Privacy Policy
This Privacy Policy defines the principles of processing and protecting personal data collected via paweldomanski.eu, in full compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation - GDPR).
1. Data Controller
The controller of your personal data is:
- Entity / Name: Paweł Domański conducting business activity under the trade name: [TO BE COMPLETED: Full registered company name in CEIDG or KRS]
- Tax ID (NIP): [TO BE COMPLETED: Tax ID Number / NIP, e.g. PL0000000000]
- National Business Registry (REGON): [TO BE COMPLETED: REGON Number]
- Registered Address: [TO BE COMPLETED: Street, building/suite, postal code, city, country]
- Business Registry: [TO BE COMPLETED: Central Register and Information on Economic Activity (CEIDG) maintained by the Polish Ministry of Development / District Court]
- Contact Email: kontakt@paweldomanski.eu
- Phone: [TO BE COMPLETED: Contact telephone number]
The Data Controller has not appointed a Data Protection Officer (DPO). In all matters regarding privacy, data rights, and GDPR compliance, please contact us directly at kontakt@paweldomanski.eu.
2. Data Processing Principles and Data Minimization
The Data Controller observes strict standards under GDPR Article 5:
- Lawfulness, fairness, and transparency: Data is processed legally and transparently.
- Purpose limitation: Personal data is collected strictly for specified, explicit, and legitimate business purposes.
- Data minimization (Art. 5(1)(c) GDPR): We request only the data that is genuinely required to respond to your inquiry or fulfill an engagement. Our contact form does not mandate providing a full surname if you are inquiring on behalf of a company or prefer first-name correspondence.
- Accuracy & Storage limitation: Records are kept accurate and retained only for as long as necessary.
- Integrity and confidentiality: Data is safeguarded with robust encryption and access controls.
3. Purposes and Legal Bases for Processing
A. Handling Contact Inquiries & Direct Architectural Correspondence
- Scope: First name (or company name), email address, optional phone number, and any details provided in your message.
- Purpose: Responding to architectural inquiries, database questions, and consulting requests.
- Legal Basis: Art. 6(1)(b) GDPR (taking steps at the data subject's request prior to entering into a contract) and Art. 6(1)(f) GDPR (legitimate interests of the Controller in conducting professional business communications).
B. Delivery of Advisory Services, Team Workshops, and Fractional CTO Engagements
- Scope: Full name, company name, VAT ID (NIP), billing address, email, and technical specifications provided for audit.
- Purpose: Performance of advisory contracts, invoicing, and accounting compliance.
- Legal Basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(c) GDPR (compliance with statutory tax and accounting obligations).
C. Technical Newsletter & Engineering Lead Magnets
- Scope: Email address.
- Purpose: Delivering engineering analyses, database articles, and downloadable blueprints.
- Legal Basis: Art. 6(1)(b) GDPR (provision of free electronic newsletter service) and consent under electronic privacy regulations.
D. Live Support & Chatwoot Real-Time Messaging
- Scope: Message contents, IP address, session identifiers.
- Purpose: Real-time messaging with visitors via the embedded chat widget.
- Legal Basis: Art. 6(1)(f) GDPR (legitimate interests of the Controller in providing immediate visitor assistance).
E. Anonymous Web Traffic Analytics (Google Analytics 4 & DexterLab Analytics)
- Scope: Aggregated interaction events, device and browser metadata, anonymized IP addresses, and page navigation flows.
- Measurement ID: G-F4D5VGQ5L1
- Purpose: Evaluating site performance, monitoring conversion efficacy, and optimizing technical user experience.
- Legal Basis: Art. 6(1)(a) GDPR (voluntary consent). We implement Google Consent Mode v2: analytical storage is denied by default until you grant consent in the cookie banner.
4. Data Processors and Service Providers
Personal data may be processed by trusted third-party service providers acting under data processing agreements:
- Cloud Hosting & Server Infrastructure: [TO BE COMPLETED: Hosting provider name, e.g. Hetzner Online GmbH / OVH / Vercel / Cloudflare] — hosting servers located in the EU.
- Business Email Provider: [TO BE COMPLETED: Mail provider, e.g. Google Workspace / ProtonMail / Cyberfolks].
- Chatwoot Live Chat: Self-hosted instance hosted at chat.dexterlab.pl on European Union servers.
- Web Analytics: Google Ireland Limited / Google LLC (Google Analytics 4, measurement ID: G-F4D5VGQ5L1) governed by the EU-U.S. Data Privacy Framework; and a privacy-focused self-hosted instance at stat.dexterlab.pl.
- Accounting & Invoicing: [TO BE COMPLETED: Invoicing software / Accounting firm, e.g. Fakturownia / inFakt].
- Geographic Language Detection (GeoJS): An asynchronous, client-side IP lookup (get.geojs.io) to detect country code and suggest the appropriate language version (PL/EN). No persistent identification data is stored.
- Web Fonts (Google Fonts): Typography assets (Space Grotesk, DM Sans, JetBrains Mono) served from Google LLC CDN infrastructure.
5. International Data Transfers
The Controller predominantly processes data within the European Economic Area (EEA). If any service provider processes data in third countries (e.g., the United States), transfers are governed by European Commission adequacy decisions (such as the EU-U.S. Data Privacy Framework) or Standard Contractual Clauses (SCCs).
6. Data Retention Period
- Contact Inquiries: Retained for the duration of correspondence and up to 3 years thereafter for potential claims defense.
- Accounting & Invoices: 5 years starting from the end of the tax year in which payment was due.
- Newsletter Subscriptions: Retained until you opt out using the one-click unsubscribe link in any newsletter issue.
- Chatwoot History: Retained for a maximum of 12 months, after which records are archived or deleted.
- Google Analytics 4 Events: Retained for 14 months (standard retention window), after which data is automatically purged.
7. Your GDPR Rights
Under GDPR, you have the following enforceable rights:
- Right of Access (Art. 15): Obtain confirmation of processing and copies of your data.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete records.
- Right to Erasure ("Right to be Forgotten", Art. 17): Request deletion of your data when retention is no longer justified.
- Right to Restriction of Processing (Art. 18): Restrict processing during dispute reviews.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without retroactive impact.
To exercise any of these rights, contact us at kontakt@paweldomanski.eu.
8. Right to Lodge a Complaint with a Supervisory Authority
If you believe your data protection rights have been infringed, you have the right to lodge a formal complaint with the competent supervisory authority:
- Authority: Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office - PUODO)
- Address: ul. Stawki 2, 00-193 Warsaw, Poland
- Website: https://uodo.gov.pl
9. Automated Decision-Making & Profiling
The Controller does not engage in automated decision-making or profiling that produces legal effects or significantly affects users (Art. 22 GDPR).
10. Data Security
We deploy robust organizational and technical security measures including end-to-end HTTPS/TLS encryption, strict SSH key-based infrastructure access, and isolated server environments.