Skip to content
FAK.expert · information document

Privacy Policy and GDPR

Below, we explain what data may be processed when you use the website, contact us or complete the needs assessment.

Last updated: 7 August 2026

1. Data controller

The controller of your personal data is JERZY BEDNARSKI FAK.EXPERT, Polish Tax ID (NIP): 6783134606, email: biuro@fak.expert, telephone: 722 253 586, address: al. Powstania Warszawskiego 15, 31-539 Kraków, Poland.

For matters concerning personal data, you may contact us by email, telephone or post using the details above.

2. Categories of data

Depending on how you use the website, we may process data you provide directly, including your name or company name, email address, telephone number, message content, selected project types and parameters, preferred contact time, answers provided in the needs assessment and attachments you choose to send.

When you use the website, technical data required for operation and security may also be processed, such as your IP address, date and time of a request, URL, browser and device information, HTTP headers, error data and signals used by anti-spam protection.

We do not ask you to provide special categories of personal data (for example health data, political opinions or religious beliefs). Unless strictly necessary for your enquiry, please do not include such data in messages or attachments.

3. Purposes and legal bases

Handling enquiries and preparing a quotation

Data is processed so that we can respond, understand your requirements, prepare a recommendation or quotation and take steps before entering into a contract. The legal basis is Article 6(1)(b) GDPR and, for correspondence and the organisation of enquiry handling, the controller’s legitimate interest under Article 6(1)(f) GDPR.

Performance of a contract, accounting and claims

Once we begin working together, data may be processed to perform the contract, settle accounts, maintain accounting and tax records, and establish, pursue or defend legal claims under Article 6(1)(b), (c) and (f) GDPR.

Website security and reliability

Technical data may be used to protect forms against spam and abuse, limit automated submissions, detect errors and incidents, and maintain infrastructure security under Article 6(1)(f) GDPR.

4. Forms, needs assessment and attachments

The website provides a contact form, needs assessment and service-package forms. Data submitted through these forms is sent to the controller and may be transmitted through infrastructure and transactional-email providers. Attachments are transmitted only when you choose to add them.

The needs assessment generates an initial recommendation based on your answers. This is a simple supporting automation: the recommendation is for guidance only, does not constitute an offer, has no legal effect and is not a solely automated decision within the meaning of Article 22 GDPR.

5. Cloudflare – infrastructure, security, Turnstile and technical analytics

The website uses Cloudflare infrastructure for content delivery, traffic protection and form security. Forms use Cloudflare Turnstile, which analyses technical browser signals to distinguish a real user from an automated bot. Depending on the security mechanism and configuration, Cloudflare may use technical cookies or similar technologies that are necessary for security.

The website also uses Cloudflare Web Analytics / Real User Measurements (RUM) to measure aggregate page views and website performance. According to Cloudflare documentation, this service does not use cookies or localStorage for measurement and is not designed to track individual users across websites.

6. External services: Google Maps and Google Fonts

Google Maps – loaded only after your choice

The interactive map in the contact section is not loaded automatically. A local static location preview is displayed first. Your browser connects to Google Maps only after you click “Load Google Map”.

Once the map is loaded, Google may receive technical information, including your IP address, browser and device information and request-related data. Google Maps may also store its own cookies and similar technologies in accordance with Google’s policies. Clicking the load button constitutes consent to activate this external feature and the related Google technologies. Loading the map is not required to use the website’s other functions. If you do not click it, the interactive Google map is not embedded.

The “Open in Google Maps” link takes you directly to Google’s website; after using it you leave fak.expert and the external service’s privacy rules apply.

Google Fonts

The website currently uses Google Fonts to display its typefaces. The Google Fonts Web API does not set or log cookies, but when font files are requested your browser sends standard HTTP request data to Google servers, including the IP address, requested URL, browser/operating-system information and referrer. The purpose is consistent and correct presentation of the website, based on the controller’s legitimate interest under Article 6(1)(f) GDPR.

7. Brevo – transactional email and auto-replies

We use Brevo to send form-related transactional messages and auto-replies. Data necessary to send an email is transmitted to Brevo, in particular the recipient’s email address, name where provided, subject and message content. Messages sent to the controller may also contain the data and attachments submitted through the form.

Brevo maintains technical transactional-email logs, such as send, delivery and failure events. Anonymous email tracking is enabled on the controller’s account: email-open and link-click events may be counted for aggregate statistics, but they are not associated with a specific recipient. The controller does not use this information for advertising profiling or marketing without the required legal basis.

8. Recipients and processors

Data may be disclosed or entrusted only to the extent necessary to operate the website and handle enquiries, in particular to hosting and network-infrastructure providers, security services (Cloudflare), email and transactional-email providers (including Brevo), technical support providers and – after activation by the user – Google in connection with Google Maps. Google also receives standard technical request data when Google Fonts is used.

Data may be shared with accounting, legal or IT providers where necessary for our cooperation or legal obligations. Public authorities may receive data where required by law.

9. Transfers outside the EEA

Some infrastructure and internet-service providers operate globally and may process data outside the European Economic Area. Where this occurs, the transfer should rely on a mechanism provided for by the GDPR, such as an adequacy decision of the European Commission, Standard Contractual Clauses or another appropriate safeguard. The exact mechanism depends on the provider’s current infrastructure and contractual terms.

10. Retention periods

Enquiries that do not lead to a working relationship may be retained for up to 12 months after the last contact, unless earlier deletion is appropriate or longer retention is required to protect against legal claims.

Data relating to a contract is retained for the duration of its performance and then until the relevant limitation periods for claims have expired. Accounting and tax records are retained for the period required by law. Technical and security logs are retained for the period resulting from infrastructure configuration or as long as necessary to detect and investigate an incident.

Technical transactional-email logs in Brevo are currently retained for 1 month and are then deleted automatically under the configured retention rule. For new transactional emails, the controller has also enabled the option not to store message-content previews in Brevo.

11. Cookies and similar technologies

The website does not use first-party cookies for advertising profiling. Cloudflare security mechanisms may use technical cookies or similar technologies required to protect the service. Cloudflare Web Analytics/RUM is a client-side analytics solution that operates without cookies.

Google Maps may store its own cookies only after you deliberately load the interactive map. Under Polish Article 399 of the Electronic Communications Law, storing information on an end user’s device or accessing information already stored there generally requires prior information and the user’s consent. Exceptions include solutions necessary to transmit a communication or provide a service explicitly requested by the user.

You can also manage cookies and website data through your browser settings.

12. Voluntary provision of data

Providing data is voluntary, but without contact details we may be unable to respond. A telephone number is required in the needs assessment and quotation form because it is used to contact you about your submission. Fields marked as required are necessary to process the relevant form.

13. Your rights

To the extent provided by law, you have the right to access your data, obtain a copy, rectify or erase it, restrict processing, receive your data in a portable format, object to processing, and withdraw consent where processing is based on consent. Requests may be sent to biuro@fak.expert.

You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).

14. Security

We use encrypted HTTPS connections, restricted access to data and secrets, data validation, anti-spam safeguards, size limits for fields and attachments, and technical security measures offered by our infrastructure providers. No method of transmission or storage can, however, guarantee absolute security.

15. Changes to this document

This policy may be updated when website functionality, service configuration, providers, company details or applicable law change. The current version will always be available at this address.