Privacy Policy

Last update: July 21, 2026

1. General Information

The data controller is PP Solutions Przemysław Pietrzak with its registered office at Szczęsna 26, 02-454 Warsaw, Poland, NIP: 5993248563, REGON: 386176659. This Privacy Policy explains processing relating to website users and clients, including forms, accounts, security, consent for terminal technologies, and analytics or advertising activated only in accordance with the user's choice.

2. Personal Data We Collect

Depending on the feature used and the consents granted, we may process:

  • Contact and identification data provided in a form or account: name, email address, phone number, and company name.
  • Project information provided by the user, such as requirements, budget, and timeline.
  • Consultation-booking data linked to the inquiry: the selected start and end time, status, and service language.
  • Technical and security logs necessary to protect the website and accounts, including IP address, request time, browser type, and operating system.
  • Evidence of entering into an agreement in the Client Panel: account and proposal identifier, version and exact acceptance statement, accepted proposal parameters, timestamp, SHA-256 hash, IP address, user agent, and request identifier. These are contract and evidentiary data, not marketing analytics.
  • Minimal server-side consent evidence: a pseudonymous receipt identifier, policy version, time, category, and the recorded granted/denied state; without IP address, user agent, or advertising identifiers. Preference language remains only in essential browser storage.
  • After analytics consent: a pseudonymous session identifier in sessionStorage, the pp_analytics_client_id client identifier in localStorage, UTM campaign parameters, page path, scroll thresholds, engagement buckets, CTA type and placement, and controlled form-friction events.
  • After marketing consent: advertising click identifiers such as gclid, wbraid, and gbraid; Google Ads may process them for advertising measurement and they may enter PP Solutions restricted sales attribution.

3. Data Collection Methods

We collect data directly from the user or from the features they use:

  • Through the contact form, project request form, account registration, and email communication.
  • Through the first-party consultation scheduler after a project request has been recorded.
  • When logging in to and using the client or admin panel, to the extent needed to provide and secure the service.
  • Through the cookie and similar-technology preference manager, which records category choices.
  • Through Google Analytics 4 only after analytics consent and through Google Ads only after marketing consent.
  • Through restricted server reports and the Windsor.ai integration, without a Windsor.ai browser tag.

4. Purpose of Data Processing

We process data for the following separate purposes:

  • Responding to inquiries, preparing an offer, entering into and performing a contract, and account support.
  • Booking, rescheduling, or cancelling a consultation and sending the related transactional confirmations.
  • Security, abuse prevention, incident diagnosis, and establishing, exercising, or defending legal claims.
  • Fulfilling legal, accounting, and tax obligations.
  • Website analytics and user-journey improvement only after analytics consent.
  • Source and campaign reporting after analytics consent, and advertising-click measurement and advertising-conversion attribution only after marketing consent.
  • Direct marketing through separate channels only where the appropriate legal basis and required consents exist.

5. Legal Basis for Processing

The legal basis depends on the purpose and operation:

  • Article 6(1)(b) GDPR: steps requested before entering into a contract and contract performance.
  • Article 6(1)(c) GDPR: legal obligations, in particular accounting and tax obligations.
  • Article 6(1)(f) GDPR: security, legal claims, and necessary service administration after a balancing assessment.
  • Article 6(1)(a) GDPR and sections 399(1) and 400 of the Polish Electronic Communications Law: optional analytics, advertising, and terminal technologies.
  • Section 399(3) of the Polish Electronic Communications Law: storage or access strictly necessary for transmission or a service explicitly requested by the user.

6. Data Retention Period

We apply separate and limited retention periods:

  • Inquiry, proposal, and related consultation-booking data: for handling the matter and the period needed to establish, exercise, or defend claims; contract, accounting, and tax data for the period required by law.
  • Agreement acceptance evidence and immutable proposal snapshots: for the agreement term and then for the period needed to establish, exercise, or defend claims; a legal hold may temporarily suspend deletion.
  • The pseudonymous session identifier is stored in sessionStorage and expires after 30 minutes of inactivity; pp_analytics_client_id is stored in localStorage for no more than 90 days. Both are created only after analytics consent and removed after withdrawal or a version change requiring fresh consent.
  • Raw analytics events and pseudonymous client attribution: no more than 90 days from the event; then deletion or retention only as data aggregated so it cannot be related to an individual.
  • Client and session identifiers are pseudonymised with a keyed HMAC before backend storage. PP Solutions restricted sales attribution may retain raw gclid, wbraid, and gbraid after marketing consent for no more than 90 days and then deletes them; the analytics event store rejects them. Separate processing by Google Ads follows the live account settings and Google terms.
  • Minimal consent evidence: no more than 13 months from recording, including a record of withdrawal or policy-version replacement; this is an operational cap subject to periodic legal review.

7. Data Sharing

Recipients or processors may include, only to the extent necessary:

  • Hosting, infrastructure, email, security, and technical-support providers acting on our documented instructions.
  • iFirma as the invoicing and accounting system for the PP Solutions Przemysław Pietrzak sole proprietorship. A future P.S.A. will use a separate configuration and accounting system, without shared numbering or credentials.
  • The payment provider selected for the transaction, currently Stripe or PayPal and, after separate configuration, Przelewy24; it receives data needed to create, confirm and settle the payment. Traditional bank transfers are reconciled using bank data and the payment reference.
  • Google Ireland Limited for Google Analytics 4 after analytics consent and Google Ads after marketing consent. For GA4, Google acts as a processor under the applicable processing terms; for enabled data-sharing or Ads functions it may act as an independent controller under the relevant terms.
  • Windsor Group AG as a processor providing read-only ELT integration and reporting for selected Google sources and restricted backend reporting views under its DPA.
  • After separate functional or external-content consent: Google Ireland Limited for reCAPTCHA, Google Maps, and YouTube, and Vimeo.com, Inc. for embedded Vimeo media, where the feature is enabled.
  • The configured ntfy instance for operational lead alerts; it receives only minimized signals without form content, contact details, or advertising identifiers. The Controller documents the hosting operator and processing terms before enabling the service.
  • Accounting and legal providers and public authorities where disclosure is required by law.
  • We do not sell personal data or disclose it to partners for their own marketing without a separate legal basis.

8. User Rights

Subject to the conditions in the GDPR, you have the right to:

  • Access your data, receive a copy, and rectify inaccurate data.
  • Request erasure or restriction where the legal conditions are met.
  • Data portability where processing is automated and based on consent or a contract.
  • Object to processing based on legitimate interests and object unconditionally to direct marketing.
  • Withdraw consent at any time without affecting the lawfulness of prior processing.
  • Lodge a complaint with the President of the Polish Personal Data Protection Office.

9. Data Security

We apply appropriate technical and organizational measures to protect personal data:

  • Transport encryption, password hashing, access controls, and regular updates.
  • Event-parameter minimisation: we do not record form field values, message content, email addresses, phone numbers, or other PII in analytics.
  • One-way keyed HMAC pseudonymisation of client and session identifiers by the backend before persistence.
  • Limited retention, access logging, backups, and periodic review of recipients and permissions.

10. Cookies

We use Basic Consent Mode: before analytics consent we do not load Google Analytics and we send no beacons or optional events. Categories are independent, and inactivity means optional measurement remains denied.

  • Essential: preference storage and service security, without analytics or marketing.
  • Analytics: Google Analytics 4, _ga cookies, session and client identifiers, UTM campaign parameters, and a restricted event taxonomy only after analytics consent.
  • Marketing: Google Ads, advertising cookies, and gclid, wbraid, or gbraid only after marketing consent.
  • Functional and third-party content: YouTube, Vimeo, Google Maps, or reCAPTCHA embeds activate only after the relevant consent or an explicit request for a strictly necessary feature.
  • You may reject all optional categories or change your choice later in Cookie settings. Withdrawal is as easy as giving consent.
  • A material change in purposes, providers, or data scope versions the policy and requires fresh consent before that category is re-enabled.

11. Contact

For matters related to personal data protection, you can contact us:

PP Solutions Przemysław Pietrzak
Szczęsna 26, 02-454 Warsaw, Poland
Email: [email protected]
Phone: +48 456 702 837

12. Policy Changes

We publish the date and version of changes. Editorial changes do not alter the user choice; a material change in purpose, provider, or data requires fresh consent before the changed category is enabled.