Privacy Policy
Version of 12 September 2026. Replaces all earlier versions.
- Data controller
- What data is processed and where it comes from
- Purposes, legal bases and retention periods
- Recipients of the data
- Transfers outside the European Economic Area
- Rights of data subjects
- Cookies and visit statistics
- Browser-side tools and client reports
- Security and changes to this policy
-
DATA CONTROLLER
- The controller of personal data is Piotr Okupski, trading as ITORO, ul. Lermontowa 16/26, 92-512 Łódź, Poland, NIP (VAT) PL7282486424, REGON 366900540, entered in the Polish Central Register and Information on Economic Activity (CEIDG). Contact for data protection matters: sales@itoro.com.pl.
- The controller has not appointed a data protection officer, because none of the conditions of Article 37(1) GDPR applies: the controller is not a public body, does not monitor individuals on a large scale and does not process special categories of data on a large scale.
-
WHAT DATA IS PROCESSED AND WHERE IT COMES FROM
- The website has no user accounts and no public newsletter. Personal data arises in the following situations.
- Contact form and e-mail correspondence. Name, e-mail address, telephone number, subject and message text, together with anything the sender voluntarily includes. The data comes directly from the person writing.
- Client contact details. Names, e-mail addresses and telephone numbers of the persons a client designates as contacts under a contract. The data comes from the client.
- Server logs. IP address, date and time of the request, address of the page requested, browser identifier. Logs are kept by the hosting provider to ensure the security and continuity of the website.
- Language cookie. The website stores one cookie named
pll_language, which remembers the chosen language version for 12 months. It contains no data identifying a person and is not used for tracking. - Visit statistics, only with consent. After consent is given in the banner, the website runs Google Analytics 4; details in section 7.
- Protection of the form against automated abuse. The form checks the time taken to fill it in and the number of submissions from one IP address within ten minutes. For this purpose the IP address is stored only as a cryptographic hash for ten minutes and is not linked to the message content.
-
PURPOSES, LEGAL BASES AND RETENTION PERIODS
- Answering an enquiry and preparing an offer. Form and correspondence data. Basis: Article 6(1)(b) GDPR, steps at the request of the data subject prior to entering into a contract. Period: 12 months from the last contact if no contract is concluded.
- Performance of the contract and client service. Contact details of the client and of the persons designated by the client. Basis: Article 6(1)(b) GDPR for a client who is a natural person, and Article 6(1)(f) GDPR for the client's contact persons, the legitimate interest being the performance of the contract with their employer. Period: the term of the contract and then 6 years to the end of the calendar year in which the limitation period for claims expires.
- Informing clients about the software and services they use. Notices about new versions, security fixes and service changes, sent only to clients. Basis: Article 6(1)(b) and (f) GDPR, performance of the contract and the legitimate interest in keeping the delivered system secure. Period: the term of the contract. Every such notice explains how to stop receiving it.
- Tax and accounting. Invoice data. Basis: Article 6(1)(c) GDPR in conjunction with tax law. Period: 5 years from the end of the tax year.
- Security of the website and defence against abuse. Server logs, hashed IP address on form submission. Basis: Article 6(1)(f) GDPR, the legitimate interest in protecting the infrastructure. Period: logs no longer than 12 months, hashed IP address 10 minutes.
- Remembering the language version. Cookie
pll_language. Basis: Article 173(3) of the Polish Electronic Communications Law, a cookie necessary to provide the requested service. Period: 12 months. - Visit statistics. Cookies and data described in section 7. Basis: Article 6(1)(a) GDPR and Article 173(1) of the Polish Electronic Communications Law, consent given in the banner. Period: cookies 24 months, data in Google Analytics no longer than 14 months from the event.
- Providing data in the form is voluntary, but without an e-mail address no reply can be given. The telephone number is optional.
-
RECIPIENTS OF THE DATA
- Data is processed on the servers and in the e-mail service of the hosting provider OVH Sp. z o.o., ul. Swobodna 1, 50-088 Wrocław, Poland, under a data processing agreement.
- The recipient of statistical data collected with consent is Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, as a processor under the Google Analytics data processing terms.
- Invoice data may be shared with the accounting firm serving the controller. Data may be disclosed to authorities entitled to it by law.
- The controller does not sell personal data and does not share it with third parties for marketing purposes.
-
TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA
- Form, correspondence, contract and log data is not transferred outside the EEA.
- Google may transfer statistical data collected with consent to Google LLC in the United States. The transfer is based on the European Commission's implementing decision of 10 July 2023 on the EU-U.S. Data Privacy Framework, to which Google LLC has certified, and additionally on the standard contractual clauses contained in Google's terms.
-
RIGHTS OF DATA SUBJECTS
- Every person has the right to: access their data and obtain a copy; rectification; erasure; restriction of processing; portability of data processed on the basis of a contract or consent; and to object, on grounds relating to their particular situation, to processing based on legitimate interest.
- Consent to visit statistics can be withdrawn at any time via the "Cookie settings" link in the website footer. Withdrawal does not affect the lawfulness of processing carried out before it.
- Requests are received at sales@itoro.com.pl. The controller responds without undue delay and no later than within one month, or within three months in complex cases after prior notice of the extension.
- Anyone who considers that the processing infringes the GDPR may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl, or with the supervisory authority of their own EU member state.
- The controller does not take decisions concerning individuals based solely on automated processing and does not carry out profiling.
-
COOKIES AND VISIT STATISTICS
- To provide the service the website needs only the
pll_languagecookie described in section 2. No other cookies are set without consent. - After "Accept analytics cookies" is clicked in the banner, the website runs Google Analytics 4 provided by Google Ireland Ltd. The tool sets the cookies
_gaand_ga_LX76LNNZG8, valid for 24 months and containing a random browser identifier, and collects information about pages visited, visit time, device and browser type, and approximate location derived from the IP address, which is not stored. - The data is used solely for statistics on the use of the website. Advertising features and Google Signals are disabled in the tag configuration. Without consent the Google script is not loaded and no data reaches Google. Clicking "Reject" stores only the refusal for 12 months.
- The decision can be changed at any time via the "Cookie settings" link in the footer. Withdrawing consent deletes the analytics cookies and stops measurement. Cookies can also be removed in the browser settings.
- To provide the service the website needs only the
-
BROWSER-SIDE TOOLS AND CLIENT REPORTS
- The NIS2 and KSC self-assessment tool at itoro.com.pl/narzedzia/ksc/ runs entirely in the user's browser. The answers entered are not sent to the controller's server or anywhere else.
- Incident reports prepared for clients are published at addresses in the itoro.com.pl/rep/ directory with random, unpredictable names, accessible only to those who know the address, for 30 days from publication, after which they are deleted. They contain technical data about the client's network processed under the contract with the client; that contract governs their scope.
-
SECURITY AND CHANGES TO THIS POLICY
- The website is served exclusively over an encrypted HTTPS connection. Access to the mailbox and the server is limited to the controller and protected by authentication. The controller applies technical and organisational measures appropriate to the risk, in particular protecting data against unauthorised access, loss and unauthorised alteration.
- This policy is updated whenever the way data is processed on the website changes. The version date is stated at the top of the document. Changes do not apply retroactively.