Skip to content
Condictor Studio

Privacy policy

Effective 24 September 2026. This policy explains what data Condictor collects through the website, why it is processed, and what rights website users have.

1. Data controller

The controller is Condictor Sp. z o.o., ul. Kościuszki 3/4, 38-300 Gorlice, Poland; NIP 738-215-05-34; KRS 0000634634; share capital PLN 5,000. Contact: biuro@condictor.pl, +48 506 235 763.

2. Data we process

Depending on how you use the website, we may process:

  • form data: name, email, company, optional telephone number, and project information,
  • the address of the page on this website from which you went to the form — the path only, stored with the enquiry,
  • correspondence and arrangements connected with an enquiry or cooperation,
  • technical security data such as IP address, request time, requested URL, and browser information,
  • language preference and cookie choice,
  • administrator-session data, only after login to the protected panel.

Do not enter passwords, API keys, card details, special-category data, or other sensitive information in forms.

PurposeLegal basis
answering an enquiry, preparing an estimate, and pre-contract stepsArt. 6(1)(b) GDPR
performing a contract and running a projectArt. 6(1)(b) GDPR
accounting and legal obligationsArt. 6(1)(c) GDPR
website security, spam prevention, and handling claimsArt. 6(1)(f) GDPR
assessing which website content leads to enquiries (page path stored with the enquiry)Art. 6(1)(f) GDPR
aggregate count of page entries, without identifiersArt. 6(1)(f) GDPR
visit statistics and click and scroll heatmaps (Umami) — only with your consentArt. 6(1)(a) GDPR

Providing form data is voluntary, but we cannot accept or answer an enquiry without the required fields. We do not operate a newsletter or use form data for marketing mail.

4. Forms, notifications, and AI

Form enquiries are stored in a private PostgreSQL database whose port is not publicly exposed. Each form requires confirmation that this policy has been read and uses anti-spam protections.

Together with the enquiry we store the address of the page on our website from which you went to the form: the path only (e.g. /en/blog/post-name), without URL parameters and only when it was a condictor.pl page. Your browser keeps it only in the open tab and sends it with the form; we do not store it in cookies or browser storage (localStorage, sessionStorage), so it is gone once the tab is closed. It lets us assess which content leads to enquiries. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR).

SMTP and Discord notifications are currently disabled. Data remains in the database and application logs. The AI brief assistant is also disabled, so form content is not sent to OpenRouter or a model provider. We will update this policy before enabling any such service.

5. Cookies and privacy settings

The public website uses no advertising or profiling cookies. It uses only mechanisms required for operation or to remember a user choice:

NamePurposeLifetime
NEXT_LOCALEremember the selected languageaccording to the language mechanism setting
condictor_consentremember the privacy-window choice180 days
condictor_adminsecure logged-in administrator sessionup to 7 days

We measure visits with Umami, running on our own server — only with your consent (“Accept all” in the privacy window). Without consent the statistics script is not even downloaded. Umami stores no cookie or identifier in your browser and sends no data to external services. The IP address and browser information are used only to compute a daily, irreversible hash that distinguishes visits — we do not store them in a form that allows identification. The legal basis is your consent (Art. 399(1) of the Polish Electronic Communications Law and Art. 6(1)(a) GDPR); the processing does not serve profiling. We use neither Google Analytics nor any other third-party analytics; should such a tool ever be introduced, it will not run before consent is given. You can withdraw consent at any time through “Cookie settings” in the footer by choosing “Necessary only” — measurement stops immediately.

With the same consent, Umami also builds click and scroll maps (heatmaps): it records where on a page you clicked and how far you scrolled, together with the size of the page and the browser window and the page address (the path only, without parameters). These events are attributed to the same visit as the visit statistics. We do not record sessions: we store neither the course of your visit, nor the page content, nor what you type into forms. The heatmap script loads together with the statistics script and, like it, stores nothing in your browser. The legal basis is your consent, as above. When you withdraw consent, the page reloads without this script.

Independently of Umami, the server counts entries to individual pages of the website: for each page and day it stores only the number of entries. The counter uses no script or cookies and stores nothing on your device. Of the request your browser sends for a page, it checks only the request type and the browser header (User-Agent), to skip bots and page preloading. It stores neither the IP address, nor the browser header, nor any identifier, so the aggregate count cannot be linked to any person. The legal basis is our legitimate interest in knowing which pages are visited (Art. 6(1)(f) GDPR).

6. Data recipients and transfers

Data may be accessible only to parties needed to operate the business and website: the VPS infrastructure provider, authorised Condictor personnel, accounting or legal advisers where necessary, and public authorities where required by law.

We do not sell data or share it with advertising networks. Before enabling a service that transfers data outside the European Economic Area, we will apply the required legal basis and safeguards and update this policy.

7. Retention

We retain data no longer than necessary to answer enquiries, run cooperation, meet legal obligations, and handle claims. Outdated enquiries and technical data are deleted or anonymised during periodic maintenance. Contract and accounting records are retained for the period required by law. The page path stored with an enquiry is kept and deleted together with the enquiry. Aggregate page-entry counts contain no data that identifies a person; we keep them as long as they serve traffic comparisons. Heatmap data is kept as long as it serves to assess page layout. Backups and logs have restricted access and are kept only as long as operational security and recovery require.

8. Your rights

You may request access, rectification, deletion, restriction, portability, or object to processing. Where consent is the basis, you may withdraw it at any time without affecting earlier lawful processing.

Send requests to biuro@condictor.pl. You may also complain to the President of the Polish Personal Data Protection Office or your competent supervisory authority.

9. Security and changes

We use HTTPS, restricted server and database access, administrator authentication, a firewall, monitoring, and backups. Form data is not publicly accessible.

We update this policy when the website, data scope, or providers change. Version 1.3 is effective from 24 September 2026.