1. Data controller
FlexNet sp. z o.o., ul. Grzybowska 87, 00-844 Warsaw, Poland.
VAT (NIP): 5272769941 · REGON: 364460337 · KRS: 0000618401 (District Court for the Capital City of Warsaw, 12th Commercial Division of the National Court Register) · Share capital: 25,000 PLN.
Contact the controller: [email protected] · +48 606 464 264.
2. Purposes and legal bases
We process your personal data for the following purposes and on the following legal bases (Regulation (EU) 2016/679 of the European Parliament and of the Council — GDPR):
| Purpose | Data scope | Legal basis | Retention |
|---|---|---|---|
| Performance of a service contract (hosting, middleware, training) | name, company, VAT ID, address, email, phone, billing data | Art. 6(1)(b) GDPR (contract) | Term of the contract + 5 years (accounting) |
| Sales contact / project quote | name, company, email, phone, enquiry content | Art. 6(1)(b) GDPR (pre-contractual steps) | Up to 12 months from last contact |
| Newsletter (subscription confirmed by email — double opt-in) | email, language, IP address and the dates of signup, confirmation and unsubscribe (consent record) | Art. 6(1)(a) GDPR (consent); sending in line with the Polish Electronic Communications Law | Until consent is withdrawn (unsubscribe link in every issue); unconfirmed signups deleted within 30 days |
| Legal and tax requirements | invoice data, contact data | Art. 6(1)(c) GDPR (legal obligation — Polish Accounting Act, Tax Ordinance) | 5 years from the end of the tax year |
| Security and server logs | IP address, user agent, timestamp | Art. 6(1)(f) GDPR (legitimate interest — attack prevention) | 30 days |
3. Recipients of data
Your data may be entrusted to the following categories of recipients (always under a data processing agreement):
- Hosting operator — dhosting.pl sp. z o.o. (physical server located in Poland)
- CDN and DDoS protection — Cloudflare Inc. (transfers governed by the EU Standard Contractual Clauses)
- Accounting office and tax advisors — within the scope of accounting obligations
- Payment operators and banks — within the scope of contractual settlements
- IT subcontractors — only after a data processing agreement (DPA) has been signed
We do not sell or share data with third parties for marketing purposes.
4. Transfers outside the European Economic Area (EEA)
As a rule, we process data within the EEA. Cloudflare, as a CDN operator, may process technical data (IP, request log) outside the EEA — solely on the basis of the Standard Contractual Clauses approved by the European Commission (Decision 2021/914) and additional technical safeguards.
5. Your rights
Under Articles 15–22 GDPR you have the following rights:
- Right of access to your data (Art. 15)
- Right to rectification of inaccurate data (Art. 16)
- Right to erasure ("right to be forgotten") (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20) — in a structured format (JSON/CSV)
- Right to object to processing based on legitimate interest (Art. 21)
- Right to withdraw consent at any time (Art. 7(3)) — without affecting prior processing
- Right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland
To exercise any of the above rights, write to [email protected]. We respond within 30 days (Art. 12(3) GDPR).
6. Profiling and automated decisions
We do not make decisions about you based solely on automated processing, including profiling, that would produce legal effects (Art. 22 GDPR).
7. Cookies and similar technologies
Details about cookies — how they are used, how long they are stored, and how to manage them — are available in a separate document: Cookie policy.
8. Data security
We apply technical and organisational safeguards appropriate to the risk:
- TLS 1.2+ transport encryption (HTTPS, HSTS preload)
- Password hashing (bcrypt / Argon2)
- Backups with at-rest encryption
- Access logging, change auditing
- Access control policy (RBAC, principle of least privilege)
- Regular software updates and security patches
9. Personal data breach
In the event of a personal data breach, we will notify the President of the UODO within 72 hours (Art. 33 GDPR) and the data subjects — where the breach involves a high risk (Art. 34 GDPR).
10. Changes to this policy
This privacy policy may be updated. Every change is recorded in the document header (version number + date). We will inform data subjects whose data we process on the basis of consent about material changes by email.
ul. Grzybowska 87 · 00-844 Warsaw
Email: [email protected]
Phone: +48 606 464 264