Privacy Policy

Last updated: December 13, 2025

1. Data Controller

The data controller is RisiTech Błażej Porwoł, ul. Świeradowska 47, 02-662 Warsaw, Poland. Contact for data protection matters: - email: privacy@risitech.pl

2. Scope of Data We Process

Depending on how you use the site, we may process: 1) Data provided in the contact form: - email address, - message content, - (if you add additional fields) other data voluntarily provided in the form. 2) Technical data related to site usage: - statistical data about site traffic (analytics), - data stored in server logs and/or intermediary services (e.g., date and time of request, browser/device technical parameters; potentially IP address) – to the extent resulting from infrastructure operation and security requirements.

3. Purposes of Data Processing

We process your data for the following purposes: 1) Handling contact form inquiries – responding to messages and conducting further correspondence related to the inquiry. 2) Ensuring security and proper operation of the site (e.g., preventing abuse, error diagnostics). 3) Site traffic analytics – to understand how users interact with the site and improve it (statistics).

4. Legal Basis for Processing

We process data based on: 1) Article 6(1)(f) GDPR – legitimate interest of the Controller consisting of: - conducting correspondence and handling inquiries, - ensuring security and proper operation of the site, - conducting statistics/site analytics. 2) (If cooperation ensues) Article 6(1)(b) GDPR – taking steps at the request of the data subject prior to entering into a contract and/or performance of a contract.

5. Data Recipients / Processors

In connection with the operation of the site, your data may be transferred to the following categories of recipients: - Netlify, Inc. – site hosting and contact form handling (Netlify Forms), - entities providing IT/telecommunications services to the extent necessary for site operation. Analytics (Umami) is hosted on our own home server (Controller's infrastructure) – we do not use an external hosting provider for this purpose. Data Transfer Outside the EEA: Some providers (particularly Netlify) may process data outside the European Economic Area. In such cases, the transfer is carried out in accordance with GDPR, based on appropriate legal mechanisms provided by GDPR (e.g., standard contractual clauses or other appropriate safeguards – as per the provider's documentation).

6. Data Retention Period

- Contact form data is retained for the time necessary to conduct correspondence and handle the matter, and then for the period needed for potential establishment or defense of claims. - Technical data and logs – for the period resulting from service configuration and security and diagnostic needs (usually time-limited). - Analytics data – for the period consistent with retention settings in the analytics tool (Umami), used solely for statistical purposes.

7. Your Rights

You have the right to: - access to data, - rectification of data, - erasure of data, - restriction of processing, - data portability (in cases provided for in GDPR), - object to processing based on Article 6(1)(f) GDPR, - lodge a complaint with the supervisory authority: President of the Personal Data Protection Office (UODO). To exercise your rights, contact us at: privacy@risitech.pl.

8. Voluntary Nature of Providing Data

Providing data in the contact form is voluntary, but necessary for us to respond to your message (particularly email address and inquiry content).

9. Analytics (Umami)

The site uses Umami Analytics hosted on the Controller's infrastructure. - Umami is used to collect statistical data about site traffic (e.g., page views, traffic sources, device/browser type). - Umami is used for site analysis and improvement and is not used to identify users. Note: Depending on infrastructure configuration, technical data (e.g., IP address) may be processed briefly for network communication and security purposes. We do not use it to identify users.

10. Cookies

The site does not use cookies to track users. If cookies are added in the future (e.g., technical/functional), this section will be updated.

11. Automated Decision-Making and Profiling

We do not make automated decisions about you, including decisions resulting from profiling, that would produce legal effects or similarly significantly affect you.

12. Contact

For matters related to privacy and personal data, contact us: - email: privacy@risitech.pl