The purpose of the Personal Data Protection Policy, hereinafter referred to as the Policy, is to establish and maintain the required protection of personal data in accordance with the provisions of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 and the Act on Personal Data Protection (Journal of Laws of 2018, item 1000) in connection with the processing of personal data at Print Union Sp. z o.o. ("Print Union Limited") with its registered office in Białynin, Production Plant 96-100 Skierniewice, ul. Łowicka 127, e-mail: [email protected].
This Policy applies to both personal data processed in a traditional manner in books, records, lists, and other registration sets, as well as in IT systems. It applies to existing and future sets of personal data. The procedures and principles specified in this document apply to all persons authorized to process personal data, both employed and others, e.g. volunteers, interns, trainees. The area of processing of personal data at Print Union Sp. z o.o. ("Print Union Limited") includes buildings and/or premises located in 96-100 Skierniewice, ul. Łowicka 127.
1.1. The Data Controller processes personal data:
1.2. In order to comply with these principles, the data controller processes data legally, based on the grounds described in Article 6 of the GDPR. Personal data is collected appropriately for processing purposes and processed for a specific period. For individuals whose data is processed, the data controller fulfills the information obligations specified in Article 13 of the GDPR or Article 14 of the GDPR (when information is obtained in a manner other than from the data subject) and indicates their rights, such as the right to:
The data controller ensures data protection when using services of external entities by concluding appropriate entrustment agreements and by using processing entities that fulfill the obligations arising from the GDPR. In the event of a technical or physical incident, the data controller ensures the ability to quickly restore access to personal data and access to them.
1.3. Confirmation of compliance with the information obligations by the data controller consists of informative clauses provided to individuals whose data is processed. In the case of employees, they are presented with clauses for signature and placed in employees' personal files.
For customers and contractors, they are provided at the time of concluding the contract, and are also displayed in a visible place at the workplace.
The Data Controller ensures that access to personal data at Print Union Sp. z o.o. ("Print Union Limited") is granted only to persons who are authorized by the DC. Authorizations specify the operations to which users are entitled, i.e. creating, deleting, viewing, transferring data, in which systems, and for how long. The Data Controller maintains a record of authorized persons. Authorizations for processing personal data may be granted at the request of the user's immediate supervisor.
The Data Controller conducts a risk analysis to secure personal data adequately to identified threats. The analysis is conducted in case of a threat and cyclically every 4 months. Data analysis is carried out separately for each set of data or for several sets with a similar scope of data. If necessary, an impact assessment is carried out to assess the risk in accordance with Article 35 of the GDPR.
Taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing as well as the risk of violating the rights or freedoms of natural persons with varying likelihood and severity of the risk, the data controller and the data processor implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
The data controller keeps a register of processing activities. In this register you include:
The Personal Data Administrator may be/is obliged to appoint a Data Protection Officer. In the case of appointing a Data Protection Officer, their tasks include:
In the event of appointing a Data Protection Officer, their appointment must be reported to the President of the Office for Personal Data Protection within 14 days from the date of appointment, indicating the first name, last name, email address, or phone number of the Data Protection Officer.
The data administrator implements a procedure for handling incidents of personal data protection breaches. The purpose of this procedure is to fulfill the obligation arising from Article 33 of the GDPR. The procedure defines the way incidents threatening the security of personal data are defined and how to respond to them, as well as the procedure for implementing corrective actions. Every person authorized to process personal data is obliged to inform about the possibility of an incident occurring or its occurrence. Such information should be provided to the immediate superior or the Data Protection Officer.
Notifications are required for:
It is also necessary to notify the administrator of the information systems. Additionally, the occurrence of the incident, its consequences, as well as the corrective and remedial actions taken, must be documented. In the event that the incident results in a violation of the rights or freedoms of natural persons, the data administrator reports them to the President of the Office for Personal Data Protection within 72 hours, and if required, notifies the individuals affected by the incident.
The data administrator introduces Personal Data Protection Regulations in Print Union Ltd. in order to provide individuals processing personal data with full knowledge of the principles of personal data processing in the organization and the associated obligations. Persons familiarized with the Regulations are obliged to confirm their familiarity with this document and declare their compliance with its principles. Each person should be acquainted with the Regulations before employment. The data administrator also provides training to employees on the application of regulations regarding the protection of personal data, and the presence of employees should be confirmed in writing.
The Information System Administrator carries out tasks related to the management and ongoing supervision of the data administrator's information system. In this regard:
10.1. In the case of outsourcing the processing of personal data to external entities, the data administrator is obligated to conclude a data processing agreement. A register of agreements for entrusting the processing of personal data is maintained within the organization.
10.2. The agreement specifies the categories of individuals whose data is concerned, as well as the responsibilities and rights of the data administrator. Furthermore, it obligates the data processing entity to:
Print Union Ltd. exercises supervision and control over the protection of personal data. Control activities are carried out once every quarter. A protocol is prepared for control activities, which provides a detailed description of the scope of the control and the actions taken, as well as recommendations and corrective measures. The protocol is signed by the persons conducting the control activities.
Failure to comply with the Data Protection Policy implemented by the data administrator, the principles of which are defined in this document, and the violation of data protection procedures by employees authorized to process personal data may be treated as a serious breach of employment duties.
Textile decorations from design to finished product, from A to Z. Embroidery and prints on T-shirts, sweatshirts, hats, and many other types of clothing and accessories are our specialty.
Print Union Sp. z o.o.
VAT (TIN): PL 836-187-51-84
REGON: 387348499
Białynin 11
96-130 Głuchów
Łowicka 127
96-100 Skierniewice
We send no more than 2 messages per month – mainly about new products and promotions. You can unsubscribe at any time.
By providing your email address, you consent to its processing for the purpose of sending the newsletter by Print Union Sp. z o.o. Details regarding data processing can be found in the Privacy Policy.
© Print Union 2025