Privacy policy.
This is an informative translation. In the event of any discrepancy, the Polish version of this document prevails.
This document explains what personal data we collect through apexs.pl, why we collect it, how long we keep it and what rights you have. We have written it to be readable without a lawyer.
1. Who is the controller of your data
The controller of your personal data is:
APEX SUPPORT Spółka z ograniczoną odpowiedzialnością
ul. Stanisławowska 47, 54-611 Wrocław, Poland
VAT ID (NIP) 894 320 78 65 · REGON 524815558 · Company no. (KRS) 0001026908
For any matter concerning personal data, write to: biuro@apexs.pl.
We have not appointed a Data Protection Officer. We are not required to, as we do not carry out large-scale processing or process special categories of data within the meaning of Article 37 GDPR. Data protection matters are handled directly by the controller at the address above.
2. What data we collect
2.1. Contact form data
When you send us a brief through the form on our site, you provide:
- full name and e-mail address - required fields;
- company name, phone number and project type - optional, provided only if you wish;
- project description - you decide how much information to share. Please do not include data we do not need in order to prepare a quote, in particular data concerning health, beliefs or other special categories of data.
2.2. Technical data
Our hosting provider records standard server logs: IP address, date and time of the request, browser type and referring page. This data is generated automatically and is necessary to operate and secure the site.
We additionally use the IP address to limit how many submissions can be sent from one source in a short period - an anti-spam measure.
2.3. Cookies and visit statistics
The site stores no cookies - neither our own nor anyone else's. We do collect anonymous visit statistics (page views, country, device type, referring page), which do not allow us to work out who you are. See section 9.
3. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Answering your enquiry and subsequent correspondence | Art. 6(1)(b) GDPR - steps taken at your request prior to entering into a contract | until discussions end, then up to 12 months |
| Preparing and presenting a quote | Art. 6(1)(b) GDPR | up to 12 months from last contact |
| Establishing, exercising or defending legal claims | Art. 6(1)(f) GDPR - our legitimate interest | until claims become time-barred |
| Site security, prevention of abuse and spam | Art. 6(1)(f) GDPR | server logs - up to 30 days |
| Anonymous visit statistics (which pages are viewed and where visits come from) | Art. 6(1)(f) GDPR - our legitimate interest | aggregate data that cannot be linked back to you |
| Compliance with statutory obligations (e.g. tax) | Art. 6(1)(c) GDPR | as required by law |
4. Is providing data mandatory
No. Providing data is entirely voluntary. Without a name and e-mail address we will not, however, be able to reply - that is the only consequence. You can always write to us by ordinary e-mail instead of using the form.
5. Who we share data with
We do not sell data and we do not share it for marketing purposes. We do use technical service providers who process data on our behalf under data processing agreements:
| Entity | Role | Location |
|---|---|---|
| Vercel Inc. | website hosting, server logs, anonymous visit statistics | USA |
| Resend (Plus Five Five, Inc.) | delivery of messages sent through the form | USA |
| Google Ireland Ltd. | e-mail (Google Workspace), where your message is received | Ireland / USA |
Data may also be disclosed to authorities entitled to request it under applicable law.
6. Transfers outside the European Economic Area
Yes, your data is transferred to the United States. This follows from the fact that our site is hosted by Vercel and form messages are delivered by Resend - both are US-established companies. We consider it better to state this plainly than to bury it in generic wording.
The transfer takes place on the basis of:
- an adequacy decision of the European Commission (EU-U.S. Data Privacy Framework), to the extent the given provider is certified under that programme, or
- standard contractual clauses approved by the European Commission, together with supplementary technical safeguards (encryption in transit).
You may obtain a copy of the safeguards applied by writing to biuro@apexs.pl.
7. Your rights
In connection with the processing of your data, you have the right to:
- access your data and obtain a copy of it;
- rectification of inaccurate data and completion of incomplete data;
- erasure of your data (the "right to be forgotten");
- restriction of processing;
- data portability - receiving your data in a structured, machine-readable format;
- object to processing based on our legitimate interest (Art. 6(1)(f) GDPR);
- withdraw consent at any time where processing is based on it - withdrawal does not affect the lawfulness of processing carried out beforehand.
To exercise any of these rights, simply write to biuro@apexs.pl. We respond without undue delay, at the latest within one month.
8. Complaint to the supervisory authority
If you believe we process your data unlawfully, you have the right to lodge a complaint with the supervisory authority:
President of the Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
uodo.gov.pl
9. Cookies and visit statistics
This site does not store cookies. We do not use Google Analytics, advertising pixels or heatmaps. We do not embed videos, maps or widgets from third-party services.
Typefaces are served from our own server rather than an external library, so visiting the site does not put your browser in contact with a font provider.
We do use Vercel Web Analytics, a visit counter provided by our hosting company. It works differently from typical analytics:
- it stores nothing on your device - no cookies, no data in browser storage;
- it does not build a profile of you and does not follow you across other sites - visits are recognised by a technical hash computed on the server, which changes daily and cannot be traced back to an individual;
- the script is served from our own address, so your browser contacts no third-party server for this purpose.
What we see is aggregate only: which pages are viewed, which country visits came from, on what kind of device and from which referring page. We cannot see who visited the site.
For that reason we do not display a cookie consent dialogue. Consent is required for files and other information stored on your device, and we store nothing there. Should we ever add a tool that writes data to your browser or profiles visitors, we would enable it only after obtaining your consent and would update this document.
10. Automated decision-making and profiling
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR. No decision concerning you is made automatically.
11. Security
We apply technical and organisational measures appropriate to the risk: transmission takes place over an encrypted HTTPS connection, access to the mailbox receiving enquiries is limited to those who need it, and the form is protected against automated submission.
12. Changes to this policy
We may update this document, for example when we change a service provider or the scope of data collected. The current version is always available at this address, and the date of the last change is shown at the top of the page.
13. Related documents
The rules for using the site and services provided by electronic means are set out in the Terms of Service.