Skip to content

535 040 361511 275 531

Book an IT review

Legal document

Privacy and cookie policy

Updated: 11 September 2026

General information

This Privacy Policy sets out how personal data is processed and cookies are used on the nexait.pl website (the "Website").

It describes how we collect, process and protect user data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the Polish Personal Data Protection Act of 10 May 2018.

Data controller

The controller of personal data is NEXAIT sp. z o.o., ul. Jeziorowa 2, 66-200 Świebodzin, Poland, NIP 9731116070, REGON 543038261, KRS 0001201062, email office@nexait.pl.

The controller has not appointed a Data Protection Officer. For privacy matters or to exercise your rights, contact us directly by email or by phone: +48 535 040 361 or +48 511 275 531.

Scope and source of data

When you use the Website, we may process data you provide directly and technical data collected automatically. Technical data collected for analytics or marketing purposes is processed only after you consent to the relevant cookies.

  • data you provide voluntarily when contacting us: first and last name, company name, email address, phone number, message content
  • technical data: IP address, cookie identifiers, information about the browser, operating system and interactions with the website

Purposes and legal bases of processing

We process data for the purposes and on the legal bases set out in Article 6 GDPR. The purpose, legal basis, scope and duration of processing are summarised below.

  • Responding to enquiries sent by email, by phone or through an external booking calendar - legal basis: Article 6(1)(f) GDPR (the controller's legitimate interest in communicating with the user); data processed until the correspondence ends and for 12 months afterwards.
  • Providing services and operating the Website, including security, hosting, logs and backups - legal basis: Article 6(1)(f) GDPR; technical data processed automatically and stored for up to 12 months.
  • Visitor statistics and traffic analysis, if analytics is enabled - legal basis: Article 6(1)(a) GDPR (consent); only after you consent to "Analytics" cookies.
  • Marketing and remarketing, if carried out - legal basis: Article 6(1)(a) GDPR (consent); only after you consent to "Marketing" cookies.
  • Compliance with legal obligations, including tax and record-keeping obligations - legal basis: Article 6(1)(c) GDPR; for the period required by law.

Data recipients

Your data may be entrusted only to trusted entities providing services to the Controller. Each of them processes data under a data processing agreement (Article 28 GDPR) and solely to provide services to NexaIT. We do not sell personal data.

  • the provider of the hosting and server infrastructure on which the Website runs
  • CookieYes Limited - cookie banner and consent log
  • Google Ireland Limited - analytics and advertising services and Consent Mode, if these tools are enabled
  • partners providing IT, marketing, accounting and legal services
  • public authorities, where required by law

Data transfers outside the EEA

If a service provider such as Google processes data outside the European Economic Area, including in the United States, the transfer relies on a mechanism provided for in the GDPR.

We ensure an adequate level of protection through the European Commission's adequacy decision on the EU-US Data Privacy Framework (2023/1795) or through Standard Contractual Clauses (SCCs).

Data retention periods

We store data only for as long as is necessary to achieve the purpose for which it was collected, or for the period required by law. After these periods, the data is deleted or anonymised.

  • contact correspondence - up to 12 months after communication ends
  • server logs - up to 12 months
  • CookieYes consent log - up to 36 months, for evidential purposes
  • analytics data, if analytics is enabled - up to 14 months
  • marketing data, if marketing is carried out - until consent is withdrawn
  • cookies - for the lifetime stated in the cookies section

Rights of the data subject

Under the GDPR, you have rights in relation to your data. If you believe your data is being processed unlawfully, you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

  • access to your data and a copy of it
  • rectification
  • erasure (the right to be forgotten)
  • restriction of processing
  • data portability
  • objection to processing
  • withdrawal of consent at any time, without affecting the lawfulness of previous processing

Contact channels

The Website has no contact form. Messages are sent directly by phone, email, WhatsApp or through an external booking calendar. The data collected and how it is processed by the provider of the chosen channel are also governed by that provider's privacy policy.

Cookies and consent management

The Website uses CookieYes to manage consent in line with the GDPR and the ePrivacy Directive. On your first visit, a banner lets you accept all cookies, reject all of them or customise your preferences. No analytics or marketing cookies are activated until you give consent.

You can change or withdraw your consent at any time using the "Manage consent" link in the page footer or through your browser settings. Disabling necessary cookies may limit some features of the Website.

If Google Consent Mode is enabled on the website, the ad_storage, analytics_storage, ad_user_data and ad_personalization parameters remain set to "denied" until consent is given, so that the corresponding cookies are not saved.

  • Necessary - required for the site to work, for example to remember your consent choices; no consent required
  • Analytics - help us analyse website traffic; consent required
  • Marketing - enable personalised advertising; consent required

Automated decision-making and profiling

The Controller does not make decisions producing legal effects for users based solely on automated processing. Profiling for marketing purposes may take place only with your consent.

Whether providing data is required

Providing personal data is voluntary but necessary for us to contact you and handle your enquiry; for analytics and marketing it requires your consent. Refusing analytics or marketing cookies does not limit your use of the Website's basic features.

Security measures

The Controller applies organisational and technical measures appropriate to the risk to protect data.

  • encrypted HTTPS connections (SSL/TLS)
  • regular updates of the components and dependencies used
  • access control for data and configuration
  • backups and technical monitoring
  • logging and analysis of unauthorised access attempts

Changes to this Policy

This Policy may be updated when laws, technology, providers or the scope of processing change. The new version is published at the same address with its update date. It was prepared in accordance with the GDPR (EU 2016/679), the Polish Personal Data Protection Act (Journal of Laws 2018, item 1000), Directive 2002/58/EC (ePrivacy), EDPB Guidelines 05/2020 on consent and current practice for Google Consent Mode.