Up&More sp. z o.o.
Version dated 7 September 2026
This Privacy Policy explains how Up&More sp. z o.o. processes personal data in connection with the use of the upmore.com website, contacting us, marketing activities, recruitment, operating social media profiles, and business relationships with customers and contractors.
1. Data Controller and contact details
The controller of your personal data is Up&More sp. z o.o., with its registered office in Warsaw at Rondo ONZ 1, 00-124 Warsaw, entered in the National Court Register (KRS) under number 0000531450, NIP 5223020746, REGON 360132211 (hereinafter: „Up&More” or the „Controller”).
For matters concerning privacy and the processing of personal data, you can contact us:
- by email: hello@upmore.com,
- by post: Up&More sp. z o.o., Rondo ONZ 1, 00-124 Warsaw, Poland.
2. When we process personal data
We may process your personal data in particular when you:
- use the upmore.com website,
- send us a contact form or an email,
- consent to receiving marketing communications,
- are our customer or represent a customer,
- are our contractor or represent a contractor,
- take part in an event, training session, webinar or similar activity organised by us,
- take part in a recruitment process conducted by us,
- interact with our social media profiles.
3. Use of upmore.com, technical logs and security
When you use the website, our technical infrastructure may automatically process information necessary to display the website, ensure its proper operation and security, and diagnose errors. This may include, in particular, your IP address, the date and time of a request, the requested URL, information about your browser and device, technical connection parameters, server response status, and diagnostic and security-related data.
We process this data in order to:
- make the website available and ensure its proper operation,
- ensure the security of our systems and detect abuse,
- diagnose errors and incidents,
- ensure the performance and continuity of our infrastructure.
The legal basis for this processing is our legitimate interest in maintaining a secure and properly functioning website and protecting our systems and users (Article 6(1)(f) GDPR).
We retain technical data and logs for periods resulting from the configuration of the systems we use, and no longer than is necessary for security, diagnostics, business continuity or the investigation of a specific incident. The retention period may vary depending on the type of log and system. When the need for further processing ceases, data is deleted or overwritten in accordance with the retention cycle of the relevant system.
4. Contact forms and correspondence
If you contact us using a form, by email or in another way, we process your contact details and other information that you voluntarily provide in connection with your enquiry.
We process this data in order to:
- receive, handle and respond to your enquiry,
- conduct further correspondence concerning the matter,
- prepare an offer or take steps prior to entering into a contract, where your enquiry concerns this,
- establish, pursue or defend legal claims, where necessary.
The legal basis for processing is:
- Article 6(1)(f) GDPR – our legitimate interest in communicating, handling enquiries and documenting correspondence,
- Article 6(1)(b) GDPR – where processing is necessary, at your request, in order to take steps prior to entering into a contract to which you are to be a party,
- Article 6(1)(f) GDPR – to the extent necessary to establish, pursue or defend legal claims.
Data relating to an enquiry that does not result in a contract is retained for the period necessary to handle the enquiry and then for no longer than 24 months from the last contact. If the contact results in a contract, the data may continue to be processed under the rules applicable to customers. We may retain data for longer only where and to the extent justified by the need to establish, pursue or defend specific legal claims.
Information contained in enquiries may be stored in our email system and in the systems we use to manage enquiries, leads and projects.
5. Email marketing
If you voluntarily consent to receiving marketing communications from Up&More at the email address you provide, we may use that address and related contact details to send information about Up&More services and to contact you directly for marketing purposes by email.
The legal basis for processing personal data for this purpose is your consent (Article 6(1)(a) GDPR). The use of email to send commercial communications, including direct marketing, is based on the prior consent required under Article 398 of the Polish Electronic Communications Law.
Consent is voluntary and is not a condition for submitting a form or receiving a response to an enquiry. You may withdraw your consent at any time by contacting us at hello@upmore.com. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
We process data used for email marketing until you withdraw your consent or until we discontinue the relevant marketing purpose, whichever occurs first. After consent is withdrawn, we may retain limited information concerning the granting and withdrawal of consent where this is necessary to demonstrate the lawfulness of our activities, respect your decision or defend against legal claims. The legal basis for this limited processing is our legitimate interest (Article 6(1)(f) GDPR).
6. Customers and persons representing customers
If you are our customer, represent a customer, or participate in the performance of our cooperation on the customer’s side, we may process data necessary to enter into and perform a contract, maintain working contact, handle settlements and document our cooperation.
In particular, we process data for the following purposes:
- entering into and performing a contract – Article 6(1)(b) GDPR, if you are a party to the contract,
- organising cooperation and communicating with representatives, employees or associates of a customer – Article 6(1)(f) GDPR; our legitimate interest is the efficient performance of the contract and business communication,
- complying with tax, accounting and other legal obligations – Article 6(1)(c) GDPR,
- establishing, pursuing or defending legal claims – Article 6(1)(f) GDPR.
Data relating to the performance of a contract is retained for the duration of the cooperation. After the cooperation ends, accounting and tax documentation is generally retained for 5 years, calculated in accordance with the applicable laws. Other data relating to the contract may be retained until the applicable limitation period for claims expires; for claims related to business activity, this period is generally 3 years, subject to exceptions resulting from specific laws or the nature of a particular claim.
7. Contractors and persons representing contractors
If you provide services to us, supply goods to us, or represent an entity that is our contractor, we process data necessary to establish and perform the cooperation, communicate, handle settlements and protect our rights.
The legal basis for processing is, as applicable:
- Article 6(1)(b) GDPR – if you are a party to the contract,
- Article 6(1)(f) GDPR – if you represent a contractor or are a contact person; our legitimate interest is the efficient performance of business cooperation,
- Article 6(1)(c) GDPR – to the extent necessary to comply with tax, accounting and other legal obligations,
- Article 6(1)(f) GDPR – for the purpose of establishing, pursuing or defending legal claims.
Data relating to the cooperation is retained for its duration. After the cooperation ends, accounting and tax documentation is generally retained for 5 years, calculated in accordance with the applicable laws. Other data relating to the cooperation may be retained until the applicable limitation period for claims expires; for claims related to business activity, this period is generally 3 years, subject to exceptions resulting from specific laws or the nature of a particular claim.
8. Data of representatives and contact persons received from organisations
In our relationships with customers or contractors, we may receive your data not directly from you, but from the organisation you represent or cooperate with. In such a case, the source of the data is that organisation or a person acting on its behalf.
In such cases, we generally process identification and business data, such as your name, contact details, position or role within the organisation, and information relating to the cooperation and correspondence.
We process this data on the basis of Article 6(1)(f) GDPR. Our legitimate interest is to communicate with persons responsible for the cooperation and to properly manage business relationships.
The retention period corresponds to the period applicable to the relationship with the customer or contractor you represent, taking into account legal obligations and possible legal claims.
9. Events, training sessions and webinars
If you register for an event, training session, webinar or similar activity organised by us, we may process data necessary for registration, organisation of the event, communication with participants and documenting the event.
The legal basis for processing may be:
- Article 6(1)(b) GDPR – where participation is based on a contract or registration constitutes a step leading to its conclusion,
- Article 6(1)(f) GDPR – where processing is necessary to organise a free event or communicate with a participant; our legitimate interest is the organisation and administration of the event,
- Article 6(1)(c) GDPR – where we are required to retain certain data due to legal obligations,
- Article 6(1)(f) GDPR – to the extent necessary to establish, pursue or defend legal claims.
We retain data for the period necessary to organise and settle the event and then for the period resulting from legal obligations or justified by applicable limitation periods for legal claims. We do not use your data for email marketing solely because you participated in an event – such marketing contact requires a separate legal basis and, where required, consent.
10. Recruitment
If you participate in a recruitment process conducted by us, we process the data contained in your application, including contact details and information about your experience and qualifications, for the purpose of conducting the recruitment process.
The legal basis for processing is:
- Article 6(1)(b) or (c) GDPR in conjunction with Article 22¹ of the Polish Labour Code – with respect to data required or permitted under employment law, depending on the type of data and the purpose of processing,
- Article 6(1)(b) GDPR – where the recruitment concerns a civil-law contract or B2B cooperation,
- Article 6(1)(a) GDPR – with respect to additional data processed on the basis of your consent and where you consent to the use of your data in future recruitment processes.
We delete data relating to the current recruitment process after it has ended. If you consent to the use of your data in future recruitment processes, we process it until you withdraw your consent, but no longer than 12 months from the date on which the consent was given.
11. Social media profiles
We operate profiles on Facebook, Instagram and LinkedIn. If you interact with our profile, for example by following it, reacting to content, commenting or sending us a message, we process data associated with that interaction in order to operate the profile, communicate with you and promote our activities. The legal basis for this processing is our legitimate interest in promoting our brand and communicating with our audience (Article 6(1)(f) GDPR).
For certain statistical functions made available by social media services, we may act jointly with the provider of the relevant service as joint controllers where this follows from the rules and terms of that service. Independently of this, social media providers also process users’ data for their own purposes and on their own legal bases, in accordance with their privacy policies.
We process data relating to activity on our profiles for the period during which we operate the relevant profile and for as long as the interaction or content remains available on the service, unless it is deleted earlier or is no longer necessary for the stated purpose. If contact through a social media service leads to a business enquiry or cooperation, further processing takes place under the rules described in the relevant sections of this Policy.
12. Recipients of personal data
We do not sell your personal data.
To the extent necessary for the purposes described above, personal data may be disclosed to, or processed on our behalf by, the following categories of recipients:
- providers of hosting, cloud infrastructure, content delivery networks and other services related to maintaining the website,
- providers of email and communication tools,
- providers of systems for managing enquiries, leads, projects and business cooperation,
- providers of IT, security and system maintenance services,
- providers of accounting, tax, banking, payment and legal services,
- postal operators, couriers or other logistics providers where necessary for a particular matter,
- entities supporting us in marketing and analytics activities – to the extent resulting from the consents you have given and your privacy settings,
- public authorities or other entities entitled to receive data under applicable law.
Depending on the nature of the cooperation, these entities may act as processors acting on our instructions or as independent controllers.
Access to personal data within Up&More is limited to persons who need it to perform their duties.
13. Transfers of personal data outside the European Economic Area
We use technology and cloud service providers whose infrastructure or subprocessors may be located outside the European Economic Area (EEA), including in the United States. As a result, in certain cases personal data may be transferred to third countries.
Where such a transfer takes place, we use mechanisms provided for in Chapter V of the GDPR. Depending on the provider and the location of processing, this may include, in particular, a European Commission adequacy decision – where it covers the relevant recipient – or Standard Contractual Clauses approved by the European Commission together with any required supplementary safeguards.
You can obtain information about the safeguards used in a particular case and how to obtain a copy of them by contacting us at hello@upmore.com.
14. Cookies and similar technologies
We use cookies and similar technologies on the website, among other things, to ensure the website functions properly, remember settings and – after obtaining the appropriate consent – for analytics, measurement and marketing.
Technologies necessary for the operation of the website may be used without consent to the extent permitted by applicable law. Where their use involves the processing of personal data, the legal basis is our legitimate interest in ensuring the website operates properly, securely and in accordance with users’ choices (Article 6(1)(f) GDPR). Other technologies are activated after obtaining the required consent.
We use a cookie consent management tool available on the website. In its settings you can find up-to-date information on the categories and technologies used, their providers, purposes and retention periods.
You can change your preferences or withdraw your consent at any time using the „Manage cookies” option available on the website. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
To the extent that optional cookies or similar technologies involve the processing of personal data, the legal basis for processing is consent (Article 6(1)(a) GDPR). The rules concerning storing information on a user’s device and accessing such information are also governed by Article 399 of the Polish Electronic Communications Law.
15. Profiling and automated decision-making
We do not make decisions about you based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
If you consent to certain analytics or marketing technologies, the tools we use may enable the creation of statistics, segments or audience groups based on how you use the website. Detailed information about such technologies and their providers is presented in the cookie consent management tool.
16. How long we retain personal data
The retention period depends on the purpose of processing. The main rules are described above in the sections relating to the individual processing purposes.
In particular:
- enquiries that do not result in a contract – for a maximum of 24 months from the last contact,
- data processed on the basis of marketing consent – until consent is withdrawn or the marketing purpose ends earlier,
- data of candidates in an ongoing recruitment process – until the recruitment process ends; where consent is given for future recruitment processes – until consent is withdrawn, but no longer than 12 months from the date on which it was given,
- data relating to activity on our social media profiles – for the period during which we operate the profile and the relevant interaction or content remains available, unless the data is no longer necessary for the stated purpose earlier,
- data relating to contracts – for the duration of the cooperation and then until the applicable limitation period for claims expires; for claims related to business activity, this period is generally 3 years, subject to exceptions,
- accounting and tax documentation – generally for 5 years, calculated in accordance with the applicable laws,
- technical logs – in accordance with the retention cycle of the relevant system, no longer than necessary for security, diagnostics, business continuity or the investigation of an incident.
After data has been deleted from systems in active use, copies may remain in technical backups for a limited period in accordance with their rotation cycle.
17. Your rights
Depending on the legal basis and the circumstances of processing, you may have the right to:
- access your personal data and obtain a copy of it,
- rectify inaccurate data or complete incomplete data,
- have your data erased where the conditions provided for in the GDPR are met,
- restrict processing,
- object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation,
- object at any time to the processing of personal data for direct marketing purposes; after such an objection, we will no longer process the data for that purpose,
- data portability – where processing is based on consent or a contract and is carried out by automated means,
- withdraw consent at any time where processing is based on consent; withdrawal does not affect the lawfulness of processing carried out before the withdrawal,
- lodge a complaint with a supervisory authority.
In Poland, the supervisory authority is the President of the Personal Data Protection Office, ul. Stanislawa Moniuszki 1A, 00-014 Warsaw, Poland.
To exercise your rights, you may contact us at hello@upmore.com or by post at the Controller’s address.
We respond to requests without undue delay and, as a rule, no later than within one month of receiving them. In the cases provided for in the GDPR, this period may be extended by a further two months; if so, we will inform you of the extension and the reasons for it.
Exercising your rights is generally free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may – in the cases provided for in the GDPR – charge a reasonable fee or refuse to act on the request.
If we have reasonable doubts concerning the identity of the person making a request, we may ask for additional information necessary to confirm their identity.
18. Voluntary provision of personal data
Providing data in a contact form is voluntary, but without the data necessary to contact you, we may not be able to respond to your enquiry.
Giving marketing consent is entirely voluntary and does not affect your ability to submit an enquiry or use our services.
Where data is necessary to enter into or perform a contract, or is required by law, failure to provide it may prevent us from entering into a contract, taking a particular action or complying with a legal obligation.
19. Data security
We use appropriate technical and organisational measures to protect personal data against loss, unauthorised access, disclosure, alteration or destruction. The scope of the safeguards we use is adapted to the nature of the data, the manner in which it is processed and the risks identified.
Access to personal data is granted only to authorised persons and entities that need it to perform specific tasks and are required to protect the data appropriately.
20. Changes to this Privacy Policy
This Policy may be updated if our processing activities, services, technologies or applicable laws change. The current version and its effective date are published on upmore.com. If a change materially affects how we process your data or your rights, we will inform you in a manner appropriate to the circumstances.