| Group | Source | Basis for processing | Types of data | Storage | Format | Access by | Transfer |
| Clients | |||||||
| Companies, institutions (contact persons) | E-mail from client | performance of contract under Article 6(1)(b) and legal interest under Article 6(1)(f) – in order to update the client or make inquiries regarding the ongoing project, payment, satisfaction | Full name, e-mail, phone number, Skype ID | Email, BMS – SpaceTMS | database | employees | SpaceTMS, Microsoft356 |
| Individual clients | E-mail from client, phone conversation, personal visit to the office | performance of contract under Article 6(1)(b) and legal interest under Article 6(1)(f) – in order to update the client or make inquiries regarding the ongoing project, payment, satisfaction | Full name, address, phone number, e-mail, Skype ID, business name, NIP, Regon | Email, BMS – SpaceTMS, Invoicing – Saldeo, Financial system, local file server | database and electronic documents (invoices) | employees | SpaceTMS, Microsoft356, Saldeo |
| Prospective clients | contact form on www.diuna.biz | consent | Full name, e-mail, phone number | WordPress, email, CRM – Bitrix24 | database | employees | Microsoft356 |
| Suppliers | |||||||
| Suppliers | recruitment process – application | performance of contract under Article 6(1)(b) | Full name, address, business name and address, phone numbers, e-mail address, NIP, REGON, bank account details, other payment details | Email, SpaceTMS (vendor owned account), Autenti, Saldeo, local file server | database, documents (contracts) | employees | Microsoft356, SpaceTMS, Autenti, Saldeo |
| Employees | |||||||
| Employees | job application | performance of contract under Article 6(1)(b) and statutory obligation under Article 6(1)(c) | Full name, address, mailing address, parents’ names, date of birth, tax office, NIP, Pesel, bank account | email, payroll system – Asseco, Bitrix24 (only name and contact information) | documents, contracts | General Manager, Office Manager, HR Manager | email, file server |
| Apprentices and trainees | apprenticeship application | performance of contract under Article 6(1)(b) and statutory obligation under Article 6(1)(c) | Full name, address, mailing address, parents’ names, date of birth, tax office, NIP, Pesel, bank account | Email, Bitrix24 (only name and contact information) | documents | Office Manager, Vendor Manager | |
| Translated content | |||||||
| personal data in translated content | shared by clients via e-mail or otherwise (e.g. ftp) | data processing agreement | as per delivered content | Email, SpaceTMS, translation memories | database, file | employees, shared with vendors employed to do specific tasks | email, SpaceTMS |
| Type | Provider | EEA only | Backup | Access | Scope of data |
| Microsoft365– cloud | Yes | Provider – 30 days | Personal, two-factor authentication | Client data (including personal data), client content, vendor data (including personal data) | |
| Mail 2 | Home.pl – cloud | Yes | Provider – 3 days | Personal, two-factor authentication | Client data (including personal data), client content, vendor data (including personal data) |
| File server | Local onsite | Yes | DIUNA | In accordance with user rights | Client content in TM, vendor data (contracts and invoices) |
| PC | Local onsite / with user | Yes | NO | Personal / password | No permanent storage, only for the time of processing, type of data depends on the role at DIUNA |
| Project management system | SpaceTMS.com – cloud | Yes | Provider, weekly backups | Personal / password | Client data (including personal data), client content, vendor content (on accounts owned by vendors) |
| Translation management system™ | Trados – local file server Memsource – cloud | Yes | DIUNA, Provider | In accordance with user rights | Client content |
| Machine translation (MT) | Tilde – cloud | Yes | Through translation management system | Client content | |
| Invoicing | Saldeo – cloud, outsourced accountant | Yes | Provider | Authorised users | Vendors’ personal data |
| CRM, internal communication | Bitrix24 – cloud | Yes | Provider | Authorised users | Employees, trainees, apprentices – names, e-mails, phone numbers |
| Document editors | Microsoft – Onedrive | Yes | Provider | Individual users | Client content (only on client’s explicit request) |
| Agreement handling | Autenti Sp. z o.o. | Yes | Provider | Individual users, managed roles | Contractors data (clients and suppliers) |
| Marketing; marketing automation | GetResponse S.A. | No | Provider | Individual users, managed roles | Clients, leads |
Data controller
The personal data controller is DIUNA Group sp. z o.o. with its registered office in Warsaw, address: ul. Słowicza 33, 02-170 Warsaw, entered into the Register of Entrepreneurs of the National Court Register, kept by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register under KRS number: 0000951792, NIP: 7010424337
For personal data protection matters, you can contact: GDPR@diuna.biz
Purposes and basis of processing
Personal data is processed in connection with the intention to establish a cooperation or acquire services or products for the following purposes:
Data is processed in electronic form.
Recipients of data
The recipients of the data are persons and entities to whom we outsource processing activities, in particular translators, proofreaders and other service providers. A detailed list of processors can be found below.
Data storage period.
We process data processed on the basis of a contract in accordance with the provisions of the contract and for the period of limitation of claims.
We process data processed on the basis of consent until you withdraw your consent.
We may process data processed on the basis of our legitimate interest as data controller for the duration of our interest or until you object to such processing.
Handling client assets
Client assets are handled by dedicated project managers and translated by a fixed team of translators, who are obliged to sign non-disclosure agreements. Every project is subject to standard security procedures.
| Group | Source | Basis for processing | Types of data | Storage | Format | Access by | Transfer |
| Clients | |||||||
| Companies, institutions (contact persons) | E-mail from client | performance of contract under Article 6(1)(b) and legal interest under Article 6(1)(f) – in order to update the client or make inquiries regarding the ongoing project, payment, satisfaction | Full name, e-mail, phone number, Skype ID | Email, BMS – SpaceTMS | database | employees | SpaceTMS, Microsoft356 |
| Individual clients | E-mail from client, phone conversation, personal visit to the office | performance of contract under Article 6(1)(b) and legal interest under Article 6(1)(f) – in order to update the client or make inquiries regarding the ongoing project, payment, satisfaction | Full name, address, phone number, e-mail, Skype ID, business name, NIP, Regon | Email, BMS – SpaceTMS, Invoicing – Saldeo, Financial system, local file server | database and electronic documents (invoices) | employees | SpaceTMS, Microsoft356, Saldeo |
| Prospective clients | contact form on www.diuna.biz | consent | Full name, e-mail, phone number | WordPress, email, CRM – Bitrix24 | database | employees | Microsoft356 |
| Suppliers | |||||||
| Suppliers | recruitment process – application | performance of contract under Article 6(1)(b) | Full name, address, business name and address, phone numbers, e-mail address, NIP, REGON, bank account details, other payment details | Email, SpaceTMS (vendor owned account), Autenti, Saldeo, local file server | database, documents (contracts) | employees | Microsoft356, SpaceTMS, Autenti, Saldeo |
| Employees | |||||||
| Employees | job application | performance of contract under Article 6(1)(b) and statutory obligation under Article 6(1)(c) | Full name, address, mailing address, parents’ names, date of birth, tax office, NIP, Pesel, bank account | email, payroll system – Asseco, Bitrix24 (only name and contact information) | documents, contracts | General Manager, Office Manager, HR Manager | email, file server |
| Apprentices and trainees | apprenticeship application | performance of contract under Article 6(1)(b) and statutory obligation under Article 6(1)(c) | Full name, address, mailing address, parents’ names, date of birth, tax office, NIP, Pesel, bank account | Email, Bitrix24 (only name and contact information) | documents | Office Manager, Vendor Manager | |
| Translated content | |||||||
| personal data in translated content | shared by clients via e-mail or otherwise (e.g. ftp) | data processing agreement | as per delivered content | Email, SpaceTMS, translation memories | database, file | employees, shared with vendors employed to do specific tasks | email, SpaceTMS |
| Type | Provider | EEA only | Backup | Access | Scope of data |
| Microsoft365– cloud | Yes | Provider – 30 days | Personal, two-factor authentication | Client data (including personal data), client content, vendor data (including personal data) | |
| Mail 2 | Home.pl – cloud | Yes | Provider – 3 days | Personal, two-factor authentication | Client data (including personal data), client content, vendor data (including personal data) |
| File server | Local onsite | Yes | DIUNA | In accordance with user rights | Client content in TM, vendor data (contracts and invoices) |
| PC | Local onsite / with user | Yes | NO | Personal / password | No permanent storage, only for the time of processing, type of data depends on the role at DIUNA |
| Project management system | SpaceTMS.com – cloud | Yes | Provider, weekly backups | Personal / password | Client data (including personal data), client content, vendor content (on accounts owned by vendors) |
| Translation management system™ | Trados – local file server Memsource – cloud | Yes | DIUNA, Provider | In accordance with user rights | Client content |
| Machine translation (MT) | Tilde – cloud | Yes | Through translation management system | Client content | |
| Invoicing | Saldeo – cloud, outsourced accountant | Yes | Provider | Authorised users | Vendors’ personal data |
| CRM, internal communication | Bitrix24 – cloud | Yes | Provider | Authorised users | Employees, trainees, apprentices – names, e-mails, phone numbers |
| Document editors | Microsoft – Onedrive | Yes | Provider | Individual users | Client content (only on client’s explicit request) |
Our IT resources are secured by anti-virus software with the following functions:
a) securing the IT resources against malware with a residential module that scans the entire computer system;
b) updating the virus signature database on an ongoing basis;
c) automated reaction in case new and unknown malware is detected, e.g. blocking all communications with the infected computer.
The software we are currently using is ESET and Windows Defender.
Desktop workstations are secured with a password that is changed every few months. Passwords are comprised of 9 characters or more, including at least one special character, and are never simple. Unlocked workstations are never left unsupervised. Daily work is done on an account without administrator privileges.
Access to the network drive is password-protected and is protected by a VPN with additional password and certificates.
Desktop workstations are protected with a firewall and anti-virus software.
Protection of premises
Incident procedure
Cookie policy
Rights of the data subject
Under the GDPR (General Data Protection Regulation), data subjects whose personal data is processed have a number of rights. Here are some of the key rights of data subjects in relation to data protection:
For matters relating to the exercise of these rights, please contact: GDPR@diuna.biz
Last update: April 2023
Data controller
The personal data controller is DIUNA Group sp. z o.o. with its registered office in Warsaw, address: ul. Słowicza 33, 02-170 Warsaw, entered into the Register of Entrepreneurs of the National Court Register, kept by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register under KRS number: 0000951792, NIP: 7010424337
For personal data protection matters, you can contact: GDPR@diuna.biz
Purposes and basis of processing
Personal data is processed in connection with the intention to establish a cooperation or acquire services or products for the following purposes:
Data is processed in electronic form.
Recipients of data
The recipients of the data are persons and entities to whom we outsource processing activities, in particular translators, proofreaders and other service providers. A detailed list of processors can be found below.
Data storage period.
We process data processed on the basis of a contract in accordance with the provisions of the contract and for the period of limitation of claims.
We process data processed on the basis of consent until you withdraw your consent.
We may process data processed on the basis of our legitimate interest as data controller for the duration of our interest or until you object to such processing.
Handling client assets
Client assets are handled by dedicated project managers and translated by a fixed team of translators, who are obliged to sign non-disclosure agreements. Every project is subject to standard security procedures.
| Group | Source | Basis for processing | Types of data | Storage | Format | Access by | Transfer |
| Clients | |||||||
| Companies, institutions (contact persons) | E-mail from client | performance of contract under Article 6(1)(b) and legal interest under Article 6(1)(f) – in order to update the client or make inquiries regarding the ongoing project, payment, satisfaction | Full name, e-mail, phone number, Skype ID | Email, BMS – SpaceTMS | database | employees | SpaceTMS, Microsoft356 |
| Individual clients | E-mail from client, phone conversation, personal visit to the office | performance of contract under Article 6(1)(b) and legal interest under Article 6(1)(f) – in order to update the client or make inquiries regarding the ongoing project, payment, satisfaction | Full name, address, phone number, e-mail, Skype ID, business name, NIP, Regon | Email, BMS – SpaceTMS, Invoicing – Saldeo, Financial system, local file server | database and electronic documents (invoices) | employees | SpaceTMS, Microsoft356, Saldeo |
| Prospective clients | contact form on www.diuna.biz | consent | Full name, e-mail, phone number | WordPress, email, CRM – Bitrix24 | database | employees | Microsoft356 |
| Suppliers | |||||||
| Suppliers | recruitment process – application | performance of contract under Article 6(1)(b) | Full name, address, business name and address, phone numbers, e-mail address, NIP, REGON, bank account details, other payment details | Email, SpaceTMS (vendor owned account), Autenti, Saldeo, local file server | database, documents (contracts) | employees | Microsoft356, SpaceTMS, Autenti, Saldeo |
| Employees | |||||||
| Employees | job application | performance of contract under Article 6(1)(b) and statutory obligation under Article 6(1)(c) | Full name, address, mailing address, parents’ names, date of birth, tax office, NIP, Pesel, bank account | email, payroll system – Asseco, Bitrix24 (only name and contact information) | documents, contracts | General Manager, Office Manager, HR Manager | email, file server |
| Apprentices and trainees | apprenticeship application | performance of contract under Article 6(1)(b) and statutory obligation under Article 6(1)(c) | Full name, address, mailing address, parents’ names, date of birth, tax office, NIP, Pesel, bank account | Email, Bitrix24 (only name and contact information) | documents | Office Manager, Vendor Manager | |
| Translated content | |||||||
| personal data in translated content | shared by clients via e-mail or otherwise (e.g. ftp) | data processing agreement | as per delivered content | Email, SpaceTMS, translation memories | database, file | employees, shared with vendors employed to do specific tasks | email, SpaceTMS |
| Type | Provider | EEA only | Backup | Access | Scope of data |
| Microsoft365– cloud | Yes | Provider – 30 days | Personal, two-factor authentication | Client data (including personal data), client content, vendor data (including personal data) | |
| Mail 2 | Home.pl – cloud | Yes | Provider – 3 days | Personal, two-factor authentication | Client data (including personal data), client content, vendor data (including personal data) |
| File server | Local onsite | Yes | DIUNA | In accordance with user rights | Client content in TM, vendor data (contracts and invoices) |
| PC | Local onsite / with user | Yes | NO | Personal / password | No permanent storage, only for the time of processing, type of data depends on the role at DIUNA |
| Project management system | SpaceTMS.com – cloud | Yes | Provider, weekly backups | Personal / password | Client data (including personal data), client content, vendor content (on accounts owned by vendors) |
| Translation management system™ | Trados – local file server Memsource – cloud | Yes | DIUNA, Provider | In accordance with user rights | Client content |
| Machine translation (MT) | Tilde – cloud | Yes | Through translation management system | Client content | |
| Invoicing | Saldeo – cloud, outsourced accountant | Yes | Provider | Authorised users | Vendors’ personal data |
| CRM, internal communication | Bitrix24 – cloud | Yes | Provider | Authorised users | Employees, trainees, apprentices – names, e-mails, phone numbers |
| Document editors | Microsoft – Onedrive | Yes | Provider | Individual users | Client content (only on client’s explicit request) |
Our IT resources are secured by anti-virus software with the following functions:
a) securing the IT resources against malware with a residential module that scans the entire computer system;
b) updating the virus signature database on an ongoing basis;
c) automated reaction in case new and unknown malware is detected, e.g. blocking all communications with the infected computer.
The software we are currently using is ESET and Windows Defender.
Desktop workstations are secured with a password that is changed every few months. Passwords are comprised of 9 characters or more, including at least one special character, and are never simple. Unlocked workstations are never left unsupervised. Daily work is done on an account without administrator privileges.
Access to the network drive is password-protected and is protected by a VPN with additional password and certificates.
Desktop workstations are protected with a firewall and anti-virus software.
Protection of premises
Incident procedure
Cookie policy
Rights of the data subject
Under the GDPR (General Data Protection Regulation), data subjects whose personal data is processed have a number of rights. Here are some of the key rights of data subjects in relation to data protection:
For matters relating to the exercise of these rights, please contact: GDPR@diuna.biz
Last update: April 2023