In short: we collect only what is needed to answer you and run this site. We do not sell data, we do not profile, and we do not transfer data outside the European Economic Area without a legal basis.
1. Who is the controller
The controller of your personal data is HOLAPOLSKA sp. z o.o., ul. Kielecka 1/2, 31-526 Kraków, Poland, entered in the National Court Register (KRS) under number 0001259508, NIP 6751831638, REGON 545442954, share capital 5 000,00 zł.
For any data protection matter write to kontakt@holapolska.pl. We have not appointed a Data Protection Officer as we are not required to; these matters are handled directly by the management board.
2. What data we collect
- From the contact form: full name, email address, phone number, the topic you select and the content of your message.
- Automatically, in server logs: IP address, date and time of the request, the URL requested and browser type. This data is generated technically on every connection.
- From cookies: only to the extent described in the Cookie policy and only with your consent, except strictly necessary cookies.
We do not collect special categories of data (Art. 9 GDPR) and we ask you not to include such data in your message.
3. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Answering your message and taking steps prior to a contract | Art. 6(1)(b) GDPR | 12 months from last contact |
| Maintaining correspondence and business contact | Art. 6(1)(f) GDPR — legitimate interest | 12 months from last contact |
| Statistics and marketing (analytics tools) | Art. 6(1)(a) GDPR — your consent | until withdrawn, max. 24 months |
| Site security and abuse prevention | Art. 6(1)(f) GDPR | up to 12 months (server logs) |
| Performance of a contract, if concluded | Art. 6(1)(b) GDPR | duration of the contract |
| Accounting and tax obligations | Art. 6(1)(c) GDPR | 5 years from the end of the tax year |
4. Is providing data mandatory?
It is voluntary, but necessary for us to reply. Without an email address or phone number we have no way to reach you.
5. Who we share data with
Your data may be processed by trusted providers who serve us, only as far as necessary and under a data processing agreement (Art. 28 GDPR):
- hosting and email provider,
- analytics and marketing tools provider, only if you give consent,
- accounting office and advisers, if a contract is concluded,
- public authorities, where required by law.
We do not sell or disclose personal data to third parties for marketing purposes.
6. Transfers outside the EEA
Our infrastructure is kept within the European Union. If you consent to statistics or marketing cookies, data may be processed by Google Ireland Limited, which can involve a transfer to the United States. This relies on the European Commission adequacy decision of 10 July 2023 (EU–US Data Privacy Framework) and on standard contractual clauses. Without your consent no such transfer takes place — those tools only activate once you grant it.
7. Your rights
- access to your data and a copy of it (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on legitimate interest (Art. 21 GDPR),
- withdrawal of consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3) GDPR).
Simply write to kontakt@holapolska.pl. We respond without undue delay and within one month at the latest.
8. Right to complain
If you believe we process your data unlawfully, you may lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. As an EU resident you may also contact the supervisory authority of your country of habitual residence.
9. Profiling and automated decisions
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
10. Security
We apply technical and organisational measures appropriate to the risk: encrypted connection (TLS), restricted access to data, backups and protection of the contact form against abuse. The form is protected by methods that run on our own server — we do not use external CAPTCHA systems, which would require disclosing your IP address to third parties.
11. Changes to this policy
We may update it when the law or the way the site works changes. The current version is always published at this address, with the date shown below.
Last updated: 25 August 2026