Privacy Policy
This Privacy Policy sets out the rules for the processing of personal data collected via the website allworkgroup.eu, hereinafter referred to as the “Website”.
The owner of the Website and at the same time the Data Controller is ALL WORK GROUP, 35-026 Rzeszów, ul. Reformacka 6, NIP: 8133918161, hereinafter referred to as the Controller.
Personal data collected by the Controller via the Website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), also referred to as GDPR.
The Controller exercises special care to respect the privacy of Clients visiting the Website.
§ 1 Types of data processed, purposes and legal basis
The Controller collects information concerning natural persons performing a legal act not directly related to their business or professional activity, natural persons conducting business or professional activity in their own name, and natural persons representing legal entities or organizational units not being legal entities, which the law grants legal capacity, conducting business or professional activity in their own name, hereinafter jointly referred to as Clients.
The Controller processes Clients’ personal data in connection with the use of the contact form service on the Website for the purposes necessary to perform the agreement or take action prior to its conclusion – legal basis: Article 6(1)(b) GDPR.
When using the contact form service, the Client provides the following data:
email address
first name
phone number
When using the Website, additional information may be collected, in particular: the IP address assigned to the Client’s computer or the external IP address of the Internet provider, domain name, browser type, access time, and type of operating system. Navigation data may also be collected from Clients, including information about links and references they choose to click or other activities taken on the Website, for purposes related to service provision, as well as technical, administrative, analytical, and statistical purposes – in this regard, the legal basis is also Article 6(1)(f) GDPR, i.e. the necessity for purposes arising from the legitimate interests of the Controller, such as ensuring IT security, managing the Website, and improving its functionality and services.
§ 2 Data recipients
The Client’s personal data are transferred to service providers used by the Controller in connection with running the Website. Depending on contractual arrangements and circumstances, service providers either follow the Controller’s instructions as to the purposes and methods of processing such data (processors), or independently determine the purposes and methods of their processing (controllers).
1.1. Processors: The Controller uses providers who process personal data solely at the Controller’s request. These include providers of hosting services, accounting services, marketing systems, web traffic analysis systems, and marketing campaign effectiveness analysis systems.
1.2. Controllers: The Controller uses providers who do not act solely at its request and who independently determine the purposes and methods of processing Clients’ personal data. They provide electronic payment and banking services.
Location: Service providers are mainly based in Poland and other countries of the European Economic Area (EEA).
In response to lawful requests, the Controller discloses personal data to authorized state authorities, in particular the Prosecutor’s Office, Police, the President of the Personal Data Protection Office, the President of the Office of Competition and Consumer Protection, or the President of the Office of Electronic Communications.
§ 3 Data retention period
Clients’ personal data are stored:
1.1. Where the basis for processing is consent – for as long as the consent is not withdrawn, and after its withdrawal for a period corresponding to the statute of limitations for claims that may be raised by the Controller or against the Controller. Unless otherwise provided by specific law, the limitation period is six years, and for periodic benefits or claims related to business activity – three years.
1.2. Where the basis for processing is the performance of a contract – for as long as necessary to perform the contract, and thereafter for a period corresponding to the statute of limitations for claims. Unless otherwise provided by specific law, the limitation period is six years, and for periodic benefits or claims related to business activity – three years.
§ 4 Cookies mechanism, IP address
The Website uses small files called cookies. They are saved by the Controller on the device of the Website visitor if the web browser allows it. A cookie usually contains the domain name it comes from, its “expiry time,” and a randomly generated unique number identifying the file. Information collected via such files helps to tailor the products offered by the Controller to the individual preferences and actual needs of Website visitors.
The Controller uses two types of cookies:
2.1. Session cookies: once a given browser session ends or the computer is turned off, the stored information is deleted from the device’s memory. The session cookie mechanism does not allow the collection of any personal data or confidential information from Clients’ computers.
2.2. Persistent cookies: are stored in the Client’s device memory and remain there until deleted or expired. The persistent cookie mechanism does not allow the collection of any personal data or confidential information from Clients’ computers.
The Controller uses its own cookies for:
analysis, research, and audience auditing, in particular to create anonymous statistics that help understand how Clients use the Website, enabling improvement of its structure and content.
The Controller uses external cookies for:
displaying on Website pages the map indicating the Controller’s office location using the maps.google.com service (external cookie administrator: Google Inc., USA).
The cookie mechanism is safe for Clients’ computers visiting the Website. In particular, viruses or other unwanted or malicious software cannot enter Clients’ computers via this mechanism. However, Clients may restrict or disable cookie access to their computers in their browsers. If this option is used, using the Website will still be possible, except for functions that by their nature require cookies.
The Controller may collect Clients’ IP addresses. An IP address is a number assigned to a Website visitor’s computer by an Internet service provider. An IP address enables Internet access. In most cases, it is assigned dynamically and changes with each Internet connection; therefore, it is commonly treated as non-personal identifying information. The Controller uses IP addresses when diagnosing technical problems with the server, creating statistical analyses (e.g., determining from which regions most visits are recorded), for administration and Website improvement, as well as for security purposes and potential identification of undesired automated browsing programs burdening the server.
§ 5 Rights of data subjects
Data subjects have the right to:
Withdraw consent at any time.
Object to the processing of personal data.
Request deletion of data (“right to be forgotten”).
Request restriction of data processing.
Request access to their data and receive a copy.
Request rectification (correction) of data.
Request data portability.
Lodge a complaint with a supervisory authority.
(Details of each right are maintained in the same scope as the Polish version, with full reference to GDPR provisions and Controller’s obligations.)
§ 6 Changes to the Privacy Policy
The Privacy Policy may be subject to change, and the Controller is not obliged to inform about such changes.
Questions regarding the Privacy Policy should be directed to: biuro.allworkgroup@gmail.com
Date of last modification: 14.08.2025