Privacy Policy – Brand Boost 2027

Web page www.wedesign.pl/brandboost · We Design Studio Graficzne Aleksander Rokicki

§1. General information

1. This Privacy Policy (the "Policy") sets out the rules for processing personal data in connection with the use of the web page www.wedesign.pl/brandboost (the "Page") and with applications to the "Brand Boost 2027" project (the "Project"), the rules of which are set out in the separate Project Rules available on the Page.

2. This Policy fulfils the information obligation referred to in Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).

3. In matters not covered by this Policy, the general Privacy Policy of the website www.wedesign.pl applies. In the event of any discrepancy regarding the Page and the Project, this Policy prevails.

4. The rules for using cookies and similar technologies (including the Meta and LinkedIn pixels) are described in the separate Cookies Policy available on the Page.

§2. Data controller and contact

1. The controller of your personal data is We Design Studio Graficzne Aleksander Rokicki, with its registered office in Warsaw (01-560), ul. Toeplitza 2/48, Poland, tax ID (NIP) 951-184-66-07 (the "Controller", "we", "us").

2. For any matters relating to personal data, you can contact us by e-mail at studio@wedesign.pl or by post at the registered office address above.

3. The Controller has not appointed a data protection officer, as it is not required to do so under Article 37 GDPR.

§3. Who this Policy applies to

This Policy applies in particular to:

§4. Where we obtain data from and what data we process

4.1. Data provided in the application form

We process the data that the applicant provides in the application form, in particular:

4.2. Data collected automatically

When you use the Page, the following may be collected automatically: IP address, device and browser identifiers, operating system information, the source of your visit to the Page (e.g. clicking on an ad on LinkedIn or Instagram), pages visited, time of visit and events on the Page (e.g. submitting the form). These data are collected by means of cookies and similar technologies only to the extent that the User has consented in the cookie banner – see the Cookies Policy for details.

4.3. Data obtained from other sources

When considering an application, we may review publicly available information about the applicant (website, social media profiles, public business registers such as the Polish CEIDG/KRS or their foreign equivalents) in order to assess the collaboration potential in accordance with the Project Rules.

4.4. Third-party data provided in the form

If personal data of other persons (e.g. team members, partners) are provided in the form, the applicant is responsible for having a basis to share them and for informing those persons of the content of this Policy. We recommend providing data of other persons only to the extent necessary (e.g. role in the team, without first and last names where not required).

§5. Purposes, legal bases and retention periods

Purpose of processing Legal basis Retention period
Receiving and considering the application to the Project, contact regarding the application, selection of the Participant Article 6(1)(b) GDPR – steps taken at the request of the data subject prior to entering into a contract (for businesses that are sole proprietors); Article 6(1)(f) GDPR – the Controller’s legitimate interest in conducting the Project and communicating with the persons representing applying entities Until the end of the application period and the announcement of the selected Participant, and thereafter for up to 6 months from the announcement of the result – for applications that were not selected
Carrying out the Project with the selected Participant (schedule, consultations, delivery of designs, conclusion of the rights transfer agreement) Article 6(1)(b) GDPR – performance of a contract; Article 6(1)(f) GDPR – contact with the persons representing the Participant For the duration of the Project and thereafter until the expiry of the limitation period for claims (as a rule, 6 years from the end of the year in which the Project was completed)
Fulfilling legal obligations (e.g. accounting and tax obligations – if any arise, e.g. in connection with the cost of external materials) Article 6(1)(c) GDPR For the period required by law (as a rule, 5 years from the end of the financial year)
Establishing, pursuing or defending against claims Article 6(1)(f) GDPR – the Controller’s legitimate interest Until the expiry of the limitation period for claims
Presenting the results of the Project in the Controller’s portfolio, on its website and on social media (case study) – applies to the selected Participant only Article 6(1)(f) GDPR – legitimate interest in promoting the Controller’s own business; with respect to the image of individuals or data going beyond company data – Article 6(1)(a) GDPR (consent) For as long as the portfolio is maintained, and no longer than until an effective objection is raised or consent is withdrawn
Informing about future editions of the Project and other initiatives of the Controller (marketing communication by electronic means) Article 6(1)(a) GDPR – consent given voluntarily via a separate field in the form; in conjunction with Article 398 of the Polish Electronic Communications Law of 12 July 2024 Until consent is withdrawn, and no longer than 3 years from the date it was given
Measuring the effectiveness of advertising campaigns on LinkedIn and Instagram/Facebook (Meta Pixel, LinkedIn Insight Tag), including recording form submissions as conversions, and ad targeting Article 6(1)(a) GDPR – consent given in the cookie banner (Article 399 of the Electronic Communications Law) In accordance with the retention periods of the individual cookies set out in the Cookies Policy; until consent is withdrawn
Ensuring the operation and security of the Page, including temporarily storing a draft copy of the answers in the browser Article 6(1)(f) GDPR – legitimate interest in ensuring that the Page functions properly Draft copy of the form – until the application is submitted or the browser tab is closed; server logs – 90 days
Analysing how the Page is used and improving it (Google Analytics) Article 6(1)(a) GDPR – consent given in the cookie banner (Article 399 of the Electronic Communications Law) In accordance with the cookie retention periods set out in the Cookies Policy; statistical data in Google Analytics – 14 months

§6. Recipients of data

Personal data may be shared with the following categories of recipients, solely to the extent necessary to achieve the purposes set out in §5:

Data are not sold or shared with third parties for their own marketing purposes. Data may be disclosed to competent public authorities at their request based on the law.

§7. Transfers of data outside the European Economic Area

1. As a rule, data are stored on servers located in the European Economic Area (EEA).

2. In connection with the use of Meta, LinkedIn and Google Analytics tools (only with the User’s consent) and of e-mail and office tools provided by entities belonging to corporate groups headquartered in the USA, data may be transferred to the United States.

3. Such transfers take place on the basis of the European Commission’s decision of 10 July 2023 finding an adequate level of protection under the EU-U.S. Data Privacy Framework (DPF) – with respect to entities certified under that programme – or on the basis of standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR), supplemented where necessary by additional safeguards.

4. Information about the safeguards applied and a copy of the standard contractual clauses can be obtained by contacting the Controller.

§8. Meta and LinkedIn tools – joint controllership

1. With respect to the collection of data via the Meta Pixel and its transmission to Meta Platforms Ireland Limited, the Controller and Meta are joint controllers (Article 26 GDPR). The terms of joint controllership are set out in Meta’s "Controller Addendum" (available at www.facebook.com/legal/controller_addendum). Meta is independently responsible for any further processing of the data after receiving it, in accordance with its privacy policy: www.facebook.com/privacy/policy.

2. With respect to the collection of data via the LinkedIn Insight Tag and its transmission to LinkedIn Ireland Unlimited Company, the Controller and LinkedIn are joint controllers. The terms of joint controllership are set out in the "LinkedIn Page Insights Joint Controller Addendum" / the LinkedIn Insight Tag terms (legal.linkedin.com). LinkedIn is independently responsible for any further processing of the data, in accordance with its privacy policy: www.linkedin.com/legal/privacy-policy.

3. The User may exercise their rights both against the Controller and against Meta or LinkedIn. The Controller is the point of contact for data subjects with respect to the joint controllership (contact details in §2).

4. These tools are activated only after consent has been given in the cookie banner. A detailed description of how they work and how to withdraw consent can be found in the Cookies Policy.

§9. Rights of data subjects

Every person whose data we process has – on the terms set out in the GDPR – the right to:

To exercise any of the above rights, simply write to studio@wedesign.pl. We respond without undue delay and no later than one month after receiving the request. Consent to cookies can be withdrawn at any time by selecting the relevant options in the cookie plug-in pop-up (cookie settings).

§10. Whether providing data is mandatory

1. Providing the data marked with an asterisk (*) in the form is voluntary but necessary to receive and consider the application – without them, the application will not be taken into account. Providing any other data is entirely voluntary.

2. Giving consent to marketing communication (information about future editions) and consent to marketing cookies is voluntary and does not affect the ability to submit an application or how it is considered.

§11. Automated decision-making and profiling

1. The Project Participant is selected by the Controller’s team. The Controller does not make decisions concerning data subjects based solely on automated processing, including profiling, that would produce legal effects concerning them or similarly significantly affect them (Article 22 GDPR).

2. Meta and LinkedIn may use the data collected via the Pixel and the Insight Tag to profile Users for the purpose of displaying ads on their platforms – only after consent to marketing cookies has been given. Ad settings can be managed in the User’s account on those platforms.

§12. Data security

The Controller applies technical and organisational measures appropriate to the risk, in particular: an encrypted connection to the Page (HTTPS), restricting access to applications to the persons involved in the Project, securing access accounts, and data processing agreements with service providers. The draft copy of the answers in the form is stored solely in the User’s browser (session storage) and is not sent to the server before the application is submitted.

§13. Changes to this Policy

This Policy may be updated, in particular in the event of changes to the tools or providers we use or to the applicable laws. The current version is always available on the Page. We will notify persons who have submitted an application of any material changes by e-mail.

Last updated: 16 September 2026