PRIVACY POLICY INTER MARINE SP. Z O.O.

What is the GDPR?

The GDPR (General Data Protection Regulation), which has been in force throughout the European Union since 25 May 2018, refers to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

The GDPR applies to all personal data held by the Controller and Joint Controllers, i.e. in particular data relating to: employees, associates and job applicants.

Who is the Data Controller/Joint Data Controller?

The Controller, i.e. the entity determining the purposes and means of processing your personal data, is Inter Marine Sp. z o.o., with its registered office in Gdynia (81-578), at 4 Wiczlińska Street. The following companies are also Joint Controllers:
IM Solutions and Inter Marine Energy Sp. z o.o., registered at the same address.

How can you contact the Controller/Joint Controller to obtain further information about the processing of personal data?

The Controller/Joint Controller has appointed a Data Protection Officer, who can be contacted by email at: rodo@intermarinegroup.com. You may contact them regarding any matters relating to the protection of personal data.

For what purpose is personal data processed?

Personal data is processed by the Controller/Joint Controller for the following purposes:

  • to verify and employ a staff member, on the basis of their consent to the processing of personal data (see Article 6(1)(a) of the GDPR for ordinary personal data and Article 9(2)(a) of the GDPR for special categories of personal data),
  • to fulfil the provisions of the employment contract and civil law contracts (pursuant to Article 6(1)(b) of the GDPR),
  • fulfilling a legal obligation incumbent on the Controller/Joint Controller, including, amongst other things, in relation to employees and associates concerning the payment of their taxes, the payment of social security, health insurance and other contributions required by law, as well as the provision of non-mandatory (including commercial) employee benefits (pursuant to Article 6(1)(c) of the GDPR),
  • the disclosure of an employee’s image, on the basis of consent given by the employee (see Article 6(1a) of the GDPR),
  • to contact a person who provides their personal data via the contact form on the websiteintermarinegroup.com (pursuant to Article 6(1a) of the GDPR, i.e. the data subject’s consent),
  • taking steps to enter into a contract, and/or in connection with the performance of a contract with a customer to which the data subject is a party, or with a company providing the personal data of its employees for the same purpose (pursuant to Article 6(1)(b) of the GDPR),
  • to take steps to enter into a contract, or in connection with the performance of a contract with a supplier (of a service or product/goods), including, amongst others, subcontractors (pursuant to Article 6(1b) of the GDPR),
  • communication and direct marketing, including the sending of emails (pursuant to Article 6(1)(f) of the GDPR, as a legitimate interest of the Controller/Joint Controller),
  • the pursuit or safeguarding of any potential claims (pursuant to Article 6(1)(f) of the GDPR).

How long may the Controller/Joint Controller process personal data?

The Controller/Joint Controller will process personal data for a period of:

  • 10 years in the case of employment contracts,
  • 6 years in the case of civil law contracts, including those with self-employed individuals,
  • the performance of a contract with a customer and, following its termination, for as long as required by mutual agreement or by law,
  • until any potential claims become time-barred.

In other cases, personal data will be processed until the data subject objects or withdraws their previously given consent.

What rights does a data subject have when their personal data is processed by the Controller/Joint Controller?

In connection with the processing of personal data, the data subject has the following rights:

  • the right to access the data and to have it rectified,
  • to request erasure or restriction of processing,
  • to object to the processing of data,
  • to data portability,
  • to withdraw consent to processing at any time,
  • to lodge a complaint with the supervisory authority, i.e. the Office for Personal Data Protection (https://uodo.gov.pl/), in the event of alleged breaches by the Controller/Joint Controller.

Does the Controller/Joint Controller process special categories of personal data (so-called sensitive data)?

The Controller/Joint Controller processes special categories of personal data in the form of biometric data (photographs) and information concerning the health of employees and candidates for work at sea.

Is there an obligation to provide your personal data?

Providing personal data is not compulsory. It is a voluntary act and takes place solely with the data subject’s consent; however, failure to provide such data will prevent the fulfilment of the purposes listed above, including the conclusion and performance of a contract.

To whom may the Controller/Joint Controller disclose the data?

Your personal data may be disclosed to entities cooperating with the Controller/ Joint Controller as part of the processing purpose, including, amongst others: shipowners, other employers, subcontractors, training, insurance and medical companies, grant-awarding bodies and organisations, as well as an external accountancy firm, legal adviser and banks.

The Controller/Joint Controller reserves the right to disclose selected information to the relevant authorities or third parties who submit a request for such information on an appropriate legal basis and in accordance with the provisions of applicable law.

Does the Controller/Joint Controller transfer personal data outside the EU?

The Controller/Joint Controller transfers personal data to countries outside the European Economic Area. All data, whether located within or outside the EU, is adequately protected against theft, destruction, overwriting, accidental disclosure, etc.

Does the Controller/Joint Controller process personal data by automated means?

The Controller/Joint Controller does not carry out automated processing of personal data (so-called profiling), nor does it monitor or collect information, other than cookies, about activity on the website.

Additional information

The Controller/Joint Controller reserves the right to update the content of this document, as well as to introduce a new document, by way of a unilateral act.

Cookies

As we take the privacy of users of the www.intermarinegroup.com, www.imenergy.pl, www.imsolutions.com.pl, www.imtraining.pl websites seriously, we have provided below our ‘cookies’ policy, which explains the principles governing the processing – i.e. the collection and use – of information about website users.

Cookies are pieces of data, specifically text files, which are stored on the end-user’s device (computer, laptop, smartphone) when they visit the website (usually in the web browser). They are not used to identify users, and no one’s identity is determined on the basis of these cookies in any way.

Cookies usually contain the name of the website they come from, the duration for which they are stored on the end device, and a unique number. On each subsequent visit, the servers can read the cookies from that end device.

Our website uses two basic types of cookies. ‘Session’ cookies, which are temporary files stored in the browser’s memory until the browser is closed. We also use ‘persistent’ cookies, which remain in the browser’s memory for a longer period. These make it easier to use frequently visited pages. How long they are stored depends on your browser settings.

Thanks to cookies:

  • the content of web pages is tailored to your preferences and individual needs, including, for example: your chosen website language, colour scheme, layout and content placement;
  • anonymous statistics are compiled on website traffic and how the website is used, which enables us to improve its structure and content,
  • your login details are remembered across all subpages of the website, so you do not have to re-enter your username and password every time,

We use the following types of cookies on our website:

  • essential – these enable you to use the services available on the website; without them, the site does not function correctly,
  • functional – these ‘remember’ the settings and interface personalisation chosen by the User, e.g. regarding the selected language or region, font size, website layout, etc.,
  • security cookies – used, for example, to detect authentication fraud on the website,
  • performance cookies – these enable the collection of information on how the website’s pages are used and help to rectify any errors on the site, etc.,
  • advertising – these deliver advertising content that is better tailored to the user’s interests, thereby preventing the same advert from being displayed repeatedly.

It is worth noting that in many cases, your web browser or other software used for browsing the internet allows cookies to be stored by default. You can manage cookies yourself at any time by changing your web browser settings. For example, you can manage cookies on a per-site basis for individual websites selected by the user. Detailed information on the options and methods for managing cookies is available in the software (web browser) settings.

The Website Administrator advises that restricting the use of cookies may affect certain features available on the Website’s web pages.

Cookies stored on a Website User’s device may also be used by advertisers and partners working with the Website operator.