Privacy Policy of the SoftPowerLab.pl website
1.1. This Privacy Policy is for information purposes only, which means it does not create obligations for Users of the website. It fulfills the Administrator’s information duties toward data subjects (in accordance with Articles 13 and 14 of the GDPR).
1.2. The Policy sets out the rules for processing and protecting personal data provided by Users in connection with their use of the SoftPowerLab.pl website (hereinafter: the “Service”).
1.3. The personal data controller is Ireneusz Nieznański, operating under the business name “Ireneusz Nieznański Consulting” (hereinafter: the “Administrator”). The Administrator’s contact details: correspondence address: ul. ul. Przasnyska 4a/146, 01-765 Warszawa, Polska, e-mail address: i.nieznanski@softpowerlab.pl. The Administrator operates the Service on its own behalf.
1.4. If a Data Protection Officer (DPO) is appointed, the DPO’s contact details will be published in the Service. (As of the last update of this Policy, no DPO has been appointed; all matters relating to personal data should be directed to the Administrator using the contact details provided above.)
1.5. The Administrator respects Users’ privacy. Personal data is treated as confidential and appropriately protected against access by unauthorized persons. The Service uses, among other things, a secure SSL encryption protocol, which protects data transmission (the padlock icon in the browser indicates active encryption).
2.1. The Administrator processes personal data of Service Users for the following purposes, on the corresponding legal bases (in accordance with Article 6 GDPR):
Contact with the Administrator: handling and responding to inquiries sent via the contact form — the legal basis is the Administrator’s legitimate interest consisting of communication with inquirers (Article 6(1)(f) GDPR) or taking steps at the request of the data subject prior to entering into a potential contract (Article 6(1)(b) GDPR), depending on the nature of the inquiry.
Newsletter (commercial information): sending a newsletter containing information about new articles, SoftPowerLab initiatives, or other marketing content to the provided e-mail address — the legal basis is the data subject’s consent (Article 6(1)(a) GDPR) expressed by ticking the relevant checkbox when subscribing to the newsletter. This consent also covers receiving commercial information by electronic means in accordance with Article 10 of the Act on Providing Services by Electronic Means.
Blog comments: (if commenting is available) operating the blog commenting system — the legal basis is the user’s consent to publish their comment (Article 6(1)(a) GDPR). The user may request deletion of their comment and related data at any time.
Operation of the Service and statistics: ensuring the proper functioning of the Service, adapting it to Users’ needs, measuring traffic (e.g., via analytical cookies) — the legal basis is the Administrator’s legitimate interest (Article 6(1)(f) GDPR) consisting of maintaining and improving the Service. Where analytics or personalization uses necessary cookies, it is based on this interest; any activities beyond necessary cookies require consent via the cookie mechanism (Article 6(1)(a) GDPR). Details on cookies — see the Cookie Policy.
2.2. The scope of collected data is limited to the minimum necessary for the processing purposes. It may include:
data provided in the contact form: first name, last name (if provided), e-mail address, optionally phone number and other data voluntarily included in the message;
e-mail address provided when subscribing to the newsletter;
technical data collected automatically when visiting the Service: IP address, cookies, information about the browser and device, and basic activity data (e.g., pages viewed) — according to cookie settings. This data is generally anonymized; however, an IP address may be considered personal data (an online identifier).
(if comments) name/nickname and e-mail address provided when adding a comment, and the IP address from which the comment was added (collected to protect the Service against spam/attacks).
2.3. Providing personal data is always voluntary, but it may be necessary to use certain Service functionalities:
to send a message via the contact form, at least an e-mail address is required (so a reply can be provided) and acceptance of consent for processing data for contact purposes;
to subscribe to the newsletter, an e-mail address and ticking the marketing consent checkbox are required;
failure to provide the above data or to grant consent will make it impossible to send an inquiry or receive the newsletter, but browsing the website content remains possible without providing data (except for technical data collected automatically — see the Cookie Policy).
3.1. Users’ personal data may be disclosed to the following categories of recipients:
Processors acting on behalf of the Administrator — e.g., website hosting provider, newsletter/mailing service provider (company providing an e-mail sending system), entity handling newsletter distribution, form plugin provider (if data is stored by them), IT support providers for the Service. The Administrator has entered into appropriate data processing agreements with such entities, ensuring an adequate level of protection.
External service providers used by the Service — e.g., providers of analytics tools (Google Analytics) or advertising tools (e.g., Meta/Facebook, LinkedIn), to the extent these providers independently determine the purposes of processing cookie data as separate controllers (more information in the Cookie Policy).
Public authorities — only where required by law, upon their request (e.g., police, court, the Personal Data Protection Office), or to pursue the Administrator’s claims (e.g., disclosure to a lawyer for debt collection or defense against claims).
3.2. The Administrator does not sell or disclose personal data to third parties for their own marketing or business purposes without the consent of the data subject.
3.3. As a rule, Users’ data is not transferred outside the EEA (European Economic Area). However, if the Service uses external tools from providers outside the EEA (e.g., Google, Meta), data (e.g., IP address or cookie identifiers) may be transferred to third countries (such as the USA). Such transfers take place based on standard contractual clauses adopted by the European Commission or another appropriate legal basis under Chapter V GDPR. Detailed information is provided in the privacy policies of these providers (e.g., Google’s privacy policy or LinkedIn’s privacy policy).
4.1. Personal data will be stored by the Administrator for the period necessary to achieve the stated purposes:
Correspondence data (contact form or e-mail): for the duration of the correspondence, and then up to 2 years from the last contact, in case it is necessary to defend against potential claims (limitation period) or to document the course of support.
Newsletter subscriber data: until the User unsubscribes from the newsletter (withdraws consent). After resignation, the e-mail address may be stored for up to 1 additional year for internal purposes (accountability of consent, preventing re-adding without consent, etc.).
User account data (if applicable): until the user deletes the account.
Cookies and analytics data: depending on cookie type; detailed retention times are specified in the Cookie Policy (e.g., session cookies — until the browser is closed; preference cookies — several days/weeks; analytics/marketing cookies — typically 30 days to 2 years, according to tool settings). Analytics data may be stored in aggregated (anonymized) form for longer for statistical purposes.
4.2. Where processing is based on consent, data may be processed until consent is withdrawn. After withdrawal, data may be stored only to defend against claims (for the limitation period) or where another legal basis applies (e.g., a legal obligation to archive).
4.3. The Administrator periodically reviews data and deletes data whose continued storage is not justified by any legal basis.
5.1. A user whose data is processed has the following rights under the GDPR:
Right of access — to obtain confirmation whether the Administrator processes their data and, if so, to obtain a copy and information including purposes, categories, recipients, and planned retention period.
Right to rectification — to request correction of inaccurate data or completion of incomplete data.
Right to erasure (“right to be forgotten”) — to request deletion of personal data where conditions in Article 17 GDPR apply (e.g., data is no longer necessary or consent is withdrawn and there is no other legal basis).
Right to restriction of processing — to request restriction of processing in cases set out in Article 18 GDPR (e.g., where accuracy or legal basis is contested).
Right to data portability — to receive provided personal data in a structured, machine-readable format and to transmit it to another controller, where processing is based on consent or contract and is automated.
Right to object — to object to processing based on the Administrator’s legitimate interest (Article 6(1)(f) GDPR) on grounds relating to the user’s particular situation. After an objection, the Administrator will assess whether compelling legitimate grounds exist that override the user’s interests, rights, and freedoms (e.g., grounds to establish, pursue, or defend claims). If not, data will be deleted or processing will cease for that purpose.
Right to withdraw consent — where processing is based on consent, the user may withdraw it at any time, without affecting the lawfulness of processing before withdrawal. For example, the user can unsubscribe from the newsletter by clicking the “Unsubscribe” link in the footer of each e-mail or by contacting the Administrator.
5.2. To exercise these rights, contact the Administrator (e.g., by e-mail to the address in section 1.3). The Administrator may verify the identity of the requesting person (e.g., by requesting identifying information) to ensure the rights are exercised by an authorized person.
5.3. Right to lodge a complaint with a supervisory authority: If the User believes their data is processed in breach of data protection laws, they have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw). A complaint may be submitted in writing or electronically; detailed procedures are available on the UODO website.
6.1. The Service uses cookies and similar technologies (e.g., Local Storage) to ensure proper operation and, with the User’s consent, for analytics and marketing purposes. Detailed information about cookies used is provided in a separate document, the Cookie Policy (available here and via a link in the website footer).
6.2. For information: cookies are small text files stored on the User’s end device (computer, smartphone) while browsing. Cookies make it possible, among other things, to recognize a device on subsequent visits so the User does not have to set preferences each time. Cookies may also be used to collect statistical data about Service use or to display personalized content.
6.3. The Service uses both necessary cookies — required for proper website operation (e.g., session handling, language settings, security) — and optional cookies (analytics and marketing). Necessary cookies may be stored without consent as permitted by law. Analytics and marketing cookies are used only if the User gives consent via the cookie banner.
6.4. On the User’s first visit, a cookie banner is displayed allowing the User to accept all non-essential cookies, reject them, or select categories (preferences). The User may change their choice at any time via a permanent mechanism (a link or “cookies” icon) available on the website.
6.5. The Cookie Policy provides details including:
types of cookies used (e.g., session, persistent, first-party, third-party),
purposes (e.g., traffic statistics via Google Analytics, social integrations — LinkedIn Insight, etc.),
retention periods for individual cookies,
ways the User can manage cookies (besides the banner mechanism — also via browser settings).
6.6. Consent to cookies is voluntary. The User may use the Service while refusing analytics and marketing cookies — some functions may then behave slightly differently (e.g., no personalized content). Refusal does not affect access to substantive website content — the User still has full access to articles, services, etc.
7.1. The Service may contain links to external websites (e.g., links in articles, social media share buttons). Such websites operate independently of the Administrator and may have their own privacy policies and terms, which we recommend reviewing. The Administrator is not responsible for how data is handled by these independent websites.
7.2. The Administrator makes every effort to secure Users’ personal data and protect it against third-party actions. For this purpose, appropriate organizational and technical measures are applied in line with data protection regulations (including SSL encryption, server security, access policies).
7.3. In matters not governed by this Privacy Policy, the GDPR and other applicable laws on personal data protection apply (e.g., the Personal Data Protection Act, the Electronic Communications Law with regard to cookies).
7.4. This Privacy Policy may be amended as the Service develops or laws change. In the event of significant modifications, Users may be informed via the Service (e.g., a notice on the homepage or an e-mail notice for subscribers). We recommend checking the Policy regularly for updates.
7.5. Last updated: 28.01.2025.