This policy applies to the website operating under the URL address: https://ddja.pl
The operator of the website and the Personal Data Administrator is: Droga Do Ja ul. Górczewska 240/49, 01-460 Warsaw
The contact email address of the operator: kontakt@ddja.pl
The Operator is the Administrator of your personal data in relation to data provided voluntarily on the Website.
The Website uses personal data for the following purposes:
Running a newsletter
Operating a comment system
Handling inquiries via the contact form
The Website performs functions of obtaining information about users and their behavior in the following ways:
Through data voluntarily entered in forms, which are entered into the Operator’s systems.
By storing cookies on end-user devices (so-called “cookies”).
2. Selected data protection methods used by the Operator
Login areas and places where personal data are entered are protected at the transmission layer (SSL certificate).
Thanks to this, personal data and login data entered on the website are encrypted on the user’s computer and can be
read only on the target server.
User passwords are stored in a hashed form. The hashing function works in a one-way manner – it is not possible to
reverse its operation, which is currently a modern standard in the field of storing user passwords.
The Operator periodically changes its administrative passwords.
In order to minimize the risk of unauthorized access to data, the Operator uses complex passwords containing
lowercase and uppercase letters, numbers and special characters, not shorter than 8 characters.
Two-factor authentication is used on the Website, which constitutes an additional form of protection for logging
into the Website.
An important element of data protection is the regular updating of all software used by the Operator to process
personal data, which in particular means regular updates of programming components.
In order to protect data, the Operator regularly performs backups.
3. Hosting
The Website is hosted (technically maintained) on the servers of the operator: lh.pl
The hosting company, in order to ensure technical reliability, keeps logs at the server level. The following may be
recorded:
resources identified by URL identifiers (addresses of requested resources – pages, files),
time of request arrival,
time of sending the response,
client station name – identification carried out via the HTTP protocol,
information about errors that occurred during the execution of the HTTP transaction,
URL address of the page previously visited by the user (referrer link) – in the event that access to the Website
occurred via a link,
information about the user’s browser,
information about the IP address,
diagnostic information related to the process of independently ordering services via registrars on the website,
information related to handling electronic mail directed to the Operator and sent by the Operator.
4. Your rights and additional information on the use of data
In certain situations, the Administrator has the right to transfer your personal data to other recipients if this
is necessary to perform the contract concluded with you or to fulfill obligations incumbent on the Administrator.
This applies to the following groups of recipients:
hosting company on the basis of entrustment
payment operators
authorized employees and collaborators who use the data to achieve the purpose of the website’s operation
banks
companies providing marketing services to the Administrator
Your personal data are processed by the Administrator no longer than is necessary to perform activities related to
them specified in separate regulations (e.g. accounting regulations). With regard to marketing data, the data will
not be processed for longer than 3 years.
You have the right to request from the Administrator:
access to personal data concerning you,
rectification,
erasure,
restriction of processing,
and data portability.
You have the right to object to processing referred to in point 3.3 c) regarding the processing of personal data for
the purposes of legitimate interests pursued by the Administrator, including profiling, whereby the right to object
may not be exercised if there are valid legally justified grounds for processing that override your interests,
rights and freedoms, in particular the establishment, exercise or defense of claims.
You have the right to lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2,
00-193 Warsaw.
Providing personal data is voluntary, but necessary to use the Website.
Automated decision-making, including profiling, may be carried out with respect to you for the purpose of providing
services under the concluded agreement and for the purpose of conducting direct marketing by the Administrator.
Personal data are transferred to third countries within the meaning of data protection regulations. This means that
we transfer them outside the European Union.
5. Information in forms
The Website collects information voluntarily provided by the user, including personal data, if such data are
provided.
The Website may record information about connection parameters (time indication, IP address).
In some cases, the Website may record information facilitating linking the data in the form with the e-mail address
of the user filling out the form. In such a case, the user’s e-mail address appears inside the URL address of the page
containing the form.
Data provided in the form are processed for the purpose resulting from the function of a specific form, e.g. to
carry out the process of handling a service request or commercial contact, service registration, etc. Each time,
the context and description of the form clearly inform what it is used for.
6. Administrator logs
Information about users’ behavior on the Website may be subject to logging. These data are used for the purpose of
administering the Website.
7. Significant marketing techniques
The Operator uses statistical analysis of website traffic via Google Analytics (Google Inc. based in the USA). The
Operator does not transfer personal data to the operator of this service, only anonymized information. The service
is based on the use of cookies on the user’s end device. With regard to information about user preferences collected
by Google’s advertising network, the user can view and edit information resulting from cookies using the tool:
https://www.google.com/ads/preferences/
The Operator uses the Facebook pixel. This technology causes the Facebook service (Facebook Inc. based in the USA) to
know that a given person registered with it uses the Website. In this case, it is based on data for which Facebook
itself is the administrator; the Operator does not transfer any additional personal data to Facebook. The service is
based on the use of cookies on the user’s end device.
The Operator uses remarketing techniques that allow matching advertising messages to the user’s behavior on the
Website, which may give the illusion that the user’s personal data are used to track them, however in practice no
personal data are transferred from the Operator to advertising operators. The technological condition for such
activities is enabled cookie support.
The Operator uses a solution that examines user behavior by creating heat maps and recording behavior on the
Website. This information is anonymized before being sent to the service operator, so that they do not know which
natural person it concerns. In particular, entered passwords and other personal data are not recorded.
8. Information about cookies
The Website uses cookies.
Cookies are IT data, in particular text files, which are stored on the end device of the Website User and are
intended for use on the Website’s pages. Cookies usually contain the name of the website they originate from, the
storage time on the end device and a unique number.
The entity placing cookies on the end device of the Website User and accessing them is the Website operator.
Cookies are used for the following purposes:
maintaining the Website user session (after logging in), thanks to which the user does not have to re-enter
login and password on each subpage of the Website;
achieving the purposes specified above in the section “Significant marketing techniques”.
The Website uses two basic types of cookies: “session” cookies and “persistent” cookies. “Session” cookies are
temporary files that are stored on the User’s end device until logging out, leaving the website or switching off the
software (internet browser). “Persistent” cookies are stored on the User’s end device for the time specified in the
cookie parameters or until they are deleted by the User.
Web browsing software (internet browser) usually allows cookies to be stored on the User’s end device by default.
Website users can change the settings in this regard. The internet browser allows cookies to be deleted. Automatic
blocking of cookies is also possible. Detailed information on this subject is contained in the help or documentation
of the internet browser.
Restrictions on the use of cookies may affect some of the functionalities available on the Website’s pages.
Cookies placed on the end device of the Website User may also be used by entities cooperating with the Website
operator, in particular companies: Google (Google Inc. based in the USA), Facebook (Facebook Inc. based in the USA),
Twitter (Twitter Inc. based in the USA).
9. Managing cookies – how to express and withdraw consent in practice?
If the user does not wish to receive cookies, they may change their browser settings. We reserve that disabling
cookies necessary for authentication processes, security, and maintaining user preferences may hinder, and in
extreme cases may prevent, the use of websites.
In order to manage cookie settings, select the web browser you are using from the list below and follow the
instructions: