Privacy Policy
Table of Contents
COOKIES & TRACKING TECHNOLOGIES
DATA SHARING & INTERNATIONAL TRANSFERS
1. Controller Information
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Company:
JP Management
Address:
Jerzmanki 185E, 59-900 Zgorzelec, Poland
NIP:
6152080019
Email:
Website:
If you have any questions about data protection, please contact us at info@jp-management.com.
2. Data We Collect
When you visit our website or use our services, we may collect the following categories of personal data:
Personal data you provide voluntarily: When you submit a contact form, application, or other inquiry, we collect the information you provide, such as your name, email address, phone number, and the content of your message.
Usage data from server logs: Our web servers automatically collect technical information when you visit our website, including your IP address, browser type and version, operating system, referring URL, pages visited, date and time of access, and the amount of data transferred.
3. How We Use Your Data
We process your personal data for the following purposes:
Service inquiries and communication: To respond to your contact requests, process applications, and communicate with you about our services.
Website operation and security: To ensure the technical functionality and security of our website, to detect and prevent abuse, and to optimise the user experience.
4. Legal Basis for Processing
We process your personal data on the following legal bases under Art. 6(1) GDPR:
Consent (Art. 6(1)(a) GDPR): Where you have given us your explicit consent to process your personal data for specific purposes. You may withdraw your consent at any time with effect for the future.
Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR): Where data processing is necessary to take steps at your request prior to entering into a contract, such as when you submit an application or service inquiry through our contact form.
Legitimate interest (Art. 6(1)(f) GDPR): Where processing is necessary for our legitimate interests, provided that these interests are not overridden by your rights and freedoms. Our legitimate interests include ensuring the security and functionality of our website.
5. Cookies & Tracking Technologies
Our website uses only the cookies and storage that are strictly necessary for it to work. Cookies are small text files that are stored on your device when you visit a website; they enable basic website functionality. We do not use analytics, tracking, or advertising cookies.
We distinguish between the following types of cookies:
Strictly necessary cookies and storage: These are essential for the operation of our website and cannot be disabled. Our website stores a single technical entry in your browser's session storage; it is deleted when you close the browser tab.
You can manage your cookie preferences at any time through your browser settings. For comprehensive information about each cookie, its purpose, and its retention period, please refer to our Cookie Policy.
6. Third-Party Services
We use the following third-party service on our website. The service, its provider, purpose, and the data transferred are described below.
Bunny.net content delivery network
Provider: BunnyWay d.o.o. (bunny.net), Slovenia
Purpose: Delivery of the videos embedded on our website. The video files are requested from vz-ea618fed-974.b-cdn.net. This is the only external host our website contacts.
Data transferred: IP address, browser and device information, and the video file requested.
This service does not set cookies. Privacy policy: https://bunny.net/privacy
7. Data Sharing & International Transfers
We do not sell, rent, or trade your personal data to third parties. We may share your data with the third-party service providers listed in Section 6 solely for the purposes described. These providers act as data processors on our behalf and are contractually obligated to process data only in accordance with our instructions and applicable data protection laws.
Where personal data is transferred to countries outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place, including:
- EU-US Data Privacy Framework (DPF): For transfers to US-based providers certified under the DPF, in accordance with the European Commission's adequacy decision.
- Standard Contractual Clauses (SCCs): Where the DPF does not apply, we rely on EU Standard Contractual Clauses adopted by the European Commission to ensure an adequate level of data protection.
- Additional technical and organisational measures where necessary to supplement these safeguards.
We may also disclose your personal data if required to do so by law, by a court order, or by a binding decision of a competent regulatory authority.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. The specific retention periods depend on the type of data:
Contact form submissions:
Retained for up to 12 months after the inquiry has been resolved, unless a contractual relationship is established.
Server log files:
Automatically deleted after 30 days.
After the applicable retention period expires, personal data is securely deleted or anonymised. Statutory retention obligations (e.g., under tax or commercial law) may require us to store certain data for longer periods.
9. Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights with regard to your personal data. To exercise any of these rights, please contact us at info@jp-management.com.
Right of access (Art. 15 GDPR): You have the right to request confirmation as to whether we process your personal data and, if so, to obtain access to that data along with information about the purposes, categories of data, recipients, and retention periods.
Right to rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate personal data and the completion of incomplete data we hold about you.
Right to erasure (Art. 17 GDPR): You have the right to request the deletion of your personal data where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent, where you object to processing, or where the data has been unlawfully processed.
Right to restriction of processing (Art. 18 GDPR): You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when processing is unlawful but you oppose erasure.
Right to data portability (Art. 20 GDPR): Where processing is based on consent or a contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to object (Art. 21 GDPR): You have the right to object at any time to the processing of your personal data based on legitimate interests (Art. 6(1)(f) GDPR). Where personal data is processed for direct marketing purposes, you have the right to object at any time, and we will cease processing your data for that purpose.
Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
10. Right to Lodge a Complaint
If you believe that the processing of your personal data violates the GDPR or other applicable data protection laws, you have the right to lodge a complaint with a supervisory authority.
As our company is registered in Poland, the competent supervisory authority is:
Authority:
Urząd Ochrony Danych Osobowych (UODO)
Address:
ul. Stawki 2, 00-193 Warsaw, Poland
Website:
If you are located in Germany, you may also lodge a complaint with the data protection authority (Landesdatenschutzbeauftragter) of the German federal state in which you reside. A list of all German state data protection authorities and their contact details can be found on the website of the Federal Commissioner for Data Protection and Freedom of Information (BfDI) at www.bfdi.bund.de.
11. Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction.
Our website uses SSL/TLS encryption (HTTPS) to ensure that all data transmitted between your browser and our servers is encrypted and protected during transit. We regularly review and update our security practices to maintain an appropriate level of protection.
Please note that no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee its absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or regulatory guidance. Any changes will be posted on this page with an updated revision date. We encourage you to review this Privacy Policy periodically.
Last updated: February 2026