Privacy Policy

website https://drblitz-weblab.com/

Last updated: 10 June 2026

1. General provisions

  1. This Privacy Policy sets out the rules governing the processing and protection of personal data of users of the website available at https://drblitz-weblab.com/ (hereinafter: the “Website”).
  2. Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter: ‘GDPR’) and the Act of 10 May 2018 on the protection of personal data.
  3. Use of the Website is voluntary. The provision of personal data (e.g. via the contact form) is voluntary, but may be necessary in order to respond to an enquiry or to provide a service.

2. Data controller

  1. The data controller is: Dr Blitz-Weblab Sp. z o.o., ul. Obozowa 50b/33, 30-383 Kraków, Tax Identification Number (NIP): 6762690377
  2. To contact the Data Controller regarding personal data:
    • by email: [email protected]
    • telefon: 12 333 44 01
    • by post: to the registered office address given above.

3. Purposes, legal bases and duration of data processing

3.1. Contact form and contact via email/telephone

  • Scope of data: first name and surname, email address, telephone number, company name and any other data voluntarily provided in the message.
  • Purpose: to respond to enquiries, conduct correspondence and prepare a commercial offer.
  • Legal basis: Article 6(1)(b) of the GDPR (measures taken to enter into a contract at the request of the data subject) and Article 6(1)(f) of the GDPR (the Controller’s legitimate interest in communicating with persons interested in its services).
  • Retention period: for the time necessary to handle the enquiry, and subsequently for the limitation period of any potential claims (as a rule, up to 6 years).

3.2. Booking an appointment (Microsoft Bookings)

  • The service enables you to book a meeting via Microsoft Bookings (Outlook), provided by Microsoft Ireland Operations Ltd.
  • Scope of data: first name and surname, email address, telephone number, selected meeting date and time, and any data voluntarily provided in the booking form.
  • Purpose: to arrange and organise a meeting.
  • Legal basis: Article 6(1)(b) of the GDPR and Article 6(1)(f) of the GDPR.
  • Microsoft’s data processing practices are set out in Microsoft’s privacy policy: https://privacy.microsoft.com/pl-pl/privacystatement

3.3. Recruitment (the ‘Careers’ tab)

  • Scope of data: data contained in the application documents submitted (CV, cover letter).
  • Purpose: to conduct the recruitment process.
  • Legal basis: Article 6(1)(b) and (c) of the GDPR in conjunction with Article 22¹ of the Labour Code (in respect of data required by law) and Article 6(1)(a) of the GDPR (consent – in respect of data provided voluntarily beyond the statutory requirements and consent to participate in future recruitment processes).
  • Retention period: until the end of the recruitment process, and in the case of consent to future recruitment processes – for no longer than 12 months.

3.4. Conclusion and performance of contracts

  • Scope of data: identification and contact details of the contracting parties, billing details.
  • Purpose: conclusion and performance of the contract, issuing invoices, fulfilment of tax and accounting obligations.
  • Legal basis: Article 6(1)(b) of the GDPR (performance of a contract) and Article 6(1)(c) of the GDPR (legal obligations, in particular tax and accounting obligations).
  • Retention period: for the duration of the contract, followed by the period required by law (as a rule, 5 years from the end of the tax year) and the limitation period for claims.

3.5. Analytics and statistics

  • Purpose: to analyse traffic on the Website, to study how the Website is used, and to improve the quality of services and the usability of the Website.
  • Legal basis: Article 6(1)(a) of the GDPR (consent given via the cookie consent management tool) and Article 6(1)(f) of the GDPR (the Controller’s legitimate interest in relation to anonymised statistics).
  • Details regarding the analytical tools used are set out in section 6 (Cookies and analytical tools).

3.6. Establishing, pursuing and defending claims

  • Legal basis: Article 6(1)(f) of the GDPR (the Controller’s legitimate interest).
  • Retention period: for the duration of the limitation period for claims as provided for by law.

4. Recipients of data

Personal data may be disclosed to the following categories of recipients, solely to the extent necessary to fulfil the purposes of processing:

  1. Hosting and IT infrastructure providers – in particular Hetzner Online GmbH (Germany), on whose servers the Website is hosted.
  2. Cloudflare, Inc. – a provider of CDN, DNS and network security services (protection against attacks, traffic optimisation).
  3. Microsoft Ireland Operations Ltd. – in relation to the appointment booking service (Microsoft Bookings), email and the Microsoft Clarity analytics tool (where the user has given their consent).
  4. Entities providing accounting, legal and advisory services to the Controller.
  5. Postal operators and couriers – in relation to correspondence.
  6. Public authorities – only where the obligation to disclose data arises from statutory provisions.

All entities processing data on behalf of the Controller operate on the basis of data processing agreements (Article 28 of the GDPR).

5. Transfer of data outside the European Economic Area (EEA)

  1. As a general rule, data is processed within the EEA.
  2. In connection with the use of services provided by Cloudflare, Inc. and Microsoft (Microsoft Clarity), data may be transferred to the United States. The transfer takes place on the basis of:
    • a decision by the European Commission confirming an adequate level of protection under the EU-USS. Data Privacy Framework (DPF) – in relation to entities certified under the DPF, and/
    • or the
    • Standard
    • Contractual Clauses (SCCs) approved by the European Commission.
  3. You may obtain a copy of the safeguards in place by contacting the Data Controller.

6. Cookies and analytics tools

6.1. What are cookies?

Cookies are small text files stored on the user’s device whilst using the Website. They are used, amongst other things, to ensure the website functions correctly, to remember preferences and for statistical purposes.

6.2. Managing consent

  1. On their first visit to the Website, users are shown a cookie consent banner, allowing them to give, withdraw or restrict consent for specific categories of cookies (with the exception of essential cookies).
  2. Consent may be withdrawn or modified at any time via the cookie settings available on the Website. Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal.
  3. Users may also manage cookies via their web browser settings, including blocking or deleting them. Restricting the use of cookies may affect certain features of the Website.

6.3. Categories of cookies used

CategoryPurposeLegal basis
EssentialTo ensure the proper functioning of the Website, security (including Cloudflare cookies), and to remember consent decisionsLegitimate interest (Article 6(1)(f) of the GDPR)
Statistical / analyticalAnalysis of traffic and how the Website is used (Matomo, Microsoft Clarity)Consent (Article 6(1)(a) of the GDPR)

6.4. Matomo

  • The Website uses the Matomo analytics tool, hosted on the Controller’s own infrastructure (data is not transferred to an external analytics provider).
  • Matomo collects, amongst other things, information on the subpages visited, the duration of the visit, the type of device and browser, and a truncated (anonymised) IP address.
  • The data is used solely for statistical purposes and is not used to identify specific individuals.

6.5. Microsoft Clarity

  • With the user’s consent, the Website uses the Microsoft Clarity tool to analyse user behaviour (heatmaps, session recordings with sensitive data masked).
  • The tool is provided by Microsoft Corporation. Information on data processing by Microsoft: https://privacy.microsoft.com/pl-pl/privacystatement

6.6. Cloudflare

  • The Website uses the services of Cloudflare, Inc. (CDN, DNS, protection against DDoS attacks). Cloudflare may process technical data, such as IP addresses, to ensure the security and performance of the Website.
  • Further information: https://www.cloudflare.com/privacypolicy/

7. Social media

  1. The Website contains links to the Controller’s profiles on Facebook (Meta Platforms Ireland Ltd.) and LinkedIn (LinkedIn Ireland Unlimited Company).
  2. When you visit these profiles, your data is processed in accordance with the privacy policies of these platforms. With regard to page statistics (Page Insights), the Controller and the social media provider may act as joint controllers.
  3. Providers’ privacy policies:

8. Rights of data subjects

Every data subject whose data is processed has the following rights:

  1. the right to access their data and obtain a copy thereof (Article 15 of the GDPR),
  2. the right to rectification of data (Article 16 of the GDPR),
  3. the right to erasure – the ‘right to be forgotten’ (Article 17 of the GDPR),
  4. the right to restriction of processing (Article 18 of the GDPR),
  5. the right to data portability (Article 20 of the GDPR),
  6. the right to object to processing based on a legitimate interest (Article 21 of the GDPR),
  7. the right to withdraw consent at any time – without affecting the lawfulness of processing carried out prior to its withdrawal,
  8. the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl).

To exercise the above rights, please contact the Controller (contact details in point 2). The Controller will respond without undue delay, no later than one month after receiving the request.

9. Automated decision-making and profiling

Users’ personal data is not used for automated decision-making that produces legal effects, including profiling within the meaning of Article 22 of the GDPR.

10. Data security

  1. The Controller implements technical and organisational measures to ensure the protection of the personal data being processed, appropriate to the risks and the category of data, in particular:
    • data transmission encryption (SSL/TLS certificate),
    • server infrastructure security measures (including firewalls and access restrictions),
    • regular software updates, and
    • access to data restricted to authorised persons only.
  2. The Controller analyses risks on an ongoing basis and adapts the security measures in place accordingly.

11. Changes to the Privacy Policy

  1. The Data Controller reserves the right to amend this Privacy Policy, in particular in the event of changes to legislation, the technologies used or the scope of services.
  2. The current version of the Privacy Policy is always available at: https://drblitz-weblab.com/polityka-prywatnosci
  3. Users will be informed of any significant changes through the publication of the updated version on the Website.