PRIVACY AND COOKIES POLICY

Website www.beesset.com

Last updated: 2 September 2026

1. Personal Data Controller

The controller of the personal data of users of the website www.beesset.com is:

Beesset sp. z o.o.
ul. Gen. Gustawa Orlicz-Dreszera 1 lok. 10
15-797 Białystok
Poland
Tax Identification Number (NIP): 9662111772
e-mail: office@beesset.com

hereinafter referred to as the “Controller”, “Beesset” or the “Company”.

For matters concerning personal data protection, the exercise of rights arising from data protection legislation or this Privacy Policy, you may contact the Controller at office@beesset.com or in writing at the Company’s registered office address.

2. Basic Principles of Personal Data Processing

The Controller processes personal data in accordance with applicable law, in particular:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”);
  • the Polish Act of 10 May 2018 on Personal Data Protection;
  • the Polish Act of 12 July 2024 – Electronic Communications Law (“PKE”).

The Controller processes personal data solely for specified and lawful purposes and only to the extent necessary to achieve those purposes.

3. What Data We May Process

Depending on how the Website is used and the nature of the contact with Beesset, we may process, in particular:

  • first name and surname;
  • e-mail address;
  • telephone number;
  • company or institution name;
  • position or function;
  • data provided in the contact form or correspondence;
  • data related to entering into and performing a contract;
  • billing, accounting and tax data;
  • IP address;
  • information about the device, operating system and browser;
  • information regarding the manner in which the Website is used;
  • data concerning consents given and privacy preferences;
  • information collected using cookies and similar technologies.

The scope of the data processed depends on the specific purpose of processing.

4. Purposes and Legal Bases for Processing Personal Data

4.1. Contact Form, E-mail and Telephone Contact

If a user contacts Beesset using the contact form, e-mail, telephone or otherwise, the personal data provided are processed for the purpose of:

  • responding to an enquiry;
  • conducting correspondence;
  • handling a request or notification;
  • providing information about products or services;
  • taking steps aimed at entering into a contract.

The legal basis for processing is:

  • Article 6(1)(b) GDPR – where the contact concerns taking steps at the request of the data subject prior to entering into a contract or the performance of a contract;
  • Article 6(1)(f) GDPR – in other cases, as the Controller’s legitimate interest consisting in conducting communication, responding to enquiries and assisting persons interested in the Company’s activities.

Providing data through the contact form is voluntary, but failure to provide data necessary for contact may make it impossible to respond.

No separate consent to the processing of personal data is required for sending an ordinary enquiry via the contact form if the data are processed on one of the legal bases indicated above.

4.2. Entering Into and Performing a Contract

The data of customers and contractors who are natural persons are processed for the purpose of entering into and performing a contract, including communication related to its performance.

The legal basis is Article 6(1)(b) GDPR.

4.3. Representatives, Employees and Contact Persons of Contractors

If a user is a representative, employee or contact person designated by a customer, contractor or business partner of Beesset, their data may be processed on the basis of Article 6(1)(f) GDPR. In such a case, the Controller’s legitimate interest consists in maintaining business cooperation, communicating with the contractor and ensuring the proper performance of contracts.

The data may be obtained directly from the data subject, from their employer or the entity they represent, as well as from publicly available registers and sources, such as the National Court Register (KRS) or the Central Register and Information on Economic Activity (CEIDG).

4.4. Legal, Tax and Accounting Obligations

Personal data may be processed for the purpose of fulfilling legal obligations imposed on the Controller, in particular those arising from tax, accounting and business activity regulations.

The legal basis is Article 6(1)(c) GDPR.

4.5. Establishment, Exercise and Defence of Legal Claims

Personal data may be processed for the purpose of establishing, pursuing or defending against claims related to the Company’s activities.

The legal basis is Article 6(1)(f) GDPR, and the Controller’s legitimate interest consists in protecting its rights and interests.

4.6. Ensuring the Security and Proper Operation of the Website

Technical data concerning the use of the Website, including the IP address and information regarding the device and browser, may be processed for the purpose of:

  • ensuring the proper operation of the Website;
  • ensuring the security of IT systems;
  • detecting errors and failures;
  • preventing abuse and unauthorised access.

The legal basis is Article 6(1)(f) GDPR – the Controller’s legitimate interest consisting in maintaining the security and proper functioning of the Website.

5. Newsletter

Beesset may enable users to subscribe to a newsletter. If a user subscribes to the newsletter, the Controller will process the user’s e-mail address and, if the subscription form contains additional fields, also the data voluntarily provided in those fields. The data will be used to send newsletters, information about Beesset’s activities, new services, solutions, projects, events and other commercial or marketing information.

The legal basis for processing personal data for this purpose is the user’s consent – Article 6(1)(a) GDPR. The sending of newsletters and commercial information by means of electronic communication takes place after obtaining the required prior consent in accordance with the provisions of the Electronic Communications Law.

Subscription to the newsletter is voluntary.

The user may unsubscribe from the newsletter at any time by using the unsubscribe mechanism available in the messages sent or by contacting the Controller at office@beesset.com. Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal. The Controller may retain information about consent having been given and subsequently withdrawn for the period necessary to demonstrate the Controller’s compliance with the law and until the expiry of limitation periods for any potential claims.

6. Cookies and Similar Technologies

The Website uses cookies and similar technologies used to store or access information on the user’s device. Depending on their function, the following categories of technologies may be used:

6.1. Necessary Technologies

Technologies necessary for the proper and secure operation of the Website and for providing functions explicitly requested by the user. To the extent that personal data are processed through their use, the legal basis may be Article 6(1)(f) GDPR, i.e. the Controller’s legitimate interest related to ensuring the operation and security of the Website.

In cases provided for under the Electronic Communications Law, the use of technologies necessary for transmitting a communication or providing a service explicitly requested by the user does not require separate consent.

6.2. Analytics Technologies

Analytics technologies enable the Controller to obtain information on how the Website is used, the number of visits, the popularity of individual subpages and how users navigate the Website. They help analyse and improve the operation of the Website. Analytics technologies that are not necessary for the operation of the Website are activated after obtaining the user’s appropriate consent.

With regard to the processing of personal data, the legal basis is Article 6(1)(a) GDPR, while the storage of or access to information on the user’s device takes place in accordance with the provisions of the Electronic Communications Law.

6.3. External Content and Services

The Website may use content supplied by external providers, such as maps or video materials. If activating such content involves the use of non-essential cookies or similar technologies, the content is activated only after obtaining the required consent from the user.

6.4. Consent Management

The user may consent to individual categories of technologies during their first visit to the Website using the consent management panel. The user may refuse consent to technologies that are not necessary for the operation of the Website. Consent previously given may be changed or withdrawn at any time using the “Cookie Settings” function available on the Website. Withdrawing consent should be as easy as giving it. The user may also manage cookies using their web browser settings.

A detailed list of the cookies and similar technologies currently used, including their provider, purpose and duration, may be made available in the “Cookie Settings” panel.

7. Google Analytics

The Website uses Google Analytics, a service provided by Google. Google Analytics is used to generate statistics regarding how the Website is used, such as information about pages visited, time spent on the Website, type of device, browser, approximate location and the user’s interactions with the Website. Google Analytics is used on the Website for analytical purposes and to improve the Website.

Google Analytics technologies that are not necessary for the operation of the Website are activated only after obtaining the user’s consent. The legal basis for processing personal data in connection with Google Analytics is Article 6(1)(a) GDPR. The user may withdraw consent at any time using the “Cookie Settings” panel. As a rule, the provider of Google services for users located in the European Economic Area is Google Ireland Limited.

8. Google Tag Manager

The Website uses Google Tag Manager, a tool enabling the technical management of tags and scripts used on the Website. Google Tag Manager may be used, among other things, to manage the activation of Google Analytics and other tools in accordance with the user’s privacy preferences. Scripts and technologies requiring the user’s consent should be configured so that they are not activated before the required consent has been obtained.

9. Google Maps

The Website uses Google Maps to display the location of Beesset. Displaying an interactive map may cause a connection to be established with Google’s servers and technical information concerning the user’s device and connection, in particular the IP address, to be transferred to Google. If the use of Google Maps involves storing or accessing information on the user’s device in a manner that is not necessary for the operation of the Website, the map should be activated only after obtaining the user’s appropriate consent.

The legal basis for processing personal data in such a case is Article 6(1)(a) GDPR.

10. YouTube

The Website may contain video materials provided via YouTube, a service belonging to Google. Playing or loading YouTube content may involve transferring to Google information concerning the user’s device, IP address and manner of interaction with the content. If embedded content uses technologies that are not necessary for the operation of the Website, it should be loaded only after obtaining the user’s appropriate consent. The legal basis for processing personal data in such a case is Article 6(1)(a) GDPR.

The Controller may use solutions limiting the transfer of data before the content is activated, in particular a mechanism under which the content is activated only after the user has given consent.

11. Facebook and LinkedIn

The Website may contain links to Beesset profiles on:

  • Facebook, operated by entities belonging to the Meta group;
  • LinkedIn, whose service provider for users in the European Union is LinkedIn Ireland Unlimited Company.

If these are ordinary links to social media profiles, use of the relevant service takes place after the user clicks the relevant link and is subject to the privacy rules of the respective operator. After the user proceeds to Facebook or LinkedIn, the operator of the relevant service processes the user’s data in accordance with its own rules and as a separate controller.

If Beesset begins using advertising or tracking tools provided by these providers in the future, such as Meta Pixel or LinkedIn Insight Tag, this Privacy Policy and the consent management mechanism will be updated accordingly.

12. Recipients of Personal Data

Personal data may be disclosed to entities supporting the Controller in conducting its business where this is necessary to achieve a specified purpose.

Such categories of recipients may include, in particular:

  • IT service providers;
  • cloud service and e-mail providers;
  • Google in connection with services used by the Controller;
  • entities maintaining or developing the Website;
  • the provider of the system used for sending newsletters, after such service has been launched;
  • accounting and bookkeeping offices;
  • law firms and other professional advisers;
  • entities providing maintenance and technical services;
  • entities providing services to the Controller under appropriate data processing agreements.

Personal data may also be disclosed to public administration authorities, courts, law enforcement authorities and other authorised entities where the obligation to provide such data arises from applicable law.

13. Transfers of Personal Data Outside the European Economic Area

Some service providers used by the Controller, in particular entities belonging to the Google group, may also process personal data outside the European Economic Area, including in the United States.

Where personal data are transferred outside the European Economic Area, the Controller ensures that an appropriate legal basis and safeguards required under Chapter V of the GDPR are applied.

Where data are transferred to entities in the United States participating in the EU–US Data Privacy Framework, such transfer may take place on the basis of a valid European Commission adequacy decision. In other cases, other mechanisms provided for under the GDPR may be used, in particular standard contractual clauses approved by the European Commission and, where required, additional safeguards.

The user may contact the Controller at office@beesset.com to obtain additional information regarding the mechanisms used for international data transfers.

14. Data Retention Period

Personal data are retained no longer than necessary to achieve the purpose for which they were collected.

In particular:

  • data related to an enquiry or correspondence – until the matter has been handled, and thereafter for the period necessary to secure or pursue potential claims;
  • data related to entering into and performing a contract – for the duration of the contract, and thereafter for the period required by law and until the expiry of applicable limitation periods for claims;
  • data contained in tax and accounting documentation – for the period required by applicable regulations;
  • data processed on the basis of a legitimate interest – until that interest ceases to exist or an effective objection is raised, unless there are overriding legal grounds for continued processing;
  • data related to the newsletter – until consent is withdrawn or the newsletter service is discontinued, with the possibility of further retention of information necessary to demonstrate the fact and scope of consent given for the period required to protect against potential claims;
  • data processed on the basis of consent concerning cookies or external services – until consent is withdrawn or the purpose of processing ceases to exist;
  • analytics data – for the period resulting from the configuration of the analytics tool used and no longer than necessary for conducting statistics and analyses;
  • logs and security-related data – for the period necessary to ensure system security, analyse incidents and prevent abuse.

Once the purpose and legal basis for processing cease to apply, the data are deleted or anonymised, unless further retention is required by law.

15. Rights of Data Subjects

Subject to the conditions specified in the GDPR, a person whose personal data are processed may have the right to:

  • obtain information about the processing of personal data;
  • access their personal data and obtain a copy thereof;
  • rectify inaccurate personal data;
  • complete incomplete personal data;
  • erase personal data;
  • restrict processing;
  • data portability;
  • object to the processing of personal data;
  • withdraw consent at any time where personal data are processed on the basis of consent.

The scope of individual rights depends on the legal basis and the circumstances of the specific processing activity.

Where personal data are processed on the basis of Article 6(1)(f) GDPR, the data subject may object to such processing on grounds relating to their particular situation.

Where personal data are processed for direct marketing purposes, the user may object to such processing at any time. Following such an objection, the personal data will no longer be used for direct marketing purposes.

To exercise the above rights, the data subject should contact the Controller at office@beesset.com.

16. Withdrawal of Consent

Where the processing of personal data is based on consent, the user may withdraw that consent at any time.

In particular:

  • consent relating to the newsletter may be withdrawn using the unsubscribe link contained in the messages or by contacting the Controller;
  • consent relating to cookies, analytics and external content may be changed or withdrawn using the “Cookie Settings” panel.

Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal.

17. Complaint to the Supervisory Authority

If a user believes that their personal data are being processed unlawfully, they have the right to lodge a complaint with:

the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – UODO).

The right to lodge a complaint does not limit the possibility of using other legal remedies.

18. Automated Decision-Making

The Controller does not make decisions concerning users based solely on automated processing of personal data, including profiling, that would produce legal effects concerning the user or similarly significantly affect them.

Information collected using Google Analytics may be used to create statistics and analyses concerning the manner in which the Website is used, but such information is not, in itself, used by Beesset to make decisions concerning users that produce legal effects.

19. Data Security

The Controller applies appropriate technical and organisational measures designed to ensure a level of security appropriate to the risks associated with the processing of personal data.

The Controller takes measures aimed at protecting personal data, in particular against:

  • unauthorised access;
  • unauthorised disclosure;
  • accidental loss;
  • destruction;
  • unauthorised alteration;
  • processing contrary to applicable law.

Access to personal data is granted only to persons and entities appropriately authorised to process such data.

20. External Websites

The Website may contain links to websites operated by third parties. After accessing an external website, the user becomes subject to the privacy rules applicable to that website’s operator.

The Controller recommends reviewing the privacy policy of each external website used by the user.

21. Changes to the Privacy Policy

The Controller may update this Privacy Policy, in particular in the event of:

  • changes in applicable law;
  • changes in the manner in which personal data are processed;
  • implementation of new services;
  • changes in technology service providers;
  • changes in Website functionality;
  • implementation of new analytics or marketing tools.

The current version of the Privacy Policy is published on the Website www.beesset.com.

The date of the most recent update of this document is indicated at the beginning of the Privacy Policy.