1. Data Controller
The data controller is PP Solutions Przemysław Pietrzak with its registered office in Warsaw, Szczęsna 26, 02-454 Warsaw, Poland, NIP: 5993248563, REGON: 386176659.
2. Data protection contact
For data protection matters, contact the Controller directly at: [email protected]
3. Processing Purposes
Personal data is processed for the following purposes:
- Pre-contract steps, contract performance, and service provision.
- Communication with clients and contractors and account management.
- System security, abuse prevention, and establishing, exercising, or defending claims.
- Website analytics after analytics consent and advertising measurement after separate marketing consent.
- Direct marketing where the appropriate legal basis and required consents exist.
- Fulfilling legal, accounting, and tax obligations.
4. Legal Basis for Processing
Data is processed on the basis of:
- Article 6(1)(b) GDPR - pre-contract steps and contract performance.
- Article 6(1)(c) GDPR - compliance with a legal obligation.
- Article 6(1)(f) GDPR - security, service administration, and claims after a balancing assessment.
- Article 6(1)(a) GDPR together with sections 399(1) and 400 of the Polish Electronic Communications Law - optional analytics, advertising, and terminal technologies.
5. Personal Data Categories
We process the following data categories:
- Identification data (name, surname, company name)
- Contact data (email, phone, address)
- Cooperation data (contact history, contracts)
- Consultation-booking data (selected time, status, and service language)
- Technical and security data (IP address, request time, system logs)
- Minimal preference and consent-evidence data
- After the relevant consents: pseudonymous analytics data and restricted marketing attribution
6. Data Recipients
Data may be disclosed to:
- IT, hosting, email, security, and support providers acting as processors.
- Google Ireland Limited: Google Analytics 4 after analytics consent and Google Ads after marketing consent; its processor or independent-controller role depends on the service and enabled settings.
- Windsor Group AG as a processor providing read-only integration and selected-data reporting.
- After the relevant consent and only when enabled: Google Ireland Limited (reCAPTCHA, Google Maps, YouTube) and Vimeo.com, Inc.
- The operator of the configured ntfy instance receives only minimized lead-alert data, without contact details, form content, or advertising identifiers.
- Accounting and legal service providers.
- Public authorities where disclosure is required by law.
7. Retention Period
Data is stored for the period:
- Contract, accounting, tax, and claims data - for the period resulting from applicable laws and limitation periods.
- Unconverted contact and project inquiries and related consultation bookings - no more than 12 months after the last meaningful activity; after that, content and contact details are anonymised unless an active project, contract, legal obligation, or documented legal-claims need requires continued retention.
- Pseudonymous session identifier - until 30 minutes of inactivity; client identifier, raw analytics events, and first-party attribution - no more than 90 days. Raw click identifiers occur in PP Solutions restricted sales attribution only after marketing consent.
- Minimal consent evidence - no more than 13 months from recording, including withdrawal or version-replacement records.
- After retention expires, data is deleted or irreversibly aggregated unless law requires longer storage.
8. Data Subject Rights
Every person has the right to:
- Access to their personal data
- Rectification of incorrect data
- Erasure of data (right to be forgotten)
- Restriction of processing
- Portability of data to another controller
- Object to processing
- Withdraw consent at any time
9. Consent for Processing
Consent is freely given, specific, informed, unambiguous, and separated by category. It can be rejected or withdrawn as easily in Cookie settings or by contacting the Controller. Withdrawal stops future optional processing and does not affect the lawfulness of prior processing. A material change in purpose, provider, or data requires fresh consent.
10. Security Measures
We apply appropriate technical and organizational measures to ensure data security:
- Data encryption in transmission and storage
- Access control to systems
- Regular software updates
- Data backup and recovery
- Employee training in data protection
11. Data Transfer Outside EEA
We do not claim that all processing remains in the EEA. Google, Windsor Group AG, Vimeo, the operator of any hosted ntfy instance, and their approved subprocessors may process data in the EEA, Switzerland, or other countries. Depending on the recipient, a transfer relies on an adequacy decision, the EU-U.S. Data Privacy Framework, or European Commission Standard Contractual Clauses with required supplementary measures. Information about the applicable mechanism is available from the Controller.
12. Cookies
Basic Consent Mode blocks Google Analytics, Google Ads, optional scripts, storage, pixels, beacons, and events until the relevant consent. We use:
- Strictly necessary storage for consent choices, security, and features explicitly requested by the user.
- Google Analytics 4 and privacy-safe events only after analytics consent.
- Google Ads, advertising cookies, and click identifiers only after marketing consent.
- sessionStorage for a session identifier expiring after 30 minutes of inactivity and localStorage for a client identifier lasting no more than 90 days; both only after analytics consent, without form values or PII.
13. Complaint to Supervisory Authority
In case of personal data protection regulations violation, the person has the right to lodge a complaint with the President of the Personal Data Protection Office.
14. Contact
For matters related to personal data protection, please contact:
15. Policy Changes
We publish the change date. A material change in purpose, provider, or data scope triggers versioned re-consent before the changed category resumes.