| Ensuring the proper and secure operation of the Website (strictly necessary cookies, server logs) | Art. 6(1)(f) GDPR – legitimate interest; Art. 173 PKE |
| Analytical or marketing purposes carried out by means of cookies other than strictly necessary ones, where used | Art. 6(1)(a) GDPR – consent; Art. 173 PKE |
| Establishing, pursuing or defending against claims, including demonstrating that consents were given (accountability) | Art. 6(1)(f) GDPR – the Controller’s legitimate interest |
4. Newsletter
- An interested person may subscribe to the newsletter by providing their e-mail address and consenting to receive commercial and industry information related to the Controller’s activity by electronic means.
- Subscribing to the newsletter requires two related consents: consent to the processing of personal data for the purpose of sending the newsletter (Art. 6(1)(a) GDPR) and consent to sending commercial information by e-mail (Art. 398 PKE). Both consents are voluntary but necessary to provide the newsletter service.
- To operate the newsletter, the Controller uses the Mailchimp tool provided by The Rocket Science Group LLC (a company within the Intuit group) based in the United States, acting as a processor under a data processing agreement. As part of the service, data on interaction with messages may be collected, in particular information about whether a message was opened and whether links within it were clicked. This data is used solely to assess the effectiveness of the newsletter and to tailor its content; no decisions producing legal effects concerning the recipient or similarly significantly affecting them are made on this basis (see point 6 on transfers outside the EEA).
- Consent to receive the newsletter may be withdrawn at any time, without giving a reason, by clicking the unsubscribe link included in every message or by contacting the Controller. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
- Data processed for the newsletter is stored until consent is withdrawn. After withdrawal, the Controller may retain basic information confirming the fact and scope of the consent given, for the period of limitation of potential claims, solely for the purpose of demonstrating compliance (accountability).
5. Cookies
- The Website uses cookies, i.e. small text files stored on the user’s end device, and similar technologies.
- Strictly necessary cookies serve to ensure the proper and secure operation of the Website. Their use does not require the user’s consent (Art. 173 PKE).
- Cookies other than strictly necessary (e.g. statistical or marketing), where used, are used only after the user has given prior consent via the mechanism (banner) available on the Website. Consent is voluntary, and giving and withdrawing it are equally straightforward.
- The user may at any time change or withdraw consent regarding cookies via the settings on the Website, and may also manage cookies through their web browser settings.
- Limiting the use of cookies may affect certain functionalities of the Website.
6. Data recipients and transfers outside the EEA
- Personal data may be entrusted for processing to entities that support the Controller in operating the Website and handling the purposes set out above, in particular: hosting providers, IT service providers, and the provider of the newsletter tool (Mailchimp). These entities process data solely on the Controller’s documented instructions, under data processing agreements compliant with Art. 28 GDPR.
- In connection with the use of Mailchimp, personal data (including the e-mail address and engagement data) is transferred to the United States. The transfer is based on the provider’s certification under the EU-U.S. Data Privacy Framework and, as an additional safeguard, on Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR), which form part of the data processing agreement. On request, the Controller will make available information about the safeguards applied.
- Apart from the case described in paragraph 2, data is not transferred to countries outside the European Economic Area, unless appropriate safeguards compliant with the GDPR are ensured.
7. Data retention period
Personal data is stored for the period necessary to achieve the purpose for which it was collected:
- newsletter – until consent is withdrawn; data confirming that consent was given – for the period of limitation of potential claims;
- correspondence – for the time necessary to handle the enquiry and conduct further correspondence, and thereafter for the period of limitation of potential claims;
- data stored in cookies – for the period appropriate to the given cookie, no longer than until consent is withdrawn (for cookies requiring consent) or the cookies are deleted by the user;
- server logs – for the period necessary to ensure the security and proper operation of the Website.
8. Rights of the data subject
The data subject has the right to:
- access their data and obtain a copy of it,
- rectify their data,
- erase their data,
- restrict processing,
- data portability – with respect to data processed on the basis of consent or a contract, by automated means,
- object to processing based on the Controller’s legitimate interest (Art. 6(1)(f) GDPR), on grounds relating to their particular situation,
- withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal,
- lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland) if they consider that the processing infringes the law.
To exercise the above rights, please contact the Controller as set out in point 1.
9. Automated decision-making and profiling
The Controller does not make decisions concerning data subjects based solely on automated processing, including profiling, that would produce legal effects concerning them or similarly significantly affect them. The analysis of newsletter engagement referred to in point 4 serves solely to assess the effectiveness of communication and to tailor its content.
10. Data security
The Controller applies appropriate technical and organisational measures to protect the personal data processed, proportionate to the risks and to the categories of data protected.
11. Changes to the privacy policy
The Controller reserves the right to make changes to this privacy policy. The current version of the document, together with the date from which it applies, is published on the Website.
12. Final provisions
In matters not governed by this policy, the provisions of the GDPR, the Act on the Protection of Personal Data, the Electronic Communications Law, and other applicable provisions of Polish law shall apply.