Warsaw · Kyiv · Europe
Concierge Pro

Privacy Policy

Website
[[DOMENA]]
Effective date
[[DATA_WEJSCIA]]
Document version
[[WERSJA]]

The Polish language version of this Policy is the binding one. The Russian and English versions are provided for information only.

1. Controller of personal data

The controller of your personal data, that is the entity deciding how it is used, is:

Referred to below as “the Controller”, “we”, “Concierge Pro”.

Contact for all matters concerning personal data: e-mail [[EMAIL]], phone [[TELEFON]], postal address [[ADRES]].

The Controller [[IOD_TAK_NIE]] a Data Protection Officer.

2. What data we collect

2.1. Data you provide in the contact form

DataRequired
First name (or full name)yes — otherwise we do not know how to address you
Phone numberoptional — at least one contact channel is required
E-mail addressoptional — at least one contact channel is required
Your messageoptional — but it helps us answer to the point
Selected preferred contact channelyes
Wording and scope of the consents given, date and time, IP address, form versioncollected automatically as proof of consent

Please do not include special categories of data in your message (health, beliefs, sexual orientation and similar). If your request requires such information (for example arranging a medical appointment), we will provide separate information and ask for your explicit consent before processing it.

2.2. Data collected automatically

While you use the website, technical data is recorded: IP address, browser type and version, operating system, date and time of the visit, referring page. This data comes from server logs and serves solely the security and correct operation of the website.

3. Purposes and legal bases of processing

PurposeLegal basis
Answering the enquiry sent through the form, preparing and presenting a service proposalart. 6(1)(b) GDPR — steps taken at your request prior to entering into a contract
Replying through the channel you selected (phone, SMS, WhatsApp, Telegram, e-mail)art. 6(1)(a) GDPR — your consent, in conjunction with art. 398(1) of the Polish Electronic Communications Law
Concluding and performing a contract for concierge servicesart. 6(1)(b) GDPR
Issuing and storing invoices and accounting recordsart. 6(1)(c) GDPR — legal obligation
Securing the website, preventing abuse and spamart. 6(1)(f) GDPR — our legitimate interest
Demonstrating that consent was given (accountability)art. 6(1)(c) and (f) GDPR in conjunction with art. 5(2) and art. 7(1) GDPR
Establishing, pursuing or defending against claimsart. 6(1)(f) GDPR

Providing data is voluntary. However, without your name and at least one contact channel we are unable to answer your enquiry.

We do not run a newsletter or marketing campaigns and we do not collect consent for them. Should that change, we will ask for separate, voluntary consent for each channel individually.

4. Consent — how you give it and how you withdraw it

We collect consent solely through separate checkboxes that are not ticked by default. Every communication channel has its own separate consent — in line with art. 398(1) of the Act of 12 July 2024, the Polish Electronic Communications Law.

You may withdraw your consent at any time, without giving a reason — by writing to [[EMAIL]] or through the same channel we use to contact you. Withdrawal does not affect the lawfulness of processing carried out before it and is as easy as giving consent.

5. How long we keep the data

CategoryPeriod
An enquiry from the form that did not lead to cooperation[[OKRES_ZAPYTANIA]]
Data of clients with whom a contract was concludedfor the term of the contract and, after it ends, for the limitation period for claims (art. 118 of the Polish Civil Code)
Accounting and tax records5 years from the end of the calendar year in which the tax payment deadline fell
Evidence of consent given and withdrawn[[OKRES_DOWODU_ZGODY]]
Server logs[[OKRES_LOGOW]]

6. Who we share data with (recipients)

With every entity that processes data on our behalf we conclude a data processing agreement in line with art. 28 GDPR — before any data is entrusted to it. We do not sell your data and we do not share it with third parties for marketing purposes.

7. Confidentiality

Confidentiality is the foundation of our service. Access to enquiries and client data is limited to persons authorised by the Controller and bound in writing to secrecy (art. 29 GDPR). We impose the same obligation on contractors carrying out assignments.

8. Transfers outside the European Economic Area

As a rule we process data within the European Economic Area. Exceptions follow from the contact channel you choose:

If you prefer your data not to leave the EEA, choose a phone call or e-mail.

9. Your rights

  1. access to your data and a copy of it (art. 15 GDPR);
  2. rectification of inaccurate or incomplete data (art. 16 GDPR);
  3. erasure of data — the “right to be forgotten” (art. 17 GDPR);
  4. restriction of processing (art. 18 GDPR);
  5. data portability (art. 20 GDPR);
  6. objection to processing based on our legitimate interest (art. 21 GDPR);
  7. withdrawal of consent at any time (art. 7(3) GDPR);
  8. lodging a complaint with the supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland.

We handle requests without undue delay and no later than one month from receipt. In complex cases the deadline may be extended by a further two months — of which we will inform you together with the reasons (art. 12(3) GDPR). Please send requests to [[EMAIL]].

10. Profiling and automated decisions

We do not take decisions about you based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect you (art. 22 GDPR).

11. Cookies and similar technologies

The website uses no analytics tools, advertising pixels or cross-site tracking. We also load no fonts or any other resources from external servers — everything is hosted on our own domain.

The website uses only cookies that are necessary for it to work correctly (including protecting access to the draft version of the site). Under art. 399(3) of the Polish Electronic Communications Law such cookies do not require your consent, as they are necessary to deliver the service you requested. That is why we display no consent banner.

12. Data security

We apply technical and organisational measures appropriate to the risk. Always in force: encrypted connections (HTTPS/TLS) and confidentiality obligations for authorised persons. To the extent confirmed by the Controller, we also apply access control to the mailbox and enquiry handling system, multi-factor authentication and backups.

13. Links to external services

The website links to external platforms: WhatsApp, Telegram, Instagram. Once you follow such a link, your data is processed by the operators of those platforms under their own privacy policies, over which we have no influence.

14. Changes to this Privacy Policy

We may update this Policy — for example following a change in the law or in the scope of our services. The current version is always available at [[DOMENA]]/polityka-prywatnosci together with its effective date.

15. Legislation referred to in this document

Back to the home page