Skip to content
Condictor Studio

Privacy policy

Effective 10 August 2026. This policy explains what data Condictor collects through the website, why it is processed, and what rights website users have.

1. Data controller

The controller is Condictor Sp. z o.o., ul. Kościuszki 3/4, 38-300 Gorlice, Poland; NIP 738-215-05-34; KRS 0000634634; share capital PLN 5,000. Contact: biuro@condictor.pl, +48 506 235 763.

2. Data we process

Depending on how you use the website, we may process:

  • form data: name, email, company, optional telephone number, and project information,
  • correspondence and arrangements connected with an enquiry or cooperation,
  • technical security data such as IP address, request time, requested URL, and browser information,
  • language preference and cookie choice,
  • administrator-session data, only after login to the protected panel.

Do not enter passwords, API keys, card details, special-category data, or other sensitive information in forms.

PurposeLegal basis
answering an enquiry, preparing an estimate, and pre-contract stepsArt. 6(1)(b) GDPR
performing a contract and running a projectArt. 6(1)(b) GDPR
accounting and legal obligationsArt. 6(1)(c) GDPR
website security, spam prevention, and handling claimsArt. 6(1)(f) GDPR
optional preferences if a consent-based tool is introducedArt. 6(1)(a) GDPR

Providing form data is voluntary, but we cannot accept or answer an enquiry without the required fields. We do not operate a newsletter or use form data for marketing mail.

4. Forms, notifications, and AI

Form enquiries are stored in a private PostgreSQL database whose port is not publicly exposed. Each form requires confirmation that this policy has been read and uses anti-spam protections.

SMTP and Discord notifications are currently disabled. Data remains in the database and application logs. The AI brief assistant is also disabled, so form content is not sent to OpenRouter or a model provider. We will update this policy before enabling any such service.

5. Cookies and privacy settings

The public website uses no advertising or profiling cookies. It uses only mechanisms required for operation or to remember a user choice:

NamePurposeLifetime
NEXT_LOCALEremember the selected languageaccording to the language mechanism setting
condictor_consentremember the privacy-window choice180 days
condictor_adminsecure logged-in administrator sessionup to 7 days

Optional analytics are not currently enabled. A future tool requiring consent will not run before consent is given. You can reopen the choice through “Cookie settings” in the footer.

6. Data recipients and transfers

Data may be accessible only to parties needed to operate the business and website: the VPS infrastructure provider, authorised Condictor personnel, accounting or legal advisers where necessary, and public authorities where required by law.

We do not sell data or share it with advertising networks. Before enabling a service that transfers data outside the European Economic Area, we will apply the required legal basis and safeguards and update this policy.

7. Retention

We retain data no longer than necessary to answer enquiries, run cooperation, meet legal obligations, and handle claims. Outdated enquiries and technical data are deleted or anonymised during periodic maintenance. Contract and accounting records are retained for the period required by law. Backups and logs have restricted access and are kept only as long as operational security and recovery require.

8. Your rights

You may request access, rectification, deletion, restriction, portability, or object to processing. Where consent is the basis, you may withdraw it at any time without affecting earlier lawful processing.

Send requests to biuro@condictor.pl. You may also complain to the President of the Polish Personal Data Protection Office or your competent supervisory authority.

9. Security and changes

We use HTTPS, restricted server and database access, administrator authentication, a firewall, monitoring, and backups. Form data is not publicly accessible.

We update this policy when the website, data scope, or providers change. Version 1.0 is effective from 10 August 2026.