PRIVACY NOTICE

General Provisions

  1. This privacy policy (Policy) sets out the rules for the processing of personal data and the use of cookies and similar technologies in connection with the use of the misot.pl website and related subpages (hereinafter jointly referred to as: Website).
  2. The administrator of personal data is MiŚOT Spółka Akcyjna with its registered office in Bytom, ul. Antoniego Józefczaka 29/40, 41‑902 Bytom, nip 626 303 74 81, REGON 385370626, KRS 0000824003, entered into the register of entrepreneurs kept by the District Court Katowice-Wschód in Katowice, 8th Commercial Division of the National Court Register (hereinafter referred to as the Administrator).
  3. In matters related to the processing of personal data, you can contact the Controller at the correspondence address indicated above or the Data Protection Officer at the following e-mail address: [email protected].
  4. The Controller processes data in accordance with the GDPR, the Personal Data Protection Act, the provisions on electronic communication, the Act on the National Cybersecurity System (KSC) and other relevant provisions of law.

Principles of Data Processing

  1. The Administrator processes personal data in accordance with the principles of: legality, reliability, transparency, minimization, adequacy, correctness, limitation of storage and confidentiality and integrity of data.
  2. The data is processed to the extent necessary to achieve the specified purposes and only for as long as it is necessary to achieve them or as required by law.
  3. In particular, the Controller may process:
    • identification and contact details (name, surname, company name, e-mail, telephone, correspondence address),
    • data on business relations and contracts (invoice data, billing history, content of correspondence),
    • data related to the use of the Website (IP address, data on activity on the Website, cookie identifiers, data on the device and browser),
    • data of third parties provided by the user (e.g. contact persons, event participants) – the user declares that he is entitled to provide them,
    • data related to network traffic and the provision of telecommunications services to the extent specified in the regulations on electronic communications, the GDPR and Directive 2002/58/EC

Purposes and legal grounds for processing

The Controller may process your data for the following purposes:

  1. use of the Website and ICT security - provision of content and functionality of the Website, including forms, information materials and multimedia content – necessity to perform the contract for the provision of services by electronic means (legal basis: Article 6 (1) (b) of the GDPR);
  2. analysis of network traffic, ensuring the security of the Website, prevention of abuse and security incidents – the legitimate interest of the Administrator (legal basis: Article 6 (1) (f) of the GDPR) and obligations arising from the Act of 5 July 2018 on the national cybersecurity system (hereinafter referred to as: KSC) and cybersecurity regulations;
  3. contact and handling of inquiries - answering questions sent via the contact form or e-mail, conducting correspondence and settling the case – the legitimate interest of the Administrator (legal basis: Article 6 (1) (f) of the GDPR), and in the scope of data necessary to provide the service – the necessity to perform the contract (legal basis: Article 6 (1) (b) of the GDPR);
  4. newsletter and marketing communication - sending newsletters, industry information, invitations to events and other marketing content (including PING, ISPortal) – on the basis of consent (legal basis: Article 6 (1) (a) of the GDPR) and provisions on the provision of electronic services;
  5. events, conferences, trainings and conventions - registration and participation in events (e.g. MiŚOT Convention, workshops, conferences), handling of applications, organizational communication, settlements – necessity to perform the contract (legal basis: Article 6 (1) (b) of the GDPR) and the legitimate interest of the Administrator (legal basis: Article 6 (1) (f) of the GDPR);
  6. provision of services and handling of B2B/B2C relations - conclusion and performance of contracts regarding the offered solutions (including EPIX, Data Center, TeleCentrum, NET47/CRM, tsec/cybersecurity, Sencito/IoT, voice services, tenders and other projects of the MiŚOT Group) – necessity to perform the contract (legal basis: Article 6 (1) (b) of the GDPR) and to fulfill legal obligations, including tax and accounting obligations (legal basis: Article 6 (1) (c) of the GDPR);
  7. ongoing communication with customers, partners, suppliers and persons indicated as contact persons – legitimate interest of the Controller (legal basis: Article 6 (1) (f) of the GDPR);
  8. online marketing and analytical activities - conducting marketing, remarketing and statistical activities based on data collected using cookies (marketing and analytical), including the use of external tools (e.g. Google Analytics, advertising systems, social media) – on the basis of consent (legal basis: Article 6 (1) (a) of the GDPR);
  9. analysis of how to use the Website, measurement of the effectiveness of the campaign, optimization of content and functionality – the Administrator's legitimate interest (legal basis: Article 6 (1) (f) of the GDPR);
  10. fulfillment of legal obligations - accounting, tax documentation, archiving of documents, fulfillment of obligations arising from the provisions of electronic communication and KSC, as well as responses to requests of authorized bodies – fulfillment of a legal obligation (legal basis: Article 6 (1) (c) of the GDPR).
  11. pursuing claims and defending against claims - determining, pursuing or defending against claims arising from the conducted activity, concluded contracts and conducted proceedings – legitimate interest of the Controller (legal basis: Article 6 (1) (f) of the GDPR).

The obligation or voluntary submission of personal data:

  1. Providing data as part of contact, registration, application or contractual forms is voluntary, but necessary to provide a specific service or to settle the matter. Failure to provide them may make it impossible, for example, to respond to an inquiry, register for an event, conclude a contract or execute an order.
  2. Providing data for analytical and marketing purposes (e.g. as part of cookies) is voluntary and subject to consent. Lack of consent or its withdrawal does not affect the possibility of using the Website, although it may limit the availability of some functions or the personalization of content.

Data retention period

  1. The data will be stored for the period necessary to achieve the given purpose of processing, and then for the period required by law or until the expiry of the limitation period for claims.
  2. Data processed on the basis of consent (e.g. newsletter, marketing/analytical cookies) are stored until the consent is withdrawn.
  3. Data related to the performance of contracts and settlements are stored for the period required by tax and accounting regulations (usually 5 years from the end of the tax year in which the tax obligation arose) and until the expiry of the limitation period for civil law claims.
  4. Data used for analytical and marketing purposes based on cookies are stored for the lifetime of individual cookies or until the browser settings are changed or consent is withdrawn in the cookie management mechanism.

Telecommunications data categories and specific purposes

As a telecommunications entrepreneur, the Administrator also processes the data of subscribers and end users in the scope and on the terms specified in the regulations on electronic communication and other special provisions. This may include in particular:

  1. subscriber's details (name, surname/name, address, contact details, contract and billing details),
  2. network and device user identification data (service numbers, device identifiers, SIM cards, logins),
  3. traffic data (initial and target numbers, dates and times, duration, amount of data transmitted, IP addresses, connection attempts),
  4. location data (base stations, access points, installation address, place of service provision),
  5. data necessary to handle complaints and network security (notifications, technical logs, information about incidents).

These data are processed, among others, in order to perform the contract, settlements, network security, fulfillment of legal obligations (including data retention) and sharing data with authorized bodies to the extent provided for by law

Data sharing with authorities and telecommunications retention

  1. The Administrator is obliged to share certain data, including connection, location and subscriber data, only with authorized entities (e.g. courts, prosecutor's office, police, other services, regulatory authorities), in cases and to the extent provided for by law.
  2. The disclosure takes place on the basis of the relevant provisions and the request or application of the authority and to the extent necessary to implement these provisions.
  3. The administrator keeps records of data sharing with authorized bodies, if required by law.
  4. Telecommunications data, including traffic and location data, are retained for the period required by applicable retention laws and then deleted or anonymized; the exact periods may vary depending on the type of data, services and current regulations.

Data recipients

The recipients of the data may be:

  1. providers of IT systems and services, including hosting, maintenance of the Website, CRM systems, analytical and marketing tools;
  2. entities providing accounting, legal, advisory, debt collection, courier, postal services and other entities supporting the Administrator in the implementation of its activities;
  3. event organizers and partners, if necessary to handle the participation (e.g. hotels, conference facilities, technical subcontractors);
  4. advertising partners, providers of analytical and social tools to whom data from cookies is transferred (e.g. Google, Meta), in accordance with their regulations and privacy policies;
  5. state authorities and other entities authorized by law (e.g. police, courts, regulatory bodies, CSIRTs and other KSC entities).

All entities processing data on behalf of the Administrator operate on the basis of appropriate entrustment agreements and are obliged to apply appropriate security measures.

Transfer of data outside the EEA

As a rule, data is not transferred to third countries (outside the European Economic Area) or international organizations, subject to the use of analytical, advertising and social media tool providers based outside the EEA (e.g. Google, Meta). In the case of transferring data outside the EEA, the Controller ensures an adequate level of their protection by applying the mechanisms provided for in the GDPR (including decisions stating an adequate level of protection, standard contractual clauses, other instruments provided for in Articles 46 to 49 of the GDPR). Information about the intention to transfer data outside the EEA, together with a description of the safeguards used, is provided at the time of data collection or in the content of this Policy.

5. User rights

In connection with the processing of personal data, you are entitled to:

  1. the right to access and obtain a copy of the data (Article 15 of the GDPR);
  2. the right to Rectification (Art. 16 GDPR)
  3. the right to erasure ("the right to be forgotten") in the cases provided for in Article 17 of the GDPR;
  4. the right to Restriction of Processing (Art. 18 DSGVO)
  5. the right to data portability (Article 20 of the GDPR), to the extent that the processing takes place on the basis of consent or a contract and in an automated manner;
  6. the right to object to processing based on the Controller's legitimate interest or for direct marketing purposes (Article 21 GDPR);
  7. the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;
  8. the right to lodge a complaint with the President of the Office for Personal Data Protection (UODO) when you consider that the processing violates the provisions on the protection of personal data.

In order to exercise the above rights, you may contact the Controller or the Data Protection Officer using the data indicated in point 1 of this Policy, in particular by e-mail or traditional correspondence.

Profiling and automated decision making

  1. The Controller may conduct basic analytics and segmentation (e.g. by type of services, usage history) in order to match the content of the Website or marketing communication.
  2. As a rule, the Administrator does not make decisions against users based solely on automated processing that would have legal effects on them or significantly affect them in a similar way (within the meaning of Article 22 of the GDPR); any automated decisions result from clear criteria provided for in contracts and regulations and are subject to human supervision.
  3. If the automated process would significantly affect your rights or the legal situation, the Controller will provide you with the opportunity to obtain human intervention, express your own position and challenge the decision within the limits of applicable regulations

Data security and KSC

  1. The Controller applies technical and organizational measures to ensure the security of personal data complying with the requirements of Articles 24 and 32 of the GDPR, including, but not limited to, access control, encryption, pseudonymisation, backup procedures, incident monitoring and testing of security measures.
  2. As an entity operating in the telecommunications sector and a key entity within the meaning of the Act on the National Cybersecurity System, the Administrator also implements organizational, technical and procedural measures provided for in the National Cyber Security System, in particular in the field of: risk management, incident handling, reporting serious incidents to the competent CSIRT, business continuity and security of the digital services supply chain.
  3. Data from server and system logs are used, among others, to maintain and manage the Website, ensure security, detect abuse and create aggregate statistics, without identifying specific users, unless it is necessary to determine liability for violations of law.
  4. In the event of a personal data breach that may cause a high risk of violating the rights or freedoms of natural persons, the Administrator – in accordance with the GDPR and special provisions – will notify the competent supervisory authority and data subjects, as well as take the necessary corrective actions.

Cookies and similar technologies

  1. As part of the Website, cookies and similar technologies are used to, among others, ensure the proper functioning of the Website, adjust content, analyze traffic, conduct marketing activities and integration with social media.
  2. Cookies are small text files stored on the user's device (computer, smartphone, etc.) that can be read by the Administrator's or third parties' IT system.
  3. The Website uses the following categories of cookies:
    • technical/necessary cookies – necessary for the proper operation of the Website, ensuring security, maintaining sessions, handling forms; their use does not require the user's consent;
    • functional/analytical cookies – allow you to analyze the use of the Website, create statistics and reports, optimize content and functionality; they are used on the basis of consent;
    • marketing cookies – are used to profile users, conduct remarketing, match advertising content, also with the use of advertising partners; they are used on the basis of consent.
  1. During the first visit to the Website, a cookie banner is displayed, through which the user can manage their preferences and consent to certain categories of cookies. These consents may be changed or withdrawn at any time using the appropriate mechanism provided on the Website ("Cookie Settings").
  2. The user can also independently manage cookies through the web browser settings (blocking, deleting, limiting). However, disabling or limiting cookies may affect the functioning of some elements of the Website.
  3. The Website may use cookies and technologies provided by external partners, in particular for analytical (e.g. Google Analytics) and marketing purposes (e.g. advertising systems, Meta pixel, social integrations), in accordance with the principles described in their privacy policies.

Changes to this policy

  1. The Administrator reserves the right to make changes to this Policy, in particular in the event of: changes in the law, guidelines of supervisory authorities, changes in the technologies used on the Website or modifications to the services offered.
  2. Users will be informed about the change of the Policy by publishing a new content of the Policy on the Website and – in the event of significant changes – by an appropriate message.
  3. The policy is effective from the date of its publication on the Website. The date of the last update will be indicated below.

Date of the last update of the Policy: 22.06.2026

. .
. .