Privacy Policy

Last updated: June 2026

GENERAL PROVISIONS

The controller of personal data collected through the websites www.rank-higher.pl and www.rank-higher.eu is RANK-HIGHER LIMITED LIABILITY COMPANY with its registered office at ul. Maślicka 181A / 11, 54-104 Wrocław, Poland, entered into the Register of Entrepreneurs of the National Court Register under KRS number: 0001092171, NIP: 8982305000, REGON: 528000681, with share capital of PLN 5,000.00, whose management board members are Maciej Paweł Bodziarczyk and Kamil Łukasz Janusz.

Office / correspondence address: ul. Szczytnicka 11, 5th floor, office 5.29, 50-382 Wrocław, Poland, e-mail: biuro@rank-higher.pl.

Personal data collected by the Controller through the Website are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), and the Polish Act on the Protection of Personal Data of 10 May 2018.

TYPES OF PERSONAL DATA, PURPOSE AND SCOPE OF COLLECTION, PROCESSING PURPOSE AND LEGAL BASIS

The Controller processes personal data through www.rank-higher.pl and www.rank-higher.eu in the following cases:

Use of the contact form by the user. Personal data are processed on the basis of Art. 6(1)(f) GDPR as the controller's legitimate interest.

If the user subscribes to the newsletter for commercial information sent electronically. Personal data will be processed on the basis of Art. 6(1)(a) GDPR with separate consent.

TYPES OF PERSONAL DATA PROCESSED

The Controller processes the following categories of your personal data:

first and last name, name/company or business name, PESEL/NIP, ID card number and series, citizenship, phone number, e-mail address, delivery/residence/location address (street or locality, building and plot number, postal code, post office address, country), property addresses related to the contract and other property data, bank account numbers.

RETENTION PERIOD OF PERSONAL DATA

Users' personal data will be stored by the Controller:

When the basis for processing is contract performance, for as long as necessary to perform the contract, and thereafter for a period equal to the limitation period for claims. Unless otherwise stated, the limitation period is six years, and for claims related to ordinary performance of duties and business activity – five years.

When processing is based on consent, data are processed until consent is withdrawn, and after withdrawal – for a period equal to the limitation period for claims. Unless otherwise stated, the limitation period is six years, and for recurring claims and business-related claims – five years.

When using the website, additional information may be collected, including: IP address, domain name, browser type, access time, operating system type.

Navigation data may also be collected, including information about links clicked and other actions on the website. The legal basis is the Controller's legitimate interest (Art. 6(1)(f) GDPR) in facilitating electronic services and improving their functionality.

Providing personal data by the user is voluntary.

Personal data may also be processed in an automated manner through profiling, if the user consents under Art. 6(1)(a) GDPR. Profiling means assigning a profile to assess preferences, behaviour and attitudes.

The Controller pays particular attention to protecting the interests of data subjects and ensures that collected data:

  • are processed lawfully;
  • are collected for specified, lawful purposes and not further processed incompatibly with those purposes;
  • are accurate and adequate in relation to the purposes for which they are processed;
  • are stored in a form permitting identification of data subjects for no longer than necessary.

DISCLOSURE OF PERSONAL DATA

Users' personal data will be disclosed to service providers used by the Controller to operate the Service. Depending on contractual arrangements, such providers either act as processors following the Controller's instructions or as independent controllers.

Your personal data will be stored exclusively within the European Economic Area (EEA).

RIGHT OF ACCESS, INFORMATION AND RECTIFICATION

Data subjects have the right to access, rectify, erase, restrict processing, data portability, object, and withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Legal bases for user requests:

  • Access to data – Art. 15 GDPR
  • Rectification – Art. 16 GDPR
  • Erasure (right to be forgotten) – Art. 17 GDPR
  • Restriction of processing – Art. 18 GDPR
  • Data portability – Art. 20 GDPR
  • Objection – Art. 21 GDPR
  • Withdrawal of consent – Art. 7(3) GDPR

To exercise the above rights, send an e-mail to: biuro@rank-higher.pl

If a user submits a request based on the above rights, the Controller will fulfil it without undue delay, no later than within one month, or reject it. If fulfilment within one month is not possible due to complexity or number of requests, the Controller will fulfil it within a further two months, informing the user within one month of the extension and its reasons.

If processing is considered to violate GDPR, the data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (UODO).

COOKIES

The Controller's website uses cookies.

Cookies are necessary for proper provision of services on the website. They contain information required for the service to function and enable general visit statistics.

The Service uses session cookies and persistent cookies.

Session cookies are temporary files stored on the user's device until logout (leaving the Service).

Persistent cookies are stored on the user's device for the period specified in cookie parameters or until deleted by the user.

The Controller uses its own cookies to better understand how users interact with the Website. Cookies collect usage statistics without collecting specific personal data.

Users may control cookie access through browser settings. See your browser documentation for details.

FINAL PROVISIONS

The Controller applies technical and organisational measures ensuring appropriate protection of personal data against unauthorised disclosure, theft, unlawful processing, alteration, loss, damage or destruction.

The Controller provides technical measures preventing unauthorised acquisition and modification of personal data transmitted electronically.

Matters not regulated by this Privacy Policy are governed by GDPR and other applicable Polish law.