Privacy Policy

WEBSITE PRIVACY POLICY

KONSULTACJE-DUBAJ.PL

General provisions

This privacy policy of the website available at www.konsultacje-dubaj.pl (the “Site” or the “Website”) is informational in nature, which means it is not a source of obligations for users of the Site. The privacy policy sets out, above all, the rules for the processing of personal data by the Controller on the Website, including the grounds, purposes and scope of processing and the rights of data subjects, as well as information about the use of cookies and analytics tools on the Website.

The controller of personal data collected through the Website, and its owner, is:

NDN REAL ESTATE CONSULTANTS LLC, with its registered office in Dubai, United Arab Emirates (registered address: Emaar Square Building 6 Unit 702, Dubai, United Arab Emirates; correspondence address: PO BOX 122347, Dubai, United Arab Emirates); tax registration number (TAX REG. NO.): 104383347200001, email address: kontakt@demo.agencjacudo.pl, phone number: +48 455444000 (call charged as a standard phone call, in line with your provider’s tariff plan).

(the “Controller” or the “Owner”)

Quick contact:

  • email: kontakt@demo.agencjacudo.pl
  • the contact form available on the Site
  • phone: +48 455444000 (call charged as a standard phone call, in line with your provider’s tariff plan)

Personal data on the Website is processed by the Controller in accordance with the applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), referred to below as the “GDPR”. The official text of the GDPR: http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679

Use of the Website is voluntary. Likewise, the related provision of personal data by a user of the Website is voluntary, except where it is necessary to use certain functionalities of the Website, including, for example, the contact form. Failing to provide, in the cases and to the extent required, the personal data necessary to use a given functionality of the Site results in not being able to use that functionality. In each case the scope of data required to use a functionality of the Site is indicated by the Controller on the Website (for example before filling in the contact form).

The Controller takes particular care to protect the interests of the data subjects whose personal data it processes and, in particular, is responsible for and ensures that the data it collects is: (1) processed lawfully; (2) collected for specified, lawful purposes and not further processed in a way incompatible with those purposes; (3) accurate and adequate in relation to the purposes for which it is processed; (4) kept in a form that permits identification of the data subjects for no longer than is necessary to achieve the purpose of processing; and (5) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

Taking into account the nature, scope, context and purposes of processing and the risk to the rights and freedoms of natural persons of varying likelihood and severity, the Controller implements appropriate technical and organisational measures to ensure that processing is carried out in accordance with the GDPR and to be able to demonstrate this. These measures are reviewed and updated where necessary. The Controller uses technical measures to prevent unauthorised persons from obtaining and modifying personal data sent electronically.

Legal notice

This Site is informational in nature. It lets you learn about the Owner’s products or services and get in touch with the Owner, for example by submitting an enquiry through the contact form. The Site may also offer a newsletter whose purpose is to inform about the Owner’s activities, news and new products and services. The law applicable to the Site, these terms and any agreements concluded on their basis is Polish law.

The Site is not an online shop and it is not possible to conclude a contract of sale through it (this means, among other things, that adverts, price lists and other information about products published on the Site should not be treated as an offer, but at most as an invitation to conclude a contract). A contract of sale may be concluded following an enquiry addressed to the Owner and only after the parties have agreed the detailed terms of that contract. The conclusion and terms of such a contract are, however, governed by a separate contract of sale or separate general terms of sale of products by the Owner, which the Owner will make available.

Grounds for processing data

The Controller is entitled to process personal data where, and to the extent that, at least one of the following conditions is met: (1) the data subject has given consent to the processing of their personal data for one or more specific purposes; (2) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; (3) processing is necessary for compliance with a legal obligation to which the Controller is subject; or (4) processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

Processing of personal data by the Controller always requires at least one of the grounds indicated above. The specific grounds for the Controller’s processing of the personal data of Website users are indicated in the next section of the privacy policy, in relation to a given purpose of the Controller’s processing of personal data.

Purpose, basis and period of data processing on the Website

In each case the purpose, basis and scope of, and the recipients of, personal data processed by the Controller arise from the actions taken by a given user on the Website.

The Controller may process personal data on the Website for the following purposes, on the following bases, for the following periods and to the following extent:

Purpose of data processingLegal basis for data processingData retention period
Performance of a contract for the provision of an Electronic Service, or taking steps at the request of the data subject prior to entering into a contractArticle 6(1)(b) GDPR (performance of a contract), processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contractThe data is kept for the period necessary to perform, terminate or otherwise end the electronic services contract concluded with the Controller.
Direct marketingArticle 6(1)(f) GDPR (the controller’s legitimate interest), processing is necessary for the purposes of the Controller’s legitimate interests, namely caring for the interests and good image of the Controller and pursuing the sale of products or servicesThe data is kept for the period during which the Controller’s legitimate interest exists, but no longer than the limitation period for claims against the data subject arising from the Controller’s business activity. The limitation period is set by law, in particular the Civil Code (the basic limitation period for claims connected with running a business is three years, and for a contract of sale two years). The Controller may not process data for direct marketing purposes if the data subject has effectively objected to it.
MarketingArticle 6(1)(a) GDPR (consent), the data subject has given consent to the processing of their personal data for marketing purposes by the ControllerThe data is kept until the data subject withdraws consent to the further processing of their data for this purpose.
Establishing, pursuing or defending claims that the Controller may raise or that may be raised against the ControllerArticle 6(1)(f) GDPR, processing is necessary for the purposes of the Controller’s legitimate interests, namely establishing, pursuing or defending claims that the Controller may raise or that may be raised against the ControllerThe data is kept for the period during which the Controller’s legitimate interest exists, but no longer than the limitation period for claims against the data subject arising from the Controller’s business activity. The limitation period is set by law, in particular the Civil Code (the basic limitation period for claims connected with running a business is three years).
Use of the Website and ensuring it works properlyArticle 6(1)(f) GDPR (the controller’s legitimate interest), processing is necessary for the purposes of the Controller’s legitimate interests, namely running and maintaining the WebsiteThe data is kept for the period during which the Controller’s legitimate interest exists, but no longer than the limitation period for the Controller’s claims against the data subject arising from the Controller’s business activity. The limitation period is set by law, in particular the Civil Code (the basic limitation period for claims connected with running a business is three years).
Keeping statistics and analysing traffic on the WebsiteArticle 6(1)(f) GDPR (the controller’s legitimate interest), processing is necessary for the purposes of the Controller’s legitimate interests, namely keeping statistics and analysing traffic on the Website in order to improve how the Website worksThe data is kept for the period during which the Controller’s legitimate interest exists, but no longer than the limitation period for the Controller’s claims against the data subject arising from the Controller’s business activity. The limitation period is set by law, in particular the Civil Code (the basic limitation period for claims connected with running a business is three years).

Recipients of data on the Website

For the Website to work properly, the Controller needs to use the services of external entities (such as a software provider). The Controller uses only processors that provide sufficient guarantees to implement appropriate technical and organisational measures so that processing meets the requirements of the GDPR and protects the rights of data subjects.

Personal data may be transferred by the Controller to a third country, but the Controller ensures that in such a case this will take place in relation to a country that provides an adequate level of protection, compliant with the GDPR, and in the case of other countries, that the transfer will take place on the basis of standard data protection clauses. The Controller ensures that the data subject is able to obtain a copy of their data. The Controller transfers collected personal data only where and to the extent necessary to achieve a given data processing purpose consistent with this privacy policy.

Data is not transferred by the Controller in every case and not to all recipients or categories of recipients indicated in the privacy policy. The Controller transfers data only where it is necessary to achieve a given personal data processing purpose and only to the extent necessary to achieve it.

The personal data of Website users may be transferred to the following recipients or categories of recipients:

  • service providers that supply the Controller with technical, IT and organisational solutions that enable the Controller to run its business, including the Website and the electronic services provided through it (in particular providers of the software used to run the Website, email and hosting providers, and providers of business management software and technical support for the Controller). The Controller shares collected personal data of a Site user with a selected provider acting on its instructions only where and to the extent necessary to achieve a given data processing purpose consistent with this privacy policy.
  • legal and advisory service providers that provide the Controller with accounting, legal or advisory support (in particular a law firm). The Controller shares collected personal data of a Site user with a selected provider acting on its instructions only where and to the extent necessary to achieve a given data processing purpose consistent with this privacy policy.

Profiling on the Site

The GDPR requires the Controller to provide information about automated decision-making, including profiling, referred to in Article 22(1) and (4) of the GDPR, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. With this in mind, the Controller provides in this section of the privacy policy information about possible profiling.

Profiling on the Site involves the automatic analysis or prediction of a person’s behaviour on the Site, for example by viewing the page of a specific product on the Site. The condition for such profiling is that the Controller holds the person’s personal data so that it can then send them, for example, a discount code.

The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

The rights of the data subject

The right of access, rectification, restriction, erasure or portability. The data subject has the right to request from the Controller access to their personal data, its rectification, erasure (“the right to be forgotten”) or restriction of processing, and has the right to object to processing, as well as the right to data portability. The detailed conditions for exercising the above rights are set out in Articles 15 to 21 of the GDPR.

The right to withdraw consent at any time. A person whose data is processed by the Controller on the basis of given consent (under Article 6(1)(a) or Article 9(2)(a) GDPR) has the right to withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.

The right to lodge a complaint with a supervisory authority. A person whose data is processed by the Controller has the right to lodge a complaint with a supervisory authority in the manner and form set out in the GDPR and Polish law, in particular the Personal Data Protection Act. The supervisory authority in Poland is the President of the Personal Data Protection Office.

The right to object. The data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of their personal data based on Article 6(1)(e) (public interest or tasks) or (f) (the controller’s legitimate interest), including profiling based on those provisions. In such a case the Controller may no longer process that personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal claims.

The right to object to direct marketing. Where personal data is processed for direct marketing purposes, the data subject has the right to object at any time to the processing of their personal data for such marketing, including profiling, to the extent that the processing is related to such direct marketing.

To exercise the rights referred to in this section of the privacy policy, you can contact the Controller by sending an appropriate message in writing or by email to the Controller’s address indicated at the beginning of the privacy policy.

Cookies on the Website and analytics

Cookies are small pieces of text information in the form of text files, sent by a server and saved on the device of the person visiting the Website (for example on the hard drive of a computer or laptop, or on the memory card of a smartphone, depending on the device the visitor uses). Detailed information about cookies, and the history of how they came about, can be found, among other places, here: https://en.wikipedia.org/wiki/HTTP_cookie.

The Controller may provide on the Site a tool for easy and active management of cookies, available on your first visit to the Site and then available in the Site footer. Active management lets you, among other things, check which cookies are or may be saved while using the Site, and choose and later change the scope and purposes of cookie use in relation to the device and the person visiting the Site. When you start using the Site you will be asked to choose your cookie settings. You can change them later by changing the settings in this tool available on the site.

In the privacy policy the Controller provides a range of information about the use of cookies on the Site, their types and purposes and how to manage them using, for example, web browser settings or the cookie management tool available on the Site. The Controller encourages you to use the cookie management tool available on the Site, which lets you easily and actively manage cookies while using the Site, and, if it is not available, to read the information below about, among other things, managing cookies from the browser.

The cookies that may be sent by the Website can be divided into different types, according to the following criteria:

By their provider: first party (created by the Controller’s Website) and third party (belonging to persons or entities other than the Controller). By how long they are stored on the device of the person visiting the Website: session cookies (stored until you leave the Website or close the browser) and persistent cookies (stored for a set time, defined by the parameters of each file, or until manually deleted). By the purpose of their use: necessary (enabling the Website to work properly), functional or preference cookies (enabling the Website to be adapted to the preferences of the person visiting the site), analytical and performance cookies (gathering information about how the Website is used), and marketing, advertising and social media cookies (gathering information about the person visiting the Website in order to display adverts to that person, personalise them, measure their effectiveness and carry out other marketing activities, including on websites other than this Site, such as social media platforms or other sites belonging to the same advertising networks as the Website).

The Controller may process the data contained in cookies while visitors use the Website for the following specific purposes:

Purposes of using cookies on the Controller’s Websiteremembering data from completed forms (necessary or functional/preference cookies)
adapting the content of the Website to the user’s individual preferences (for example colours, font size, page layout) and optimising the use of the Website (functional/preference cookies)
keeping anonymous statistics showing how the Website is used (analytical and performance cookies)
displaying and rendering adverts, limiting the number of ad impressions and ignoring adverts the user does not want to see, measuring the effectiveness of adverts, and personalising adverts, that is studying the behaviour of people visiting the Website through an anonymous analysis of their actions (for example repeated visits to certain pages, keywords and so on) in order to create their profile and deliver adverts matched to their expected interests, including when they visit other websites in the advertising network of Google Ireland Ltd. and Facebook, that is Meta Platforms Ireland Ltd. (marketing, advertising and social media cookies)

You can check, in the most popular web browsers, which cookies (including how long they last and their provider) are being sent at a given moment by the Website in the following way:

In Chrome:
(1) in the address bar click the padlock icon on the left, (2) go to the “Cookies” tab.
In Firefox:
(1) in the address bar click the shield icon on the left, (2) go to the “Allowed” or “Blocked” tab, (3) click “Cross-site tracking cookies”, “Social media trackers” or “Tracking content”.
In Internet Explorer:
(1) click the “Tools” menu, (2) go to “Internet options”, (3) go to “General”, (4) go to “Settings”, (5) click “View files”.
In Opera:
(1) in the address bar click the padlock icon on the left, (2) go to the “Cookies” tab.
In Safari:
(1) click the “Preferences” menu, (2) go to “Privacy”, (3) click “Manage website data”.
Regardless of the browser, using tools available for example at: https://www.cookiemetrix.com/ or https://www.cookie-checker.com/

By default, most web browsers available on the market accept the saving of cookies. Everyone can define the conditions for the use of cookies through their own browser settings. This means you can, for example, partly limit (for example temporarily) or completely disable the saving of cookies, though in the latter case this may affect some functionalities of the Website.

Web browser settings for cookies are important from the point of view of consent to the use of cookies by our Website, under the applicable rules such consent may also be expressed through the web browser settings. Detailed information about changing cookie settings and deleting cookies yourself in the most popular web browsers is available in the browser’s help section and on the pages below (just click the relevant link):

in Chrome

in Firefox

in Internet Explorer

in Opera

in Safari

in Microsoft Edge

On the Website the Controller may use Google Analytics 4 and Google Search Console, provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). These services help the Controller keep statistics and analyse traffic on the Website. The data collected is processed within these services to generate statistics that help with administering the Website and analysing traffic on the Website. This data is aggregated in nature. Using these services on the Website, the Controller collects data such as the sources and medium through which visitors reach the Website and how they behave on the Website, information about the devices and browsers they use to visit the site, IP address and domain, geographic data and demographic data (age, gender) and interests.

A person can easily block the sharing of information about their activity on the Website with Google Analytics. To do this you can, for example, install the browser add-on provided by Google Ireland Ltd., available here: https://tools.google.com/dlpage/gaoptout

In connection with the Controller’s possible use of services provided by Google Ireland Ltd. on the Website, the Controller indicates that full information about the rules for processing the data of people visiting the Website (including information saved in cookies) by Google Ireland Ltd. can be found in the Google services privacy policy available at: https://policies.google.com/technologies/partner-sites

External links

The Site may contain links to other websites. The Controller encourages you, after moving to other sites, to read the terms and privacy policy set out there. This privacy policy applies only to this Site.

Contact us

If you have any problems or questions about using the Site, or any other questions, please contact the Owner:

  • email: kontakt@demo.agencjacudo.pl
  • the contact form available on the Site
  • phone: +48 455444000 (call charged as a standard phone call, in line with your provider’s tariff plan)