This clause concerns personal data processed by Aurea Enterprises sp. z o.o. as the data controller, in particular in connection with account registration, contact, conclusion of an agreement, customer service, settlements, security and use of the Bezpieczna Kancelaria website or application.
If your data is contained in documents, case files, recordings, transcripts or other materials entered into Bezpieczna Kancelaria by a law firm or another client, as a rule, that client is the controller of such data, and Aurea Enterprises sp. z o.o. acts as a processor processing the data on its instructions.
1. Data controller
The controller of your personal data is:
Aurea Enterprises sp. z o.o., ul. Plac Bankowy 2, 00-095 Warszawa, NIP: 9591956107, KRS: 0000510950, REGON: 260773108.
Contact regarding personal data protection: privacy@bezpiecznakancelaria.pl.
We have not appointed a data protection officer - contact regarding data protection is available through the address specified above.
2. Purposes and legal bases of processing
We process your personal data for the following purposes:
Account creation and administration
We process data for the purpose of creating an account, authenticating the user, and managing sessions, roles, permissions and access to the Organization.
Legal basis: performance of an agreement or taking steps prior to entering into an agreement, Article 6(1)(b) RODO.
Provision of the Bezpieczna Kancelaria service
We process data for the purpose of providing the service, maintaining the application, operating system features, integrations, notifications, user settings and system communications.
Legal basis: performance of an agreement, Article 6(1)(b) RODO.
Contact and handling enquiries
We process data for the purpose of responding to messages, handling forms, conducting correspondence, preparing an offer and handling requests.
Legal basis: our legitimate interest in handling contact, Article 6(1)(f) RODO, or taking steps prior to entering into an agreement, Article 6(1)(b) RODO.
Support and technical assistance
We process data for the purpose of handling technical requests, diagnosing problems, communicating with the user and improving the operation of the service.
Legal basis: performance of an agreement, Article 6(1)(b) RODO, or our legitimate interest, Article 6(1)(f) RODO.
Settlements and accounting obligations
We process data for the purpose of issuing invoices, maintaining accounts, processing payments and complying with tax obligations.
Legal basis: compliance with a legal obligation to which the controller is subject, Article 6(1)(c) RODO.
Security
We process technical data, logs and event information for the purpose of ensuring application security, detecting abuse, protecting against unauthorised access, conducting audits and handling incidents.
Legal basis: our legitimate interest in ensuring security, Article 6(1)(f) RODO.
Development and improvement of service quality
We process limited technical and diagnostic data for the purpose of improving the operation, stability, performance, usability and security of BK.
Legal basis: our legitimate interest, Article 6(1)(f) RODO.
Direct marketing
We may process contact details for the purpose of providing information about our services, news and offers, insofar as this is permitted by law.
Legal basis: our legitimate interest, Article 6(1)(f) RODO, and in cases requiring consent - consent, Article 6(1)(a) RODO.
Establishment, pursuit and defence of claims
We may process data for the purpose of establishing, pursuing or defending against claims.
Legal basis: our legitimate interest, Article 6(1)(f) RODO.
3. Categories of data processed
We may process the following categories of data:
- first name and surname,
- email address,
- telephone number,
- name of the organisation or law firm,
- position or role,
- login data and account identifiers,
- permission information,
- billing data,
- contact details,
- content of correspondence,
- technical data concerning the device and browser,
- IP address,
- session identifiers,
- security logs,
- data concerning the use of application features,
- data contained in support requests.
4. Data processed on the client's instructions
Documents, case files, recordings, transcripts, notes, calendars, invoices and other content entered into BK by the client may contain personal data of various persons, including special categories of data, data concerning proceedings, data covered by professional secrecy or other confidential information.
In this respect, the data controller is the client using BK, and we process the data as a processor on the basis of a data processing agreement.
If you wish to exercise rights relating to data contained in the files of a case handled by a law firm, please contact that law firm in the first instance.
5. Recipients of data
Data may be disclosed to the following categories of recipients:
- IT infrastructure providers,
- hosting and cloud service providers,
- email and transactional message providers,
- security system and technical monitoring providers,
- support tool providers,
- payment service providers,
- an accounting firm,
- law firms providing services to the controller,
- transcription, speech recognition or AI service providers, if the relevant feature is used,
- third-party integration providers,
- public authorities, courts or other authorised entities, if required by law.
We enter into appropriate data processing agreements with processors processing data on our instructions.
The current list of subprocessors we use:
- Hetzner Online GmbH (Germany, European Economic Area) - server and hosting infrastructure.
- OpenAI (USA) - transcription and AI features; transfer outside the EEA on the basis of standard contractual clauses (SCC).
- ElevenLabs (USA) - transcription and speech recognition; transfer outside the EEA on the basis of standard contractual clauses (SCC).
6. Transfers of data outside the EEA
As a rule, we seek to ensure that data is processed within the European Economic Area.
If data is transferred outside the EEA in connection with the use of specific providers or features, this is carried out using the mechanisms provided for under RODO, in particular a European Commission adequacy decision, standard contractual clauses or other required safeguards.
Information on transfers outside the EEA is provided in the list of subprocessors.
7. Data retention period
We retain data for the period necessary to fulfil the purposes for which it was collected.
In particular:
- we retain account data for the duration of the use of the service and subsequently for the period necessary for settlements, handling claims or complying with legal obligations,
- we retain billing data for the period required by tax and accounting legislation,
- we retain contact details for the duration of handling the matter and subsequently for the period necessary to demonstrate its course or defend against claims,
- we retain technical data and security logs for a period of 12 months,
- we retain marketing data until an objection is raised, consent is withdrawn or the data ceases to be useful,
- we retain data processed on the client's instructions in accordance with the agreement, account configuration and the client's instructions.
8. Your rights
To the extent that we are the controller of Your data, You have the right to:
- access the data,
- receive a copy of the data,
- rectify the data,
- erase the data,
- restrict processing,
- data portability,
- object to processing based on our legitimate interest,
- withdraw consent, where processing is based on consent.
The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
To exercise Your rights, contact us at: privacy@bezpiecznakancelaria.pl.
We respond without undue delay, no later than within one month of receiving the request. In complex cases, the time limit may be extended in accordance with RODO.
9. Right to lodge a complaint
You have the right to lodge a complaint with the supervisory authority competent for personal data protection matters if You consider that the processing of Your data infringes the provisions of RODO.
In Poland, the supervisory authority is the President of the Personal Data Protection Office.
10. Voluntary provision of data
The provision of data is voluntary, but may be necessary to create an account, enter into an agreement, use BK, receive a response to an inquiry, obtain technical support or fulfil accounting obligations.
Failure to provide the required data may prevent the use of the service or the handling of the matter.
11. Automated decision-making
We do not make decisions concerning users based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them.
AI, transcription, summarisation and document analysis features are auxiliary in nature and support the user's work. Final decisions are made by the user or the client using BK.
12. Contact
For matters concerning personal data, contact us:
Aurea Enterprises sp. z o.o., ul. Plac Bankowy 2, 00-095 Warszawa. E-mail: privacy@bezpiecznakancelaria.pl.
Language
This document is available in Polish and English. The Polish version is the source text; in case of any discrepancy between the versions, the Polish version prevails. The English version is a translation provided for convenience only.