GDPR Information Notice
This notice provides a concise, comprehensible and transparent summary of the information contained in the Privacy Policy concerning the Data Controller, the purposes and methods of processing Personal Data, and your rights in connection with such processing, in the form required to fulfil the information obligation under the GDPR. Detailed information regarding the methods of processing and the entities involved in this process is available in the Privacy Policy referred to above.
Who is the Data Controller?
The Data Controller, hereinafter referred to as the Controller, is Reesco Sp. z o.o., with its registered office in Warsaw, operating at al. Jerozolimskie 136, 02-305 Warsaw, Poland, Tax Identification Number (NIP): 701-023-39-27, National Court Register Number (KRS): 0000355407.
How can the Data Controller be contacted?
- Postal address: Reesco Sp. z o.o., al. Jerozolimskie 136, 02-305 Warsaw, Poland
- Email: reesco@reesco.pl
- Telephone: the telephone numbers published on the Website
The Website does not provide a contact form. Contact is possible exclusively by email or telephone.
Has the Controller appointed a Data Protection Officer?
Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer. For matters concerning Personal Data, please contact the Controller directly.
Where do we obtain Personal Data and what are its sources?
Personal Data is obtained:
- directly from the data subjects, particularly through email correspondence or telephone conversations initiated using the contact details published on the Website
- automatically, in relation to technical data and Cookies collected while the Website is being used
The Website does not allow users to register accounts, sign in through social media services or subscribe to a newsletter through the Website.
What is the scope of the Personal Data we process?
We process ordinary Personal Data voluntarily provided by the data subjects, such as their full name, email address, telephone number, enquiry details and company information, as well as technical data such as IP addresses and Cookie identifiers.
Detailed information regarding the scope of the data processed is available in the Privacy Policy.
For what purposes do we process Personal Data?
- responding to enquiries and communicating with Users, including taking steps prior to entering into a contract
- processing recruitment applications sent to the designated HR email address, where applicable
- ensuring the operation and security of the Website and collecting Website statistics
- ensuring the security of the Website, preventing misuse and protecting the Controller’s rights and interests
What are the legal bases for processing Personal Data?
- Article 6(1)(a) of the GDPR – Consent, particularly in relation to the use of Cookies or other technologies requiring the User’s Consent
- Article 6(1)(b) of the GDPR – taking steps at the request of the data subject prior to entering into a contract
- Article 6(1)(c) of the GDPR – compliance with a legal obligation to which the Controller is subject, to the extent applicable
- Article 6(1)(f) of the GDPR – the Controller’s legitimate interests
What legitimate interests are pursued by the Controller?
- operating the company Website and presenting the company’s services
- ensuring the security of the Website and protecting it against misuse
- handling correspondence and maintaining business relationships
- establishing, pursuing or defending against potential legal claims
How long do we process Personal Data?
Data contained in correspondence is retained for the period necessary to handle the relevant matter and subsequently for a period resulting from the Controller’s legitimate interests, particularly for the purposes of documenting communications and protecting the Controller against potential claims, unless a longer retention period is required by law.
Technical data and Cookies are retained in accordance with the periods applied by the Controller and the providers of the relevant tools. Detailed information is available in the Privacy Policy.
Who receives the data, including Personal Data?
As a general rule, the Controller is the recipient of the data.
Processing may be entrusted to entities providing services to the Controller, particularly:
- the hosting provider – cyber_Folks S.A.
- authorised employees and associates
- providers of tools such as Google Tag Manager, Google Analytics, Google Fonts and TagEmbed, to the extent that technical data and Cookies are involved
Will your Personal Data be transferred outside the European Union?
Data obtained through email correspondence or telephone conversations is generally not transferred outside the European Economic Area by the Controller.
The use of Google and TagEmbed tools may involve transferring technical data, including IP addresses, outside the European Economic Area in accordance with the rules applied by those providers. Detailed information is available in the Privacy Policy.
Will Personal Data be used for automated decision-making?
Personal Data is not used for automated decision-making that produces legal effects concerning the User.
What rights do you have in connection with the processing of Personal Data?
These rights may be exercised upon request submitted to the Controller, for example by email to reesco@reesco.pl:
- the right of access to Personal Data
- the right to rectification of Personal Data
- the right to erasure of Personal Data
- the right to restriction of Processing
- the right to data portability in the circumstances specified in the GDPR
- the right to object to Processing
- the right to lodge a complaint with the President of the Personal Data Protection Office in Poland
Publication date of this version: 5 August 2026.