WebSolutionsLab
Privacy Policy
This policy explains what happens to personal data on websolutionslab.dev. In short: the Controller receives data only when you write through the contact form or by email. The site has no user accounts, analytics tools or ads.
Data controller
The controller of personal data is Damian Kowalczyk WebSolutions, Polish tax ID (NIP) 9462735077, operating under the WebSolutionsLab brand (the “Controller”).
For anything related to personal data, write to contact@websolutionslab.dev. The Controller has not appointed a data protection officer, as it is not required to.
What this policy covers
This policy covers websolutionslab.dev in both its Polish and English versions.
The Controller’s mobile apps have their own privacy policies, available in each app’s store listing and in its settings.
Contact form and email
When a message is sent through the form, the Controller receives:
- the name,
- the email address,
- the project type selected from the list,
- the message itself and anything included in it.
The message goes to the Controller’s email inbox. The email address is used only to reply and to continue the conversation about the project. It is not added to any newsletter or used for marketing. The same applies to messages sent directly to the Controller’s email address.
Legal basis: the Controller’s legitimate interest in answering the enquiry (Art. 6(1)(f) GDPR). If the conversation concerns a specific project, the basis is taking steps at your request before entering into a contract (Art. 6(1)(b) GDPR).
Providing data is voluntary. Without a name, email address and message a reply is not possible, which is why the form requires them.
Spam protection (Cloudflare Turnstile)
The form is protected by Cloudflare Turnstile, which checks that a person, not a bot, is sending the message. The widget loads only once you start filling in the form. Usually nothing needs to be clicked.
For this check Cloudflare processes, among other things, the IP address, the browser’s User-Agent header and technical characteristics of the connection. The service is provided by Cloudflare, Inc. (USA).
Legal basis: the Controller’s legitimate interest in protecting the form and inbox from spam and abuse (Art. 6(1)(f) GDPR).
For improving its own bot detection, Cloudflare acts as a separate controller. Details: Turnstile Privacy Addendum and Cloudflare Privacy Policy.
Hosting and server logs
The site runs on servers of an external hosting provider. Every visit is automatically recorded in server logs with technical data: IP address, date and time of the request, the page requested and browser information.
The logs are used to keep the site running, find errors and protect it against attacks. They are not combined with form data or used to identify visitors.
Legal basis: the Controller’s legitimate interest in running the site securely and reliably (Art. 6(1)(f) GDPR).
Recipients and transfers outside the EEA
Data is shared only with service providers the site and the form cannot work without:
- the website hosting provider,
- the provider that delivers messages from the form,
- the email provider whose inbox receives the Controller’s messages,
- Cloudflare, for spam protection (section 04).
These providers process data on the Controller’s behalf under data processing agreements and may not use it for their own purposes. The exception is Cloudflare to the extent described in section 04. Data may be disclosed to anyone else only where the law requires it, for example at the request of a competent authority.
On request, the Controller will provide the names of the specific providers.
Some providers are based in the USA, so data may be transferred outside the European Economic Area. Such transfers rely on the European Commission’s adequacy decision (EU-US Data Privacy Framework) or on standard contractual clauses approved by the European Commission.
How long data is kept
- Form messages and emails: for as long as needed to reply and discuss the project. If the conversation leads to working together, for the duration of that work and then until any possible claims become time-barred. Sooner if you successfully object.
- Copy of the sent message at the delivery service: up to 30 days.
- Server logs: for a short time, usually no more than a few days.
- The ws-lang cookie: one year from the last language change, or until it is deleted in the browser.
Your rights
Under the GDPR you have the right to:
- access your data and receive a copy,
- have your data corrected,
- have your data erased,
- restrict processing,
- data portability,
- object to processing based on legitimate interest.
To exercise these rights, write to contact@websolutionslab.dev. The Controller replies without undue delay and within one month at the latest.
You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl). You can also complain to the authority in the country where you live or work.
Security and automated decisions
The connection to the site and form submissions are encrypted (HTTPS). The Controller does not keep its own database of messages.
The Controller does not make decisions based solely on automated processing, including profiling, that produce legal effects for you. The Turnstile check is automated, but at most it blocks a message that looks like spam. In that case you can always write directly to the Controller’s email address.
Changes to this policy
This policy is updated when the way the site works or the law changes. The current version is always at this address, and the date of the last change is shown at the top of the page.