AMBERLAN PRIVACY AND COOKIE POLICY

This Privacy Policy sets forth the rules for the processing and protection of personal data provided by Users and Contractors (including potential ones) in connection with the use of the amberlan.com website and as part of the company's business, recruitment, and marketing relationships. This document was prepared taking into account the requirements of the GDPR and the Electronic Communications Law (PKE).

1. Data Controller and Contact Details

The Controller of your personal data is Amberlan Sp. z o.o. with its registered office in Warsaw (00-406), ul. Ludna 2 / 208, entered into the Register of Entrepreneurs under KRS number: 0001195611, NIP: 7011278470, REGON: 542784111 (hereinafter: the "Controller" or "We").

The Controller has not appointed a Data Protection Officer (DPO) as there is no such legal obligation under Article 37 of the GDPR. A designated team is directly responsible for all matters relating to privacy and the exercise of data subjects' rights, and they can be contacted at the e-mail address: office@amberlan.com.

2. Purposes, Legal Bases and Data Processing Period

We process personal data in accordance with the principle of minimization and solely on the basis of applicable laws:

A. Communication and quote inquiries

Purpose: To respond to messages sent via the contact form or e-mail and to provide an initial offer.

Legal basis: Article 6(1)(b) of the GDPR (actions necessary prior to the conclusion of a contract) and Article 6(1)(f) of the GDPR (our legitimate interest – ensuring communication).

Processing period: Until the completion of correspondence, and subsequently until the expiry of the limitation period for potential claims.

B. B2B relations and contractor representatives (Information per Article 14 of the GDPR)

Purpose: Establishing and maintaining business relationships with corporate entities. If you are a member of the management board, a commercial proxy, or a contact person for our contractor, we may have obtained your data (name, surname, position, business contact details) directly from your employer or from public registers (KRS, CEIDG, LinkedIn).

Legal basis: Article 6(1)(f) of the GDPR (our legitimate interest – initiating and maintaining business relations).

Processing period: For the duration of the B2B cooperation, and subsequently until the limitation of claims.

C. Marketing Activities (GDPR vs. PKE)

In the area of B2B marketing, we strictly distinguish between the processing of analytical data and physical communication with the recipient:

Profiling and database segmentation (CRM): The processing of contractor contact data within our systems for the purpose of assessing business potential is based on Article 6(1)(f) of the GDPR (legitimate interest).

Sending messages and voice calls: Initiating electronic contact (e.g., e-mails, newsletters, so-called "cold mailing") or telephone contact for direct marketing purposes takes place exclusively on the basis of the recipient's prior, express consent, in accordance with Article 398 of the Electronic Communications Law (PKE). This consent is entirely voluntary.

Processing period: Until consent is withdrawn or an effective objection to profiling is raised.

D. Recruitment intermediation and recruitment processes

Due to the nature of intermediation services, candidates' data are subject to a specific regime:

Mandatory data: Processed on the basis of Article 6(1)(c) of the GDPR in connection with Article 22(1) of the Labor Code (legal obligation).

Additional data: Provided voluntarily by the candidate (e.g., image) – processed on the basis of consent (Article 6(1)(a) of the GDPR).

Retention period: In order to defend against potential claims regarding employment discrimination, recruitment documentation of non-hired candidates is stored for a period of 3 years from the end of the selection process. The legal basis in this case is our legitimate interest (Article 6(1)(f) of the GDPR), which is confirmed by case law (including the judgment of the Supreme Administrative Court, case file no. III OSK 2700/22).

E. Performance of operational contract and legal obligations

Purpose: Execution of contracts (e.g., investment handling, asset management), accounting, tax settlements.

Legal basis: Article 6(1)(b) of the GDPR (performance of a contract) and Article 6(1)(c) of the GDPR (legal obligation, including tax regulations).

Processing period: 5 years from the end of the calendar year in which the tax payment deadline expired.

F. Server Logs

Purpose: Site administration, prevention of hacker attacks, technical diagnostics (recording, among others, IP, query time).

Legal basis: Article 6(1)(f) of the GDPR (maintaining the security and integrity of the infrastructure). Logs are stored short-term and overwritten.

3. International Transfers and Protective Measures (Schrems II)

Due to the global nature of our operations (including operational support in Central Asian markets, e.g., in Uzbekistan) and the use of infrastructure from technology providers (Google, Meta), your data may be transferred outside the European Economic Area (EEA).

We do not rely solely on Standard Contractual Clauses (SCC). In accordance with the CJEU judgment (C-311/18, "Schrems II") and the EDPB guidelines 01/2020, we conduct Transfer Impact Assessments (TIA) each time. For third countries that do not guarantee a level of protection adequate to the EEA, we implement technical supplementary measures (e.g., advanced pseudonymization, end-to-end encryption protocols) to guarantee the security of the transmitted information. For US-based providers, we also use the Data Privacy Framework mechanism.

4. Social Media Ecosystem and Joint Controllership

We maintain profiles on social media and use analytical and advertising tools (e.g., Meta Pixel, Custom Audiences, LinkedIn Insight Tag). In light of the CJEU case law and EDPB guidelines 08/2020, we act as Joint Controllers together with the providers of these platforms (Meta Platforms Ireland Ltd., LinkedIn Ireland Unlimited Company) with regard to data aggregation and profiling.

Essential content of the arrangements (Article 26(2) of the GDPR):

Platform providers (Meta, LinkedIn): Responsible for the IT infrastructure of the advertising database, implementation of appropriate IT security measures, and the technical enablement of the deletion of a user profile from their systems.

Amberlan Sp. z o.o.: Responsible for the configuration of campaign parameters, installation of tracking tools on our own website in a compliant manner, and management of segmentation.

In accordance with Article 26(3) of the GDPR, the User has the right to exercise their rights (e.g., objection, data deletion) directly against each of the joint controllers independently.

5. Security and DPIA (Accountability)

We have implemented adequate technical and organizational measures to protect data against loss and unauthorized access (including SSL certificates, access control policy, records of processing activities). When deploying advanced tools that monitor traffic and feed B2B targeting systems, we carry out a Data Protection Impact Assessment (DPIA – Article 35 of the GDPR) before launch, preventively examining the proportionality of these actions against user rights.

6. Data Subject Rights (including the right to object)

We guarantee a seamless and fast communication channel for the exercise of your rights (write to: office@amberlan.com). However, we reserve that, in accordance with Article 15(4) of the GDPR, the exercise of the right to obtain a copy of data may not adversely affect the rights and freedoms of others (e.g., infringe on the trade secrets of contractors).

You have the following rights:

Right of access to data and to receive a copy thereof.

Right to rectification or completion of data.

Right to erasure of data ("right to be forgotten").

Right to restriction of processing and the right to data portability.

RIGHT TO OBJECT (Article 21 of the GDPR): You have the absolute right to object to the processing of your data for direct marketing purposes (including profiling). We honor this objection immediately, without performing any balancing-of-interests tests. You may also object to processing based on legitimate interests for reasons related to your particular situation.

Right to withdraw consent: You may withdraw it at any time, as easily as you provided it.

Right to lodge a complaint with the President of the Personal Data Protection Office.

7. Cookies, Dark Patterns and Consent Mode

Our website uses cookie technology and similar tracking mechanisms (e.g., pixels). We adhere to the highest standards of transparency and privacy by design principles, eliminating so-called deceptive interfaces (Dark Patterns) from the interface.

Principle of equal choice: The option to reject tracking files ("Reject all") is available in the first layer of the cookie banner and is displayed with the same prominence as the accept button. We do not use pre-ticked boxes, nor do we treat the mere scrolling of the page as implied acceptance.

Withdrawal of consent: Changing or revoking tracking preferences is possible at any time via a static widget (preference icon) available in the corner of the screen, without the need to clear the browser cache.

Categories of cookies:

Necessary: Technically critical for the website's operation. Their installation does not require consent (basis: necessity for providing a telecommunications service).

Analytical: Used to measure traffic (e.g., Google Analytics). Activated only after obtaining your active consent.

Marketing: Used for advanced B2B targeting (Meta Pixel, LinkedIn Insight Tag). Activated only after obtaining active consent.

Google Consent Mode v2: To respect your choices and maintain minimal diagnostic analytics, we have implemented the Consent Mode mechanism. If you reject analytical cookies, the platform will not install cookies, and only anonymized, cookie-less signals (so-called pings) will be sent to Google servers, informing about the basic connection state, from which your profile cannot be generated.

Last update: September 17, 2026.