Privacy Policy
This Privacy Policy sets out the rules governing the processing of personal data of Website Users and the use of cookies and other similar technologies.
The Website does not provide electronic forms, does not allow users to register accounts and does not offer newsletter subscriptions. The Controller may be contacted exclusively through the email addresses and telephone numbers published on the Website.
This Privacy Policy forms an integral part of the Website Terms of Service, which set out the rules, rights and obligations applicable to Users of the Website. A summary GDPR notice is also available on the following page: GDPR Information Notice.
I. Definitions
- Website Administrator / Data Controller – the Website Administrator and Data Controller, hereinafter referred to as the Controller, is Reesco Sp. z o.o., operating at al. Jerozolimskie 136, 02-305 Warsaw, Poland, Tax Identification Number (NIP): 701-023-39-27, National Court Register Number (KRS): 0000355407, providing electronic services through the Website
- Cookies – text data collected in the form of files stored on the User’s Device
- Personal Data – any information relating to an identified or identifiable natural person
- Processing – any operation or set of operations performed on Personal Data, including collecting, storing, using and deleting data
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Website – the website operated by the Service Provider, available at http://reesco.pl
- External Website – a website operated by a partner, service provider or customer cooperating with the Controller
- Device – an electronic device together with its software through which the User accesses the Website
- Service Provider – Reesco Sp. z o.o., with its registered office in Warsaw, al. Jerozolimskie 136, 02-305 Warsaw, Poland, Tax Identification Number (NIP): 701-023-39-27, National Court Register Number (KRS): 0000355407
- User – a natural person who accesses the Website or contacts the Controller
- Consent – any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which the data subject agrees to the Processing of Personal Data relating to them
II. Data Protection Officer
Pursuant to Article 37 of the GDPR, the Controller has not appointed a Data Protection Officer.
For matters relating to the Processing of Personal Data, please contact the Controller directly using the details provided in Section XIV.
III. Types of Cookies
- First-party Cookies – files placed on and read from the User’s Device by the Website’s IT system, for example language preferences or a session providing access to password-protected content
- Third-party Cookies – files placed on and read from the User’s Device by systems operated by External Websites, such as Google or TagEmbed, whose scripts have been included on the Website
- Session Cookies – files stored during a single session on the Device and deleted after that session ends
- Persistent Cookies – files stored until they are deleted by the User or expire in accordance with the settings applied by their provider
- Necessary or technical Cookies – files required for the Website to operate correctly; they do not require Consent, but are described in this Privacy Policy
- Analytics, marketing and external-media Cookies – files activated after the User has given Consent
IV. Data Storage Security
- Cookie mechanisms – Cookies are saved and read using browser mechanisms. These mechanisms do not allow other data to be downloaded from the User’s Device or from other websites
- First-party Cookies – the Cookies used by the Controller are safe for Users’ Devices and do not contain malicious software
- Third-party Cookies – the Controller selects recognised partners, but does not have full control over the contents of Cookies originating from External Websites. A list of partners is provided in Section VII
- Cookie management – the User may independently change the Cookie settings in their browser. Information about disabling Cookies is available here: how to disable cookies. Restricting Cookies may affect the operation of certain Website functions
- Personal Data storage – the Controller applies technical and organisational measures designed to protect data against unauthorised access, loss or destruction. Access is limited to authorised persons
V. Purposes for Which Cookies Are Used
- ensuring the correct operation of the Website, including technical functions, language selection and security
- remembering the User’s preferences, such as their selected language
- enabling access to password-protected content where the User has been granted such access
- collecting website traffic statistics, for example through Google Tag Manager or Google Analytics, after Consent has been given, where applicable
- displaying embedded social media content through TagEmbed, after Consent has been given, where applicable
VI. Purposes of Personal Data Processing
Personal Data voluntarily provided by Users, particularly in an email message or telephone conversation, is processed for the following purposes:
- responding to enquiries and communicating with the User, including taking steps prior to entering into a contract
- processing recruitment applications where the User contacts the Controller regarding employment using the designated HR email address
- pursuing the Controller’s legitimate interests, including operating the Website, ensuring security and establishing, pursuing or defending legal claims
- complying with the Controller’s legal obligations, where applicable
Data collected automatically while the Website is being used, including technical data and Cookies, is processed for the following purposes:
- ensuring the operation, security and improvement of the Website
- collecting statistics after Consent has been given, where applicable
- pursuing the Controller’s legitimate interests
VII. Cookies Used by External Websites
The Controller uses scripts and components supplied by partners who may place their own Cookies on the User’s Device. The User may restrict Cookies through their browser settings and through the Consent-management mechanism available on the Website.
The Website may use services including:
- Google Tag Manager – management of analytics and marketing scripts (Google Privacy Policy)
- Google Analytics – website traffic statistics, where this service is activated through the Tag Manager container (Google Privacy Policy)
- Google Fonts – delivery of fonts; this may involve transmitting the User’s IP address to Google
- TagEmbed – an embedded social media feed, for example content from Instagram, LinkedIn or TikTok (TagEmbed Privacy Policy)
Services provided by third parties remain outside the Controller’s full control. Partners may change their terms of service, the purposes for which they process data and the manner in which they use Cookies.
VIII. Types of Data Collected
The Website does not collect data through forms available on the Website. Data may originate from:
- email or telephone contact – data provided by the User in a message or during a telephone conversation, such as their full name, email address, telephone number, enquiry details, company information or recruitment application data
- automatic collection of technical data while the Website is being used
Data collected automatically, within the typical scope of analytics tools and server logs:
- IP address
- browser type and language
- Device type and operating system
- screen resolution
- approximate location determined on the basis of the IP address
- pages visited and time spent on the Website
- referring website address
- Cookie identifiers, where Cookies have been stored
The Website does not collect data in connection with user-account registration or newsletter subscriptions through the Website, as these functions are not available.
IX. Access to Personal Data by Third Parties
As a general rule, the Controller is the recipient of the Personal Data. The data is not sold.
Entities providing infrastructure and services for the Website may have access to the data, most commonly on the basis of a data-processing agreement. These entities may include:
- the hosting provider
- authorised employees and associates of the Controller
- entities providing IT support or Website maintenance services, where the Controller uses such services
- providers of analytics tools and embedded content, including Google and TagEmbed, to the extent that technical data or Cookies are involved
Hosting
The Controller uses hosting services provided by cyber_Folks S.A.. Data connected with the operation of the Website is stored within the service provider’s infrastructure, generally in Poland or elsewhere in the European Economic Area. The provider’s personnel may access the data to the extent necessary to provide hosting services under an agreement with the Controller.
X. Method of Personal Data Processing
Personal Data provided voluntarily through email or telephone contact:
- is not sold to third parties
- is not used for automated decision-making that produces legal effects concerning the User
- is generally not transferred outside the European Economic Area; an exception may arise where the User independently uses third-party services connected with the Website or where the Controller uses global tools, as described below
Technical data, Cookies and external tools:
- the use of Google services, including Tag Manager, Analytics and Fonts, and TagEmbed may involve transferring data, including IP addresses, outside the European Economic Area, particularly to the United States, in accordance with the rules applied by these providers
- the Controller does not sell this data
XI. Legal Bases for Processing Personal Data
The Controller processes Personal Data on the following legal bases:
- Article 6(1)(a) of the GDPR – Consent, for example Consent to non-essential Cookies or external tools
- Article 6(1)(b) of the GDPR – taking steps at the request of the data subject prior to entering into a contract, including responding to a request for an offer
- Article 6(1)(c) of the GDPR – compliance with a legal obligation to which the Controller is subject, to the extent that Processing is necessary to fulfil that obligation
- Article 6(1)(f) of the GDPR – the Controller’s legitimate interests, including operating and securing the Website, communicating with Users and establishing, pursuing or defending legal claims
XII. Personal Data Retention Period
Email and telephone correspondence: the data is retained for the period necessary to handle the relevant matter and subsequently for a period resulting from the Controller’s legitimate interests, particularly those connected with documenting communications and protecting the Controller against potential claims.
Recruitment data, where the User submits it by email, is retained for the duration of the recruitment process. Where separate Consent has been given or retention is based on a legitimate interest, the data may also be retained for the period specified in the relevant recruitment notice, but no longer than necessary.
Technical data, logs and Cookies: such data is retained in accordance with the periods applied by the Controller and the providers of the relevant tools. Statistical data may be retained for the period resulting from the configuration of the tools used. Anonymised data that does not make it possible to identify an individual may be retained indefinitely.
XIII. Users’ Rights
Users have the following rights, which may be exercised upon request submitted to the Controller, for example by email to reesco@reesco.pl:
- the right of access to Personal Data
- the right to rectification of Personal Data
- the right to erasure of Personal Data, also known as the right to be forgotten, subject to the exceptions provided for in the GDPR
- the right to restriction of Processing
- the right to data portability in the circumstances specified in the GDPR
- the right to object to Processing based on Article 6(1)(f) of the GDPR
- the right to lodge a complaint with the President of the Personal Data Protection Office in Poland
The Controller may refuse or delay erasure where retaining the data is necessary to protect a legitimate interest, such as establishing, pursuing or defending legal claims, or to comply with a legal obligation.
XIV. Controller Contact Details
The Controller may be contacted using the following details:
- Postal address: Reesco Sp. z o.o., al. Jerozolimskie 136, 02-305 Warsaw, Poland
- Email: reesco@reesco.pl
- Telephone: the telephone numbers published on the Website, including in the footer and on contact pages
The Website does not provide a contact form.
XV. Website Requirements
- Restricting the storage of or access to Cookies may cause certain Website functions to operate incorrectly, including language selection, access to password-protected content and embedded media.
- The Controller shall not be liable for the incorrect operation of Website functions where the User restricts Cookies in a manner that prevents those functions from operating.
XVI. External Links
The Website may contain links to external websites, including social media services, SharePoint and partners’ websites. The Controller is not responsible for the content or privacy policies of those websites.
XVII. Changes to the Privacy Policy
- The Controller may amend this Privacy Policy.
- The current version will always be published on this page of the Website.
- Amendments will enter into force when they are published, unless otherwise stated in the amended text.
- In the event of material changes concerning the Processing of Personal Data, the Controller will use reasonable efforts to provide appropriate notice, for example by publishing a notice on the Website.
Publication date of this version: 5 August 2026.