General information
This Privacy Policy sets out how personal data is processed and cookies are used on the nexait.pl website (the "Website").
It describes how we collect, process and protect user data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the Polish Personal Data Protection Act of 10 May 2018.
Data controller
The controller of personal data is NEXAIT sp. z o.o., ul. Jeziorowa 2, 66-200 Świebodzin, Poland, NIP 9731116070, REGON 543038261, KRS 0001201062, email office@nexait.pl.
The controller has not appointed a Data Protection Officer. For privacy matters or to exercise your rights, contact us directly by email or by phone: +48 535 040 361 or +48 511 275 531.
Scope and source of data
When you use the Website, we may process data you provide directly and technical data collected automatically. Technical data collected for analytics or marketing purposes is processed only after you consent to the relevant cookies.
- data you provide voluntarily when contacting us: first and last name, company name, email address, phone number, message content
- technical data: IP address, cookie identifiers, information about the browser, operating system and interactions with the website
Purposes and legal bases of processing
We process data for the purposes and on the legal bases set out in Article 6 GDPR. The purpose, legal basis, scope and duration of processing are summarised below.
- Responding to enquiries sent by email, by phone or through an external booking calendar - legal basis: Article 6(1)(f) GDPR (the controller's legitimate interest in communicating with the user); data processed until the correspondence ends and for 12 months afterwards.
- Providing services and operating the Website, including security, hosting, logs and backups - legal basis: Article 6(1)(f) GDPR; technical data processed automatically and stored for up to 12 months.
- Visitor statistics and traffic analysis, if analytics is enabled - legal basis: Article 6(1)(a) GDPR (consent); only after you consent to "Analytics" cookies.
- Marketing and remarketing, if carried out - legal basis: Article 6(1)(a) GDPR (consent); only after you consent to "Marketing" cookies.
- Compliance with legal obligations, including tax and record-keeping obligations - legal basis: Article 6(1)(c) GDPR; for the period required by law.
Data recipients
Your data may be entrusted only to trusted entities providing services to the Controller. Each of them processes data under a data processing agreement (Article 28 GDPR) and solely to provide services to NexaIT. We do not sell personal data.
- the provider of the hosting and server infrastructure on which the Website runs
- CookieYes Limited - cookie banner and consent log
- Google Ireland Limited - analytics and advertising services and Consent Mode, if these tools are enabled
- partners providing IT, marketing, accounting and legal services
- public authorities, where required by law
Data transfers outside the EEA
If a service provider such as Google processes data outside the European Economic Area, including in the United States, the transfer relies on a mechanism provided for in the GDPR.
We ensure an adequate level of protection through the European Commission's adequacy decision on the EU-US Data Privacy Framework (2023/1795) or through Standard Contractual Clauses (SCCs).
Data retention periods
We store data only for as long as is necessary to achieve the purpose for which it was collected, or for the period required by law. After these periods, the data is deleted or anonymised.
- contact correspondence - up to 12 months after communication ends
- server logs - up to 12 months
- CookieYes consent log - up to 36 months, for evidential purposes
- analytics data, if analytics is enabled - up to 14 months
- marketing data, if marketing is carried out - until consent is withdrawn
- cookies - for the lifetime stated in the cookies section
Rights of the data subject
Under the GDPR, you have rights in relation to your data. If you believe your data is being processed unlawfully, you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
- access to your data and a copy of it
- rectification
- erasure (the right to be forgotten)
- restriction of processing
- data portability
- objection to processing
- withdrawal of consent at any time, without affecting the lawfulness of previous processing
Contact channels
The Website has no contact form. Messages are sent directly by phone, email, WhatsApp or through an external booking calendar. The data collected and how it is processed by the provider of the chosen channel are also governed by that provider's privacy policy.
Cookies and consent management
The Website uses CookieYes to manage consent in line with the GDPR and the ePrivacy Directive. On your first visit, a banner lets you accept all cookies, reject all of them or customise your preferences. No analytics or marketing cookies are activated until you give consent.
You can change or withdraw your consent at any time using the "Manage consent" link in the page footer or through your browser settings. Disabling necessary cookies may limit some features of the Website.
If Google Consent Mode is enabled on the website, the ad_storage, analytics_storage, ad_user_data and ad_personalization parameters remain set to "denied" until consent is given, so that the corresponding cookies are not saved.
- Necessary - required for the site to work, for example to remember your consent choices; no consent required
- Analytics - help us analyse website traffic; consent required
- Marketing - enable personalised advertising; consent required
Automated decision-making and profiling
The Controller does not make decisions producing legal effects for users based solely on automated processing. Profiling for marketing purposes may take place only with your consent.
Whether providing data is required
Providing personal data is voluntary but necessary for us to contact you and handle your enquiry; for analytics and marketing it requires your consent. Refusing analytics or marketing cookies does not limit your use of the Website's basic features.
Security measures
The Controller applies organisational and technical measures appropriate to the risk to protect data.
- encrypted HTTPS connections (SSL/TLS)
- regular updates of the components and dependencies used
- access control for data and configuration
- backups and technical monitoring
- logging and analysis of unauthorised access attempts
Changes to this Policy
This Policy may be updated when laws, technology, providers or the scope of processing change. The new version is published at the same address with its update date. It was prepared in accordance with the GDPR (EU 2016/679), the Polish Personal Data Protection Act (Journal of Laws 2018, item 1000), Directive 2002/58/EC (ePrivacy), EDPB Guidelines 05/2020 on consent and current practice for Google Consent Mode.