Get in touch

Privacy

Notice

LAST CHANGE:

02.09.2025

Reporting violations

Notice for whistleblowers and other individuals submitting reports of potential or actual security incidents, personal data breaches, or other irregularities.

Data Controller and Contact Details, DPO:

The Controller of your personal data is: Asseco Poland S.A. with its registered office in Rzeszów, ul. Olchowa 14, 35-322 Rzeszów (controller). Contact in matters concerning personal data protection: Data Protection Officer of Asseco Poland S.A., e-mail: iod@asseco.pl, phone no.: +48 691 992 077.

Purpose and Legal Basis for Processing:

Your personal data will be processed for the following purposes:

  1. to handle reports, including their receipt, verification, and clarification, based on the controller’s legal obligations under applicable law – pursuant to Article 6(1)(c) GDPR;
  2. to handle reports, including their receipt, verification, and clarification, in accordance with internal company procedures beyond those required by law – based on the controller’s legitimate interest in ensuring compliance with the company’s internal standards and procedures (Article 6(1)(f) GDPR).

Data Recipients:

Your personal data may be shared with: entities authorized under applicable laws, entities processing data on behalf of the controller to support its day-to-day business operations (subcontractors, suppliers, including providers of external systems). Such entities process personal data on the basis of a contract with the controller and only under the controller’s instructions.

Data Transfers outside the European Economic Area (EEA):

Your personal data will not be transferred outside the EEA.

Data Retention Period:

Your personal data will be retained for the period required by applicable law and for the period necessary to demonstrate the controller’s accountability in handling and recording reports.

Your Rights:

In relation to the processing of your personal data, you have the right to:

  1. access your personal data and request rectification;
  2. request the erasure of your data, under the conditions provided in Article 17 GDPR;
  3. request restriction of processing, under the conditions provided in Article 18 GDPR;
  4. object to processing under the conditions set out in Article 21 GDPR.

If you believe that the processing of your personal data does not comply with applicable law, you have the right to lodge a complaint with the President of the Personal Data Protection Office.

Requirement to Provide Data:

Providing your personal data is mandatory under the internal regulations adopted by the controller.

Automated Decision-Making and Profiling:

We do not make any decisions that significantly affect you through automated means, including profiling.

GDPR – Regulation (EU) 2016/679 of the European Parliament andof the Council of 27 April 2016 on the protection of natural persons withregard to the processing of personal data and on the free movement of suchdata, and repealing Directive 95/46/EC (OJ L. of 2016 No. 119, page 1, asamended).