Information on personal data processing for our business partners

Information on personal data processing for business partners

Pursuant to Article 13(1-2) and Article 14(1-2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (OJ UE L 119/1, 4.05.2016), hereinafter "GDPR", please be advised that:

I. The Controller of your personal data is PGE Paliwa sp. z o.o. with its registered office in Kraków (31-587), ul. Ciepłownicza 1.

II. With regard to the protection of your personal data, you may contact the Data Protection Officer at the email address: iod.pgepaliwa@gkpge.pl or in writing at the address of our registered office indicated in paragraph I above or through the contact forms available on this website.

III. Data source.

Personal data not obtained directly from you may originate:

  1. from your employer/principal who has entered into a contract with the Controller for the provision of a specific service for the performance of which it is necessary to provide your contact details, as well as additional information in the case of the performance of work on the premises of our Company;
  2. from publicly available sources (e.g. the CEDiG and KRS registers);
  3. from persons representing you on the basis of a power of attorney granted by you.

IV. Objectives and basis of processing.

We will process your personal data:

  1. On the basis of Article 6(1)(a) of the GDPR (consent), where you voluntarily consent to the processing of data for specific purposes.
  2. On the basis of Article 6(1)(b) of the GDPR for the purpose of entering into and performing a contract with the Controller.
  3. On the basis of Article 6(1)(c) of the GDPR (legal obligation to which the Controller is subject), in particular for the purpose of complying with requests from law enforcement authorities and for the purposes of legal proceedings, as well as to comply with other obligations imposed on the Controller under the generally applicable legal regulations (including tax regulations).
  4. On the basis of Article 6(1)(f) of the GDPR (legitimate interest):
    a. for archival (evidential) purposes, being the fulfilment of the Controller's legitimate interest to safeguard information in the event of a legal need to prove facts,
    b. for the purpose of establishing, pursuing or defending claims,
    c. for the purpose of facilitating communication among PGE Capital Group entities,
    d. for the purpose of ensuring security on the employer's premises (including the strengthening of its image),
    e. for the purpose of exchanging correspondence, including electronic correspondence, e.g. in order to conduct negotiations, make arrangements,
    f. for analytical purposes (e.g. optimisation of service processes, collection of general information on customers, financial analysis, etc.),
    g. for statistical purposes,
    h. for administrative purposes of the Seller constituting the pursuit of the Seller's legitimate interests (based on Article 6(1)(f) of the GDPR). 

V.  Data categories. 

Depending on the purpose for which your personal data will be processed, we will process the following categories of data:

  1. data processed for contact purposes: basic identification data, including contact details (e.g. forename, surname, email address, telephone number, official position);
  2. data processed for the purpose of performing a contract and carrying out work for the benefit of the Company (including carrying out health and safety training): identification data, including contact details as mentioned above, as well as information about skills and qualifications, the expiry dates of medical certificates;
  3. data processed for the purpose of ensuring security on the Company's premises: additional identification data, including PESEL no. / series and number of an identity document, a vehicle registration number and image.

VI.Right to object.

You have the right at any time to lodge an objection against the processing of your data processed on the basis of  Article 6(1)(f) of the GDPR for the purposes indicated above. We will stop processing your data for these purposes unless we can demonstrate that there are compelling legitimate grounds that override your interests, rights and freedoms, or that your data will be necessary for the Controller to possibly establish, pursue or defend claims.

VII. Recipients of data. 

Your personal data may be transferred to:

a. institutions, entities or persons in cases in which the Controller is obliged to transfer the data in accordance with the legal regulations;
b. entities from the PGE Capital Group, in particular PGE Polska Grupa Energetyczna S.A., to the extent necessary for contact purposes (joint venture, project, exercise of corporate governance);
c. partners and contractors of the Controller to the extent necessary for contractual purposes;
d. processors who provide services to the Controller, including those to whom the data are entrusted, e.g. PGE Polska Grupa Energetyczna S.A., PGE Systemy S.A.;
e. debt purchasers.

VIII. Transfer of personal data outside the EEA. 

In principle your personal data will not be transferred outside the European Economic Area (hereinafter: EEA). However, taking into account the IT services provided by PGE Systemy as a Shared Services Centre within the PGE Capital Group, the performance of specific IT activities or tasks by this subcontractor may result in the transfer of data outside the EEA. For more information on possible data transfer and how to secure it, please contact PGE Systemy S.A.

IX. Data retention period.

Personal data will be processed for the following periods of time:

a. data processed for the purpose of contract performance - until the statute of limitations for claims arising under a contract, for the time necessary to pursue or defend such claims;
b. data processed on the basis of a legal regulation - for the period resulting from the generally applicable law;
c. data processed on the basis of the Controller's legitimate interest - for the time necessary to achieve the purpose or for you to make an effective objection;
d. in the case of data processed on the basis of the given consent - until the consent is withdrawn or it is determined that the data have become obsolete.

X. Rights of data subjects.

Pursuant to the GDPR, you have the following rights:

a. to request access to your data and to receive a copy of your data,
b. to request the rectification (correction) of your data,
c. to request that your data be deleted or restricted, or to lodge an objection to their processing,
d. to request that your data be transferred,
e. to lodge a complaint with the supervisory authority.

XI. Information on the voluntary provision of data. 

In the case of the processing of data obtained directly from you, the provision of data is:

a. necessary for the conclusion and performance of a contract or for any other purpose related to the processing of data in accordance with paragraph III above,
b. voluntary with regard to the processing of personal data based on your consent (you have the right to withdraw your consent at any time).

XII. Automated decision-making. 

Please be advised that we do not make automated decisions for the above purposes and your data is not used for profiling purposes.

XIII. Consent and information about the possibility of withdrawing your consent. 

Consent and information about the possibility of withdrawing your consent. You have the right to withdraw your consent to the processing of your personal data on the basis of your consent at any time, but the withdrawal of your consent does not affect the lawfulness of the processing performed on the basis of your consent prior to its withdrawal.

 

Data Protection Officer – Mariusz Lach 

iod.pgepaliwa@gkpge.pl