Privacy Policy
Effective date: December 5, 2023
Whereas
1.
This page informs you of our policies regarding the collection, use and disclosure of personal data, security of data, financial transactions when you use our Service and the choices you have associated with that data.
2.
CNT Holding Sp. z o. o. (“we”) operate the https://cnt.global/ website and the CNT App mobile application
(hereinafter referred to as the “Service”)
3.
We use the data we collect to provide and improve the Service. By using the Service, you agree to the collection
and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, the terms
used in this Privacy Policy have the same meanings as in our Terms and Conditions.
4.
Legal Basis for Processing Personal Data under the General Data Protection Regulation (GDPR):
If you are from the European Economic Area (EEA), CNT Holding Sp. z o. o. legal basis for collecting and using
the personal information described in this Privacy Policy depends on the Personal Data we collect and the
specific context in which we collect it. CNT Holding Sp. z o. o. may process your Personal Data because:
4.1.
We need to perform a contract with you.
4.2.
You have given us permission to do so
4.3.
The processing is in our legitimate interests and it is not overridden by your rights
4.4.
For payment processing purposes
4.5.
To comply with the law.
5.
We at CNT Global are committed to safeguarding the privacy and security of your information and the security
of our financial transactions. The Privacy, Financial Transaction and Security Policies below outline our practices concerning the collection, use, and protection of your data.
6.
Use of Data: CNT Holding Sp. z o. o. uses the collected data for various purposes whichinclude but are not limited to:
6.1.1.
To provide and maintain our Service
6.1.2.
To notify you about changes to our Service
6.1.3.
To allow you to participate in interactive features of our Service when you
choose to do so
6.1.4.
To provide customer support
6.1.5.
To gather analysis or valuable information so that we can improve our
Service
6.1.6.
To monitor the usage of our Service
6.1.7.
To detect, prevent and address technical issues
6.1.8.
To provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information
3.
Service: Service means the https://cnt.global/ website and the CNT App mobile application operated by
CNT Holding Sp. z o. o.
4.
Personal Data: Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
5.
Usage Data: Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
6.
Cookies: Cookies are small files stored on your device (computer or mobile device).
7.
Data Controller: Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal information are,
or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your Personal Data.
8.
Data Processors (or Service Providers): Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.
9.
Data Subject (or User): Data Subject is any living individual who is using our Service and is the subject of Personal Data.
10.
Information Collection and Use: We collect several different types of information for various purposes to provide and improve our Service to you. Types of Data Collected:
10.1.
Personal Data: While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“PersonalData”). Personally identifiable information may include, but is not limited to:
10.1.1.1.
Email address
10.1.1.2.
First name and last name
10.1.1.3.
Phone number
10.1.1.4.
Address, State, Province, ZIP/Postal code, City
10.1.1.5.
Cookies and Usage Data
10.1.1.6.
We may use your Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you.
10.1.1.7.
You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send or by contacting us.
10.2.
Usage Data: We may also collect information that your browser sends whenever you visit our Service or when you access the Service by or through a mobile device (“UsageData”). This Usage Data may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data. When you access the Service with a mobile device, this Usage Data may include information such as the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.
10.3.
Location Data: We may use and store information about your location if you give us permission to do so (“Location Data”). We use this data to provide features of our Service, to improve and customise our Service. You can enable or disable location
services when you use our Service at any time by way of your device settings.
10.4.
Tracking Cookies Data: We use cookies and similar tracking technologies to track the activity on our Service and we hold certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent toyour browser from a website and stored on your device. Other tracking technologies arealso used such as beacons, tags and scripts to collect and track information and toimprove and analyse our Service. You can instruct your browser to refuse all cookies orto indicate when a cookie is being sent. However, if you do not accept cookies, youmay not be able to use some portions of our Service. Examples of Cookies we use
10.4.1.
Session Cookies. We use Session Cookies to operate our Service.10.4.2.Preference Cookies. We use Preference Cookies to remember your preferencesand various settings.10.4.3.Security Cookies. We use Security Cookies for security purposes.
Definitions
4.0 User Data Protection Rights
7.
If you are a resident of the European Economic Area (EEA), you have certain data protection rights. CNT Holding Sp. z o. o. aims to take reasonable steps to allow you to correct, amend, delete or limit the use of your Personal Data.
8.
If you wish to be informed about what Personal Data we hold about you and if you want it to be removed from our systems, please contact us.
9.
In certain circumstances, you have the following data protection rights:
9.1.
The right to access, update or delete the information we have on you. When ever made possible, you can access, update or request deletion of your Personal Datadirectly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you.
9.2.
The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
9.3.
The right to object. You have the right to object to our processing of your PersonalData.
9.4.
The right of restriction. You have the right to request that we restrict the processing of your personal information.
9.5.
The right to data portability. You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format.
9.6.
The right to withdraw consent. You also have the right to withdraw your consent at any time where CNT Holding Sp. z o. o. relied on your consent to process your personal information.
9.7.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).
10.
Please note that we may ask you to verify your identity before responding to such requests.
11.
Data Collection and Usage
12.
Personal Information: We may collect and process personal information for legitimate business purposes, such as providing subcontracting services, managing relationships, and ensuring compliance with legal obligations.
13.
Categories of Data: The types of personal data collected may include but are not limited to:
14.
Contact information (name, email, address, phone number)
15.
Professional information (job title, company, responsibilities)
16.
Billing information (if applicable)
17.
Purpose of Processing: Personal data will be processed for the purposes for which it was collected and in accordance with applicable data protection laws.
18.
Data Security Measures: We implement industry-standard security measures to protect against unauthorized access, alteration, disclosure, or destruction of personal data.
19.
Data Access: Access to personal data is restricted to employees and subcontractors who need it for legitimate business purposes. All personnel are trained on data protection and confidentiality.
20.
Data Retention
21.
Retention Period: Personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements.
22.
Data Deletion: Upon the expiration of the retention period, or at the request of the data
subject, personal data will be securely deleted or anonymized.
23.
Data Sharing
24.
Third-Party Disclosure: We may share personal data with third parties for the purpose of providing subcontracting services, and we ensure that such third parties comply with data protection laws.
25.
International Transfers: If personal data is transferred outside the EU, we will ensure that appropriate safeguards are in place, such as standard contractual clauses or adherence to an approved certification mechanism.
26.
Data Subject Rights
27.
Access and Correction: Data subjects have the right to access and correct their personal data.
28.
Deletion: Data subjects may request the deletion of their personal data in certain circumstances.
29.
Objection: Data subjects have the right to object to the processing of their personal data.
30.
Children’s Data Our Service does not address anyone under the age of 18 (“Children”).
31.
We do not knowingly collect personally identifiable information from anyone under the age of 18.
32.
If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.
Service Providers
33.
Links to Other Sites: Our Service may contain links to other sites that are not operated by us.
34.
If you click a third party link, you will be directed to that third party’s site.
35.
We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
36.
We may employ third party companies and individuals to facilitate our Service (“Service Providers”), provide the Service on our behalf, perform Service-related services or assist us in analysing how our Service is used.
37.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
38.
Analytics: We may use third-party Service Providers to monitor and analyse the use of ourService.
39.
Google Analytics: Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualise and personalise the ads of its own advertising network. For more information on the privacy practices of Google, please visit the Google Privacy Terms webpage: https://policies.google.com/privacy?hl=en
40.
Piwik / Matomo: Piwik or Matomo is a web analytics service. You can visit their Privacy Policy page here: https://matomo.org/privacy-policy
41.
Clicky: Clicky is a web analytics service. Read the Privacy Policy for Clicky here: https://clicky.com/terms
42.
Statcounter: Statcounter is a web traffic analysis tool. You can read the Privacy Policy for Statcounter here: https://statcounter.com/about/legal/
43.
Unity Analytics: Unity Analytics is provided by Unity Technologies. For more information on what type of information Unity Analytics collects, please visit their Privacy Policy page: hhttps://unity3d.com/legal/privacy-policy
44.
Behavioral Remarketing: CNT Holding Sp. z o. o. uses remarketing services to advertise on third party websites to you after you visited our Service. We and our third-party vendors use cookies to inform, optimise and serve ads based on your past visits to our Service.
45.
Google Ads (AdWords): Google Ads (AdWords) remarketing service is provided by Google Inc. You can opt-out of Google Analytics for Display Advertising and customise the Google Display Network ads by visiting the Google Ads Settings page:
http://www.google.com/settings/ads. Google also recommends installing the Google Analytics Opt-out Browser Add-on –
https://tools.google.com/dlpage/gaoptout – for your web browser. Google Analytics Opt-out Browser Add-on provides visitors with the ability to prevent their data from being collected and used by Google Analytics. For more information on the privacy
practices of Google, please visit the Google Privacy Terms web page: https://policies.google.com/privacy?hl=en
46.
Facebook: Facebook remarketing service is provided by Facebook Inc. You can learn more about interest-based advertising from Facebook by visiting this page: https://www.facebook.com/help/164968693837950. To opt-out from Facebook’s interest-based
ads, follow these instructions from Facebook: https://www.facebook.com/help/568137493302217. Facebook adheres to the Self-Regulatory Principles for Online Behavioural Advertising established by the Digital Advertising Alliance. You can also opt-out from Facebook and other participating companies through the Digital Advertising Alliance in the USA http://www.aboutads.info/choices/, the Digital Advertising Alliance of Canada in Canada http://youradchoices.ca/ or the European Interactive Digital Advertising Alliance in Europe http://www.youronlinechoices.eu/, or opt-out using your mobile device settings. For more information on the privacy practices of Facebook, please visitFacebook’s Data Policy: https://www.facebook.com/privacy/explanation.
Information Security Policy
47.
Responsibility: The company is committed to ensuring the confidentiality, integrity, and availability of information by establishing and maintaining
an information security management system.
48.
Risk Assessment: Regular risk assessments are conducted to identify potential threats and vulnerabilities to the security of information.
49.
User Access: Access to systems and data is granted based on job responsibilities, andaccess is promptly revoked when it is no longer required.
50.
Authentication: Strong authentication measures are in place to ensure the identity of users accessing systems and data.
51.
Reporting Incidents: Employees are trained to promptly report any security incidents or breaches to the designated security contact.
52.
Investigation and Remediation: A defined process is in place to investigate security incidents, mitigate risks, and implement corrective actions.
53.
Training Programs: All employees undergo regular training on information security best practices and data protection.
54.
Awareness: Employees are made aware of their roles and responsibilities in maintaining information security.
55.
Facility Access Controls: Physical access to facilities housing information systems is restricted and monitored.
56.
Equipment Security: Measures are in place to secure physical devices and media that store or process sensitive information.
57.
Legal Compliance: The company adheres to all relevant data protection and privacy laws, regulations, and contractual obligations.
58.
Auditing and Monitoring: Regular audits and monitoring activities are conducted to ensure
compliance with security policies and procedures.
Financial Transaction Processing Policy
59.Payments: We may provide paid products and/or services within the Service. In that case,we use third-party services for payment processing (e.g. payment processors).
60.
We will not store or collect your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their Privacy Policy.
61.
These payment processors adhere to the standards set by PCI-DSS as managed by thePCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard,American Express and Discover.
62.
PCI-DSS requirements help ensure the secure handling of payment information.63.The payment processors we work with are:
63.1.
Apple Store In-App Payments: Their Privacy Policy can be viewed at https://www.apple.com/legal/privacy/en-ww/
63.2.
Google Play In-App Payments: Their Privacy Policy can be viewed at https://www.google.com/policies/privacy/
63.3.
Stripe: Their Privacy Policy can be viewed athttps://stripe.com/us/privacy
63.4.
PayPal / Braintree: Their Privacy Policy can be viewed athttps://www.paypal.com/webapps/mpp/ua/privacy-full
63.5.
FastSpring: Their Privacy Policy can be viewed athttp://fastspring.com/privacy/
63.6.
Authorize.net: Their Privacy Policy can be viewed athttps://www.authorize.net/company/privacy/
63.7.
Checkout: Their Privacy Policy can be viewed athttps://www.2checkout.com/policies/privacy-policy
63.8.
Sage Pay: Their Privacy Policy can be viewed athttps://www.sagepay.co.uk/policies
63.9.
Square: Their Privacy Policy can be viewed athttps://squareup.com/legal/privacy-no-account
63.10.
Go Cardless: Their Privacy Policy can be viewed athttps://gocardless.com/en-eu/legal/privacy/
63.11.
Elavon: Their Privacy Policy can be viewed athttps://www.elavon.com/privacy-pledge.html
63.12.
Verifone: Their Privacy Policy can be viewed athttps://www.verifone.com/en/us/legal
63.13.
WeChat: Their Privacy Policy can be viewed athttps://www.wechat.com/en/privacy_policy.html
63.14.
Alipay: Their Privacy Policy can be viewed athttps://render.alipay.com/p/f/agreementpages/alipayglobalprivacypolicy.html
Modifications and Changes
64. We reserve the right to modify these Privacy and Security Policies at any time.
65. Changes will be effective immediately upon posting on the Site.
66. Please review this statement periodically for any updates.
67. Your continued use of the Site after modifications constitutes acceptance of thosechanges. Any such changes will be communicated through our website.
Effective Date
December 5 2023
Contact Us
If you have any questions about this Privacy Policy, please contact us:
68. By email:dpo@cnt.global
69. By visiting this page on our website:https://cnt.global/privacypolicy
70.By phone number: +4872277607771.By mail: Goleszowska 3A / B96, 01-249, Warsaw, Poland