Privacy Policy
This Privacy Policy defines the rules for processing personal data obtained via the website gr8direction.com, hereinafter referred to as the “Website”.
The owner of the website and the Data Controller is Magdalena Nowak Firma Usługowa Inter Level, 35-602 Rzeszów, ul. Jadwigi Smosarskiej 15A, NIP: 6292102293, hereinafter referred to as the Controller.
Personal data collected by the Controller via the Website is processed in accordance with Regulation (EU) 2016/679 (GDPR).
The Controller makes every effort to respect the privacy of Clients visiting the Website.
§ 1 Types of processed data, purposes and legal basis
The Controller collects information concerning individuals (including sole traders) and representatives of legal persons, collectively referred to as Clients.
The Controller processes personal data when using the contact form on the Website in order to perform a contract or take steps prior to entering into a contract — legal basis: Article 6(1)(b) GDPR.
When using the contact form, the Client provides:
email address
first name
phone number
While using the Website, additional information may be collected, in particular: IP address, domain name, browser type, access time, operating system type, navigation data (clicked links, actions) — for technical/admin/analytics/statistics purposes; legal basis also Article 6(1)(f) GDPR (legitimate interest: IT security, website management and improvement).
§ 2 Data recipients
Client data may be transferred to service providers used by the Controller to run the Website. Depending on arrangements, they act either as processors or as separate controllers.
1.1. Processors: e.g., hosting, accounting, marketing systems, website traffic analytics, marketing campaign effectiveness analytics.
1.2. Controllers: e.g., electronic payments and banking services.
Location: providers are mainly based in Poland and other EEA countries.
Upon request, the Controller may share data with authorized public authorities (e.g., prosecutor’s office, police, the President of the Personal Data Protection Office, etc.).
§ 3 Data retention period
Client personal data is stored:
1.1. If the basis is consent — until consent is withdrawn, and afterwards for the limitation period for claims (generally 6 years; for periodic claims and business-related claims — 3 years).
1.2. If the basis is performance of a contract — as long as necessary to perform the contract, and afterwards for the relevant limitation period (generally 6 years; periodic/business-related claims — 3 years).
§ 4 Cookies mechanism, IP address
The Website uses small files called cookies. Cookies are stored on the end device if the browser allows it. A cookie usually contains the domain name, expiry time, and an identifier. Cookies help tailor the offer to preferences and needs.
The Controller uses two types of cookies:
2.1. Session cookies — removed after the browser session ends.
2.2. Persistent cookies — stored until deleted or expired.
The Controller uses own cookies for analytics, research, and audience measurement (anonymous stats) to improve structure and content.
The Controller uses third-party cookies for displaying a map of the office location via maps.google.com (Google Inc., USA).
Cookies are safe; however, users can limit/disable cookies in their browser (then some cookie-dependent functions may not work).
The Controller may collect IP addresses for technical diagnostics, statistical analysis, administration, improvements, security, and identifying abusive automated browsing programs.
§ 5 Rights of data subjects
Data subjects have the right to:
Withdraw consent at any time (withdrawal applies from the moment of withdrawal and does not affect earlier lawful processing; may limit further use of consent-based features).
Object to processing (including profiling) based on Article 6(1)(e) or (f) GDPR; unsubscribing from marketing emails is treated as an objection for marketing/profiling.
Erasure (“right to be forgotten”) under conditions listed in the policy, with possible retention for legal claims or obligations.
Restriction of processing in defined cases.
Access to data and obtaining a copy.
Rectification of inaccurate data and completing incomplete data (via email per §6).
Data portability (Controller may provide data in CSV format, machine-readable).
Lodge a complaint with the President of the Personal Data Protection Office.
9–10. The Controller responds without undue delay (no later than one month; may extend by two months with explanation). Complaints/questions can be submitted to the Controller.
§ 6 Changes to the Privacy Policy
The Privacy Policy may change and the Controller is not obliged to inform about it.
Questions regarding the Privacy Policy should be sent to: nowakmagda987@gmail.com
Last modification date: 15.07.2025