Privacy Policy
Last updated: 11/20/2025
TL;DR: We protect your personal data in accordance with GDPR. We only collect necessary information, don't sell it to third parties, and use it solely for business purposes related to our services.
1. Data Controller
The controller of your personal data is:
2. What Data We Collect
Data Provided Voluntarily
- Contact Form: first name, last name, email address, phone number (optional), message content
- Newsletter: email address
- Marketing Consents: information about contact permissions
Data Collected Automatically
- Technical Data: IP address, browser type, operating system
- Cookies: essential cookies for website functionality (details in Cookie Policy)
- Analytics (Rybbit Analytics): anonymous usage statistics - pages visited, visit duration, traffic sources. Important: Rybbit Analytics doesn't use cookies, doesn't collect personal data, and is 100% GDPR compliant. It's a privacy-focused tool that doesn't track users across sites.
3. Why We Process Your Data
- Business Contact: responding to inquiries, presenting offers, customer service
- Marketing: sending information about products and services (with consent only)
- Statistics: website traffic analysis, service quality improvement
- Security: protection against spam and abuse
- Legal Obligations: document archiving according to regulations
4. Legal Basis for Processing
- Consent (Art. 6(1)(a) GDPR): marketing, newsletter
- Legitimate Interest (Art. 6(1)(f) GDPR): analytics, security
- Contract Performance (Art. 6(1)(b) GDPR): service provision
- Legal Obligation (Art. 6(1)(c) GDPR): document archiving
5. How Long We Keep Your Data
- Contact Data: until consent withdrawal or as long as necessary to handle inquiry
- Marketing: until consent withdrawal, maximum 3 years
- Accounting Documents: 5 years according to tax regulations
- Analytics Data: maximum 26 months
6. Who We Share Data With
Your data may be shared with the following categories of recipients:
- IT Service Providers: hosting, email (Resend), analytics (Rybbit Analytics - privacy-focused, cookieless)
- Payment Service Providers: when entering into contracts
- Accounting and Legal Service Providers: as necessary for business operations
- Public Authorities: upon request from authorized bodies
We do not sell your personal data to third parties.
7. Data Transfers Outside EEA
Some tools we use may transfer data outside the European Economic Area (EEA):
- Resend (USA): email sending - protected by EU standard contractual clauses
- We always ensure an appropriate level of protection in accordance with GDPR requirements
8. Your Rights
Under GDPR, you have the following rights:
- Right of Access: you can obtain information about processed data
- Right to Rectification: you can correct inaccurate data
- Right to Erasure: you can request data deletion ("right to be forgotten")
- Right to Restriction: in certain situations
- Right to Data Portability: receiving data in a structured format
- Right to Object: to data processing for marketing purposes
- Right to Withdraw Consent: at any time
To exercise these rights, contact us: hello@safezoneai.eu
9. Right to Lodge a Complaint
You have the right to lodge a complaint with the supervisory authority:
Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
Tel: +48 22 531 03 00
Web: uodo.gov.pl
10. Data Security
We implement appropriate technical and organizational measures to ensure data security:
- SSL/TLS connection encryption
- Server and database security
- Regular backups
- Limited data access only for authorized personnel
- Security incident response procedures
11. Changes to Privacy Policy
We reserve the right to make changes to this privacy policy. We will inform about significant changes on the website or by email.
12. Privacy Contact
For questions regarding personal data processing, contact us: