WebCraft

Privacy Policy

Rules for the processing of personal data and the use of cookies and local technologies on the web-craft.com.pl website.

1. General information

This Privacy Policy sets out the rules for the processing and protection of the personal data of users of the WebCraft website available at web-craft.com.pl.

The owner of the website and the Personal Data Controller is Mirosław Wajman, conducting business activity under the name WebCraft. Registration details (address, NIP, REGON) will be provided prior to publication.

You may contact the Controller electronically at the email address: [email protected] or by telephone at: +48 694 048 320.

2. Purposes and legal bases for data processing

The personal data of website users is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR). The data is processed for the following purposes:

  • Handling enquiries submitted through the contact form — we process data such as your name, email address, the address of your current website and the content of your message on the basis of the Controller's legitimate interest in responding to the enquiry submitted (Art. 6(1)(f) GDPR).
  • Preparation of a commercial offer — at the user's request prior to entering into a contract (Art. 6(1)(b) GDPR).
  • Proper functioning of the website — including saving user preferences (e.g. the choice of language version) on the basis of a legitimate interest (Art. 6(1)(f) GDPR).

3. Data retention period

Users' personal data will be stored for the period necessary to fulfil the purposes for which it was collected:

  • Data processed for the purpose of handling correspondence and the contact form will be stored for the duration of the correspondence and for up to 12 months after its conclusion for evidentiary purposes.
  • Data necessary for the performance and settlement of a contract — for the period required by tax and accounting regulations (5 years from the end of the tax year) and until the expiry of the limitation period for any potential claims.

4. Data recipients

Access to personal data may be granted only to authorised employees or subcontractors of the Controller (e.g. entities providing hosting services, email handling, CRM systems, legal services). Data is neither sold nor transferred to third parties for marketing purposes. Personal data is not transferred outside the EEA or to international organisations.

5. Users' rights

Every data subject has the right to:

  • access the content of their personal data and to obtain a copy of it,
  • rectify (correct) their data,
  • erase their data (the right to be forgotten),
  • restrict the processing of their data,
  • object to the processing of their data on the basis of legitimate interest,
  • data portability,
  • lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (UODO).

To exercise your rights, please contact the Controller by writing to the email address: [email protected].

6. Cookies and local technologies

The website may use the LocalStorage mechanism in the user's browser in order to save preferences (e.g. the selected language version). This data is stored locally on the user's device and is not transmitted to the Controller's server.

The website may also use cookies necessary to ensure the security and correct operation of the contact forms.

This Privacy Policy was last updated on: 21 June 2026.