Privacy Policy
INTRODUCTION
- This Data Protection Policy, together with its appendices, constitutes the documentation in effect at WinWin Sp. z o.o., the operator of the WinWin System and the WinWin Application (the Entity), regarding the implementation, compliance with, and verification of personal data protection rules.
- Every person responsible for implementing, maintaining, or monitoring the rules governing the processing of personal data within the Entity—in particular, members of senior management and, if applicable, the Data Protection Officer—is required to familiarize themselves with this Data Protection Policy, comply with it, and ensure its enforcement within the Entity.
- The Data Protection Policy, together with its attachments, shall take effect on the date it is signed by the persons authorized to represent the Entity.
- With respect to matters not covered by the Data Protection Policy, the provisions of generally applicable law shall apply.
REGISTERS
The entity maintains the following records:
- Record of personal data processing activities—a record of the activities performed by the Entity on personal data, understood as a set of interrelated operations on data, carried out by one or more persons, which can be defined collectively in relation to the purpose for which these activities are undertaken.
- Register of Personal Data Processing Activities—a record of the services entrusted to the Entity and performed on behalf of the controller in connection with the commissioned processing activities.
- Personal Data Breach Register—a record of personal data breaches identified within the Entity,
- Register of Personal Data Protection Measures,
- Register of recipients of personal data,
- Register of persons authorized to process personal data,
- Register of devices used for processing personal data,
- Register of applications used to process personal data,
The entity retains the documents listed in the attachment to this Data Protection Policy.
PERSONAL DATA BREACHES
- The entity implements the breach response procedure set forth in the appendix.
- This procedure applies to all persons working for or providing services to the Entity.
- This procedure applies in the event of a personal data breach or a violation of the rights or freedoms of individuals whose personal data is being processed.
The entity retains the documents listed in the attachment to this Data Protection Policy.
DISCLOSURE REQUIREMENTS
- The entity implements the disclosure requirements listed in the appendix.
- It is prohibited to process personal data without fulfilling the obligation to provide information, unless the grounds for an exemption from this obligation have been individually established in a given case.
- Storage of Templates: attached to this Data Protection Policy.
- Retention of the disclosure obligations imposed: together with the relevant documentation (e.g., as an attachment to the contract).
The entity stores:- the information disclosure templates attached to this Data Protection Policy,
- The disclosure obligations, together with the relevant documentation (e.g., attached to the contract).
AUTHORIZATIONS TO PROCESS PERSONAL DATA
- The entity implements the use of authorizations for the processing of personal data,
- Unauthorized persons are prohibited from processing personal data.
- Authorizations apply to employees.
- Authorizations may be granted to third-party individuals who provide services to the Entity using the Entity’s tools (e.g., an IT specialist working under a contract for services); however, decisions in this regard should be made on a case-by-case basis.
The entity stores:- authorization templates attached to this Data Protection Policy,
- authorizations granted in Part B of personnel files, and, in the case of non-employees, as attachments to the relevant cooperation agreements,
- a record of authorizations in the register of persons authorized to process personal data.
PERSONAL DATA PROCESSING AGREEMENTS
The entity implements the use of model contracts for the processing of personal data.
The model contract for the controller applies when the processing of personal data is outsourced to external processors.
The model contract for the processor applies when the entity performs personal data processing activities entrusted to it by external controllers.
The use of contract templates provided by business partners is permitted, provided they have been documented as approved by senior management or a person designated by senior management.
It is prohibited to outsource the processing of personal data without an appropriate data processing agreement or other legal instrument in accordance with Article 28 of the GDPR.
The entity maintains templates for data processing agreements and executed data processing agreements as attachments to this Data Protection Policy.
RISK ANALYSIS
- The entity applies the principle of assessing the risk of infringing the rights or freedoms of individuals whose personal data is being processed.
- Risk assessment will be conducted in accordance with the terms set forth in the annex.
- It is prohibited to implement new personal data processing activities, deploy new resources for processing such data, or modify personal data protection measures without first conducting or updating a risk assessment.
- The entity agrees to update the risk analysis included in the attachment.
The entity maintains the risk assessment documentation as an attachment to this Data Protection Policy.
PERSONAL DATA PROTECTION IMPACT ASSESSMENTS
- The entity follows a policy of monitoring personal data processing activities to determine whether they require a DPIA (Data Protection Impact Assessment).
- If a particular activity requires an OSOD to be conducted, the template provided in the attachment shall be used.
- It is prohibited to implement new personal data processing activities without first conducting a risk analysis or updating an existing one, and, if the analysis confirms the necessity of such activities, without conducting a Data Protection Impact Assessment (DPIA).
The entity maintains a template for personal data impact assessments and documentation of the assessments conducted, which are attached to this Data Protection Policy.
PERSONAL DATA PROTECTION MEASURES
Taking into account the recommendations from the risk assessment and the requirements set forth in Article 32 of the GDPR:
- The entity implements the personal data protection measures listed in the appendix—the Register of Data Protection Measures. It is prohibited to implement changes to personal data protection measures without recording them. Furthermore, the entity undertakes to keep them up to date.
- The entity shall implement the procedures (organizational measures for the protection of personal data) listed in the appendix—“Procedures.” It is prohibited to make changes to the implemented procedures without adopting them in accordance with the rules of representation. Furthermore, the entity undertakes to update them.
- The entity shall maintain a register of devices and a register of applications used to process personal data. It is prohibited to use devices or applications that are not listed in these registers. Furthermore, the entity undertakes to keep these registers up to date.
The entity maintains the documentation listed in the appendix to this Data Protection Policy.
MEASUREMENT AND TESTING
The entity undertakes to regularly test, measure, and evaluate the effectiveness of its personal data protection measures, in particular by:
- ongoing updates to the personal data breach log, risk assessments, the personal data protection measures log and implemented procedures, device and application logs, the IT system inspection and maintenance log, as well as the log of significant activities in the IT system.
- conducting audits of the personal data processing system,
- Recording audits of the personal data processing system in the personal data processing system audit log.
The entity maintains a record of audits of the personal data processing system, which is attached to this Data Protection Policy.
DATA PROTECTION OFFICER
- The entity has appointed a Data Protection Officer, as set forth in the document attached to this Data Protection Policy.
XII MONITORING
The entity does not use any form of monitoring.
XIII APPENDICES
The appendices to this Data Protection Policy constitute an integral part thereof:
A – LIST OF ATTACHMENTS A (basic documents):
- Record of personal data processing activities,
- Register of categories of personal data processing activities,
- Record of Personal Data Breaches,
- Register of Personal Data Protection Measures,
- Register of recipients of personal data,
- Disclosure requirements,
- Authorization for Employees – Template,
- Authorization for Individuals Employed Under Civil Law Contracts – Template,
- Data Processing Agreement for a Data Controller – Template,
- Data Processing Agreement for a Data Processor – Template,
- Risk Analysis – Guiding Document,
- Risk matrices,
- Data Protection Impact Assessment – Template,
- Statement on the Appointment of the Data Protection Officer,
B – LIST OF ANNEXES B (procedures – organizational data protection measures):
- Procedure for Handling Personal Data Breaches,
- The "privacy by default" procedure,
- Procedure for Recording Equipment and Data Storage Media,
- Procedure for using the Internet,
- Procedure for Using a Work Computer,
- Procedure for Using a Company Phone,
- Procedure for using email,
- Procedure for Using Mobile Devices,
- Procedure for Handling Passwords and Access Files,
- Procedure for Outsourcing the Processing of Personal Data,
- Privacy-by-design procedure,
- Procedure for Inspections and Maintenance of the IT System,
- Procedure for processing personal data in paper form,
- Procedure for Receiving Personal Data in Trust,
- Procedure for Complying with the Disclosure Requirement,
- Procedure for Deleting Personal Data,
- Procedure for Handling Data Subject Requests,
- Backup procedure,
- Procedure for Sharing Personal Data,
- Procedure for accessing keys and objects,
- Procedure for Disposing of Devices and Data Storage Media,
- Procedure for Controlling Access to the Information System,
- Antivirus Protection Procedure,
C – LIST OF APPENDICES C (supplementary documents):
- Register of persons authorized to process personal data,
- Audit log for the personal data processing system,
- Register of devices used for processing personal data,
- Register of applications used to process personal data,
- IT System Inspection and Maintenance Log,
- Log of significant activities in the IT system.