Basic information
The administrator of personal data is Gorilla Software Sp. z o.o. with its registered office in Rzeszów (35-006)
Contact with the Administrator: contact@softgorillas.com
Service: gorilla-commerce.eu (hereinafter: „Service") — the website of Gorilla Commerce, providing migration, implementation, and maintenance services for e-commerce stores.
Full registration data: ul. Jana i Jędrzeja Śniadeckich 20D/7, 35-006 Rzeszów, NIP: 8133856997, REGON: 388472110, KRS: 0000890717.
Purposes and legal basis for processing
- Art. 6 sec. 1 lit. a GDPR (consent) — newsletter, marketing, analytical and advertising cookies.
- Art. 6 sec. 1 lit. b GDPR (performance of the contract) — provision of services, order handling, invoicing.
- Art. 6 sec. 1 lit. c GDPR (legal obligation) — keeping tax and accounting documentation.
- Art. 6 sec. 1 lit. f GDPR (legitimate interest) — analytics, optimization of the Service, pursuit of claims, remarketing, contact with potential clients.
Types of collected data
- Identification and contact data: first name, last name, e-mail address, phone number, company name, position.
- Technical data: IP address, device identifier, internet browser data, operating system, approximate location, browser language.
- Data related to the use of the Service: visited pages, time spent on the page, traffic source, clicks, navigation path, progress in interactive tools (e.g. SEO Checklist).
- Business data: provided in contact forms — industry, business scale, budget, current store technology, development plans.
- Data for contract performance: company data (NIP, REGON, KRS, registered address), contact person data on the client's side, invoicing data.
- Data from cookies: session identifiers, preferences, analytical data — details in the Cookie Policy.
Data processing time
- Contact forms: until a response is provided, and then for a period of up to 3 years for the purpose of handling potential claims and contact history.
- Newsletter: until the User withdraws their consent (possible at any time by clicking the "Unsubscribe" link in each message).
- Data for contract performance: for the duration of the contract, and then for the period of limitation of claims arising from the contract (usually 6 years) and the period required by tax regulations (5 years from the end of the year in which the invoice was issued).
- Data from cookies: in accordance with the validity periods of individual cookies — details in the Cookie Policy (from session to 24 months).
- Server logs and technical data: up to 14 months for security and diagnostic purposes.
- Data processed on the basis of consent: until consent is withdrawn.
- Data for remarketing: up to 540 days from the last interaction with the Service.
Recipients of personal data
- Infrastructure and hosting providers: server and file hosting service providers.
- Analytics tool providers: Google LLC (Google Analytics 4, Google Tag Manager, Google Search Console), Hotjar Ltd, Microsoft Clarity.
- Marketing tool providers: Google LLC (Google Ads), Meta Platforms Inc. (Facebook Pixel, Instagram Ads), LinkedIn Corporation (LinkedIn Insight Tag).
- CRM and email marketing system providers: systems for managing customer databases and sending newsletters.
- Form tool providers: systems for handling contact forms and data transmission.
- Accounting office: in the scope of invoice handling and settlements with clients.
- Law firms: in the scope of legal services, including claims enforcement.
- State authorities and institutions: in cases provided for by law (e.g. tax offices, law enforcement agencies on the basis of valid requests).
User Rights
Right of access to data (Article 15 GDPR)
The User has the right to obtain from the Administrator confirmation of whether personal data concerning them is being processed, and to obtain a copy of such data.
Right to rectification (Article 16 GDPR)
The User has the right to request the rectification of inaccurate data and the completion of incomplete data.
Right to erasure ("right to be forgotten", Article 17 GDPR)
The User has the right to request the erasure of data in cases specified in the GDPR — including when the data is no longer necessary for the purposes for which it was collected.
Right to restriction of processing (Article 18 GDPR)
The User has the right to request the restriction of data processing in certain situations provided for in the GDPR.
Right to data portability (Article 20 GDPR)
The User has the right to receive their data in a structured format and to transfer it to another administrator.
Right to object (Article 21 GDPR)
The User has the right to object to the processing of data, in particular in the case of processing for direct marketing purposes.
Right to withdraw consent
If the processing is based on consent (Article 6(1)(a) GDPR), the User has the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of the processing that took place prior to the withdrawal of consent.
Right to lodge a complaint with a supervisory authority
The User has the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl).
Transferring data outside the EEA
- Decisions of the European Commission confirming an adequate level of data protection — in particular, Commission Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy Framework for certified US entities.
- Standard contractual clauses (Standard Contractual Clauses, SCC) approved by the European Commission, used in contracts with providers outside the EEA.
- Additional security measures required by the CJEU (in particular, the Schrems II judgment).
Profiling and automated decision-making
The Administrator does not make automated decisions towards Users, including decisions based on profiling within the meaning of Article 22(1) GDPR, which would have legal effects on them or similarly significantly affect them.
Within the analytical and advertising tools (Google Analytics 4, Meta Pixel, LinkedIn Insight Tag), behavioral profiles of Users may be created based on their activity in the Service. These profiles serve only statistical purposes and optimization of advertising campaigns and do not constitute the basis for making individual automated decisions.
The User has the right not to be subject to marketing profiling — it is enough to withdraw consent for analytical and advertising cookies through the cookie preferences panel available in the Service.
Data security
- Encryption of communication — The Service operates in the HTTPS protocol with a current SSL certificate, ensuring the encryption of data transmitted between the User's browser and the server.
- Access control — access to personal data is limited to authorized employees of the Administrator and data processors to whom the data has been entrusted on the basis of a contract.
- Regular backups and data recovery procedure tests.
- Security monitoring — systems for detecting unauthorized access, log monitoring, DDoS protection.
- Regular security audits and software updates.
- Internal security policies — employee training, incident response procedures, business continuity plans.
Cookies
The Service uses cookies (cookies) — small text files saved on the User's device while using the Service. Detailed information about the types of cookies, the purposes of their use, third parties having access to cookies, and ways of managing cookie preferences can be found in a separate document — Cookie Policy.
The User can change cookie settings at any time through the preferences panel available in the Service or through their internet browser settings.
Changes to the Privacy Policy
- changes to the laws applicable to the Administrator;
- the introduction of new functionalities or services in the Service requiring new processing purposes;
- changes to the tools and data processors used by the Administrator;
- the introduction of significant organizational changes on the part of the Administrator.
Contact
In matters related to personal data protection, please contact:
E-mail: contact@softgorillas.com
Correspondence address: Gorilla Software Sp. z o.o., 35-006 Rzeszów
We respond to inquiries regarding personal data without undue delay, no later than 30 days from the receipt of the request.
Children's data protection
The Service is not directed at children and we do not knowingly collect personal data from anyone under the age of 16. If a parent or legal guardian becomes aware that a child has provided us with their data without consent, please contact us at contact@softgorillas.com — we will remove such data promptly.