Last updated: September 09, 2026

Privacy and Cookies Policy

Last updated: 09 September 2026

1. General provisions

  1. This Privacy and Cookies Policy sets out the rules for the processing of personal data and the use of cookies and similar technologies on the website available at ato.pl, including its language versions and subpages.
  2. The controller of personal data is ATO SIGNAGE spółka z ograniczoną odpowiedzialnością with its registered office in Kalisz, address: Aleja Wojska Polskiego 29B, 62-800 Kalisz, Poland, entered in the Register of Entrepreneurs of the National Court Register under KRS number: 0000700288, NIP: 6182136552, REGON: 301888834, hereinafter referred to as the “Controller” or “ATO SIGNAGE”.
  3. The Controller may be contacted:
    • by e-mail: ato@ato.pl,
    • by phone: +48 62 767 85 00,
    • in writing at the registered office address: Aleja Wojska Polskiego 29B, 62-800 Kalisz, Poland.
  4. In matters relating to personal data protection, the Controller may be contacted by e-mail at ato@ato.pl or in writing at the registered office address of the Controller.
  5. The Controller processes personal data in accordance with applicable laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, hereinafter referred to as the “GDPR”.
  6. The website is informational in nature and is used to present the activities, services, projects, contact details and recruitment information of ATO SIGNAGE.

2. What data may be processed

  1. The Controller does not operate an online store or user account registration through the website.
  2. The Controller does not collect users’ personal data for marketing analytics or remarketing purposes.
  3. Personal data may be processed primarily when the user voluntarily provides it to the Controller, in particular by:
    • contacting the Controller by e-mail,
    • contacting the Controller by phone,
    • sending a business enquiry,
    • sending application documents in connection with recruitment,
    • using any other voluntary form of contact with the Controller.
  4. Depending on the form of contact, the Controller may process the following categories of data:
    • first name and surname,
    • company or organisation name,
    • job title,
    • e-mail address,
    • phone number,
    • content of the message sent,
    • data included in a business enquiry,
    • data included in application documents, such as a CV, cover letter or portfolio,
    • technical data related to the use of the website, such as IP address, date and time of connection, browser type, device type, operating system, visited subpage and basic server logs.
  5. The Controller does not require the provision of special categories of data, such as data concerning health, political opinions, religious beliefs, trade union membership, genetic data, biometric data or data concerning sex life. The user should not provide such data unless it is necessary due to the nature of the matter.

3. Purposes and legal bases for data processing

The Controller may process personal data for the following purposes:

3.1. Handling contact and correspondence

  1. If the user contacts the Controller by e-mail, phone or another available communication channel, the data is processed in order to respond, conduct correspondence and handle the enquiry.
  2. The legal basis for processing is:
    • Article 6(1)(f) GDPR — the legitimate interest of the Controller consisting in conducting correspondence and handling enquiries,
    • Article 6(1)(b) GDPR — if the contact is aimed at concluding or performing a contract.

3.2. Handling business enquiries and cooperation

  1. Data provided in connection with offer, project, commercial or business cooperation enquiries is processed in order to prepare a response, provide information about services, conduct negotiations, conclude or perform a contract.
  2. The legal basis for processing is:
    • Article 6(1)(b) GDPR — taking steps prior to entering into a contract or performance of a contract,
    • Article 6(1)(f) GDPR — the legitimate interest of the Controller consisting in maintaining business relations, handling enquiries and pursuing or defending claims.

3.3. Recruitment and job candidate data

  1. The website may contain information about current job offers and a button or link “Send application”, which enables the preparation of an e-mail message addressed to ATO SIGNAGE.
  2. ATO SIGNAGE does not operate candidate accounts, a recruitment panel or a recruitment form that stores data directly on the Website, unless a given functionality clearly indicates otherwise.
  3. Sending a recruitment application takes place through the e-mail software or e-mail service used by the candidate and means that the candidate voluntarily provides personal data contained in the e-mail message and attachments, in particular in a CV, cover letter or portfolio.
  4. Personal data of job candidates is processed for the purpose of:
    • conducting the current recruitment process,
    • assessing the candidate’s qualifications, experience and skills,
    • contacting the candidate regarding recruitment,
    • taking steps aimed at concluding an employment contract, civil law contract or another form of cooperation,
    • securing potential claims,
    • including the candidate in future recruitment processes if the candidate gives separate consent.
  5. The Controller may process the following personal data of a candidate:
    • first name and surname,
    • contact details provided by the candidate, such as e-mail address, phone number or correspondence address,
    • education,
    • professional qualifications,
    • employment history,
    • professional experience,
    • skills and authorisations,
    • information included in a CV, cover letter, portfolio or other application documents,
    • additional data voluntarily provided by the candidate,
    • information obtained during recruitment interviews, competence tests or correspondence with the candidate.
  6. The legal basis for processing candidates’ data is:
    • Article 6(1)(c) GDPR — with regard to data that the Controller may request from the candidate under labour law provisions,
    • Article 6(1)(b) GDPR — to the extent that processing is necessary to take steps prior to entering into a contract,
    • Article 6(1)(a) GDPR — with regard to data voluntarily provided by the candidate that goes beyond data required by law or is provided on the candidate’s own initiative,
    • Article 6(1)(a) GDPR — in the case of the candidate’s consent to participate in future recruitment processes,
    • Article 6(1)(f) GDPR — with regard to the legitimate interest of the Controller consisting in establishing, pursuing or defending claims.
  7. The candidate should provide only data necessary to participate in the recruitment process, in particular contact details, information about professional experience, education, qualifications and skills.
  8. The candidate should not provide special categories of data, in particular data concerning health, political opinions, religious beliefs, trade union membership, biometric data, genetic data or data concerning sex life, unless this is necessary and clearly justified.
  9. Personal data processed for the purposes of the current recruitment process will be stored for the duration of the recruitment process and then for up to 6 months after its completion in order to secure potential claims.
  10. If the candidate consents to participation in future recruitment processes, personal data will be stored for up to 12 months from the date of sending the application or until consent is withdrawn earlier.
  11. Recipients of candidates’ data may include persons authorised by the Controller to participate in the recruitment process, IT service providers, e-mail service providers, hosting providers, entities providing advisory, legal or administrative services, and public authorities or other entities authorised under applicable law.
  12. As a rule, candidates’ data is not transferred outside the European Economic Area. If, in connection with the use of IT tools, e-mail or external service providers, data is transferred outside the EEA, the Controller will ensure appropriate safeguards required under the GDPR.
  13. The candidate has the right of access to data, to obtain a copy of data, to rectify data, to erase data, to restrict processing, to data portability, to object, to withdraw consent at any time and to lodge a complaint with the President of the Personal Data Protection Office.
  14. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
  15. Candidates’ data will not be used for decisions based solely on automated processing or for profiling that would produce legal effects concerning the candidate or similarly significantly affect the candidate.
  16. If the candidate includes in application documents data other than data required by labour law provisions or other than data necessary to conduct the recruitment process, the provision of such data is treated as a voluntary action by the candidate.
  17. If the candidate wishes their data to be used also in future recruitment processes, they should give separate consent in the e-mail message or in the application documents.
  18. Consent to future recruitment processes is voluntary and may be withdrawn at any time by contacting the Controller.

3.4. Ensuring the operation and security of the website

  1. The Controller may process technical data, in particular IP address, device data, browser data, date and time of connection and server logs, in order to ensure the proper operation of the website, security, prevention of abuse, detection of errors and protection of IT systems.
  2. The legal basis for processing is Article 6(1)(f) GDPR — the legitimate interest of the Controller consisting in ensuring the security, continuity and proper operation of the website.

3.5. Pursuing and defending claims

  1. Personal data may be processed for the purpose of establishing, pursuing or defending claims.
  2. The legal basis for processing is Article 6(1)(f) GDPR — the legitimate interest of the Controller consisting in protecting the rights and interests of the Controller.

4. Recipients of data

  1. Personal data may be transferred to entities supporting the Controller in conducting its business and operating the website, in particular:
    • hosting providers,
    • e-mail service providers,
    • IT service providers,
    • entities maintaining or securing the website,
    • entities providing accounting, legal, advisory or administrative services,
    • public authorities or other entities authorised under applicable law.
  2. Data is transferred only to the extent necessary to achieve the given processing purpose.
  3. Entities processing data on behalf of the Controller act on the basis of appropriate data processing agreements or other required legal bases.

5. Transfers of data outside the European Economic Area

  1. As a rule, the Controller does not intend to transfer personal data of website users outside the European Economic Area.
  2. The website may contain links to external social media services, such as Facebook or LinkedIn. Clicking such a link redirects the user to an external service, which operates according to its own privacy and cookies rules.
  3. If, in connection with the use of external service providers, data is transferred outside the European Economic Area, the Controller will ensure appropriate safeguards required under the GDPR, in particular standard contractual clauses approved by the European Commission or other mechanisms provided for by law.

6. Data retention period

  1. Personal data is stored for the period necessary to achieve the purpose for which it was collected, and thereafter for the period required by law or necessary to secure potential claims.
  2. Data processed for the purpose of handling a contact enquiry is stored for the time necessary to handle the enquiry and may subsequently be stored for the limitation period of potential claims.
  3. Data processed in connection with offer enquiries or business cooperation is stored for the duration of the business relationship and subsequently for the period resulting from legal provisions or the limitation period of claims.
  4. Data of job candidates is stored in accordance with section 3.3. Recruitment and job candidate data of this Policy.
  5. Data processed on the basis of consent is stored until the consent is withdrawn, unless the purpose of processing ceases earlier.
  6. Technical data and server logs are stored for the period necessary to ensure the security and proper operation of the website, no longer than necessary to achieve these purposes.

7. Rights of data subjects

  1. The data subject has the following rights:
    • the right of access to data,
    • the right to obtain a copy of data,
    • the right to rectification of data,
    • the right to erasure of data,
    • the right to restriction of processing,
    • the right to data portability,
    • the right to object to data processing,
    • the right to withdraw consent at any time, if data is processed on the basis of consent,
    • the right to lodge a complaint with the President of the Personal Data Protection Office.
  2. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
  3. In order to exercise rights, the data subject may contact the Controller by e-mail at ato@ato.pl or in writing at the registered office address of the Controller.
  4. The Controller may request additional information to confirm the identity of the person making the request, if this is necessary to protect personal data.

8. Voluntary provision of data

  1. Providing data is voluntary, but it may be necessary to handle an enquiry, provide a response, conduct correspondence, participate in recruitment or achieve another purpose of contact.
  2. Failure to provide data may prevent the Controller from responding, handling the request, preparing an offer, conducting correspondence or enabling participation in the recruitment process.

9. Automated decision-making and profiling

  1. Users’ personal data is not used for decisions based solely on automated processing that would produce legal effects concerning the user or similarly significantly affect the user.
  2. The Controller does not profile users on the website.

10. Cookies and similar technologies

  1. According to the current configuration, the website does not store analytical or marketing cookies in the user’s browser.
  2. According to the current configuration, the website does not actively use tools such as Google Analytics, Meta Pixel, LinkedIn Insight Tag or other tools used to track users for analytical, advertising or remarketing purposes.
  3. The website may use only technical mechanisms necessary for its proper operation, security, loading of content or maintaining connection with the server.
  4. The website code may contain technical references used to optimise the loading of resources, such as the dns-prefetch mechanism. Such a reference alone does not mean that web analytics is conducted or that analytical cookies are stored in the user’s browser.
  5. If the Controller implements analytical cookies, marketing cookies or other tracking technologies in the future, this Policy will be updated accordingly, and the user will be given the opportunity to give or refuse consent, where such consent is required by law.
  6. The user may manage cookies and similar technologies in the settings of their web browser. Restricting the use of cookies may, however, affect certain website functions if they are technically necessary for its operation.

11. Links to external websites and social media

  1. The website may contain links to external websites, in particular ATO SIGNAGE profiles on social media services such as Facebook and LinkedIn.
  2. Clicking a link leading to an external service redirects the user to a third-party website. From that moment, the privacy rules, terms and cookies policies of that external service apply.
  3. The Controller is not responsible for the personal data processing rules applied by external websites to which links are placed on the website.
  4. The mere placement of a link to a social media profile does not mean that the Controller tracks users on the website for marketing purposes.

12. Data security

  1. The Controller applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration or unauthorised disclosure.
  2. These measures are adapted to the nature, scope, context and purposes of processing and to the risk of violation of the rights or freedoms of natural persons.
  3. The user should exercise caution when using the Internet, in particular by not sending data that is not necessary to handle the matter.

13. Changes to the Privacy and Cookies Policy

  1. The Controller may amend this Privacy and Cookies Policy in the event of:
    • changes in legal provisions,
    • changes in the website functionality,
    • changes in the manner of data processing,
    • implementation or removal of cookies, analytical or marketing tools,
    • changes in the Controller’s data,
    • the need to clarify information concerning data processing.
  2. The current version of the Privacy and Cookies Policy is published on the website.
  3. The amended Policy applies from the date of its publication, unless another date is indicated in the document.

14. Language versions

In the event of discrepancies between language versions of this Privacy and Cookies Policy, the Polish version shall prevail, unless mandatory provisions of law provide otherwise.


Obraz Codex 11 wrz 2026, 14_15_21

We would like to hear about your challenges and ambitions and offer a tailored solution.

Get in touch.