Privacy Policy
Privacy Policy of the nobilishome.eu website
Last updated: October 15, 2025
Version: 1.0
General Provisions
This document explains how we process the personal data of users of the nobilishome.eu website (the “Service”), as well as how we use cookies and similar technologies. This Privacy Policy fulfills the information obligations arising from data protection regulations (in particular the GDPR).
Data Controller and Contact Information
The controller of personal data is:
YouPal s.r.o.
Nové sady 988/2, Staré Brno
602 00 Brno
E-mail: office@nobilishome.eu
Phone: +420 776 039 028
For all matters related to data protection, we kindly ask you to contact us primarily via email.
Data Protection Officer
The controller has not appointed a Data Protection Officer (DPO). If one is designated in the future, this Policy will be updated accordingly.
What Data We Process and Where It Comes From
We primarily process data provided directly by you: your name, email address, phone number, the content of your inquiry/message, and data necessary for the performance of a contract. We also process technical data related to your use of the Service (IP address, server logs, information about your browser and operating system), as well as activity data collected via cookies (for analytical/marketing purposes — only with your consent). Data may also originate from public registers (e.g. CEIDG/KRS) or from your employers/contractors, if they indicate you as a contact person.
Purposes, Legal Bases, and Retention Periods
Below we describe the main purposes of data processing. Retention periods are generally calculated from the completion of the purpose, and for claims — until the expiry of the applicable limitation periods.
a) Handling inquiries, preparing offers, and follow-up contact
Legal basis: necessity to take steps prior to entering into a contract or our legitimate interest (communication) — Article 6(1)(b) or (f) of the GDPR.
Retention period: for the duration of the correspondence and up to 12 months after its completion (for evidential purposes).
b) Conclusion and performance of a contract
Legal basis: Article 6(1)(b) of the GDPR.
Retention period: for the duration of the contract and until the expiry of claims (typically up to 6 years).
c) Accounting and tax settlements
Legal basis: legal obligation — Article 6(1)(c) of the GDPR.
Retention period: up to 5 years from the end of the year in which the obligation arose.
d) Establishment, exercise, and defense of claims
Legal basis: Article 6(1)(f) of the GDPR.
Retention period: until the expiry of the applicable limitation periods.
e) Marketing of our services (commercial communication)
Legal basis: consent — Article 6(1)(a) of the GDPR (for channels requiring consent), and our legitimate interest — Article 6(1)(f) of the GDPR (direct marketing within the limits of the law).
Retention period: until consent is withdrawn or an effective objection is raised.
f) Analytics and statistics (analytical cookies)
Legal basis: consent — Article 6(1)(a) of the GDPR.
Retention period: until consent is withdrawn or the cookie expires.
g) Remarketing i personalizacja (cookies marketingowe)
Podstawa: zgoda – art. 6 ust. 1 lit. a RODO.
Okres: do czasu wycofania zgody lub wygaśnięcia cookie.
h) Service security (logs, backups)
Legal basis: Article 6(1)(f) of the GDPR.
Retention period: up to 12 months, and for backups — in accordance with the backup retention policy.
i) Recruitment (if conducted)
Legal basis: the candidate’s consent — Article 6(1)(a) of the GDPR and/or Article 6(1)(b) of the GDPR, if the recruitment process leads to the conclusion of a contract.
Retention period: for the duration of the recruitment process and — if you give your consent — up to 12 months for future recruitment purposes.
Data Recipients and Transfers Outside the EEA
We may entrust data to service providers acting on our behalf, including hosting and IT maintenance providers, email services, analytics and marketing tools, accounting offices, legal advisors, subcontractors, and — where applicable — payment operators and courier companies. If data is transferred outside the European Economic Area (EEA), such transfers are carried out using appropriate mechanisms and safeguards provided for under the GDPR (e.g. Standard Contractual Clauses — SCC).
Cookies and Similar Technologies
7.1. What are cookies
Cookies are small files stored on your device when you use the Service. Similar technologies may also be used (such as local storage, pixels, and advertising identifiers).
7.2. Categories of cookies
• Essential — necessary for the proper functioning of the Service (ensuring functionality and security).
• Analytical — help us understand how you use the Service in order to improve it.
• Marketing — enable remarketing activities and the personalization of advertising content.
Consent is required for analytical and marketing cookies. Essential cookies operate based on our legitimate interest.
7.3. Managing consent
Within the Service, we provide a cookie banner/preference center where you can accept or reject individual categories and change your choices at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. You can also configure your browser to block cookies (this may limit the functionality of the Service).
7.4. Cookie lifetimes
Session cookies expire at the end of the browser session. Persistent cookies have a defined lifespan. The current list of cookies used, their providers, and their lifetimes is available in the preference center.
Marketing and Commercial Communication
We may carry out marketing of our services. In channels that require consent (e.g. email/phone/SMS directed to individuals), communication is conducted only after obtaining your voluntary consent, which you can withdraw at any time — by contacting us or (for email) using the unsubscribe link.
Newsletter (if available)
Registration is confirmed using a double opt-in process. Each message contains an unsubscribe link. Data is processed until consent is withdrawn or the newsletter service is discontinued.
Social Media
We maintain profiles on social media platforms (e.g. Facebook, Instagram, LinkedIn). Data of users visiting our profiles and interacting with us is processed in accordance with the rules defined by these platforms. The legal basis is our legitimate interest (communication and brand building).
Your Rights
You have the right to: access your data, rectify it, request its erasure, restrict processing, transfer your data, object to processing based on our legitimate interest (including direct marketing), and withdraw your consent at any time (where consent is the legal basis). You also have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl).
Requests regarding your rights should be sent to: office@nobilishome.eu
We will respond no later than within 30 days.
Automated Decision-Making and Profiling
We do not make decisions concerning you that produce legal effects based solely on automated processing. We may carry out basic marketing profiling based on marketing cookies — only with your consent — in order to tailor advertising content.
Data Security
We apply appropriate technical and organizational measures, including encrypted transmission (HTTPS), access control, incident logging, software updates, and regular backups. Access to data is granted only to authorized persons and processors acting on our behalf.
Voluntary Provision of Data and Consequences
Providing data is voluntary, but necessary to use certain functionalities (e.g. receiving a response to an inquiry). Failure to provide data may prevent the fulfillment of the intended purpose (e.g. follow-up contact).
Changes to the Policy
We reserve the right to update this Policy in the event of changes in regulations, technology, or the functionality of the Service. The new version will be published together with the update date.
