PRIVACY POLICY

PRIVACY AND COOKIE POLICY

Personal data is a highly valuable asset, often considered a form of currency in the digital economy. The Controller ensures the protection of all personal data it processes. This Policy contains information regarding the rules, scope, purposes, and legal basis of the User’s personal data processing, as well as the rights granted to the User in this regard.

PERSONAL DATA CONTROLLER

Jennet Arshimova, conducting sole proprietorship under the name Jennet Arshimova NEW HSE, with registered office at ul. Dereniowa 2/98, 02-776 Warsaw, NIP (Tax ID): 5842722630, REGON: 221529844

CONTACT WITH THE CONTROLLER

Email: biuro@newhse.pl
Phone: +48 785 330 705

Below is a glossary of terms used throughout this Policy. You can recognise them as they begin with a capital letter:

  • Controller – Jennet Arshimova, conducting sole proprietorship under the name Jennet Arshimova NEW HSE, with registered office at ul. Dereniowa 2/98, 02-776 Warsaw, NIP: 5842722630, REGON: 221529844.
  • Website – the website under the domain https://newhse.pl/ and its subpages.
  • Shop – the online store available under the domain https://akademiahse.pl/ and its subpages.
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC.
  • User – any person whose data is processed under the terms of this Policy.
  • Policy – this Privacy and Cookie Policy.

GENERAL PROVISIONS

The Controller ensures transparency in the processing of personal data. Users are informed about the processing of their personal data, including the scope, purpose, and legal basis for collection. Providing personal data is voluntary and depends on the User’s decision; however, in certain cases it may be necessary to access specific services and/or functionalities.

The Controller implements and maintains technical and organisational measures to ensure the protection of personal data processed, appropriate to the risks, threats, and categories of data. These measures are designed to prevent access, acquisition, or modification of personal data by unauthorised individuals, as well as to protect against data loss or damage. All personal data is processed in accordance with applicable data protection regulations, including the GDPR. The Controller ensures that personal data is collected only to the extent necessary for the purpose of processing. The Controller also verifies cooperating entities to ensure they provide an adequate level of data protection.

A Data Protection Officer has not been appointed, as there is no legal obligation to do so.

For any questions or suggestions regarding the operation of the Website and the content published on it, you may contact the Controller by email at: [email address].

SCOPE, PURPOSE, AND LEGAL BASIS FOR PERSONAL DATA PROCESSING

All User personal data is processed exclusively for the purpose for which it was collected, unless separate consent has been given for processing for other purposes.

Processing Activity What Data Is Processed? Purpose, Legal Basis, and Duration of Processing
Visiting the Website, Use of Cookies and Tracking Technologies IP address
Information contained in cookies or similar technologies
Anonymous browser and device data
Anonymous website traffic data, including specific subpages
Anonymous conversion data
Approximate geolocation
Anonymous behaviour on the Website
Data is processed to ensure the functionality of the Website, optimise its operation, and for marketing, analytical, and statistical purposes under Art. 6(1)(f) GDPR – the legitimate interest of the Controller, which is maintaining the website and direct marketing.
Data is processed until a valid objection is raised by the data subject, the purpose of processing is achieved, or data becomes outdated or no longer useful.
Contact via Email Email address
First and last name
Data provided in the message content
IP address
Data is processed to enable contact and ensure communication continuity under Art. 6(1)(f) GDPR – the legitimate interest of the Controller.
For archiving purposes to prove facts in the future – Art. 6(1)(f) GDPR – the legitimate interest of the Controller to defend or raise potential claims.
Until the expiration of the limitation period, typically 3 or 6 years + 1 year depending on whether the data concerns a business or individual.
Social Media First and last name
Data available on the User’s public profile
Content of messages, comments or posts
Data on activity on the Controller’s profile
Contact and communication under Art. 6(1)(f) GDPR – legitimate interest of the Controller.
Analytical and statistical purposes – marketing – until objection or fulfilment of purpose.
Archiving to demonstrate facts in the future under Art. 6(1)(f) GDPR – until claims expire (3/6 years + 1).
Own Marketing Data processed in “Social Media” and “Cookies and Tracking Technologies” sections
Image
For marketing activities: publishing content on social media, initiating direct communication, targeting advertisements – Art. 6(1)(f) GDPR.
For entering into a contract – Art. 6(1)(b) GDPR.
Analytical, statistical, and archiving purposes – Art. 6(1)(f) GDPR.
Until objection or fulfilment of purpose or claims expire.
User Account Email address
First and last name
Home address
Billing address
Phone number
Tax ID (NIP)
For contract execution – Art. 6(1)(b) GDPR – for duration needed to fulfil the order.
For issuing and using invoices for accounting – Art. 6(1)(c) GDPR – until expiry of statutory retention period.
For statistical and analytical purposes, identifying returning customers, and proving contract terms – Art. 6(1)(f) GDPR – until objection or limitation period ends.
Placing Orders and Performing Sales Agreements / Providing or Delivering Digital Content or Services Email address
First and last name
Residential address
Delivery address
Billing address
Phone number
Tax ID (NIP)
For placing and performing the contract – Art. 6(1)(b) GDPR – for the duration required to complete the order and perform the agreement.
For processing payments – Art. 6(1)(b) GDPR – for the duration required to complete the payment.
For issuing and storing invoices for accounting and tax purposes – Art. 6(1)(c) GDPR – until the end of the statutory retention period under the Accounting Act, Tax Ordinance, and other applicable laws.
For proving the content of the agreement and circumstances – Art. 6(1)(f) GDPR – the Controller’s legitimate interest – until limitation periods expire (3 or 6 years + 1).
Enrolment in Trainings Organised with The National Examination Board in Occupational Safety and Health (NEBOSH) Email address
First and last name
Residential address
Billing address
Phone number
Image
Passport data
For entering and performing the contract with the client and NEBOSH – Art. 6(1)(b) GDPR – for the duration required to fulfil the agreement.
For issuing and storing invoices (accounting obligations) – Art. 6(1)(c) GDPR – until the end of the statutory retention period.
For proving the content of the agreement – Art. 6(1)(f) GDPR – the Controller’s legitimate interest – until claims expire.
Complaint Process or Withdrawal from Contract Email address
First and last name
Residential address
Billing address
Phone number
Tax ID (NIP)
Bank account details
For handling complaints or exercising the right of withdrawal – Art. 6(1)(c) GDPR – until the procedure is completed.
For archiving documentation to demonstrate the process – Art. 6(1)(f) GDPR – the Controller’s legitimate interest – until limitation periods expire (3 or 6 years + 1).
GDPR Documentation All data referred to in section II of the Policy, excluding anonymous data To fulfil the legal obligation under data protection laws and GDPR – Art. 6(1)(c) GDPR – until expiry of the documentation obligation.
For future reference of documentation content – Art. 6(1)(f) GDPR – the Controller’s legitimate interest.
Accounting and Bookkeeping Email address
First and last name
Residential address
Billing address
Phone number
Tax ID (NIP)
Bank account details
To comply with accounting, bookkeeping, and tax obligations – Art. 6(1)(c) GDPR – until expiry of the statutory retention period.
For archiving purposes – Art. 6(1)(f) GDPR – the Controller’s legitimate interest in defending or raising potential claims – up to 3 or 6 years + 1.
Archiving and Evidentiary Purposes, Assertion or Defence Against Claims All personal data listed in this table where archiving or evidentiary purposes are indicated For fulfilling legal obligations under accounting and tax laws – Art. 6(1)(c) GDPR.
For archiving documents and proving their content in the future – Art. 6(1)(f) GDPR – the Controller’s legitimate interest – until limitation periods expire (3 or 6 years + 1).
Newsletter First and last name
Email address
Subscription date
Newsletter delivery information
Consent to receive commercial and marketing content – Art. 6(1)(a) GDPR.
Performance of newsletter service – Art. 6(1)(b) GDPR – for the duration of service or until the User unsubscribes.
Marketing own products or services, providing educational content, promotional offers – Art. 6(1)(f) GDPR – the Controller’s legitimate interest in direct marketing.
For archiving purposes – Art. 6(1)(f) GDPR – until claims expire (3 or 6 years + 1).

NEWSLETTER SERVICE PROVIDER

The newsletter service is provided by:

MailerLite Limited, Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593, Ireland.

Information on how this entity processes personal data can be found at:
Privacy Policy: https://www.mailerlite.com/legal/privacy-policy

Personal data will not be transferred outside the European Economic Area (EEA).

You may withdraw your consent at any time by unsubscribing from the newsletter. However, the data provided to the Controller prior to the withdrawal may continue to be processed in accordance with the principles outlined in this document.

COOKIES

Like many other websites, the Website uses cookies to ensure optimal performance and functionality, manage visitor sessions, and support promotional and statistical purposes.

When visiting the Website for the first time, the User is given the option to modify cookie settings. These settings may also be changed at any later time. Providing data is voluntary; however, in some cases (such as functional cookies), it is necessary for the Website to operate correctly.

First-party cookies belong to the Website and can be read by the Controller. The Controller also uses third-party services (listed in this Policy), some of which may read specific cookies for their own purposes, such as performance optimisation, content personalisation, or targeted advertising.

The Website uses both session cookies (temporary) and persistent cookies. Session cookies are stored until the browser or Website is closed. Persistent cookies are stored for a period defined in the cookie parameters.

If the User does not wish to share such data, they may browse the Website in incognito mode or use browser plugins to block tracking technologies. Users may also manually delete selected or all cookies.

More details on cookie management are available on the websites of popular browsers:

GOOGLE ANALYTICS

When visiting the Website, the Controller collects anonymous analytical and statistical data concerning page views, visited subpages, traffic sources, and user devices. Tools such as Google Analytics are used for this purpose.

If the User does not wish to share such information, they may browse the Website in incognito mode or use browser extensions that block tracking technologies.

The Controller uses the Google Analytics service provided by Google LLC, with registered office at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, for analytical and statistical purposes. Google Analytics operates by analysing services and online activities for marketing purposes. Information collected includes how Users navigate the Website, which browser they use, their operating system, time spent on the site, pages visited, and any errors experienced.

The data collected does not allow the identification of individual users. More details about the service can be found at: https://analytics.google.com/analytics/web/provision/?hl=pl#/provision

Personal data collected for analytical and statistical purposes is gathered automatically while browsing the Website. Google Analytics uses cookies. The cookie policy for Google Analytics is available here: [link not provided in source]

Google Analytics and Google Analytics 360 ensure an adequate level of personal data protection. Data may be transferred and stored on Google servers in the USA. Google states that it applies data protection mechanisms and safeguards in line with European legislation.

Detailed information on how data is used in websites and applications using Google services can be found at: [link not provided in source]

META PIXEL

The Meta Pixel service is provided by Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland. The Meta Pixel is a code snippet placed on the Website, which enables measurement, optimisation, and creation of advertising audiences. It activates during page load and sends anonymous information about user activity back to servers located in the USA. This may include visited pages, time spent on the site, and user actions (e.g., clicks, purchases).

By using Meta Pixel, the Controller may, based on a legitimate interest in direct marketing, monitor user behaviour on the Website, analyse campaign effectiveness, personalise ads, and optimise the user experience.

A user-friendly explanation of how Meta Pixel works can be found here: [link not provided in source]

SERVER LOGS

Using the Website also involves sending requests to the server on which the Website is hosted. These are known as server logs – files that record various actions and events on the server. The anonymous data stored in the logs may include the date and time of the event, IP address, session identifiers, HTTP request details, event type, diagnostic information, and browser or operating system data.

These logs help monitor, troubleshoot, and analyse server performance.

PROFILING

The Controller does not make decisions based on profiling.

ADMINISTRATOR’S SOCIAL MEDIA

When interacting with the Controller on social media, the Controller automatically obtains personal data available in the public profile of the interacting person or entity (e.g., by liking the Controller’s profile, leaving a comment, or sending a private message).

Providing such information is voluntary but necessary to interact with the Controller via social media. The Controller also processes data contained in private messages. In such cases, personal data may also be processed by these platforms outside the European Economic Area, including countries such as the USA and Canada.

  • Facebook – Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
  • Privacy Policy: [not provided]
  • Instagram – Meta Platforms Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland
  • Privacy Policy: https://help.instagram.com/515230437301944
  • LinkedIn – LinkedIn Corp., 1000 West Maude Avenue, Sunnyvale, 94085, United States
  • Privacy Policy: [not provided]

COOPERATION WITH NEBOSH

The Controller offers training courses in cooperation with NEBOSH (The National Examination Board in Occupational Safety and Health), a UK-based awarding body established in 1979, providing globally recognised qualifications in occupational health and safety, environmental protection, and risk and wellbeing management.

With regard to personal data processing, the Controller and NEBOSH act as independent data controllers, each deciding individually on the purposes and means of personal data processing in the context of their operations. Personal data is not co-administered under Article 26 GDPR.

NEBOSH’s privacy policy is available at:
https://www.nebosh.org.uk/privacy-policy/

TARGETED ADVERTISING

The Controller uses targeted (behavioural) advertising based on anonymous analytical data collected by third-party providers, including:

  • Google Ads (Google LLC)
  • Facebook and Instagram Ads (Meta Platforms Ireland Limited)
  • Microsoft Advertising / Bing Ads (Microsoft Ireland Operations Limited)
  • LinkedIn Ads (LinkedIn Ireland Unlimited Company, a Microsoft subsidiary)

These entities process data according to their own privacy policies, linked earlier in this Policy. Details regarding the processing of anonymous data are also provided in the section: “Visiting the Website, Use of Cookies and Tracking Technologies.”

DATA RETENTION PERIODS

The retention periods for personal data are defined individually for each of the processing purposes listed above. After the retention period expires, the Controller will irreversibly delete or anonymise the data.

For more information about specific retention periods, you may contact the Controller via email.

USER RIGHTS

In accordance with the GDPR, individuals whose data is processed by the Controller have several rights. However, due to the provisions of the law, these rights do not always apply unconditionally.

To exercise your rights, you may contact the Controller by email.

The following table outlines your rights:

User Right What It Means Legal Basis
Right of access You have the right to request information on whether your personal data is being processed. You also have the right to access your data. Art. 15 GDPR
Right to receive a copy of the data You have the right to receive a copy of your personal data in a structured, commonly used, and machine-readable format. Art. 15(3) GDPR
Right to rectification You may request that inaccurate personal data be corrected or incomplete data be completed. Art. 16 GDPR
Right to erasure You may request the deletion of your data when there is no longer a legal basis for processing or when the data is no longer needed for processing purposes. Art. 17 GDPR
Right to restrict processing You have the right to request restriction of your data processing, for example when you contest the accuracy of the data, or processing is unlawful, or you object to processing. Art. 18 GDPR
Right to data portability You may request that your data be transmitted to another controller (under certain conditions). Art. 20 GDPR
Right to object You have the right to object to the processing of your personal data. Art. 21 GDPR
Right to withdraw consent You may withdraw your consent to data processing at any time without giving a reason. Any processing carried out before the withdrawal remains lawful. Art. 7(3) GDPR
Right to lodge a complaint If you believe your data is being processed unlawfully, you may lodge a complaint with the competent supervisory authority: President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland.
Website: https://www.uodo.gov.pl/pl/p/kontakt
Phone: +48 (22) 531 03 00
Art. 77 GDPR

THIRD-PARTY ACCESS

Personal data collected by the Controller may be accessed by entities whose services are used to conduct business activities. Where required, these entities process data based on data processing agreements in accordance with the law. These entities ensure an appropriate level of personal data protection.

Data may also be disclosed to entities authorised by law, including judicial authorities and legal professionals bound by professional secrecy if necessary.

Due to the dynamic nature of business, data may also be processed by partners providing legal, technical, and substantive support.

Entities processing data within the European Economic Area (EEA):

  • Hosting provider: lh.pl, NIP 7831711517, REGON 302693647
  • Email provider: Microsoft Ireland Operations Limited
  • Invoicing system provider: Fakturownia Sp. z o.o., NIP 5213704420, REGON 362333847
  • Accounting services: EASY TAX Biuro Rachunkowe, NIP 6191641798, REGON 147157288
  • IT technical support: ProfProjekt sp. z o.o.
  • Newsletter provider: MailerLite Limited, Dublin 2, Ireland

Entities processing data outside the EEA:

Data processing outside the EEA is conducted by entities listed below. They guarantee an adequate level of data protection under GDPR. Transfers are based on standard contractual clauses approved by the European Commission (Art. 46(2) GDPR).

  • Google Analytics, Google Worksheet
    Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
  • Facebook, Instagram
    Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02X525, Ireland
  • NEBOSH (The National Examination Board in Occupational Safety and Health)
    Dominus Way, Meridian Business Park, Leicester, Leicestershire LE19 1QW, UK
  • LinkedIn
    LinkedIn Corp., 1000 West Maude Avenue, Sunnyvale, 94085, United States

POLICY UPDATES

The Controller reserves the right to amend or supplement this Policy as needed — e.g. due to changes in law, organisational, or technical reasons. In case of changes, the date of the last update will be indicated at the beginning of this document.

FINAL PROVISIONS

The materials posted on this website, including this Policy, are protected by copyright, particularly under the Polish Act of 4 February 1994 on Copyright and Related Rights.

The previous version of the Privacy Policy, valid until 08/05/2025, is available here:
https://newhse.pl/polityka-prywatnosci-archive/

Controller