NORTHON / PRIVACY
Privacy policy
Clear data protection rules for Northon.pl and the company LinkedIn integration.
1. Data controller
The controller is Northon Spółka z ograniczoną odpowiedzialnością, 4 Zofii Nałkowskiej Street, 77-100 Bytów, Poland. For privacy or deletion requests, contact office@northon.pl.
2. Website and contact enquiries
When you use Northon.pl, the server may process your IP address, request date and time, visited URL, browser and device information, and diagnostic data. We use these data to operate and secure the website and detect abuse, based on our legitimate interests.
The Knowledge Centre form prepares a message in your email application and does not submit it directly to our server. If you email us, we process the name, company, email address and message you provide to answer your enquiry, take pre-contractual steps or manage our business relationship.
4. Company LinkedIn integration
Northon’s password-protected editorial panel allows authorised staff to prepare news for Northon.pl and, after a separate selection, publish it to Northon’s company Page on LinkedIn. The integration uses LinkedIn’s official API and the w_organization_social permission.
Data we process
- the company Page administrator’s authorisation code and OAuth token, token expiry and connection date;
- company post content, title, link and publishing status;
- technical logs required for security and troubleshooting.
We do not retrieve contacts, private messages or private profile content. We do not publish to the administrator’s personal profile. A post is sent only to the selected Northon company Page and only after a user clicks the publishing button in the panel.
Purpose, legal basis and sharing
We use these data solely to authenticate the administrator and publish approved company materials. The legal bases are the connecting person’s consent and Northon’s legitimate interest in managing company communications. LinkedIn data are not sold, used for profiling or shared with other advertisers.
LinkedIn Ireland Unlimited Company and Vercel Inc., which provides hosting and private data storage, support the integration. Transfers outside the EEA may rely on safeguards recognised by law, including relevant adequacy decisions and standard contractual clauses.
Disconnecting and deleting LinkedIn data
An administrator can revoke access in their LinkedIn account settings or email office@northon.pl to request disconnection and token deletion. We delete API data, including the token, promptly after such a request, when use of the integration ends, or when required by LinkedIn’s terms, unless retention is required by law.
LinkedIn also acts as an independent controller under its own Privacy Policy.
5. Recipients and retention
Recipients may include hosting and IT infrastructure providers, email providers, Google for Google Ads, and LinkedIn for the company integration. Depending on the service, they act under data-processing terms or as independent controllers.
- correspondence is retained while we handle the matter or relationship and for the period needed to establish or defend claims;
- security logs are retained only as long as needed for diagnostics and service protection;
- your cookie choice remains in browser storage until changed or removed;
- the LinkedIn token is retained until expiry, disconnection or a deletion request.
6. Your rights
Where the GDPR applies, you may request access, rectification, erasure, restriction, portability, or object to processing. You may withdraw consent at any time. We respond without undue delay and generally within one month.
You may lodge a complaint with the President of the Polish Personal Data Protection Office. Contact details are available at uodo.gov.pl.
7. Security and policy changes
We apply safeguards appropriate to the risk, including restricted panel access, AES-256-GCM encryption of the LinkedIn token, private file storage, session protection and HTTPS. We may update this policy when laws, services or the integration change. The current version is always available at this URL.
