INFORMATION REGARDING THE PROCESSING OF PERSONAL DATA BY AUDIORIVER SP. Z O.O.
As of 25 May 2018, new personal data protection regulations resulting from Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter referred to as the “GDPR”) apply throughout the European Union. Therefore, in this document (hereinafter referred to as the “Policy”), we provide information regarding:
- the legal bases for the processing of personal data,
- the methods of collecting and using personal data,
- your rights related to the processing of personal data.
Personal data means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Processing of personal data includes, in particular, the collection, storage, recording, organization, modification, consultation, use, disclosure, restriction, erasure, or destruction of personal data, regardless of whether such processing is carried out by automated means or manually.
I. Data Controller
Pursuant to the GDPR, the data controller is the entity that determines the purposes and means of processing personal data.
Audioriver spółka z ograniczoną odpowiedzialnością
ul. Mickiewicza 62
01-650 Warsaw, Poland
KRS: 0001078010
NIP (Tax ID): 5252986173
REGON: 527284133
This Privacy Policy governs matters relating to the processing of personal data in connection with the Controller’s activities, in particular the organization and operation of cultural and artistic events, as well as the management and support of artists’ activities, including publishing activities.
For matters concerning the protection and processing of personal data, you may contact the Controller:
- by post: ul. Mickiewicza 62, 01-650 Warsaw, Poland (marked “GDPR”),
- by email: hello@audioriver.pl
The Controller has not appointed a Data Protection Officer (DPO).
II. What Is the Purpose and Legal Basis for Processing Personal Data?
Your personal data is processed only to the minimum extent necessary for the provision of services by the Controller.
The legal basis for processing your personal data depends on the purpose of the processing:
- Conclusion and performance of a contract – processing is necessary for entering into and performing a contract (Article 6(1)(b) GDPR).
- Legitimate interests of the Controller – sending information about the Controller’s services, direct marketing, traffic analytics, and ensuring website stability (Article 6(1)(f) GDPR).
- Consent – sending newsletters electronically and conducting surveys (Article 6(1)(a) GDPR).
- Compliance with a legal obligation – processing necessary for tax settlements and payment of social security contributions (Article 6(1)(c) GDPR).
- Establishment, exercise, or defense of legal claims – safeguarding rights arising from contracts (Article 6(1)(f) GDPR).
- Processing through cookies – website traffic analysis and maintenance of website stability in accordance with the user’s browser settings (Article 6(1)(f) GDPR).
Providing personal data is voluntary; however, it is necessary for conducting negotiations and entering into a contract.
III. How Long Does the Controller Process Personal Data?
The retention period depends on the legal basis for processing:
- Contractual basis – until the performance and termination of the contract.
- Consent – until the consent is withdrawn.
- Legitimate interest – until the purpose ceases to exist or an objection is raised, unless processing remains necessary due to another overriding purpose or legal basis.
- Archival purposes (e.g., limitation periods for claims, tax and accounting obligations) – up to 6 years from the date the data was obtained.
IV. Is Personal Data Disclosed to Third Parties?
Your personal data will only be disclosed to:
- employees of the Controller, where access to the data is necessary for the performance of their duties;
- external service providers (IT services, courier services, online payment providers, hosting providers, legal and accounting advisors) solely on the basis of data processing agreements and with safeguards ensuring a level of protection no lower than that applied by the Controller; in the case of payment processing and courier services, disclosure will occur only with your prior consent;
- the Controller’s business partners, to the extent necessary for the performance of contracts involving employees’ data; the Controller ensures the protection of such data;
- third countries (outside the EEA) only through the use of EU Standard Contractual Clauses, Privacy Shield certification, or binding corporate rules of the processor.
V. What Rights Do You Have Regarding the Processing of Your Personal Data?
You are entitled to the following rights:
Right of Access
The right to access your personal data and obtain a copy thereof.
Right to Rectification
The right to correct incomplete, inaccurate, or outdated personal data.
Right to Restriction of Processing
You may request restriction of processing where:
- you wish to verify the accuracy of the data processing;
- the processing is unlawful and you oppose erasure, requesting restriction instead;
- the data is required for the establishment, exercise, or defense of legal claims, even though the Controller no longer needs it for its own purposes;
- you have objected to processing and the Controller must verify whether overriding legitimate grounds exist.
Right to Erasure (“Right to Be Forgotten”)
You may request erasure where:
- the data is no longer necessary for the purposes for which it was collected;
- consent has been withdrawn and there is no other legal basis for processing;
- you have objected to processing and there are no overriding legitimate grounds for continued processing;
- the data has been processed unlawfully.
Right to Data Portability
The right to receive and transfer personal data processed on the basis of consent or a contract, where processing is carried out by automated means.
Right to Object
The right to object to processing based on the Controller’s legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
The right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Right to Lodge a Complaint
The right to lodge a complaint with the President of the Personal Data Protection Office (UODO).
The Controller does not carry out automated profiling of your personal data.
VI. Cookies
Cookies are small files stored on a device (computer, smartphone, tablet) while browsing websites.
Categories of Cookies
Essential (Session) Cookies
Temporary files stored in the browser’s memory until the end of a session. They are used to ensure the proper functioning of the website, authentication, and protection against abuse. These cookies do not require user consent.
Functional and Performance Cookies
These cookies enable personalization of settings, session maintenance, language selection, form completion, and traffic analytics (e.g., Google Analytics, Gemius) for website optimization purposes. Restricting or deleting these cookies may affect certain functionalities.
The Controller does not use cookies for advertising purposes.
Storage Period
- Session cookies – until the browser session ends.
- Persistent cookies – up to 12 months, unless deleted by the user.
Users may manage cookies through their browser settings.
VII. Final Provisions
The Controller regularly reviews this Privacy Policy and introduces changes in the event of:
- new legal regulations,
- guidelines issued by supervisory authorities,
- best practices in personal data protection.
Any changes to this Policy will be communicated on the website or via email.
This Policy enters into force on the date of its publication.