Privacy and Cookies Policy
Website: https://readyoffice.pl. Last updated: 13 August 2026.
§1. General provisions
- This Policy sets out the rules for processing and protecting the personal data of persons using the readyoffice.pl website (hereinafter: “the Website", “the User") and the rules for using cookies.
- The Controller of personal data is READY OFFICE spółka z ograniczoną odpowiedzialnością (limited liability company) with its registered office in Wrocław, ul. Braniborska 7 lok. 2, 53-680 Wrocław, entered in the Register of Entrepreneurs of the National Court Register under number KRS 0001016520, whose registration files are kept by the District Court for Wrocław-Fabryczna in Wrocław, 6th Commercial Division of the National Court Register, Tax ID (NIP) 8971917432, statistical number (REGON) 524338740 (hereinafter: “the Controller").
- Contact regarding personal data: e-mail info@readyoffice.pl, tel. +48 696 468 551, or the form: https://readyoffice.pl/en/contact/.
- The Controller has not appointed a Data Protection Officer. For all matters concerning personal data, please use the contact details set out in point 3.
- Data is processed in accordance with: Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), the Personal Data Protection Act of 10 May 2018, and the Electronic Communications Law of 12 July 2024 (PKE).
- The Website uses SSL data transmission encryption.
§2. Scope, purposes and legal bases of processing
- We obtain data: (a) when the User voluntarily provides it in the Website forms (contact, enquiry, quote request), (b) when the User completes a contact form made available on Facebook or Instagram (a so-called Instant Form), (c) automatically through cookies, (d) from server logs, (e) when the User interacts with our profile on social media.
- Scope of data: first name and surname, company name, phone number, e-mail address, content of the enquiry (including the city indicated), answers to the questions asked in the form, IP address, connection and browser information, and other data provided voluntarily.
- Purposes and legal bases (Article 6(1) GDPR):
- handling the enquiry and contact, preparing a quote and offer – Article 6(1)(b) (steps taken to conclude a contract) and (f) (legitimate interest: handling correspondence). Where the User requests contact in a form, we contact them through the channel they have indicated, that is by e-mail or by phone on the number provided;
- electronic marketing (offers, newsletter, contact by e-mail/SMS/phone) – Article 6(1)(a) (consent). Sending marketing communications by electronic means, including contact by phone and SMS, requires separate prior consent in accordance with Article 398 of the Electronic Communications Law and the Act on Providing Services by Electronic Means;
- fulfilment of the Controller’s legal obligations (e.g. accounting, tax) – Article 6(1)(c);
- statistics, analytics, security and development of the Website – Article 6(1)(f) (legitimate interest); analytics and marketing cookies are used on the basis of consent – Article 6(1)(a), given in the consent banner;
- measuring the effectiveness of advertising campaigns run on Meta platforms, including assessing the quality of submissions received – Article 6(1)(f) (legitimate interest: conducting and optimising the Controller’s own marketing activities and reducing advertising costs). Details in §3 point 8;
- maintaining profiles on social media and communicating with the audience – Article 6(1)(f) (legitimate interest: promoting the Controller’s own services and responding to enquiries). Details in §3 point 9.
- The consent to electronic marketing referred to in point 3(b) is voluntary. Withholding it has no effect on the handling of the enquiry, the preparation of an offer or the terms we may propose.
- Providing data is voluntary but necessary to handle the enquiry or prepare an offer.
- Instant Forms: data entered in a contact form displayed on Facebook or Instagram is first collected by Meta Platforms Ireland Ltd. and subsequently transferred to the Controller and saved in the CRM system. The rules governing processing on Meta’s side are set out in that company’s privacy policy: https://www.facebook.com/privacy/policy
§3. Cookies and analytics and advertising tools
- Cookies are text files stored on the User’s end device while using the Website.
- We use the following cookies: strictly necessary (ensuring the Website functions), functional, analytics and marketing.
- Consent: cookies other than strictly necessary ones are installed only after the User has given prior CONSENT via the consent banner (the CookieYes tool). Consent is voluntary, and the User may withdraw it or change settings in the consent panel at any time. The legal basis is Article 399 of the Electronic Communications Law of 12 July 2024 in conjunction with the GDPR. As of 10 November 2024, that provision replaced Article 173 of the repealed Telecommunications Law.
- Until consent is given, analytics and marketing tools operate in a restricted mode (consent mode), without storing data on the User’s device.
- Forms on the Website are protected by Google reCAPTCHA. It operates as a measure necessary to provide the service requested by the User within the meaning of Article 399(3)(2) of the Electronic Communications Law and, to that extent, processes among other things the IP address and information about behaviour on the Website.
- Cookies are divided into session cookies (deleted when the browser is closed) and persistent cookies (stored for a specified time or until manually deleted). The User can also manage cookies from the browser settings, including disabling them entirely.
- Google Signals: within Google Analytics 4 we use the Google Signals feature. It allows information about visits to the Website to be associated with the Google account data of those Users who are signed in to their Google account and have consented to ad personalisation. The feature serves to obtain aggregate information about the Website’s audience, including approximate age, gender and interests, as well as cross-device measurement. The Controller receives aggregate data only and has no access to data identifying individual persons. Legal basis: Article 6(1)(a) GDPR (consent given in the consent banner in respect of analytics and marketing cookies). Users may disable ad personalisation on Google’s side at any time in their account settings at https://myadcenter.google.com, and may review and delete the data collected at https://myactivity.google.com
- Meta advertising tools: the Website may use the Meta Pixel and the Meta Conversions API, provided by Meta Platforms Ireland Ltd.
- The Meta Pixel operates in the browser and collects information about Users’ actions on the Website in order to personalise advertising on Facebook and Instagram. It is activated only after consent to marketing cookies has been given. The Pixel may use Advanced Matching, transferring to Meta in encrypted form (SHA-256 hash) data provided in forms, such as an e-mail address or telephone number, solely in order to better match conversions and advertising audiences.
- The Meta Conversions API enables information about conversions to be transferred directly from the Controller’s systems, on the server side. The following is transferred: the submission identifier assigned by Meta (Lead ID) and the advertisement click identifier, the e-mail address and telephone number in one-way encrypted form (SHA-256 hash), and information about the stage of handling the submission (for example: contact made, submission qualified, contract concluded) – without the content of conversations, without financial data and without information about the subject matter of the contract. This processing covers exclusively submissions originating from the Controller’s advertising campaigns run on Meta platforms. The transfer takes place on the server side and does not require cookies.
- The User has the right to object to the processing referred to in (b) pursuant to Article 21(1) GDPR and, in respect of direct marketing, pursuant to Article 21(2) GDPR, without giving any reason. An objection may be submitted to info@readyoffice.pl. Advertising settings on Meta’s side can be managed at: https://www.facebook.com/ads/preferences
- Social media profiles: the Controller maintains profiles on Facebook and Instagram. With regard to statistics concerning the profile’s audience (aggregate data on reach, impressions and audience demographics), the Controller and Meta Platforms Ireland Ltd. act as joint controllers. The arrangement governing this joint controllership and the allocation of responsibilities between the parties is set out in the document available at: https://www.facebook.com/legal/terms/page_controller_addendum. The Controller receives aggregate data only and has no access to data identifying individual members of the audience.
§4. Data recipients and processors
Data may be entrusted to trusted processors acting on behalf of the Controller, to the extent necessary to achieve the stated purposes. Among others, we use:
- hosting provider: Zenbox;
- Brevo (Sendinblue) – handling of mailing and e-mail marketing;
- Pipedrive – CRM system (managing enquiries and contacts);
- Make (Integromat) – automation of data flow from forms and transfer of conversion information to advertising systems;
- Google – Google Analytics, Google Ads, Google reCAPTCHA, Google Tag Manager, Google Maps;
- Meta Platforms Ireland Ltd. – advertising and remarketing tools (Meta Pixel, Conversions API, Instant Forms, advertising on Facebook and Instagram);
- CookieYes – cookie consent management;
- entities providing accounting, legal and advisory services.
Data may also be disclosed to public authorities on the basis of applicable law. Access to data is granted only to persons authorised by the Controller.
§5. Transfers of data outside the EEA
The use of certain services (e.g. Google and Meta tools) may involve transferring personal data outside the European Economic Area, including to the United States. The transfer takes place on the basis of appropriate safeguards, i.e. Standard Contractual Clauses (SCC) approved by the European Commission and/or the EU-US Data Privacy Framework.
A copy of the safeguards applied, or information on where they have been made available, can be obtained by writing to info@readyoffice.pl.
§6. Data retention period
We store data no longer than necessary to achieve the purposes and in accordance with legal requirements:
- data from an enquiry / preparation of an offer – for the time the matter is being handled and 12 months after its completion, unless a contract is concluded;
- data processed on the basis of marketing consent – until consent is withdrawn;
- data related to the performance of contracts and accounting and tax obligations – for the period required by law (as a rule, 5 years);
- information about the source of a submission transferred to advertising systems – for the time the matter is being handled and the limitation period for claims; data transferred to Meta is processed in accordance with that company’s rules;
- server logs – for 12 months.
§7. User’s rights
The User has the right to: access their data, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent at any time – without affecting the lawfulness of processing carried out before its withdrawal.
An objection to the processing of data for direct marketing purposes may be raised at any time and does not require any justification (Article 21(2) GDPR). Otherwise, an objection concerns processing based on the Controller’s legitimate interest and requires the User to indicate their particular situation.
Marketing consent may be withdrawn at any time by sending a message to info@readyoffice.pl or by using the unsubscribe link included in the footer of our messages.
The User has the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw.
The Controller does not make decisions concerning the User based solely on automated processing that would produce legal effects on the User or similarly significantly affect them. Within analytics and advertising tools (e.g. Google, Meta), profiling for statistical and marketing purposes may take place – it is carried out on the basis of consent given in the cookie banner, which can be withdrawn at any time.
Profiling for marketing purposes also includes assessing the quality of submissions originating from advertising campaigns, carried out on the basis of the stage of handling the matter in the CRM system. This assessment produces no legal effects concerning the User and does not significantly affect them – it serves solely to direct future advertising to persons with a similar interest profile. The User has the right to object to such processing.
§8. Server logs
Information about certain User activities (URLs, request time, IP address, browser information, errors encountered) is recorded on the server side and used solely to administer the Website and to ensure its security and performance. This data is not linked to specific individuals.
§9. How we protect your data
We apply technical and organisational measures appropriate to the risk:
- SSL/TLS encryption of the connection to the website and forms;
- access to data is limited to authorised persons bound by confidentiality;
- we conclude data processing agreements with our processors (§4);
- the server is secured and regularly backed up by the hosting provider;
- the admin panel and access accounts are protected.
§10. Personal data breaches
In the event of a personal data breach that may result in a risk to the rights or freedoms of individuals, we report it to the President of the Personal Data Protection Office (PUODO) within 72 hours of becoming aware of it (Article 33 GDPR). Where the breach involves a high risk, we also inform the affected individuals without undue delay (Article 34 GDPR). We keep an internal register of breaches. A suspected breach can be reported to: info@readyoffice.pl.
§11. Changes to the Policy
The Controller may update this Policy. The current version is always available on the Website, together with the last updated date shown at the top of the document. If you have any questions, please contact: info@readyoffice.pl.
This is a translation of the Polish-language Privacy Policy. In the event of any discrepancy between the language versions, the Polish version prevails.