Legal
Privacy Policy
Last updated: March 2026
1. Identity of the data controller
The controller of your personal data is:
Mateusz Ciuła
Młyńska 8
43-300 Bielsko-Biała
2. Categories of personal data we process
Depending on how you interact with us, we may process the following categories of data:
- Identification data: name, surname, job title, company name.
- Contact data: e-mail address, phone number.
- Communication content: messages sent via contact forms and correspondence.
- Technical data: IP address, browser type and version, device identifiers, pages visited, time spent on pages, access timestamps — collected via server logs and, if consented, analytics tools.
- Booking data: date, time, and subject of booked sessions.
We do not process special categories of personal data (sensitive data) as defined in Art. 9 GDPR.
3. Purposes and legal bases of processing
| Purpose | Legal basis (GDPR) | Retention period |
|---|---|---|
| Responding to contact inquiries | Art. 6(1)(b) — contract performance / pre-contractual steps; Art. 6(1)(f) — legitimate interest | 3 years from last contact |
| Managing strategy session bookings | Art. 6(1)(b) — contract performance | 5 years (accounting obligations) |
| Website analytics (if consented) | Art. 6(1)(a) — consent | Until withdrawal of consent, max. 2 years |
| Security of IT systems and fraud prevention | Art. 6(1)(f) — legitimate interest | 90 days (server logs) |
| Compliance with legal obligations | Art. 6(1)(c) — legal obligation | As required by applicable law |
4. Recipients of personal data
Your personal data may be shared with the following categories of recipients, strictly on a need-to-know basis:
- IT service providers and hosting providers (data processors acting on our behalf under data processing agreements);
- Calendar and video conferencing tools used to manage booked sessions;
- Legal and accounting advisors, as required;
- Public authorities, if required by law.
We do not sell personal data to third parties.
5. Transfers to third countries
Where we use service providers based outside the European Economic Area, we ensure an adequate level of protection through: the European Commission's adequacy decisions, Standard Contractual Clauses (SCCs), or other appropriate safeguards under Chapter V GDPR. Upon request, we will provide information about the specific safeguards applied.
6. Your rights as a data subject
Under the GDPR you have the following rights:
- Right of access (Art. 15) — to obtain a copy of your personal data and supplementary information.
- Right to rectification (Art. 16) — to correct inaccurate or complete incomplete data.
- Right to erasure (Art. 17) — to request deletion of your data when it is no longer necessary or when you withdraw consent.
- Right to restriction of processing (Art. 18) — to temporarily halt processing in certain circumstances.
- Right to data portability (Art. 20) — to receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — to object to processing based on legitimate interest.
- Right to withdraw consent — at any time, without affecting prior lawful processing.
To exercise your rights, contact the data controller. We will respond within 30 days (extendable by a further 2 months in complex cases, with prior notice).
7. Right to lodge a complaint
You have the right to lodge a complaint with the Polish supervisory authority:
President of the Personal Data Protection Office
ul. Stawki 2, 00-193 Warszawa
Tel.: +48 22 531 03 00
kancelaria@uodo.gov.pl | uodo.gov.pl
8. Automated decision-making and profiling
We do not make decisions based solely on automated processing that would produce legal effects or significantly affect you (Art. 22 GDPR). We do not engage in profiling for marketing purposes.
9. Data security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These include encrypted data transmission (TLS/HTTPS), access controls, regular security assessments, and staff training.
10. Changes to this policy
We may update this Privacy Policy periodically. The date at the top indicates when it was last revised. Material changes will be communicated via a prominent notice on our website.
11. Contact
For any privacy-related questions or to exercise your rights, contact the data controller at:
Mateusz Ciuła
Młyńska 8
43-300 Bielsko-Biała