Get in touch

Privacy

Notice

LAST CHANGE:

11.09.2025

Business relations

Notice for individuals whose data have been made available to us in connection with establishing business relations, individuals indicated for contact, or those representing parties to concluded commitments.

Data Controller and Contact Details, DPO:

The Controller of your personal data is: Asseco Poland S.A. with its registered office in Rzeszów, ul. Olchowa 14, 35-322 Rzeszów (controller). Contact in matters concerning personal data protection: Data Protection Officer of Asseco Poland S.A., e-mail: iod@asseco.pl, phone no.: +48 691 992 077.

Purpose and Legal Basis for Processing:

Your personal data will be processed for the following purposes:

  1. to perform the Contract, including conducting ongoing correspondence, documenting arrangements, monitoring the quality of services provided, and handling complaints or claims – pursuant to Article 6(1)(b) GDPR;
  2. to comply with legal obligations under applicable laws, in particular those relating to anti-money laundering and counter-terrorist financing, transaction security (including identification, verification, or assessment and monitoring of business relationships), as well as obligations under tax regulations and the Accounting Act – pursuant to Article 6(1)(c) GDPR in conjunction with relevant legal provisions;
  3. to establish, pursue, or defend against potential claims, should such claims arise – based on the controller’s legitimate interest in safeguarding its rights (Article 6(1)(f) GDPR).

Categories of Personal Data:

The controller processes the following personal data: your name, surname, job title, and business contact details.

Data Recipients:

Your personal data may be shared with: entities authorized under applicable laws, the controller’s contractors, entities processing data on behalf of the controller to support its day-to-day business operations (subcontractors, suppliers, providers of external systems). Such entities process personal data on the basis of a contract with the controller and only under the controller’s instructions.

Data Transfers outside the European Economic Area (EEA):

As a rule, your personal data will be processed and stored on servers located in the European Union, and transfers outside the EEA are not planned. However, if necessary for the performance of the Contract, such transfers may occur. In such cases, transfers will be carried out in accordance with the mechanisms set out in Chapter 5 of the GDPR, with appropriate standards and safeguards in place.

Data Retention Period:

Your personal data will be processed for the duration of the business relationship and for as long as necessary to fulfill all related obligations and rights. Applicable laws may require the controller to retain your data for a longer period.

Your Rights:

In relation to the processing of your personal data, you have the right to:

  1. access your personal data and request rectification;
  2. request the erasure of your data, under the conditions provided in Article 17 GDPR;
  3. request restriction of processing, under the conditions provided in Article 18 GDPR;
  4. object to processing under the conditions set out in Article 21 GDPR.

If you believe that the processing of your personal data does not comply with applicable law, you have the right to lodge a complaint with the President of the Personal Data Protection Office.

Source of Personal Data:

Your personal data were obtained either from the entity you represent under the Contract or directly from you.

Automated Decision-Making and Profiling:

We do not make any decisions that significantly affect you through automated means, including profiling.

GDPR – Regulation (EU) 2016/679 of the European Parliament andof the Council of 27 April 2016 on the protection of natural persons withregard to the processing of personal data and on the free movement of suchdata, and repealing Directive 95/46/EC (OJ L. of 2016 No. 119, page 1, asamended).