Version: 8 May 2025
Introduction
At Nomios, we are committed to processing your personal data in a secure, transparent and fair manner. This Privacy Statement explains what personal data we collect, how we use it and what rights you have in relation to its processing. We encourage you to review this policy periodically, as it may be updated to reflect changes in our practices or legal requirements.
For more details, please also refer to our Cookie Policy.
Who are we?
Nomios Poland is responsible for the processing of personal data and is the controller of your personal data. Nomios Poland is part of a group of subsidiaries of Nomios, registered in various European countries (Nomios group companies).
All companies within the group cooperate with each other as if they were a single entity. This means that Nomios group companies may share information and personal data with each other in the course of their business. We have taken all necessary measures to ensure that, regardless of which group company processes your personal data, this is done in accordance with European and local data protection and privacy regulations.
Data Protection Officer (DPO)
At Nomios, we have appointed a Data Protection Officer (DPO) to ensure compliance with data protection regulations, including the GDPR. The DPO oversees our data protection strategy, trains staff, conducts audits and ensures that your rights are respected and that all data processing is carried out in a secure manner and in accordance with applicable regulations. The DPO is also the point of contact for any questions or concerns regarding privacy.
If you have any questions about this Privacy Statement or if you wish to exercise your rights, please contact our Data Protection Officer (DPO), Ms Alicja Tengli, at [email protected].
What personal data do we process?
When providing our services or using our website, we collect and process the following categories of personal data:
- Personal data: name, address, email address, telephone number.
- Company data: job title, company name, address.
- Communication data: information provided to us during communication.
- Account data: username, password.
- Technical data: IP address, browser type, operating system and other technical identifiers.
- Usage details: information about your interactions with our websites, products or services (e.g. pages visited, links clicked).
Why do we process personal data?
The personal data we collect and process is used exclusively for the specific purpose for which it was collected. We use your personal data for the following purposes:
- Communication: responding to requests for information or questions when you contact us via the contact form or email.
- Marketing: sending content such as newsletters, information about events or promotion of goods or services.
- Events: sending invitations and registering participants for events and training courses.
- Business operations: communication regarding the services provided
- Provision and improvement of services: providing, analysing and improving our products and services to ensure a more personalised experience.
- Compliance with legal regulations: fulfilling legal obligations, e.g. tax or regulatory obligations.
- Recruitment: detailed information can be found in our Candidate Privacy Statement.
Each processing activity is carried out with respect for your privacy, which allows us to ensure that your data will only be used for the intended purposes.
On what legal basis do we process your personal data?
In addition to the specific purpose, the processing of personal data requires a legal basis. We process your data on the following legal bases:
- Consent: if you have given your consent to the processing of your personal data for a specific purpose. You can withdraw your consent at any time.
- Performance of a contract: when it is necessary to fulfil our obligations under the contract between you and Nomios.
- Legal obligations: to comply with legal and regulatory requirements.
- Legitimate interest: when it is in our legitimate interest, provided that your right to privacy does not override our legitimate interest. For example, to maintain communication while providing our services, to improve our services or to respond to your questions.
How long do we store personal data?
We only store personal data for as long as necessary to fulfil the purposes for which it is processed. After the retention period has expired, we anonymise or securely delete your personal data.
Who do we share personal data with?
We share your data in a secure manner:
- Nomios Group entities: for internal operational purposes.
- Processors: external service providers, such as IT, support and postal services. Service providers are carefully selected and are contractually bound by a data processing agreement to comply with our instructions, to process personal data only for the agreed purposes and to protect personal data in accordance with the GDPR.
Transfer of data to third countries
Our goal is to process your personal data within the European Economic Area (EEA). In some cases, your personal data may be transferred outside the EEA. In such cases, if the country to which the personal data is transferred is not recognised by the European Commission as providing an adequate level of protection, we implement the necessary safeguards, such as standard contractual clauses (SCCs), to ensure an adequate level of data protection in accordance with the GDPR.
How do we ensure the security of personal data?
At Nomios, we combine various technical and organisational measures to protect your personal data against loss, theft or other unlawful use. Technical measures include the implementation of access controls, encryption and firewalls. We take organisational measures such as training our employees in the responsible handling of your personal data, monitoring systems to prevent unauthorised access and auditing compliance with the GDPR.
In the event of a data breach, we will notify you if the breach is likely to result in a high risk to your rights or freedoms.
What rights do you have in relation to your personal data?
Under the GDPR, you have the following rights:
- Right of access: you may request information about the processing of your personal data and obtain a copy of the personal data we process.
- Right to rectification: you may ask us to correct inaccurate personal data or complete incomplete personal data.
- Right to erasure: you may request that your personal data be erased in certain cases, for example, when the personal data is no longer necessary or when you have not given your consent to its processing.
- Right to restrict processing: you may request that we restrict the processing of your personal data in certain cases, for example, if you dispute the accuracy of the personal data or have objected to its processing.
- Right to data portability: you may request that your data be transferred in a machine-readable format to another provider if the processing is based on consent or the performance of a contract and the processing is carried out by automated means.
- Right to object to processing: You may object to the processing of your personal data on the basis of legitimate interests, such as processing for direct marketing purposes. We will no longer process personal data unless there is a legitimate reason that overrides your interests, rights and freedoms or serves to establish, pursue or defend claims.
- Right to withdraw consent: the right to withdraw consent to the processing of personal data at any time. Once you withdraw your consent, we will no longer process your personal data. This does not affect the lawfulness of processing based on consent before its withdrawal.
To exercise these rights, please contact us using the contact details below. In order to ensure the security of your personal data, we may ask you to confirm your identity. We will respond to your request within one month. This period may be extended by a further two months if necessary, depending on the complexity of the request or the number of requests received.
Third-party websites
Our websites contain links to external websites, such as social media platforms, whose terms of use are not covered by this Privacy Statement. We recommend that you review their terms and conditions and privacy policies.
Contact
If you have any questions about this Privacy Statement or wish to exercise your rights, please contact us at:
Nomios Poland sp. z o.o.
Puławska 537
02-844 Warsaw
Poland
Tel.: +48 22 567 17 40
Email: [email protected]
If you believe that your request has not been properly addressed, you may contact the relevant data protection authority, UODO, to lodge a complaint.