Information clause for the "report abuse" form

Basic information on the processing of your personal data by KRUK S.A. pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27th 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the "GDPR").

Personal Data Controller

The Controller processing data within the meaning of Article 4(7) of the GDPR is the entity indicated as the recipient of the data at the time of submission of the notification by the notifier.

KRUK S.A.
51-116 Wroclaw, 8 Wołowska Street
Email: info@kruksa.pl

Data Protection Officer

We have appointed a Data Protection Officer who you may contact regarding any matters related to the processing of your personal data and your rights related to the processing of your data. You can contact our Data Protection Officer by mail to the address: Magdalena Pakosińska – Krawczyńska, Data Protection Officer, KRUK S.A., ul. Wołowska 8, 51-116 Wrocław, or by e-mail: dpo@kruksa.pl.

Where did we get the data from?

The use of the online form to report violations/abuses is voluntary, so the data provided to us by the form comes directly from the notifier, i.e. you. The information you provide to us determines what data we will process. We regularly process the following information:

Information clause for the "report abuse" form

Basic information on the processing of your personal data by KRUK S.A. pursuant to Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27th 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the "GDPR").

Personal Data Controller

The Controller processing data within the meaning of Article 4(7) of the GDPR is the entity indicated as the recipient of the data at the time of submission of the notification by the notifier.

KRUK S.A.
51-116 Wroclaw, 8 Wołowska Street
Email: info@kruksa.pl

Data Protection Officer

We have appointed a Data Protection Officer who you may contact regarding any matters related to the processing of your personal data and your rights related to the processing of your data. You can contact our Data Protection Officer by mail to the address: Magdalena Pakosińska – Krawczyńska, Data Protection Officer, KRUK S.A., ul. Wołowska 8, 51-116 Wrocław, or by e-mail: dpo@kruksa.pl.

Objectives and basic data processing

The online form for reporting breaches/abuses has been created to report observed breaches/abuses, in particular with respect to ensuring compliance of KRUK S.A.'s operations with applicable laws, internal regulations, market and ethical standards. It allows you to communicate information about possible compliance violations that can have serious consequences for your business. This includes the consequences of criminal liability.

Your personal data will be processed for the following purposes:

Recipients of the data

Your data may be shared with entities that support our activities, such as entities that provide legal services, entities that support our IT infrastructure, our advisors or auditors and law enforcement authorities, as well as other authorities and entities where the obligation to provide data arises from legal provisions. The data provided will be processed by employees of the Compliance Department of KRUK S.A. who are authorised to do so.

As a matter of principle, we do not transfer data to third parties. However, it may happen that we transfer the provided data to other departments of the controller or to KRUK Group companies in accordance with Article 28 of the GDPR if it is necessary to clarify the matter.

As a general rule, we are required by law to inform the accused persons or witnesses named in the report that we have received a notification about them, as long as such information does not impede further investigation of the report. The identity of the notifier will not be disclosed to the extent permitted by law.

Period of storage of personal data (data retention)

The data is stored for as long as it is necessary to fulfill the purposes listed above or to complete the processing of the breach/abuse report, within the framework of applicable law. The criteria are, for example, the complexity of the case, the length of time it has been processed and the subject matter of the complaint.

Rights of the data subject

Your rights are:

How to make a request

By sending an e-mail to: info@kruksa.pl, by sending a letter by traditional mail or in person at: 51-116 Wrocław, 8 Wołowska Street

Requirement to provide data

Providing data is voluntary

Profiling and Automated decision-making

Your personal data will not be used for automated decision making, including profiling.

Passing Data beyond European Area Economic (EEA)

We use suppliers and partners outside the EEA and it is therefore possible that personal data may be transferred to countries outside the EEA. Such transfer of personal data may take place on the basis of an adequacy decision or subject to appropriate safeguards, Art. 45 and 46 GDPR.

KRUK Group Companies

more +

Board of Directors

more +