ITmedesSysOps & Cloud
PL EN

Privacy policy

Last updated: 30 July 2026

1. Data controller

The controller of personal data is ITmedes Łukasz Sulikowski, ul. Szczęśliwa 12A, 05-270 Marki, Poland, VAT ID PL1251610854, REGON 525145290 (the “Controller”).

For any matter concerning the processing of personal data, please write to kontakt@itmedes.pl or to the registered address above.

The Controller has not appointed a Data Protection Officer, as there is no statutory obligation to do so given the scope of the business.

2. Scope

This policy applies to the website available at itmedes.pl and to correspondence conducted via the email addresses published on the site.

3. What data is processed

This is a static, informational website. It contains no contact forms, no user registration, and no cookies used for analytics or marketing.

3.1. Email contact

If you send a message to an address published on the site, the Controller processes the data you provide — typically your name, email address, company name, job title, phone number and the content of your message.

3.2. Server technical data

The hosting provider may automatically record in server logs your IP address, browser type, the date and time of the request and the page requested. This data is used solely to ensure the security and correct operation of the site.

4. Purposes and legal bases

PurposeLegal basisRetention period
Responding to enquiries and handling correspondence Art. 6(1)(b) and (f) GDPR — pre-contractual steps and legitimate interest until the correspondence ends, then up to 12 months
Concluding and performing a service agreement Art. 6(1)(b) GDPR for the duration of the agreement
Tax and accounting obligations Art. 6(1)(c) GDPR 5 years from the end of the tax year
Establishing, pursuing or defending legal claims Art. 6(1)(f) GDPR until the limitation period expires
Website security (server logs) Art. 6(1)(f) GDPR as per the hosting provider's policy

5. Is providing data mandatory?

Providing data is voluntary but necessary in order to receive a reply and to conclude and perform any agreement. Without it, no response can be sent.

6. Recipients of data

Data may be disclosed only to the following categories of recipients:

  • hosting and email service providers,
  • the accounting office serving the Controller,
  • providers of IT tools used to run the business,
  • authorities entitled to receive data under applicable law.

Data processing agreements have been concluded with all processors acting on the Controller's behalf. Data is never sold or shared with third parties for marketing purposes.

7. Transfers outside the EEA

The Controller uses cloud services whose providers may process data outside the European Economic Area. Where this occurs, transfers are based on Standard Contractual Clauses approved by the European Commission or on an adequacy decision.

8. Your rights

In relation to the processing of your data, you have the right to:

  • access your data and obtain a copy of it,
  • rectify inaccurate or incomplete data,
  • erasure (the “right to be forgotten”),
  • restriction of processing,
  • data portability,
  • object to processing based on legitimate interest,
  • withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

Requests can be submitted to kontakt@itmedes.pl and are answered without undue delay, and in any event within one month.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland) if you consider that the processing infringes the GDPR.

9. Cookies

The site uses no cookies other than any technical cookies strictly necessary for the page to display correctly. No analytics or tracking tools are used — in particular, there is no Google Analytics and no social media pixels.

10. Security

The Controller applies technical and organisational measures appropriate to the risk, including encrypted transmission (HTTPS), multi-factor authentication on administrative accounts and the principle of least privilege.

11. Automated decision-making

Data is not subject to automated decision-making or to profiling that produces legal effects or similarly significantly affects the data subject.

12. Changes to this policy

This policy may be updated to reflect changes in law or in the scope of services provided. The current version is always available at this address, together with the date of the last update.

← Back to home