Privacy Policy

Last updated: 23 July 2026

1. General information

This Privacy Policy sets out the rules for processing the personal data of users of the website available at est-pologne.eu, hereinafter referred to as the “Website”.

This Policy applies in particular to:

  • use of the Website,
  • contact through forms, email and telephone,
  • submission of applications relating to job offers,
  • participation in recruitment processes,
  • subscription to the newsletter, if launched,
  • use of cookies,
  • use of Google Tag Manager and Google Analytics,
  • use of links to social media platforms.

The legal basis for processing personal data includes, in particular:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council, hereinafter referred to as the “GDPR”,
  • the Polish Electronic Communications Law of 12 July 2024,
  • applicable labour law, employment and recruitment regulations,
  • other laws applicable to the Controller’s activities.

2. Personal data controller

The controller of personal data is:

EST-POLSKA spółka z ograniczoną odpowiedzialnością
Plac Kilińskiego 2
35-005 Rzeszów
Poland

KRS: 0000438991
NIP: 5170360668
REGON: 180908731

The Controller may be contacted:

Requests concerning the exercise of rights under the GDPR may be sent to biuro@est-pologne.eu with “Personal Data” or “GDPR” in the subject line.

3. How personal data is collected

The Controller may collect personal data:

  1. directly from the data subject, in particular through a contact form, application form, email or telephone conversation;
  2. from documents submitted by candidates, including CVs, application forms and employment-related documents;
  3. from the Controller’s clients or partners, where necessary to carry out a recruitment process or provide services;
  4. automatically when the Website is used, in particular in the form of technical data, server logs and data collected through cookies, depending on the user’s settings and consent choices.

4. Technical data and server logs

When the Website is used, certain technical information may be recorded automatically, including:

  • the device’s IP address,
  • the date and time of the connection,
  • the address of the page visited,
  • the address of the page from which the user accessed the Website,
  • browser type,
  • operating system,
  • device type,
  • information about errors and security-related events.

This data is processed in order to:

  • ensure the proper functioning of the Website,
  • protect IT systems and maintain security,
  • detect errors, misuse and unauthorised access attempts,
  • prepare technical statistics,
  • establish, pursue or defend legal claims.

The legal basis for processing is the Controller’s legitimate interest under Article 6(1)(f) of the GDPR.

Server logs are generally retained for up to 30 days, unless a longer period is necessary to investigate a security incident, establish liability or defend legal claims.

5. Contact form and enquiries from employers

Through the contact form, the Controller may process, in particular:

  • first name and surname,
  • email address,
  • telephone number,
  • company name,
  • industry,
  • message content,
  • other data voluntarily included in the message.

The data is processed in order to:

  • respond to an enquiry,
  • present an offer,
  • take steps before entering into a contract,
  • conduct negotiations and further communication,
  • perform a concluded contract,
  • document correspondence,
  • establish, pursue or defend legal claims.

The legal basis for processing is:

  • Article 6(1)(b) of the GDPR, where the contact concerns entering into or performing a contract,
  • Article 6(1)(f) of the GDPR, namely the Controller’s legitimate interest in handling enquiries, maintaining communication and protecting itself against legal claims,
  • Article 6(1)(a) of the GDPR, where data is processed for an additional purpose on the basis of voluntary consent.

Data relating to an enquiry is retained for the period necessary to handle it and then for up to 12 months after the correspondence has ended.

The data may be retained for longer where a contract has been concluded or where continued retention is necessary to comply with legal obligations or protect against legal claims.

6. “Quick Application” form and recruitment processes

The Controller may process candidates’ personal data, including:

  • first name and surname,
  • telephone number,
  • email address, if provided,
  • selected job offer or preferred type of work,
  • information about qualifications, professional experience and education,
  • information contained in a CV or other submitted documents,
  • information concerning the right to legally reside and work in Poland,
  • citizenship or nationality, only to the extent necessary to determine the conditions of legal employment,
  • information about gender, only where its processing is necessary, lawful and properly justified,
  • other data voluntarily provided by the candidate.

Candidates’ data is processed in order to:

  • receive and review an application,
  • contact the candidate,
  • match the candidate with suitable job offers,
  • conduct the recruitment process,
  • assess qualifications and employability,
  • present the candidate to a potential employer or the Controller’s client,
  • fulfil obligations connected with legal residence and employment,
  • enter into a contract,
  • conduct future recruitment processes, only after obtaining separate consent,
  • establish, pursue or defend legal claims.

The legal basis for processing is:

  • Article 6(1)(b) of the GDPR, for taking steps at the candidate’s request before entering into a contract,
  • Article 6(1)(c) of the GDPR, for compliance with obligations arising from labour law, employment law, residence legalisation rules and other applicable regulations,
  • Article 6(1)(a) of the GDPR, in relation to additional data or participation in future recruitment processes,
  • Article 6(1)(f) of the GDPR, namely the Controller’s legitimate interest in organising recruitment, documenting the process and protecting itself against legal claims.

Where a candidate voluntarily provides special-category data, such as information about health, disability, ethnic origin, religious beliefs or other data referred to in Article 9 of the GDPR, such data will be processed only where an appropriate legal basis exists, in particular the candidate’s explicit consent or a legal obligation.

Candidates should not provide special-category data unless it is necessary for the recruitment or employment process.

Data relating to a specific recruitment process is retained for the duration of that process and for no longer than 6 months after it ends, unless:

  • the candidate has consented to participation in future recruitment processes,
  • a longer retention period is required by law,
  • the data is necessary to establish, pursue or defend legal claims.

Data processed for future recruitment purposes may be retained for 24 months from the date consent is given, unless the consent is withdrawn earlier.

If a candidate is employed, their data will continue to be processed and retained in accordance with regulations concerning employee records, tax settlements, social insurance and employment legalisation.

7. Disclosure of candidates’ data to employers and clients

As part of recruitment processes, candidates’ data may be disclosed to:

  • employers seeking employees,
  • temporary-work user employers,
  • the Controller’s clients,
  • entities involved in legalising employment or residence,
  • entities organising accommodation, transport or employee onboarding, only to the extent necessary.

Candidate data will not be disclosed to a potential employer beyond what is necessary for the recruitment process.

Where disclosure requires the candidate’s consent, the data will be disclosed only after the relevant consent has been obtained or the candidate has accepted a specific job offer.

8. Newsletter and commercial communications

If a newsletter is launched, the Controller may process:

  • email address,
  • first name, if provided,
  • information about the granting and withdrawal of consent,
  • technical data relating to delivery and opening of messages, where such statistics are used.

The data will be processed in order to:

  • send the newsletter,
  • provide information about the Controller’s activities,
  • send job offers, industry information, educational materials and commercial information,
  • prepare basic statistics concerning newsletter effectiveness.

The legal basis for processing is voluntary consent under Article 6(1)(a) of the GDPR.

Commercial information sent by email, SMS or telephone will be communicated only after obtaining the consent required under the applicable Electronic Communications Law.

Consent to receive the newsletter and marketing communications is voluntary and may be withdrawn at any time:

Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.

Data used to send the newsletter is retained until consent is withdrawn or the newsletter service is discontinued.

Information confirming that consent was granted or withdrawn may be retained for the period necessary to demonstrate the lawfulness of the Controller’s actions and protect against legal claims.

9. Cookies

The Website uses cookies and similar technologies.

Cookies are small pieces of information stored on the user’s device while using a website.

Cookies may be used to:

  • ensure the proper functioning of the Website,
  • maintain security,
  • remember the user’s choices and settings,
  • operate forms,
  • record the user’s cookie consent choices,
  • prepare anonymous or pseudonymous statistics,
  • analyse traffic and how the Website is used,
  • conduct marketing activities, where such tools are implemented and the user has given the appropriate consent.

10. Categories of cookies

Necessary cookies

These cookies are required for the proper functioning of the Website, security, operation of forms and storage of the user’s consent choices.

Necessary cookies may be used without additional consent because they are required to provide a service requested by the user or to ensure the transmission of data.

Analytics cookies

These cookies make it possible to analyse the number of visits, traffic sources, popularity of individual pages and the way the Website is used.

Analytics cookies are activated only after the user has given consent.

Functional cookies

These cookies may be used to remember the selected language, website settings or other user preferences.

Where they are not necessary to provide a service requested by the user, they are activated only after consent has been given.

Marketing cookies

These cookies may be used to measure advertising effectiveness, personalise marketing communications and conduct remarketing activities.

The Website should not activate marketing cookies or advertising tags before obtaining the user’s separate consent.

11. Google Tag Manager

The Website may use Google Tag Manager, a tool provided by Google for managing codes, scripts and tags placed on the Website.

Google Tag Manager may enable the activation of other tools, such as Google Analytics. The scope of collected data depends on the tags configured through Google Tag Manager.

Analytics and marketing tags managed through Google Tag Manager should be activated in accordance with the user’s choices made in the consent management panel.

12. Google Analytics

After obtaining the user’s consent, the Website may use Google Analytics 4, an analytics service provided by Google.

Google Analytics may collect, in particular:

  • approximate location derived from the IP address,
  • information about the device, operating system and browser,
  • traffic source,
  • pages visited,
  • time spent on the Website,
  • information about interactions with Website elements,
  • a pseudonymous browser or device identifier.

Google Analytics may use cookies including:

  • _ga, used to distinguish users and retained by default for up to 2 years,
  • _ga_<identifier>, used to store session-state information and retained by default for up to 2 years.

The Controller should configure the retention of user and event data in Google Analytics for a period of no longer than 14 months, unless a shorter period is sufficient for analytical purposes.

Google Analytics is activated only after consent to analytics cookies has been given.

The Controller should not disclose to Google Analytics data such as first name, surname, email address, telephone number, identification document number or any other information that allows Google to identify the user directly.

13. Managing cookie consent

On the first visit to the Website, the user may be given the option to:

  • accept all optional cookies,
  • reject all optional cookies,
  • select specific categories of cookies,
  • save individual settings.

Refusing consent to analytics or marketing cookies should not prevent the user from using the basic functions of the Website or submitting a form.

The user may change or withdraw consent at any time through the “Cookie settings” panel or a similar mechanism available on the Website.

The user may also manage cookies through browser settings. However, blocking all cookies may cause certain Website features to function incorrectly.

14. Recipients of personal data

Personal data may be disclosed to:

  • the Controller’s authorised employees and contractors,
  • hosting and server providers,
  • email service providers,
  • IT and administrative service providers,
  • providers of recruitment systems, CRM tools and form-processing tools,
  • newsletter service providers,
  • Google Ireland Limited and other Google group entities in connection with Google Tag Manager and Google Analytics,
  • law firms, advisers, accountants and auditors,
  • clients and potential employers conducting recruitment processes,
  • entities performing tasks connected with legalising residence and employment,
  • public authorities, where disclosure is required by law.

Entities processing data on behalf of the Controller should act under appropriate agreements and only in accordance with the Controller’s instructions.

15. Transfers of personal data outside the European Economic Area

In connection with the use of services provided by global suppliers, including Google services, personal data may be processed outside the European Economic Area.

Such transfers are carried out using appropriate legal safeguards, including:

  • a European Commission adequacy decision,
  • the EU–US Data Privacy Framework, where the recipient participates in it,
  • Standard Contractual Clauses approved by the European Commission,
  • other safeguards permitted under the GDPR.

Users may obtain additional information about the safeguards used by contacting the Controller.

16. Personal data retention periods

Personal data is retained no longer than necessary for the purpose for which it was collected.

The retention period depends, in particular, on:

  • the time required to handle an enquiry,
  • the duration of the recruitment process,
  • the duration of a contract,
  • document-retention periods required by law,
  • limitation periods for legal claims,
  • the period for which consent remains valid,
  • the need to demonstrate that consent was properly granted or withdrawn.

After the retention period ends, the data is deleted, anonymised or archived where continued retention is required by law.

17. Rights of data subjects

Depending on the circumstances, a person whose personal data is processed may have the right to:

  • obtain information about the processing of their data,
  • access their data and receive a copy,
  • rectify or complete their data,
  • request deletion of their data,
  • restrict the processing of their data,
  • receive and transfer their data,
  • object to processing based on a legitimate interest,
  • object to direct marketing,
  • withdraw consent at any time,
  • lodge a complaint with the President of the Polish Personal Data Protection Office.

The right to data portability applies to data processed by automated means on the basis of consent or a contract.

The right to object applies, in particular, to processing based on Article 6(1)(f) of the GDPR.

Where personal data is processed for direct marketing purposes, the right to object is unconditional. Once an objection has been submitted, the data will no longer be used for such purposes.

Requests concerning the exercise of these rights may be sent to biuro@est-pologne.eu.

The Controller may request additional information where necessary to verify the identity of the person submitting the request.

18. Voluntary provision of personal data

Providing personal data through the forms is voluntary, but may be necessary to:

  • receive a response,
  • obtain an offer,
  • have an application considered,
  • participate in a recruitment process,
  • enter into or perform a contract,
  • receive the newsletter.

Failure to provide data marked as required may make it impossible to submit a form or provide a particular service.

Consent to future recruitment processes, the newsletter and marketing communications is voluntary and may not be made a condition for handling an enquiry or participating in a current recruitment process.

19. Automated decision-making and profiling

The Controller does not make decisions concerning users that produce legal effects or similarly significantly affect them and that are based solely on automated processing.

Analytics data may be grouped and analysed in order to understand how the Website is used, but this does not result in decisions producing legal effects for the user.

If the Controller introduces automated candidate-matching systems or marketing profiling in the future, this Policy will be updated accordingly.

20. Links to social media platforms

The Website may contain links to the Controller’s profiles on platforms such as Facebook, Instagram or LinkedIn.

The inclusion of a link does not itself result in the automatic transfer of data to the relevant platform, unless additional plugins or scripts are embedded on the Website.

After clicking such a link, the user leaves the Website and uses the social media platform in accordance with the rules established by its operator.

21. Data security

The Controller applies appropriate technical and organisational measures to protect personal data against:

  • loss,
  • destruction,
  • accidental alteration,
  • unauthorised disclosure,
  • unauthorised access,
  • use contrary to its intended purpose.

Access to personal data is granted only to persons who require it to perform their duties and who have been appropriately authorised.

22. Changes to the Privacy Policy

This Privacy Policy may be updated, in particular, in the event of:

  • changes in applicable law,
  • changes in the scope of the Controller’s activities,
  • changes to forms or categories of collected data,
  • implementation of new analytics, marketing or recruitment tools,
  • changes of service providers,
  • launch of a newsletter or advertising system.

The current version of the Policy will be published on the Website together with the date of the latest update.