BDO spółka z ograniczoną odpowiedzialnością sp.k. is a member of BDO International Limited, a UK company limited by guarantee, and forms part of the BDO worldwide network of independent member firms. District Court for the capital city of Warsaw, XIII Business Division, KRS: 0000729684, NIP: 108-000-42-12.
BDO is an international network of independent public accounting, tax and advisory firms (the ‘BDO Network’), which perform professional services under the name of BDO (the ‘BDO Firms”). BDO International Limited (BDOI) is a UK company. It is the governing entity of the BDO network.
Each of BDO and the Member Firms is a separate legal entity and has no liability for another such entity's acts or omissions. Nothing in the arrangements or rules of the BDO Network shall constitute or imply an agency relationship or a partnership between BDO and the Member Firms.
This privacy statement (‘Privacy Statement’) applies to the www.bdo.pl web site (the ‘web site’) which is provided by BDO spółka z ograniczoną odpowiedzialnością sp.k. (also referred to below as ‘we’, ‘us’, ‘our’ or ‘BDO’).
Please note that the other country or specific web sites linked through www.bdo.pl are provided by the applicable BDO Member Firms or related entities managing them and are not the responsibility of BDO. Such web sites, as well as other web sites that may be linked to this web site, are not governed by this Privacy Statement. We encourage visitors to review each of these other web sites’ privacy statements before disclosing any personal information to them.
Please be informed that at BDO spółka z ograniczoną odpowiedzialnością sp.k., in accordance with Article 13 of Regulation (EU) of the European Parliament and of the Council of 27 April 2015 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (general data protection regulation), hereinafter referred to as the GDPR:
1. Personal Data Controller
The controller of your personal data is BDO spółka z ograniczoną odpowiedzialnością sp.k. located at ul. Postępu 12, 02-676 Warszawa.
2. Data Protection Officer
If you have questions on how and to what extent your personal data are processed as part of the operations of BDO spółka z ograniczoną odpowiedzialnością sp.k., as well as on your rights, you may contact the Company’s Data Protection Officer – Ms. Adriana Głuchowska via e – mail: [email protected] or telephone: 696 011 969.
3. Purpose and legal basis for processing
Your personal data are processed to perform marketing tasks, on the basis of Article 6 par. 1 letter c of the Regulation. If you are participating in training/conferences, the basis for processing is the conclusion of a contract by registering for the training/conference (Article 6 par. 1 letter b of the GDPR). In other cases, your personal data are only processed on the basis of your consent (Article 6 par. 1 letter a of the GDPR). Personal data are also processed in order to maintain and grow business relationships with those who have contacted us (via email, online contact form, by telephone or in person by providing a business card) for business purposes.
4. Data recipients
While your matter is being handled, your personal data may be made available to other entities authorized to receive personal data on the basis of relevant legal regulations, as well as entities that process personal data on behalf of the Controller on the basis of a data processing agreement concluded with the Controller. The following may be your personal data recipients:
1) public authorities and entities performing public tasks or acting on behalf of public authorities, to the extent and for purposes that arise out of generally binding regulations;
2) other entities which, on the basis of relevant agreements signed with the Controller, process the personal data of which BDO spółka z ograniczoną odpowiedzialnością sp.k. is the Controller.
5. Data processing period
BDO spółka z ograniczoną odpowiedzialnością sp.k. may process the personal data of its Clients for the period necessary for the purposes indicated in point. 3 and to the extent required by law or to secure claims. Where personal data processed on the basis of consent (Art. 6 par. 1 letter a of the GDPR), personal data are processed until the said consent is withdrawn.
6. Data subject rights
In connection with the processing of your personal data, you have the following rights:
1) the right to access personal data,
2) the right to have personal data rectified – if the data are incorrect or incomplete,
3) the right to erasure,
4) the right to restrict processing,
5) the right to data portability,
6) the right to object to processing,
7) should you obtain information that your personal data are being processed by BDO spółka z ograniczoną odpowiedzialnością sp.k. in breach of the law, you have the right to file a complaint with the supervisory authority, namely the President of the Personal Data Protection Office in Warsaw,
8) where the processing of personal data is performed on the basis of a data subject’s consent your consent (Article 6 par. 1 letter a of GDPR), you have the right to withdraw the consent at any time. Such withdrawal will have no effect on the compliance with binding regulations of the processing performed based on the consent prior to its withdrawal
Where your personal data are processed on the basis of your consent, the provision of your personal data to the Controller is voluntary. You have the right to withdraw consent at any time. All processing activities performed prior to the withdrawal of consent remain lawful and have no effect on the compliance with binding regulations of the processing performed on the basis of the consent prior to its withdrawal. To withdraw your consent to the processing of your personal data, please contact us at: [email protected].
Please be informed that BDO spółka z ograniczoną odpowiedzialnością sp.k. does not process personal data by automated means and that data are not profiled.
Our web site uses Google Analytics (with IP anonymization). Google Analytics is a web analytics service. The web site is analyzed by collecting and tracking visitor activities. Among other things, it collects data about the web site from which the visitor came (the so-called referrer), which subpages were visited or how often and for how long a particular subpage was viewed. Such analysis is used to optimize the web site, as well as to analyze the costs and benefits of online advertising.
Our web site uses Google Analytics (with IP anonymization). Google Analytics is an online analytics service. The web site is analyzed by collecting and analyzing data on the activities of web site visitors. The service collects such data as the web site from which the visitor arrived (the so-called referrer), what subpages were visited or how often and for how long a given subpage was viewed. The analysis is used to optimize the web site and to analyze the costs and benefits of online advertising.
Google Analytics is operated by Google Inc., 1600 Amphitheater Pkwy, Mountain View, CA 94043-1351, USA (hereinafter: “Google”).
The purpose of the Google Analytics component is to fulfill our legitimate interest in analyzing the flow of visitors to our web site (Article 6 par. 1 letter f of the GDPR). Google uses the data and information obtained on our behalf to, among other things, evaluate the use of our web site, compile online reports showing actions taken on our web site, and to perform other services related to the use of our web site.
The purpose of the Google Analytics component is to fulfill our legitimate interest in analyzing the flow of visitors to our web site (Article 6(1)(f) of the General Data Protection Regulation). Google uses the data and information obtained on our behalf to, among other things, evaluate the use of our web site, to compile online reports showing actions taken on our web sites, and to perform other services related to the use of our web site.
Data collected during a visit to www.bdo.pl
We do not require registration for access to www.bdo.pl, but if you want to obtain access to any services offered by BDO spółka z ograniczoną odpowiedzialnością sp.k. via www.bdo.pl, we are required to collect the personal information we need in order to provide you with those services. Failure to provide the information we require in order to complete the registration process may prevent or delay the provision of services to you.
The categories of information that we collect from you are:
- Contact details, such your: name, city, job title, email address, employer's name and phone number,
- Information relating to the services we provide, such as details of your requests, queries or complaints.
When you visit our web site, we may collect technical information such as your IP address, information about the pages you visit on www.bdo.pl, other pages you visit on the world wide web and which browser you use to view www.bdo.pl.
When does www.bdo.pl collect personal data
We collect your personal data in the following circumstances:
- when you subscribe to any of our services
- when you subscribe to any of our blogs
- when you register to attend an event (e.g. training, conference, etc.)
- when you enter a discussion forum
- when you contact us to request further information (e.g., about our services, to receive a proposal, etc.)
- when you subscribe to our newsletter
We collect the minimum amount of data to enable us to deal with your request or to provide a service to you. We will indicate where the provision of information is voluntary or compulsory. We would normally only request additional information to enable us to provide the most appropriate response to your request.
Use of personal data
BDO spółka z ograniczoną odpowiedzialnością sp.k. uses your personal data to:
- Identify you and create a profile for you when you register with us to use our services or to request information from us
- Verify your identity when you use our services or contact us
- Communicate with you with respect to the services and information that we provide
- Provide, improve and personalize our services by analyzing information about the manner in which you use our web site, to gain an understanding of how our web site is used in order to make it more intuitive
- Deal with your enquiries and requests
- Comply with the legal obligations to which we are subject and cooperate with regulators and law enforcement bodies
- Contact you with marketing information in relation to services offered by us (unless you have opted out of receiving marketing communications, or we are otherwise prevented by law from doing so)
- Contact you with marketing information in relation to events organized by us – conferences, training (unless you have opted out of receiving such marketing communications)
- Personalize the marketing messages that we send to you to make them more relevant and interesting by analyzing details of the services and information that you are receiving and the history of your transactions in order to suggest other information that may be of interest to you
- Exercise our legal rights where it is necessary to do so, for example to detect violations of law
We must have a legal basis to process your personal data. In most cases the legal basis will be one of the following:
- To provide services to you in accordance with Article 6 par. 1 letters b and c of the GDPR
- To meet our legal obligations, for example to enable us to meet the requirements relating to the prevention of fraud and money laundering
- To meet our legitimate interests, for example to understand how you use our services and our web site and to help us to derive knowledge that helps us to develop new services. When we process your personal information to meet our legitimate interests, we put in place robust safeguards to ensure that your privacy is protected and to ensure that our legitimate interests are not overridden by your interests or fundamental rights and freedoms. For more information about the balancing test that we carry out to process your personal information to meet our legitimate interests, please contact us via the contact details below
You have certain rights regarding your personal data, subject to local law. These include the right to: request access to the personal information that we may process on www.bdo.pl; update or correct your details; restrict our use of your personal data; object to our use of your personal data; receive your personal data in a usable electronic format and transmit it to a third party; request that your personal data are deleted from our systems.
You may exercise these rights by sending an e-mail to [email protected]. We will treat all such requests in accordance with applicable law.
If you would like to opt out of receiving promotional or marketing communications from us in the future, you may let us know by sending an e-mail to [email protected] and stating the e-mail address you wish to be removed from our mailing list. However, your option not to receive promotional and marketing e-mail shall not preclude us from corresponding with you, by e-mail or otherwise, regarding your existing relationship with us.
Provision of data to third parties
We may contract with other companies or individuals to deal with your enquiry or to otherwise operate this web site or our business activities (e.g., to run marketing campaigns, host our databases, support email and messaging services and analyze information). We may give such companies access to your personal data in connection with those purposes on our behalf. We may also share your personal data with other BDO Firms within the BDO Network (e.g. for the purposes of customer insights or service optimization), provided that this is consistent with the basis on which we have collected your personal data.
From time to time, we may disclose personal information in response to a court order, subpoena, government investigation, or as otherwise required or permitted by law.
We do not provide data to third parties for their own marketing purposes and we do not undertake mailings for third parties.
We may, as a result of a sale, merger, consolidation, change in control, transfer of assets, reorganization or liquidation of our company (a ‘reorganization event’) transfer, sell or assign your personal data to third parties involved in the reorganization event.
Retention of data
We will keep your personal data for as long as we have a relationship with you. Once our relationship with you has come to an end, we will retain your personal data for a period of time that enables us to: maintain our business records for analysis and/or audit purposes; comply with record retention requirements under the law; defend or bring any legal claims; deal with any complaints.
We will delete your personal information when it is no longer required for these purposes. If there is any information that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further processing or use of the data.
You have the right to withdraw your consent given to us at any time by sending an e-mail to [email protected].
Security of data
We have implemented generally accepted standards of technology and operational security to protect personal data from loss, misuse, alteration or destruction. We require all employees and principals to keep personal information confidential and only authorized personnel have access to this information.
In order to provide services to you via www.bdo.pl, we may need to transfer your personal information outside the EEA to countries that may not provide a level of protection of personal data that may be regarded as equivalent to that afforded under the European data protection legislation. Whenever your personal information is transferred internationally, we will take appropriate steps to ensure its security and confidentiality in accordance with applicable data protection law. For more information as to how we protect your personal data, please contact us via the contact details in the “Contact” section below.
Updating this Privacy Statement
We may modify or update this Privacy Statement from time to time.
If you have any concerns about the way in which we handle your personal data, you may contact the relevant data protection authority, i.e. the President of the Personal Data Protection Authority.
Please be informed that the Personal Data Controller is BDO spółka z ograniczoną odpowiedzialnością sp.k. with its registered office at ul. Postępu 12, 02-676 Warszawa, tel: +48 22 542 16 00; fax: +48 22 543 1601; e-mail: [email protected], and that you may contact the Data Protection Officer at: [email protected].
Data protection complaints procedure
All of your data protection complaints are reviewed by BDO’s Data Protection Officer.
You may contact the Data Protection Officer at BDO spółka z ograniczoną odpowiedzialnością sp.k. via e-mail at: [email protected] and by telephone at: 696 011 969.
The Data Protection Officer will respond to all such complaints immediately, no later than within 1 month of receipt.
If you disagree with the response provided by the Data Protection Officer, you may file an appeal with the BDO Global Data Protection Officer via e-mail: [email protected], at which point the matter will be sent to the Global Data Protection Officer who will review it and notify of their decision – to approve the initial response, or to change it following reconsideration.