Privacy Policy and Personal Data Protection

§1. General provisions

  1. This Privacy Policy, hereinafter referred to as the "Policy", defines the principles of processing and protection of personal data provided by Customers in connection with their use of services provided via the website zest.agency.
  2. We respect the right to privacy and we care about data security. For this purpose we use, among others, a secure communication encryption protocol (SSL).
  3. Personal data provided in the forms available on the website (including the contact form and the recruitment form) are treated as confidential and are not visible to unauthorized persons.

§2. Administrator of personal data

  1. The administrator of personal data is Zest Sp. z o.o. with its registered office in Aleksandrów Łódzki (postal code: 95-070) at Szatonia 28A Street, Poland, NIP (Taxpayer ID Number): 7322206426, e-mail address: info@zest.agency, and the addresses and contact numbers indicated on the Website in the "Contact" tab.
  2. In matters related to personal data, please contact us at info@zest.agency.

§3. Personal data protection

  1. Personal data is processed:
    1. in accordance with the applicable provisions on the protection of personal data,
    2. in accordance with the implemented Policy.
  2. Personal data is processed in order to perform the concluded contract, to exercise the rights and obligations arising from it and to pursue claims on its basis. The legal basis for processing is Art. 6(1)(b) GDPR.
  3. In the case of processing personal data for newsletter purposes, the legal basis for processing is Art. 6(1)(a) GDPR.
  4. The data will be kept for the duration of the contract and for the period necessary to establish and assert claims or defend against reported claims.
  5. The Customer's personal data may be provided to:
    1. system suppliers with whom the Personal Data Controller cooperates,
    2. entities providing postal or courier services in order to deliver correspondence,
    3. entities authorized by law, on a documented request.
  6. The Customer has the right to access their personal data, rectify it, delete it or limit its processing, as well as the right to object to the processing, the right to data portability and the right to lodge a complaint with the supervisory body (i.e. the President of the Personal Data Protection Office).
  7. Providing personal data is voluntary, but it is a condition for the conclusion and performance of the contract.
  8. Personal data may be processed in an automated manner, including in the form of profiling. Profiling is aimed at enabling the preparation of the best, personalized offer and dedicated advertising, as well as personalizing content and ads and analyzing traffic on the website.

§4. Cookies

  1. The website uses cookies. These are small text files sent by the web server and stored by the browser software. When the browser reconnects with the site, the site recognizes the type of device the Customer connects from. The parameters allow the information contained in them to be read only by the server that created them. Cookies therefore make it easier to use previously visited websites.
  2. The information collected relates to the IP address, type of browser used, language, type of operating system, Internet service provider, time and date information, location and information sent to the website via the forms.
  3. The collected data is used to monitor and check how Customers use our website in order to improve its functioning, providing more effective and problem-free navigation.
  4. We monitor Customer information using, among others, the Google Analytics tool, which records Customer behavior on the website. To measure the effectiveness of our marketing activities we also use tools provided by Meta Platforms Ireland Ltd. (Meta Pixel and Meta Conversions API). For this purpose we may transfer to Meta data about on-site events (e.g. form submission) together with a limited set of data provided by the Customer in the form (e.g. email address), transferred in a hashed (irreversibly encoded) form. This data is used solely for conversion matching and measuring advertising effectiveness and is not used for any other purpose.
  5. Cookies identify the Customer, which allows the content of the website to be adapted to their needs. By remembering their preferences, they make it possible to match the ads addressed to them. We use cookies to guarantee the highest standard of convenience of our website, and the collected data is used only to optimize activities.
  6. We use the following cookies on our website:
    1. "necessary" cookies, enabling the use of services available on the website, e.g. authentication cookies used for services that require authentication on the website,
    2. cookies used to ensure security, e.g. used to detect fraud in the field of authentication within the website,
    3. "performance" cookies, enabling the collection of information on the use of websites,
    4. "functional" cookies, allowing the settings selected by the Customer to be "remembered" and the Customer's interface to be personalized, e.g. in terms of the selected language or region, font size, website appearance, etc.,
    5. "advertising" cookies, enabling the delivery of advertising content more tailored to Customers' interests.
  7. The Customer can at any time disable or restore the option of collecting cookies by changing the settings in their web browser, as well as manage consents in the consent management tool available on the website. Instructions for managing cookies are available at: http://www.allaboutcookies.org/manage-cookies.
  8. Additional personal data, such as an e-mail address, is collected only in places where the Customer has expressly consented to it by completing a form. This data is retained and used only for the purposes necessary to perform a given function.

§5. Google Analytics account access (the “GA4 Audit” tool)

  1. The “GA4 Audit” tool at zest.agency/en/ga4-audit lets the owner of a Google Analytics 4 property review its settings. Using this feature is optional and requires signing in with a Google account and granting access to the https://www.googleapis.com/auth/analytics.readonly scope (read-only access to Google Analytics configuration) as well as openid and the account email address.
  2. The access scope is read-only. We have no technical means to change property settings, delete data, or send anything to Google Analytics.
  3. We read property settings only: the property name and ID, currency and time zone, the data retention setting, the list of key events, custom definitions (dimensions and metrics), attribution, reporting identity and Google Signals settings, the number of audiences, the list of data streams together with measurement IDs, enhanced measurement and data redaction settings, the number of event modification rules and the number of Measurement Protocol secrets, and whether the property is linked to Google Ads and BigQuery. We do not download reports or any data about the visitors of your site.
  4. The access token is not stored. We request a one-time token from Google (with no refresh token), keep it only in a browser session cookie (HttpOnly, 30 minutes at most), and revoke it with Google and delete it immediately after the audit runs.
  5. We store the audit result (the list of findings), the name and ID of the audited property, and the email address of the account used — so that the report states whose account the data came from. We delete that record no later than 30 days after the audit.
  6. We do not share information read from Google Analytics with third parties, do not use it for advertising, do not sell it, and do not use it to train artificial intelligence models.
  7. You can revoke access at any time at myaccount.google.com/permissions. To have the report deleted sooner, write to info@zest.agency.
  8. Zest Sp. z o.o.'s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.