Skip to content
GDPR / PRIVACY

Privacy policy.

Last updated: 2026-08-17/APEX SUPPORT Sp. z o.o.

This is an informative translation. In the event of any discrepancy, the Polish version of this document prevails.

This document explains what personal data we collect through apexs.pl, why we collect it, how long we keep it and what rights you have. We have written it to be readable without a lawyer.

1. Who is the controller of your data

The controller of your personal data is:

APEX SUPPORT Spółka z ograniczoną odpowiedzialnością
ul. Stanisławowska 47, 54-611 Wrocław, Poland
VAT ID (NIP) 894 320 78 65 · REGON 524815558 · Company no. (KRS) 0001026908

For any matter concerning personal data, write to: biuro@apexs.pl.

We have not appointed a Data Protection Officer. We are not required to, as we do not carry out large-scale processing or process special categories of data within the meaning of Article 37 GDPR. Data protection matters are handled directly by the controller at the address above.

2. What data we collect

2.1. Contact form data

When you send us a brief through the form on our site, you provide:

  • full name and e-mail address - required fields;
  • company name, phone number and project type - optional, provided only if you wish;
  • project description - you decide how much information to share. Please do not include data we do not need in order to prepare a quote, in particular data concerning health, beliefs or other special categories of data.

2.2. Technical data

Our hosting provider records standard server logs: IP address, date and time of the request, browser type and referring page. This data is generated automatically and is necessary to operate and secure the site.

We additionally use the IP address to limit how many submissions can be sent from one source in a short period - an anti-spam measure.

2.3. Cookies and visit statistics

The site stores no cookies - neither our own nor anyone else's. We do collect anonymous visit statistics (page views, country, device type, referring page), which do not allow us to work out who you are. See section 9.

3. Purposes and legal bases

PurposeLegal basisRetention
Answering your enquiry and subsequent correspondenceArt. 6(1)(b) GDPR - steps taken at your request prior to entering into a contractuntil discussions end, then up to 12 months
Preparing and presenting a quoteArt. 6(1)(b) GDPRup to 12 months from last contact
Establishing, exercising or defending legal claimsArt. 6(1)(f) GDPR - our legitimate interestuntil claims become time-barred
Site security, prevention of abuse and spamArt. 6(1)(f) GDPRserver logs - up to 30 days
Anonymous visit statistics (which pages are viewed and where visits come from)Art. 6(1)(f) GDPR - our legitimate interestaggregate data that cannot be linked back to you
Compliance with statutory obligations (e.g. tax)Art. 6(1)(c) GDPRas required by law

4. Is providing data mandatory

No. Providing data is entirely voluntary. Without a name and e-mail address we will not, however, be able to reply - that is the only consequence. You can always write to us by ordinary e-mail instead of using the form.

5. Who we share data with

We do not sell data and we do not share it for marketing purposes. We do use technical service providers who process data on our behalf under data processing agreements:

EntityRoleLocation
Vercel Inc.website hosting, server logs, anonymous visit statisticsUSA
Resend (Plus Five Five, Inc.)delivery of messages sent through the formUSA
Google Ireland Ltd.e-mail (Google Workspace), where your message is receivedIreland / USA

Data may also be disclosed to authorities entitled to request it under applicable law.

6. Transfers outside the European Economic Area

Yes, your data is transferred to the United States. This follows from the fact that our site is hosted by Vercel and form messages are delivered by Resend - both are US-established companies. We consider it better to state this plainly than to bury it in generic wording.

The transfer takes place on the basis of:

  • an adequacy decision of the European Commission (EU-U.S. Data Privacy Framework), to the extent the given provider is certified under that programme, or
  • standard contractual clauses approved by the European Commission, together with supplementary technical safeguards (encryption in transit).

You may obtain a copy of the safeguards applied by writing to biuro@apexs.pl.

7. Your rights

In connection with the processing of your data, you have the right to:

  • access your data and obtain a copy of it;
  • rectification of inaccurate data and completion of incomplete data;
  • erasure of your data (the "right to be forgotten");
  • restriction of processing;
  • data portability - receiving your data in a structured, machine-readable format;
  • object to processing based on our legitimate interest (Art. 6(1)(f) GDPR);
  • withdraw consent at any time where processing is based on it - withdrawal does not affect the lawfulness of processing carried out beforehand.

To exercise any of these rights, simply write to biuro@apexs.pl. We respond without undue delay, at the latest within one month.

8. Complaint to the supervisory authority

If you believe we process your data unlawfully, you have the right to lodge a complaint with the supervisory authority:

President of the Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
uodo.gov.pl

9. Cookies and visit statistics

This site does not store cookies. We do not use Google Analytics, advertising pixels or heatmaps. We do not embed videos, maps or widgets from third-party services.

Typefaces are served from our own server rather than an external library, so visiting the site does not put your browser in contact with a font provider.

We do use Vercel Web Analytics, a visit counter provided by our hosting company. It works differently from typical analytics:

  • it stores nothing on your device - no cookies, no data in browser storage;
  • it does not build a profile of you and does not follow you across other sites - visits are recognised by a technical hash computed on the server, which changes daily and cannot be traced back to an individual;
  • the script is served from our own address, so your browser contacts no third-party server for this purpose.

What we see is aggregate only: which pages are viewed, which country visits came from, on what kind of device and from which referring page. We cannot see who visited the site.

For that reason we do not display a cookie consent dialogue. Consent is required for files and other information stored on your device, and we store nothing there. Should we ever add a tool that writes data to your browser or profiles visitors, we would enable it only after obtaining your consent and would update this document.

10. Automated decision-making and profiling

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR. No decision concerning you is made automatically.

11. Security

We apply technical and organisational measures appropriate to the risk: transmission takes place over an encrypted HTTPS connection, access to the mailbox receiving enquiries is limited to those who need it, and the form is protected against automated submission.

12. Changes to this policy

We may update this document, for example when we change a service provider or the scope of data collected. The current version is always available at this address, and the date of the last change is shown at the top of the page.

13. Related documents

The rules for using the site and services provided by electronic means are set out in the Terms of Service.