Transparency policy
PERSONAL DATA PROCESSING POLICY
(TRANSPARENCY POLICY)
FOR COMPANIES
(1) EPP PROPERTY MANAGEMENT Sp. z o. o
(2) EPP COMMUNITY PROPERTIES – PM SERVICES Sp. z o. o
1. DEFINITIONS
1.1. Administrator – means Administrator 1 and Administrator 2 jointly or, depending on the context, either of them.
1.2. Administrator 1 – a company under the name EPP PROPERTY MANAGEMENT Spółka z ograniczoną odpowiedzialnością with its registered office in Kielce, address: ul. Świętokrzyska 20, 25-406 Kielce.
1.3. Administrator 2 – a company under the name EPP COMMUNITY PROPERTIES – PM SERVICES sp. z o. o. with its registered office in Kielce, address: ul. Świętokrzyska 20, 25-406 Kielce.
1.4. Personal data – information about a natural person identified or identifiable by one or more specific factors determining their physical, physiological, genetic, mental, economic, cultural or social identity, including image, voice recording, contact details, location data, information contained in correspondence, information collected via recording equipment or other similar technology.
1.5. Facility – a shopping mall, managed by the Administrator.
1.6. Data Subject – a natural person to whom the Personal Data processed by the Controller relates.
1.7. Policy – this Personal Data Processing Policy.
1.8. Employee – a natural person employed by the Controller under an employment contract.
1.9. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
1.10. Company – Administrator
1.11. Collaborator – a natural person providing services to the Administrator on the basis of a civil law contract (e.g. contract of mandate, contract for specific work).
2. DATA PROCESSING BY THE CONTROLLER
2.1. In connection with their business activities, Administrator 1 and Administrator 2 process Personal Data in accordance with applicable legal provisions, including in particular the GDPR, and the data processing principles provided for therein.
2.2. Administrator 1 and Administrator 2 are joint controllers of Personal Data based on an appropriate agreement.
2.3. The Controller ensures transparency in the processing of Personal Data, in particular by always providing information about data processing at the time of collection, including the purpose and legal basis of processing (e.g., when concluding a lease agreement). The Controller ensures that data is collected only to the extent necessary to achieve the indicated purpose and processed only for the period necessary.
2.4. When processing Personal Data, the Controller ensures their security and confidentiality, as well as access to information about the processing for data subjects. If, despite the security measures in place, a breach of Personal Data protection occurs (e.g., data leak or loss), the Controller will inform Data Subjects of such an event in a manner consistent with the regulations.
2.5. Personal Data may be processed in an automated manner, i.e., automated decision-making by the Controller based on personal data processed in connection with the use of the participant's account in the application, and/or participation in the points program, incentive program, and/or, as appropriate, in individual campaigns and in connection with the use of the application – taking into account the participant's interests and preferences – in order to prepare individual offers for participants, including offers from the Controller and/or campaign partners – at the time of registration in the application or during participation in a particular campaign – as made available in the application – the legal basis is Article 22 paragraph 2 letter a of the GDPR). Thanks to automated data processing, the Controller may evaluate selected factors relating to natural persons in order to analyze their behavior or create future forecasts for marketing purposes, including for the purpose of targeting participants with contextual advertising, i.e. advertising tailored to the participant's individual preferences.
If the Participant provides a sufficient scope of data, the Administrator will perform profiling as part of the necessity to perform the contract in order to prepare and deliver tailored Promotions.
3. CONTACT WITH THE ADMINISTRATOR
3.1. Contact with the Administrator is possible via the following correspondence address: ul. Świętokrzyska 20, 25-406 Kielce.
3.2. The Controller has appointed a Personal Data Protection Coordinator, who can be contacted via the following e-mail address: [email protected] in any matter concerning the processing of Personal Data by the Administrator.
4. PERSONAL DATA SECURITY
4.1. To ensure data integrity and confidentiality, the Controller has implemented procedures that allow access to Personal Data only to authorized individuals and only to the extent necessary for the tasks they perform. The Controller employs organizational and technical solutions to ensure that all operations on personal data are recorded and performed only by authorized individuals.
4.2. The Controller shall also take all necessary measures to ensure that its subcontractors and other cooperating entities guarantee the application of appropriate security measures whenever they process Personal Data on behalf of the Controller.
4.3. The Controller conducts ongoing risk analysis related to Personal Data processing, assesses the impact on data protection, and monitors the adequacy of data security measures to address identified threats. If necessary, the Controller implements additional measures to enhance data security.
5. PURPOSES AND LEGAL BASIS FOR PROCESSING VIDEO MONITORING
5.1. To ensure the safety of persons and property, the Controller uses video surveillance in facilities related to its business and controls access to the premises and areas it manages. Data collected in this manner is not used for any purposes other than those described below.
5.2. Personal data in the form of surveillance recordings are processed to ensure the safety of persons and property and to maintain order within the Facility, and possibly to defend against claims brought against the Controller or to establish and pursue claims by the Controller. The legal basis for the processing of Personal Data is the Controller's legitimate interest (Article 6, Section 1, Letter f of the GDPR), consisting in ensuring the safety of persons and property located within the premises managed by the Controller and protecting their rights.
5.3. The area covered by the Company's monitoring is marked with appropriate graphic signs.
E-MAIL AND TRADITIONAL CORRESPONDENCE
5.4. In the event of sending to the Controller via e-mail or traditional correspondence unrelated to the services provided to the sender, another agreement concluded with him or her, or otherwise unrelated to any relationship with the Controller, the Personal Data contained in such correspondence are processed solely for the purpose of communication and resolving the matter to which the correspondence relates.
5.5. The legal basis for processing is the legitimate interest of the Controller (Article 6, paragraph 1, letter f of the GDPR), consisting in conducting correspondence addressed to it in connection with its business activities.
5.6. The Company only processes Personal Data relevant to the matter to which the correspondence relates. All correspondence is stored in a manner that ensures the security of the Personal Data (and other information) contained therein and is disclosed only to authorized persons.
TELEPHONE CONTACT
5.7. When contacting the Controller by telephone, regarding matters unrelated to the concluded contract or services provided, the Controller may request the provision of Personal Data only if it is necessary to handle the matter to which the contact relates. The legal basis in such a case is the Controller's legitimate interest (Article 6, paragraph 1, letter f of the GDPR), consisting in the need to resolve the reported matter related to its business activities.
COLLECTION OF DATA IN CONNECTION WITH THE PROVISION OF SERVICES OR THE PERFORMANCE OF OTHER AGREEMENTS
5.8. In the event of data collection for purposes related to the performance of a specific contract (e.g. a lease agreement, a commercial agreement with a business partner or an agreement regarding debt collection activities related to the business activity), the Controller provides the Data Subject with detailed information regarding the processing of their personal data at the time of concluding the contract or at the time of obtaining personal data if the processing is necessary for the Controller to take action at the request of the Data Subject, before concluding the contract.
POINTS PROGRAMS, INCENTIVE PROGRAMS, APPLICATIONS
5.9. The Administrator collects Personal Data from participants to the extent necessary to fulfill its obligations towards participants in the scope of managing the participant's account in applications and platforms used to manage point and incentive programs and individual campaigns, as well as to fulfill the obligations arising from participation in the point program, incentive program or individual campaigns, respectively, and to provide participants with services offered via the application.
5.10. The Administrator processes Personal Data to the extent necessary to analyze the behavior of participants, evaluate the effects and effectiveness of actions undertaken using the application, and to direct marketing offers related to the gallery to participants using tools other than the application after the participant has given appropriate consent.
5.11. Participants’ personal data will be processed for the purposes of managing the participant’s account in the application – in order to provide services available within the application’s functionalities – the legal basis is the necessity of processing for the performance of the contract (Article 6, paragraph 1, letter b of the GDPR), in particular:
5.11.1. Maintaining and servicing the participant's account in the application;
5.11.2. joining the points program;
5.11.3. Access to Information about offers available in the Gallery.
5.12. Participants’ personal data will be processed for the purposes of organizing and conducting the points program – in order to provide services available within the application’s functionalities – the legal basis is the necessity of processing for the performance of the contract (Article 6, paragraph 1, letter b of the GDPR), in particular:
5.12.1. registering in the points program and creating a points account;
5.12.2. maintaining and servicing a points account, i.e. registering proof of purchase, accruing points, including non-purchase points, maintaining the points balance;
5.12.3. ordering and issuing prizes;
5.12.4. access to information about offers within the points program and/or offered in the application.
5.13. Participants' personal data will be processed for the purposes of organizing and conducting the motivational program – in order to provide services available within the application functionality – the legal basis is the necessity of processing for the performance of the contract (Article 6, paragraph 1, letter b of the GDPR), in particular:
5.13.1. maintaining and managing the reward account, i.e. registering referral links and referral codes, verifying eligibility for the reward, calculating the bonus points, maintaining the bonus points balance; and ordering and issuing rewards provided for in the incentive program (see definitions in the incentive program regulations).
5.14. The legal basis for processing participants' Personal Data for the purposes of organizing the points program, the incentive program and, accordingly, conducting individual campaigns is:
5.14.1. in the case of a points programme and/or an incentive programme, respectively – the legal basis is the necessity of processing for the conclusion and performance of a contract (Article 6, paragraph 1, letter b of the GDPR) regarding participation in the points programme and/or the incentive programme;
5.14.2. in the case of campaigns – advertising and promotion of the gallery – the legal basis is the legitimate interest of the controller consisting in carrying out the individual campaigns by the controller (Article 6 paragraph 1 letter f of the GDPR) – unless another basis is indicated in the regulations of the individual campaign;
5.14.3. in the case of considering any complaints related to participation in a points program, an incentive program and, as appropriate, in a particular campaign – the legal basis is the legitimate interest of the Controller in fulfilling its obligations towards participants arising from these projects (Article 6, paragraph 1, letter f of the GDPR);
5.14.4. in the case of fulfilling legal obligations incumbent on the Controller resulting from legal provisions, including tax and accounting regulations – the legal basis is the legal obligation (Article 6, paragraph 1, letter c of the GDPR).
5.15. The legal basis for processing participants' Personal Data for the purposes of providing services available within the application functionality is:
5.15.1. In the case of registration in the application and creation of a participant account in the application, a points account and, respectively, a bonus account; maintaining and operating a participant account in the application, a points account and, respectively, a bonus account, access to information about offers in the gallery carried out using the application – the necessity of processing for the performance of the contract (Article 6, paragraph 1, letter b of the GDPR).
5.16. In addition, Personal Data of participants in applications and platforms used to manage point and incentive programs and in individual campaigns are processed on the following basis:
5.16.1. In the case of considering any complaints related to the use of the application and participation in the points program, incentive program or, as appropriate, in a particular campaign – the legal basis is the necessity of processing for the performance of the contract (Article 6 paragraph 1 letter b of the GDPR);
5.16.2. In the case of fulfilling legal obligations incumbent on the Controller resulting from legal provisions, including tax and accounting regulations – the legal basis is the legal obligation (Article 6, paragraph 1, letter c of the GDPR);
5.16.3. For analytical and statistical purposes regarding participants' activity, as well as their preferences in connection with the use of the participant's account in the application and the points program, the incentive program and, respectively, within individual campaigns and/or applications – the legal basis is the legitimate interest of the controller and the group administrator (Article 6 paragraph 1 letter f of the GDPR) – i.e. improving the functionalities used and the services provided;
5.16.4. In the case of establishing, pursuing or defending against claims – the legal basis is the legitimate interest of the Controller (Article 6 paragraph 1 letter f of the GDPR), i.e. protection of its rights;
5.16.5. In the case of geolocation of a participant within the mall, including monitoring the frequency of visits and movements within the mall, if the participant consents to this at the time of registration in the application or during their participation in the points program – as provided in the application – the legal basis is consent (Article 6 paragraph 1 letter a of the GDPR and Article 22 paragraph 2 letter c of the GDPR);
MARKETING AND COMMERCIAL INFORMATION
5.17. The Administrator processes participants' Personal Data in applications and platforms used to manage point and incentive programs and in individual campaigns, on the following basis:
5.17.1. for the purpose of direct marketing in the scope related to the use of the participant's account in the application and participation in the points program, the incentive program and, respectively, participation in individual campaigns, benefits resulting from such projects, services offered and the application and its functionalities – the legal basis is (Article 22 paragraph 2 letter a of the GDPR);
5.17.2. for marketing purposes of the campaign partner – if the participant consents thereto at the time of registration in the application or during his/her participation in the points program or in a particular campaign – as provided in the application – the legal basis is consent (Article 6, paragraph 1, letter a of the GDPR);
5.17.3. If the participant has ordered the newsletter service, the Controller may send marketing content within the newsletter – constituting direct marketing of the Controller (in which case the legal basis is the legitimate interest of the controller (Article 6 paragraph 1 letter f of the GDPR) – i.e. direct marketing) or concerning the marketing of goods and services of the campaign partner – if the participant consents thereto at the time of registration in the application or during his/her participation in the points program or in a given campaign – as made available in the application – the legal basis is the granting of consent (Article 6 paragraph 1 letter a of the GDPR).
5.18. Participants may consent to receiving commercial information for marketing purposes via email, SMS/MMS, or the use of telecommunications terminal equipment (including automated calling systems). Consent is expressed by submitting an appropriate declaration in the form provided at the time of registration in the application and/or registration for the points program, incentive program, and/or individual campaign, as applicable. Granting consent is not required to use the application or to join and participate in the points program, incentive program, and/or individual campaign, as applicable. However, granting consent is necessary if the participant is interested in receiving marketing content, advertisements, information, and notifications about available promotions, news, or personalized offers (behavioral advertising), including marketing content within the newsletter.
PROCESSING OF PERSONAL DATA OF MEMBERS OF CONTRACTORS' STAFF OR TENANTS COOPERATING WITH THE CONTROLLER
5.19. In connection with concluding commercial and lease agreements as part of its business activities, the Controller obtains data from contractors/tenants regarding persons involved in the execution of such agreements (e.g., authorized contact persons, persons executing orders, suppliers, etc.). The scope of the data transferred is in each case limited to the extent necessary for the execution of the agreement and typically does not include information other than name, surname, and business contact details.
5.20. Such personal data are processed to pursue the legitimate interest of the Controller and its contractor (Article 6, Section 1, Letter f of the GDPR), consisting in enabling the proper and effective performance of the contract. Such data may be disclosed to third parties involved in the performance of the contract, as well as to entities obtaining access to data based on regulations on the transparency of public information and proceedings conducted under public procurement law, to the extent provided for by those regulations.
5.21. Data are processed for the period necessary to pursue the above interests and to comply with the obligations arising from the regulations.
DATA COLLECTION IN OTHER CASES
5.22. In connection with its business activities, the Controller also collects Personal Data in other cases – for example, by building and leveraging lasting mutual business contacts (networking) during business meetings, at industry events, or by exchanging business cards – for purposes related to initiating and maintaining business contacts. The legal basis for processing in this case is the Controller's legitimate interest (Article 6, paragraph 1, letter f of the GDPR), consisting in creating a network of contacts in connection with its business activities.
5.23. Personal data collected in such cases are processed solely for the purpose for which they were collected, and the Controller ensures their appropriate protection.
6. DATA RECIPIENTS
6.1. In connection with conducting business activities requiring processing, Personal Data is disclosed to external entities, including in particular suppliers responsible for operating IT systems and equipment (e.g., CCTV equipment for video surveillance), entities providing legal, accounting, or Facility security services, couriers, and marketing agencies. Data is also disclosed to entities belonging to the EPP capital group for the internal administrative purposes of companies belonging to the EPP capital group (administrative services for the EPP group) based on their legitimate interest. More information about the Controller's capital group can be found on the website https://pl.epp-poland.com/.
6.2. The Administrator reserves the right to disclose selected information concerning the Data Subject to competent authorities or third parties who submit a request for such information, based on an appropriate legal basis and in accordance with applicable law.
7. DATA TRANSFERS OUTSIDE THE EEA
7.1. The level of protection of Personal Data outside the European Economic Area ("EEA") differs from that provided by European law. For this reason, the Controller transfers Personal Data outside the EEA only when necessary and with an adequate level of protection, in particular by:
7.1.1. cooperation with entities processing Personal Data in countries for which an appropriate decision of the European Commission has been issued regarding the adequate level of protection of Personal Data;
7.1.2. use of standard contractual clauses issued by the European Commission;
7.1.3. application of binding corporate rules approved by the relevant supervisory authority.
8. PERIOD OF PERSONAL DATA PROCESSING
8.1. The period of data processing by the Controller depends on the type of service provided and the purpose of processing. The period of data processing may also result from legal provisions, when they constitute the basis for processing. In the case of data processing based on the Controller's legitimate interest (e.g., for security reasons), the data is processed for a period necessary to fulfill that interest or to effectively object to data processing. If processing is based on consent, the data is processed until its withdrawal. When the basis for processing is the necessity to conclude and perform a contract, the data is processed until the contract is terminated.
8.2. The data processing period may be extended if processing is necessary to establish, pursue or defend against claims, and after this period – only if and to the extent required by law.
9. RIGHTS RELATED TO PERSONAL DATA PROCESSING
DATA SUBJECT RIGHTS
9.1. Data subjects have the following rights:
9.1.1. the right to information about the processing of personal data – on this basis, the Controller provides the natural person submitting the request with information about the processing of data, including in particular the purposes and legal basis of processing, the scope of the data held, the entities to which they are disclosed, and the planned date of data deletion;
9.1.2. the right to obtain a copy of the data – on this basis, the Controller provides a copy of the processed data relating to the natural person submitting the request;
9.1.3. right to rectification – the Controller is obliged to remove any inconsistencies or errors in the Personal Data being processed and to supplement them if they are incomplete;
9.1.4. the right to delete data – on this basis, you may request the deletion of data whose processing is no longer necessary to achieve any of the purposes for which they were collected;
9.1.5. the right to restrict processing – in the event of such a request, the Controller shall cease performing operations on Personal Data – with the exception of operations to which the data subject has given consent – and their storage, in accordance with the adopted retention principles or until the reasons for restricting data processing cease to exist (e.g. a decision of the supervisory authority is issued permitting further data processing);
9.1.6. the right to data portability – on this basis, to the extent that data is processed by automated means in connection with a concluded contract or expressed consent, the Controller releases the data provided by the data subject in a machine-readable format. It is also possible to request that this data be transferred to another entity, provided, however, that there are technical possibilities in this regard on the part of both the Controller and the indicated entity;
9.1.7. the right to object to the processing of data for marketing purposes – the Data Subject may object to the processing of Personal Data for marketing purposes at any time, without having to justify such objection;
9.1.8. the right to object to other purposes of data processing – the Data Subject may at any time object – for reasons relating to their particular situation – to the processing of Personal Data which is carried out on the basis of the Controller’s legitimate interest (e.g. for analytical or statistical purposes or for reasons related to property protection); the objection in this respect should contain a justification;
9.1.9. right to withdraw consent – if data are processed on the basis of expressed consent, the Data Subject has the right to withdraw it at any time, which, however, does not affect the lawfulness of processing carried out before its withdrawal;
9.1.10. the right to human intervention in the event of profiling – the Data Subject has the right to obtain human intervention on the part of the Controller, to express his or her own position and to challenge an automated decision;
9.1.11. Right to complain – if the processing of Personal Data violates the provisions of the GDPR or other provisions regarding the protection of Personal Data, the Data Subject may file a complaint with the authority supervising the processing of Personal Data, with jurisdiction over the Data Subject's place of habitual residence, place of work, or place of the alleged infringement. In Poland, the supervisory authority is the President of the Personal Data Protection Office.
MAKING REQUESTS RELATED TO THE EXERCISE OF RIGHTS
9.2. A request to exercise the rights of Data Subjects may be submitted:
9.2.1. in writing to the following address: ul. Świętokrzyska 20, 25-406 Kielce;
9.2.2. electronically to the following e-mail address: [email protected],
9.2.3. in justified cases – related to the applicant's stay at the Facility – to an Employee/Co-worker of the Administrator present at the Facility, using a special form (application), which will be available at selected points in the Facility, e.g. from security staff.
9.3. If the Controller is unable to identify a natural person based on the submitted request, it will request additional information from the requestor. Providing such information is not mandatory, but failure to provide it will result in refusal to comply with the request.
9.4. The request may be submitted in person or through a proxy (e.g., a family member). For data security reasons, the Controller encourages the use of a power of attorney certified by a notary or authorized legal counsel or attorney, which will significantly speed up verification of the request's authenticity.
9.5. A response to a request should be provided within one month of its receipt. If an extension of this deadline is necessary, the Administrator will inform the requester of the reasons for doing so.
9.6. If a request is submitted to the Company electronically, the response will be provided in the same form, unless the requester has requested a response in a different form. In other cases, the response will be provided in writing. If the deadline for fulfilling the request prevents a written response, and the scope of the requester's data processed by the Controller allows for electronic contact, the response should be provided electronically.
9.7. The Company stores information regarding the submitted request and the person who submitted the request in order to ensure compliance and to establish, defend, or pursue any claims by data subjects. The request log is stored in a manner that ensures the integrity and confidentiality of the data contained therein.
FEES COLLECTION RULES
9.8. The application process is free of charge. Fees may only be charged in the following cases:
9.8.1. submitting a request for the second and each subsequent copy of the data (the first copy of the data is free of charge); in such a case, the Controller may request payment of a fee of PLN 30. The above fee includes administrative costs related to fulfilling the request;
9.8.2. the same person submitting excessive (e.g., unusually frequent) or clearly unjustified requests; in such a case, the Administrator may request payment of a fee of PLN 30. The above fee includes the costs of communication and the costs associated with taking the requested actions;
9.8.3. If a decision to impose a fee is contested, the data subject may file a complaint with the supervisory authority responsible for the processing of personal data, with jurisdiction over the data subject's place of habitual residence, place of work, or place of the alleged infringement. In Poland, the supervisory authority is the President of the Personal Data Protection Office.
10. CHANGES TO THE PERSONAL DATA PROCESSING POLICY
10.1. The policy is reviewed on an ongoing basis and updated as necessary.