NORTHON / PRIVACY

Privacy policy

Clear data protection rules for Northon.pl and the company LinkedIn integration.

1. Data controller

The controller is Northon Spółka z ograniczoną odpowiedzialnością, 4 Zofii Nałkowskiej Street, 77-100 Bytów, Poland. For privacy or deletion requests, contact office@northon.pl.

2. Website and contact enquiries

When you use Northon.pl, the server may process your IP address, request date and time, visited URL, browser and device information, and diagnostic data. We use these data to operate and secure the website and detect abuse, based on our legitimate interests.

The Knowledge Centre form prepares a message in your email application and does not submit it directly to our server. If you email us, we process the name, company, email address and message you provide to answer your enquiry, take pre-contractual steps or manage our business relationship.

3. Cookies and Google Ads

We use essential browser storage to remember your privacy choice. With your consent, Google Ads may use advertising data and cookies to measure campaign performance and conversions such as phone, email or form interactions.

Before consent, advertising, analytics and personalisation storage are denied. Limited cookieless technical signals may still be sent to Google through Consent Mode. You can change your choice at any time using the “Privacy” button on the website. Withdrawal does not affect processing carried out before it.

4. Company LinkedIn integration

Northon’s password-protected editorial panel allows authorised staff to prepare news for Northon.pl and, after a separate selection, publish it to Northon’s company Page on LinkedIn. The integration uses LinkedIn’s official API and the w_organization_social permission.

Data we process

  • the company Page administrator’s authorisation code and OAuth token, token expiry and connection date;
  • company post content, title, link and publishing status;
  • technical logs required for security and troubleshooting.

We do not retrieve contacts, private messages or private profile content. We do not publish to the administrator’s personal profile. A post is sent only to the selected Northon company Page and only after a user clicks the publishing button in the panel.

Purpose, legal basis and sharing

We use these data solely to authenticate the administrator and publish approved company materials. The legal bases are the connecting person’s consent and Northon’s legitimate interest in managing company communications. LinkedIn data are not sold, used for profiling or shared with other advertisers.

LinkedIn Ireland Unlimited Company and Vercel Inc., which provides hosting and private data storage, support the integration. Transfers outside the EEA may rely on safeguards recognised by law, including relevant adequacy decisions and standard contractual clauses.

Disconnecting and deleting LinkedIn data

An administrator can revoke access in their LinkedIn account settings or email office@northon.pl to request disconnection and token deletion. We delete API data, including the token, promptly after such a request, when use of the integration ends, or when required by LinkedIn’s terms, unless retention is required by law.

LinkedIn also acts as an independent controller under its own Privacy Policy.

5. Recipients and retention

Recipients may include hosting and IT infrastructure providers, email providers, Google for Google Ads, and LinkedIn for the company integration. Depending on the service, they act under data-processing terms or as independent controllers.

  • correspondence is retained while we handle the matter or relationship and for the period needed to establish or defend claims;
  • security logs are retained only as long as needed for diagnostics and service protection;
  • your cookie choice remains in browser storage until changed or removed;
  • the LinkedIn token is retained until expiry, disconnection or a deletion request.

6. Your rights

Where the GDPR applies, you may request access, rectification, erasure, restriction, portability, or object to processing. You may withdraw consent at any time. We respond without undue delay and generally within one month.

You may lodge a complaint with the President of the Polish Personal Data Protection Office. Contact details are available at uodo.gov.pl.

7. Security and policy changes

We apply safeguards appropriate to the risk, including restricted panel access, AES-256-GCM encryption of the LinkedIn token, private file storage, session protection and HTTPS. We may update this policy when laws, services or the integration change. The current version is always available at this URL.