Privacy Policy
Privacy Policy
The owner and operator of www.pbkm.pl is Polski Bank Komórek Macierzystych sp.
z o.o., hereinafter referred to as “PBKM”.
PBKM is responsible for the content of the service and for processing the information collected on it.
Personal data controller
The administrator of the personal data of the Users of the service, including customers of the e-store, who have concluded a contract for the collection and storage of stem cells is PBKM (Al. Jana Pawła II 29, 00-867 Warsaw).
In the case of opting for the SwissSafety service (which allows storage of the collected material in Poland and Switzerland), the controller of personal data will also be Famicord Suisse SA, based in Switzerland, c/o Studio Fiduciario Pagani SA, Corso Pestalozzi 3, 6900 Lugano.
In the case of joining a group life insurance contract offered to PBKM clients, the data controller will also be SIGNAL IDUNA Polska TU S.A. with registered office at ul.
Siedmiogrodzka 9, 01-204 Warsaw If additional studies are selected, data controllers will also be:
- Novogenia GmbH, headquartered in Austria, Saalachstrasse 92, 5020 Salzburg (for screening);
- Genomed S.A, based in Warsaw at ul.
Ponczowa 12 (for molecular genetic testing).
Personal Data Inspector
PBKM has appointed a Data Protection Inspector (Agnieszka Wiercińska-Krużewska). The Inspector can be contacted via email at: [email protected].
Information collection policy
The www.pbkm.pl website processes personal data in accordance with applicable regulations, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016.
on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and the repeal of Directive 95/46/EC (“RODO“).
Any inquiries submitted to us will be processed with confidentiality and commercial confidentiality.
Personal data and email addresses will not be used for any purpose other than to respond to an inquiry submitted or for the conclusion and performance of a contract with PBKM.
In particular, personal data will not be used to provide commercial information in the future about services other than directly related to the submitted inquiry, nor will they be transferred to third parties, unless the user agrees to receive commercial information and/or other forms of contact.
Purpose and legal basis of data processing
The processing of personal data will take place:
- For the fulfillment of contractual obligations (Article 6(1)(b) RODO)
The data is processed for the purpose of performing PBKM’s activities in the execution of contracts concluded with clients or for pre-contractual activities that are performed at the request of the client.
Data processing is necessary for qualification, preparation and storage of collected biological material.
The data is also processed for the establishment of the user’s account in the e-store and the handling of the contract concluded with PBKM through the e-store.
- For the fulfilment of legal obligations related to the settlement of the contract and the fulfilment of tax and accounting obligations (Article 6(1)(c) of the GDPR)
The data is processed in order for PBKM to fulfil legal obligations related to the settlement of the contract, resulting in particular from tax laws and the Accounting Act.
- Based on explicit consent (Article 6(1)(a) and Article 9(2)(a) of the RODO)
Entering into a contract for the qualification, preparation and storage of collected biological material involves the processing of health data, which is a special category of data.
Data on health and processed for the purpose of depositing biological material for public purposes in a public bank are processed on the basis of consent.
Based on consent, we also process personal data for email or telephone contact for the purpose of making a business offer.
Consent may be withdrawn at any time.
The withdrawal of consent does not affect the lawfulness of data processing until the consent is withdrawn.
- for the fulfillment of legal obligations (Article 6(1)(c) RODO) or the performance of tasks carried out in the public interest (Article 6(1)(e) RODO)
As a cord blood bank and a medical entity, we are subject to a number of legal obligations, i.e.
requirements arising, for example, from the Law on Patients’ Rights and the Patients’ Ombudsman and the Law on the Collection, Storage and Transplantation of Cells, Tissues and Organs.
- for the purpose of conducting marketing activities consisting in:
-
- sending commercial information about offers or content regarding the Controller’s products and services in connection with the customer’s consent to receive commercial information through a specific communication channel (Article 6(1)(a) of the GDPR)
In order to send commercial information about offers or content related to PBKM’s products and services, only the personal data of individuals who have consented to receive such commercial information through a selected communication channel are processed. Such consent may be withdrawn at any time.
- sending commercial information about offers or content regarding the Controller’s products and services in connection with the customer’s consent to receive commercial information through a specific communication channel (Article 6(1)(a) of the GDPR)
-
- directing advertising to customers who have visited the Controller’s website on other websites and social networks (remarketing) (Article 6(1)(f) of the GDPR in conjunction with the customer’s consent to the use of tracking technologies that rely on information about their use of the website)
In order to conduct remarketing activities, PBKM processes the personal data only of those users who have consented to the use of tracking technologies which use information about their activity on the website. Users may withdraw such consent at any time. The process of displaying or re-displaying personalized ads involves trusted partners of the Controller, a detailed list of which is provided under “On-site analytical tools” section.
- directing advertising to customers who have visited the Controller’s website on other websites and social networks (remarketing) (Article 6(1)(f) of the GDPR in conjunction with the customer’s consent to the use of tracking technologies that rely on information about their use of the website)
Once consent is granted, the User’s personal data collected as part of other processing activities performed by the Controller may be used for profiling. This means that the Controller analyses selected aspects concerning the user in order to assess their behaviour or predict future needs. This allows to better match content to the individual preferences and interests of the user, including presenting properly tailored advertisements and sending commercial information in accordance with their expectations.
- for other purposes arising from the legitimate interests pursued by PBKM (Article 6(1)(f) RODO)
If necessary, we process data to protect our legitimate interests.
Examples of this include:
- Handling user inquiries and contacting potential customers;
- customer satisfaction survey,
- Investigation of claims and defense against claims,
- Ensuring the safety of biological material,
- Ensuring IT security, including the functionality of the website.
Recipients of personal data
Personal data may be shared with other recipients in order to perform a contract, to comply with PBKM’s legal obligation, based on consent, or for purposes arising from the legitimate interests of the administrator referred to herein.
Recipients may be, in particular: authorized employees of a business information bureau, credit and payment institutions, a law firm providing services to PBKM, a courier company delivering a contract or download kit.
In addition, data may be transferred to entities that process personal data on behalf of PBKM and their authorized employees, with such entities processing data on the basis of a contract with PBKM and only in accordance with instructions and subject to confidentiality and adequate protection of personal data security.
If the service is selected:
- SwissSafety, data will be shared with Famicord Suisse, for the purpose of executing the concluded contract.
The information clause regarding the processing of data by Famicord Suisse can be found in the contract concluded with the company; - accession to group life insurance, data will be made available to SIGNAL IDUNA Polska TU S.A. Information clause on data processing by SIGNAL IDUNA Polska TU S.A. is included in the Declaration of accession;
- to perform the screening test, the data will be shared with Novogenia GmbH for the purpose of performing the test.
The processing information clause can be found on the company’s website; - to perform a molecular genetic test, the data will be shared with Genomed S.A. for the purpose of performing the test.
The processing information clause can be found on the company’s website.
Duration of storage of personal data
Personal data will be processed for the period necessary to achieve the purposes of processing, in particular:
- with regard to the execution of the contract concluded with PBKM – until the completion of its execution, and after that time for the period required by law or for the realization of possible claims;
- in terms of fulfilling legal obligations incumbent on PBKM in connection with the conduct of its business and performance of concluded contracts – until PBKM fulfills these obligations;
- with regard to direct marketing carried out on the basis of consent or any PBKM’s activities carried out by PBKM based on your consent – until you withdraw your consent to such processing;
- until the PBKM’s legitimate interests forming the basis for such processing are fulfilled or until you object to such processing, unless there are legitimate grounds for further processing.
Rights of persons whose data is processed by PBKM
A person whose data is processed by PBKM has the right to:
- to request access to their personal data and to rectify, limit the processing of their personal data, or to have it deleted,
- to the extent that the processing of personal data is based on consent, to withdraw at any time the consent previously given for the processing of personal data,
- object at any time to the processing of personal data on grounds related to your particular situation, where the PBKM processes the data for the purposes of legitimate interests (Article 21(1) RODO),
- object to the processing of personal data for marketing purposes if it is based on the legitimate interest of PBKM;
- request the transfer of personal data processed for the purpose of entering into and performing a contract or processed on the basis of consent.
A transfer consists of receiving personal data from the PBKM, in a structured, commonly used machine-readable format, and sending such data to another data controller.
The right to data portability does not apply to data that constitute company secrets, - lodge a complaint with the President of the Office for Personal Data Protection, in case the processing of personal data is deemed to violate the law.
Necessity of transfer of personal data
Provision of data is voluntary, but may be necessary for the conclusion and performance of a contract or for the deposit of biological material for public purposes in a public bank.
Source of personal data
First of all, the personal data collected by PBKM comes directly from customers.
Data processed for marketing purposes may also be obtained through marketing campaigns conducted on behalf of PBKM by third parties.
Transfer of data to a third country
If you choose the SwissSafety service, your data will be transferred to Famicord Suisse, a company based in Switzerland.
Switzerland has been recognized by the European Commission as providing an adequate level of protection for personal data.
About cookies
As part of the www.pbkm.pl website, the Administrator uses information contained in cookie files. Cookies constitute digital data, including, but not limited to small text files that are stored on the user’s terminal device (e.g. laptop, tablet, smartphone) when they visit the www.pbkm.pl website. They can be used by the Controller – in such a case they are installed directly by the www.pbkm.pl website, as well as by the Controller’s partners (e.g. Google) – in this case, the cookies originate from a different website than the one visited by the user.
Cookies store information that is created in cooperation with the user’s terminal device. The cookies used on the www.pbkm.pl website are primarily used to ensure the proper functioning of the site, including maintaining a login session. If the user grants separate consents to the installation of other cookies, they will also be used for the purpose of adjusting the website, analytical and marketing settings. Detailed information on the cookies used is presented by the Controller below. The section “Blocking or limiting cookies by the user” provides information on the cookie settings management options.
As part of the www.pbkm.pl website, the Controller uses the following categories of cookies: essential, preferences, statistics and marketing.
- The Controller uses essential cookies in order to provide the user with access to the content and functions available on the www.pbkm.pl website, including those necessary for the proper functioning of the website. The legal basis for the processing of the user’s personal data consists in this being necessary for the performance of a contract regarding the use of www.pbkm.pl (Article 6(1)(b) of the GDPR). Essential cookies can be installed via the website by the Controller.
- Preference cookies are used by the Controller to save settings that adjust the www.pbkm.pl website to the user’s preferences (e.g. language selection) and personalize the functions used by the user. In order to use them, the user’s prior consent is required. The user can consent to the use of preference cookies via the cookie banner available at www.pbkm.pl; they can also withdraw their consent at any time in the same way. Preference cookies can be used both by the Controller and by their trusted partners. The legal basis for the processing of the user’s personal data is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR), consisting in improving the quality of the service provided, which consists in providing access to the www.pbkm.pl website, based on the user’s consent.
- Statistics cookies are used by the Controller to understand how the user uses the website, including where the traffic comes from and what content is visited most often. Using these files makes it possible to carry out statistical analyses, e.g. regarding the number of visits to the website, which allows for its improvement and the introduction of new functions. Using these files requires prior consent of the user. The user can consent to the use of statistics cookies via the cookie banner available at www.pbkm.pl; they can also withdraw their consent at any time in the same way. Statistics cookies can be used by both the Controller and their trusted partners. The legal basis for the processing of users’ personal data is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR), consisting in improving the www.pbkm.pl website on the basis of analyses of users’ activity in connection with their consent.
- Marketing cookies are used to display advertisements tailored to the user’s preferences. The purpose of collecting user information using these cookies is to personalize advertisements, measure their effectiveness and conduct marketing campaigns, including on external websites. The legal basis for the processing of personal data is the legitimate interest of the Controller (Article 6(1)(f) of the GDPR), consisting in providing information promoting the Controller’s services and creating content dedicated to the user, based on the consent expressed by the user.
Detailed information on the individual cookies used within a given category (including the name, purpose of their use and validity period) is available to the user by clicking on the “Cookie Settings” button located in the footer of the www.pbkm.pl website. After clicking the button, the user will see a cookie banner displayed in the www.pbkm.pl website window, and then they should select and expand the category of cookies they are interested in.
In order to use preference, statistics and marketing cookies, the user must grant separate consents. User’s consent is not required only for cookies that are essential to provision of the service involving access to the www.pbkm.pl website. Without using these cookies, the Controller cannot provide the service consisting in granting access to the website. The User may express separate consents to the use of preference, statistics and marketing cookies using the cookie management platform (i.e. the “Cookie Settings” button in the footer of the www.pbkm.pl website or the cookie banner displayed after accessing the website).
User blocking or restricting cookies
The user can manage the consents granted, including their withdrawal, at any time. To withdraw or grant consent, the user should click the “Cookie Settings” button in the footer of the www.pbkm.pl website, and then move the slider next to the selected category of cookies and click “Accept” or “Reject”.
Moreover, the user may delete cookies at any time using their browser settings. Instructions on how to do this in different browsers can be found below:
The user can also check their cookie settings at any time, e.g. via http://optout.aboutads.info.
Third-party cookies
Third parties (third-party providers) may display advertisements published by PBKM on websites that provide their advertising space.
These providers may use cookies or use web beacon images to collect information on websites and then to display ads based on your previous visits to www.pbkm.pl or other PBKM-affiliated websites, as well as other websites.
PBKM may run advertising campaigns based on the user’s previous visits to www.pbkm.pl, as well as statistical information about the user’s interests determined from previously visited websites in order to present the user with its offer or to attract the user to visit www.pbkm.pl again.
These advertisements will not contain the user’s personal information, nor will they suggest that the user has performed a specific action on www.pbkm.pl.
Detailed information about the individual tools used by PBKM and their trusted partners can be found in the “On-site analytical tools” section below.
On-site analytical tools
PBKM and their trusted partners use a variety of tools and solutions for analytical and advertising purposes. Essential information on these tools are presented below. Please refer to your specific partner’s privacy policy for details in this regard.
- Google Analytics
Google Analytics cookies are used by Google to analyse how the website is used by the user, create statistics and reports on the functioning of the website. Google does not use the collected data to identify the user nor does it combine this information to enable identification. Detailed information about the scope and principles of data collection as part of this service is available here: https://policies.google.com/technologies/ads?hl=pl.
- Teracent
Teracent is a dynamic advertisement display tool that uses cookies to tailor advertising content to users. To opt-out of Teracent cookies, the user can use the opt-out options available on sites such as the Network Advertising Initiative or use the opt-out options described under this Policy.
- DoubleClick
DoubleClick is a tool for assessing the effectiveness of advertising campaigns conducted by the Controller (including Google AdWords campaigns) and for analysing their results. Details of data collection and information on how this service works can be found here: https://support.google.com/campaignmanager/answer/2839090.
- HotJar
HotJar is a tool that allows the Controller to analyse user behaviour on the website, e.g. by conducting surveys, satisfaction surveys and collecting anonymous data concerning individual website element click patterns. This tool does not allow user identification. Detailed information about the data collected by HotJar and instructions on how to disable user monitoring can be found here: https://www.hotjar.com/privacy/ or the user may use the cookies opt-out options described in this Policy.
- Sales Manago
Sales Manago solutions allow to store customer data in one place and use it to select target groups and personalize campaigns using personal, transactional and behavioural data. Sales Manago uses Machine Learning and AI to create customer profiles. More information can be found here: https://www.salesmanago.pl/info/rodo.htm.
- Meta Pixels
Meta Pixel is a tool that allows to assess the effectiveness of advertising campaigns conducted by the Controller on the Facebook platform. It enables advanced data analytics, which supports optimization of the Controller’s activities, also using other functions offered by Facebook.
In the context of the processing of personal data using this tool, Meta Platforms Ireland Limited with its registered office in Ireland and the Controller act as joint controllers. Personal data is processed jointly by them for the purpose of conducting analyses and measurements within the Website. The Controller and Meta (Facebook) have agreed on the rules of cooperation in this regard, which are available here: https://pl-pl.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0https%3A%2F%2Fpl%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pl.facebook.com%2Fhelp%2F443357099140264%3Fhelpref%3Dabout_content and here: https://www.facebook.com/legal/controller_addendum.