Privacy Policy
This Privacy Policy sets out the rules for processing personal data of users of the efkabe-tech website and the use of cookies and similar technologies.
The provided website files do not contain the controller's legal details (full name, address, NIP/REGON or the controller's e-mail address). Therefore, fields marked [TO BE COMPLETED] must be filled in with the actual details before this document is published. Do not use default or fictitious data.
1. Data controller
The controller of personal data is:
[FULL COMPANY NAME / ENTREPRENEUR'S FULL NAME]
[REGISTERED OFFICE / PLACE OF BUSINESS]
Tax ID (NIP): [NIP]
e-mail: [E-MAIL ADDRESS FOR PERSONAL DATA MATTERS]
If the controller has appointed a Data Protection Officer, their contact details should be provided here: [DPO DETAILS / “NOT APPOINTED”].
2. Scope and sources of data
Depending on how the website is used, we may process in particular data voluntarily provided by the user, such as first name, surname, e-mail address, telephone number and message content.
We may also process technical data related to the use of the website, such as the IP address, date and time of connection, information about the browser and operating system, and information contained in server logs.
The data may come directly from the user or, in the case of technical data, be generated automatically while using the website.
3. Purposes and legal bases for processing
- Handling enquiries and contact – Article 6(1)(f) GDPR (the controller's legitimate interest in handling correspondence) or, where appropriate, Article 6(1)(b) GDPR (steps taken at the request of the data subject prior to entering into a contract).
- Preparation and performance of a contract – Article 6(1)(b) GDPR.
- Compliance with legal obligations – Article 6(1)(c) GDPR, in particular tax and accounting obligations.
- Establishing or defending claims and ensuring website security – Article 6(1)(f) GDPR.
- Direct marketing of our own services – as a rule, Article 6(1)(f) GDPR, subject to separate requirements concerning electronic communications; where consent is required, the legal basis is Article 6(1)(a) GDPR.
- Statistical and marketing analysis – only after appropriate tools have been implemented and, where required by law, after the user has given consent.
4. Recipients of data
Data may be disclosed to entities supporting the controller in operating the website and conducting business activities, in particular providers of hosting, e-mail, IT support, accounting and legal services, and other services necessary to achieve the purposes indicated above — only to the extent necessary to provide those services and on the basis of appropriate agreements or legal provisions.
The actual list of service providers should be verified before publication. If the controller uses providers outside the EEA, this fact and the appropriate mechanism legalising the data transfer should also be indicated.
5. Data retention period
We retain data for no longer than is necessary to achieve the purpose for which it was collected, and subsequently for the period required by law or until the relevant limitation periods for claims expire.
The controller should determine specific retention periods for individual categories of data, in particular correspondence, accounting documents and server logs: [COMPLETE IN ACCORDANCE WITH THE ACTUAL CONFIGURATION AND LEGAL OBLIGATIONS].
6. Data subject rights
In the cases specified by the GDPR, the data subject has the right to:
- access their data and obtain a copy;
- rectify inaccurate data;
- erase data;
- restrict processing;
- data portability where processing is based on consent or a contract and is carried out by automated means;
- object to processing based on the controller's legitimate interest, as well as to direct marketing;
- withdraw consent at any time where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
To exercise these rights, contact the controller at: [E-MAIL ADDRESS].
The data subject also has the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).
7. Voluntary provision of data
Providing data is generally voluntary, but it may be necessary to respond to an enquiry, enter into or perform a contract, or comply with a legal obligation. The scope of data required for a specific purpose should be limited to what is necessary.
8. Cookies and similar technologies
The website may use cookies and similar technologies. Cookies necessary for the proper operation of the website may be used without separate consent if they are genuinely necessary to provide the requested service. Analytical, advertising or other cookies that are not necessary for the operation of the website may only be activated after obtaining the user's consent where required by law.
As of the date this document was prepared, no analytics or marketing tools were found in the provided website code. Before publication, however, the configuration of the server, CMS, hosting, CDN, fonts, maps, forms, statistics tools and other external services should also be verified.
If cookies that are not necessary for the operation of the website are implemented, a consent mechanism should be used that allows the user to make a choice before such cookies are used, without preselected consent, and to withdraw consent just as easily.
9. Server logs and security
In connection with the operation of the website, technical information may be automatically recorded in server logs, including the IP address, date and time of connection, address of the requested resource, browser information and security-related events. This data is processed to ensure the security, continuity and diagnostics of the website on the basis of Article 6(1)(f) GDPR.
Log retention period: [COMPLETE — ACCORDING TO HOSTING SETTINGS].
10. Automated decision-making and profiling
User data is not used for automated decision-making that produces legal effects concerning them or similarly significantly affects them, unless this is explicitly stated in a separate notice in the future.
11. Changes to the Privacy Policy
This Privacy Policy may be updated if laws, the operation of the website, the services used or the purposes of processing change. The current version of the document is published on this page.
Last updated: 28 August 2026
12. Legal basis
This document takes into account, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), the Polish Personal Data Protection Act, and provisions concerning the use of information stored on users' terminal devices, including the Polish Electronic Communications Law Act of 12 July 2024.