Privacy Policy (Submission Form)

PRIVACY POLICY regarding the submission of reports of suspected HFC smuggling/illegal trading

Introduction

Thank you for visiting the website:

Bezpieczne HFC – Report suspected illegal activity anonymously (bezpiecznehfc.pl).

This Privacy Policy contains information regarding the processing of personal data of visitors to the above website by the Climate Protection Foundation PROZON, with its registered office in Warsaw, 03-876, ul. Matuszewska 14, Building B9, Tax ID (NIP): 524-18-25-696 (hereinafter referred to as the “Foundation”, “controller”, “PROZON”, or “we”), operated by the Foundation (hereinafter collectively referred to as “Users”).

As the data controller, we wish to assure you that the processing of your personal data is carried out in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as “GDPR”), as well as other generally applicable legislation.

We respect the privacy of our Users and therefore provide this Privacy Policy so that every User is aware of the scope and manner in which their personal data is processed, and can independently, consciously and freely decide whether to use the services and products we offer. In this Privacy Policy, we describe in general terms how and to what extent we collect Users’ personal data, the purposes for which we use such data, to whom we disclose or entrust it, how we protect it, and what rights Users have.

Contact details of the Data Protection Officer

The Data Protection Officer at the PROZON Climate Protection Foundation is Paweł Modrzejewski, and the Deputy Data Protection Officer is Izabela Walczak.

The designated Data Protection Officer can be contacted by email at: inspektor@kiodo.pl.

The Deputy Data Protection Officer can be contacted by telephone at: 791 543 400.

Principles of personal data processing

We value the trust placed in us by our Users. Below we set out the key principles that guide us in processing data:

  • we make every possible effort to ensure that personal data is processed in a secure, fair, lawful and transparent manner,
  • personal data is collected and further processed to the minimum extent necessary for the purposes for which it is gathered,
  • the purposes for collecting personal data are clearly defined and grounded in law — we do not process data in a manner inconsistent with those purposes,
  • PROZON makes every effort to ensure the accuracy and currency of Users’ personal data and to respond promptly to any requests for rectification or updating,
  • in accordance with the principles set out in the GDPR, and depending on the legal basis for processing, we provide Users with the right of access to their personal data, the right to rectification, as well as the right to erasure, restriction of processing, data portability and the right to object to processing,
  • where processing is based on consent, we ensure that consent can be withdrawn as easily as it was given. Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal,
  • we ensure every User the right not to be subject to a decision based solely on automated processing, including profiling,
  • we limit the retention of personal data in accordance with applicable law, to the period strictly necessary for the purposes for which the data is collected, unless circumstances arise that may extend the retention period, such as the pursuit of legal claims,
  • we ensure the security of the data processed,
  • where personal data is shared with third parties, this is done in a secure manner, contractually safeguarded and in compliance with applicable law.

Personal data security

The Foundation implements technical and organisational measures to protect personal data against unlawful or unauthorised access or use, as well as against accidental destruction, loss or compromise of integrity. We ensure the commitment of management and all staff to the operation of the data security system we have established, and a process-based approach to data processing.

As part of ensuring the security of the personal data we process, we undertake to take into account:

  1. confidentiality of data — we protect data against accidental disclosure to third parties,
  2. integrity — we protect data against unauthorised modification,
  3. availability — we ensure that data can be accessed on request, within the assumed timeframe, by an entity authorised to work within the given IT system or resource.

Users’ personal data may be processed by third parties only where such a party has committed to providing appropriate technical and organisational measures guaranteeing the security of personal data processing, as well as to maintaining the confidentiality of such data. Every employee and contractor of the Foundation who has access to personal data holds the appropriate authorisation and is obliged to maintain confidentiality.

  • For what purposes and on what legal basis do we process Users’ data?

The Foundation processes Users’ personal data exclusively for specified, explicit and lawful purposes and on a defined legal basis, namely:

  • Article 6(1)(e) GDPR — processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, in connection with the implementation of the project “Development and implementation of a model of cooperation between state authorities and other entities in order to improve monitoring in the area of HFCs and their illegal trade”, for the purpose of enabling the submission of reports of suspected illegal activities concerning suspected HFC (hydrofluorocarbon) smuggling/illegal trading and taking appropriate action in response to such reports — activities undertaken for the purpose of environmental protection (pollution prevention) in cooperation with the relevant public authorities;
  • for the purposes described in detail in the “Cookies” section, on the basis of consent given (Article 6(1)(a) GDPR) or the Foundation’s legitimate interest (Article 6(1)(f) GDPR);
  • for the purpose of pursuing or defending against legal claims, should any arise, which constitutes our legitimate interest (Article 6(1)(f) GDPR);
  • for statistical and archiving purposes, on the basis of applicable law or our legitimate interest (Article 6(1)(c) and Article 6(1)(f) GDPR).

Reports may be submitted anonymously. The Foundation does not require reporters to provide their personal details. However, it may occur that a reporter voluntarily chooses to provide a detailed description of the matter, thereby consenting to the processing of additional data provided on a voluntary basis.

Where necessary for the proper consideration of a report, the reporter may indicate the participants in the illegal activity. It should be noted that the form created by the Foundation is intended solely for reporting interventions related to the activities of business entities (companies). Reports concerning offences committed by natural persons should be directed to the relevant local municipality or law enforcement authorities — directory of Local Government Units.

Manner and scope of data collection

The personal data of our Users is, as a rule, provided by the Users themselves. The source of any personal data is the reporting party.

Independently, in connection with the User’s use of PROZON’s websites, we also collect data contained in system logs (see the Cookies Policy below for further details).

Users’ rights in connection with the processing of personal data

PROZON upholds Users’ rights in connection with the processing of their personal data. These rights arise from the applicable personal data legislation, in particular Articles 15–22 of the GDPR.

We ensure that every User has:

  • the right of access to data, meaning the right to receive from the Foundation confirmation of whether personal data is being processed by PROZON, to what extent and in what manner, including the right to obtain a copy thereof,
  • the right to rectification — applicable, for example, to outdated or inaccurate personal data, as well as the right to have incomplete data completed,
  • the right to object to the processing of personal data, where we process personal data on the basis of our legitimate interest (e.g. for direct marketing purposes or in pursuit of legal claims — in such cases, upon the User’s objection, we will be required to cease processing their data, unless we can demonstrate the existence of compelling legitimate grounds for the processing that objectively override the User’s privacy interests),
  • the right to erasure of personal data (the “right to be forgotten”) — this consists, as a rule, in requesting the controller to erase the User’s personal data without undue delay. Such a request will be fulfilled in particular where data is processed on the basis of consent or our legitimate interest that is not overriding in relation to the User’s rights and freedoms, or where the purpose of processing based on statutory provisions has ceased to apply. We note, however, that a request for erasure will not be fulfilled where processing is necessary for compliance with a legal obligation to which PROZON is subject,
  • the right to restriction of processing of personal data — this typically involves the temporary blocking of access to the User’s data or the transfer of data to another system,
  • the right to data portability — this entails the ability to receive or have a copy of data transmitted to a specified recipient. It applies where processing is carried out on the basis of consent or a contract, and in an automated manner,
  • the right to lodge a complaint with a supervisory authority — this entails the ability to lodge a complaint with the President of the Personal Data Protection Office (UODO), where the User considers that the processing is being carried out in breach of applicable regulations,
  • the right to withdraw consent to the processing of personal data at any time (see details below in the “Consent — Withdrawal of Consent” section).

The exercise of the above rights must be carried out in accordance with the law, principles of social coexistence and must not infringe the rights and freedoms, including personal rights, of other individuals. Any requests concerning the processing of personal data, including the exercise of rights, may be submitted by email to: prozon@prozon.org.pl or in writing to the Foundation’s registered office, marked “Personal Data”. In the case of a request to withdraw consent, please refer to the “Consent — Withdrawal of Consent” section below.

Each request will be fulfilled without undue delay, and in any event no later than one month after its receipt. This period may be extended in the case of a complex or high volume of requests.

Consent — Withdrawal of consent

The User has the right to withdraw their consent at any time by contacting the Foundation’s office directly or by sending an email to rodo@prozon.org.pl.

Contact details for our individual departments are available at: https://prozon.org.pl/kontakt/.

Withdrawal of consent does not entail any negative consequences or inconvenience; however, it may result in the inability to use certain additional services.

Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.

A request for withdrawal of consent will be processed without undue delay.

Data retention

The User has the right to obtain from us information on the retention period for their personal data in connection with a specific matter.

Where data is processed on the basis of consent, it will be processed until consent is withdrawn, unless the purpose for which consent was given has ceased to apply.

We retain personal data in accordance with applicable law and to the extent necessary, unless circumstances arise that may extend the retention period (e.g. the pursuit of legal claims).

Data recipients and transfers to third countries

The recipients of your personal data may include entities entitled to receive data under applicable legal provisions — that is, public authorities and entities performing public tasks or acting on the instructions of public authorities, to the extent and for the purposes arising from generally applicable law.

In particular, a recipient of personal data in the context of activities undertaken for the purpose of environmental protection may be the Chief Inspector of Environmental Protection, who receives and processes data on the basis of Article 6(1)(c) and (e) GDPR, for the purpose of processing reports, applications and complaints and intervention requests, for the purpose of carrying out inspection and intervention activities relating to environmental pollution or suspected environmental pollution, initiated on the basis of the provisions of the Act of 20 July 1991 on the Environmental Protection Inspectorate, for the purpose of taking action under the aforementioned legal act, for the purpose of ensuring the proper handling of complaints and applications referred to in Chapter VIII of the Act of 14 June 1960 — the Code of Administrative Procedure, and for the purpose of properly conducting administrative proceedings.

In the context of EU projects, data may also be transferred to entities cooperating with us and to the European Commission.

Data may also be transferred to entities that cooperate with us in implementation, including entities processing personal data on our behalf on the basis of a data processing agreement concluded with us (e.g. hosting companies, IT providers, software suppliers).

As a rule, we will not transfer your data to third countries.

Cookie Policy

We inform you that when using the website Bezpieczne HFC – Report suspected illegal activity anonymously (bezpiechnehfc.pl), we collect data contained in system logs. We use this data primarily for technical purposes related to the administration of the website.

In addition, PROZON uses this information for statistical purposes. The statistics we collect allow us primarily to analyse how users make use of the functionalities provided by our websites. System logs contain information about IP addresses (network interface numbers); however, this data does not enable us to unambiguously identify a User (i.e. to identify a specific natural person using a computer or other device connected to the Internet).

Cookies are small text files sent by a given website and stored on the User’s computer (or other device in use). We do not use cookies to collect personal data such as names, surnames or email addresses.

The websites operated by the Foundation use cookies to recognise Users’ personal preferences. In other words, the cookies we use enable us to recognise the User’s computer on their next visit to the website and are intended solely to make navigation easier.

Cookies typically contain the name of the website from which they originate, the duration of their storage on the end device, and a unique identifier. Cookies are used for the purpose of:

  • tailoring the content of the website to the user’s preferences and optimising the use of the website; in particular, these files allow the user’s device to be recognised and the website to be displayed in a manner adapted to their individual needs;
  • generating statistics that help us understand how users navigate the website, enabling us to improve its structure and content; maintaining the user’s session (after logging in), so that the user does not need to re-enter their login credentials on each subpage of the website.

The website uses two principal types of cookies: “session” cookies and “persistent” cookies. Session cookies are temporary files stored on the user’s end device until they log out, leave the website or close the browser. Persistent cookies are stored on the user’s end device for the period specified in the cookie parameters, or until they are deleted by the user.

The following types of cookies are used on the website:

  • “essential” cookies, enabling the use of services available within the website, e.g.

authentication cookies used for services requiring authentication within the website;

  • security cookies, e.g. used to detect authentication abuses within the website;
  • “performance” cookies, enabling the collection of information about how users navigate the website;
  • “functional” cookies, enabling the website to “remember” the settings chosen by the user and to personalise the user interface, e.g. with regard to the selected language or region, font size, website appearance, etc.;
  • “advertising” cookies, enabling the delivery of advertising content better tailored to users’ interests.

In many cases, web browsing software (internet browsers) allows cookies to be stored on the user’s end device by default. Users of the website may at any time change their cookie settings. These settings may be changed in particular so as to block the automatic handling of cookies in the browser settings or to receive notification each time a cookie is placed on the user’s device. Detailed information on the options and methods for managing cookies is available in the software (browser) settings.

The Foundation informs that restrictions on the use of cookies may affect certain functionalities available on the website. Cookies may be placed on the end device of the user of the PROZON website and may also be used by advertisers and partners cooperating with us.

Detailed information on changing cookie settings and deleting them manually in the most popular internet browsers is available in the browser’s help section and on the following pages (simply click the relevant link):

in Chrome in Firefox in Internet Explorer in Opera in Safari in Microsoft Edge

Changes to the Policy

PROZON reserves the right to make changes to this policy, which may result from the need to adapt to changes in legislation or applicable privacy standards, or from the expansion of our offering. The Foundation will notify Users of any such changes by means of an appropriate notice on its websites.

Copyright

All rights to the website Bezpieczne HFC – Report suspected illegal activity anonymously (bezpiechnehfc.pl), including all graphic elements, photographs, page layouts and any other elements thereof, are reserved. The website and all its elements are protected by law, in particular by the Act of 4 February 1994 on Copyright and Related Rights, the Act of 16 April 1993 on Combating Unfair Competition, and the Act of 27 July 2001 on the Protection of Databases.

Updated: 30 July 2024