PRIVACY POLICY
| Document number | PR-02 |
|---|---|
| Document ID | OID: [1.2.616.1.113813.1.5.2.1.5] |
| Document classification | public |
| Document owner | Autenti S.A. („Autenti”) ul. Święty Marcin 29/8, 61-806 Poznań KRS nr 0001254852, NIP: 7831693251, REGON: 302246285 |
| Version | ver. 1.5 |
The protection of personal data and privacy is a priority for Autenti. This Privacy Policy ("Privacy Policy") explains how Autenti collects, shares, stores, or otherwise processes the Personal Data of Users who access or use our websites and services, including the mobile application and other applications or services that link to this Privacy Policy. Furthermore, the Privacy Policy specifies how data subjects may exercise their privacy rights. By using our Services, the User acknowledges that Autenti will collect and use their personal data as described in this Privacy Policy.
In certain cases, we may process the User's Personal Data pursuant to an agreement concluded with an external organization. In such instances, the terms of that agreement may govern the manner in which the User's Personal Data is processed. If you believe that an external organization has requested us to process your personal data on its behalf, please contact that organization first, as it shall be responsible for the manner in which your data is processed. This Privacy Policy does not apply to third-party websites and applications that you may use, including those linked within our Services. Before clicking any link, you should review the terms and conditions and policies of such third-party websites and applications.
If you have any questions or doubts regarding our use of Personal Data, please contact us using the contact details provided in section X.
I. Definitions
- Individual terms used in the Policy bear the meaning assigned to them in section I.2 below or in the Autenti Platform Terms & Conditions.
- The terms used in the Policy shall mean:
- Administrator - Autenti S.A. with its registered office in Poznań at ul. Św. Marcin 29/8, 61-806 Poznań, entered into the register of entrepreneurs kept by the District Court for Poznań Nowe Miasto i Wilda in Poznań VIII Commercial Division of the National Court Register under the following number KRS 0001254852, NIP [Tax ID no] 783-169-32-51;
- GDPR - Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of Personal Data and on the free movement of such data and on repealing the Directive 95/46/EC;
- Personal Data - information about a natural person identified or identifiable by one or more specific factors, including, in particular, name, surname, email address, telephone number, device IP number, location data, online identifier and information collected through cookies and other similar technology;
- Service Regulations - separate regulations or policies defining the terms and conditions for the provision of Services by the Administrator, accepted by the Client at the time of placing an order, available at https://autenti.com/en/terms-and-conditions;
- Services - services provided by the Administrator by electronic means pursuant to the applicable Service Regulations, the website, mobile application and other applications or services that link to this Privacy Policy;
- User - any natural person who uses the Administrator's Services;
- Client - a natural person acting on his or her own behalf or on behalf of a legal person or an organizational unit without legal personality who has entered into agreements with the Administrator for the provision of Services;
- Account - a set of data related to a given Client, including information provided by the Client during registration for the Services, as well as information on the activity of the Client and Users added to this Account within the Autenti Platform. The Account enables ordering or full use of the services provided within the Autenti Platform, assigned to a given Account;
- Autenti Platform - IT systems and applications developed, managed and maintained by the Administrator, through which the Administrator provides electronic services and/or trust services, available within the website provided at https://autenti.com/ or another URL in the Administrator's domain;
- Business Partner - an entity with which the Administrator cooperates in the scope of providing, promoting, or selling the Services.
II. Legal bases and purposes of personal data processing
The Administrator processes Personal Data for the following purposes:
| Purpose of processing Personal Data | Legal basis |
|---|---|
| 1. Provision of Services and performance of the agreement for the provision of services by electronic means or performing activities prior to its conclusion, in particular: creation and maintenance of the Account; processing of payments and purchases or orders; provision of Services in accordance with the relevant Service Regulations; handling of notifications (inter alia via email, contact form, telephone); performing other activities related to the performance of Services, including business contact. | art. 6(1)(b) of the GDPR |
| 2. Handling of complaints, including solving technical problems. | art. 6(1)(b) of the GDPR |
| 3. Informing Clients about changes and new functionalities of the Service they have purchased. | art. 6(1)(f) of the GDPR |
| 4. Fulfillment of obligations resulting from tax and accounting regulations. | art. 6(1)(c) of the GDPR |
| 5. Conducting statistical and analytical research, including in particular the analysis of the effectiveness of advertising campaigns (concerning data that do not allow for the identification of the User), assigning conversions, improving and developing the functionalities of Services, increasing the quality of the Services provided and conducting User satisfaction surveys. | art. 6(1)(f) of the GDPR |
| 6. Establishing and pursuing or securing claims or defending against them. | Art. 6(1)(f) of the GDPR |
| 7. Performance of marketing activities by the Administrator, including in particular: provision of the newsletter delivery Service in accordance with the Newsletter Regulations; sending commercial information by electronic means; marketing of own products or Services through Business Partners; performance of marketing campaigns in cooperation with Business Partners. | art. 6(1)(a) of the GDPR |
III. Privacy protection principle and general provisions
- The User has a choice whether to visit our websites, install our applications or provide us with their Personal Data. However, if the User does not provide certain Personal Data, the Services or some of their functionalities may not be made available by the Administrator.
- The Administrator attaches great importance to the protection of the privacy and confidentiality of Personal Data obtained in connection with the conducted activity, including the provided Services.
- Personal data is processed by the Administrator in accordance with the provisions on the protection of personal data, including, in particular, the GDPR.
- Detailed information regarding the processing of Personal Data by the Administrator with respect to specific categories of persons, including the purposes, legal bases and the rights of data subjects is also described in information clauses pursuant to art. 13 and art. 14 of the GDPR. The current content of the information clauses is available in the repository on our website.
- The Administrator selects and applies appropriate technical and organizational measures with due diligence to ensure adequate protection of the Personal Data processed. Access to Personal Data is granted exclusively to persons authorized by the Administrator who have committed to keep them confidential.
- The Administrator exclusively uses the services of such subcontractors who guarantee an adequate level of security of Personal Data.
- Personal Data is protected by the Administrator against disclosure to unauthorized persons, as well as other cases of disclosure or loss and against destruction or unauthorized modification, through the use of appropriate organizational security as well as technical and programming security, in particular data encryption or anonymization systems. Passwords are encrypted in such a way that they cannot be read by the Administrator or persons acting on his behalf.
- During the provision of the Service, the Administrator exercises due diligence to ensure that the data transmission to and from the Administrator takes place in a secure manner, for example, through the use of a secure SSL protocol; however, the Administrator is not responsible for that part of the data transmission that takes place within email systems and network services independent of the Administrator.
- The Administrator may process personal data in an automated manner, including in the form of profiling; however, automated processing will not lead to making decisions with legal effects or similarly affect Users in a significant way. Profiling may be used to create marketing profiles of Users to tailor advertisements and marketing content, in accordance with the provisions set out in section III of this Policy.
- If the User uses Services requiring identity verification and/or confirmation of the right to represent the entity they represent (e.g., eID services, Account confirmation), Personal Data may be processed in an automated manner, including the assessment and analysis of data compliance with identity documents or other data, including authentication data. A positive result of the identity verification and/or the right of representation may affect the ability to provide certain Services (e.g., electronic delivery service or electronic signature). Details of processing in this regard are described in dedicated information clauses concerning a given Service.
IV. Sources of personal data and rules for their collection
- The Personal Data of Users and Clients may be obtained by the Administrator:
- directly from the User, within the scope of:
- completing a contact form,
- direct contact via chat, electronic means or telephone,
- completing a purchase form,
- registering an Account on the Autenti Platform or updating Personal Data assigned to the Account,
- using trust services such as an electronic signature, registered electronic delivery, identity verification service or validation of electronic signatures and seals,
- identification for the purposes of Account confirmation and the right of representation,
- subscribing to a newsletter service or expressing consent to receive commercial and marketing content,
- commenting on our blog, profiles and entries in social media or on public forums,
- within other activities, e.g., voluntary surveys or participation in events (e.g., webinars).
- independently or from third parties, including from Users and Clients in connection with the performance of Services, including for the purpose of:
- conducting communication,
- recommendation processes,
- performing obligations related to the confirmation of identity or the right of representation (e.g., in public registers),
- conclusion or performance of agreements,
- adding a User to an Account or sharing specific content (e.g., granting authorizations for an e-Delivery),
- performing the dispatch of a document for signature or electronic delivery.
- directly from the User, within the scope of:
- In the case of Personal Data obtained directly from the User, providing them is voluntary; however, it may result in the failure to perform certain Services.
- In the case of registration or logging into an Account using access data to external or social media services (e.g., Google), the Administrator processes data transferred in connection with such logging in the scope shared by the given service, treating them as data provided by the User during Account registration.
- In the case of providing the Administrator with the Personal Data of third parties, the Client or User transferring the Personal Data declares that they are entitled to do so, in particular, they possess an appropriate legal basis for their processing and that they have fulfilled the information obligation towards such person, provided they are obliged to do so.
- The Administrator may obtain Personal Data in connection with the User's use of a chatbot based on artificial intelligence technology available on the Administrator's website. Within this function, Personal Data and other information that the User enters or shares during a conversation with the chatbot are collected, such as content entered in the chat field, submitted queries, responses, session parameters and other contextual information necessary to ensure the proper functioning of the chatbot. The collection of this data is performed for the purpose of the proper functioning of the chatbot, providing answers, analyzing queries and providing and improving the service.
- The Administrator may also obtain Personal Data from external sources. Examples of external sources include marketers or marketing companies, business partners, including sellers of Services (resellers), research companies, affiliates (companies under common ownership or control of the Administrator), service providers and other entities that are entitled to share Personal Data with us. For example, if a User registers for our Services or expresses a desire to purchase the Administrator's Services on another website, that site may transfer Personal Data to us.
- The Administrator may obtain Personal Data also as a result of the User's use of technological integrations with other applications or third-party services that may gain access to Personal Data or send information to and from an Account on the Autenti Platform. It is the User's responsibility to verify any third-party integrations they agree to. Certain third-party integration features may use, transfer, and/or store the data or information of the Client or User outside of the Administrator's Services and the Administrator bears no responsibility for such use, transfer or storage. Please carefully review the permissions granted to third-party integrations. The Administrator may collect information about the types of integrations that a User or Client uses in their Account.
- If Personal Data of third parties are made available to the Administrator in connection with their transfer, the Administrator becomes the controller of such data and - in cases provided for by law - fulfills the secondary information obligation pursuant to art. 14 of the GDPR.
- The Administrator may also obtain Personal Data from other external sources, in particular:
- from publicly available databases or public registers;
- from social media platforms.
- The rules for using cookies and similar technologies are set out in the Cookie Policy.
V. Types of Personal Data
- While using the Services, the Administrator may process the following types of Personal Data:
- Contact details and identifiers: name or names, surname, email address, telephone number, NIP [Tax ID No.], identity document number, date of birth, individual identification number (e.g., PESEL), electronic delivery address;
- Other Personal Data: citizenship, position, place of employment, image, identity document issuing authority, identity document expiry date;
- Billing and commercial data: data concerning billing and payments, including credit card number, bank account details and information about purchased Services;
- Other information: questions and information related thereto, as well as data or opinions that the User addresses to Autenti directly via chat, online forms, email, telephone or through our feedback surveys or customer service channels. Autenti may collect Personal Data that the User voluntarily provides during interactions, such as name and surname, email address, contact details or other information they choose to share. Autenti may also retain chat transcripts or call recordings for the purposes specified in this Privacy Policy.
- While using the Services through third-party applications or services with which Autenti has integrations, the Administrator may process, in particular, data such as name, surname, email address, telephone number and a unique identifier assigned to a given application.
- In connection with the use of the Services, the Administrator may also automatically obtain and process technical data, including:
- IP addresses, unique identifiers of end devices, such as browser type and operating system;
- Web log data, referring and exit pages and URLs, number of clicks, domain names, landing pages, pages and content viewed and the order of those pages, time spent on individual pages, dates and times of using our Services, frequency of using our Services, error logs and other related information;
- Authentication methods of transaction parties, message subject, history of actions taken by natural persons in connection with the transaction (e.g., viewing, signing, enabling functionalities) and information about the devices of those parties;
- User interests resulting from the use of our Services, preferences regarding the receipt of marketing materials from us, communication preferences and preferences regarding individual products and services.
- Some information we collect automatically is recorded using cookies - text files containing small amounts of information that are downloaded to the User's device - or using related technologies such as web beacons, local shared objects and tracking pixels to collect and/or store information. For additional information on cookies and related technologies, including detailed information on opting out, please refer to our Cookie Policy.
VI. Scope and duration of personal data processing
- The Administrator processes Personal Data to the extent necessary to achieve the purposes set out in this Privacy Policy, in particular data provided by the User or Client, obtained from other Users/Clients in connection with the use of the Services, as well as data obtained from external sources - in accordance with the principles described in Section IV.
- Personal Data processed for the purpose of performing the agreement for the provision of services specified in the relevant Service Regulations are stored for the duration of the agreement, and after its expiry for the period necessary to:
- provide after-sales service (e.g., handling complaints);
- establish, pursue, secure claims or defend against them;
- ensure the proper provision of services in accordance with the Service Regulations, including documenting declarations of will made towards other Users, if any of the other Users still use the Administrator's Services;
- comply with the legal obligations of the Administrator (arising, among others, from tax or accounting regulations or the act on trust services and electronic identification).
- Personal Data processed on the basis of the consent of the data subject are processed until the consent is withdrawn or the purpose of processing ceases.
- Personal Data are also processed for technical and organizational purposes, in particular in connection with ensuring security, business continuity and the proper functioning of the Administrator's IT systems, including within the scope of performing and restoring backups, system testing, detecting misuse or preventing attacks or abuses.
- After the expiry of the processing period, as long as it is technically feasible and provided that the applicable law does not allow or require further processing of Personal Data, the Personal Data are irreversibly deleted or anonymized.
VII. Marketing and marketing analytics
- As part of marketing activities based on the User's consent, the Administrator may process data voluntarily provided in forms (so-called user-provided data, e.g., name, surname, email address, telephone number) for the purpose of:
- analyzing the effectiveness of advertising campaigns;
- assigning conversions;
- personalizing marketing content.
- For this purpose, such data may be converted into a hashed format (e.g., using the SHA-256 hashing function) and transferred to the Administrator's advertising partners, such as Google Ireland Ltd. and Meta Platforms Ireland Ltd., as part of the Google Enhanced Conversions and Meta Advanced Matching services.
- Providing Personal Data for marketing purposes is voluntary and the lack of consent or its withdrawal does not affect the possibility of using the Administrator's Services.
- The processing of Personal Data for marketing purposes is carried out exclusively on the basis of the User's prior consent, which may be withdrawn at any time.
- The processing of personal data for marketing purposes referred to above may also take place using cookies or similar technologies, in accordance with the principles set out in the Cookie Policy.
VIII. Sharing of Personal Data
- Personal Data may be made available to entities authorized to receive them under applicable legal regulations, including competent judicial authorities and other public bodies. Personal Data may also be transferred to processors indicated by the Administrator who process Personal Data on the Administrator's behalf, i.e., service providers providing:
- technical services, including hosting (including data storage in the so-called cloud computing), supporting the development and maintenance of IT systems and websites and supporting information security activities;
- debt collection services;
- bookkeeping and accounting services;
- advisory and consulting services;
- trust service or identification service providers;
- other entities through which the Administrator performs or supports, including automates, the provision of Services.
- The Personal Data of Users or Clients may be made available to other Users or Clients if it is necessary for the purposes of communication or using the Administrator's Services, including at their request, in accordance with the nature and functionalities of the Services.
- Users' Personal Data may be transferred to third parties in cases not indicated by the Administrator or by legal regulations - only upon the consent of the User.
- If the User gives their consent, their data may also be made available to other entities for their own purposes, including marketing purposes and sending commercial content by electronic means.
- Personal Data may be transferred to third countries (outside the European Economic Area), in particular in connection with the Administrator's use of services from technological providers such as Google or Meta. The rules for such data transfer are described in detail below.
- The transfer of Personal Data to third countries takes place in accordance with art. 44 et seq. of the GDPR, in particular:
- on the basis of European Commission decision stating an adequate level of protection, including under the Data Privacy Framework (DPF) - if applicable; or
- on the basis of Standard Contractual Clauses (SCC), adopted by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, along with the application - if necessary - of additional security measures ensuring an adequate level of protection of Personal Data.
- In the case of Services used to verify Users' identities (e.g., eID service), the transfer of Personal Data to third countries or international organizations is subject to specific restrictions and takes place exclusively to the extent and on the terms ensuring an adequate level of protection of Personal Data, pursuant to art. 44-46 of the GDPR, taking into account the nature of such data and the purpose of its processing.
- If a European Commission decision stating an adequate level of protection cannot be applied, the Administrator ensures the transfer of Personal Data to third countries or international organizations based on appropriate safeguards referred to in art. 46 of the GDPR, in particular through the application of standard contractual clauses adopted by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries or - if applicable - binding corporate rules referred to in art. 47 of the GDPR. The content of the decision can be found on the website: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914. Additionally, should such a need arise, the Administrator applies additional security measures to ensure an adequate level of protection.
IX. Rights and obligations of Users
- Data subjects have the right to:
- request access to the content of their Personal Data and obtain information regarding:
- the purposes of processing;
- the categories of Personal Data;
- the recipients or categories of recipients;
- the planned storage period or criteria for determining it;
- the applicable rights and rules for their exercise;
- the source of obtaining Personal Data;
- automated decision-making, its logic, consequences and profiling;
- Personal Data safeguards applied by the Administrator;
- request a copy of the Personal Data, including by electronic means, provided that providing such a copy does not affect the rights and freedoms of others. The Administrator reserves the right to charge a reasonable fee resulting from the need to cover administrative costs related to fulfilling the request;
- request the rectification of Personal Data, whereby the Administrator reserves the right to refuse the rectification of Personal Data processed as evidence or a record in IT systems for the purpose of performing a specific Service, including primarily trust services (e.g., an affixed electronic signature). Such rectification of Personal Data may result in a violation of the evidentiary integrity or the transaction performed. The User may also independently rectify Personal Data assigned to the Account through the Account settings;
- request the deletion of Personal Data, whereby the Administrator reserves the right to refuse the deletion of Personal Data if justified by circumstances specified in art. 17(3) of the GDPR;
- request the restriction of processing of Personal Data in cases specified in art. 18 of the GDPR;
- request the transfer (portability) of Personal Data, whereby the Administrator reserves the right to refuse the claim if it is not technically feasible to perform;
- object to the processing of Personal Data if the Personal Data are processed for evidentiary purposes or other legitimate interests of the Administrator, including for direct marketing purposes. The Administrator reserves the right to refuse the request if there are valid legitimate grounds for processing Personal Data that override the rights and freedoms of the person lodging the objection. Such a valid legitimate ground is, above all, the necessity for the Administrator to store evidence of the performance of trust services, in particular document signing and electronic signature services, in accordance with the relevant policy of that Service;
- withdraw consent at any time without affecting the lawfulness of processing (if processing is based on consent) performed on the basis of the consent before its withdrawal.
- Furthermore, the data subject has the right to lodge a complaint regarding the processing of their Personal Data by the Administrator with the supervisory authority, which is the President of the Personal Data Protection Office - address: Moniuszki 1A, 00-014 Warsaw.
- request access to the content of their Personal Data and obtain information regarding:
- The Client has the right to resign at any time from receiving electronic messages referred to in Section II.7 (marketing messages) and to demand that the processing of Personal Data for this purpose be stopped. The relevant request should be sent to the address: iod@autenti.com. The Client also has the right to resign, as mentioned above, by clicking the appropriate resignation link available in the footer of every marketing email.
- The User and the Client are committed to providing the Administrator with complete, current and true Personal Data.
- Exercise of the rights indicated in paragraph 1 above is possible by contacting Customer Service or directly with the Data Protection Officer or the Administrator. The request should indicate the subject of the request, in particular, which right the User wants to exercise, which processing activity the request concerns and the expected manner of fulfilling the request.
- If the Administrator is unable to determine the content of the request mentioned above based on the submission, they will ask the applicant for additional information. In the absence of information necessary to determine the request and its scope, the Administrator may refuse to fulfill the request. Furthermore, based on art. 12(6) of the GDPR, the Administrator may request additional information from the User necessary to establish the identity of the data subject to confirm the authority to submit the request or provide information.
- A response to the request will be provided within one month of its receipt at the latest. If it becomes necessary to extend this period, the Administrator will inform the applicant of the reasons for such an extension.
X. Administrator's contact details
- The Administrator has appointed a Data Protection Officer.
- Contact with the Administrator or the Data Protection Officer appointed by the Administrator is possible through:
- the electronic form available on the website: https://autenti.com/en/contact/; or
- the email address: dpo@autenti.com; or
- the traditional mail address: Autenti S.A., ul. Św. Marcin 29/8, 61-806 Poznań.
XI. Final Provisions
- This Policy may be subject to updates, in particular in the event of changes in legal provisions, expansion of the scope of provided Services, implementation of new technological solutions or changes in the manner of processing Personal Data.
- In the case of significant changes, in particular those that may affect the rights or obligations of Users, the Administrator shall inform about them in an appropriate manner - specifically through an announcement on the website, and if justified - also via email sent to Users holding an Account.