MUNDO COWORKING PRIVACY POLICY
Last updated: 2026-06-04
§ 1. Data Controller
- The controller of your personal data is Silverhand Dominik Matczak, conducting business at ul. Garbary 35/9, 61-868 Poznań, hereinafter referred to as the “Controller”.
- For matters concerning personal data, you may contact the Controller: 1) by email: [TO BE CONFIRMED: rodo@silverhand.eu],
2) by post: ul. Garbary 35/9, 61-868 Poznań,
3) organizationally also at: office@mundo.wellmade.online. - As of the publication date of this Policy, the Controller has not appointed a Data Protection Officer / [TO BE CONFIRMED]. If the Controller appoints a DPO, contact details will be published immediately.
§ 2. Scope of the Policy
This Policy applies in particular to:
- visitors to the Mundo Coworking website,
- individuals contacting us via forms, email, telephone, or social media,
- individuals making reservations or entering into agreements,
- users of coworking spaces, meeting rooms, and other services,
- guests granted access to the premises,
- representatives of clients, contractors, and collaborators,
- individuals subject to video surveillance or access control systems, if such systems are in use.
§ 3. What data we process
Depending on the purpose and our relationship with you, we may process in particular:
- identification and contact data, such as first name, last name, email address, telephone number, company, position;
- data related to reservations or agreements, such as date and time of service use, package type, desk or room number, cooperation history, correspondence, organizational arrangements;
- billing data, such as invoice details, tax identification number, address, payment history;
- data concerning access and security, such as access logs, card number, user identifier, entry and exit times;
- video surveillance data, if monitoring is in use;
- technical data related to website or Wi-Fi use, such as IP address, online identifiers, device type, browser type, technical logs, website activity data;
- data concerning marketing consents and communication preferences;
- data contained in complaints, requests, forms, and correspondence.
As a rule, the Controller does not expect the provision of special categories of personal data or data concerning criminal convictions. If such data are provided voluntarily, they will be processed only when an appropriate legal basis exists.
§ 4. Sources of data
- We receive data primarily directly from you.
- In some cases, data may also originate from: 1) your employer or the organization you represent,
2) reservation and payment forms,
3) access control or monitoring systems,
4) publicly available registers, such as CEIDG or KRS — when necessary for entering into or performing an agreement.
§ 5. Purposes and legal bases for processing
The Controller processes personal data for the following purposes:
- handling inquiries, contact forms, email and telephone communication
– legal basis: Article 6(1)(b) GDPR, if actions are taken prior to entering into an agreement, or Article 6(1)(f) GDPR, when it concerns routine contact handling and communication organization; - accepting reservations, entering into and performing agreements concerning coworking, meeting rooms, and other services
– legal basis: Article 6(1)(b) GDPR; - issuing invoices, maintaining accounting records, settlements, archiving, and fulfilling tax and accounting obligations
– legal basis: Article 6(1)(c) GDPR; - ensuring the security of persons and property, conducting video surveillance, access control, preventing abuse, protecting IT systems and Wi‑Fi networks
– legal basis: Article 6(1)(f) GDPR; - establishing, pursuing, or defending against claims and handling complaints
– legal basis: Article 6(1)(f) GDPR, and to the appropriate extent also Article 6(1)(c) GDPR; - sending commercial and marketing information by email, telephone, or SMS
– legal basis: Article 6(1)(a) GDPR, i.e., consent, as well as required sector-specific consents, if necessary; - using cookies other than necessary ones, analytics, and online marketing
– legal basis: user consent expressed in accordance with cookie settings.
§ 6. Whether providing data is mandatory
- Providing data is generally voluntary.
- However, failure to provide certain data may prevent: 1) responding to an inquiry,
2) making a reservation,
3) entering into or performing an agreement,
4) issuing an invoice,
5) granting access to the premises. - Providing marketing consent and consent for optional cookies is voluntary and may be withdrawn at any time.
§ 7. Data recipients and processors
Your data may be transferred — only to the extent necessary — to the following categories of recipients:
- hosting, domain, email, and website maintenance providers,
- providers of forms, reservation systems, and calendar or availability management tools,
- payment operators, banks, and accounting entities,
- IT system, technical support, and security providers,
- law firms, advisors, auditors, or debt collection entities,
- providers of access control systems, CCTV, or building management — if applicable,
- public entities authorized to receive data under legal provisions,
- providers of analytical and marketing tools — only to the extent resulting from cookie settings and granted consents.
If the Controller uses data processors, it entrusts them with data on the basis of appropriate agreements and requires confidentiality and appropriate security measures.
§ 8. Data transfers outside the EEA
- As a rule, the Controller strives to ensure that data are processed within the European Economic Area.
- If the Controller uses providers whose infrastructure or subcontractors are located outside the EEA, data transfer occurs only in accordance with Chapter V of the GDPR, in particular on the basis of: 1) an adequacy decision, or
2) standard contractual clauses, or
3) another legally permitted mechanism. - Information about the specific transfer mechanism may be provided upon your request.
- [TO BE COMPLETED: list of providers that may cause transfers outside the EEA]
§ 9. Data retention period
The Controller retains data no longer than necessary to achieve the processing purpose, and subsequently for the period required by law or necessary to defend or pursue claims.
As a rule, we apply the following periods:
- quotation inquiries and routine correspondence – until the matter is closed, and subsequently as a rule for 12 months, unless an agreement is entered into earlier or there is a need for longer retention;
- reservations, agreements, settlements, and accounting documentation – for the duration of the agreement, and subsequently for the period required by tax and accounting regulations and the limitation period for claims;
- marketing data and marketing consents – until consent is withdrawn or an objection is raised, but no longer than until the communication purpose becomes outdated;
- access logs and entry control data – as a rule for [TO BE COMPLETED: 3 months / 6 months], unless needed to clarify an incident;
- video surveillance recordings – as a rule for [TO BE COMPLETED: 7–30 days], unless an incident has occurred justifying their retention for longer;
- technical logs, IT security, and Wi‑Fi – for [TO BE COMPLETED: 30–90 days], unless needed to ensure security or pursue claims;
- cookies and related data – in accordance with the lifespan of the given cookie category and consent panel settings.
§ 10. Rights of data subjects
You have the right to:
- access your data and obtain a copy,
- rectify your data,
- erase your data,
- restrict processing,
- data portability — if the processing is based on consent or an agreement and is carried out in an automated manner,
- object to processing based on the Controller’s legitimate interest, including direct marketing,
- withdraw consent at any time, if processing is based on consent,
- lodge a complaint with the President of the Personal Data Protection Office.
To exercise your rights, you may contact the Controller using the details provided in § 1. The Controller may request additional information necessary to confirm your identity. A response will be provided without undue delay, as a rule within 1 month, and in more complex cases this period may be extended in accordance with GDPR provisions.
§ 11. Automated decision-making
- As a rule, the Controller does not make decisions concerning you based solely on automated processing, including profiling, which would produce legal effects or similarly significantly affect you.
- If the Controller uses auxiliary technical tools for reservation organization, security, or abuse detection, final decisions are not made solely automatically.
§ 12. Video surveillance
- [IF APPLICABLE] Video surveillance may be used at Mundo Coworking for the purpose of: 1) ensuring the safety of persons,
2) protecting property,
3) preventing abuse and clarifying incidents. - The legal basis for processing surveillance data is the Controller’s legitimate interest.
- Surveillance does not cover restrooms or other areas requiring special privacy protection.
- Recordings may be disclosed only to authorized authorities, insurers, or professional advisors, if necessary to clarify an incident or protect claims.
- Detailed information about surveillance is provided at the entrance to the premises and upon request.
§ 13. Cookies and similar technologies
- The Mundo Coworking website uses cookies and similar technologies.
- Necessary cookies are used to ensure proper website operation, maintain sessions, security, and deliver the service requested by the user.
- Analytical, functional, and marketing cookies are used only in accordance with the user’s decision expressed in the consent panel, unless a given technology is legally exempt from the consent requirement.
- The user may: 1) accept all cookies,
2) reject optional cookies,
3) manage preferences by category. - Consent for optional cookies may be withdrawn at any time, without affecting the lawfulness of processing carried out before its withdrawal.
- Current information about cookie categories, providers, lifespan, and how to change settings is available in the consent management panel / [TO BE COMPLETED: link or CMP tool name].
§ 14. Data security
The Controller implements appropriate technical and organizational measures to protect personal data against loss, destruction, unauthorized disclosure, access, modification, or other unlawful processing. The scope of security measures is adapted to the nature of the data, the purpose of processing, and the level of risk.
§ 15. Changes to the Policy
- This Policy may be updated in the event of changes in law, technological changes, organizational changes, or changes in the manner of data processing.
- The current version of the Policy is published on the Mundo Coworking website.