The presented privacy policy specifies how User data necessary for the provision of electronic services via the website antek.exploreit.io and the "Antek" mobile application (hereinafter: "Antek" Platform) are collected, processed and stored.
1. Data Administrator
- The Administrator of data collected by the "Antek" Platform is ExploreIT sp z o.o., with its registered office in Warsaw (02 -593) at ul. Rostafińskich 4, KRS: 0000551446, NIP: 5213693366, REGON: 361234882 (hereinafter: Administrator).
- Contact with the Administrator is possible via email at info@exploreit.io or via the contact form on the website antek.exploreit.io.
2. Type of data processed
- Data entered or generated during registration and needed for the proper operation of the Application, such as email address and internal unique user identifier. In the case of user registration via Google, Facebook or Apple ID, the Administrator stores the email address associated with the social networking site account.
- Data about the child entered by the User when creating the child's profile, such as date of birth, gender, week of pregnancy in which delivery occurred, birth length, birth weight, Apgar Scale points and the height of both parents.
- Data entered by the User when taking child measurements, such as height, weight and date of measurement.
- HTTP requests made by the user. This data may include information about the URL, request body, system time when the platform received the request, and errors that occurred during the request's processing. All sensitive data, such as user passwords, is automatically removed before further processing.
- The "Antek" application allows the User to provide the child's name and photo. However, this data is saved only on the User's phone and is not processed by the Administrator.
3. Purpose of data collection
- The processed data presented in point 2.1. are required for primary verification of the User's identity and enabling the User to use the account in the "Antek" Application. Providing this data is voluntary, but its absence prevents the User from logging into the Application.
- The processed data described in point 2.2. and point 2.3. enable the use of algorithms that allow the User to monitor the correct development of the child in the "Antek" Application. Providing this data is voluntary, but its absence may result in partial or complete inability of the User to view information about the child's development.
- If the user agrees, the email address provided may be used for marketing purposes. This option is disabled by default, but the User may opt out of it at any time using the option in the "Profile" tab of the "Antek" mobile application.
- HTTP request logs may be processed for traffic analysis and error information, which will help improve the quality of services the Administrator provides.
- The data entered by the User may be used to establish and pursue claims or defend against them based on art. 6 sec. 1 letter f) of the GDPR.
4. Data processing period
- Suppose the basis for data processing is the performance of a contract, rights or obligations. In that case, the User's data are processed until the statute of limitations for claims in this respect expires.
- Anonymized measurement data and child data specified in points 2.2. and 2.3. Maybe it will be processed by the Administrator and the Children's Memorial Health Institute (hereinafter: IPCZD) indefinitely, i.e., as long as they have scientific value. Maintaining the anonymity of data guarantees that they cannot be linked to specific individuals, which protects users' privacy.
- User data may be processed for marketing purposes until the User withdraws consent. The User has the right to withdraw their consent to data processing for marketing purposes at any time, which will not affect the lawfulness of the processing carried out before its withdrawal.
5. Sharing data
- User data is shared with entities cooperating with the Administrator, such as subcontractors, hosting companies, law firms and others necessary for the provision of services. All these entities are obliged to ensure an adequate level of personal data protection and process it per applicable law.
- The measurement data specified in points 2.2 and 2.3 will be anonymised and transferred to the IPCZD for scientific purposes. Anonymisation ensures that data cannot be linked to specific individuals, which protects Users' privacy.
- User data will not be transferred outside the European Economic Area (EEA). In the event of a change, the User will be informed immediately, and the Administrator will ensure that the recipient processes the personal data appropriately and does not violate the rights relating to their processing.
6. User Rights
- The User of the Service has the right to access the content of their data, rectify it, delete it, limit its processing, transfer it, object to the processing, and withdraw consent at any time (which does not affect the lawfulness of processing based on consent before its withdrawal).
- The User has the option to delete the account using the "Delete account" option in the "Antek" application profile, which will remove the link to the User's email address, anonymize the measurement data collected on the platform and immediately stop processing the User's email address by the Administrator.
- A notification about the User's exercise of the right resulting from the above rights should be sent to info@exploreit.io.
- The User has the right to file a complaint with the President of the Personal Data Protection Office if they consider that the processing violates their rights and freedoms in accordance with GDPR.
7. Cookies
- Information may be collected on the website through cookies—session cookies, persistent cookies, and third-party cookies.
- Cookies used on the website may be utilized for:
- Storing user settings, such as preferences regarding the cookies used by the website,
- Conducting statistics—gathering information about how the user interacts with the website and which parts of the website are the most popular.
- In the case of third-party cookies, the Administrator takes all possible measures to verify and select service partners concerning user security. The Administrator selects well-known, large partners with global social trust. However, the Administrator does not have complete control over the content of cookies from external partners. To the extent permitted by law, the administrator is not responsible for the security of cookies, their content, or compliance with licensing for their use by scripts from external services.
- Users of the website can change their cookie preferences at any time. Clicking the button with the cookie icon in the lower right corner of the screen will open a popup, allowing for changes to the settings.
8. Security
- The Administrator stores all information received about Users on appropriately secured servers. The necessary technical and organisational measures have been implemented to protect User data against accidental or unlawful loss, unauthorized access, disclosure, alteration, damage or destruction. All sensitive user data sent outside the Administrator's internal network is encrypted using SSL technology.
- Due to the specificity of information technology, sharing information via the Internet is never completely secure, and data shared by the User may reach an unauthorized third party. The Application's vulnerability to specific threats may be revealed in the future. For this reason, it is recommended that the User update the Application. The Administrator may also issue publicly available recommendations regarding security principles related to using the Application.
9. Final Provisions
- The Administrator reserves the right to make changes to this Privacy Policy; however, the changes introduced will not limit the rights of Users. Any modifications are intended to improve the quality of services provided and adapt the policy to applicable legal regulations.
- Information on changes to the Privacy Policy will be immediately made available to Users via the "Antek" application. Users will be informed of the changes introduced and asked to accept them. In the event of failure to accept the changes, the User will not be able to continue using the Application.
- The services offered within the "Antek" application are intended exclusively for persons over 18. Minors' use of the Application is prohibited. In the event of reporting a violation of this requirement, the Administrator undertakes to delete all data associated with such a user immediately.
- In matters not regulated in this Privacy Policy, the Personal Data Protection Regulation (GDPR) and the relevant provisions of Polish law shall apply. Any disputes will be resolved by applicable legal regulations.