Privacy Policy of the ‘Truck Work’ Website
This Policy, governing the processing of personal data and the rules for handling confidential information (hereinafter referred to as the Policy), applies to all information posted on the Internet resource available at https://www.truckwork.pl/ (hereinafter referred to as the Website).
The company FRIEDMANN SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (hereinafter referred to as the Service Provider) considers the security of personal data of Website visitors and users of its functionality as one of its key priorities. The Service Provider takes comprehensive measures to protect any personal information, thereby ensuring safe and comfortable use of the Website’s services for every individual accessing this resource.
I. Data Controller
The processing of personal data posted on the Internet resource https://www.truckwork.pl/ is carried out by FRIEDMANN SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, registered in Warsaw and entered into the National Court Register under NIP 5213956191 and KRS 0000953966. This organization acts as the data controller in accordance with applicable law.
II. Purposes and Grounds for Personal Data Processing
User data is processed in specially formed and structured databases, distributed according to the tasks for which this information is collected. The volume of processed data is limited to the scope necessary to achieve a specific purpose. The categories of databases, the composition of information, and their purpose are listed below.
| Database Name | List of Processed Data | Purpose of Processing |
| Database of individuals using the contact form on the Website | First name, last name, phone number | Ability to contact users who have expressed interest in the Service Provider’s services |
| Database of training course participants | First name and last name, phone number, passport details, driver’s license, medical certificate | Fulfillment of obligations arising from contracts with participants of courses organized by the Service Provider |
The user always receives information about the specific purpose of personal data processing before providing it or directly at the moment of data collection.
III. Grounds and Retention Periods for Personal Data Processing
When collecting personal information, users are always informed about the legal basis for processing this data. Specifically:
- Article 6(1)(a) of the GDPR implies the processing of personal data based on the voluntary consent of the user;
- Article 6(1)(b) of the GDPR applies when processing is necessary for the performance of a contract or for actions taken at the user’s request prior to entering into a contract;
- Article 6(1)(c) of the GDPR is used to fulfill legal obligations imposed on the Controller;
- Article 6(1)(f) of the GDPR allows data processing for the legitimate interests of the Controller, of which users are notified in advance.
In addition to the above grounds, processing may also be carried out on other legal grounds, for example, in accordance with the provisions of the Act on the Provision of Electronic Services.
Personal data retention periods are determined by their purpose and the grounds for processing. Users are informed of these periods before or at the moment of providing the information. Examples of retention periods include:
- data processed as part of marketing activities is retained until an objection is received from the data subject;
- information whose processing is based on user consent is stored until its withdrawal;
- data collected using cookies and similar technologies are processed until such files are deleted through browser or device settings, or until an objection is received from the user;
- personal information related to the fulfillment of legal or accounting obligations (e.g., for invoicing) is stored for the period prescribed by applicable law;
- data related to the provision of services and sales are stored until the expiration of possible legal claims related to the services rendered.
IV. Rights of Personal Data Subjects
Every individual whose data is processed has certain rights regarding their personal information. The ability to exercise these rights depends on the legal basis of processing and the specific situation.
- Right of access to data. The data subject has the right to obtain confirmation as to whether their personal data is being processed. They may request access to this data, as well as additional information about the purposes, categories of data, recipients, legal grounds for processing, and data sources. Upon receipt of a relevant request, the Controller is obliged to provide a copy of the processed information. If the request was submitted electronically and no other format is specified, the information is also provided electronically.
- Right to rectification. The data subject may request the rectification of inaccurate or incomplete information relating to them. Within the scope of the processing purposes, they also have the right to request the completion of any incomplete personal data, including by providing additional documents or statements.
- Right to be forgotten (data erasure). The data subject has the right to request the immediate erasure of their personal data. The Controller is obliged to fulfill such a request without undue delay if at least one of the following conditions is met:
- consent to data processing has been withdrawn, and there are no other legitimate grounds for processing;
- the data subject has objected to the processing;
- the data has been unlawfully processed;
- erasure is required to fulfill legal obligations;
- the data was collected in the context of providing information society services.
- Right to restriction of processing. The data subject may request the restriction of processing of their personal information in cases where:
- the accuracy of the data is contested until its correctness is verified;
- the processing is unlawful, and the data subject opposes the erasure of the personal data and requests the restriction of its use instead;
- the Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise, or defense of legal claims;
- an objection has been raised pursuant to Article 21(1) of the GDPR, pending the verification whether the legitimate grounds of the Controller override those of the data subject.
- Right to object. The data subject may object to the processing of their data based on Article 6(1)(f) of the GDPR (legitimate interest of the Controller), including profiling. In this case, the processing of such data shall cease unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims. If processing is carried out for direct marketing, including marketing profiling, the data subject has the right to prohibit such processing.
- Automated decision-making and profiling. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. Exceptions apply in situations:
- where the decision is necessary for entering into, or performance of, a contract;
- if authorized by EU or Polish law, which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests;
- if the data subject has given their explicit consent.
Users can also control the processing of their data, including access, rectification, updating, supplementation, temporary or permanent suspension of processing, or deletion of data if it is incomplete, outdated, inaccurate, collected in violation of the law, or has lost the purpose for which it was collected.
To exercise your rights or obtain additional instructions, please contact the Controller.
V. System Logs
The Website maintains internal system logs that automatically record user actions when accessing Website resources. The logs reflect information such as requested pages, user’s IP address, browser type and language, date and time of access, and at least one cookie that uniquely identifies the user’s device.
Detailed information about the rules for using cookies and their processing methods is available in the “Cookie Policy” section of the Website.
VI. Transfer of Personal Data Outside the European Economic Area (EEA)
The level of personal data protection in countries outside the European Economic Area (EEA) may differ from the standards established by EU law. Therefore, the Controller transfers personal data abroad only when necessary and provided that an adequate level of protection is ensured. The following measures are applied for this purpose:
- cooperation with organizations located in countries recognized by the European Commission as providing an adequate level of protection;
- use of standard contractual clauses approved by the European Commission;
- implementation of Binding Corporate Rules approved by the competent supervisory authority;
- when transferring data to the USA – working with organizations participating in the Privacy Shield program recognized by the European Commission.
The Controller informs users about the intention to transfer their personal data outside the EEA at the time of collection or before processing begins.
VII. Intellectual Property Rights
All materials posted on the Website pages are the property of FRIEDMANN SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ. Any copyright and property rights to the elements of the Website – including texts, graphics, page design, and other components – are protected by law.
The Website and its content are protected in accordance with applicable law, including, but not limited to:
- The Act of February 4, 1994, on Copyright and Related Rights (consolidated text, Dziennik Ustaw No. 00.80.904 with subsequent amendments);
- The Act of April 16, 1993, on Combating Unfair Competition (consolidated text, Dziennik Ustaw 03.153.1503 with amendments).
Any use of Website materials without the permission of the copyright holder is prohibited and may result in legal liability.
VIII. Other Provisions
The Website may contain links to third-party Internet resources. The Controller is not responsible for compliance with privacy rules on these resources. It is recommended to carefully review the privacy policy of each website when visiting third-party resources.
The Service Provider reserves the right to make changes to this Privacy Policy and Cookie Policy at any time. Users will be notified of such changes in the prescribed manner.
IX. Definitions and Terms Used
For the purposes of this Policy, the terms below have the following meanings:
- Controller – FRIEDMANN SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, acting as the entity responsible for personal data processing.
- GDPR – The General Data Protection Regulation of the European Union, adopted on April 27, 2016, and effective from May 25, 2018.
- Personal data – any information relating to an identified or identifiable natural person (data subject). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Database – any structured set of personal data accessible according to established criteria, regardless of whether it is centralized, decentralized, or distributed on a functional or geographical basis.
- Personal data processing – any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Website – The Internet resource located at https://www.truckwork.pl/, provided by the Controller.
- User – A natural person who accesses the Website via the Internet and uses its functionality.