Privacy Policy
1. General
This Privacy Policy (“Policy”) explains how Meloop Sp. z o.o. (“Meloop”, “we”, “us”) collects, uses, stores, and protects personal data of individuals whose data we process.
This Policy applies to all activities carried out by Meloop Sp. z o.o., in particular HR-related services, including:
HR outsourcing, payroll administration, HR consultancy, HR transformation, talent management and organisational support.
Where providing HR, payroll, consulting or outsourcing services, Meloop may act either as:
Data Controller – for its own candidates, employees, clients, and business partners, or
Data Processor – when processing personal data on behalf of its clients under a data processing agreement.
Company details:
Meloop Sp. z o.o., ul. Święty Marcin 29/8, 61-806 Poznań, Poland
KRS: 0001157692, NIP: 7831923490, REGON: 540991828
By using our website, submitting an application, filling in forms, or entering into a contract with us, you acknowledge that you have read and understood this Policy.
We process personal data in accordance with applicable data protection laws, including the GDPR and Polish data protection regulations.
1.1 Legal basis
All personal data is processed in accordance with:
- Regulation (EU) 2016/679 (GDPR),
- Polish data protection legislation,
- applicable labour, tax, and commercial laws.
1.2 Contact & complaints
For any questions regarding personal data, you may contact:
Data Protection Officer / Contact Point
Meloop Sp. z o.o.
Ul. Święty Marcin 29/8, 61-806 Poznań, Poland
Email: dataprivacy@meloop.eu
Phone: +48 721 361 540
You also have the right to lodge a complaint with the supervisory authority:
Data Protection Office (UODO – Urząd Ochrony Danych Osobowych), Poland
Ul. Stanisława Moniuszki 1A, 00-014 Warszawa
Email: kancelaria@uodo.gov.pl
1.3 Data breaches
We implement appropriate technical and organisational measures to protect personal data. In the event of a personal data breach, we will act in accordance with applicable legal obligations, including notifying affected individuals where required.
2. How We Collect Personal Data
We collect and process personal data in the following ways:
- directly from individuals (e.g. applications, contact forms, contracts, recruitment processes),
- from our clients (e.g. HR outsourcing, payroll, talent management or advisory services),
- from business partners and publicly available sources (e.g. LinkedIn, job boards, business registers),
- automatically via our website and IT systems (e.g. cookies, IP addresses, usage data),
- when visiting our premises or participating in events (e.g. visitor logs, CCTV where applicable).
Depending on the service, Meloop may act as either a Data Controller or Data Processor to process personal data on behalf of its clients under a data processing agreement and in accordance with applicable data protection laws.
3. Why We Use Personal Data
3.1 Purposes and legal bases
We process personal data to:
- provide HR, payroll, benefits and talent management, outsourcing, and advisory services,
- manage relationships with candidates, employees, clients, and partners,
- comply with legal and regulatory obligations,
- support business operations and internal processes,
- ensure IT security and business continuity,
- carry out marketing and communications activities (where permitted),
- health-related data processing (where applicable).
Legal bases:
- performance of a contract (Art. 6(1)(b) GDPR),
- legal obligation (Art. 6(1)(c) GDPR),
- legitimate interests (Art. 6(1)(f) GDPR),
- consent (Art. 6(1)(a) GDPR), where required,
- protection of vital interests, where applicable.
3.2 Categories of personal data
Candidates
We may process:
- Identification data (name, surname, date of birth, contact details)
- Contact details (email address, phone number, postal address)
- Professional experience (CV, employment history, qualifications, education, references)
- Recruitment data (interview notes, assessment results, interview feedback)
- Preferences (job interests, availability, salary expectations, mobility)
- Technical data (IP address, cookies, website usage data)
Special categories of data (where applicable):
- Data related to work eligibility or legal status
- Other sensitive data only if voluntarily provided or required by law
Employees / Workers / Individuals assigned to clients
We may process:
- Identification and employment data (name, address, ID numbers, employment history)
- Employment details (position, contract terms, salary, benefits)
- Payroll and tax data (bank account, tax identifiers, social security data)
- Time and attendance data (working hours, leave, absences)
- Performance and training data
- HR administration data (personnel files, onboarding/offboarding information)
- Emergency and compliance data (health & safety training, occupational medicine certificates)
Special categories of data (where applicable):
Health-related data strictly necessary for employment or legal compliance
Clients, prospects and business partners
We may process:
- Identification and business data (name, company name, VAT number, registration details, job title)
- Contact details (business email, phone number, address)
- Contract and service data (project descriptions, scope of services, duration, pricing)
- Financial data (invoices, bank details, payment history, contractual terms)
- Communication data (business correspondence and cooperation history)
- Compliance documents (certificates, declarations, legal and regulatory documentation)
Website and technical data
We may process:
- IP address
- Cookies and tracking technologies
- Website usage and analytics data
4. Disclosure of Personal Data
We may share personal data only where necessary for service delivery, legal compliance, or legitimate business purposes.
Recipients may include:
- authorised employees and personnel of Meloop,
- clients and business partners (where required for HR/recruitment/payroll services),
- service providers acting as data processors,
- public authorities and regulatory bodies (e.g. tax offices, social security institutions, courts, labour authorities),
- auditors, consultants, legal and compliance advisors,
- other entities where required by law or to establish, exercise, or defend legal claims.
- We do not sell personal data.
- Where data is shared, we ensure appropriate legal, technical, and organisational safeguards and conclude data processing agreements in accordance with Article 28 GDPR where applicable.
4.1 International transfers
Where personal data is transferred outside the EEA, we ensure appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission and additional security measures where required.
4.2 Categories of recipients
Personal data may be shared with:
- clients and business partners,
- IT, HR, payroll, cloud and software service providers (We work with trusted third-party providers acting on our behalf. These providers process data only under our instructions and subject to data processing agreements)
- accounting, legal, and tax advisors,
- regulatory and public authorities,
- auditors and compliance reviewers,
- occupational health and safety providers,
- insurance providers,
- dispute resolution or legal representatives.
5. Data retention
We retain personal data only as long as necessary for the purposes for which it was collected.
Retention is based on:
- contractual necessity,
- legal and regulatory obligations,
- limitation periods for legal claims,
- operational and business needs.
Typical retention periods:
- employment and payroll data: up to 10 years or as required by law,
- candidate data: for the duration of recruitment or until consent is withdrawn,
- client and financial data: as required by accounting and tax laws,
- communication and business data: for the duration of cooperation and legal limitation periods.
- where necessary, personal data may be retained for the duration of applicable limitation periods to enable the establishment, exercise or defence of legal claims.
For more information about specific retention periods, please contact our Data Protection Officer at: dataprivacy@meloop.eu
6. Your rights
As data subject, you have the following rights under applicable data protection laws:
- right of access – to obtain information about your personal data
- right to rectification – to correct inaccurate or incomplete data
- right to erasure – to request deletion of your data where legally applicable
- right to restriction of processing – to limit the processing of your data
- right to data portability – to receive your data in a structured format
- right to object – to object to processing based on legitimate interests or public interest
- right to withdraw consent.
These rights may be subject to certain legal limitations. We may not be able to delete your data where it is required to:
- comply with legal obligations
- establish, exercise or defend legal claims
- ensure compliance with regulatory requirements
- maintain necessary records for HR, payroll or tax purposes
Where deletion is not possible, we will inform you of the reason.
6.1 Exercising your rights
Requests should be sent to the contact details provided in Section 1.
6.2 Response time
We respond within one month. This period may be extended by up to two additional months if necessary.
You also have the right to lodge a complaint with the supervisory authority. Requests should be sent to the contact details provided in Section 1.
7. Cookies
Our website uses cookies and similar technologies. Detailed information is provided in our separate Cookie Policy.
8. Changes to this Policy
We may update this Policy from time to time to reflect legal, technical, or organisational changes. The latest version will always be available on our website.
9. Contact
Meloop Sp. z o.o.
Ul. Święty Marcin 29/8, 61-806 Poznań, Poland
Email: dataprivacy@meloop.eu
