Last updated: 4 July 2025

1. Data Controller

Name: Wojciech Wiesławski (“Controller”)
Registered address: Skrybicze 26g, 15‑606 Skrybicze, Poland
Tax ID (NIP): 5451475771
REGON: 050800701
Contact e‑mail: [email protected]
Phone: +48 601 699 187

2. Types of personal data we process

  • Browsing data: IP address, user‑agent, device information, referral URL, time stamps (collected automatically by our server, Cloudflare CDN and Google Analytics 4).

  • Contact forms: first name, surname, e‑mail address, band name, services requested, project details, any other information you voluntarily provide in the message.

  • Newsletter: name, e‑mail address, subscription preferences.

  • Email correspondence: e‑mail address, metadata and content of your messages.

  • Log files & security events: IP, HTTP headers, firewall events (processed by Cloudflare and our hosting provider).
    We do not intentionally collect special categories of data.

3. Purposes & legal bases

PurposeLegal basis (GDPR art.)
Responding to enquiries sent via contact form or e‑mailArt. 6(1)(b) – contract or steps prior to contract
Providing newsletterArt. 6(1)(a) – consent
Web analytics & website optimisation (GA4)Art. 6(1)(a) – consent (analytics cookies disabled until granted)
Marketing / remarketing via Google AdsArt. 6(1)(a) – consent
Server logs & security, CDN (Cloudflare)Art. 6(1)(f) – legitimate interest in ensuring security and performance

4. Retention periods

  • Contact form messages: 12 months after last communication.

  • Newsletter: until you withdraw consent (unsubscribe) or we stop sending.

  • Analytics data: 26 months (Google Analytics 4 retention setting).

  • Server logs: 14 days (Cyber‑Folks), Cloudflare edge logs: 30 days.

  • Accounting documents (invoices): 6 years (per Polish tax law).

5. Recipients & processors

Recipient/ProcessorRoleLocation & safeguards
Cyber‑Folks S.A.Web & e‑mail hostingPoland – processing agreement
Cloudflare, Inc.CDN, security, DNSUSA & EU – EU‑U.S. Data Privacy Framework + SCC
Google Ireland Ltd.GA4, Google AdsIreland (EEA). Data may be processed in USA under SCC + EU‑U.S. DPF
Complianz B.V.Cookie bannerNetherlands
Cyber‑Folks SMTPTransactional e‑mailPoland

We do not sell your data. Data is not transferred outside the EEA except through the providers above, all of whom rely on Standard Contractual Clauses or Data Privacy Framework.

6. Cookies & tracking

We use three categories of cookies:

  1. Strictly necessary – site functionality, security (always active).

  2. Analytics – Google Analytics 4 (expires 1‑24 months), loaded only after consent via Complianz banner.

  3. Marketing – Google Ads remarketing (up to 90 days), loaded only after consent.

You can change or withdraw consent at any time by clicking the floating “Cookie settings” link.

7. Your rights

You have the right to access, rectify, erase, restrict, object, data portability, and to withdraw consent at any time. Send requests to [email protected].

8. Complaints

You may lodge a complaint with the supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00‑193 Warszawa, Poland, tel. +48 22 531 03 00, www.uodo.gov.pl.

9. Children

The website is not directed at children under 16. We do not knowingly process their data.

10. Security

We use TLS encryption, firewalls, access control, and security monitoring. Cloudflare protects against DDoS and malicious traffic.

11. Updates

We may update this Policy; material changes will be announced on the website. This version is effective from 4 July 2025.