Personal data processing policy
1.1.Controller – Nextbike Polska S.A. with its registered seat in Warsaw, ul. Przasnyska 6b, 01-756 Warsaw.
1.2.Mobile Application – mobile application available on mobile phones and portable devices, offered by the Controller for devices operating within Android and iOS systems.
1.3.Personal data – all information about a natural person identified or identifiable by one or more specific factors determining a physical, physiological, genetic, psychological, economic, cultural or social identity, including IP of device, location data, internet identifier, information collected via cookies files and by means of another similar technology.
1.4.Nextbike Group – companies belonging to the Nextbike group in the meaning of art. 4 point 14 of the Act of 16 February 2007 on protection of competition and consumers.
1.5.Client – natural person, participant of the municipal bike system who has accepted Terms of Service and carried out registration in the municipal bike system as well as concluded Agreement with the Operator.
1.6.Operator – entity realizing services related to maintenance of municipal bike systems.
1.8.Terms of Service of the Kajteroz – Chorzowski Rower Miejski System– document specifying the principles and conditions of use of the system of urban bikes, in particular in the scope of the rights and obligations and the responsibility of persons availing of the services of urban bike rentals, the Operator of which is the Controller. Terms of Service shall be available at the following address wwww.kajteroz.pl/en/terms.
1.9.GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
1.10.Service – internet service located at the address www.kajteroz.pl or available by means of Mobile Application through which the Controller provides services electronically to Users, in particular, the service consisting of facilitating the conduct of urban bikes’ rental.
1.11.Agreement with the Operator – Agreement between Client and Operator, established by means of the Service, which specifies mutual rights and obligations, as defined in the Terms of Service.
1.12.Act – Act from 10 May 2018 on Personal Data Protection (Journal of Laws from 2018, item 1000).
1.13.User – each natural person visiting the Service or availing of one of several services or functionalities, specified in the hereby Policy.
1.14.Trusted Partner – entity cooperating with the Controller, whose marketing contents are directed by the Controller towards Clients and Users.
2.PROCESSING OF DATA IN RELATION TO THE USE OF THE SERVICE
2.1.In relation to the use by the User of the Service, the Controller gathers data in the scope necessary for the provision of individual offered services as well as information on User activity in the Service. Detailed principles and purposes of the processing of Personal Data gathered during the use of Services by the User have been specified below.
3.PURPOSES AND LEGAL BASES FOR THE PROCESSING OF DATA IN THE SERVICE
USE OF SERVICE
3.1.Personal data of all persons availing of the Service (including the IP address or other identifiers and information stored by means of the cookies files or other similar technologies), which are not registered Users (that is persons who do not have a set up profile within the Service), are processed by the Controller:
3.1.1.in order to provide services electronically in the scope of making available to users the contents collected on the website – in such case the legal basis for processing is the necessity of processing in order to implement the agreement (article 6, paragraph 1(b) of the GDPR);
3.1.2.for analytical and statistical purposes – in such case the legal basis for processing is the justified interest of the Controller (article 6, paragraph 1(f) of the GDPR), consisting of conducting the analysis of users’ activity, as well as their preferences in order to improve the used functionalities and provided services;
3.1.3.in order to possibly determine and pursue claims or defend against them – the legal basis for the processing is justified interest of the Controller (article 6, paragraph 1(f) of GDPR), consisting of the protection of its rights;
3.1.4.for marketing purposes of the Controller and other entities – rules for the processing of personal data for marketing purposes have been described in the “Marketing” section.
3.2.The User’s activities in the Service, including their Personal data, are recorded in system logs (special computer programme intended for the storing of chronological record containing information about events and activities concerning the IT system used to provide services by the Controller). Information collected in the logs are processed mainly for the purposes associated with the provision of services. The Controller also processes them for technical and administrative purposes, in order to ensure the security of the IT system, as well as management of this system, and also for analytical and statistical purposes – in this scope the legal basis for processing is the legally justified interest of the Controller (article 6, paragraph 1(f) of the GDPR).
REGISTRATION IN THE KAJTEROZ – CHORZOWSKI ROWER MIEJSKI SYSTEM
3.3.Persons who carry out registration in the Kajteroz – Chorzowski Rower Miejski System are asked to indicate data necessary for the creation and servicing of their account, which is administered by the Operator. Such data may be deleted at any time. Providing data marked as obligatory is required in order to set up and maintain the account, and failure to provide such data results in a lack of the possibility to set up such an account. Indication of the remaining data is voluntary.
3.4.Personal data are processed:
3.4.1.for the purpose of providing services related to the maintenance and servicing of an account within the Kajteroz – Chorzowski Rower Miejski System – legal basis for the processing is the necessity to process data for the execution of agreement (art. 6 sec. 1 letter b of GDPR);
3.4.2.fulfilling public-legal obligations resting on the Controller, above all, those stemming from the accounting provisions and tax provisions – the legal basis for the processing will be the necessity to fulfil legal obligations resting on the Controller (art. 6 sec. 1 letter c of GDPR);
3.4.3.for analytical and statistical purposes – legal basis for the processing shall be the legally justified interest of the Controller (art. 6 sec. 1 letter f of GDPR), consisting of the conduct of analyses of User activities in the Service and the way the accounts are used, as well as User preferences for the purpose of improving the applied functionalities;
3.4.4.ensuring the possibility of monitoring the locations at which bikes are rented or to which they are returned to in the Kajteroz – Chorzowski Rower Miejski System or verification by means of GPS system where a given bike is located in case of lack of its return – legal basis for the processing shall be the legally justified interest of the Controller (art. 6 sec. 1 letter f of GDPR); legally justified interest of the Controller is the protection of material interest through gathering information which enable locating a given bike;
3.4.5.in order to possibly determine and pursue claims or defend against them – the legal basis for processing is the justified interest of the Controller (art. 6 sec. 1 letter f of GDPR) consisting of the protection of its rights;
3.4.6.for marketing purposes of the Controller and other entities – rules for the processing of Personal data for marketing purposes have been described in the MARKETING section.
3.5.If a User places any sort of Personal data of other persons in the Service (including their first name, surname, address, telephone number or email address), they may do so solely under the condition of abiding by the provisions of the law and the rights of publicity to which these persons are entitled.
3.6.The Controller provides the possibility of contacting him with the use of electronic contact forms. Using the form requires providing Personal data, necessary for establishing contact between the User and for replying to the inquiry. The User may also provide other data in order to facilitate contact or enable handling of the inquiry. Providing data marked as obligatory is required in order to receive and handle the inquiry, and failure to provide such data results in the lack of possibility to handle such inquiry. Indication of the remaining data is voluntary.
3.7.Personal data are processed:
3.7.1.for the purpose of identifying the sender and handling their submitted inquiry by means of the available form – the legal basis for the processing shall be the necessity of processing for the execution of agreement on provision of service (art. 6 sec. 1 letter b of GDPR); in the scope of data indicated voluntarily the legal basis for their processing shall be the consent (art. 6 sec. 1 letter a of GDPR)
3.7.2.for analytical and statistical purposes – the legal basis for the processing shall be the legally justified interest of the Controller (art. 6 sec. 1 letter f of GDPR), consisting of the maintenance of statistics of inquiries submitted by Users by means of the Service for the purpose of improving its functionality.
4.1.The Controller processes Personal Data of Users for the purpose of realizing marketing actions which consist of carrying out actions related to the direct marketing of goods and services (sending commercial information electronically and telemarketing actions).
4.2.Personal data of Users may be used by the Controller in order to direct at them marketing content of entities from Nextbike Group as well as entities cooperating with the Controller on various channels, such as by means of an electronic post, including in the form of a newsletter, via text and MMS messages or via telephone. Such actions shall be undertaken by the Controller solely in case when the User has expressed consent which may be withdrawn by them at any time.
4.3.The list of entities forming part of the Nextbike Group and entities cooperating with the Controller may be found in section “NEXTBIKE Group and entities cooperating with the Controller” of our Policy of Transparency.
4.4.In order to realize marketing actions the Controller uses profiling in certain cases. This means that thanks to automated processing of data, the Controller performs an assessment of the selected factors concerning the Users in order to analyse their behaviours or create prognosis for the future. This allows for a better adjustment of the displayed content to the individual preferences and interests of Users.
5.1.The Controller processes Personal data of the Users visiting the Controller’s profile accounts in the social media (Facebook, YouTube, Instagram, Twitter). Such data are processed only in connection with the running of a given profile, including to inform Users about the activity of the Controller and to promote various types of events, services and products. The legal basis for the processing of Personal data by the Controller for this purpose is his justified interest (article 6, sec. 1, letter f of GDPR), consisting of promoting his own brand.
6.COOKIES FILES AND SIMILAR TECHNOLOGY
6.1.Cookies are small text files installed on a device of User browsing the website. Cookies collect information that facilitate the use of a given website – e.g. through memorizing User’s visits in the Service and the activities carried out by them.
6.2.1.cookies files with data entered by a given User (session identifier) for the duration of a given session (user input cookies);
6.2.2.authentication cookies used for services requiring authentication for the duration of a given session (authentication cookies);
6.2.3.cookies used to ensure security, e.g. used to detect abuses in the scope of authentication (user centric security cookies);
6.2.4.session cookies for multimedia players (e.g. flash player cookies), for the duration of a given session (multimedia player session cookies);
6.2.5.permanent cookies used to personalize User interface for the duration of a given session or a little longer (user interface customization cookies).
6.3.The Controller and its trusted partners also apply cookies files for marketing purposes, such as pursuant to directing behavioural advertising towards Users. For this purpose, the Controller and its trusted partners store information or obtain access to information already stored in an end telecommunication device of a given User (computer, telephone, tablet etc.)
7.1.The Controller processes personal data of Clients in the scope of location for the purpose of ensuring the possibility of control of location at which bikes were rented or to which they were returned within the system of urban bikes with the use of GPS system or verification, where a bike is located in case of lack of its return – legal basis for the processing will be the legally justified interest of the Controller (art. 6 sec. 1 letter f of GDPR); legally justified interest of the Controller is the protection of material interest through gathering information which enable locating a bike,
8.ANALITICAL AND MARKETING TOOLS APPLIED BY THE CONTROLLER AND ITS PARTNERS
8.2.Google Analytics cookies are the files which are used by Google in order to analyse how a User uses the website, to generate statistics and reports regarding the functioning of the Service. Google does not use the collected data to identify Users and it does not combine these information in order to allow identification. Detailed information about the scope and rules of data collection in connection with this service may be found at: https://www.google.com/intl/pl/policies/privacy/partners.
8.3.Google Adwords is a tool which enables the measurement of efficiency of advertising campaigns realized by the Controller, allowing to analyse such data as, for instance, keywords or number of unique users. Google Adwords platform also allows for a display of our advertisements to person who visited our Service in the past. Information on the processing of data by Google in the scope of the above specified service are available at: https://policies.google.com/technologies/ads?hl=pl.
8.4.Facebook pixels is a tool which enables measurement of the efficiency of advertising campaigns realized by the Controller on Facebook. This tool allows for an advanced data analysis for the purpose of optimizing actions of the Controller also with the use of other tools offered by Facebook. Detailed information on the subject of data processing by Facebook may be found at:
8.5.The Service uses plug-ins to social media portals (Facebook, Google+, LinkedIn, Twitter). Plug-ins allow Users to disclose the content published in the Service in the selected social media. Application of plug-ins by the Service causes that a given social media obtains information on the use of Service by a given User and such information may be assigned to the profile of a given User, created in that social media portal. The Controller does not possess any knowledge regarding the purpose and scope of data gathering by social media portals. Detailed information on this topic may be found at the following links:
9.MANAGING COOKIES SETTINGS
9.2.No permission is required solely in case of cookies files the applying of which is necessary for the provision of telecommunication service (data transmission for the purpose of content display).
9.3.1.Internet Explorer: https://support.microsoft.com/pl-pl/help/17442/windows-internet-explorer-delete-manage-cookies
9.3.2.Mozilla Firefox: http://support.mozilla.org/pl/kb/ciasteczka
9.3.3.Google Chrome: http://support.google.com/chrome/bin/answer.py?hl=pl&answer=95647
9.4.The User may verify the status of their current privacy settings at any time with regards to the used browser, by means of the tools available at:
10.PERIOD OF THE PERSONAL DATA PROCESSING
10.1.The period of data processing by the Controller depends on the type of provided service and the purpose of processing. As a rule, data are processed for the period of provision of service or realization of order, until the time of withdrawal of the granted consent or submission of effective objection towards the processing of data in cases when the legal basis for the processing of data is the legally justified interest of the Controller.
10.2.The data processing period may be extended in case, when the processing is necessary to establish or pursue potential claims or defend against claims, and after this period – only in the case and to the extent that it will be required by the provisions of law. After expiry of the processing period, the data are irreversibly deleted or anonymised.
11.1.The User shall be entitled to access the content of data and demand their amendment, removal, limiting of their processing, the right to transfer data and the right to submit an objection towards their processing as well as the right to submit a complaint to the supervisory body dealing with personal data protection.
11.2.In the scope in which User data are processed pursuant to their consent, they may withdraw it at any time by contacting the Controller.
11.3.The User is entitled to submit an objection against the processing of data for marketing purposes should such processing occur pursuant to the legally justified interest of the Controller, as well as – due to reasons related to a particular situation of a given User – in other cases when the legal basis for the processing of data is the legally justified interest of the Controller (i.e. in relation to the realization of analytical and statistical purposes).
11.4.More information on the entitlements stemming from GDPR may be found within our Transparency Policy.
12.1.Pursuant to the realization of services, Personal data shall be disclosed to external entities, including in particular entities from Nextbike Group, entities cooperating with the Controller (the so called trusted partners), providers responsible for servicing IT systems, entities such as banks and payment operators, entities providing accounting services, marketing agencies (in the scope of marketing services).
12.2.In case of obtaining consent from a User, their data may also be disclosed to other entities for their own purposes, including marketing purposes.
12.3.The Controller reserves the right to disclose selected information regarding Users to competent authorities or third parties who will submit a request for providing such information in accordance with an appropriate legal basis and pursuant to the provisions of applicable law.
13.TRANSFER OF DATA OUTSIDE THE EEA
13.1.The level of personal data protection outside the European Economic Area (EEA) differs from that provided by the European law. Due to that fact, the Controller transfers personal data outside the EEA only when it’s necessary and subject to ensuring an adequate level of protection, mainly through:
13.1.1.cooperation with entities processing personal data in countries in regard to which an appropriate decision of the European Commission has been issued concerning ensuring adequate degree of personal data protection;
13.1.2.use of standard contractual clauses issued by the European Commission;
13.1.3.application of binding corporate rules approved by a competent supervisory authority;
13.1.4.in the case of data transfer to the USA – cooperation with entities participating in the Privacy Shield program, Approved by the European Commission.
14.SECURITY OF PERSONAL DATA
14.1.The Controller carries out on an ongoing basis market analysis for the purpose of ensuring that Personal data are processed by them in a safe manner – ensuring above all that access to data is granted solely to authorized persons and exclusively in the scope in which it is necessary, due to the tasks carried out by them. The Controller shall take steps to ensure that all operations on Personal data are registered and made solely by authorized employees and collaborators.
14.2.The Controller also undertakes all necessary actions to ensure that its subcontractors and other cooperating entities provide guarantee of using appropriate security measures in every case, when they process personal data on behalf of the Controller.
15.1.The Controller may be contacted by means of the following e-mail address firstname.lastname@example.org, via contact form at www.nextbike.pl , via telephone, at 22 208 99 90 or in writing at the address of the seat of Nextbike Polska S.A.
15.2.The Controller appointed Data Protection Officer, who may be contacted using the following
e-mail address: email@example.com regarding any matter concerning personal data processing.
16.1.This policy is verified on an ongoing basis and it is updated if such a need occurs.
16.2.The current version of this Policy was adopted on 5 April 2019.