1.1. This document sets out the terms, rules and manner of processing personal data through the IT System available at www.resfind.com.
1.2. The owner of the Resfind IT System is Mirosław Butryn conducting business activity under the name "MIRBU Mirosław Butryn" in Rzeszów at Aleja Powstańców Warszawy 36/40, VAT ID: 8652336196, REGON: 122784033, e-mail address: info@mirbu.pl.
Electronic Service – a service transmitted, received or sent entirely via a telecommunications network within the meaning of the Act of July 16, 2004 – Telecommunications Law, provided without the simultaneous presence of the parties (remotely) upon the individual request of the Service Recipient sent and received using devices for electronic processing and storage of data.
IT System – cooperating IT devices and software ensuring the processing and storage, as well as sending and receiving of data via telecommunications networks using a terminal device appropriate for the given type of network.
Operator – the owner of the Resfind IT System.
Service Recipient – a party to the License Agreement; a natural person, including one conducting business activity, a legal person or an organisational unit without legal personality, to which the law grants legal capacity.
User – a person authorised by the Service Recipient to use the Booking System.
License Agreement – an agreement for the provision of an Electronic Service, granting or extending access to the IT System, concluded or being concluded by the Operator and the Service Recipient.
Booking System – a component of the IT System used for managing event calendars.
Booking Form – a component of the IT System used for booking events by the Service Recipient's Clients.
Event – the purpose of booking a time slot in a calendar, e.g. a meeting, appointment, consultation, procedure, etc., characterised by a defined duration.
Service Recipient's Account – a separate section of the IT System, accessible after logging in using a username and password, containing resources and data belonging to the Service Recipient that are not accessible to other Service Recipients.
User Account – access credentials in the form of a phone number and password, provided to each User within the Service Recipient's Account.
Service Recipient's Client – a person using the Booking Form.
GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
3.1. The Operator acts as the controller of personal data with respect to the Service Recipients and Users who are natural persons.
3.2. With regard to data submitted by the Service Recipient's Clients, the Operator acts as a data processor, while the Service Recipient remains the data controller who entrusts the processing of such data to the Operator for a strictly defined purpose.
3.3. The Operator undertakes to process the personal data entrusted to it in accordance with this privacy policy as well as with the GDPR and other universally applicable laws protecting the rights of data subjects.
4.1. The sets of processed personal data include:
– in the case of Service Recipients and Users: first and last name, e-mail address, phone number, IP address, cookies
– in the case of Service Recipients' Clients: first and last name, phone number, e-mail address, IP address, cookies
– in the case of Website Guests: cookies
4.2. The Operator uses cookies – anonymous, short text files stored on the computer, phone, tablet or other device of the User, which may be read by the website, Booking Form or Booking System, as well as by other websites and online systems belonging to third parties whose services the Operator uses (e.g. Facebook, Google, LinkedIn).
4.3. The collection of cookies is aimed at improving the features available on the website, Booking System and Booking Form, identifying errors, facilitating access, and conducting marketing activities.
4.4. Upon the first visit, each Website Guest is displayed a notice regarding the use of cookies; acceptance or disregard of this notice, as well as continued use of the website, constitutes consent to the use of cookies in accordance with this privacy policy.
4.5. Web browsers allow the use of cookies on terminal devices by default, however browser users may block or limit the saving of cookies on their devices by changing browser settings.
4.6. Disabling or restricting the handling of cookies may cause difficulties in using the website and Booking Form, e.g. longer loading times or the need to re-enter data in the Booking Form or contact form.
4.7. The Operator collects logs related to operations performed by Users in the Resfind IT System, containing their identifiers, timestamps and parameters of executed queries. This information serves as auxiliary material for the administration of the Booking System and Booking Form.
4.8. By entering into the License Agreement, the Service Recipient consents to receiving commercial information by electronic means, which may entail the periodic receipt of information from the Operator about available solutions and services within the scope of the Electronic Service provided.
4.9. In certain cases, acting as a controller, the Operator is entitled to further transfer User or Service Recipient data, in particular in the following situations:
– transferring data to persons authorised by the controller, i.e. employees and associates who need access to the data in order to properly perform their duties related to the organisation and provision of services,
– transferring data to entities whose assistance and services the controller may use in the course of its business activity, by entrusting them with tasks that require data processing, e.g. IT system providers, entities providing technical support for software, accounting firms, lawyers, etc.,
– transferring data to competent state authorities pursuant to applicable law.
4.10. The Operator does not transfer personal data processed in connection with the provision of its services to third countries, understood as countries not belonging to the European Economic Area (EEA).
4.11. The Operator does, however, use services and technologies offered by entities such as Facebook, Google and LinkedIn, which are headquartered in the USA and, under the GDPR, are treated as third countries with respect to which an adequate level of protection or appropriate safeguards must be demonstrated. The aforementioned entities have joined the EU-US Data Privacy Framework (DPF) and guarantee compliance with the high personal data protection standards applicable in the European Union; therefore, the use of their services and technologies in the personal data processing process is lawful.
5.1. Personal data are processed for the following purposes:
– placing an order for an Electronic Service and performance of the Electronic Service; the legal basis is the concluded agreement or the necessity to take steps prior to its conclusion (Art. 6(1)(b) GDPR),
– marketing purposes, where the data subject has given consent (Art. 6(1)(a) GDPR),
– statistical purposes relating to the use of the website, Booking System and Booking Form, which constitutes the Operator's legitimate interest in facilitating the use of the Electronic Service (Art. 6(1)(f) GDPR),
– handling complaints and requests, responding to queries and surveying User satisfaction, which constitutes a legitimate interest consisting in improving service functionality and building positive relationships with Users (Art. 6(1)(f) GDPR),
– fulfilment of legal obligations incumbent on the controller under applicable law (Art. 6(1)(c) GDPR),
– establishing, asserting or enforcing claims, which constitutes the Operator's legitimate interest in initiating proceedings and defending against claims before courts and other state authorities (Art. 6(1)(f) GDPR).
5.2. Personal data are processed for as long as necessary to achieve the purposes set out in this privacy policy, but no longer than required to ensure the correct operation of the Electronic Service and at most 30 calendar days from the date of termination of the License Agreement.
The Operator offers an optional integration with the Google Calendar service. The integration is voluntary and requires a separate consent granted by the user on the Google OAuth 2.0 consent screen. The Operator's use of information received from Google APIs (including Google Calendar data) complies with the Google API Services User Data Policy, including the Limited Use requirements.
6.1. Requested access scope. Resfind requests only the following scope:
https://www.googleapis.com/auth/calendar.events.owned – creating, modifying and deleting events on calendars owned by the user. Resfind does not request access to:
– the full calendar (auth/calendar)
– calendars shared with the user (auth/calendar.events)
– the calendar list (auth/calendar.calendarlist)
– settings (auth/calendar.settings.readonly)
– ACL or free/busy information.
6.2. How Resfind uses access to Google Calendar. Upon granting consent, Resfind performs exclusively the following API operations:
– Insert – creating a new event in the user's calendar when a new appointment is created in Resfind. The returned googleEventId is stored in our own database.
– Update – modifying an existing event with a known googleEventId when the corresponding appointment in Resfind is changed.
– Delete – removing an event with a known googleEventId when the corresponding appointment is deleted in Resfind.
Resfind does not retrieve the list of events from Google Calendar, does not read events created outside Resfind, and does not analyse their content. Every API call refers to a specific googleEventId previously generated by Resfind.
6.3. Data flow and storage. The data flow is one-directional: Resfind → Google. Resfind's database stores: the encrypted OAuth refresh token, the Google account identifier (sub), and the googleEventId for each synchronised appointment. OAuth tokens are encrypted at rest and transmitted exclusively over HTTPS/TLS 1.2+. Resfind does not copy event content from Google to its own database.
6.4. Revoking consent and removing the integration. At any time, the user may:
– disconnect the integration from the Resfind account settings – in which case the OAuth tokens are irreversibly deleted,
– revoke access directly in the Google account panel: https://myaccount.google.com/permissions.
After disconnecting the integration, Resfind ceases to send any requests to the Google API. Events previously created in Google Calendar remain in the user's calendar (Resfind does not delete them automatically upon disconnection, so as to avoid accidental data loss).
6.5. Limited Use compliance. Use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. /text in English required by Google/
Resfind commits and ensures in particular that:
– it does not use data from Google Workspace APIs to train or improve artificial intelligence or machine learning (ML) models, including large language models (LLMs),
– it does not share data obtained through Google APIs with third parties for advertising or analytical purposes,
– it does not permit unauthorised persons to read data from Google APIs, except in the situations listed in Google's policy (user consent, security, legal requirement, anonymisation, debugging),
– it does not use data obtained through Google APIs for advertising purposes or to display personalised advertisements,
– it uses data from Google APIs solely to deliver the calendar synchronisation feature visible to the user.
7.1. Service Recipients, Users and Service Recipients' Clients have the right to access their data, correct, delete, port, restrict processing, cease processing and the right to object to the processing of their data under the GDPR, including the right to lodge a complaint with the Personal Data Protection Office (UODO).
8.1. The Operator guarantees the confidentiality of all personal data entrusted to it and does not disclose such data to third parties, but may entrust their processing, in particular for the purpose of recording and storing them in an electronic system and for the purpose of providing the service, including the sending of SMS messages.
8.2. Upon termination of the License Agreement, the Operator (data processor) returns to the Service Recipient (controller of clients' personal data) all personal data and deletes all existing copies thereof, or sends electronic confirmation of their destruction.
8.3. Acting as a processor, the Operator does not transfer data to other entities without an explicit instruction from the data controller.
9.1. This privacy policy may be amended or supplemented; Service Recipients and Users will be informed of any material changes by e-mail or SMS.
9.2. Questions regarding the privacy policy should be directed to the e-mail address: pomoc@resfind.com.