In brief: we do not sell personal data. Forms are used to handle business enquiries and auditor applications. Optional technologies are not activated without a user choice. Privacy settings remain available through the floating shield icon.
1. Data controller
The controller is IQ CORPORATION PROSTA SPÓŁKA AKCYJNA (abbreviated as IQ CORPORATION P.S.A.), 40/1 Prezydenta Gabriela Narutowicza Street, 90-135 Łódź, Poland, National Court Register number KRS 0000992173, Polish tax number NIP 7252323396 and REGON 523129559 (“Controller”). Mystery-Shopper.pl is a brand operated by the Controller.
Privacy contact: Show email address, telephone Show phone number, or the registered-office address above. The Controller has not appointed a data protection officer.
2. Scope and sources
This policy applies when you browse the website, submit a business enquiry, contact us by email or telephone, or apply to cooperate as an auditor. Most information is obtained directly from you. Technical information is generated when your device connects to the website.
3. Data we may process
- business enquiries: name, company, email address, message and information voluntarily included in correspondence;
- auditor applications: name, telephone number, email, province, city, age, gender, student status, access to a car, experience and information voluntarily provided by the applicant;
- technical information: IP address, request date and URL, browser and device type, operating system, diagnostic data and form-security information;
- contract and accounting information: identification, contact, project-delivery and billing data if a business relationship is established.
Please do not submit special-category data, such as health, beliefs, origin or political views, unless this is expressly necessary and agreed in advance.
4. Purposes and legal bases
| Purpose | Legal basis | Scope |
|---|---|---|
| Responding to an enquiry and preparing a proposal | Article 6(1)(b) GDPR — pre-contractual steps; Article 6(1)(f) — efficient business communication | Form, email or call data |
| Reviewing an auditor application and contacting the applicant | Article 6(1)(b) GDPR; Article 6(1)(a) for additional data voluntarily supplied on the basis of consent | Information submitted on the Jobs page |
| Entering into and performing a contract | Article 6(1)(b) GDPR | Contacts, contractors and client representatives |
| Accounting, tax and corporate duties | Article 6(1)(c) GDPR | Information required by law |
| Website and form security; prevention of abuse | Article 6(1)(f) GDPR — protecting the website, users and Controller | Logs, technical information and reCAPTCHA signals |
| Establishing, exercising or defending legal claims | Article 6(1)(f) GDPR | Information relevant to the event or relationship |
| Optional analytics or electronic marketing | Article 6(1)(a) GDPR and Articles 398–400 of the Polish Electronic Communications Law, where applicable | Only after prior consent; no GA4, GTM or Google Ads tag is active at the date of this policy |
The required checkbox next to a form confirms that the privacy information has been read; it does not replace consent where consent is genuinely required by law.
5. Legitimate interests
Where Article 6(1)(f) GDPR applies, our interests are handling business correspondence, ensuring security, documenting arrangements, managing client and contractor relationships, and protecting against claims. We assess necessity, proportionality and the reasonable expectations of the individual.
6. Recipients
Information may be made available, on a need-to-know basis and under appropriate agreements, to hosting and email providers, IT and security support, communication or CRM providers, accountants, legal advisers and Google as the reCAPTCHA provider. Public authorities may receive information where disclosure is legally required. We do not sell personal data or contact databases.
7. Google reCAPTCHA and international transfers
Forms are protected by Google reCAPTCHA. It loads after interaction with a form begins and may process an IP address, browser and device information, referring page, interaction data and Google security identifiers. This is used to prevent automated abuse and spam.
The provider is Google Ireland Limited. Information may be further processed by Google companies outside the European Economic Area. Depending on the destination and entity, safeguards may include an adequacy decision such as the EU–US Data Privacy Framework or Standard Contractual Clauses. See the Google Privacy Policy and Google Terms.
8. Retention
- enquiries that do not lead to a relationship — generally up to 12 months after correspondence ends;
- auditor applications — during review and generally for up to 12 months, unless cooperation begins or consent covering additional data is withdrawn earlier;
- contract documentation — throughout the relationship and until relevant limitation periods expire;
- tax and accounting documents — for the statutory period, generally five years from the end of the relevant year;
- security logs — usually up to 30 days, or longer where required to investigate an incident;
- the privacy preference record — up to 180 days, after which a new choice is requested.
9. Your rights
Depending on the circumstances, you may request access, a copy, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Consent can be withdrawn at any time without affecting processing lawfully carried out before withdrawal.
Contact us to exercise a right. We may request information needed to confirm identity securely. We respond without undue delay and generally within one month.
10. Supervisory authority
You may lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), 2 Stawki Street, 00-193 Warsaw, Poland — uodo.gov.pl. You may also contact the supervisory authority of your habitual residence in the EU.
11. Whether data is required
Providing information is voluntary, but fields marked as required are needed to answer an enquiry or assess an application. Where information is required by contract or law, not providing it may prevent us from proceeding.
12. Automated decisions
We do not make decisions that produce legal or similarly significant effects solely by automated means. A reCAPTCHA score evaluates technical form risk, not the person and not the merits of an offer or application.
13. Cookies, localStorage and similar technologies
Strictly necessary technologies may operate without consent where needed for security or a function expressly requested by the user. Other categories require a prior choice. Refusing optional technologies does not restrict access to website content.
| Technology or category | Purpose | Period / status |
|---|---|---|
ms_cookie_consent_v2 — localStorage, necessary | Remembering the privacy choice and allowing it to be changed | Up to 180 days |
| Google reCAPTCHA — security | Protecting forms against spam and abuse; Google may use its own security identifiers | Activated on form interaction; Google determines its identifier retention |
| Analytics | Measuring website use | Inactive at publication; prior consent would be required before activation |
| Functional | Optional convenience settings | Inactive apart from storage of the privacy choice itself |
| Marketing | Advertising measurement and personalisation | Inactive at publication; requires consent |
Google Consent Mode v2
The website sets analytics_storage, ad_storage, ad_user_data and ad_personalization to denied by default and updates them after a user choice. Consent Mode is not an analytics tool, does not replace the consent interface and does not itself store the choice. No GA4, Google Tag Manager or Google Ads identifier is active on the website at the date of this update.
You can change the choice at any time through the floating shield icon in the lower-right corner, or clear site data in your browser settings.
14. External links
The website may link to external services. Once you follow a link, that operator acts as a separate controller and applies its own privacy terms.
15. Security
We apply organisational and technical measures proportionate to risk, including HTTPS encryption, access controls, backups, form protection and component updates. No transmission or storage method can guarantee absolute security.
16. Changes
We update this policy when the law, website functionality or providers change. The current version and effective date are published at this URL. If a change requires renewed consent, a new choice will be requested.