PolicyPrivacy
Neadoo Digital Polska Privacy Policy as a Service Provider
dated 15.05.2018, last updated: 9 September 2026
§1. General information
- The Privacy Policy defines the rules for the processing and protection of personal data related to the use of the contact forms available on this website.
- A form User is a natural person who places a service order or submits an inquiry regarding services via those forms.
- The Data Controller within the meaning of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ("GDPR") (Official Journal of the European Union L 119/40, 4.5.2016) is Neadoo Digital Polska Sp. z o.o., ul. Matejki 46/3, 60-767 Poznań, Tax ID (NIP): 7831752485, Statistical ID (REGON): 366327737, National Court Register (KRS): 0000658277, tel: +48 502 821 828, email: [email protected]
- For matters regarding data processing by Neadoo Digital Polska, please contact: [email protected]
- Information about Website Users and their behavior is obtained through:
- data voluntarily entered into any contact forms throughout the website,
- through the storage of cookies,
- through the collection of server logs by the hosting provider.
§2. Purpose and legal basis of data processing by the Controller
- We process personal data in order to handle service inquiries and orders, to reply to the inquiry submitted, to run website statistics and analytics, and to protect our forms against abuse.
- Legal bases for processing:
▪ Article 6(1)(b) GDPR - steps taken at the request of the data subject prior to entering into a contract: handling an inquiry, an audit or a quote,
▪ Article 6(1)(f) GDPR - the legitimate interests of the Controller, namely replying to the inquiry, contacting the person representing a business partner, marketing our own services, and protecting our forms against bots and abuse,
▪ Article 6(1)(a) GDPR - consent, as regards analytics and marketing cookies, given through the consent banner,
▪ Article 6(1)(c) GDPR - a legal obligation, as regards accounting and tax records. - Providing your data is voluntary but necessary for us to reply to your inquiry. We do not collect a separate consent for processing the data you enter in a form - submitting the form is itself your request to be contacted.
- The User's personal data may be entrusted to processors acting on the Controller's behalf:
▪ Resend, Inc. (United States) - delivery of the e-mail messages sent from the forms,
▪ Cloudflare, Inc. (United States) - website hosting and the Cloudflare Turnstile service protecting the forms against bots; that service processes the IP address and browser characteristics,
▪ Google Ireland Ltd. - Google Analytics and Google Tag Manager,
▪ Microsoft Ireland Operations Ltd. - Microsoft Clarity,
▪ the Controller's own system used to handle form submissions,
▪ cooperating partners - if necessary for the performance of a contract - and subcontractors: accounting, consulting, or IT support firms. - Some of the entities listed above are established outside the European Economic Area, in the United States. Data is transferred to them on the basis of a European Commission implementing decision on the adequate level of protection (the EU-U.S. Data Privacy Framework) or on the basis of standard contractual clauses approved by the European Commission.
§3. Scope of data processing by the Controller
- Personal data collected under this policy may include:
▪ full name,
▪ contact phone number,
▪ company name,
▪ contact email address, - IP addresses,
- the URL of the domain that the user wishes to promote using the Administrator's services.
- The scope of data processing mentioned above also includes performing backups.
- This data is strictly limited to what is necessary to effectively process your inquiry.
§4. Automatically collected data
- When you use our website, we also collect data automatically. This includes: domain name, IP address, browser type, and operating system. We collect this automatic data using cookies and the Google Tag Manager, Google Analytics and Microsoft Clarity tools.
- Cookies are files sent to a user's computer or other device while browsing a website,
- Cookies remember user preferences, which enables, among other things:
a) improving service quality,
b) improving the quality and relevance of search results,
c) generating statistics,
d) creating user search preferences,
e) maintaining a logged-in user session. - Analytics and marketing cookies are set ONLY after consent has been given in the banner shown on your first visit. Until then, only the cookies strictly necessary for the website to work are used.
- Consent can be changed or withdrawn at any time via the “Cookie settings” link in the site footer. That panel also carries the full cookie listing: name, provider, purpose and expiry.
- Regardless of the banner, Users may block or delete cookies in their browser settings. This process may vary depending on the browser being used.
- Blocking or deleting these files may affect the proper functioning of certain elements of the site.
- Microsoft Clarity is a click-map and session-recording tool used to monitor user activity on the website.
- Users who do not consent to the use of Microsoft Clarity can withdraw consent in the cookie banner - via the “Cookie settings” link in the footer - or block cookies in their browser. As a result, the user will be treated as an anonymous user, meaning no preferences, characteristics, or similar attributes can be assigned to them.
- Google Analytics is an analytical system that provides insights into website traffic data as well as user demographics.
- Users who do not consent to the use of Google Analytics can withdraw consent in the cookie banner - via the “Cookie settings” link in the footer. That panel also carries the full cookie listing: name, provider, purpose and expiry.
- The consent banner also includes a “Marketing” category covering cookies used for remarketing and ad personalisation. Advertising tags are loaded only after consent has been given in that category - without it they are not loaded at all.
§5. User Rights Regarding Data Processing
- The user has the right to:
- access their personal data,
- rectification of personal data,
- erasure of personal data,
- restriction of personal data processing,
- data portability,
- object to the processing of personal data,
- withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal. - To exercise your rights regarding your personal data, please send your request to the following email address: [email protected]
- Requests are processed promptly, but please note that they may affect the proper fulfillment of your inquiry.
- Users also have the right to lodge a complaint with the supervisory authority - the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.
§6. Data Retention Period
We keep data only for as long as it is necessary for the purposes for which it was collected:
- data from contact and inquiry forms - for 3 years from the last contact, matching the limitation period for claims arising from business activity,
- newsletter subscriber data - until the subscription is cancelled,
- accounting and tax records - for 5 years, counted from the end of the calendar year in which the tax obligation arose,
- cookie data - for the expiry period shown next to each file under “Cookie settings”, and no longer than until consent is withdrawn.
§7. Controller's Obligations
As the Data Controller, Neadoo Digital, we are committed to taking all necessary measures to protect the personal data we process, including:
– protecting data against unauthorized access, damage, or destruction,
– monitoring the accuracy of data processing,
– maintaining a register of individuals authorized to process data,
– implementing appropriate IT security policies, including data encryption methods on computers and other solutions to prevent unauthorized access,
– maintaining documentation and procedures aimed at data security, including our Data Security Policy and IT Systems Security Policy.