Skip to content

Privacy Policy

This Privacy Policy sets out the rules for storing and accessing data on the Devices of Users using the Website for the purpose of providing electronic services by the Administrator, as well as the rules for collecting and processing Users’ personal data provided by them personally and voluntarily through the tools available on the Website.

This Privacy Policy is an integral part of the Website’s Terms of Service, which sets out the rules, rights and obligations of Users of the Website.

§1 Definitions

  • Website – the website “squarestate.pl” operating at https://squarestate.pl
  • External website – websites of partners, service providers or service recipients cooperating with the Administrator
  • Website / Data Administrator – the Administrator of the Website and the Data Administrator (the “Administrator”) is “Square Enterprises Sp. z o.o.”, operating at: ul. Wielopole 7/6, 31-072 Kraków, Poland, Tax Identification Number (NIP): 6751672921, providing electronic services through the Website
  • User – a natural person for whom the Administrator provides electronic services through the Website
  • Device – an electronic device together with software, through which the User accesses the Website
  • Cookies – text data collected in the form of files placed on the User’s Device
  • GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC
  • Personal data – information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity
  • Processing – an operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, alignment, restriction, erasure or destruction
  • Restriction of processing – marking stored personal data with the aim of limiting its processing in the future
  • Profiling – any form of automated processing of personal data used to evaluate certain personal aspects of a natural person, in particular to analyse or predict aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements
  • Consent – any freely given, specific, informed and unambiguous indication of the data subject’s wishes, by which they, through a statement or clear affirmative action, agree to the processing of their personal data
  • Personal data breach – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data
  • Pseudonymisation – processing personal data so that it can no longer be attributed to a specific data subject without additional information, provided such information is kept separately and protected by technical and organisational measures
  • Anonymisation – an irreversible process that destroys/overwrites “personal data”, making it impossible to identify or link a record to a specific user or natural person

§2 Data Protection Officer

Pursuant to Article 37 of the GDPR, the Administrator has not appointed a Data Protection Officer.

For matters relating to data processing, including personal data, please contact the Administrator directly.

§3 Types of cookies

  • Internal cookies – files placed and read from the User’s Device by the Website’s own IT system
  • External cookies – files placed and read from the User’s Device by the IT systems of external websites, placed via scripts and services made available on the Website
  • Session cookies – placed and read during a single Device session, deleted once the session ends
  • Persistent cookies – remain on the Device until manually deleted, or until the Device’s browser is configured to remove them at the end of a session

§4 Data storage security

Cookie storage and reading mechanisms – implemented through built-in web browser mechanisms and do not allow retrieval of any other data from the User’s Device or from other websites visited by the User, including personal data or confidential information. Transferring viruses, trojan horses or other malware to the User’s Device is also practically impossible.

Internal cookies – cookies used by the Administrator are safe for Users’ Devices and contain no scripts, content or information that could threaten the security of personal data or the Device.

External cookies – the Administrator takes all possible steps to verify and select website partners in the context of User security, and selects well-known, large partners with global public trust. It does not, however, have full control over the content of cookies from external partners and, to the extent permitted by law, is not liable for their security, content, or licence-compliant use.

Cookie control

  • Users may, at any time, independently change their settings regarding the saving, deletion and access to cookies stored by any website.
  • Users may, at any time, delete any cookies saved so far using the tools of the Device through which they use the Website.

Risks on the User’s side – the Administrator applies all possible technical measures to secure data placed in cookies. Security of this data, however, depends on both parties, including the User’s own actions. The Administrator is not liable for interception of this data, impersonation of the User’s session, or its deletion, resulting from the User’s conscious or unconscious actions, or from viruses, trojan horses or spyware that may have infected the User’s Device.

Storage of personal data – the Administrator makes every effort to keep personal data voluntarily provided by Users secure, with access limited and carried out in line with its intended purpose, including through appropriate physical and organisational safeguards.

§5 Purposes for which cookies are used

  • Improving and facilitating access to the Website
  • Personalising the Website for Users
  • Maintaining statistics (users, number of visits, device types, connection, etc.)

§6 Purposes of processing personal data

Personal data voluntarily provided by Users is processed for one of the following purposes:

  • provision of electronic services,
  • communication between the Administrator and Users regarding the Website and data protection,
  • ensuring the Administrator’s legitimate interest.

Data on Users collected anonymously and automatically is processed for one of the following purposes:

  • maintaining statistics,
  • ensuring the Administrator’s legitimate interest.

§7 Cookies of external websites

The Administrator uses JavaScript scripts and web components of partners who may place their own cookies on the User’s Device. Users can decide in their browser settings which cookies may be used by particular websites. Below is a list of partners or services implemented on the Website that may place cookies:

  • Statistics: Google Analytics

Services provided by third parties are beyond the Administrator’s control. These entities may change their terms of service, privacy policies, purposes of data processing and cookie use at any time.

§8 Types of data collected

The Website collects data about Users. Some data is collected automatically and anonymously, and some is personal data provided voluntarily by Users while using the Website’s services.

Anonymous data collected automatically:

  • IP address,
  • browser type,
  • screen resolution,
  • approximate location,
  • website subpages visited,
  • time spent on a given subpage,
  • operating system type,
  • address of the previous subpage,
  • referring page address,
  • browser language,
  • internet connection speed,
  • internet service provider.

Data collected through the contact form:

  • name,
  • email address,
  • phone number,
  • message content and any other data voluntarily provided in the form.

Some data (excluding identifying data) may be stored in cookies or shared with a statistics service provider.

§9 Access to personal data by third parties

As a rule, the Administrator is the sole recipient of personal data provided by Users. Data collected as part of the services provided is not shared with or sold to third parties.

Access to data (usually based on a data processing agreement) may be granted to entities responsible for maintaining the infrastructure and services necessary to run the Website, i.e. hosting companies providing hosting or related services to the Administrator.

§10 How personal data is processed

Personal data voluntarily provided by Users:

  • will not be transferred outside the European Union, unless published as a result of the User’s own individual action,
  • will not be used for automated decision-making (profiling),
  • will not be sold to third parties.

Anonymous data (without personal data) collected automatically:

  • may be transferred outside the European Union,
  • will not be used for automated decision-making (profiling),
  • will not be sold to third parties.

§11 Legal basis for processing personal data

The Website collects and processes User data on the basis of:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR),
  • Article 6(1)(a) – the data subject has given consent to the processing of their personal data for one or more specific purposes,
  • Article 6(1)(b) – processing is necessary for the performance of a contract to which the data subject is party, or to take steps at their request prior to entering into a contract,
  • Article 6(1)(f) – processing is necessary for the purposes of the legitimate interests pursued by the Administrator or a third party,
  • the Polish Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws 2018, item 1000),
  • the Polish Telecommunications Law Act of 16 July 2004 (Journal of Laws 2004, No. 171, item 1800),
  • the Polish Act of 4 February 1994 on Copyright and Related Rights (Journal of Laws 1994, No. 24, item 83).

§12 Period of processing personal data

Personal data voluntarily provided by Users is, as a rule, stored only for the period necessary to achieve the purpose for which it was collected (e.g. responding to an enquiry submitted through the contact form), and is deleted or anonymised within 30 days of that purpose being fulfilled.

An exception applies where it is necessary to safeguard the Administrator’s legitimate interest in further processing (e.g. pursuing claims) — in such cases, data may be stored for up to 3 years.

Anonymous statistical data, which does not constitute personal data, is stored for an indefinite period for the purpose of maintaining Website statistics.

§13 Users’ rights relating to the processing of personal data

  • Right of access – to obtain access to their personal data, upon request to the Administrator.
  • Right to rectification – to request prompt rectification of inaccurate personal data and completion of incomplete data.
  • Right to erasure – to request prompt erasure of personal data. The Administrator reserves the right to withhold fulfilment of such a request to protect its legitimate interest (e.g. where data is necessary to continue ongoing correspondence).
  • Right to restriction of processing – in the cases indicated in Article 18 GDPR, including where the accuracy of the data is contested.
  • Right to data portability – to receive personal data in a structured, commonly used, machine-readable format.
  • Right to object – to processing of personal data in the cases specified in Article 21 GDPR.
  • Right to lodge a complaint – with the President of the Personal Data Protection Office (UODO), the supervisory authority.

All of the above rights are exercised upon request submitted to the Administrator, as described in §14 below.

§14 Contact with the Administrator

The Administrator can be contacted in one of the following ways:

  • postal address – Square Enterprises Sp. z o.o., ul. Wielopole 7/6, 31-072 Kraków, Poland,
  • email address – hello@squarestate.pl,
  • phone – +48 533 378 405.

§15 Website requirements

Restricting the saving of and access to cookies on the User’s Device may cause some Website functions to work incorrectly. The Administrator is not liable for any malfunction resulting from a User restricting cookies in any way.

§16 External links

The Website may contain links to external websites with which the Administrator does not cooperate. The Administrator is not liable for content located outside the Website.

§17 Changes to the Privacy Policy

  • The Administrator reserves the right to change this Privacy Policy, in particular regarding the use of anonymous data or cookies, without a separate obligation to notify Users.
  • Changes will be published on this Website subpage.
  • Changes take effect from the moment of publication.

Last updated: 10 June 2026.