Skip to content
Forum Legal – kancelaria prawna
PL

LEGAL DOCUMENT

GDPR

Information on the processing of personal data in electronic communication

In performance of the obligations set out in Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR”), we provide the following information:

1. Personal data controller

The controller of your personal data is Forum Legal Miśkowiec, Nowak i Wspólnicy Kancelaria Prawna sp.k. with its registered office in Kraków, ul. Wadowicka 3c, registered with the District Court for Kraków-Śródmieście in Kraków, 11th Commercial Division of the National Court Register, under KRS number 0001016557, NIP 6793258913, REGON 524338911 (referred to in this notice as the “Controller” or the “Firm”), being a party to the professional relationship to which the correspondence relates.

Contact details: biuro@forlegal.pl.

The purpose of processing personal data in electronic communication is to establish or maintain a relationship in connection with the Controller’s activity, i.e. the provision of legal services, and to conduct related correspondence and business communication. The basis for this processing may be: necessity for the performance of a contract or for taking steps prior to entering into a contract (Article 6(1)(b) GDPR); provisions of law (Article 6(1)(c) GDPR), including provisions on court and administrative proceedings, accounting, taxes and the archiving of data and documents; and the Controller’s legitimate interest (Article 6(1)(f) GDPR), including maintaining professional relationships and business contacts and, where applicable, pursuing and defending against claims.

3. Categories of personal data

The Controller processes in particular the following categories of data: identification data, contact details, data concerning the business position held, data on the represented entity and the relationship with it, other data provided by the client which is necessary for the provision of legal services and the maintenance of professional relationships, data concerning liabilities, and transactional data.

4. Recipients of personal data

Your data may be disclosed to the following categories of recipients:

  1. entities and authorities to which the Controller is obliged or authorised to disclose personal data under generally applicable law, including entities and authorities entitled to receive personal data from the Controller or to request access to personal data under generally applicable law,
  2. entities providing services to the Controller, including advisory, audit, accounting, valuation, IT and archiving services,
  3. other entities entrusted by the Controller with the performance of activities related to its business.

5. Transfers of personal data to third countries

Your personal data may be transferred outside the European Economic Area where the Controller uses the services of providers of IT solutions and systems which may store personal data on servers located outside that area (including in the United States), or in the course of the Controller’s provision of legal services to the extent necessary for the performance of the service. The basis for such a transfer may be a European Commission decision finding an adequate level of protection, or the application of appropriate legal safeguards, in particular the standard contractual clauses on personal data protection approved by the European Commission. In the absence of such a European Commission decision and of appropriate safeguards, personal data may be transferred to a third country on the basis of one of the grounds listed in Article 49(1) GDPR, in particular on the basis of your explicit consent. You have the right to obtain a copy of the personal data transferred to a third country.

6. Retention period

Depending on the basis for processing, your personal data will be stored for the duration of the business contacts and professional relationship or the term of the contract and, thereafter, for the period and to the extent required by law or for the period necessary to secure potential claims – until the expiry of their limitation period.

7. Your rights

You have the right to request from the Controller:

  • access to your data, under Article 15 GDPR,
  • rectification of your data, under Article 16 GDPR,
  • erasure of your data, under Article 17 GDPR,
  • restriction of processing, under Article 18 GDPR,

as well as the right to:

  • object to the processing of your data, under Article 21 GDPR,
  • data portability, under Article 20 GDPR.

You also have the right to lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office (UODO).

8. Voluntary provision of data

Providing your data is voluntary; however, failure to provide it may make it impossible to respond to correspondence, to keep in contact with you, or to establish or maintain a professional relationship (this applies where data is collected directly from the data subject).

9. Source of the data (where data has not been collected directly from the data subject)

If you have not provided your personal data directly, your personal data has been provided by the entity on whose behalf you act, or by an entity which provided your personal data as necessary for maintaining business contacts or a professional relationship with that entity.

We would also like to inform you that detailed information on personal data protection intended for particular categories of persons, which may supplement the information above, is available at www.forlegal.pl/en/gdpr.