Terms and documents
Information notice for contractors
Pursuant to Articles 13(1) and (2) and Article 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as "GDPR"), we hereby inform you that:
- The Controller of your personal data is OMNIRES Spółka z ograniczoną odpowiedzialnością, with its registered office in Warsaw at Solec 18, 00-410 Warszawa, entered in the Register of Entrepreneurs under number KRS: 0000088578 and tax identification number NIP: 5222626866.
- You may contact the Controller by phone at (+48) 22 351 06 20 or electronically via e-mail at [email protected].[email protected]
- The Controller has appointed a Data Protection Officer, who may be contacted electronically at [email protected].[email protected]
- Your personal data will be processed for the purpose of concluding and performing the contract entered into between the Controller and the entity you represent, or the entity that designated you as a contact person in connection with the conclusion or performance of the contract, pursuant to Article 6(1)(f) of the GDPR.
- Your personal data are processed for the purpose of issuing, receiving, and archiving structured invoices within the National e-Invoicing System (KSeF), and for the purpose of fulfilling obligations arising from tax and accounting regulations, pursuant to Article 6(1)(... c) GDPR, i.e., the Act of 11 March 2004 on the Tax on Goods and Services (VAT) and implementing regulations; the Act of 29 October 2021 amending the Act on the Tax on Goods and Services and certain other acts (Journal of Laws of 2021, item 2076); the Regulation of the Minister of Finance of 27 December 2021 on the use of the National e-Invoicing System (KSeF) (Journal of Laws of 2021, item 2481), as amended (Journal of Laws of 2022, item 2667 and Journal of Laws of 2023, item 1760).
- In the event that any claims arise, your personal data will also be processed for the purpose of defending against or pursuing such claims, as well as for demonstrating compliance with the legal obligations incumbent upon the Controller—based on the legitimate interest pursued by the Controller (Article 6(1)(f) of the GDPR).
- The recipients of your personal data will be persons authorized by the Controller to process personal data in the course of performing their professional duties, as well as entities to which the Controller entrusts tasks involving the necessity of data processing. In particular, these include entities providing us with accounting services, IT system administration, and providers of electronic tools used for data storage. Data recipients may also include state authorities, in accordance with applicable law—such as the Ministry of Finance and the National Revenue Administration—in connection with the operation of the KSeF.
- Data will be stored for the duration of the contract and subsequently for the period required by law (e.g., tax or accounting regulations)—specifically, for the duration of invoice archiving in the KSeF system or until the statute of limitations for claims expires.
- You have the right to request access to your personal data from the controller, as well as the right to rectification, erasure, or restriction of processing, the right to object to processing, the right to data portability, and the right to withdraw your consent at any time.
- If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the President of the Personal Data Protection Office.
- Providing personal data is voluntary but necessary for the conclusion and performance of the contract. Failure to provide such data will make it impossible to perform the contract.
- The processing of your personal data will not be subject to automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the GDPR.
- The controller does not transfer personal data outside the European Economic Area (EEA). However, should such a transfer occur, the controller will comply with the requirements set out in the GDPR, particularly those specified in Articles 44–47.