Skip to content

operationalwrocław--:-- cet

RITE NRG

Legal

Privacy Policy

This Privacy Policy explains how RITE NRG processes personal data when you visit ritenrg.com, contact us, interact with website features, or communicate with us in a professional context. A separate Recruitment Privacy Notice applies to job candidates.

Last updated: 30 August 2026

1. Controller and Contact Details

The controller is:

  • RITE NRG sp. z o.o.
  • ul. gen. Władysława Sikorskiego 3/2, 53-659 Wrocław, Poland
  • KRS 0000710267 · NIP 7642687723 · REGON 369015211
  • Email: hello@ritenrg.com

For privacy questions or to exercise your rights, email hello@ritenrg.com or write to the address above. When RITE NRG processes data solely on a customer’s documented instructions while delivering a customer solution, the customer is normally the controller for that processing and the customer’s privacy information applies.

2. Data We Process and Its Sources

Depending on how you use the website or communicate with us, we may process:

  • Information you provide, such as your name, business email address, telephone number, employer, role, inquiry, correspondence, uploaded material and communication preferences.
  • Technical and security data, such as IP address, date and time, requested URL, response or error information, browser, device, operating system, referrer and security-event data.
  • Consent and preference data, such as the choices, time, version and identifier associated with your cookie or marketing permissions.
  • Usage data, such as page and campaign interactions, only where an optional analytics or marketing technology is enabled with the required permission.
  • Professional information obtained elsewhere, such as name, employer, role and business contact details from your employer, a colleague or referral, a public professional profile, a company website, a public register, an event, or a recruitment/business-data provider lawfully used by RITE NRG.

If we obtain your personal data from another source, we provide the information required by GDPR Article 14 within the applicable period — normally no later than our first communication or one month after obtaining the data — and identify the specific source or source category.

3. Why We Use Data, Legal Bases and Retention

We use personal data only for the purposes and legal bases described below. Article references are to the General Data Protection Regulation (“GDPR”).

Activity and purposeDataLegal basisRetention
Deliver, operate, secure and diagnose the website; prevent abuse and investigate incidentsIP address, timestamp, request, browser/device, referrer, error and security logsArt. 6(1)(f): our legitimate interest in a secure, reliable website and network/information securityOrdinary technical logs for up to 90 days. Records relevant to a security incident or claim may be isolated and retained until the incident, investigation or applicable claim period is resolved.
Answer a contact form, email, meeting request or other inquiry and manage the requested business communicationIdentity, business contact details, employer/role, message, attachments and correspondence metadataArt. 6(1)(b) where you ask for steps before entering a contract with you; otherwise Art. 6(1)(f): our legitimate interest in handling inquiries and professional B2B relationshipsWhile the inquiry or relationship is active, then normally up to 3 years after the last substantive interaction where necessary for continuity, accountability or claims. We delete or anonymize information sooner when it is no longer needed.
Negotiate, conclude and perform a contract; administer a customer or supplier relationshipContact, role, contract, order, billing and correspondence dataArt. 6(1)(b) if you are the contracting person; Art. 6(1)(f) for representatives and contacts of corporate parties; Art. 6(1)(c) for legal, tax and accounting dutiesFor the relationship, then for applicable statutory accounting, tax and limitation periods. Contract-specific privacy information may provide further detail.
Record and honor cookie/privacy choices and demonstrate complianceConsent identifier, choice, date/time, policy version and withdrawal/change eventArt. 6(1)(c): compliance with consent and accountability duties; Art. 6(1)(f): defending legal claimsFor as long as needed to honor the current choice and demonstrate compliance for the applicable limitation or regulatory period, then deleted or anonymized.
Optional audience analytics and website improvementOnline identifier, consented page/event data, device/browser, referrer and approximate locationArt. 6(1)(a): consent, together with the permission required by Polish electronic-communications lawUntil consent is withdrawn or for the provider-specific period shown in Cookie settings, whichever occurs first, subject to data already aggregated or lawfully retained by the provider.
Optional campaign measurement, advertising or external mediaOnline identifiers, campaign/page events, device data and media interactionsArt. 6(1)(a): consent, together with the permission required by Polish electronic-communications lawUntil consent is withdrawn or for the provider-specific period shown in Cookie settings, whichever occurs first.
Send information or direct marketing through a channel you have expressly selected, if this feature is offeredName, business contact channel, preferences, consent and communication historyArt. 6(1)(a): consent; minimal withdrawal/suppression information on Art. 6(1)(c) and/or Art. 6(1)(f) as necessary to prove and honor the choiceUntil withdrawal or the stated subscription period. A minimal suppression record is kept only as long as needed to ensure we do not contact you contrary to your choice and to demonstrate compliance.
Relevant one-to-one professional relationship management using business data obtained from public or referral sourcesName, employer, role, business contact details, source and communication historyArt. 6(1)(f): our legitimate interest in developing relevant professional relationships, after assessing necessity and impact. Any electronic commercial communication is sent only where separately permitted by Polish electronic-communications law.Until you object, the information becomes irrelevant or inaccurate, or the adopted review period expires. We review the need for the record periodically.
Comply with law and establish, exercise or defend legal claimsThe minimum information relevant to the duty or claimArt. 6(1)(c) and/or Art. 6(1)(f). If special-category data are strictly necessary for a claim, Art. 9(2)(f) may apply.Until the legal duty, applicable limitation period or proceedings end.

Where we rely on a legitimate interest, we consider the interest, necessity and likely effect on you. You may object as explained in the section on your rights.

4. Cookies, Similar Technologies and External Content

Our Cookie Policy and Cookie settings explain the technologies actually used, their providers, purposes and durations.

Technologies strictly necessary to transmit a communication or provide a feature you expressly request may operate without optional consent. Analytics, advertising, campaign measurement, optional functionality and external-media technologies remain disabled until you make the relevant choice. You can reject optional technologies and later change or withdraw your choice through Cookie settings in the footer.

Where a video, map, booking widget or similar service would contact a third party, it remains blocked until the relevant permission is given or you deliberately activate the feature after receiving the information shown beside it.

5. Recipients

Access is limited to authorized people who need the information for the stated purpose. Depending on the feature used, recipients may include:

  • Website hosting, content-delivery, security, maintenance and consent-management providers.
  • Business email, cloud storage, CRM, form, booking and collaboration providers.
  • Analytics, advertising, campaign-measurement or external-media providers, only where enabled and permitted by your choice.
  • Recruitment and assessment providers where you apply for a role.
  • Professional advisers, including lawyers, accountants, auditors and insurers.
  • Courts, regulators, law-enforcement bodies or other public authorities where disclosure is required or permitted by law.

Processors may use personal data only on documented instructions and under contractual data-protection obligations. A recipient that determines its own purposes acts as a separate controller and must provide its own privacy information.

6. International Transfers

Some service providers or their subprocessors may process or permit access to personal data outside the European Economic Area (“EEA”). Where this happens, we use a mechanism permitted by GDPR Chapter V, such as:

  • An adequacy decision of the European Commission.
  • The European Commission’s Standard Contractual Clauses, with supplementary measures where required.
  • An active EU–US Data Privacy Framework certification for an eligible US recipient.
  • Another lawful mechanism available for the specific transfer.

You may ask us for information about the safeguard applicable to your data and for a copy where available by emailing hello@ritenrg.com.

7. Whether Providing Data Is Required

Fields marked as required in a contact or booking form are needed to identify and answer the request. If you do not provide them, we may be unable to respond or take the requested step. Other fields are optional.

Please do not include special-category data, national identification numbers, criminal-record information or other unnecessary confidential information in a general website message.

8. Automated Decisions and Profiling

RITE NRG does not use website or contact-form data to make decisions based solely on automated processing that produce legal effects or similarly significant effects for you.

If you consent to analytics or advertising tools, those tools may group interactions into statistical audiences or inferred interests. RITE NRG does not use those results to make decisions with legal or similarly significant effects. If this practice changes, we will provide the legally required information before the new processing starts.

9. Your Rights

Subject to the conditions in the GDPR, you may:

  • Request access to your personal data and a copy.
  • Request correction of inaccurate or incomplete data.
  • Request deletion.
  • Request restriction of processing.
  • Receive data you provided in a structured, commonly used and machine-readable format and transmit it to another controller where the portability conditions apply.
  • Object to processing based on our legitimate interests.
  • Withdraw consent at any time, without affecting processing carried out before withdrawal.

If you object to direct marketing, including related profiling, we will stop that processing. For another activity based on legitimate interests, we will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the data are required for legal claims.

Send a request to hello@ritenrg.com. We may ask for information reasonably necessary to verify identity. We normally respond within one month. The GDPR permits a further two months for complex or numerous requests; if this applies, we will explain the extension within the first month. Requests are normally free, subject to the GDPR rules for manifestly unfounded or excessive requests.

10. Complaints

You may lodge a complaint with the Polish supervisory authority:

President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl.

You may also complain to the supervisory authority in the EEA country of your habitual residence, place of work or the alleged infringement. We encourage you to contact us first so that we can try to resolve the issue.

11. Security

We apply technical and organizational measures appropriate to the nature, context and risks of the processing, and require our processors to protect personal data. No Internet transmission or information system can be guaranteed completely secure.

12. Children

The website and RITE NRG’s business services are not directed to children. If you believe a child has submitted personal data through the website, contact us so that we can assess and take appropriate action.

13. Other Websites

The website may link to services controlled by others. Their privacy notices apply when you use those services. A link does not cause us to accept responsibility for the third party’s processing.

14. Changes to This Policy

We may update this policy when our processing, website or legal obligations change. The current version and effective date will appear on this page. If a change materially affects individuals, we will provide additional notice where required. Continued browsing is not treated as consent to a new purpose.

Back to top ↑