Legal

Privacy policy

28 August 2026

This policy explains what happens to personal data on bitperfect.pl: what you type into the contact form, and what the server records on its own. The site has no database, carries no analytics or advertising, and embeds nothing from third-party servers. It does not cover the Poznaj app — that app has its own privacy policy, published separately.

1. Who the controller is

The controller of personal data collected through bitperfect.pl is Sebastian Zabrzyski, trading as BitPerfect Sebastian Zabrzyski, ul. Armii Krajowej 33/14, 81-395 Gdynia, Poland, VAT ID (NIP) 5862377082, business register number (REGON) 521142580, entered in the Polish Central Register and Information on Economic Activity (CEiDG).

For anything concerning personal data, including the rights described in section 7, write to kontakt@bitperfect.pl or by post to the address above.

I have not appointed a Data Protection Officer — the scale and nature of the processing do not trigger that obligation under Article 37 GDPR. I handle your requests directly.

2. What data I process

From the contact form — only what you type into it:

  • your name, or whatever you choose to call yourself,
  • the email address I should reply to,
  • the content of your message.

The form has no other fields and attaches no data gathered in the background.

On every visit the server records ordinary technical details of the request in its log: IP address, date and time, the page requested, the response code, and the browser and operating system names.

When you submit the form I additionally keep a hash of your IP address for the length of the rate-limit window. It serves only to reject further attempts from the same address and is not linked to anything else.

The site does not ask for special categories of data (health, beliefs, membership of organisations) and has no use for them — please do not put them in your message.

3. Why, and on what legal basis

  • To answer your enquiry and carry on the related correspondence — Article 6(1)(f) GDPR, my legitimate interest in handling enquiries addressed to the business.
  • If the correspondence turns into talks about working together — Article 6(1)(b) GDPR, steps taken at your request prior to entering into a contract.
  • To keep the site running, diagnose failures and defend it against abuse, including form spam — Article 6(1)(f) GDPR.
  • To establish, exercise or defend legal claims if the need arises — Article 6(1)(f) GDPR.

4. How long I keep it

  • Your message — until the correspondence on the matter is finished, and then for as long as follow-up questions may still come up or the correspondence may be needed to establish, exercise or defend legal claims; at the longest, until claims become time-barred.
  • Server logs — for as long as needed to maintain and secure the site; they are overwritten by routine rotation.
  • The hashed IP address used for rate limiting — for the length of the rate-limit window, after which the entry expires on its own.

5. Where your message goes

Your message goes to the company mailbox at kontakt@bitperfect.pl and stays there like any other email. I do not store it in any database — bitperfect.pl has no database. The form is a replacement for writing to me from your own mail client, not a new data set.

I do not write message contents to the logs either. The only thing logged is the fact that a delivery failed, so that a lost enquiry can be noticed.

Mail is handled by the same server that runs the site. Your message does not pass through an external mail provider or any intermediary service.

6. Who else sees the data

I do not sell your data and do not share it with data brokers, ad networks or anyone for marketing purposes.

The only party processing this data on my behalf is my server provider: Webdock.io ApS, Asperup, Denmark — hosting for the site and its mail. The servers are located within the European Economic Area.

I may also disclose data to public authorities entitled to demand it under the law, strictly to the extent and in the manner those provisions require.

I do not transfer data to third countries or international organisations.

7. Your rights

In connection with the processing of your data you have the right to:

  • access your data and obtain a copy of it (Article 15 GDPR),
  • have inaccurate data corrected and incomplete data completed (Article 16 GDPR),
  • have your data erased (Article 17 GDPR),
  • have the processing restricted (Article 18 GDPR).

Right to object. Because I process your data on the basis of a legitimate interest, you have the right to object to that processing at any time on grounds relating to your particular situation (Article 21(1) GDPR). Once you object I will stop processing your data, unless I can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or grounds for establishing, exercising or defending legal claims.

The right to data portability (Article 20 GDPR) does not apply here — it covers data processed on the basis of consent or a contract, and this data is processed on the basis of a legitimate interest. You can of course still obtain a copy of your data under the right of access.

Send requests to kontakt@bitperfect.pl. I will tell you what action I have taken within one month of receiving the request; where necessary I may extend that by a further two months because of the complexity of the request, and will let you know about the extension and its reasons.

If you believe I process your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. You may also complain in the country of your habitual residence, place of work, or the place of the alleged infringement.

8. Do you have to provide the data

Providing your data is entirely voluntary, but without an email address and a message there is no way for me to reply. To simply browse the site you need to provide nothing at all.

9. Automated decisions and profiling

I do not take decisions about you by automated means that would produce legal effects concerning you or similarly significantly affect you, and I do not carry out profiling.

The only automated step is rejecting submissions that look like spam — based on a hidden field, how long the form took to fill in, and how many submissions came from one IP address. It does not assess your personal characteristics, and its only effect is that one message is not accepted. You can always write to kontakt@bitperfect.pl directly instead.

10. Cookies

The site stores two cookies in your browser, both strictly necessary for the contact form to work:

  • bitperfect-session — the session holding the token that protects the form against submission from another site (CSRF), and the confirmation shown after you send a message,
  • XSRF-TOKEN — the same token, in the form the page itself reads.

Both expire after two hours and are not used for tracking. I use no analytics cookies, no advertising cookies and no third-party cookies.

The site embeds nothing from other servers: fonts, images, styles and scripts are all hosted at this same address, so opening the page connects your browser to no server but mine.

Because both cookies are necessary to deliver the service you asked for — sending a message — the law does not require your consent for them, and the site shows no consent banner.

11. Security

The site is served exclusively over an encrypted connection (HTTPS). The number of messages that can be sent from a single IP address is limited, and I am the only person with access to the mailbox they arrive in.

12. Changes to this policy

If I change how data is processed, I will publish a new version of this policy at this address together with its date. The date of the version in force is given at the top of the document.

Controller details

BitPerfect Sebastian Zabrzyski
ul. Armii Krajowej 33/14, 81-395 Gdynia, Polska
NIP 5862377082 · REGON 521142580
kontakt@bitperfect.pl