1. Data controller
The controller is Jan Jarczyk IT Consulting, Polish tax ID (NIP) 8361877579, REGON 389925038. Privacy contact: kontakt@jjarczyk.com. The company has been operating since 2021.
2. Data that may be processed
Depending on how you use the website, processing may include technical HTTP request data, browser/device category, visited path, referring domain, browser language, UTM campaign parameters and information you voluntarily submit through the contact form.
An IP address is necessary for network communication and may be processed by the web server or reverse proxy. JJIT application analytics does not persist the raw IP address in its analytics file. Server infrastructure may create technical access/security logs according to its configuration and retention policy.
3. Statistics and optional analytics
3.1. Basic server statistics
The site keeps privacy-minimised first-party server statistics such as page views, paths, device type, browser/OS category, referring domain and UTM parameters. This mechanism does not store an analytics identifier on your device. It is used to maintain the site, understand content performance and detect technical issues. The legal basis is the controller’s legitimate interest under Article 6(1)(f) GDPR.
3.2. Extended analytics — consent only
After consent, the site may additionally measure active time, scroll depth, section visibility, clicks, returning visits, screen/viewport size, basic Web Vitals and JavaScript errors. A random first-party visitor ID is then stored in localStorage and a session ID in sessionStorage.
The legal basis is consent under Article 6(1)(a) GDPR. You can change or withdraw it at any time using Privacy settings in the footer. Rejecting or withdrawing analytics removes the extended analytics identifiers from the browser.
The website does not load Google Analytics, Meta Pixel or third-party advertising trackers.
3.3. Data stored on your device
A first-party localStorage entry stores your analytics choice so the site can respect it on later visits. A visitor identifier is created only after consent. The selected audience path (for example small business / growing business / enterprise) is not stored as a persistent preference. Rejecting or withdrawing analytics removes the extended analytics identifiers from the browser.
4. Contact form
If you submit the form, the site processes the data you provide: name/company, email address, message and optional attachments. The data is used to respond to your enquiry and, where applicable, to take steps at your request before entering into a contract.
The legal basis may be Article 6(1)(b) GDPR or Article 6(1)(f) GDPR depending on the nature of the enquiry. Legal obligations may also require processing under Article 6(1)(c) GDPR.
The form does not require marketing consent and does not automatically subscribe you to marketing communications.
5. Retention
- Extended analytics session and visitor identifiers: automatically removed by the application after no more than 30 days.
- Aggregated statistics: may be retained longer where they no longer identify an individual.
- Infrastructure logs: according to server configuration and security needs; their scope and retention should be reviewed periodically.
- Correspondence: for as long as required to handle the enquiry, cooperation and, where justified, relevant legal limitation or record-keeping periods.
6. Recipients and providers
Data may be accessible to providers technically necessary to operate the website and email, including infrastructure, connectivity, email, backup or security providers, to the extent required to provide those services.
LinkedIn links are external. Data is sent to LinkedIn only after you choose to visit that service; further processing is governed by LinkedIn’s own policies. Outbound links use referrer-limiting settings.
If a provider used for infrastructure or correspondence processes data outside the EEA, the transfer should rely on an appropriate GDPR mechanism. The exact scope depends on the services actually configured.
7. Your rights
Where applicable under GDPR, you may request access, correction, erasure, restriction, portability and object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time.
You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (UODO).
8. Security
The website uses HTTPS, attachment type/size restrictions, basic anti-spam controls, security headers configured at the reverse proxy and token-protected access to internal statistics. Infrastructure, dependencies and backups should be kept updated and monitored.