Privacy Policy
Last updated: 12 May 2026
1. Personal data controller
The controller of personal data within the meaning of Art. 4(7) GDPR is a natural person not conducting business activity:
Adrian
Projektant stron internetowych
Personal brand: SEVENEDGE
Correspondence address: Krosno, Podkarpacie
Contact: contact@sevenedge.pl
The Controller provides website design services on the basis of civil-law contracts concluded directly with clients (specific-task contracts with transfer of copyright, Art. 627 of the Polish Civil Code). The Controller does not conduct business activity within the meaning of the Entrepreneurs' Law Act and does not hold a NIP or REGON number as an entrepreneur.
2. Scope of collected data
As part of using the Website, we may collect the following data:
- Data from the contact form: name, e-mail address, telephone number (optional), message content.
- Technical data: IP address, browser type, operating system, screen resolution, visit time, subpages visited.
- Cookies: data stored in cookies and similar technologies (details in section 7).
Data sources for direct marketing (cold mail):
As part of the B2B direct marketing it conducts, the Controller processes companies' contact data obtained from publicly available sources: company websites (contact addresses such as kontakt@, biuro@, office@), the National Court Register (KRS), the Central Register and Information on Business Activity (CEIDG), and other publicly available registers. In accordance with Art. 14 GDPR, we inform you that this data is not obtained directly from the persons to whom it relates.
3. Purposes of data processing
We process personal data for the following purposes:
- Responding to enquiries sent via the contact form (Art. 6(1)(b) GDPR, performance of a contract or taking steps prior to its conclusion).
- Provision of website creation services (Art. 6(1)(b) GDPR, performance of a contract).
- Analysis of visit statistics and improvement of the quality of the Website (Art. 6(1)(f) GDPR, the controller's legitimate interest).
- Conducting marketing activities, including remarketing (Art. 6(1)(a) GDPR, the user's consent).
- Establishing, pursuing or defending against claims (Art. 6(1)(f) GDPR, the controller's legitimate interest).
B2B direct marketing (cold mail):contacting companies with a proposal of cooperation in the field of website design. Legal basis: Art. 6(1)(f) GDPR (the Controller's legitimate interest, recital 47 GDPR — direct marketing constitutes a legitimate interest of the controller).
Fulfilment of legal obligations: keeping tax records (PIT-11 issued by clients acting as remitters), accounting, handling requests from state authorities. Legal basis: Art. 6(1)(c) GDPR (a legal obligation incumbent on the Controller, the PIT Act, the Tax Ordinance).
Data of contact persons on the counterparties' side: The parties, as separate personal data controllers, process the data of contact persons indicated in commercial correspondence (first name, surname, position, business e-mail address, telephone) on the basis of Art. 6(1)(f) GDPR (legitimate interest — performance and settlement of the contract and maintaining business contacts). The data is processed for the duration of the contract and for 6 years after its termination (the limitation period for tax and civil-law claims).
4. Data retention period
- Data from the contact form, until the correspondence is concluded, and thereafter for the period required by law (up to 6 years in the case of potential claims).
- Data related to the performance of the contract, for the duration of the contract and the period required by tax and accounting regulations (5 years from the end of the tax year).
- Analytical data (cookies), in accordance with the validity period of the individual cookies (details in section 7).
Company contact data from direct marketing (cold mail): stored for 12 months from the first contact, or until an objection to processing is raised (Art. 21 GDPR) or the unsubscribe link is used. If cooperation is established, the data moves into the "client data" category and is stored in accordance with the periods arising from tax and accounting obligations (5 years from the end of the tax year).
5. User rights
Under the GDPR you have the following rights:
- The right to access your personal data.
- The right to rectification (correction) of data.
- The right to erasure of data ("the right to be forgotten").
- The right to restriction of processing.
- The right to data portability.
- The right to object to processing based on a legitimate interest.
- The right to withdraw consent at any time (without affecting the lawfulness of processing carried out before the withdrawal).
- The right to lodge a complaint with the supervisory authority, the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw).
To exercise the above rights, please contact us at: contact@sevenedge.pl.
Supervisory authority: the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw (uodo.gov.pl). Notwithstanding the above, in consumer disputes the User may use the EU ODR (Online Dispute Resolution) platform operated by the European Commission, available at ec.europa.eu/consumers/odr.
6. Recipients of data
Personal data may be transferred to the following categories of recipients, who act as data processors on behalf of the Controller:
- Resend Inc.: provider of the e-mail transmission service used to handle marketing and transactional communication. Resend processes data within the European Economic Area (servers in the EU).
- Hosting service provider (VPS): the server infrastructure of the sevenedge.pl website, located in the European Economic Area.
- Google Ireland Limited: Google Analytics (website traffic analytics). Technical data is processed in accordance with Google's policy, with a possible transfer to the USA on the basis of standard contractual clauses approved by the European Commission (EC Implementing Decision 2021/914).
- Meta Platforms Ireland Limited: Meta Pixel (remarketing). Technical data may be transferred to the USA on analogous grounds.
- Plausible Insights OÜ: Plausible Analytics (cookie-free traffic analytics). Data processed in the European Union (servers in Germany), without transfer outside the EEA.
- State authorities: solely on the basis of applicable legal provisions (e.g. requests from the prosecutor's office, the UODO, tax authorities).
Transfer of data outside the EEA: data processed by the Controller as part of cold mailing (Resend) and website hosting remains within the European Economic Area and is not transferred to third countries. The exception is technical data collected by Google Analytics and Meta Pixel, which may be transferred to the USA; the user may disable these tools by rejecting analytical and marketing cookies in the consent banner.
7. Data transfers outside the EEA
Some of the services used by the Controller (e.g. Cloudflare Inc., USA) may involve the transfer of data outside the European Economic Area. These transfers take place on the basis of the mechanisms in Chapter V of the GDPR, in particular: an adequacy decision of the European Commission (EU-US Data Privacy Framework) or standard contractual clauses (SCC) of 4 June 2021. An up-to-date list of providers together with the transfer mechanisms is made available on request.
9. Google Analytics
The Website uses the Google Analytics service provided by Google LLC. This service collects anonymous information about visits to the Website in order to analyse traffic and improve the quality of services. Google Analytics uses cookies to identify the user's session. You can find more information about the processing of data by Google in the Google Privacy Policy.
10. Meta Pixel (Facebook Pixel)
The Website may use the Meta Pixel tool provided by Meta Platforms, Inc. This tool makes it possible to measure the effectiveness of advertisements and to direct marketing content to the appropriate groups of recipients. You can find more information in the Meta Privacy Policy.
11. Plausible Analytics
The Website may use the Plausible Analytics service provided by Plausible Insights OÜ (Estonia), a GDPR-compliant analytics tool that does not use cookies and does not track users across websites. Only aggregated, anonymised traffic data is collected (number of visits, sources of visits, countries, device type) without identifying individual persons and without creating user profiles. Data is processed on servers in the European Union (Germany). More information in the Plausible Privacy Policy.
12. Artificial intelligence (AI Act)
The Controller informs that, if it uses AI systems within the meaning of Regulation (EU) 2024/1689 (AI Act) in communication with the User (e.g. a chatbot, conversational assistant, generative features), the User will be informed of this in accordance with the transparency obligations of Art. 50 of the AI Act. The Controller does not use high-risk AI systems.
13. Data security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or disclosure. The Website uses an encrypted SSL/TLS connection.
14. Changes to the privacy policy
The Controller reserves the right to make changes to this Privacy Policy. Users will be informed of any material changes by an appropriate notice on the Website. The current version of the Privacy Policy is always available at sevenedge.pl/privacy.
15. Contact
For matters related to the protection of personal data, please contact us at the e-mail address: contact@sevenedge.pl.


