Policy
Privacy
General information
This Privacy Policy defines the rules for the processing of personal data by Carrywater (hereinafter: the “Administrator”) in connection with the use of the website and services provided by the Administrator.
The Administrator takes particular care to protect users’ privacy and ensures compliance with applicable laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”).
Data administration
Personal data administrator is:
Carrywater Group SA
02-212 Warsaw, Bakalarska 34
NIP: 897-16-32-646
REGON: 932170730
For matters related to personal data processing, you may contact us at: [email protected].
Data processing scope
The administrator may process the following personal data:
- identification data (first name, last name),
- contact details (email address, phone number),
- professional data (position, company),
- data related to service and project delivery,
- data contained in correspondence,
- technical data (IP address, cookies, browser data).
Purposes and legal basis for data processing
Personal data is processed for the following purposes:
Contact and inquiry
- responding to inquiries submitted via forms or email
- legal basis: Article 6(1)(f) GDPR (legitimate interest of the Controller)
Services delivery
Within the scope of activities including:
- Project and Program Management
- IT Experts Outsourcing
- Consulting (business and IT advisory)
- Software Solutions (custom software development)
data may be processed for the purpose of:
- performing contracts,
- organizing and managing projects,
- enabling collaboration within project teams,
- communication with clients and partners.
Legal basis:
- Article 6(1)(b) GDPR (performance of a contract),
- Article 6(1)(f) GDPR (legitimate business interest).
Recruitment and cooperation with experts
- processing candidate and contractor data,
- evaluating qualifications and project fit.
Legal basis:
- Article 6(1)(b) GDPR,
- Article 6(1)(a) GDPR (consent, where applicable).
Marketing and business communication
- providing information about services,
- maintaining business relationships in a B2B context.
Lega basis:
- Article 6(1)(f) GDPR (legitimate interest),
- Article 6(1)(a) GDPR (consent, e.g. newsletters).
Legal obligations
- accounting and financial reporting,
- compliance with tax and legal requirements.
Legal basis:
- Article 6(1)(c) GDPR.
Data recipients
Personal data may be shared with:
- entities cooperating in service delivery (e.g. IT experts, subcontractors),
- IT service providers (hosting, CRM systems, communication tools),
- legal advisors and consultants,
- public authorities, where required by law.
The Administrator ensures that all data processors comply with GDPR requirements.
Data transfers outside the EEA
Where IT tools provided by entities outside the European Economic Area are used (e.g. cloud providers), personal data may be transferred outside the EEA.
In such cases, the Controller applies appropriate safeguards, including:
- Standard Contractual Clauses (SCC),
- cooperation with entities ensuring an adequate level of data protection.
Data retention period
Personal data is retained:
- for the duration of the contract and service delivery,
- for the period required by applicable law (e.g. tax regulations),
- until an objection is raised or consent is withdrawn (if applicable),
- for the period necessary to establish, exercise or defend legal claims.
Rights of the data subject
Data subjects have the right to:
- access their data,
- rectify their data,
- erase their data (“right to be forgotten”),
- restrict processing,
- data portability,
- object to processing,
- withdraw consent (if processing is based on consent).
To exercise these rights, please contact the Controller.
Cookies and technical data
The website may use cookies in order to:
- ensure proper functioning of the website,
- analyze traffic and statistics,
- optimize user experience.
Users can manage cookies through their browser settings.
Data security
The administrator implements appropriate technical and organizational measures to protect personal data, including:
- access control mechanisms,
- IT system security measures,
- access and authorization management procedures,
- actions minimizing the risk of unauthorized access.
Changes to Policy Privacy
This Privacy Policy may be updated periodically due to changes in legal requirements or the scope of the Administrator’s activities.
The current version is always available on the website.
Contact
For matters related to personal data protection, please contact:
e-mail: [email protected]
or by post at the Administrator’s registered address.