Privacy Policy

Privacy Policy

Effective from 1 October 2022 until revoked or amended

The controller of your personal data is Fonia Telecom spółka z ograniczoną odpowiedzialnością, with its registered office in Warsaw at ul. Zwycięzców 2, 03-941 Warsaw, holding REGON number: 388645503, NIP: 1133031081, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under KRS number 0000890861, hereinafter referred to as the "Data Controller".

The Data Controller fulfils the information obligations arising from Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, hereinafter referred to as the "GDPR", as well as the Act of 10 May 2018 on the Protection of Personal Data, hereinafter referred to as the "Act", and other applicable personal data protection regulations.

The Data Controller undertakes to maintain the security and confidentiality of the personal data obtained from you. All employees have been appropriately trained in the processing of personal data, and as the Data Controller, we have implemented appropriate safeguards as well as technical and organisational measures to ensure the highest level of personal data protection. We have implemented personal data protection procedures and policies compliant with the GDPR and the Act, which ensure the lawfulness and reliability of data processing processes, as well as the enforceability of all rights available to you as a data subject. Additionally, where necessary, we cooperate with the supervisory authority in the territory of the Republic of Poland, namely the President of the Personal Data Protection Office.

This Privacy Policy sets out the rules for collecting, processing and using personal data, as well as the conditions for using devices and other data originating from persons who have provided personal data for processing by the Data Controller.

The Data Controller makes this Privacy Policy publicly available on its website: https://fonia.app/polityka-prywatnosci/, hereinafter the "Website", and in the Fonia mobile application, hereinafter the "Application".

§ 1 What personal data do we process?

The Data Controller processes the following personal data of users provided on the website https://fonia.app/ in connection with the conclusion of a telecommunications services agreement or in connection with the use of the Application:

  1. full name, PESEL number, series and number of an identity document, passport number or residence card number. These data are processed when, as a user of our Website, you provide them via the Order Form in order to use the telecommunications services provided by the Data Controller. The above data may also be processed by the Data Controller to verify the identity of an authorised person;
  2. company name, NIP number and data of persons representing the entrepreneur. These data are processed when, as a user of our Website, you provide them via the Order Form in order to use the telecommunications services provided by the Data Controller. The above data may also be processed by the Data Controller to verify identity, in particular to identify persons authorised to represent the entrepreneur;
  3. correspondence address. This is processed in order to deliver the ordered SIM card;
  4. e-mail address. This is processed for the performance of the agreement, in particular to deliver confirmation of the SIM card order, to send confirmation of the conclusion of the telecommunications services agreement, and to deliver correspondence related to the concluded agreement, including settlement documents. Your e-mail address is also processed to activate the mobile Application. Additionally, the e-mail address may be processed if you voluntarily register a Cashback Account in the Application. The e-mail address may also be processed for marketing purposes if you consent to receiving commercial and marketing information;
  5. telephone number. This is processed when, as a user of our Website, you wish to use the number portability service to transfer your number to the network operated by the Data Controller;
  6. bank account number. This is processed for the provision of services within the Cashback Account;
  7. IP address of the device or browser identifier. Information resulting from the general rules of Internet connections, such as the IP address and other information included in system logs, is used for technical and statistical purposes, including in particular to collect general demographic information, for example about the region from which the connection is made.

Personal data in the form of an e-mail address and telephone number may be processed for the performance of the concluded agreement. The Data Controller sends information concerning the provision of services by SMS and e-mail.

In connection with the conclusion by you of a telecommunications services agreement, the Data Controller processes transmission data and location data. Transmission data means data showing the manner and frequency of use of telecommunications services. In particular, these are data showing the number of incoming and outgoing calls, their duration, the numbers you contact, and the number of incoming and outgoing SMS messages.

Transmission data also includes data concerning Internet use, meaning data on the addresses of websites visited, data on the type of terminal device used, as well as data on session duration and the amount of data transferred. The Data Controller processes the above data in connection with the performance of the telecommunications services agreement, including for the calculation of telecommunications service fees, for the purpose of managing traffic in the telecommunications network and settlements with other operators, as well as to ensure network security, including fraud detection.

In connection with the provision of services within the Cashback Account, we process data concerning your use of the services of our Partners in order to calculate the cashback due to you. As part of the above, we only process information about the session and the fact that a purchase of a specific amount was made. We do not transfer your personal data to our Partners. Data may be provided directly by you when making purchases in the Partner's online store. In such a case, the Partner processes your personal data as an independent personal data controller.

While you use the Application or services enabled through the Application, the Data Controller or entities whose additional services you choose to use may obtain other data, including data on the use of the telecommunications network, services, website or application. By using the Application, you may, among other things, order additional services or goods or use new functionalities made available. Where this requires the use of personal data in a manner other than described in this document, we will supplement and provide the missing information, where possible, before obtaining the data. In all other respects, the information on data processing contained in this document will remain valid.

§ 2 How do we obtain data?

The Data Controller obtains information through:

  1. your entry of data in forms made available on the Website or in the Application, for the purpose of concluding a telecommunications services agreement or using the number portability service;
  2. your entry of data in the Application, for the purpose of purchasing additional services or goods or using new functionalities;
  3. your entry of data in the Application, including via chat, or your provision of data via e-mail correspondence, in order to answer your question and handle the reported matter;
  4. storing cookies on terminal devices;
  5. collecting logs from devices, web servers and other information generated in connection with or as a result of the functioning and use of the Application.

You are fully responsible for completing the data in the forms and orders referred to above correctly and in accordance with the legal and factual state.

Providing personal data is voluntary, necessary for us to send commercial and marketing information, and in certain cases constitutes a condition for concluding an agreement with the Data Controller.

The consequence of not providing your personal data will be the inability to receive commercial and marketing information from us, the inability to continue the performance of the agreement with the Data Controller and use the Application, or, depending on the case, the inability to purchase additional services or goods or use new functionalities.

§ 3 For what purpose do we process your personal data? What is the legal basis for processing personal data?

We use your personal data obtained via contact forms, during registration in the Application, and while using services made available through the Application for the following purposes:

  1. sending commercial information electronically, as well as marketing services via terminal devices in connection with the performance of the concluded agreement, pursuant to Article 6(1)(b) of the GDPR, within the scope of personal data of persons who are clients of the Data Controller;
  2. performing contractual requirements, meaning that the processing of personal data is necessary for the performance of the agreement concluded with the Data Controller, pursuant to Article 6(1)(b) of the GDPR, within the scope of personal data of persons who are clients of the Data Controller;
  3. fulfilling a legal obligation incumbent on the Data Controller under applicable regulations, including those related to SIM card registration, pursuant to Article 6(1)(c) of the GDPR, within the scope of personal data of persons who are clients;
  4. pursuing the legitimate interests of the Data Controller, consisting in particular of ensuring security and protection of property, detecting and preventing abuse, protecting information, pursuing possible claims and compensation, improving service quality, adapting services and service quality, marketing the Data Controller's own products, direct marketing, preparing summaries, analyses and statistics for the Data Controller's internal purposes, and supporting customer service, pursuant to Article 6(1)(f) of the GDPR.

Within the above scope, we may perform profiling, meaning automated analysis of your data and the development of predictions about your preferences or future behaviour, for example for marketing purposes, in order to determine which offer you may be most interested in.

Your data are processed for the period necessary to achieve the purposes indicated above. Data are processed for the duration of the Agreement, unless the need for longer processing results from obligations imposed by law. In the case of data processing for purposes related to defending against claims or pursuing claims, the data will be processed until such claims become time-barred or until the relevant proceedings are completed, if they were initiated during that period. Data processed on the basis of consent are processed until such consent is withdrawn.

§ 4 What are the rules for collecting personal data?

Your data may be transferred outside the EEA, which includes the EU, Norway, Liechtenstein and Iceland, in the manner specified by applicable regulations, namely:

  1. on the basis of a European Commission decision confirming an adequate level of protection, for example in a third country to which we transfer the data; or
  2. subject to ensuring appropriate safeguards, such as:
  • binding corporate rules, as defined in Article 47 of the GDPR;
  • standard data protection clauses adopted by the European Commission or the competent personal data supervisory authority, Article 46(2)(c) or (d) of the GDPR;
  • an approved code of conduct, Article 46(2)(e) of the GDPR;
  • an approved certification mechanism, Article 46(2)(f) of the GDPR;
  • contractual clauses authorised by the supervisory authority, Article 46(3) of the GDPR;
  • and also in cases necessary due to the legitimate interests of the Data Controller, provided that the requirements of Article 49(1), second subparagraph, of the GDPR are met.

The obtained data are not disclosed to third parties, except in specific situations where:

  1. the recipients of such data are:
  • entities enabling data verification;
  • entities operating ICT systems or providing us with ICT tools;
  • advertising agencies cooperating with the Data Controller and other entities intermediating in the sale of our services or the organisation of marketing campaigns;
  • subcontractors of the Data Controller who support us or will support us, for example in the provision of telecommunications services or other services ordered by you, handling correspondence or customer service processes;
  • entities operating and maintaining our telecommunications network;
  • entities providing us with advisory, consultancy and audit services, legal, tax and accounting assistance, and research agencies acting on our behalf;
  • payment institutions handling payments in the Application;
  • suppliers of goods and services available in the Application;
  • in the case of transferring a number to our network: the President of UKE, in connection with the operation of the system enabling operators to identify the network in which a given telephone number operates;
  1. you give your consent;
  2. it is necessary to fulfil obligations arising from applicable law.

§ 5 Do we use automation?

Personal data of persons who are clients are subject to automated decision-making during account verification in the Application.

We also make automated decisions that have a significant effect on persons who are clients in the following situations:

  1. within contractual terms, for example in the service provision regulations, we may specify that reaching or exceeding thresholds or limits indicated by us, for example the number of messages sent, calls made or data transferred, may result in specific consequences, for example suspension of the service or its operation under different terms. If IT systems record that thresholds or limits have been reached, we will automatically apply the solution specified in the relevant regulations;
  2. in order to detect and respond to abuse in the use of services, we make automated decisions recognising certain unusual telecommunications traffic, for example short calls made very frequently from the same number, as inconsistent with the regulations and constituting so-called telecommunications abuse. As a consequence, we limit such traffic or block the numbers generating such traffic. You may challenge such a decision, in which case the matter will be reviewed by a designated employee of the Data Controller. To make an automated decision, we use information about telecommunications connections in our network, including typical and atypical network traffic patterns, and previously observed cases of abuse.

We do not use automation in decision-making when sending commercial information or processing personal data for marketing purposes.

§ 6 What rights do you have in connection with the processing of your personal data?

In accordance with the GDPR, every person whose personal data we process as the Data Controller has the right to:

  1. be informed about the processing of personal data, as referred to in Article 12 of the GDPR;
  2. access their personal data, as referred to in Article 15 of the GDPR;
  3. correct, supplement, update and rectify personal data, as referred to in Article 16 of the GDPR;
  4. erase data, the right to be forgotten, as referred to in Article 17 of the GDPR;
  5. restrict processing, as referred to in Article 18 of the GDPR;
  6. data portability, as referred to in Article 20 of the GDPR;
  7. object to the processing of personal data, as referred to in Article 21 of the GDPR;
  8. withdraw consent at any time without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal;
  9. not be subject to profiling, as referred to in Article 22 in conjunction with Article 4(4) of the GDPR;
  10. lodge a complaint with the supervisory authority, namely the President of the Personal Data Protection Office, address: ul. Stawki 2, 00-193 Warsaw, Poland, as referred to in Article 77 of the GDPR;
  11. exercise the above rights subject to the rules for using and implementing these rights arising from the applicable provisions.

In every case, you may contact the Data Controller with an inquiry or request for clarification. Contact addresses are provided below.

§ 7 Information obtained from your device and how it is processed

Our Application obtains access, among other things, to the following functionalities or applications of your device:

  1. calls and call management;
  2. contacts;
  3. notifications.

The Application uses tools from other entities. Therefore, cookies, tokens or elements from cooperating tools or applications may be placed on your device. Additionally, the providers listed below may gain access to information stored on your device through the Google Analytics or Firebase statistical tool, provided by Google Ireland Limited, through which a unique application identifier and general information about the use of the Application will be collected for the purpose of improving its functionality.

Information on the rules under which Google Analytics collects and processes data is available at www.google.com/intl/pl/policies/privacy/partners/ or at another URL that may be made publicly available by Google at any time. This page also indicates how you can control the information collected by Google in connection with the use of the Application.

You may withdraw your consent to the use of the tools of the above-mentioned providers at any time by changing the settings in the operating system of your device and using solutions blocking such tools made available by the providers, or by uninstalling the Application from your device.

§ 8 Final provisions

Taking into account the fundamental principles of the GDPR, in particular the principles of purpose limitation, storage limitation and data minimisation, we process your personal data only for a period no longer than necessary to achieve the purposes of processing and as permitted by law. Once the purpose of processing has been achieved, your personal data will be deleted, provided that the law allows it. Depending on the legal basis for processing your personal data, different data retention periods may apply.

Your personal data will be stored until claims become time-barred or until the expiry of the obligation to store data arising from legal provisions.

In all matters, including matters relating to personal data, you may contact us in writing at the address of the Data Controller's registered office, namely ul. Zwycięzców 2, 03-941 Warsaw, and electronically via the e-mail address: dpo@fonia.app.

Contact details of the Data Protection Officer: dpo@fonia.app