1. Data controller
The controller of your personal data is Beat Hangartner, sole trader operating under the brand Pan Ciepełko, with registered office in Gdańsk, Poland, entered in the Polish Central Register of Business Activity (CEIDG), VAT ID PL5833495608, REGON 527118848 (“we”, the “Controller”).
Contact for data protection matters: [email protected] or by post to the registered office as published in CEIDG. We have not appointed a data protection officer — the scale of our processing does not require one.
We process data in accordance with Regulation (EU) 2016/679 (GDPR), the Polish Personal Data Protection Act of 10 May 2018 and the Polish Electronic Communications Law of 12 July 2024 (as regards cookies).
2. What data we process, why and for how long
| Situation | Data | Purpose and legal basis | Retention |
|---|---|---|---|
| Visiting the website | IP address, device and browser identifiers, date and time, page visited, referring page, response code | operation and security of the website, protection against abuse, error diagnostics — legitimate interest (Art. 6(1)(f) GDPR) | technical logs at the hosting provider: up to 90 days |
| Usage statistics and analysis | cookie identifiers, on-page events (page views, clicks, scrolling), approximate location from the IP address, device data | understanding how the site is used and improving it — your consent (Art. 6(1)(a) GDPR and Art. 399 of the Polish Electronic Communications Law), given in the cookie banner | until consent is withdrawn; data in analytics tools: up to 14 months |
| Record of your cookie decision | consent identifier, content of the decision, date | demonstrating that consent was given or refused (accountability) — legal obligation and legitimate interest (Art. 6(1)(c) and (f) GDPR) | 12 months from the decision |
| E-mail correspondence and enquiries | name, e-mail address, telephone number (if provided), company, message content, attachments (e.g. floor plans) | replying to your enquiry, preparing a quote, steps prior to entering into a contract (Art. 6(1)(b) GDPR); otherwise legitimate interest: conducting correspondence, defence against claims (point (f)) | until the matter is closed, then until limitation periods for claims expire (as a rule 3 years in business dealings, at most 6 years) |
| Clients and business partners (quotes, orders, contracts, invoices) | identification data, address, tax ID, invoicing data, contact data, order history, payment data | concluding and performing the contract (Art. 6(1)(b) GDPR); issuing and storing invoices, tax settlements, obligations towards the Polish national e-invoicing system KSeF (point (c)); pursuing and defending claims (point (f)) | for the term of the contract, then 5 years from the end of the tax year (accounting records) or until limitation periods expire, whichever is longer |
| Project data (floor plans, building data, meter readings, booking data) | may contain personal data: names on drawings, property addresses, details of unit owners, occupancy patterns | performing the design, simulation, configuration and commissioning service (Art. 6(1)(b) GDPR); for third-party data — our and the client’s legitimate interest (point (f)) | for the duration of the project and the maintenance period, then until limitation periods expire |
| Contact persons at clients and partners (employees, representatives, installers, architects) | name, position, business contact details | contact concerning the contract or project — legitimate interest (Art. 6(1)(f) GDPR) | for the duration of the relationship, then until limitation periods expire |
If we launch user accounts on the platform (the portal for architects and investors), detailed information on processing within the account will be provided at registration, in a separate document.
3. Where the data comes from
We receive data directly from you (a message, an order, uploaded documents) or from your employer or principal — for example when an investor names the architect or installer we are to contact. We verify registration data of business partners in public registers (CEIDG, KRS, the VAT taxpayer register).
4. Recipients of data
We pass data only to entities we need in order to operate, under data processing agreements or within their own legal obligations:
- Cloudflare, Inc. (USA) — website hosting, CDN, web application firewall, DNS.
- Google Ireland Limited — Google Tag Manager and Google Analytics 4 (only after consent); e-mail and office tools (Google Workspace).
- Contentsquare SAS (France) — analysis of how the site is used: click maps, anonymised session recordings (only after consent).
- The provider of the consent management tool (Consentboard) — displaying the cookie banner and recording your decision.
- Odoo S.A. (Belgium) — quoting, invoicing and customer management system (Odoo Online).
- Microsoft Ireland Operations Ltd. — Microsoft Azure cloud services in the Poland Central region: storage and processing of project data and authentication of platform users.
- Accounting office, tax and legal advisers — to the extent necessary for their tasks.
- Contractors named by the client (installers, designers) — transfer of project documentation on the client’s instruction.
- Public authorities — where required by law, in particular the Polish national e-invoicing system KSeF (Ministry of Finance).
We do not sell personal data and do not share it for third-party marketing purposes.
5. Transfers outside the European Economic Area
Some of our providers (Cloudflare, Google) are established in the USA or use infrastructure outside the EEA. Transfers take place on the basis of the European Commission’s adequacy decision for entities certified under the EU-U.S. Data Privacy Framework and — additionally — on the basis of standard contractual clauses adopted by the European Commission, with supplementary safeguards (encryption in transit and at rest). You can obtain a copy of the safeguards by writing to the address in section 1.
6. Cookies and similar technologies
The website uses cookies and similar technologies (e.g. local storage) in the following categories:
- Necessary — remembering your cookie decision, protection against abuse (Cloudflare). No consent required; based on Art. 399(3) of the Polish Electronic Communications Law.
- Analytics — Google Analytics 4 (visit statistics) and Contentsquare (click maps, session recordings with masking of typed content). Activated only after your consent.
- Marketing — we currently use no marketing cookies. The consent banner provides for this category in case such tools are launched in future; until then a choice in this category has no effect.
We use Google Consent Mode v2 with the default set to “denied”: until you give consent, analytics tools set no cookies and collect no identifiers.
Managing consent. You decide in the banner on your first visit. You can change or withdraw your decision at any time with the button at the end of this page, or by deleting cookies in your browser settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. You can also block cookies in your browser — the site will work, but analytics tools will not be active.
7. Your rights
You have the right to:
- access your data and obtain a copy (Art. 15 GDPR),
- rectification of inaccurate or incomplete data (Art. 16),
- erasure of data where there is no longer a basis for processing (Art. 17),
- restriction of processing (Art. 18),
- data portability for data processed on the basis of consent or a contract by automated means (Art. 20),
- object to processing based on legitimate interest, on grounds relating to your particular situation (Art. 21),
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal,
- lodge a complaint with a supervisory authority: the President of the Polish Personal Data Protection Office (Prezes UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl — or with the authority in your EU member state of residence.
Send requests to [email protected]. We reply without undue delay, at the latest within one month. We may ask for additional information needed to confirm your identity.
8. Is providing data voluntary?
Providing data is voluntary. Without contact data, however, we cannot reply to an enquiry, and without identification and invoicing data we cannot conclude a contract or issue an invoice. Consent to analytics cookies is entirely voluntary and does not affect access to the site.
9. Automated decision-making and profiling
We do not make decisions about you based solely on automated processing that would produce legal effects or similarly significantly affect you. The automated processing of drawings and building data within the design service concerns the building, not persons, and is not used for profiling.
Uploaded drawings and project data are not used to train publicly available artificial intelligence models and are not shared with providers of such models for training.
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), a web application firewall and bot protection, multi-factor authentication for systems holding data, access control on a least-privilege basis, backups, and data processing agreements with providers.
11. Changes to this policy
This policy may be updated when our services, providers or the law change. The current dated version is always available at panciepelko.pl/en/privacy-policy. For material changes affecting clients we will additionally inform them by e-mail.
12. Language versions
The Polish version of this policy is binding. The English and German versions are provided for information; in case of discrepancy, the Polish text prevails.