The controller of your personal data is MSGA, with its registered office in Łódź, Piotrkowska 276A, 90-361 Łódź, Poland, Tax ID (NIP): 7331362657, Business Registry No. (REGON): 383902384 (hereinafter: the "Controller").
Contact regarding personal data matters: [email protected]
We process personal data from three sources, depending on how we came into contact with you.
For data obtained from publicly available sources, pursuant to Article 14(3) of the GDPR this information is provided no later than within one month of obtaining the personal data, or at the first contact with the data subject.
When you contact us through the form on our website, we process the data you choose to provide: your first and last name, business email address, company name, job role, the content of your message, and any service interests you select.
The legal basis for this processing is Article 6(1)(b) of the GDPR, as processing is necessary to take steps at your request prior to entering into a contract, and, where applicable, Article 6(1)(f) of the GDPR (our legitimate interest in responding to enquiries addressed to us).
Our contact form is operated through Web3Forms, which transmits your submission to us by email. Web3Forms acts as our data processor and may process your data on servers located outside the European Economic Area (in the United States), on the basis of the standard contractual clauses approved by the European Commission (see section 10).
Providing your data through the form is voluntary, but the name, business email address, and message are necessary for us to respond to your enquiry. Contact form data is retained for as long as necessary to handle your enquiry and any resulting business relationship, and no longer than 12 months from our last contact where no relationship is established.
The legal basis for processing your personal data is the legitimate interest of the controller within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the GDPR).
The legitimate interest consists in establishing business contacts, conducting commercial (B2B) communication, and presenting an offer of services related to the recipient's professional activity.
Where the processing is based on your consent - in particular where you have explicitly agreed to receive commercial or marketing communication from us - the legal basis is Article 6(1)(a) of the GDPR. In such cases we process your data only within the scope covered by your consent, and you may withdraw that consent at any time (see section 8).
We process only professional data:
We process your data for the following purposes:
Your data will be processed for a period no longer than 12 months from the last contact or attempted contact. After this period, the data will be reviewed to assess whether further processing is justified. If there is no legitimate interest in continuing the processing, the data will be permanently deleted.
The data will be deleted earlier if an effective objection to its processing is raised.
Data processed on the basis of your consent is retained until you withdraw that consent. Following withdrawal, the data will be deleted without undue delay, unless we have another legal basis for continuing to process it.
Under the GDPR, you have the following rights:
Your data may be shared only with entities that support the Controller in achieving the processing purposes. The categories of recipients include:
Each of these entities processes the data on the basis of appropriate data processing agreements.
In connection with the use of technological tools (including our contact form provider Web3Forms, as well as CRM and communication platforms), your data may be transferred to countries outside the European Economic Area, including the United States. In such cases, the transfer takes place on the basis of standard contractual clauses approved by the European Commission or an adequacy decision.
The Controller does not make decisions concerning you based solely on automated processing, including profiling, that would produce legal effects concerning you or similarly significantly affect you.
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, or destruction. Access to the data is granted only to authorised persons, and the systems we use are secured in accordance with current industry standards.
The Controller reserves the right to update this Privacy Policy. We will inform you of any material changes via the website. The current version of the document is always available at: msga.pro/privacy-policy