1. INFORMATION ABOUT THE PRIVACY POLICY
Below you will find the necessary information regarding your personal data that we process when you:
visit the website available at https://www.absystems.pl/, including any of its subpages (hereinafter the website and its subpages jointly referred to as the “Service”),
are a supplier, customer, contractor, or member of staff,
have consented to receive marketing information from the Controller,
have subscribed to the Newsletter,
contact us, including, for example, via the contact forms available on the Service, in person, by email or by telephone, or provide us with your data so that we can contact you regarding a specific matter.
This Policy fulfils the information obligation specified in Articles 13(1) and (2) and Articles 14(1) and (2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: the “GDPR”).
2. DATA CONTROLLER
The Controller of your personal data is Advanced Business Systems spółka z ograniczoną odpowiedzialnością, with its registered office in Kraków at ul. Galicyjska 1, entered in the Register of Entrepreneurs maintained by the District Court for Kraków-Śródmieście in Kraków under KRS number 0000173536 (hereinafter referred to as the “Controller” or the “Company”).
You may contact the Controller in writing at the address indicated above or by email at: biuro@absystems.pl.
3. DATA PROTECTION OFFICER
The Controller has appointed a Data Protection Officer (DPO).
For matters relating to your data and this Policy, you may contact the Data Protection Officer:
by post: ul. Galicyjska 1, 31-586 Kraków,
by email: iod@absystems.pl.
4. WHAT DATA WE PROCESS
When you visit our website, we retain information such as the IP address of the device you use, information about how you use the website, and your decisions regarding cookies.
The scope of the data processed, the purposes of processing, and the legal basis for processing are described in detail below.
If you contact us by email, we process the information you choose to provide to us and the personal data necessary to respond to your message. This includes:
identification data, including your first and last name,
contact details, including your email address and telephone number,
the date and time the message was sent,
the IP address of the device you use.
Data collected while you use our website is processed for the following purposes:
presentation of services – Article 6(1)(f) GDPR,
analysis and security of the Service – Article 6(1)(f) GDPR,
responding to enquiries – Article 6(1)(b) and (f) GDPR,
contact and handling of enquiries, including responding to messages and contacting you regarding a specific matter – Article 6(1)(b) and (f) GDPR,
archiving and backups – Article 6(1)(c) and (f) GDPR,
direct marketing, including newsletters and commercial information – solely on the basis of consent, Article 6(1)(a) GDPR,
establishment, exercise, or defence of legal claims – Article 6(1)(f) GDPR,
performance of contracts – Article 6(1)(b) GDPR,
compliance with legal obligations – Article 6(1)(c) GDPR,
technical support – Article 6(1)(b) and (f) GDPR,
reCAPTCHA, for protection against spam and abuse – Article 6(1)(f) GDPR.
Providing your data is voluntary; however, it may be necessary in order to contact the Controller or use selected services.
5. HOW LONG WE PROCESS YOUR DATA
Your personal data will be processed for the following periods:
contact – for a maximum of 3 years after the correspondence has ended,
claims – until the expiry of the applicable limitation period, up to 6 years,
legal obligations – in accordance with applicable regulations, e.g. tax and accounting regulations,
analytics and security – for a maximum of 24 months or until an objection is raised,
marketing based on consent – until consent is withdrawn,
archiving – in accordance with the backup policy.
In each case, however, we will process your data no longer than until you effectively object to its processing where the legal basis for processing is our legitimate interest, or no longer than until you withdraw your consent where consent is the legal basis for processing, unless we have another legal basis that permits or requires us to continue processing your personal data.
6. YOUR RIGHTS
Data may be used for profiling for marketing and analytical purposes, particularly on the basis of information concerning activity within the Service and data obtained from cookies. Profiling does not produce legal effects or similarly significantly affect the user.
In relation to each of the rights listed below, you may contact us using the contact details provided in this Policy. You have:
The right to information, access to your data, and to obtain a copy of your data. You may request information at any time concerning your personal data that we store or have access to. At your request, a copy of your personal data undergoing processing will be provided to you free of charge. We may charge a fee covering reasonable administrative costs for any additional copies requested.
The right to withdraw consent. Whenever your data is processed on the basis of your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
The right to rectification of personal data. We make reasonable efforts to ensure that your personal data is accurate, complete, and up to date. If your data needs to be updated, please let us know.
The right to data portability. You have the right to receive your personal data in a structured, commonly used, machine-readable format and the right to transmit your data to another data controller where the legal basis for processing is your consent or the performance of a contract.
The right to erasure and restriction of processing. In cases specified by data protection laws, you may request the deletion of your personal data. However, this is not an absolute right, and there may be circumstances in which we remain entitled to process such data. You may also request that further processing of your data be restricted.
The right to object to processing. In cases specified by law, you may object to further processing of your data where the legal basis for processing is our legitimate interest and your objection is based on grounds relating to your particular situation, or where you wish to object to the profiling of personal data.
The right to lodge a complaint with a supervisory authority. You may lodge a complaint with a supervisory authority responsible for personal data protection. As a rule, this will be the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
7. RECIPIENTS OF DATA
We exercise due care when selecting entities to which we disclose your data and require such entities to protect your data using appropriate technical and organisational measures.
Your personal data may be disclosed to:
third parties providing services to us that are necessary for the purposes for which we process your data, e.g. IT services, accounting services, electronic communications, data hosting, services necessary for the operation of the Service, data analysis, email distribution, and telephone communications,
recipients to whom disclosure is required under applicable law or pursuant to a court order or an order issued by another public authority,
other recipients where you have given your consent or where disclosure is necessary to protect your vital interests or the vital interests of other persons,
in particular, data recipients may include Google Ireland Ltd., Meta Platforms Ireland Ltd., Microsoft Corporation, and LinkedIn Ireland Unlimited Company.
The Controller uses marketing and CRM tools supporting customer service and electronic communication.
8. TRANSFERS OF DATA TO THIRD COUNTRIES
Data may be transferred outside the European Economic Area (EEA), e.g. to the United States, in accordance with the Data Privacy Framework and Standard Contractual Clauses.
Whenever personal data is transferred outside the EEA to countries that do not provide the same or an adequate level of personal data protection as that resulting from the laws applicable in Poland, we will ensure that such transfer is based on a valid legal basis and uses safeguards required by law.
9. DATA SECURITY
We make every effort to prevent data from being disclosed to unauthorised persons. We continuously analyse risks to ensure that personal data is secure and that its processing complies with the GDPR and other generally applicable laws.
All entities to which we entrust the processing of personal data guarantee the application of appropriate data protection and security measures required by law.
10. COOKIES
The Service uses analytics and marketing tools such as Google Analytics 4, Google Tag Manager, Microsoft Clarity, Google Ads, and LinkedIn Insight Tag.
The Service uses cookies (small text files handled by the Service and stored on the user’s device) and other similar technologies, such as pixel tags or local storage, to the extent necessary for its operation, including to ensure the functioning of the Service and to adapt its display to the user’s devices, software, preferences, and selected settings. Cookies may originate from the Controller or its trusted partners. The Controller is the entity using these tools.
The website uses the tools referred to above for various purposes, including:
adapting the way the website is displayed to users’ devices, software, preferences, and selected settings,
monitoring how users use the Service and improving its operation.
The Controller uses the following types of cookies:
Necessary cookies – these cookies are installed to provide the user with access to the Service and its basic functions. They do not require the user’s consent.
Optional cookies – the Controller uses these only with the user’s consent. These cookies include:
functional cookies – allowing us to remember the user’s preferences and choices, such as username, language, text size, or other customisable elements, and to provide personalised content within the Service,
analytics cookies – allowing us to see the number of visits and sources of traffic to the Service. They help identify which pages are more or less popular and understand how users navigate the Service so that the Controller can improve its performance.
While using the Service, the user may receive cookies originating from third parties cooperating with the Controller. Third parties cooperating with the Controller within the Service include:
analytics service providers – we cooperate with analytics providers in order to better understand how the website operates,
functional service providers – in order to enable users to use the Service in a personalised manner, the Controller may cooperate with telecommunications service providers.
Cookies and similar technologies may constitute personal data within the meaning of the GDPR, in particular where they make it possible to identify a user or their device. They do not modify the user’s browser settings or the configuration of the user’s device. Exceptional situations in which data collected by means of cookies may be considered the user’s personal data, as well as the related user rights, are described in detail in the relevant section of this Privacy Policy.
The Service uses:
session cookies – some cookies are temporary files stored until the user logs out, leaves the Service, or closes the web browser. Such cookies help analyse internet traffic, identify and resolve technical problems, and facilitate navigation within the Service,
persistent cookies – some cookies are persistent cookies that are stored for the period specified in their parameters or until deleted by the user. They help us remember the user’s settings and preferences in order to make subsequent visits more convenient or provide content tailored to the user’s needs.
The Service uses a consent management platform to help users manage their cookie preferences. When visiting the Service for the first time, the user will be asked to select one of the available options:
consent to all cookies – by selecting “Allow all”,
consent to selected cookies – by selecting “Allow selection” and then being redirected to the platform to customise cookie settings according to the user’s preferences,
refusal to consent to any cookies – by selecting “Reject”.
The user may change their cookie settings at any time via the website. This enables the user to:
obtain detailed information about cookies collected within the Service,
grant and withdraw consent for the Controller and its trusted partners to use optional cookies,
change previously selected settings.
We also remind users that cookie support may be disabled in their web browser. The web browser should provide an option to change settings in order to reject, delete, or block certain cookies. Giving consent through the platform for the Controller and its trusted partners to use optional cookies does not prevent the user from changing their cookie settings through their web browser.
To facilitate cookie management, links to some of the most popular browsers are provided below:
Mozilla Firefox: https://support.mozilla.org/pl/kb/ciasteczka
Microsoft Edge: https://support.microsoft.com/
Google Chrome: https://support.google.com/chrome/answer/95647?hl=pl
Safari: https://support.apple.com/
Opera: https://help.opera.com/pl/latest/web-preferences/#cookies
The user may also configure their browser to ask for permission before accepting cookies each time. This gives the user control over what is stored on their device, but has the disadvantage of slowing down navigation within the Service and other websites.
Some cookies are necessary for the Service to function properly, so changing browser settings may prevent certain services from operating correctly or may even completely prevent use of the Service.
A detailed list of cookies, their providers, and their retention periods is available in the Consent Management Platform (CMP).
11. CHANGES TO THE POLICY
The Privacy Policy is reviewed on an ongoing basis and updated when necessary.
The current version of the Privacy Policy was adopted and has been effective since 31 December 2025.