Introduction

The following statement specifies all legal grounds for processing and methodology of collection and usage of personal data. This statement provides necessary information on the rights of all concerned individuals. We use personal data provided only for purposes specified in the presented document or any other reason indicated at the time of their transfer to Sun Winner. Personal data protection at Sun Winner is always taken very seriously and handled in most professional manner.

Sun Winner processes personal information for various, specific purposes. Different collection methods, legal bases for processing, use, disclosure and retention periods may apply. Personal data is to be understood as information collected on a particular individual.

We maintain full transparency in terms of acquiring and processing methods of personal data.

Data protection and security means

We provide appropriate procedures, policies and training covering data protection, confidentiality and security. We control the measures introduced in terms of their adequacy to secure the data held. We adhere to recognized security standards, and our information security management system for personal data is subject to constant research and development. We take the security of all data we hold very seriously.

Data processing

1. Business contacts

Personal data collection
Sun Winner uses IT systems to process business partners personal data (current and potential Sun Winner customers and / or natural persons associated with them).

Sun Winner employee supervises the provision and collection of personal data into the ERP System. Personal data includes name, surname, employer’s name, contact person’s position, telephone number, e-mail address and other business contact details. It is also possible to obtain personal data of our business partners. They can be obtained as an xml exchange file, generated by customer service systems. The scope of the obtained data does not exceed the above-mentioned.

Personal data is collected at the registration stage or logging in to the system, when creating projects and filling in contact forms: e-mail address, IP address, name, surname, assembly address, telephone number. The user may allow the download of his location data via the browser. This process consists of determining which of the administrator’s business customers (the so-called Dealer) should contact the User. The user can edit the data assigned to him, such as: e-mail address, name, surname, assembly address, if logged in at any time.

Use of personal data

Disclosure of business customers personal data Sun Winner employees and our Business Partners may be possible in the event of ongoing business activities. Personal data may be used for the purposes of:

Sun Winner and Business Partner business and service development,

Sharing personal information with Sun Winner employees to carry out business activities and offer new products and services,

Provide information about Sun Winner and the range of our services and products,

Fulfillment of orders for products and services,

Analyzing of sales opportunities, market trends or relationship maps,

Access of Sun Winner business partners (dealers) to the personal data of users of IT systems.

Legal basis for the processing of personal data

Personal data of our business clients are processed on the basis of the legitimate interest of the personal data administrator or in the event of consent, when the data subject has been asked for consent. The administrator’s interest is related to the sale of products and services to our current and future customers.

Personal data storage

The storage of personal data in the ERP system takes place for the period necessary for the purposes specified above for the use of personal data. This may be for the relationship’s duration with the business client or for the period in which it is necessary to document the relationship with the client, or for legal purposes.


2. Individual clients personal data

Sun Winner collects only personal information that is necessary for the fulfillment of the stated purposes in accordance with the data policy. Sun Winner asks customers to provide data only when necessary. The ERP system processes personal data of individual customers. A Sun Winner employee initiates the collection of personal data and its entry into the ERP system. The data includes the name, surname, home address, possibly delivery address, e-mail address, telephone number.

Use of personal data

Individual Customers personal data may be disclosed to Sun Winner employees and our Business Partners in their regular business activities.

Personal data may be used for the purposes of:

Providing information about Sun Winner and the range of our services and products,

Sharing personal information with Sun Winner employees to carry out business activities and offer new products and services,

Fulfillment of orders for products and services.

Legal basis for the processing of personal data

Personal data of our business clients is processed on the basis of the legitimate interest of the personal data administrator or in the event of consent, when the data subject has been asked for consent. The administrator’s interest is related to the sale of products and services to our current and future customers.

Storage of personal data

The storage of personal data in the ERP system takes place for the period necessary for the purposes specified above for the use of personal data. This may be for the duration of the relationship with the business client or for the period in which it is necessary to document the relationship with the client, or for legal reasons.


3. Recruitment proces candidates

Candidates’ personal data

We collect personal data of our candidates in the course of the recruitment process. We obtain personal data directly from candidates or from third parties, i.e. recruitment agencies, depending on the requirements. The processed information includes the necessary data specified by law regarding the education, work experience, employment history of the candidate applying for a job in our company. The information provided to us is processed in the CV, cover letters or other forms necessary in the recruitment process. We do not require any information from our candidates in the field of specific data describing as « sensitive data », including data on racial or ethnic origin, biomedical, genetic and health data, trade union membership, religious beliefs, political or philosophical views. In the case of an application for a position where the law requires confirmation of information about a clean criminal record, we may ask the candidate to provide such data. We collect this type of data only to the extent that it is compliant and appropriate to the law.


Use of personal data

Applicants data is used in the following way:

to enable us to effectively run the recruitment process for a given position,

with the applicant’s consent, we may notify him or her of job opportunities at Sun Winner which may be of interest to him. It can also be information about work events that are organized by or with the participation of Sun Winner.

Legal basis for processing

Personal data collected and processed by Sun Winner are carried out in accordance with applicable regulations, i.e. the Labor Code or when applying for a job. The data may also be processed as part of our legitimate interest, if the applicant agrees to use the data for other purposes. The data will be processed within the granted consent. In the event of unsuccessful recruitment, personal data of persons will be stored on the basis of consent.

Data storage

In the event of successful recruitment, the personal data obtained in this way is stored for the purpose of preparing an employment contract, in accordance with statutory provisions. Documents of rejected candidates are removed at the latest six months after the end of the recruitment process. If the applicant wishes to leave his documents in our database of candidates for a longer period, his consent will be required.


4. Suppliers (subcontractors and individuals related to suppliers and subcontractors)

Collection of personal data

We collect and use personal data of our suppliers, goods and services (including subcontractors and individuals related to suppliers and subcontractors) in order to manage these relationships, orders, receive services from suppliers and provide professional services to customers.

Use of personal data

Personal data is used for the following purposes:

purchase of goods and services:

We process personal data about our suppliers of goods and services and their employees to the extent necessary to carry out business activities. For example, when a supplier supplies us with goods, or provides transportation, assembly, equipment / facility management or other outsourced services, we process the personal data of individuals who perform these services.

administration, management and development of activities and services.

Personal data is processed in order to conduct business, which includes:

managing our relationships with suppliers,

development of commercial and production activities and services (eg identification of customer needs and improvement of service performance),

maintenance and use of IT systems,

administration and management of our website, servers, e-mail, ERP System and other systems and applications,

safety, quality and risk management.

We have security measures in place to protect our clients’ own information and information (including personal data), which includes detecting, investigating and solving security threats. We may process personal data as part of security monitoring; for example, by automatic scans to detect malicious messages.

The deliveries and services provided by our contractors are subject to quality checks, which may include the processing of personal data. As a part of the supplier selection and acceptance procedures, we collect and store personal data.

Legal basis for the processing of personal data


In the event of the data processing referred to in this section, it is necessary for the performance of a contract to which the data subject is a party (for example, when processing is necessary to act as a recipient or service recipient), the processing takes place on the basis of a contract.

In the event the data processing is necessary to fulfill any legal obligations (e.g. tax regulations resulting from the need to demonstrate or document business activity), the processing takes place on such a legal basis.

In the event of processing personal data for other purposes specified above, we act on the grounds of the legitimate interest of the data controller (e.g. purchasing goods, receiving services, providing services, administration, business management and development, as well as business, security, quality or risk management) or consent if we have asked the data subject for such consent.

Personal data storage
Personal data processed by us is stored for the period deemed necessary for the purpose for which they were collected (in accordance with the requirements of applicable laws and regulations).

Personal data may be stored longer, if required by law or regulations and for the purpose of establishing, exercising or defending our rights.


5. Company’s premises and visitors monitoring

Our company’s premises are covered by security measures, including a monitoring and buildings access control systems. Appropriate markings placed in visible places inform about the operation of the monitoring system. The materials recorded as part of the monitoring are stored securely and access to them can be obtained only in exceptional cases (e.g. to investigate an incident). Monitoring recordings are usually automatically overwritten after a maximum period of 3 months (or less), unless the recording is necessary to investigate a specific event (e.g. theft, fire). People entering company’s premises are registered at the gatehouse. Registered data are name and surname and / or company name, vehicle registration number. We keep guest documentation for a maximum of one year. This documentation is securely stored, and access to it can only be obtained in exceptional cases (e.g. to investigate an incident). The legal basis for processing is the legitimate interest of the data controller (ensuring necessary security levels Sun Winner’s premises).

6. Sun Winner’s web page visitors

Personal data collection
Our web page’s visitors usually have control over the personal information they provide. To a limited extent, we may collect personal data automatically via cookies on these websites. We receive the following personal data from our websites visitors: name, surname or company name, company address, e-mail address which is also a login to our website. Visitors can also send us an email via the website. Such messages contain the city and e-mail address – optionally: name, surname and telephone numer or additional information that the user wants to include in the message.

Browsing history „cookies”
Cookies are small text files, placed on your computer when you visit websites to help in providing more personalized experience. The use of cookies is now standardized on most websites. If you do not wish to receive cookies, you can manage and control them via your browser. Before registering on our website, you must accept cookies. If these files are deactivated, other website functions may not work properly. After completing your visit to the website, you can delete cookies from your « browsing history ».

Personal data usage
When a visitor provides us with personal data, it is used for purposes specified at the time of their transmission (or when they are obvious in the context of the data being transferred). Typically, personal data is collected for the following purposes:

web page registration,

signing up to receive information,

inquiry for details,

publications / materials distribution,

monitoring and enforcement of website terms and conditions.

administering and managing of our site, including confirming and certifying identity, preventing unauthorized access to restricted parts of the web page, premium content or other services available only to registered users,

aggregating data for the purpose of analyzing and improving the operation of the website,

Unless otherwise specified, we may also use your information to contact you and present information about Sun Winner’s activities, products and services or other information that may be of interest to you. The User may opt out of receiving the above information by contacting us via e-mail sent to the following address: sunwinner@sunwinner.pl.

We do not collect personal data on our website for the purpose of transferring it or selling it to third parties for marketing purposes, and we do not send messages on behalf of third parties. In the event that such information may be provided to a company other than Sun Winner’s contracting party the visitor must first consent.

Legal basis for processing personal data
We process personal data of people visiting our websites on the basis of the legitimate interest of the data controller or consent in the event that the data subject has been asked for such. For example, based on the legitimate interest of the data controller, we send marketing materials tailored to the preferences of the data subject.

Personal data storage
We store personal data collected via websites for as long as necessary (e.g. for the duration of our relationship with a given person).

Legal basis for personal data processing

Legal grounds for each processing operation are set out in the relevant section above. In the event of the personal data processing on the basis of legitimate controller’s interest, we try to analyze and balance our interest and the potential impact on the data subject (positive and negative) and the rights of that person under the data protection provisions.

Our legitimate interest of the data controller does not automatically override the rights of the data subjects – we do not process personal data in the event that the impact on the data subject outweighs our interests (unless we have the appropriate consent or it is required or permitted by law rights).

Personal data. When and how we transfer data to third parties

We provide personal data to others only if we are permitted to do so by the law.

In such cases, the contract provides provisions and security mechanisms necessary to protect personal data and to maintain our standards in terms of data protection, confidentiality and security.

Our company operates globally and in cooperation with other products, goods and services suppliers we conduct our business directly and through external entities based in other countries. As a result, personal data may be transferred outside the territory of the countries in which our company or our clients’ companies are based.

Personal data stored by Sun Winner may be transferred to:

External organizations that provide applications / functionalities or provide data processing or IT services,

Thanks to the support of external entities, we can carry out our business tasks, provide services, as well as provide, operate and manage internal IT systems. They include, among others providers of information technology, ERP system, cloud based software, as well as entities providing identity management, hosting and website management services, data analysis, backup, security and data storage services. The servers supporting and supporting the cloud infrastructure are located in secure data centers around the world, and personal data can be stored in any of them.

Third-party organizations that otherwise assist us with the provision of products, goods or information or services.

Statutory auditors and other professional advisers.

Law enforcement agencies, regulators and other governmental authorities or third parties where required by applicable law (in a manner consistent with such law).

We may receive requests from authorized third parties to disclose personal information, for example, to verify compliance with applicable laws and regulations, to investigate alleged crime, to establish, exercise or defend statutory rights. We will only comply with such requests where we are permitted to do so by applicable law or regulation.

Korekty niniejszego dokumentu

We recognize that transparency is an ongoing obligation and we will review and update this document on a regular basis.

This statement was last updated on 02/10/2020.

Data administrator’s and Sun Winner’s contact details

Sun Winner is the data administrator. In case of any questions regarding the presented document or our personal data processing policy, please contact us at:

​Sun Winner Piechowska Agnieszka
ul. Łomżyńska 102, 18-400 Stare Kupiski
Helpline: (+48) 731-731-311 / FAX: (+48) 86-444-15-84
E-mail: sunwinner@sunwinner.pl
www.sunwinner.pl

Personal data access rights

Individuals whom the data processing concerns have specific rights regarding their personal data and data controllers are responsible for the implementation of these rights. If the decision on the method and purpose of processing personal data belongs to us, we are the data administrator and below we provide further information on the rights of concerned individuals and how to exercise them.

Access to personal data

Concerned individuals have the right to access data that we store as the data administrator. This right can be exercised by sending an e-mail with a relevant request to sunwinner@sunwinner.pl or by mail.

Please send a request to the Administrator by e-mail or by mail to the addresses indicated in the contact details above.

Personal data updating

Updating the personal data provided to us can be made by sending an appropriate e-mail to the following address: sunwinner@sunwinner.pl, by correspondence or, where appropriate, by contacting us via the relevant registration page, or by changing the personal data stored in the respective applications for which the registration was made.

Where reasonably practicable, upon notification to us that any personal information we process about you is no longer valid, we will correct it based on updated information.

Personal data processing objection

In the case of processing personal data on the basis of consent, natural persons have the right to withdraw this consent at any time. To withdraw consent to the processing of personal data, please send us an appropriate e-mail to the address sunwinner@sunwinner.pl or by mail, in order not to receive further marketing information, please click the resignation link in the appropriate e-mail sent by us.

The right to limit the processing or object to the processing of personal data

Natural persons have the right to limit the processing or object to the processing of their personal data at any time, due to their special situation, unless the processing is required by law.

In this case, we will not further process personal data or limit the processing, as long as we are able to demonstrate the legitimate grounds for processing or for the establishment, exercise or defense of our rights.

Other personal data processing subjects rights

The purpose of the presented document is to inform you what data is collected by us and how it is used. Concerned individuals have the right to request deletion and the right to transfer personal data in addition to the right to access, change and processing limitation or object to the processing indicated above. If you wish to claim these rights, please send a message to sunwinner@sunwinner.pl or directly by post.

Complaints

If you wish to file a complaint regarding our use of your personal data, please send an email with details to sunwinner@sunwinner.pl Complaints may also be submitted by mail. Any complaints received will be dealt with and answered.

Concerned individuals have the right to lodge a complaint with the President of the Personal Data Protection Office. More information on the rights of persons and how to file a complaint to the President of the Personal Data Protection Office can be obtained at https://uodo.gov.pl/.