- Purpose
- Account creation, conclusion and performance of the Agreement
- Legal basis
- Article 6(1)(b) GDPR
- Example data
- email, account, organisation, Plan
Personal data protection
Privacy Policy
We explain what personal data we process, where it comes from, why we need it, whom we may entrust it to and what rights data subjects have.
Effective from: 2026-07-22
Operator details
- Seller / operator
- PR MANAGEMENT POLSKA sp. z o.o.
- Tax ID
- 6252465931
- Registry ID
- KRS 0000742293, REGON 380874279
- Address
- ul. Nowopogońska 98, 41-250 Czeladź
- Billing
- office@atvradar.com
- Privacy
- office@atvradar.com
1.Data controller
The personal data controller is the Operator identified in the “Operator details” section. Privacy contact: office@atvradar.com.
The Controller has not appointed a data protection officer unless separate DPO contact details are shown on the website. Enquiries may be sent directly to the privacy address.
2.Scope of the Policy
This Policy applies to people who use the website and panel, create an account, represent Customers, contact the Operator, subscribe to market information, participate in a demo, and people whose professional data appears in sources used to build the company catalogue and market network.
3.Categories of data processed
- identification and contact details: first name, surname, business email, phone number, job title or role;
- organisation and billing details: company name, tax-identification number or other tax number, country, address, purchaser details, selected Plan and Billing Period;
- account data: user identifier, secure password hash, organisation, permissions, and account and subscription status;
- payment and invoice data: transaction, subscription and invoice identifiers, amounts, currency, payment statuses, documents and integration errors; the Operator does not store complete card details;
- communication data: form content, correspondence, reports, history of arrangements, marketing consents and objections;
- activity data: visited routes, event type, used features, login history and technical security identifiers; the login IP address and user agent may be stored in hashed form;
- professional data from public sources: entity name, representatives or contact persons, professional role, public business address, company relationship and information source.
4.Data sources
- directly from the person or their organisation through registration, payment, demo, contact, newsletter and account support;
- from payment, communication and invoicing providers in connection with performance of the Agreement;
- from devices and systems when using the website and panel;
- from public registers and lists, official company websites, professional profiles, business materials and other lawfully available market sources.
5.Purposes and legal bases
- Purpose
- Payments, invoices and accounting and tax obligations
- Legal basis
- Article 6(1)(b) and (c) GDPR
- Example data
- purchaser details, tax ID, amounts, documents
- Purpose
- Demo, contact and pre-contract activities
- Legal basis
- Article 6(1)(b) or (f) GDPR
- Example data
- contact, company, business need
- Purpose
- Support, security, abuse prevention and establishment or defence of claims
- Legal basis
- Article 6(1)(f) GDPR
- Example data
- logs, IP hashes, events, correspondence
- Purpose
- Usage measurement and product development without creating an advertising profile
- Legal basis
- Article 6(1)(f) GDPR
- Example data
- route, event type, feature
- Purpose
- Marketing communication
- Legal basis
- Article 6(1)(a) or (f) GDPR and applicable electronic-communications law
- Example data
- email, consent, interest
- Purpose
- Building the company catalogue and professional market map
- Legal basis
- Article 6(1)(f) GDPR
- Example data
- public professional data, company, role, source
| Purpose | Legal basis | Example data |
|---|---|---|
| Account creation, conclusion and performance of the Agreement | Article 6(1)(b) GDPR | email, account, organisation, Plan |
| Payments, invoices and accounting and tax obligations | Article 6(1)(b) and (c) GDPR | purchaser details, tax ID, amounts, documents |
| Demo, contact and pre-contract activities | Article 6(1)(b) or (f) GDPR | contact, company, business need |
| Support, security, abuse prevention and establishment or defence of claims | Article 6(1)(f) GDPR | logs, IP hashes, events, correspondence |
| Usage measurement and product development without creating an advertising profile | Article 6(1)(f) GDPR | route, event type, feature |
| Marketing communication | Article 6(1)(a) or (f) GDPR and applicable electronic-communications law | email, consent, interest |
| Building the company catalogue and professional market map | Article 6(1)(f) GDPR | public professional data, company, role, source |
Legitimate interests include ensuring security, handling B2B enquiries, developing the product, protecting the Operator's rights and building a reliable view of the market's professional structure. Before such processing, we assess its necessity and its impact on individuals' rights.
6.Is providing data mandatory?
Providing data is voluntary, but some data is necessary to create an account, conclude the Agreement, process a payment, issue an invoice or respond to an enquiry. Failure to provide data required for a particular process may prevent that process from being completed. Marketing consent is voluntary and does not affect the ability to purchase.
7.Recipients and processors
Data may be received only by entities that need it to perform a specific task:
- DigitalOcean and infrastructure providers — hosting, network, backups and maintenance;
- Stripe — payments, subscriptions, fraud prevention and payment documents;
- Brevo — transactional messages and, with consent or another appropriate legal basis, marketing communication;
- wFirma — issuing and handling invoices;
- Google Ireland Ltd — user authentication for sign-in or registration with Google and, only after analytics consent is given, Google Analytics 4 usage statistics, pseudonymous User-ID and Google Ads conversion measurement using matched hashed contact details;
- Microsoft Ireland Operations Ltd — limited cookieless Microsoft Clarity usage analysis before a choice and fuller session measurement after analytics consent;
- Meta Platforms Ireland Ltd — conversion and advertising-effectiveness measurement through Meta Pixel and Conversions API, including advanced matching using hashed contact details you provide, only after analytics consent is given;
- email, security, monitoring, technical-support, accounting and legal-service providers;
- public authorities where disclosure is required by law or a legally binding request.
Processors act under contracts and the Controller's instructions, except where they independently determine the purposes and legal bases of processing as separate controllers.
8.Transfers outside the EEA
Some providers may process data outside the European Economic Area. In that case, the transfer is based on a mechanism permitted by the GDPR, in particular a European Commission adequacy decision, standard contractual clauses or another appropriate safeguard.
Information about the safeguard used, or a copy of it, may be obtained by writing to the privacy address, subject to the need to protect confidential information.
9.Retention periods
- account and Agreement data — for the term of the Agreement and then until the end of the period needed for settlements and the defence or establishment of claims;
- accounting and tax documents — for the period required by law;
- enquiries and correspondence — until the matter is closed and then for a period justified by potential claims or the need to evidence arrangements;
- marketing consent — until withdrawn, a valid objection is lodged or the purpose is no longer current; information about an objection may be kept longer in order to respect it;
- security logs and events — for the period needed to detect abuse, analyse incidents and protect the Service, subject to periodic review;
- professional data from public sources — until it becomes outdated, a valid objection is upheld or the analytical purpose ceases, with periodic source verification.
After the applicable period, data is deleted, anonymised or isolated solely for legal obligations and claims.
10.Data-subject rights
Depending on the legal basis and circumstances of processing, you have the right to:
- access your data and receive a copy;
- rectify inaccurate data and complete incomplete data;
- erasure of data;
- restriction of processing;
- data portability where data is processed automatically on the basis of consent or the Agreement;
- object, on grounds relating to your particular situation, to processing based on a legitimate interest;
- object to direct marketing at any time;
- withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal;
- lodge a complaint with the President of the Polish Personal Data Protection Office.
A request may be sent to office@atvradar.com. To protect data, we may request information needed to verify identity or authority.
11.Data of company representatives and data from public sources
If you contact us on behalf of a company or your professional data appears in a public source, it may still be personal data. We process it only in a professional context and to the extent needed to identify an entity, verify a market relationship, maintain B2B contact or protect catalogue quality.
The source may be a public register, official company website, public professional profile or material published by the entity itself. You have the right to obtain information about the source and to object. We assess each objection individually, taking into account the person's rights and the legitimate analytical interest.
12.Automated decisions and profiling
We do not make decisions about users based solely on automated processing that produce legal effects or similarly significantly affect them. We may automatically aggregate usage events, detect suspicious activity and calculate market indicators, but these are not decisions concerning a natural person's rights.
13.Security
We use measures appropriate to the risk, including access control, encrypted connections, password hashing, secure session cookies, permission restrictions, abuse protection, backups and operational event logging. However, no system can guarantee absolute security.
Suspected compromise of an account or data should be reported immediately to office@atvradar.com.
14.Cookies and usage measurement
The website and panel use an essential session cookie for sign-in. We also record limited usage events, such as opening a route or clicking a key CTA. Google Analytics 4 and Microsoft Clarity start in consent mode without analytics cookies; before acceptance, Clarity performs only limited measurement without a persistent identifier. After consent, we enable fuller session measurement, optional analytics cookies, Meta Pixel and Conversions API. You can change the decision at any time. Details are available in the Cookie Policy.
15.Children's data
The Service is intended for professional users and is not directed at children. If we receive reliable information that a child's data was provided without an appropriate legal basis, we will take steps to delete it.
16.Changes to the Policy
The Policy may be updated due to changes in law, providers, features or processing methods. We publish a new version with its effective date and may notify active users of material changes in the panel or by email.
