Privacy Policy
PRIVACY POLICY SNIPERCAM LIMITED LIABILITY COMPANY WITH ITS REGISTERED OFFICE IN OLKUSZ
The policy applies to the website snipercam.pl, the store, the SniperCam Portal, the application, the newsletter, and contact with SniperCam.
§ 1. Administrator
The administrator of personal data is SNIPERCAM limited liability company with its registered office in Olkusz (address: ul. Króla Kazimierza Wielkiego 63, 32-300 Olkusz), entered in the register of entrepreneurs of the National Court Register maintained by the District Court for Kraków-Śródmieście in Kraków, XII Economic Department of the National Court Register under the number KRS: 0001043355, NIP: 6372221887, REGON: 525673327, with a share capital of 45,000.00 PLN. For data protection matters, you can contact us at contact@snipercam.pl or at the registered office address. The administrator has not appointed a data protection officer; data protection tasks are carried out by the management.
§2. Definitions
For the purposes of this Policy, the following definitions are adopted:
1) Administrator – SNIPERCAM limited liability company with its registered office in Olkusz, whose full details are provided in § 1 of the Policy;
2) Application – SniperCam software installed on a compatible device and working with SniperCam devices or the Portal;
3) Personal data – information about an identified or identifiable natural person;
4) Client – a natural person, legal person, or organizational unit using the Store or entering into a contract with SniperCam;
5) Portal Account – an individual User account in the Portal, separate from the Store Account;
6) Account of the Store – a voluntary account of the Customer in the Store, serving in particular for the handling of orders;
7) Cookies – data stored on the User's end device or read from that device while using the Site, Store, or Portal;
8) Policy – this Privacy Policy;
9) Portal – the SniperCam website available at the address https://portal.snipercam.pl/ along with related web functions;
10) GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016;
11) Session – a record of the shooting process, including in particular the image of the target, detected hits, results, settings, or information entered by the User;
12) Store – the SniperCam online store operated under the website snipercam.pl;
13) SniperCam or Company – SNIPERCAM limited liability company based in Olkusz;
14) Site – the website available at https://snipercam.pl/;
15) User – a natural person using the Site, Store, Application, Portal, or other electronic services of SniperCam;
16) EEA – European Economic Area.
§ 3. Purposes, bases, and periods of processing
|
Process |
Data |
Basis |
Period |
|
Website operation and security |
IP, logs, device identifiers |
art. 6 sec. 1 lit. f GDPR |
12 months; longer only if the log concerns an incident or claim |
|
Order and contract |
identification data, contact, address, order |
art. 6 sec. 1 lit. b GDPR |
duration of the contract, then 6 years for consumer relations or 3 years for B2B, calculated according to the statute of limitations |
|
Taxes and accounting |
billing and payment data |
art. 6 sec. 1 lit. c GDPR |
5 years from the end of the year in which the tax payment deadline expired, unless the law requires longer |
|
Delivery |
first name, last name, address, phone, email, customs data |
art. 6 sec. 1 lit. b and c GDPR |
for the execution of delivery, then the period of claims and legal obligations |
|
Complaints, returns, warranty |
customer data, purchase, description of the defect, correspondence |
art. 6 sec. 1 lit. b, c and f GDPR |
duration of the case, then 6 years for consumer relations or 3 years for B2B, according to the statute of limitations |
|
Store account |
account data, order history |
art. 6 sec. 1 lit. b GDPR |
for account deletion, retaining data required by law |
|
Portal Account and sessions |
email, identifier, settings, sessions, results, links |
art. 6 sec. 1 lit. b GDPR |
for account deletion; logs 12 months; sessions only after effective anonymization |
|
Contact |
data provided in the message |
art. 6 sec. 1 lit. b or f GDPR |
12 months from the closure of the case, unless the correspondence became part of the contract, complaint or claim |
|
Newsletter |
email, proof of consent, technical activity |
art. 6 sec. 1 lit. a GDPR and consent required by the PKE |
to withdraw consent; minimal proof of consent for 3 years from the end of the year of its withdrawal |
|
Analytics and marketing cookies |
IP, cookie identifiers, events |
art. 6 sec. 1 lit. a GDPR |
to withdraw consent or the expiration of the validity period of a given cookie, in accordance with a separate Cookie Policy |
|
Claims and abuses |
data related to the event |
art. 6 sec. 1 lit. f GDPR |
to the limitation of claims or the conclusion of proceedings |
§ 4. Data recipients
1. Data may be received by hosting, server, software, email, and IT service providers (including Odoo, OVH, and dhosting.pl), payment operator PayU, Accounting and Advisory Company “NEST” sp. z o.o., carriers and logistics operators, analytics providers – upon obtaining the required consent – as well as Google and Apple in the context of application distribution. Data may be made available to public authorities when required by law.
2. If the basis for processing is art. 6 sec. 1 lit. f GDPR, the legitimate interest of the Administrator is to ensure the security of the website, store, and Portal, to conduct correspondence and relationships with contractor representatives, and to establish, pursue, and defend claims.
§ 5. Transfers outside the EEA
If, in connection with the use of a specific provider, data is transferred outside the European Economic Area, the Administrator applies the transfer basis appropriate for that provider, in particular, a decision of the European Commission determining an adequate level of protection, the recipient's participation in the EU–US Data Privacy Framework, or standard contractual clauses along with the required safeguards. The transfer mechanism used is subject to documentation in the provider register. Information about the safeguards applicable to a given recipient can be obtained by contacting the Administrator.
§ 6. Rights of the individual
1. The individual, whose data is concerned, has – in cases specified in the GDPR – the right to access the data and receive a copy, to rectify the data, to delete it, to restrict processing, to transfer the data, and to object to processing based on the legitimate interest of the Administrator.
2. The right to delete data is not absolute. The Administrator may retain the data if further processing is necessary, in particular, to fulfill a legal obligation or to establish, pursue, or defend claims.
3. If processing is based on consent, it can be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
4. An objection can be raised for reasons related to the particular situation of the individual, when the basis for processing is Article 6(1)(f) of the GDPR. In the case of processing data for direct marketing purposes, an objection can be raised at any time and does not require justification.
5. Requests can be directed to contact@snipercam.pl or the address of the Administrator's office. The Administrator may request additional information only when there are reasonable doubts about the identity of the person making the request.
6. A person has the right to file a complaint with the President of the Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, or through the current channel indicated on the office's website.
§ 7. Sources of data obtained indirectly
1. If the person acts as a representative, employee, or collaborator of a client, a supplier, or another contractor, their data may be provided to the Administrator by the represented entity, a person collaborating with that entity, or obtained from a public register or public professional source, in particular from the contractor's website.
2. In such a case, the Administrator processes, in principle, the first name and last name, the position or function, work contact details, and information related to representation and conducted correspondence.
§ 8. Voluntariness of data and automated decisions
1. Providing data is voluntary, but data marked as required is necessary for concluding and performing a contract, creating an account, or providing a response. SniperCam does not make decisions that have legal effects exclusively in an automated manner within the meaning of Article 22 of the GDPR.
2. Detailed information about cookies, similar technologies, their duration, and the way to give, refuse, and withdraw consent can be found in a separate Cookie Policy available on the snipercam.pl website. Optional analytical and marketing cookies are not activated before obtaining the User's consent.
§ 9. Sessions shared by link
The user should assume that a person with the link to the session can familiarize themselves with its content. One should not include in the session data of third parties without appropriate grounds. After the account is deleted, sessions may be retained only after their effective anonymization; pseudonymization or just deleting the account name is not anonymization.
§ 10. Camera Image
1. The system is intended for observing shooting targets, not individuals. The user should not point the camera at individuals or place materials in the Portal containing personal data of third parties without appropriate legal grounds.
2. In the standard operating mode, the camera image is transmitted locally to the User's device. Internet access is required to use the Portal's functions, particularly for uploading Sessions. SniperCam does not use the system to monitor third parties.
§ 11. Policy Changes
The policy may be updated in connection with changes in law, functions, or providers. The current version will be available on the site, and the user will be informed of significant changes regarding the account or the Portal through the appropriate channel.