Privacy Policy

mirrorich Privacy Policy

If you don’t have much time, please find below a summary of how mirrorich processes your data.

Summary

This website is operated by mirrorichLTD, with its registered address at .

  1. ABOUT US. We are mirrorichLTD z ograniczoną odpowiedzialnością with its registered office at , Company no. . (, and we process the data, including Personal Data, of our Customers, the Users of our Website, other Personal Data subjects – as their controller. We also act as the processor – when we store the Personal Data entrusted by our Customers and allow them to carry out operations on such data using our tools and services.
  2. YOUR RIGHTS. You have the right to gain access, correct or delete your Personal Data. In some cases, you may also have other rights, such as the right to withdraw your consent, to object to the use of your data or the right to data portability, as explained in detail below.
  3. WHAT PERSONAL DATA WE PROCESS. We process data to provide the highest standard of service to our Customers and Users and to efficiently do business. The scope of the collected data and how they are used depend on how you use the Website and services, type of interactions with Us, and on your privacy settings. We collect data that you give us yourself, for example while filling out the form on the Website, logging in the Mobile App, enrolling on our webinar or creating a Service Account. We also collect the content and data you create, send and receive from other Users. We collect information about the applications, browsers and devices you use to access the Website or our Services, as well as about their interactions with the Website or the Services. We also receive data from third parties.
  4. WHY WE PROCESS YOUR DATA. As the data controller, we will process your data for example to allow you to create an Account, provide you with our Service and if you want – also with marketing materials. In order to adapt our Services, Website and content of messages to your preferences, we do profiling. We have the right to process your data for different reasons. The most important one is that we need it to carry out the contract concluded with you the moment you accept the mirrorich Terms of Service. There are also other reasons that allow us to use the data, for example preparing an answer to your queries or your consent to receive our newsletter.
  5. WHO WE DISCLOSE YOUR DATA TO. We disclose your data to service providers who support or assist us. These are companies from the group of affiliates or third parties with whom we have entered into appropriate agreements, whether within or outside the European Union. We may also disclose your data to public authorities, such as the Police, the Tax Office, if so requested under applicable laws.
  6. WE USE COOKIES AND OTHER SIMILAR TECHNOLOGIES. We use cookies (small text files saved on your device) and other similar technologies to provide the Service, improve efficiency and offer increasingly improved functionalities to the Website Users and Service Customers. Analysis of data from such technologies shows us which content on our Website or Service feature you find the most interesting and which is less popular. Cookies allow us also to store your preferences and settings, to handle your logging in the Service Account, fight fraud, and display targeted advertisements. We also allow some other entities to use cookies in line with the description in our Privacy Policy. You may disable or accept all or some of cookies and other similar technologies used by us and our service providers on your own at any time. Depending on the technology used, the disabling may take place either through web browser settings or through the opt-out option available on the service provider’s site.

Please read the entire content of our Privacy Policy below to fully understand how we will process your data and how you can exercise your related rights.

Privacy Policy

This Privacy Policy lays down the rules of protecting mirrorich Service Customers, Users, and other Personal Data subjects, in connection with the processing of their data. We value your trust and we do the utmost to help you feel in control of your data. Below we have described, as transparently as possible, the scope of the data we process in connection with the use of our Service, Mobile App and Website, the purposes and methods of the processing, the data security rules and your rights related to the processing.

Use of the Website, the Service or the Mobile App means acceptance of all the rules followed by mirrorich so please learn their content beforehand. If you do not agree to the rules laid down in this Privacy Policy, do not commence the use of our Services, the Mobile App and Website.

I. Who are we and how can you contact us?

1. mirrorich as a Data Controller

Controller of your Personal Data provided in connection with using the Service, the Mobile App or the Website is mirrorichLTD with its registered office at .
Our contact details:

  • address:

We have created a dedicated e-mail address for you to contact us to exercise your rights, give or withdraw consents or for any other issues connected with the protection of Personal Data: [email protected].

2. Data Protection Officer

We have appointed a Data Protection Officer here at mirrorich. You may contact the Data Protection Officer in all matters related to the processing of Personal Data and to use of the related rights. You may contact the Data Protection Officer by:

  • e-mail: [email protected]
  • in writing: Inspektor Ochrony Danych (Data Protection Officer), mirrorichLTD,

3. mirrorich as a Data Processor

In some circumstances we also process Personal Data on your behalf. In these cases you determine the scope of Personal Data you want us to process and the means of their processing, especially through your use of our Service. You can find more about this matter in section VII.3. of this Privacy Policy.

II. From what sources and what data do we collect?

The sources from which we obtain data depend on the context of your interaction with mirrorich and our Services.

If you are asked to give your Personal Data, you have the right to refuse. And if you decide against providing the data required to use a particular Service or Mobile App, you may be unable to use some of its elements, to order some Service plans, or obtain information or help from mirrorich

1. Data you give us directly

We receive some data directly from you, for instance when you are creating a Service Account, filling out a contact form, managing the Account, filling out your profile details, enrolling on a webinar organised by mirrorich, contacting us for technical assistance, posting comments on our blog.

We present below groups of information coming directly from Customers, Users, and other Personal Data subjects.

Contact Information Basic Personal Datat that identify You and enable us to provide you with the Service or contact you. They include such data as your name, email, address, phone number
Account related Data Personal Data that You provide in the “Account Settings” tab, including: first name, last name, company or business name, address, email address, phone number, tax ID number, country, time zone, transaction data necessary to process payments, as well as other optional information such as image, avatar, “About Me” information.
Content Messages, chat files, audio files, video files, documents, text files, presentations, recordings, contact lists, and other information that You posted to your Account, shared or generated during an Event. The detailed scope and rules related to the Content are set forth in the General Terms of Services.
Other communication Information You provide when you contact us for assistance, information, complaints or other purposes. In addition to your Contact Information, it may include information related to your use of our Services, copies of your messages, and other information useful in handling your case. It also includes information about your use of customer service features, questions you ask, your feedback, responses to surveys on various topics, blog comments.

2. Data received from third-party entities

We also receive data from third-party sources such as:

  • our , including marketing partners, with whom we work to deliver marketing content. For instance if you are giving us access to data in your mail account or social media network when you are creating an Account or when you give those providers consent for using your data for analytic, statistic or advertising (remarketing) purposes.
  • Service providers with whom we have integrated the Website or Services. For example, payment services providers may provide us with updated information about your payment method to enable us to collect payment due for your subscription to the Service.
  • Individuals who submit reports to us regarding activities at Events that you organize. Such individuals may provide us with your Contact Information, information about your interactions, and messages transmitted at the Event or in chat to report abuse or other violations of our General Terms of Services or applicable laws.
  • publicly available sources, such as the Central Registration and Information on Business (CEiDG) database or the National Court Register (KRS).
  • The Internet, primarily social media, for example Linkedin.
  • Participants of Events organised through the Service, whether you participate in them or organise them.

3. Data obtained automatically during use of Website or Services

Whenever you use our Services, the Mobile App or the Website, also as an Event Participant, we record your visits and your interactions with Services, the Mobile App or the Website.

Furthermore, when you contact us for troubleshooting or support, we collect detailed data connected with the incident you are reporting, including information about the condition and configuration of your device and Service at the moment of error occurrence and analysis.

We treat all such information as Personal Data when they are tied to your Service Account or with other “hard data” that identify you directly. Otherwise such data are in principle non-personal data.

We present below group of Personal Data and non-personal data, that we collect automatically.

Usage data Data about your use of the Service, Mobile Application or Website, the performance of our Services, Mobile Application and Service, the functionalities you use, the Website pages you visit and the links or content you click on, the settings you select, the problems you experience in using the Services, Mobile Application or Website. These activities are recorded, among other things, in our system and application logs. In connection with the above-described activities, we also receive information about the URL of the site you came from and the destination website when you leave the Website or stop using the Service.
Device data Information about your computer and mobile hardware (computer, phone) and peripherals that you use when using the Service, Mobile Application or Website. This may include, for example, information about speakers, microphone, camera, operating system version, IP address, web browser, device attributes.
Transmission data Data processed for the purpose of transmitting electronic messages. This includes such information as the length, time of the message (duration of the Event), start, end or length of the connection.
General location information Information about your general location (country, city) not based on GPS, which we determine from your IP address or other information such as the area code of your phone number.
Data collected through cookies The data regarding your activity in the Service, Mobile App or on the Website, which are recorded and stored through cookies or similar technologies. For instance: search history, clicks on the Website or within the Account or Mobile App, visits on the homepage and pages of the Website, dates of registering and logging into the Account, data about the use of specific services on the Website and in the Mobile App or the Service, history and your activity connected with our e-mail communications with you. We use cookies and similar technologies to improve performance and offer our Website, Mobile App and Service users further functionality improvements. We also allow some other entities to use such technologies in line with the description in our Privacy Policy. You will learn more about cookies and similar technologies in 

III. How do we use your data? Your data and how we process them.

The rules that govern the processing of your data differ depending on whether you are our Customer or a Website or Mobile App User. The purposes, scope of the data we process and legal grounds of such processing vary. Below you will find information about the legal grounds for data processing in the context of the specific purposes for which we need them.

1. Providing services

We process your data because this is required for you to use the Service, the Mobile App or Website. In other words, for you to be able to register as a Customer, use the Mobile App or order our materials as a User, we must process your Personal Data because otherwise we would be unable to provide you with the service you request (necessity for contract performance or service provision – – Article 6(1)(b) of the GDPR).

mirrorich's service provision includes the following actions: administrative activities connected with the conclusion of the Service contract under the mirrorich Terms of Service, Account creation and Customer authentication on the Website, as well as Service provision, , saving your preference settings in your Account, monitoring the Services to ensure their security and continuity, rendering the Mobile App available and delivery of the content ordered by Users, also Users who do not have an account but use the Website, actions taken to provide Customer and User service, complaint examination, invoicing, fee collection, and Service quality control.

2. Legitimate business interest

We process data for purposes connected with mirrorich's legitimate interest, depending on the types of ties between us and our Customers or Users (Article 6(1)(f) of the GDPR).

  1. For analytical and development purposes. We process data to manage Service, Mobile App and Website use statistic, to improve and facilitate Service, Mobile App and Website use and to ensure the IT security of the Service, Website and Mobile App. We believe that we have a legitimate interest in analysing the Service, Mobile App and Website performance, their use and the satisfaction of our Customers and Users. We also believe that the processing of such data is beneficial to our Customers and Users as our goal is to improve the Website performance and provide higher quality of Service and the Mobile App.
  2. To the claim and defence of rights. We believe that we have a legitimate interest in data processing where required for us to claim damages in connection with Service, Mobile App or Website use that is unlawful or in violation of the General Terms of Services or to defend against claims raised by Customers, Users or third parties.
  3. To communicate with Users and Customers. We believe that we have a legitimate interest in replying to the requests, complaints or questions you have submitted through the existing contact channels and for this purpose process data that are necessary to answer your inquiry. We assume that the processing of such data is also beneficial for you because it allows us to properly assist and reply to your communications. We also have the right to use your Personal Data (primarily Contact Information) to the extent necessary to inform you of updates to our features on the Services, changes to our Privacy Policy, General Terms of Services or other legal documents, or to provide accounting information.
  4.  To check customer satisfaction and improve Services. We believe that we have a legitimate interest in checking whether our Customers and Users are satisfied with our Services or Website and how we could improve the quality of the Website, Mobile App, and our Services. For this purpose, we may process our Customers’ data, especially those contained in the responses to our questions from surveys and forms used in the survey.
  5.  For fraud prevention. We believe that we have a legitimate interest in monitoring, preventing, detecting and combating fraud and abuse, and in connection therewith conducting the required verifications to achieve this purpose. We understand that the processing of such data is beneficial for everyone, and in particular for you and your clients, because it helps us establish the measures to protect your and your recipients against transmission of malware, attempts to disrupt your Events or fraud attempts by third parties.
  6. For direct marketing purposes. When a business relationship develops between you and mirrorich, particularly in connection with your use of the Service or conducting advanced discussions aimed at entering into a contract for the provision of Services, we believe that we have a legitimate interest to direct communications to you that constitute direct marketing of our Services. We assume that processing your Personal Data for this purpose is beneficial to you because it enables you to conveniently update your knowledge of mirrorich's offerings and, consequently, to more effectively manage the cost of the Services you purchase from mirrorich.

3. Sending marketing and promotional communications

Unless the provision of marketing or promotional content to you results directly from your request to mirrorich, we process your Personal Data for the purposes of conducting marketing and promotional campaigns based on your explicit consent (Article 6(1)(a) of the GDPR).

4. Providing personalized content and Services

We want our Service and Website, including the communications addressed to you, such as marketing or on-boarding communications or Service tips, to match your needs and preferences as much as possible (profiling). Below we describe what this is about.

If you have agreed as a User to receive commercial information from us or established a business relationship with us in connection with your use of the Service, we have a legitimate interest to process your Personal Data and for that purpose create Customer or User profile. We will adapt advertising and marketing content regarding our Services to the profile. Without your prior consent we will not send you any communications regarding the products or services of other entities.

We believe that we have a legitimate interest in analysing how our Services and Website are used by the Customers and Users so that we can improve them and help increase the number of Customers and Users who use them.

Website Users who wish to receive commercial information to the specified e-mail actions act based on voluntary, conscious and definite consent so we believe that they can reasonably expect us to send such personalized communications and process their Personal Data for that purpose; similarly, our Customers, who ordered the Service, can reasonably expect to receive news and other marketing communication pertaining to our Service. These people also expect the communications they receive to match their interests. Adapted marketing communications addressed to Customers let them use beneficial special offers and allow them to make an optimal use of our Service.

At the same time, we do the profiling only based on the data provided by them or data regarding their activity within the Service or Website. We are interested only in information related to your use of the Service or Website and not what you do on other websites.

As a result, we believe that our interest is legitimate, lawful and free of violations of any overriding User or Customer rights.

5. Complying with legal obligations

Based on applicable law, various regulatory authorities, law enforcement agencies or other public authorities may oblige us to grant access to, preserve or disclose certain information. For example, we may be obliged to provide information about You for the purposes of civil or criminal court proceedings, or proceedings conducted by regulatory authorities in the area of ​​​​Personal Data protection, electronic communications. In such cases, we have a legal obligation to comply with such a request and process your data within the limits of the imposed obligation (Article 6(1)(c) of the GDPR).

IV. To whom do we disclose your data?

1. Data disclosure within Service

Profile Page – the data on your profile page are fully visible outside the Service area (e.g. to users of third party search engines). We believe that default settings where the profile page is public are expected and beneficial for you, your Participants and invitees because this helps you promote your activity and planned Events online and the concerned parties obtain the required information about you and your planned public Events. You may decide about the availability of your profile website at any time and about the visibility of some of its parts through your Account settings.

Events – if you participate in an Event organised through the Service, your first and last name, if you provided it during registration for the event, as well as any information you provide on chat during the Event chat may be visible to other Participants of the Event. Additionally, if you have an audio or video transmission authorisation, your voice or image will be shared with other Participants of that Event. The Event host may decide to share the Event recording with a broader audience, for instance to publish it on his/her YouTube channel or carry out a live broadcast – in such case other people will be able to see your Personal Data visible in the recording. If you use the “live transcription” feature to generate captions during an Event, we transmit the audio recording of the Event to your browser provider for transcription. Once the transcript is generated, the audio analysis is not retained.

Integrations – if you integrate your Service Account with services of other providers, the content and data you have uploaded to your Account may be shared with such providers or downloaded from such services. For instance, you may integrate your Account with your CRM account to automatically export there your list of Participants from the Event or integrate with your mailbox account and import your address book to your Account. Such activities enable you to use the imported or exported data to send invitations to an Event you organise through the Service. In addition, if during the use of the Service you present content from YouTube Platform or publish your Content on that Platform using our integration with YouTube API Services, data related to your Event and the use of YouTube API Services will be processed by YouTube in accordance with the privacy policy .

2. Other data recipients

We transfer your data to the following categories of recipients:

  • Processors. We use providers who process your Personal Data only at our instruction, as processors acting on our behalf. They provide services covering certain functionalities of the Service (sending e-mails), hosting services, Customer service support and services connected with security incident tracing and response, troubleshooting and problem solving in the Service or on the Website, for the purpose of Website traffic analysis and analysis of the success of marketing campaigns.
  •  Other controllers. We work with entities who do not act exclusively on our instructions and who independently establish the purpose and methods of processing your Personal Data or non-personal data. Those are, for instance: payment institutions that enable you to pay for the Service online, telecommunications service providers through which we enable you to join the Event by telephone. We use the services of such third parties (controllers) also to reach you with our marketing communications outside the Website. Their services involve presenting our marketing communications to you on websites other than the Website. To that end, the third-party controllers install e.g. a code or pixel to collect information about your activity within the Website or the Service. You will learn more about this in Chapter V of this Privacy Policy.
  • Public authority. We provide your Personal Data if requested by competent public authorities in connection with their legal obligation to perform a public function. We provide the data exclusively at a written request of the authority filed on a case-by-case basis.
  • mirrorich affiliates. We provide your Personal Data to GetResponse SA, a company with personal ties to mirrorich, to efficiently provide Services to Customers.

In addition, we may share information that does not represent Personal Data with the public, including data collected via cookies or similar technologies, especially in the form of aggregate information about trends in Website, Service and Mobile App use, and communicate them to other partners, including publishers and providers of analytical technologies. We also allow specific providers to collect data from your browser for advertising and measurement purposes using cookies or similar technologies.

3. To which countries are my data transferred?

The providers to whom we transfer Personal Data are based mostly in Poland and in other Countries of the European Economic Area (EEA), e.g. the Netherlands or Germany. Some of them are based outside of the EEA. In connection with the transfer of your Personal Data outside the EEA, we have made sure that our providers signed appropriate data processing agreements with us and gave their guarantees of top-level data protection. Depending on the provider, these guarantees arise from:

  • European Commission Decision on the adequate protection of personal data under Article 45(1) of the GDPR. More information about such decisions: 
  • the obligation to apply standard contractual clauses adopted by the Commission (EU) based on Article 46(2)(c) of the GDPR; or
  • Participation by US providers in the US Department of Commerce’s Data Privacy Framework Program. This is a program that providers can join, as long as they commit to the US-Swiss and UK data privacy principles (as part of the EU-related rules). More information about the Data Privacy Framework Program and certificates of participation is available at: .

V. Cookies and similar technologies

1. Can you manage cookies and other similar technologies and how?

We mention this first – you may manage (disable or accept) cookies and other similar technologies used by us and our service providers on your own at any time.

Depending on the technology used – the data storage, the managing may take place in different ways.

How can you manage cookies? How can you manage similar technologies?
Via your web browser.
The web browser you use may allow cookies and similar technologies by default.

Here is information how you can manage cookies on your device in:

Here is information how you can manage some of similar technologies on your device in:

Via Privacy Preference Center available in the footer of out Website. Via opt-out functions on websites of solution providers.
You can find the information on providers and their websites here
Via mechanisms regarding ad targeting.
Here is information how you can disable cookies and similar technologies for ad targeting on your device:

    Remember that change of settings may cause problems with proper use of certain Website or the Service elements and block proper upload of page, especially where logging in to the Account is required.

    2. Cookies and similar technologies – types

    Cookies are a type of technology that records data and collects it from the devices you use when visiting our Website or using the Services. Cookies are created automatically by the web browser you use and can only be read by the website they came from.

    Aside from cookies on the Website and within the Service, we and the providers of the tools and services that we use apply other technologies that allow to save information in your system/web browser through data storage (Session Storage, Local Storage, IndexedDB) as well as Tags.

    See below for a description of the types of cookies and similar technologies.

    TECHNOLOGY TYPE

    DESCRIPTION of application

    Session cookies

    Session cookies are created in the system-user browser each time a user session is created, i.e. after the browser connects with the site.

    Session cookies expire after the user session expires – e.g, after the web browser window is closed. The information contained in session cookies are then automatically deleted.

    Persistent cookies

    Persistent cookies are created in the system – in the user’s browser after the first visit on the site or after completing a certain action.

    Unlike session cookies, persistent cookies are not deleted upon the end of the user’s session. Persistent cookies are deleted by the user’s browser automatically after a specific period. They can also be deleted manually by the user.

    Session Storage

    Data storage with the same function as cookies but with much larger data capacity (cookies have limitations connected with their quantity and the quantity of the data they can contain). Information from Session Storage is recorded and read only if clearly requested by the server, and sent to the website user’s browser. The data gathered in Session Storage are deleted just like session cookies – after the browser window is closed.

    Local Storage

    Data storage for information that are kept permanently in the system/web browser of the user until deleted. Data saved in Local Storage are not automatically available through the web server presenting a particular site but by relevant scripts (java script, flash) placed on the website or sent to the user’s browser from other servers (e.g. through placement of a partial code coming from another web server – Facebook, Twitter, Google social media icons).

    IndexedDB

    Data storage representing an internal database of a web browser that is used to store large data quantities. The storage makes it possible to store data in a structured form and as files. Data stored as objects to which access is limited only for specific data sources – the domains or subdomains from which they were saved.

    Tags

    Partial codes of the analytical tools that permit saving cookies or other technologies in the domains of those tools. Most tags simply describe the content of the page, but certain types of tags contain programmatic elements or inject dynamic content like video or audio files into the page.

    The usage of third-party cookies and similar technologies on our Website and within the Service takes place on the terms set out in privacy policies of providers who generate such cookies or similar technologies. These third-party services are outside of our control. The providers may, at any time, change their terms of services, purpose of use of cookies and other similar technologies. The current list of our partners whose services we use or whose technologies we place on the Website or in the Service and information about is available

    3. Why do we use cookies and similar technologies?

    We use cookies and similar technologies to improve performance and offer our Website, Service and Mobile App users further functionality improvements. Analysis of the data saved based on the use of cookies and similar technologies shows which content is the most interesting for the Users and Customers, and which content is less popular.

    At the same time, the use of anonymous cookies and similar technologies allows us to present better content without the need to send surveys and act through trial and error. We are able to define what can be easily improved and which elements to avoid, which ultimately renders our Website, the Mobile App and Services more user-friendly. Below you will find a description of use of particular technologies.

    PURPOSE

    TECHNOLOGY TYPE

    SCOPE OF USE

    Analytics and statistics

    Cookies, Local Storage, Session Storage, IndexedDB

    The information processed in such storage is used for analysing, developing statistics, monitoring the behaviour of Users and Customers on the Website and in the Services, and presenting our advertisement (on our Website and on other sites managed by the marketing platforms we use), which ultimately helps us improve the Website and the Services.

    User authorisation

    Cookies, Storage

    The information processed in such storage is used for User authorisation in the IT System of the Service or Mobile App. With the information contained in such storage, we are able to properly recognise a Service or Mobile App User.

    Service configuration

    Cookies, Local Storage, Tags

    The information processed in such storage is used to store the preferred settings you have chosen within the Website, the Mobile App and the Services. With the information contained in such storage we can memorise the settings and configuration of the Website, the Mobile App and the Services and of selected elements, page views.

    Interface language settings

    Cookies, Storage

    The information processed in such storage is used to store the Website, Mobile App or Service language settings you have chosen. With the information contained in such storage we can always display the right language version for you.

    Advertising

    Cookies

    The information processed in such storage is used to deliver general advertising to the Users and the Customers as well as advertising matching their preferences and remarketing.

    A detailed list of cookies on our Website and Services is available

    A list of cookies that may be placed on so-called webinar pages, depending on the type of features used by the Customer is available

     

    VI. Your rights. You have control over your data

    1. General Information

    We make sure that our Customers and Users can exercise their rights concerning their data.

    You may exercise your rights by submitting your complete request to the following email address [email protected]. All you need to do is to inform us about the reason behind your request and specify the right you want to exercise.

    If you have an Account in the Service, you can exercise some of your rights directly in Privacy Settings after you log in to your Account. Please remember that if you change your Privacy Settings, it may take us a little time to apply your changes in our systems for technical reasons. That’s why during this time our system may for example still send you an email message you have unsubscribed from while your settings are being updated.

    For requests concerning the protection of Personal Data, information security, we reserve the right to respond within 30 days from the date of receipt of a complete request. If it is not possible to respond within 30 days, we will inform you of the possible expected date for a final response. If we decide this is necessary for identification purposes or to handle your inquiry, we may ask you some additional questions or ask you to provide us with additional documents to confirm your identity.

    2. Right to give and withdraw your consent

    If we ask for consent, you can always choose whether to give it or not. In addition, you may withdraw any consent you have granted while creating an Account or using the Website at any time. This also applies to:

    • receive commercial information by electronic means to your e-mail address,
    • to the collection of your data through cookies. More about this in Chapter V of the Privacy Policy.

    Consent withdrawal is effective as of the moment of it being withdrawn. Your withdrawal does not affect any prior processing of your data. Consent withdrawal does not have any negative consequences for you. Still, you may become unable to further use some functionalities of the Service or Website which the law only allows us to provide if we have your consent (e.g. the newsletter).

    You can withdraw your consent using a few simple methods:

    • by submitting your request to our Customer Success Team via email or live chat;
    • by clicking “unsubscribe” in the message you have received;
    • for consent to cookies or similar technologies – by using one of the methods described in Chapter V of this Privacy Policy;
    • if you use the YouTube API Service integration – you may revoke access of the Service to your data via the Google security settings page at

    We treat withdrawal of your consent to commercial information as your objection to the processing of your Personal Data for direct marketing purposes, including profiling for that purpose.

    3. Right of access

    You have the right to receive information on whether or not we process your Personal Data from us. If we do, you have the right to receive:

    • information about the rules according to which we process your Personal Data,
    • access to your Personal Data,
    • a copy of your Personal Data.

    If you have your Account in the Service, you are able to obtain direct access to the majority of your Personal Data at any time after logging in the Account.

    We will not charge you for the first copy of your data. For any other requests for copies of data, we may charge a fee corresponding to the administrative costs connected with preparing that information.

    4. Right to rectification

    You have the right to demand correcting and completing Personal Data you have provided. You may do this on your own in Privacy Settings in your Account. In respect of other Personal Data, you have the right to request that we rectify them (if they are incorrect) or supplement them (if they are incomplete).

    5. Right to erasure (“right to be forgotten”)

    n the cases specified by the law, you have the right to request that we erase the Personal Data that concern you. We will treat a request to erase all Personal Data as a request to delete your Account.

    You have the right to request Personal Data erasure if:

    • the data processing violates the law or if we have to erase the data to satisfy a legal obligation,
    • your Personal Data are no longer required for the purposes for which they were processed,
    • you withdrew your consent to Personal Data processing (insofar as the consent represented a legal ground for the processing),
    • you have objected to the processing of your Personal Data for marketing purposes,
    • you have objected to the processing of your Personal Data for the purpose of statistics regarding Service or Website use and satisfaction research, and the objection was considered justified.

    We will retain some of your Personal Data despite your request to erase them if this is required for us to satisfy a legal obligation or for the establishment, exercise or defence of claim. This applies in particular to such Personal Data as: first name, last name, e-mail address, history of using the Service or Website; we retain this data for the purpose of examination of any complaints and claims connected with the use of the Service or Website.

    6. Right to restriction of processing

    You have the right to request restriction of the processing of your Personal Data. If you make such a request, you will be unable to use certain functionalities of the Service, the Mobile App or Website until your request is considered if the use of such functionalities will entail the processing of the data covered by the request. We will not send you any communications, including marketing communications, either.

    You have the right to request restriction of the use of your Personal Data:

    • When you question the correctness of your Personal Data – we will then limit their use for the time required to check the correctness of your data but not for more than 30 days,
    • If the processing of your data is unlawful, and you request restriction of processing instead of data erasure,
    • When your Personal Data are not longer required for the purposes for which we have collected or used them but you need them to establish, exercise or defend claims.
    • If you have objected to the use of your Personal Data – the restriction then takes place for the time required to determine whether, due to your particular situation, the protection of your interests, rights and freedoms overrides the interests we pursue by processing your Personal Data.

    7. Right to object to data processing

    You have the right to object to the use of your Personal Data if we process your Personal Data based on our legitimate interests. We have already described such cases above in Chapter III of this Privacy Policy.

    In particular, you have the right to object at any time to the processing of your Personal Data for direct marketing purposes, which include creating your customer profile. In such a case, we will not longer process your data for that purpose and we will no longer send you marketing information.

    Additionally, withdrawal of the consent to the commercial information regarding our Services will mean your objection to the processing of your data for direct marketing purposes, including for the development of your customer profile.

    In relation to the processing described in section III.2 of the Privacy Policy, if your objection turns out to be justified and we will have no other legal ground to process your Personal Data, we will delete the data to the processing of which you objected.

    8. Right to data portability

    If you have created an Account with us or agreed to the processing of your Personal Data, you have the right to receive the Personal Data that concern you which you have provided to us in a structured, commonly used, machine-readable and interoperational format that permits sending them to another controller. We will send you your Personal Data in the form of a csv file. The csv format is a commonly used, machine-readable format that permits sending the received Personal Data to another controller.

    If technically feasible, you have the right to request that we send your Personal Data directly to anther controller. Just remember that controllers are not legally obligated to keep technically compatible processing systems.

    9. Right to lodge a complaint with a supervisory authority

    Please be informed that you have the right to complain about the processing of your Personal Data to a supervisory authority; in Poland this is the President of the Personal Data Protection Office, contact details: ul. Stawki 2, 00-193 Warsaw, Poland.

    VII. Other useful information

    1. Do I have to give mirrorich my data?

    We sometimes ask you for your Personal Data. Some data (marked as mandatory) in registration forms are required for Account registration or sending of the ordered materials or for participation in an event of your choice. Their consequence is inability to use some or all of the Website, the Mobile App or Service functionalities. Any data other than mandatory and Data specified in the Account details are given on a voluntary basis.

    2. How long do we retain your data?

    If you are our Customer, we retain the Personal Data of third parties which you have provided to us for processing for as long as you have an Account in the Service. After Account cancellation, your data will be retained for 30 days, only to allow you to reactivate your Account, should you wish to do this. As regards Expired Accounts or Enterprise Accounts the storage period is extended to 90 days from Account deactivation date. By doing this we want to allow you to renew your Service subscription smoothly, that is without losing data, without the necessity to re-configure the Account or uploading the Content again. During that time, your data will only be processed for your account and they will not be subject to any other operations, unless we are otherwise required under applicable laws or by competent authorities. After that time, we will delete your Personal Data from the main database, without the possibility to recover it. In the next 120 days, your Personal Data will be subject to encryption and stored in backup copies only. The said 120-day period is required to delete the Personal Data completely due to the specifics of the backup copy operations.

    We retain data of Users who are not our Customers for the time corresponding to the life cycle of the cookies or similiar technologies saved on their devices.

    We will process the Personal Data of our newsletter subscribers or those who have agreed to receive commercial information from us until they unsubscribe from the newsletter or the commercial information.

    Upon the expiry of the above periods, your Personal Data will be anonymised or deleted, except for the following data: first name, last name, e-mail address, history of Service use, information about the consents granted – we will retain such data for another period as required for the purpose of complaint examination, compliance with accounting and tax legislation and handling of claims connected with the use of the Service, the Mobile App or the Website or communication sent.

    3. Why do I enter into a Data Processing Agreement with mirrorich?

    If you are our Customer and you run a business within the European Economic Area or in any other cases where the GDPR applies to your business, you entrust to mirrorich the processing of the Personal Data needed for Service provision on the terms as set forth in the Data Processing Agreement (DPA), which forms and integral part of the Terms of Service and is available for download in the Customer Account.

    In respect of the Personal Data you entrust to us for processing, you are the one to decide about the purposes and means of processing such data as their controller or you act on behalf of the controller of such data. Make sure you have secured consents to the processing of the data which you entrust to us.

    4. Does mirrorich process Personal Data of children or special categories of data?

    Acting as a data controller, we do not process the Personal Data of children and we do not collect special categories of data.

    The Service, the Mobile App and the Website are addressed to people of legal age, that is over the age of 18 (eighteen) and those who run a business. By commencing the use of the Service, the Mobile App or Website, you declare that you are 18. If you are a minor, please do not give us any information, Personal Data in particular.

    If you entrust us with the processing of special categories of Personal Data or Personal Data of children, you represent that you have the legally required consents to the processing of the special categories of Personal Data listed in Article 9 of the GDPR, the Personal Data relating to criminal convictions and offences referred to in Article 10 of the GDPR and Personal Data of children, or you have other valid legal ground for such Personal Data processing and that you consider the security measures put in place by mirrorich as sufficient for the protection of the entrusted Personal Data.

    5. How does mirrorich protect my Personal Data?

    We have implemented appropriate and effective measures to ensure the security of your data in accordance with current industry standards. We use various encryption methods, alternative procedures and data centers in case of cyber attacks or other emergencies. We also perform regular penetration tests.

    More about security.

    6. Update of our Privacy Policy

    We may amend and supplement the Privacy Policy from time to time as needed. We will inform you about any changes or supplements by posting relevant information on the Website, and in the case of major changes we may also send you a notice to your e-mail address or to your Account.

    The Privacy Policy does not limit any rights you have under the Terms of Service and applicable laws.

    VIII. Basic terms

    Here are the basic terms that will help you better understand this Policy:

    Personal Data

    The data of our Customers, data entrusted to us by our Customers for processing, data of our Users nad of other individuals, processed in connection with the use of the Service, the Mobile App or Website or other interactions with us. Personal Data are only such data that represent information about an identified or a directly or indirectly identifiable natural person, i.e. such data as first name, last name, e-mail address etc. In the classification of information to Personal Data we consider objective factor, such as available technology at the time of the processing, and the cost and time required to identify a person. For these reasons we treat, in principle, data obtained automatically during the use of the Website, the Mobile App or the Services as non-personal data, unless they are tied to your Service Account or with other “hard data” that identify you directly.

    mirrorich (us)

    mirrorichLTD with its registered office at , company no., VAT ID no. .

    Customer

    A person using the Service for their business or professional purposes, notwithstanding the legal form of the business.

    Account

    Individual space provided to the Customer within the mirrorich Website to allow them to use the Service.

    Expired Account An Account that has an unpaid status for a period not exceeding 90 days. This Account has retained Content, but blocked functionalities of the mirrorich Platform. If the Customer continues to fail to pay the fee, the Customer is deemed to have abandoned further use of the mirrorich Platform, resulting in termination of the Agreement.

    Event

    A webinar or online meeting organized with the use of the Service or Mobile App; the term also includes “Conferences” organized as part of the ClickConference service.

    Processing

    Operations on data, including Personal Data, such as collection, recording, retention, development, modification, sharing, backup of data and other operations as necessary for Service or Mobile App performance or Website use.

    GDPR

    Regulation 2016/679 of the European Parliament and of the Council (EU) of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

    Website

    Sites of mirrorich, available especially at the following address: mirrorich. The Customer may log in to their Account in mirrorich Platform through the Website.

    Service(s)

    Any Services provided by mirrorich by electronic means, including on a Software-as-a-Service (Saas) basis, which include in particular allowing the Customer to use the mirrorich Platform.

    Mobile App

    Application for mobile devices created by mirrorich for the purpose of enabling Presenters and Attendees to organize and participate in Events via their mobile devices.

    Privacy Settings

    The space within the Account where the Customer may manage their privacy protection preferences and exercise the rights as a data subject.

    User

    A person using the Website or the Mobile App.

    Any capitalised terms not defined above shall have the meanings as specified in the General Terms of Services.

    Version: 2024-10-31