1. Data controller
The controller of personal data collected via the website is Thermonext Michał Sendrowski with its registered office at ul. Olszowa 8B, 18-400 Konarzyce, Poland, tax ID (NIP) 7182165488 (the “Controller” or “we”).
For any matters concerning personal data, you can contact us by e-mail at [email protected] or in writing to our registered address.
2. What data we process and where it comes from
We only process data that you provide yourself or that your browser generates during your visit:
- Contact and demo request forms: e-mail address and — if provided — name, company name, phone number, industry and message content.
- Newsletter: e-mail address.
- Technical visit data: IP address, cookie identifiers, browser and device information and visit statistics — to the extent described in the Cookie policy and only in line with the consents you have given.
- Page interaction data (cursor movement, clicks, scrolling) collected by the Microsoft Clarity tool — only after you consent to analytics cookies.
3. Purposes and legal bases of processing
We process data for the following purposes and on the following bases:
- Handling enquiries from the contact and demo forms — steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) and, for enquiries unrelated to a contract, our legitimate interest in conducting correspondence (Art. 6(1)(f) GDPR).
- Sending the newsletter — your voluntary consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
- Analytics, visit statistics and possible marketing activities — your consent given in the cookie banner (Art. 6(1)(a) GDPR in conjunction with electronic communications law).
- Website security (including protecting forms against bots) — our legitimate interest (Art. 6(1)(f) GDPR).
- Establishing, exercising or defending legal claims — our legitimate interest (Art. 6(1)(f) GDPR).
4. Data recipients
We do not sell your data. We share it only with trusted service providers acting on our behalf (processors) or as independent controllers within their own services:
- Cloudflare, Inc. (USA) — website hosting and delivery (CDN), form handling, and protection against bots and abuse; processor.
- Resend (USA) — e-mail delivery (system replies, newsletter); processor.
- Google Ireland Limited (Ireland) — analytics tools (Google Analytics 4, Google Tag Manager — visit statistics) operating only after consent, respecting Consent Mode v2 settings; processor.
- Microsoft Ireland Operations Ltd (Ireland) — (a) e-mail and office tools used to handle correspondence and (b) the Microsoft Clarity tool used to analyse how the website is used (anonymised heatmaps and session recordings), operating only after you consent to analytics cookies; processor.
- SMSAPI sp. z o.o. (Poland) — SMS gateway used when you ask to be contacted by phone/SMS in response to a form enquiry; processor. SMS notifications within the Nextriv application are covered by the application's separate documentation.
- Entities supporting our business under law or contracts: e.g. accounting and legal services (processors or independent controllers, depending on the service), as well as public authorities where disclosure is required by law.
5. Transfers outside the EEA
Some of our providers (including Cloudflare, Google, Microsoft and Resend) are established or operate data centres outside the European Economic Area, in particular in the USA. In such cases, transfers rely on GDPR-approved mechanisms: adequacy decisions (including the EU–US Data Privacy Framework for certified providers) or Standard Contractual Clauses (SCCs) with supplementary safeguards.
More information about these mechanisms is available on the EU–US Data Privacy Framework website (www.dataprivacyframework.gov) and on the European Commission's website on Standard Contractual Clauses (commission.europa.eu). You can obtain information about the safeguards applied by a specific provider by contacting us at the address given in section 1.
6. How long we keep data
Retention depends on the purpose of processing:
- Form correspondence — for the time needed to handle the matter, and then for the limitation period of any related claims (as a rule 3 years for claims connected with business activity, counted in line with Article 118 of the Polish Civil Code).
- Newsletter — until consent is withdrawn (unsubscribing); after that we may keep limited data evidencing that consent was given and withdrawn (accountability).
- Analytics data — for the periods described in the Cookie policy and the configuration of the analytics tools.
- Data processed on the basis of consent — at the latest until consent is withdrawn.
7. Your rights
Under the GDPR you have the following rights. We respond to related requests without undue delay and at the latest within one month of receipt (Art. 12(3) GDPR); for particularly complex matters this period may be extended by a further two months, of which we will inform you.
- the right of access to your data and to obtain a copy (Art. 15),
- the right to rectification (Art. 16),
- the right to erasure (Art. 17),
- the right to restriction of processing (Art. 18),
- the right to data portability for data processed on the basis of consent or a contract (Art. 20),
- the right to object to processing based on legitimate interest (Art. 21); an objection to processing for direct marketing purposes is always effective (Art. 21(2)),
- the right to withdraw consent at any time — without affecting the lawfulness of processing carried out before withdrawal.
8. Complaint to the supervisory authority
If you believe we process your data unlawfully, you may lodge a complaint with the President of the Polish Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, www.uodo.gov.pl, or with the supervisory authority of the EU/EEA country of your habitual residence, place of work or the place of the alleged infringement. We encourage you to contact us first — most issues can be resolved directly.
9. Voluntary nature of data provision and automated decisions
Providing data is voluntary but necessary for the given purpose: without an e-mail address we cannot reply to a form message or send the newsletter.
We do not make decisions about you based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect you.
10. Changes to this policy
This policy may be updated, e.g. when providers or regulations change. The current version, with the last-updated date, is always available on this page. We will communicate material changes visibly on the website.
11. Nextriv mobile applications
This section applies to the Nextriv mobile applications (Android and iOS), used to access the nextriv.app service. The data controller is the entity indicated in section 1; with respect to the data of the organisation using the service (e.g. sensor readings, team member data entered by the organisation) we act as a processor on that organisation's behalf — under the terms of the Data Processing Agreement (DPA). Within the applications we process:
- Account and sign-in data: e-mail address, name, role within the organisation and session tokens — stored solely in the device's secure system storage; purpose: provision of the service (Art. 6(1)(b) GDPR).
- Profile picture (avatar) — only if you add one yourself; you can remove it at any time in the settings.
- Push notification token — a technical device identifier used solely to deliver the notifications requested by your organisation (e.g. sensor alarms); removed upon sign-out. Delivery providers: Firebase Cloud Messaging (Google Ireland Ltd) and, on iOS, additionally the Apple Push Notification service (Apple Distribution International Ltd).
- Application crash diagnostics: device model, OS and app version and a technical error trace — processed by Sentry (Functional Software, Inc.) on servers within the European Union to maintain application stability (Art. 6(1)(f) GDPR); URLs and headers are masked before transmission.
- Measurement and configuration data of your organisation's sensors — as part of providing the monitoring service.
12. Mobile applications — what we do not do, and account deletion
The applications do not collect the user's phone location and request no system location permissions; they contain no ads or advertising SDKs, do not profile users and do not sell data. The Tracking feature may display approximate positions of your organisation's IoT trackers, estimated from cellular network stations (typically accurate to about 1 km, up to 5 km) — this data concerns the organisation's devices, is fetched from our servers only for authorised users, and is never stored on the phone (it is cleared when leaving the view, locking the app, or losing access). System permissions (NFC, Bluetooth) are used solely to configure your organisation's sensors and are not used for tracking or determining the phone's location.
You can delete your account directly in the application (Settings → Account → Delete account) or by sending a request to the address indicated in section 1. Deleting the account permanently removes the personal data associated with it, except for data we are legally required to retain longer (e.g. billing records). The rights described in section 7 fully apply to the mobile applications as well.
