PRIVACY AND COOKIES POLICY
Effective Date: September 24, 2026
Last Updated: September 24, 2026
This Privacy Policy sets out the rules for the processing of personal data collected via the informational website of the ERGOCONTROL platform (hereinafter: the “Service”). This document has been prepared in accordance with the requirements of the General Data Protection Regulation (GDPR).
§ 1. Data Controller
The Data Controller for personal data processed through the Service is ERGO ENERGIA SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office at ul. Podmiejska 95, 44-207 Rybnik, Poland, registered in the Register of Entrepreneurs under KRS: 0000869858, VAT ID (NIP): 6423226803, REGON: 387526156.
Inquiries regarding personal data processing can be addressed directly to our registered office.
§ 2. Separation of the Informational Service and the SaaS Application
The Service serves an informational role (showcase/landing page) and enables users to establish contact to request demonstration access. “Log In” buttons located within the Service redirect users to external web application instances (including the ergocontrol.ergoenergia.pl subdomain or dedicated client instances).
Important: This Privacy Policy governs solely the collection of data on the public marketing website. The processing of data entrusted directly to the ERGOCONTROL SaaS platform (within the scope of services provided after logging in) is regulated by separate Data Processing Agreements (DPA) and the Terms of Service of the application itself.
§ 3. Scope, Purposes, and Legal Grounds for Processing
The Controller processes data under the following circumstances and for the following purposes:
1. Contact Forms and Demo Requests
When a User submits an inquiry or schedules a demonstration (Demo), we process data such as name, surname, company name, corporate email address, and phone number. For demonstrations based on real customer scenarios, the Controller may request anonymized data samples to configure the test sandbox.
Legal basis: Measures taken at the request of the data subject prior to entering into a contract (Art. 6(1)(b) GDPR) and the legitimate interest of the Controller in handling B2B inquiries (Art. 6(1)(f) GDPR).
2. IT Infrastructure and Security
The Service utilizes security and performance filters (including Cloudflare and anti-spam mechanisms) that evaluate IP addresses, authentication tokens (if applicable), and browser request headers to protect against automated abuse, spam, and cyberattacks.
Legal basis: Legitimate interest of the Controller in safeguarding the integrity of network and server infrastructure (Art. 6(1)(f) GDPR).
3. Web Analytics
The Controller utilizes Google Analytics 4 for traffic monitoring, user journey statistics, and conversion analytics. This data is processed only after obtaining voluntary consent through the cookie consent management banner.
Legal basis: User consent (Art. 6(1)(a) GDPR).
4. Marketing and Conversion Tracking (Meta Pixel / Meta Ads)
The Service implements the Meta Pixel tracking tool (provided by Meta Platforms Ireland Ltd.). It enables performance measurement of marketing campaigns, audience behavior analysis, and the delivery of targeted advertising across Facebook and Instagram (e.g., retargeting, conversion tracking for PageView or form submissions). This data is processed strictly on the basis of prior explicit marketing consent.
Legal basis: User consent (Art. 6(1)(a) GDPR).
§ 4. Data Recipients and Technical Infrastructure
To ensure high availability and reliability of our SaaS platform and informational website, the Controller engages trusted third-party service providers (processors):
- Hosting infrastructure: OVH.
- Mail routing infrastructure (SMTP): nazwa.pl.
- DNS management and CDN security: Cloudflare, Inc.
- Spam protection: Akismet (Automattic Inc.).
- Analytics tooling (subject to consent): Google Ireland Limited.
- Advertising analytics & retargeting (subject to consent): Meta Platforms Ireland Ltd.
Data is primarily stored and processed within the European Economic Area (EEA). Where global providers utilize US-based infrastructure or affiliates (e.g., Google, Meta Platforms, Cloudflare), transfers are executed pursuant to the European Commission’s Adequacy Decision (EU-US Data Privacy Framework) or based on Standard Contractual Clauses (SCC).
§ 5. Data Retention Period
Information collected via demo inquiries and contact forms is retained for the duration of ongoing commercial discussions and B2B negotiations, and thereafter archived for the period necessary to establish, exercise, or defend against legal claims under applicable commercial limitation statutes. Data collected through cookies is stored for the timeframe defined in individual cookie parameters or until consent is revoked by the User.
§ 6. User Rights
Every data subject has the right to:
- Access, rectify, erase, or restrict the processing of their personal data,
- Object to processing (including profiling),
- Data portability,
- Withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal,
- Lodge a complaint with a supervisory authority (in Poland: the President of the Personal Data Protection Office – PUODO).
§ 7. Amendments to This Policy
This document may be amended in line with the ongoing development of the ERGOCONTROL system architecture and the deployment of new technological tools. Any updates become effective upon their publication within the Service.