Privacy Policy
This Policy explains how 2Secure Sp. z o.o. processes personal data in connection with the e-podpis.online website, under the GDPR (Regulation 2016/679). The binding version is the Polish one.
1. Data controller
The controller is 2Secure Sp. z o.o., registered office at Żelazna 51/53, 00-841 Warszawa (NIP 5273147526, KRS 0001150455, REGON 54069139), email [email protected], phone +48 22 398 70 00.
2. Data Protection Officer
[TO BE COMPLETED: whether a DPO has been appointed; if so, contact details. If not, indicate a contact point for data protection matters.]
3. Purposes and legal bases
- performing the contract and handling enquiries — Art. 6(1)(b) GDPR,
- identity verification and obligations related to certificate issuance — Art. 6(1)(c) and (b) GDPR,
- compliance with legal obligations (e.g. tax, accounting) — Art. 6(1)(c) GDPR,
- own marketing and pursuing claims (legitimate interest) — Art. 6(1)(f) GDPR,
- marketing based on consent — Art. 6(1)(a) GDPR.
4. Categories of data
We process, among others, identification and contact data provided in the form and data needed to verify identity (e.g. ID document data).
[TO BE COMPLETED: detailed scope of data collected during video verification and any recordings.]
5. Recipients
- Certum as the qualified trust service provider issuing the certificate,
- IT, hosting and email providers acting on the controller's behalf,
- [TO BE COMPLETED: full list of processors and any other recipients.]
6. Transfers outside the EEA
[TO BE COMPLETED: whether data is transferred outside the EEA and on what basis (e.g. standard contractual clauses).]
7. Retention
We keep data for as long as necessary to achieve the purposes and as required by law (e.g. limitation periods, tax obligations).
[TO BE COMPLETED: specific retention periods per data category.]
8. Your rights
- access to your data and a copy,
- rectification, erasure or restriction of processing,
- data portability,
- objection to processing based on legitimate interest,
- withdrawal of consent at any time (without affecting prior processing),
- a complaint to the President of the Personal Data Protection Office (PUODO).
9. Voluntariness
Providing data is voluntary but necessary to handle the enquiry, conclude the contract and issue the certificate. Without it the service cannot be provided.
10. Profiling
We do not make decisions producing legal effects based solely on automated processing, including profiling.
11. Cookies
The use of cookies is described in the Cookie Policy available in the Service.
12. Changes
This Policy may be updated. The current version is published in the Service with the date of the last update.