PRIVACY POLICY
JustFilm.it
USER
In this Policy you will find the following information
DEFINITIONS .................................................................................................................................. 2
DATA PROCESSING IN CONNECTION WITH THE USE OF THE PORTAL AND APPLICATIONS ............... 2
PURPOSES AND LEGAL BASIS OF DATA PROCESSING IN THE PORTAL AND APPLICATION ................ 2
MARKETING ................................................................................................................................... 4
SOCIAL NETWORKS ........................................................................................................................ 6
COOKIES AND SIMILAR TECHNOLOGY ............................................................................................. 6
PERIOD OF PERSONAL DATA PROCESSING ...................................................................................... 8
YOUR ENTITLEMENTS ..................................................................................................................... 8
DATA RECIPIENTS ........................................................................................................................... 9
TRANSFER OF DATA OUTSIDE THE EOG .......................................................................................... 9
SECURITY OF PERSONAL DATA ....................................................................................................... 9
CONTACT DETAILS .......................................................................................................................... 9
PRIVACY POLICY CHANGES ............................................................................................................ 10
DEFINITIONS
1. Administrator (We) - JustFilm.it sp. z o.o. with its registered seat in Warsaw at 12 PuĊ‚awska
Street, premises 3, 2nd floor, 02-566 Warsaw, whose registration files are kept by the District
Court for the Capital City of Warsaw in Warsaw, XIII Economic Department of the National Court
Register under the KRS number: 0001032165, having NIP number: 5214016076, with the share
capital of PLN 5,000.00, having, e-mail address: [email protected] and tel number: 452 113 114.
2. Personal data - all information about a natural person identified or identifiable by one or more
specific factors that determine physical, physiological, genetic, mental, economic, cultural or
social identity, including device IP, location data, Internet ID and information collected through
cookies and other similar technology.
3. Policy - this Privacy Policy.
4. RODO - Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016
on the protection of individuals with regard to the processing of personal data and on the free
movement of such data and repealing Directive 95/46/EC.
5. Portal - the web portal owned by the Administrator and available at https://justfilm.it.
6. Application - software operating in the SaaS (Software as a Service) model, based on cloud
computing, installed on and managed by the Administrator's servers, made available through a
web browser at https://app.justfilm.it.
7. User (You) - any natural person who visits the Portal or Application or uses one or more of the
services or functionalities described in the Policy.
8. Regulations - regulations of the Portal and Application.
PROCESSING OF DATA IN CONNECTION WITH THE USE OF PORTAL OR APPLICATION
In connection with your use of the Portal or the Application, we collect your data to the extent
necessary to provide the particular services offered, as well as information about your activity on the
Portal or the Application. The detailed rules and purposes of the processing of personal data collected
during your use of the Portal or the Application are described below.
PURPOSES AND LEGAL BASIS OF DATA PROCESSING IN PORTAL AND APPLICATION
USE OF A PORTAL OR APPLICATION
1. We process personal data of all persons using the Portal or the Application (including IP address
or other identifiers and information collected through cookies or other similar technologies), and
who are not registered Users (i.e., persons without an account) for the following purposes:
1.1. for the purpose of providing services electronically in terms of providing Users with access to
content collected on the Portal or Application - in which case the legal basis for processing is
the necessity of processing to perform the agreement (Article 6(1)(b) RODO);
1.2. for analytical and statistical purposes, in which case the legal basis for the processing is our
legitimate interest (Article 6(1)(f) RODO) consisting in conducting analyses of Users' activities,
as well as their preferences in order to improve the functionalities used and services
provided;
1.3. for the purpose of possible establishment, investigation or defense of claims - the legal basis
for processing is our legitimate interest (Article 6(1)(f) RODO) in protecting our rights;
1.4. for marketing purposes (ours and those of our partners), in particular related to the
presentation of behavioral advertising - the principles of processing personal data for
marketing purposes are described in the "MARKETING" section.
2. Your Activity on the Portal or Application, including your personal information, is recorded in
system logs. The information collected in the logs is processed primarily for purposes related to
the provision of services. We also process them for technical, administrative purposes, for the
purposes of ensuring the security of the IT system and the management of this system, as well as
for analytical and statistical purposes - in this regard, the legal basis for processing is our legitimate
interest (Article 6(1)(f) RODO).
3. We process your data provided in the Application in the Azure cloud computing provided by
Microsoft.
4. The portal is hosted by CloudFlare.
REGISTRATION
5. During registration, you will be asked to provide the data necessary to create and operate your
account. In order to facilitate service, you can provide additional data, thereby giving your consent
to their processing. Such data can be deleted at any time. Provision of data marked as mandatory
is required to create and operate your account, and failure to provide such data will result in our
inability to create your account. Provision of other data is voluntary.
6. Your personal data is processed:
4.1. for the purpose of providing services related to the maintenance and operation of the
account - the legal basis for processing is the necessity of processing for the performance of
the contract (Article 6(1)(b) RODO), and with regard to data provided optionally - the legal
basis for processing is consent (Article 6(1)(a) RODO);
4.2. for analytical and statistical purposes - the legal basis for the processing is our legitimate
interest (Article 6(1)(f) RODO) consisting in conducting analyses of Users' activity on the
Portal and Application, as well as the way they use their account, and their preferences in
order to improve the functionalities used;
4.3. for the purpose of possible establishment, investigation or defense of claims - the legal basis
for processing is our legitimate interest (Article 6(1)(f) RODO) in protecting our rights;
4.4. for marketing purposes (ours and those of our partners) - the principles of processing
personal data for marketing purposes are described in the "MARKETING" section.
5. In the event that the Application allows you to log in via other services (such as, for example,
Facebook, Google, Instagram, Twitter, Apple), we will only retrieve from your account within the
respective service the data necessary to register and operate your account. By changing the plug-
in's settings yourself, you can easily expand the scope of the downloaded data to include such
data as may be useful for using your account functionality.
6. We use the Auth0 authorization system for logging in, registering and storing User account data.
CHAT
7. If you contact us via chat, we will process your personal data for the following purposes:
7.1. for the purpose of processing your request - the legal basis for the processing is the necessity
for the performance of a contract to which the data subject is a party, or to take action at the
request of the data subject prior to entering into a contract (Article 6(1)(b) RORO);
7.2. for analytical and statistical purposes - the legal basis for the processing is our legitimate
interest (Article 6(1)(f) RODO) consisting in conducting analyses of Users' activity on the
Portal and the Application, as well as the way they use them, and their preferences in order
to improve the functionalities used;
7.3. for the purpose of possible establishment, investigation or defense of claims - the legal basis
for the processing is our legitimate interest (Article 6(1)(f) RODO) in protecting our rights.
8. We use an external chat room provided by Crisp IM.
USE OF PAID SERVICES
9. If you place an order with us (to purchase a service), we will process your personal data for the
following purposes:
9.1. for the purpose of fulfilling a submitted order - the legal basis for processing is the necessity
of processing for the performance of the contract (Article 6(1)(b) RODO); for data provided
optionally, the legal basis for processing is consent (Article 6(1)(a) RODO);
9.2. in order to comply with statutory obligations incumbent on us, and arising in particular from
tax and accounting regulations - the legal basis for processing is a legal obligation (Article
6(1)(c) RODO);
9.3. for analytical and statistical purposes - the legal basis for the processing is our legitimate
interest (Article 6(1)(f) of the RODO) consisting in conducting analyses of your activity on the
Portal or Application, as well as your shopping preferences in order to improve the
functionalities used;
9.4. for the purpose of possible establishment, investigation or defense of claims - the legal basis
for the processing is our legitimate interest (Article 6(1)(f) RODO) in protecting our rights.
10. We use EasyCart payment system, which allows you to make payments via Stripe, Przelewy24 and
BLIK (the payment method is selected by the User).
MARKETING
11. We process your personal data to carry out marketing activities, which may consist of:
11.1. displaying marketing content that is not tailored to your preferences (contextual
advertising);
11.2. displaying marketing content that matches your interests (behavioral advertising);
11.3. targeting e-mail notifications of interesting offers or content, which in some cases contain
commercial information (newsletter service);
11.4. Directing e-mail notifications about offers or promotions of our own services or on behalf of
third parties, which in some cases contain commercial information, in connection with an
interrupted shopping process (abandoned shopping cart);
11.5. carrying out other activities related to direct marketing of goods and services (sending
commercial information by electronic means and telemarketing activities).
12. In order to carry out marketing activities, in some cases we use profiling (if you agree). This means
that through automated data processing, we evaluate selected factors about individuals in order
to analyze their behavior or create a forecast for the future.
13. The legal basis for processing your personal data for marketing purposes is always your consent
(Article 6(1)(a) of the DPA), which you can withdraw at any time.
CONTEXTUAL ADVERTISING
14. We process your personal data for marketing purposes in connection with targeting you with
contextual advertising, i.e. advertising that is not tailored to your preferences. The processing of
your personal data is then done in connection with the fulfillment of our legitimate interest
(Article 6(1)(f) of the DPA).
BEHAVIORAL ADVERTISING
15. We and our trusted partners process your personal data, including personal data collected
through cookies and other similar technologies, for marketing purposes in connection with
targeting you with behavioral advertising, i.e. advertising that is tailored to your preferences. The
processing of personal data then includes profiling. The use of personal data collected through
this technology for marketing purposes, in particular for the promotion of services and goods of
third parties, requires your consent, which you may withdraw at any time.
NEWSLETTER
16. We provide the newsletter service under the terms of the Terms and Conditions only if you
provide us with your e-mail address for this purpose. Provision of data is required to provide the
newsletter service, and failure to do so will result in the inability to send the newsletter.
17. We use an external entity, Brevo (formerly Sendinblue), to handle our mailing list.
18. Personal data collected for the newsletter are processed:
18.1. for the purpose of providing the newsletter mailing service - the legal basis for processing is
the necessity of processing for the performance of the contract (Article 6(1)(b) of the DPA);
18.2. in the case of targeting you with marketing content within the newsletter - the legal basis
for processing, including profiling, is our legitimate interest (Article 6(1)(f) RODO) in
connection with your consent to receive the newsletter;
18.3. for analytical and statistical purposes - the legal basis of the processing is our legitimate
interest (Article 6(1)(f) RODO) consisting in conducting analyses of your activity on the Portal
or Application in order to improve the functionalities used;
18.4. for the purpose of possible establishment, investigation or defense of claims - the legal basis
for processing is our legitimate interest (Article 6(1)(f) RODO).
APPOINTMENT CHECK FORM
19. We provide the service appointment check form under the terms of the Terms and Conditions
only if you provide us with your email address, your name and the date of your event for this
purpose. Provision of data is required in order to provide the service of the date check form, and
failure to do so will result in the inability to check the date.
20. We use third-party service providers to handle the appointment check form: Airtable and Make.
21. Personal data collected for the purpose of the appointment check form are processed:
21.1. in order to provide with the service of checking the date of - the legal basis for processing is
the necessity of processing for the performance of the contract (Article 6(1)(b) of the DPA);
21.2. in the case of directing marketing content to you as part of the appointment checking service
- the legal basis for processing, including profiling, is our legitimate interest (Article 6(1)(f) of
the DPA) in connection with your consent to receive marketing content related to your
appointment booking;
21.3. for analytical and statistical purposes - the legal basis of the processing is our legitimate
interest (Article 6(1)(f) RODO) consisting in conducting analyses of your activity on the Portal
or Application in order to improve the functionalities used;
21.4. for the purpose of possible establishment, investigation or defense of claims - the legal basis
for processing is our legitimate interest (Article 6(1)(f) RODO).
DIRECT MARKETING
22. Your Personal Data may also be used by us so that we can target you with marketing content
through various channels, i.e. via email, via MMS / SMS or by phone. We only undertake such
activities if you have given your consent, which you may withdraw at any time.
SOCIAL NETWORKS
We process your personal data when you visit our profiles maintained on social media (Facebook,
YouTube, Instagram, Twitter, TikTok). This data is processed solely in connection with the operation
of the profile, including to keep you informed about our activities and to promote various events,
services and products. The legal basis for processing personal data for this purpose is our legitimate
interest (Article 6(1)(f) RODO) in promoting our own brand.
COOKIES AND SIMILAR TECHNOLOGY
Cookies are small text files installed on your device when you browse the Portal or Application. Cookies
collect information that makes it easier for you to use the website - for example, by remembering your
visits and the actions you perform.
We may use the following types of cookies within the Portal and Application:
"SERVICE" COOKIES
23. We use so-called service cookies primarily to provide you with electronically delivered services
and to improve the quality of these services. In this regard, we and other entities providing
analytical and statistical services to us use cookies to store information or access information
already stored on your telecommunications end device (computer, phone, tablet, etc.). Cookies
used for this purpose include:
23.1. cookies with data you input (session ID) for the duration of the session (user input cookies);
23.2. authentication cookies used for services that require authentication for the duration of the
session (authentication cookies);
23.3. Security cookies, such as those used to detect authentication abuse (user centric security
cookies);
23.4. multimedia player session cookies (e.g. flash player cookies), for the duration of the session
(multimedia player session cookies);
23.5. Persistent cookies used to personalize the user interface for the duration of the session or
slightly longer (user interface customization cookies),
23.6. cookies used to monitor website traffic, i.e. data analytics, including Google Analytics,
Meta Pixel, HotJar and Microsoft Clarity cookies (these are cookies used to analyze how
you use the Portal or Application, to create statistics and reports on their operation). These
entities do not use the collected data to identify you, nor do they combine this information
to enable identification.
"MARKETING" COOKIES
24. We and our trusted partners also use cookies for marketing purposes, including in connection with
targeting you with behavioral advertising. For this purpose, we and our trusted partners store
information or access information already stored on your telecommunications end device
(computer, phone, tablet, etc.). The use of cookies and personal data collected through them for
marketing purposes, in particular for the promotion of services and goods of third parties, requires
your consent, which can be withdrawn at any time.
COOKIE MANAGEMENT
25. If you do not want to receive cookies, you can change your browser settings. We stipulate that
disabling cookies necessary for authentication processes, security, maintenance of user
preferences may hinder, and in extreme cases may make it impossible to use the Portal or the
Application.
26. To manage your cookie settings, select the web browser you are using from the list below and
follow the instructions:
26.1. Edge
26.2. Internet Explorer
26.3. Chrome
26.4. Safari
26.5. Firefox
26.6. Opera
Mobile devices:
26.7. Android
26.8. Safari (iOS)
26.9. Windows Phone
ESSENTIAL MARKETING TECHNIQUES
27. We use statistical analysis of website traffic, through Google Analytics, Meta Pixel, HotJar and
Microsoft Clarity. We do not transmit personal data to the operator of these services, only
anonymized information. The service is based on the use of cookies on your end user device.
28. We use remarketing techniques that allow us to tailor advertising messages to your behavior on
the Portal and Application, which may give the illusion that your personal information is being
used for tracking, but in practice we do not pass any of your personal information to advertising
operators. A technological prerequisite for such activities is that cookies are enabled.
29. We use a solution to study the behavior of Users by creating heat maps and recording behavior
on the Portal and Application, This information is anonymized before it is sent to the service
operator so that he does not know which individual it concerns. In particular, typed passwords
and other personal information are not recorded.
30. We use a solution that automates the operation of the Portal or Application with respect to Users,
e.g., that can send you an email to when you visit a particular subpage.
PERIOD OF PROCESSING OF PERSONAL DATA
31. The period for which we process your data depends on the type of service provided and the
purpose of the processing. As a general rule, your data is processed for the duration of the service
or order processing, until you withdraw your consent or make an effective objection to data
processing (in cases where the legal basis for data processing is our legitimate interest).
32. The period of data processing may be extended if the processing is necessary for the
establishment, investigation or defense of possible claims, and thereafter only if and to the extent
required by law.
33. After the end of the processing period, your data is irreversibly deleted or anonymized.
YOUR POWERS
34. As we process your personal data, you have the following rights:
34.1. The right to information about the processing of personal data - on this basis, upon your
request, we will provide you with information about the processing of your data, including,
in particular, the purposes and legal grounds for processing, the scope of the data held, the
entities to which they are disclosed, and the planned date of deletion;
34.2. The right to obtain a copy of the data - on this basis, at your request, we will provide you
with a copy of the processed data concerning the person making the request;
34.3. The right to rectification - at your request, we are obliged to remove any inconsistencies
or errors in the processed personal data and complete it if it is incomplete;
34.4. The right to erasure - on this basis you can request the erasure of data, the processing of
which is no longer necessary to carry out any of the purposes for which they were collected;
34.5. The right to restrict processing - on this basis, at your request, we will stop performing
operations on your personal data - except for operations to which you have consented -
and their storage, in accordance with accepted retention principles or until the reasons for
restricting processing cease to exist;
34.6. The right to data portability - on this basis - insofar as your data is processed in connection
with a contract concluded or consent given - we will release the data you have provided to
us in a computer-readable format. You may also request that we send the data to another
entity - provided, however, that we have the technical capacity to do so;
34.7. The right to object to the processing of data for marketing purposes - you can object to
the processing of personal data for marketing purposes at any time, without having to
justify such objection;
34.8. The right to object to other purposes of processing - you may object at any time to the
processing of personal data that is carried out on the basis of our legitimate interest (e.g.,
for analytical or statistical purposes or for reasons related to property protection); an
objection in this regard should contain a justification;
34.9. The right to withdraw consent - if the data is processed on the basis of your consent, you
have the right to withdraw it at any time, which, however, does not affect the legality of
the processing carried out before the withdrawal of consent;
34.10. The right to complain - if you believe that the way we process your personal data violates
the provisions of the RODO or other data protection laws, you can file a complaint with the
President of the Office for Personal Data Protection.
DATA RECIPIENTS
35. As we want to perform the best possible services for you, we will disclose your personal data to
our trusted partners, subcontractors and entities working with us, including, in particular,
suppliers responsible for operating IT systems, entities such as banks and payment operators,
accounting service providers, marketing agencies (for marketing services) and our affiliates.
36. Your personal data will be shared with other entities for their own purposes, including marketing
purposes only if you consent.
TRANSFER OF DATA OUTSIDE THE EOG
37. The level of protection of personal data outside the European Economic Area (EEA) may differ
from that provided by European law. For this reason, we will transfer your personal data outside
the EEA only when necessary and with an adequate level of protection. You will be notified each
time.
38. We use companies that are based in the United States, viz:
38.1. Your personal data is processed in Azure cloud computing provided by Microsoft,
38.2. The portal is hosted by CloudFlare,
38.3. We use the Auth0 authorization system as part of the login, registration and storage of your
account data,
38.4. we use statistical analysis of site traffic through Google Analytics provided by Google,
Microsoft Clarity provided by Microsoft, and Meta Pixel provided by Meta,
38.5. Your personal data related to the appointment availability check form is processed at
Airtable and Make.
SECURITY OF PERSONAL DATA
39. Know that we take all steps to ensure that your personal data is processed by us in a secure
manner - ensuring, above all, that only authorized persons have access to your data and only to
the extent necessary for their tasks.
40. We take all necessary measures to ensure that our subcontractors and other cooperating entities
provide guarantees to apply appropriate security measures whenever they process your personal
data on our behalf.
CONTACT DETAILS
41. For all matters referred to in this policy, in particular related to the processing of your personal
data, you can contact us through:
41.1. e-mail: kontakt@justfilm.it
41.2. by mail to the address: JustFilm.it sp. z o.o., 12 Pulawska St., lok.3, 2nd floor, 02-566 Warsaw.
PRIVACY POLICY CHANGES
42. This Policy is reviewed on an ongoing basis and updated as necessary. The current version of the
Policy has been adopted and is effective as of 06.05.2023.