👋 Wish to GROW with Ad Exchange or Google Ad Manager?                      

GDPR & Privacy Policy

GDPR & Privacy Policy

I. General Information

The purpose of this privacy policy is to define the principles under which personal data is collected and processed at Waytogrow. The privacy policy also specifies the purpose for which this data is collected and why Waytogrow needs it.
The Controller participates in the IAB (Interactive Advertising Bureau – Internet Industry Employers’ Association), an organization that brings together entities from the internet industry, whose goal is to take action to represent the interests of these entities, provide promotional activities, and provide legal protection. Waytogrow participates in and accepts the assumptions and principles adopted by the IAB as part of the IAB Europe Transparency & Consent Framework, a structure whose goal is to create a standard for the processing of personal data and unify the principles of their processing in order to better protect them.

II. Definitions

Controller/Company/Waytogrow – controller of Users’ personal data within the meaning of the GDPR; The Controller of personal data is Waytogrow Spółka z ograniczoną odpowiedzialnością with its registered office in Warsaw, Al. Ujazdowskie 13, 00-567 Warsaw, entered into the register of entrepreneurs maintained by the District Court for the Capital City of Warsaw, XII Commercial Division of the National Court Register under number 0000706495 , REGON: 361397727 , NIP: 6751517416 , share capital: PLN 5,000 ;

Personal Data – this is information that allows for the identification of a natural person (User), obtained by the Controller in the manner specified in this privacy policy; the scope of Personal Data obtained about the User is specified in point VI of the privacy policy; 


Cookies, Identifiers – these are small information files that constitute the User’s identifier, allowing for the separation and distinction of the User from other users of a given website or application and determining how the User uses the website or application; Cookies and other Identifiers are sent by the website to the User and installed on their end device, e.g. computer, laptop, mobile phone, tablet;

User – this means a person whose Personal Data are collected and processed via Cookies or other Identifiers by the Controller; 


Publisher – the owner or entity managing a given website or application through which Cookies or other Identifiers belonging to the Publisher or Controller are installed at the User, who collects Personal Data on behalf of Waytogrow and fulfills the information obligation on behalf of Waytogrow.

III. Details of the Controller – contact information

The Controller of Users’ Personal Data is Waytogrow Spółka z ograniczoną odpowiedzialnością with its registered office in Warsaw, at Al. Ujazdowskie 13, 00-567 Warsaw, entered into the register of entrepreneurs maintained by the District Court for the Capital City of Warsaw, Xii Commercial Division of the National Court Register under the number 0000706495 , REGON: 361397727 , NIP: 6751517416 , share capital: PLN 5,000 ; Contact with the Controller is possible via:

  • traditional mail – address: Waytogrow Sp. z o. o., Al. Ujazdowskie 13, 00-567 Warszawa;
  • e-mail address: [email protected]

To ensure the security of Personal Data and facilitate communication, the Controller has appointed a Data Protection Officer. The Data Protection Officer can be contacted via email at: [email protected] .

As part of Waytogrow’s collaboration with Publishers or as part of its own marketing activities, Cookies or other Identifiers which collect Personal Data may be installed on Users’ end devices, after they have provided consent. Depending on the content and scope of the User’s consent, Personal Data may be collected and processed for the following purposes:

  1. identifying Users for the purposes of advertising and programmatic advertising processes by entities cooperating with Waytogrow – advertising market participants (in particular SSP providers, advertising platforms, advertising exchanges and other technological partners – listed in section VII);
  2. tailoring the displayed advertisements on websites based on Users’ current activity. The Controller tailors the advertisements displayed to Users, including in cooperation with the Publisher and advertising technology providers, by optimizing and suggesting, among other things, their display time and the number of displayed advertisements, using data about the User’s end device, their operating system, and the intensity of website use;
  3. supporting the development of the Cntroller’s programming tools;
  4. keeping statistics, including:
  • statistics on the accuracy and effectiveness of advertising messages directed to Users,
  • statistics on the relevance and effectiveness of non-advertising content directed to Users,
  • statistics of interest in particular content displayed on websites by particular groups of Users;
  • creating reports and market research;
  1. ensuring the security of websites and applications, preventing fraud, identifying and solving technical problems related to the operation of the website and the display of content and advertising on it;
  2. technical display of the content of websites and applications;
    websites and applications require obtaining certain data about the User in order to display the content correctly – e.g. their IP address, web browser, screen resolution;
  3. contact via the contact form – for the purpose of answering your questions.
  4. conducting own marketing;

The basis for the processing of personal data indicated in points [1-2] and [8] is the User’s consent to the processing of data for these purposes and the installation of Cookies or other Identifiers on the User’s end device. Consent to this action is granted by checking the appropriate boxes on the Publisher’s website for points [1-2] and on the Waytogrow website for point [8].
The Controller will process Users’ Personal Data only in accordance with the content of their consents to the processing of Personal Data, which means that any personal data processing operations not based on the User’s consent will not be implemented by the User, unless the Controller performs them based on a legal basis other than the User’s consent, e.g., based on a legitimate interest. The basis for the processing of personal data indicated in points [3-7] is the Controller’s legitimate interest:

  • In the case of point [3], this is the ability to develop, test, and improve programming tools, advertising technologies, and analytical solutions used by the Controller, in particular by analyzing how websites are used, identifying errors, assessing the efficiency of the solutions used, and implementing new functionalities. These activities are intended to improve the quality of the services provided, increase their security, and adapt them to the needs of users and business partners, but do not lead to decisions being made with respect to Users that would have legal effects on them or similarly significantly affect them.
  • in the case of point [4], it is the ability to create and maintain anonymous statistics on the effectiveness of marketing activities undertaken by the Controller and Publishers, e.g. optimization of displayed advertisements; these activities do not in any way affect the rights and freedoms of Users, and only enable the assessment of the effectiveness of the website in the context of the displayed advertising content, understood as determining the reach of a given content (e.g. the popularity of an article or advertisement);
  • in the case of point [5], it is the Controller’s obligation to ensure the resilience and security of the website, programming tools and personal data collection systems against unauthorized third parties, as well as to remove errors related to the functioning of the website;
  • in the case of point [6], it is the need to display websites correctly, i.e. in a manner in which all elements of the website are displayed in the intended and correct manner, e.g. they are of appropriate size, enable the User to interact correctly and effectively with the website, e.g. filling out forms, operations carried out by Waytogrow do not affect the functioning of the website or applications for which marketing activities are carried out;
  • in the case of point [7] consisting in the possibility of contacting you in order to answer your question and maintain business relations.

For the purposes of processing listed above, the Controller may use the default settings of the browser installed on the User’s end device and the information sent by it to identify a given User and their end device from other users of a given website. Using the functionality of Cookies or other identifiers, the Controller may also collect additional information about the User and their end device, which is not sent by that end device by default, in order to identify them based on a unique set of individual information about that end device – e.g., installed and used fonts, screen resolution.

Providing Personal Data and enabling the installation of Cookies or other Identifiers is entirely voluntary and is not a contractual or statutory requirement, however, failure to consent to the processing of Personal Data and the installation of Cookies or other Identifiers will result in the inability to adapt the content and advertisements displayed to the User on the Publishers’ websites to his or her preferences.

Waytogrow uses Cookies and other Identifiers to recognize and identify Users when they visit Publishers’ websites and applications, enabling it to better tailor advertising and content to Users’ interests and expectations. Waytogrow also uses Identifiers to create anonymous website and application visitor statistics and to determine which content users found most interesting.

Cookies also make using the website interface much more convenient, for example, by storing content display preference settings and interacting with the website. Users can independently change their cookie settings at any time, specifying the conditions for their storage and access by cookies to the User’s device. Users can change these settings using their web browser settings. These settings can be changed, in particular, to block the automatic handling of cookies in the web browser settings or to notify the User each time cookies are placed on their device. Detailed information about the possibilities and methods of handling cookies is available in the software (web browser) settings.

The User may delete Cookies at any time using the functions available in the web browser he or she uses.

In the case of applications installed on the end device and consent to the processing of personal data, the User may make changes to the application settings.

VI. What data is being gathered?

The Controller obtains Personal Data using Cookies or other Identifiers installed on Users’ end devices via websites or applications belonging to Publishers. Personal Data concerns User behavior on websites and in applications used, including: reach, frequency and duration of website visits, topics of articles viewed, categories of websites visited, information on ad clicks, its type, content and characteristics of clicked advertising creatives, and information on the types of advertisements displayed to the User.

The information collected by the Controller may also include the IP address of the end device used by the User, the type of end device, the version of the browser, the screen resolution, installed fonts, information about the operating system used, and geolocation data . In the case of the contact form (the purpose of processing Personal Data specified in point IV item [3]), the collected data includes your e-mail address, telephone number, first name and last name.

VII. Recipients of the Personal Data

Personal Data collected by the Controller may be transferred to entities cooperating with the Company, including the following recipients:

  1. Technology providers – providers of server and hosting services, entities offering IT solutions enabling the display of advertisements and content on websites and maintaining statistics on User interactions and visits – as entities processing personal data on behalf of the Controller;
  2. entities operating in the programmatic advertising market , including SSP providers, advertising platforms, advertising exchanges, identification partners and other technological partners cooperating with the Controller in the implementation of the processes of broadcasting, matching, purchasing, selling and optimizing advertisements – as separate controllers of personal data;
  3. IAB – in connection with its participation in the IAB Europe Transparency & Consent Framework, for the purpose of assessing the compliance of processing with the standards set by the IAB Europe Transparency & Consent Framework.
    Each time, the Controller ensures that Personal Data is transferred to any recipient securely, while maintaining all technical requirements.

VIII. Transferring Personal Data outside of the European Economic Area

Your Personal Data may be shared outside the EEA or with international organizations, but each time such sharing is conducted in compliance with the security principles of the personal data being processed. Personal Data is transferred to the Company’s partners and contractors based outside the EEA if:

  1. this entity is based in a country that, in accordance with the decision of the European Commission, ensures an adequate level of protection of personal data;
  2. standard EU data protection clauses have been used in the agreements concluded by the Controller with this entity; to obtain a copy of the standard EU data protection clauses used by the Company, please contact the DPO or the Company.

IX. Duration of the period through which the Personal Data is to be processed

Personal Data will be processed in the Company:

  • until you exercise your rights resulting in the obligation to cease further processing of your personal data;
  • until you set appropriate browser settings for storing or accessing Cookies or other Identifiers that exclude such a possibility;
    However, regardless of the above, Personal Data will not be processed by the Controller for longer than 12 months.

X. Rights of the Users

  1. The User is entitled to obtain confirmation from the Controller as to whether his or her Personal Data are being processed, and if so, he or she is entitled to access them and the following information:
  • purpose of processing;
  • the categories of personal data concerned;
  • information on recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
  • where possible, the planned period for which personal data will be stored and, if this is not possible, the criteria for determining this period;
  • information about the right to request the Controller to rectify, delete or limit the processing of personal data relating to the data subject and to object to such processing;
  • information on the right to lodge a complaint with the supervisory authority;
  • if the personal data were not collected from the data subject – all available information about their source;
  • information on automated decision-making that produces legal effects (or similarly significantly affects Users) referred to in Article 22 paragraphs 1 and 4 of the GDPR, and – at least in these cases – relevant information on the principles of their making, as well as on the significance and anticipated consequences of such processing for the data subject – at present, the Controller does not conduct such activities.
  1. The User has the right to request from the Controller immediate rectification of any inaccurate Personal Data concerning them. Taking into account the purposes of processing, the User has the right to request the completion of incomplete Personal Data, including by providing an additional declaration.
  2. The User has the right to demand that the Controller immediately delete his/her personal data, and the Controller is obliged to delete personal data without undue delay if one of the following circumstances occurs (“the right to be forgotten”):
  • Personal Data are no longer necessary for the purposes for which they were collected or otherwise processed;
  • You have withdrawn consent on which the processing is based pursuant to Article 6(1)(a) of the GDPR and there is no other legal basis for the processing;
  • The User objects to the processing under Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or the User objects to the processing under Article 21(2) of the GDPR;
  • Personal Data were processed unlawfully;
  • Personal Data must be erased in order to comply with a legal obligation under European Union law or the law of the Member State to which the Controller is subject;
  • The Personal Data were collected in connection with the provision of information society services referred to in Article 8(1) of the GDPR.
  1. The User has the right to request the Controller to limit processing in the following cases:
  • The User questions the accuracy of the Personal Data – for a period enabling the Controller to check the accuracy of such data;
  • the processing is unlawful and the User opposes the deletion of Personal Data, requesting instead that their use be restricted;
  • The Controller no longer needs the Personal Data for the purposes of processing, but the data subject requires them to establish, pursue or defend legal claims;
  • The User has lodged an objection under Article 21(1) of the GDPR to the processing – pending determination of whether the legitimate grounds on the part of the Controller override the grounds for objection of the User whose data is being processed.
  1. If Personal Data are processed for direct marketing purposes, the Data Subject has the right to object at any time to the processing of his or her personal data for such marketing purposes, including profiling, to the extent that the processing is related to such direct marketing (“right to object”).
  2. You have the right to receive the Personal Data concerning you, which you have provided to the Controller, in a structured, commonly used and machine-readable format, and you have the right to transmit these Personal Data to another controller without hindrance from the Controller to whom the Personal Data have been provided, if: the processing is based on consent pursuant to Article 6(1)(a) of the GDPR or on a contract pursuant to Article 6(1)(b) of the GDPR; and the processing is carried out by automated means.
  3. When exercising the right to data portability, the User has the right to request that the Personal Data be sent by the Controller directly to another controller, if technically possible.
  4. The User has the right to withdraw consent to the processing of Personal Data, granted under Article 6(1)(a) of the GDPR, at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
  5. In order to exercise the other rights mentioned above, please contact the Controller in the form provided in the section: “Controller’s Data – Contact”.
  6. The User has the right to lodge a complaint with the national supervisory authority appointed to protect personal data.

XI. Safety Provisions

The Controller does not collect sensitive data, such as racial or ethnic data, data on religious or ideological beliefs, trade union membership, biometric data, data on health, sexuality or sexual orientation.

The Controller’s collaboration with Publishers is not based on websites whose content would be intended for persons under 16 years of age. Therefore, the Controller’s system does not intentionally collect any personal data from persons under 16 years of age.
The Controller also does not collect any data whose processing could cause moral or material harm. Only the data indicated in section VI. “What Personal Data is collected?” is processed in the Controller’s system.

Collected Personal Data is stored on secure, dedicated servers, and only authorized employees and associates of the Controller have access to it.
Information about Users, which does not contain data that can be used to directly identify Users, is shared only with the entities indicated in Section VII, while maintaining all security principles for its processing.

Is your head full of unanswered questions? Get them here!

contact form icon contact form icon contact form icon contact form icon contact form icon