We respect the privacy of the people who visit us — enough that we have deliberately given up information most websites collect without a second thought. We do not profile visitors, use no cookies and track nobody; we do not even know how many people have been here. We process data for three purposes: traffic statistics, server security, and contacting us. Each is described separately below.
Who is responsible for your data
The controller of the personal data covered by this document is:
Adam NowickiLęborska 3b
80-386 Gdańsk
NIP 5842593279
[email protected]
For anything concerning your data, write to the email address above.
1. Traffic statistics
We want to know which pages are read, in which language, and where visitors come from — so we know what to write next. Your privacy matters more to us than detailed information about who you are. We run the statistics ourselves: we do not use Google Analytics or any other external analytics or advertising tool, and no third-party script runs on this site at all.
What we record
- the day of the view — the date, without a time,
- the address of the page and its language,
- the domain you came to us from (e.g. google.com) — without the full address or its parameters,
- campaign tags from the link (utm_source, utm_medium, utm_campaign),
- a two-letter country code, if our network provider supplies one,
- the number of views.
What we do not record
- your IP address — the statistics hold it in no form, neither truncated nor hashed,
- your browser and system name (the user agent),
- cookies, browser storage, or a device fingerprint,
- any visitor, session or return-visit identifier.
There is no table of individual visits: a view increments one counter in a daily total. That is why we keep these figures with no time limit — they hold no PII (personally identifiable information). And it is why we do not know how many people visited or how many came back: counting that would need either storage on your device or a device fingerprint.
For those figures to mean anything, we filter out automated traffic — search engines, link-preview tools, scanners. That is the only reason we look at a browser name and an IP address at the moment a view is reported: we check whether the program identifies itself as a bot, whether the report comes from our own page, and whether one address is sending an unnatural number of reports. None of it reaches the statistics — all that remains of a rejected report is a count and the reason for rejection.
You can switch the counting off by blocking JavaScript for this site.
2. Security and administration
This is the one place your IP address stays for longer than the moment of the request — and we say so plainly, because under the GDPR an IP address is personal data. The server, like every server on the internet, writes a technical request log.
The log holds
- the date and time of the request,
- the IP address,
- the address requested and the response code,
- the browser and system name (the user agent).
The log serves security and diagnostics only: recognising an attack or an abuse, and finding the cause of an error. We do not use this data to analyse site traffic, never join it to the page-view counter, and never use it for any marketing purpose. Access is limited to the people who maintain this site and to the infrastructure provider it runs on.
Logs are deleted after three months at the latest. No consent is required for this — the basis is our legitimate interest (Art. 6(1)(f) GDPR) — but you have the right to object (Art. 21 GDPR).
3. Contacting us
The contact form is the only place where personal data reaches us knowingly, and only what you type in yourself: an email address or a phone number (either one is enough), and optionally a company name. We record the time of sending and your browser name alongside them, so we can recognise automated submissions.
That data goes into our system and triggers a generic notification.
We use the data to answer your question or arrange a call. We do not send newsletters or offers to that address without your separate consent, and we pass it to nobody for marketing purposes.
Form data is deleted automatically after 24 months. If you ask us to delete it sooner, we delete it straight away — unless other legal provisions apply.
If you write to us directly by email, your message arrives in our mailbox, which is run by Google Ireland Limited on Google Workspace. The mail service may process data outside the European Economic Area, on the terms that provider sets out (standard contractual clauses under Art. 46 GDPR, among others). We keep such correspondence for as long as the matter is open, and delete it on request.
Separately, never together
Those three sets live apart and we never cross them: the statistics are not joined to the server log, and neither of them to correspondence. We profile no one, and take no decisions about anyone by automated means.
The same holds within the statistics themselves. The dimensions we store — page, language, referring domain, campaign and country — are read one at a time, as totals over a single dimension. We build no cross-sections of the kind "traffic from this domain, from this country, on this page, on this day": that kind of combination is what narrows traffic down to a very small group and brings an aggregate statistic close to being information about a person.
Cookies and consent
We use no cookies and no browser storage. There is no consent banner here because there is no consent we would have to ask for: Art. 399 of the Polish Electronic Communications Law (and Art. 5(3) of Directive 2002/58/EC, which it implements) concerns storing information on your device or accessing information already stored there, and we do neither. Fonts and every other file are served from our own server, so no outside company learns of your visit.
Legal bases
In all three cases the basis is our legitimate interest — Art. 6(1)(f) GDPR: running our own website, keeping it secure, and answering the enquiries sent to us. Where an enquiry leads to a contract, the data needed to conclude it is processed under Art. 6(1)(b) GDPR. In our assessment aggregate view counts are not personal data, but we describe them here as though they were.
The acts we rely on
- Regulation (EU) 2016/679 (GDPR) — in particular Art. 6(1)(b) and (f), Art. 13 and Arts. 15–21.
- The Polish Electronic Communications Law of 12 July 2024 (Dz.U. 2024 item 1221) — Art. 399 (information stored in terminal equipment) and Art. 398 (direct marketing).
- Directive 2002/58/EC on privacy and electronic communications — Art. 5(3).
- European Data Protection Board Guidelines 2/2023 on Art. 5(3) of Directive 2002/58/EC — which cover device fingerprinting and certain instances of IP tracking; this is why we do not even store hashes of IP addresses.
- The Polish Personal Data Protection Act of 10 May 2018.
Your rights
For the data you give us, you have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), portability (Art. 20) and objection to processing based on legitimate interest (Art. 21). Write to the address at the top of this page — we reply within 14 days at the latest. You may also lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
Changes to this policy
If we change what we collect, we will change this document and the date at the top of the page first.