Documents

Privacy and cookie policy

How we process the personal data of people using upit.com.pl and contacting UPIT Sp. z o.o.

Last updated: 5 August 2026

1. General information

This Privacy and cookie policy sets out how personal data is processed for people using the website available at www.upit.com.pl (the „Website"), as well as people contacting UPIT Sp. z o.o. through the contact form, e-mail, telephone or social media profiles.

The policy also covers the use of cookies and similar technologies, the handling of enquiries, commercial correspondence, the performance of contracts and the Controller’s legal and accounting obligations.

The Controller processes personal data in accordance with applicable law, in particular Regulation (EU) 2016/679 („GDPR") and the Polish Electronic Communications Act of 12 July 2024.

2. Data controller

The controller of personal data is:

UPIT Sp. z o.o.
ul. Ojcowska 145
31-344 Kraków, Poland

VAT ID: PL9452246081 · REGON: 389466961 · KRS: 0000911532

You can contact the Controller:

For all matters relating to the processing of personal data, exercising GDPR rights and withdrawing marketing consent, please write to biuro@upit.com.pl.

3. How we obtain data

  1. directly from the data subject - through the form on the Website, e-mail, a phone call, social media messages, newsletter sign-up and correspondence concerning an offer or an ongoing project;
  2. automatically while the Website is used - through server logs, cookies, analytics tools and tools ensuring the security of the Website; tools requiring consent are used only once consent has been given;
  3. from a person representing a client or contractor - to the extent of the contact details of people appointed to work on the project;
  4. from publicly available sources - to the extent of company registry data needed to prepare an offer, contract or settlement.

Anyone providing the Controller with other people’s data should be entitled to do so and should inform those people about how the Controller processes data.

4. Scope of data processed

4.1. Data related to an enquiry

Name and surname, company name, e-mail address, phone number, the area of the enquiry, the content of the message, the history of correspondence and information about the offer prepared.

4.2. Data related to delivering a service

Contact details of the people appointed to cooperate, data needed to conclude and perform the contract, the scope and schedule of work, technical access credentials provided by the client, settlement data and project correspondence.

4.3. Invoicing data

For a natural person: name and surname, address, details of the service. For a business: company name, registered address, tax number, contact person, e-mail address and details of the service.

4.4. Data used for marketing communication

First name (if provided), e-mail address, date and source of consent, the scope of consent, the history of messages sent, and the date and manner of withdrawing consent.

4.5. Technical data

IP address, date and time of use of the Website, device and browser information, operating system, approximate location from the IP address, subpages visited, entry source, cookie identifiers and information about consents given.

The Controller does not require special categories of data. Please do not provide such information unless it is necessary for the agreed service.

5. Purposes and legal bases

5.1. Handling an enquiry and contact

Data from the form, e-mail, phone or social media is processed in order to receive and analyse the enquiry, reply, prepare an offer, conduct correspondence and take steps before entering into a contract. Basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest: handling correspondence and documenting arrangements).

5.2. Following up on an open enquiry

If we do not receive a reply to an offer, we may send a message directly related to the enquiry - a reminder, a question about whether it is still current, or a proposal for an alternative scope. Basis: Art. 6(1)(b) or (f) GDPR.

5.3. Concluding and performing a contract

Data is processed in order to conclude and perform the contract, run the project, communicate during it, settle it and handle changes of scope and complaints. Basis: Art. 6(1)(b) GDPR.

5.4. Tax, accounting and legal obligations

Issuing invoices and accounting documents, keeping records and meeting statutory obligations. Basis: Art. 6(1)(c) GDPR.

5.5. Newsletter and marketing communication

With separate, voluntary consent we process first name and e-mail address in order to send information about offers, materials and news from UPIT. Basis: Art. 6(1)(a) GDPR together with prior consent under the Electronic Communications Act. Consent is voluntary, is not a condition of sending an enquiry or working together, is never pre-ticked, and can be withdrawn at any time - through the link in a message or by writing to biuro@upit.com.pl.

5.6. Presenting work in our portfolio

Completed projects are presented in our portfolio and in offer materials. Publication takes place on the basis of provisions of the contract with the client or their separate consent, and in the case of contact persons’ data on the basis of the Controller’s legitimate interest (Art. 6(1)(f) GDPR).

5.7. Establishing, pursuing and defending claims

Basis: Art. 6(1)(f) GDPR (protection of the Controller’s rights and property).

5.8. Security and correct operation of the Website

Protection against abuse, detection of errors, technical logs and prevention of spam. Basis: Art. 6(1)(f) GDPR.

5.9. Web analytics

Once consent for analytics cookies has been given, we measure traffic and how the Website is used. Basis: Art. 6(1)(a) GDPR.

6. Is providing data voluntary?

Providing data is voluntary, but providing the data marked as required is necessary to send the form, receive a reply, prepare an offer, conclude a contract and issue an invoice. Providing data for marketing purposes is entirely voluntary.

7. Retention periods

Enquiries that do not lead to cooperation - as a rule no longer than 24 months from the last contact. Contract data - for the duration of performance and the period required by tax law and the limitation of claims. Accounting records - for the period required by law. Marketing data - until consent is withdrawn, an objection is raised or the purpose ceases. Records of consents - for as long as needed to demonstrate compliance.

8. Recipients of data

Data may be shared with entities supporting the Controller: providers of hosting and infrastructure, e-mail and domains, form and cookie-consent tools, mailing systems, analytics and advertising tools, subcontractors delivering project work (under data processing agreements), the accounting office, law firms and public authorities entitled by law - always only to the extent necessary. The Controller does not sell personal data.

9. Transfers outside the EEA

Some tool providers may have infrastructure outside the European Economic Area. In that case the transfer takes place on the basis of the mechanisms provided for in the GDPR - an adequacy decision, standard contractual clauses or other lawful safeguards.

10. Your rights

You have the right to: information, access to your data and a copy of it, rectification, completion, erasure, restriction of processing, data portability, objection (against processing based on legitimate interest and against direct marketing), withdrawal of consent at any time, and lodging a complaint with the President of the Polish Personal Data Protection Office (UODO). To exercise these rights, write to biuro@upit.com.pl.

11. Automated decision-making and profiling

Data from the form and correspondence is not used to make decisions based solely on automated processing with legal effects. Once consent for analytics or marketing cookies has been given, tool providers may carry out marketing profiling, which does not produce legal effects for the user.

12. Cookies and similar technologies

Cookies are small files stored on the user’s device. The Website uses:

  • essential cookies - necessary for the Website to work correctly and to remember the choices made, including the cookie decision and the settings of the accessibility panel; used without separate consent;
  • analytics cookies - Google Analytics; activated only after consent, used for statistics and improving the Website;
  • marketing cookies - used only after consent, if advertising activity is run on the Website.

The Website uses Google Consent Mode: until consent is given, analytics and advertising tools remain switched off. Consent can be changed or withdrawn at any time in the cookie settings panel available on the Website, as well as through browser settings. Withdrawing consent does not affect the lawfulness of processing carried out earlier.

13. Contact form

The form is used to send enquiries about UPIT services. Sending it means asking us to receive and analyse the enquiry, prepare a reply or an offer and make contact using the details provided. Data from the form is not automatically used for marketing mailings - that requires separate consent.

14. Wording of the statements next to the form

□ I have read the Privacy policy and I ask to be contacted at the e-mail address or phone number provided in order to handle my enquiry and present an offer.
□ I want to receive commercial and marketing information from UPIT Sp. z o.o. at the e-mail address provided, concerning offers, materials and news from UPIT. I can withdraw this consent at any time.

Marketing consent is voluntary and is not a condition of sending an enquiry or receiving an offer. The marketing checkbox is never pre-ticked.

15. Social media profiles

The Controller may run UPIT profiles in social media and process the data a user makes available on a given platform in order to run the profile, communicate, promote its services and defend against claims (Art. 6(1)(f) GDPR). The platform operator also remains an independent controller of data on the platform.

16. Links and external content

The Website may contain links to social media, maps and partners’ pages. Once you move to an external service, your data may be processed by its operator under its own rules. The Controller is not responsible for the policies of independent operators.

17. Data security

The Controller applies technical and organisational measures protecting data against loss, destruction, unauthorised change, disclosure and access by unauthorised persons, adjusted to the scope and risk of processing.

18. Changes to this policy

The policy may be updated as regulations, the scope of business, the Website’s features or the tools used change. The current version is published on the Website together with the date of the update.

19. Contact

For matters concerning personal data, GDPR rights, withdrawal of consent, unsubscribing from marketing messages, cookies and data security: biuro@upit.com.pl, UPIT Sp. z o.o., ul. Ojcowska 145, 31-344 Kraków, Poland.

20. Language versions

This document is an English translation prepared for the convenience of our international clients. In the event of any discrepancy, the Polish version of the policy prevails.