? GDPR - organizational and formal-legal information
-
Implementation of Administrator's orders
If the Administrator issues various types of orders (e.g. instructions to apply clauses, guidelines, rules, etc.), we comply with them within the scope of obligations arising fr...
-
Handling personal data protection breaches (incidents)
We have implemented a procedure in the event of a personal data protection breach and described examples of personal data protection breaches. The procedure is one of the compon...
-
Data Transfer outside the EEA
We do not transfer entrusted data outside the EEA. In practice, we do not transfer them even outside Poland. Personal data processing takes place in Szczecin (Aseco), Rybnik (Ho...
-
Privacy by design/Privacy by default
In accordance with this principle of privacy by design, we default to data protection as a mandatory element of the planned process, document, mechanism or functionality. For us...
-
Pseudonymization of personal data
Taking into account:current state of technical knowledge,implementation costs and the nature, scope, context and purposes of processingrisk of violating the rights and freedoms ...
-
Register/record of authorized persons
A register is kept of persons authorized to process personal data. The records include, among others: the date of granting access to personal data, the date of revoking access a...
-
What do we not use in the Startquestion?
We don't use it: We do not apply approved codes of conduct referred to in Art. 40 GDPR, because the Personal Data Protection Office has not yet issued any decisions in this rega...
-
Data protection impact assessment
Pursuant to Art. 35 of the GDPR, conducting an impact assessment on the protection of personal data is the responsibility of the controller (if a given type of processing - in p...
-
The principle of accountability
Each employee and collaborator whom we have authorized to process data uses a unique identifier. Logging in to the panel is only possible by providing a unique login and passwor...
-
Protocol or prior deletion of personal data
If it is necessary to delete personal data earlier or you need to have a protocol from the data deletion process, please contact us at iod@webankieta.pl
-
Deleting data after the end of service provision
The irreversible deletion of personal data from our platform can be achieved according to one of the following scenarios: 1. Respondent data or survey results will be deleted fr...
-
Checks and audits
Once a year, a company specializing in personal data protection with which we cooperate conducts an audit of the processes and procedures used at Get Feedback. The audit takes t...
-
Proceedings against PDA
To date, NO administrative or court proceedings have been initiated against us, as the processor, regarding the processing of personal data by us. This includes proceedings befo...
-
Exercise of the rights of data subjects
We have implemented measures enabling our clients to fulfill their obligations to respond to requests from the data subject regarding the exercise of his or her rights under Art...
-
Protection
We have implemented technical and organizational measures ensuring the ability to continuously ensure the confidentiality, integrity, availability and resilience of processing s...
-
Personal Data Security Policy
Our company has developed and implemented internal policies and procedures that take into account the principles of data processing specified in the GDPR. The Personal Data Prot...
-
Place of personal data processing
Personal data are processed mainly in the server room at Asseco (data are processed at the location of the ADS SA Office in Szczecin, 71-038 Szczecin), because they are stored t...
-
Further entrustment of personal data processing
We inform administrators who entrust us with personal data (or who process data at their request and who further entrust us with such processing) about the fact that we further ...
-
Scope of processing activities
In connection with the performance of the DPA contract, as a processor, we may process personal data by performing activities such as: collecting, viewing, recording, collating,...
-
Staff qualifications
All employees and closest collaborators undergo periodic training on personal data protection. At the end of each training, the trainee is obliged to complete a knowledge test. ...
-
Authorization to process data
All Startquestion employees and collaborators to whom we provide access to personal data process them on the basis of a personal authorization issued. The authorization concerns...
-
Confidential
All employees and associates processing entrusted personal data of customers sign appropriate confidentiality obligations. The commitment template is available upon request by c...
-
Categories of data subjects
Due to the fact that administrators (or if you act on behalf of such an administrator - processors) use services provided uniformly based on regulations or cooperation agreement...
-
Changing the scope of entrusted data
If, during the cooperation, it turns out that you will be entrusting us with a broader scope of data than originally indicated in the concluded DPA agreement, update the attachm...
-
Purpose and scope of data processing
The purpose and scope of Personal Data processing is determined by the Personal Data Administrator (ADO), i.e. our client. The PDC is responsible for ensuring that the personal ...
-
Personal Data Protection Inspector
The Personal Data Protection Inspector (DPO) is Katarzyna Ułasiuk, an "outsider" person from iSecure. Questions can be sent to Ms. Katarzyna at iod@webankieta.pl. We have been c...
-
ISO27001 certified
The hosting service providers we cooperate with meet the requirements of the GDPR regulation with the ISO27001 certificate.
-
Specificity of Data Entrustment
Startquestion.com is a platform for creating online surveys, including any forms that collect data (including personal data) from respondents. With Startquestion, users can coll...