Contact for personal data protection matters: gdpr@lablogic.pl
1. Personal Data Controller
The personal data controller is Michał Rutkowski, operating a business under the name LabLogic Consulting Michał Rutkowski, with the business address at ul. Wolności 15, 81-327 Gdynia, hereinafter referred to as “LabLogic” or “Controller”.
For matters concerning the processing of personal data, you can contact the Controller at: gdpr@LabLogic.pl
This policy describes the principles of personal data processing in connection with:
- using the lablogic.pl website;
- sending inquiries via the contact form;
- contact by email, phone, or during a meeting;
- preparation, conclusion, and performance of contracts;
- maintenance, analysis, and security of the website;
- using remote support services provided by LabLogic.
This policy does not describe in detail the processing of data that LabLogic carries out on the documented instructions of its clients as a processor, particularly during IT support, work in the client’s systems, incident handling, and ancillary activities in audits. In such cases, the purposes and essential means of processing are determined by the client, who is the controller, and the terms of cooperation follow from the processing agreement and the controller’s instructions.
Acting as a data protection officer is treated separately. The officer performs the tasks set out in Article 39(1) GDPR, may perform them on the basis of a service contract (Article 37(6) GDPR), receives no instructions regarding the exercise of those tasks (Article 38(3) GDPR), and access to personal data and processing operations follows from Article 38(2) GDPR. Appointing LabLogic to that role therefore does not in itself create a processor relationship under Article 28 GDPR. Where, alongside the officer’s role, LabLogic carries out separate activities for a client on its documented instructions, that part of the cooperation is covered by a separate processing agreement.
2. What data may be processed
Data related to inquiries and correspondence
- first and last name;
- company or organization name;
- position or function held;
- email address;
- phone number, if provided;
- selected area of support;
- content of the inquiry and further correspondence;
- other information voluntarily provided by the sender;
- technical data related to sending the form and protection against abuse.
Data related to cooperation
- identification and contact data;
- data of the represented organization;
- data contained in contracts, orders, offers, and correspondence;
- information necessary for the organization and provision of services;
- data of individuals participating in project implementation;
- billing, accounting, and tax data;
- information needed to demonstrate contract performance.
Technical data related to the website
- IP address;
- date and time of connection;
- visited URL address;
- referring page address;
- information about the browser, operating system, and device;
- information about errors, login attempts, and security events;
- cookie identifiers and analytical data – to the extent dependent on user settings and granted consents.
3. Where data comes from
Data is primarily obtained directly from the data subject, particularly via form, email, phone, meeting, or documents related to cooperation.
- the organization that the individual represents;
- a client or contractor who has indicated the individual as a representative, employee, contact person, or project participant;
- another person involved in organizing cooperation.
In such cases, typically processed data includes: first and last name, position or function, business contact details, organization name, and information related to the scope of cooperation.
We provide the information within a reasonable period after obtaining the data, and at the latest within one month. If the data are to be used to communicate with the person, the information reaches them at the latest at the time of the first such communication; if we envisage disclosing the data to another recipient, at the latest when the data are first disclosed. The obligation does not arise where the person already has the information or another exception under Article 14(5) GDPR applies.
4. Contact, inquiries, and offer preparation
Data provided in the form or correspondence is processed for the purpose of:
- providing a response;
- assessing needs and potential scope of support;
- preparing an offer;
- conducting further correspondence;
- taking steps prior to entering into a contract.
The legal basis for processing is:
- Art. 6(1)(b) GDPR – when actions are taken at the request of a person who may become a party to the contract;
- Art. 6(1)(f) GDPR – when contact is made on behalf of a company or organization, or does not directly lead to the conclusion of a contract with the person sending the inquiry.
The Controller’s legitimate interest is to conduct communication, respond to inquiries, prepare offers, and establish and maintain business relationships.
Data related to a general inquiry that did not lead to the initiation of cooperation is stored for a period not longer than 12 months from the end of correspondence.
If an individual offer was prepared, terms were negotiated, or other significant actions were taken before concluding a contract, data may be stored for a period not longer than 24 months from the last significant contact.
Data may be stored longer if necessary for the establishment, exercise, or defense of legal claims or for compliance with a legal obligation.
5. Conclusion and performance of contracts
Data is processed for the purpose of:
- conclusion and performance of the contract;
- organization of services;
- conducting project communication;
- documenting agreements and performed actions;
- ensuring accountability of services rendered;
- settlement of cooperation.
With regard to the person who is a party to the contract, the legal basis is Art. 6(1)(b) GDPR.
Data of employees, representatives, proxies, and other contact persons of the parties are processed on the basis of Art. 6(1)(f) GDPR. The Controller’s legitimate interest is the organization and implementation of cooperation, communication between the parties, and documentation of its course.
Data is stored for the duration of the contract, and then:
- for the period required by tax, accounting, or other legal provisions;
- until the expiry of the relevant limitation periods for claims;
- in the event of a dispute – until its final resolution and execution of the decision.
Tax and accounting documentation is stored for the period resulting from the relevant regulations, generally for 5 years counted according to the rules applicable to the given document and obligation.
6. Establishment, exercise, and defense of claims
Data may be processed for the purpose of:
- securing evidence of established facts;
- demonstrating due performance of obligations; pursuing receivables;
- clarifying disputes;
- defending against claims.
The legal basis is Art. 6(1)(f) GDPR.
The Controller’s legitimate interest is the protection of its rights and the ability to demonstrate the correctness of actions taken.
Data is stored until the expiry of the relevant limitation period for claims, and in the event of proceedings – until their conclusion and the execution of the issued decision.
7. Website security and maintenance
Technical data and information contained in logs are processed for the purpose of:
- ensuring the proper functioning of the website;
- detecting and removing errors;
- protection against spam, malware, hacking attempts, and other abuses;
- protection of forms and email;
- backup management;
- detecting, analyzing, and documenting security incidents; identifying sources of unauthorized activity.
The legal basis for processing is Art. 6(1)(f) GDPR.
The Controller’s legitimate interest is to ensure the confidentiality, integrity, availability, and resilience of the website, and the protection of data, systems, and users.
Wordfence only records security-related traffic. Data in the Live Traffic function is stored for a period not longer than 30 days.
Data related to a detected threat, block, or incident may be stored longer – for the period necessary to clarify the event, implement corrective measures, prevent similar events, and establish, exercise, or defend claims.
The hosting provider performs daily backups of website files and databases. Backups are stored for 30 days, and then deleted or overwritten.
8. Form protection against spam
Forms available on the website are protected by mechanisms that run within the Controller’s own website, without transferring data to external services.
The protection consists of:
- checking a token attached to the form on submission;
- a hidden field that only automated scripts fill in;
- rejecting submissions sent faster than a person could send them;
- protecting the form, website, and email against abuse.
In connection with this protection, the technical data described in section 2 and the content of the submission are processed. The legal basis for processing is Art. 6(1)(f) GDPR. The legitimate interest of the Controller is the protection of the form, the website, and email against spam and other abuses.
The mechanism sets no cookies and transfers no data outside the Controller’s website. The safeguards described in section 7 remain unchanged.
9. Google Analytics
After consenting to analytical cookies, the website uses the Google Analytics 4 service.
Data is processed for the purpose of:
- creating visit statistics;
- understanding how the website is used;
- assessing the effectiveness and usability of the site;
- detecting navigation and content problems;
- improving the structure and content of the website.
The legal basis is Art. 6(1)(a) GDPR, i.e., user consent.
Google Analytics is launched in conjunction with the Complianz consent management mechanism, WP Consent API, and Google Consent Mode. Cookie-based measurement and user-level data only come into being after consent to statistics has been given.
The website runs in Google advanced consent mode. The Google tag loads when the page is opened, with every consent signal set to denied. Before the user makes a choice — and where the user refuses — the tag neither writes nor reads cookies, but it may send Google basic technical data about the connection, including the IP address and the address of the page visited, without a user identifier. The legal basis for that narrow scope is Art. 6(1)(f) GDPR, the legitimate interest of the Controller being aggregate measurement of how the website operates. Full analytical measurement starts only after consent.
Consent can be given, refused, or withdrawn at any time using the consent management tool available on the website. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
User-level and event data is stored in Google Analytics for 14 months. This setting does not include standard aggregated reports, which may be stored by Google for a longer period.
Google Analytics is not used by LabLogic to make decisions concerning users that produce legal effects or similarly significantly affect them.
10. Cookies and similar technologies
The website may use cookies and similar technologies for the purpose of:
- ensuring the proper functioning of the website;
- protection against abuse;
- remembering consent decisions;
- conducting statistics – after obtaining user consent.
Cookies necessary for the operation of the website, security, or remembering consent preferences may be used without consent, to the extent permitted by applicable regulations.
Analytical cookies and other optional technologies are used after obtaining user consent.
Detailed information about the services used, cookies, their providers, purposes, and operating periods can be found in the Cookie Policy.
The user can change their decision at any time using the consent management function available on the website.
11. Data recipients
Data may be transferred or entrusted only to the extent necessary to achieve the described purposes:
- persons authorized by the Controller;
- LH.pl Sp. z o.o. – hosting, email, and backup provider;
- providers of IT, administrative, and security services;
- Defiant, Inc. – provider of the Wordfence solution;
- Google group entities – in connection with Google Analytics and Site Kit services;
- providers of accounting, legal, banking, and settlement services;
- operators of tools used for remote support – when an individual starts such a session;
- subcontractors and experts participating in the provision of a specific service, if their involvement is necessary;
- postal and courier operators, if required by the cooperation;
- public authorities, courts, and other authorized entities, when the obligation to transfer data results from law.
Entities processing data on behalf of the Controller may use it only on the basis of an appropriate agreement, in accordance with documented instructions and applicable regulations.
LabLogic does not sell personal data.
Data submitted via the general contact form is not saved in the WPForms Lite Connect service. The form is used to send messages to the Controller’s mailbox.
12. Transfer of data outside the European Economic Area
Two technological services — Google Analytics and Wordfence — involve processing data in the United States or access to data from that country. The mechanism applied to each of these transfers is set out below.
- Google — the contracting party for the European Economic Area is Google Ireland Limited, seated in Dublin. Data is transferred to Google LLC in the United States on the basis of Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection provided by the EU–US Data Privacy Framework. Google LLC participates in that framework.
- Defiant, Inc. — the provider of Wordfence does not participate in the EU–US Data Privacy Framework. The transfer is based on the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, incorporated into the data processing addendum used by that provider.
If the adequacy decision ceases to apply, or the provider stops relying on it, the standard contractual clauses remain the basis for the transfer, together with additional technical, organizational, or contractual measures.
Information about the mechanism applied in a specific case and the possibility of obtaining a copy of the safeguards used can be obtained by contacting: gdpr@LabLogic.pl
13. Voluntariness of providing data
The provision of data is voluntary.
However, providing information marked as required in the form is necessary to send the form, identify who is submitting the inquiry, assess the expected scope of support, and prepare and provide a response. Failure to provide the required data may prevent sending the form or proper handling of the inquiry.
The provision of data necessary for the conclusion and performance of a contract is voluntary, but its absence may prevent the initiation or implementation of cooperation.
Consent to analytical and other optional cookies is voluntary. Refusal does not restrict access to the basic content of the website or the ability to send an inquiry.
14. Rights of individuals
In cases specified in the GDPR, the data subject has the right to:
- obtain confirmation as to whether their data is being processed;
- access data and receive a copy thereof;
- rectify inaccurate data;
- complete incomplete data;
- erase data;
- restrict processing;
- data portability, if processing is based on consent or a contract and carried out by automated means;
- object to processing based on Art. 6(1)(f) GDPR;
- withdraw consent at any time;
- lodge a complaint with the President of the Personal Data Protection Office.
These rights are not absolute. Their exercise depends on the circumstances, legal basis, and applicable regulations. Further processing may be necessary, in particular, for compliance with a legal obligation or for the establishment, exercise, or defense of legal claims.
Requests regarding the exercise of rights can be sent to: gdpr@LabLogic.pl
The Controller may request information necessary to confirm the identity of the person submitting the request.
The Controller responds to requests without undue delay, generally no later than within one month. In cases provided for in the GDPR, this period may be extended, of which the person will be informed along with the reason.
15. Right to object
If data is processed on the basis of a legitimate interest, the individual may object at any time on grounds relating to their particular situation.
Upon receipt of an objection, the Controller shall cease processing the data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the individual, or for the establishment, exercise, or defense of legal claims.
16. Automated decision-making
The Controller does not make decisions concerning users based solely on automated processing, including profiling, which would produce legal effects concerning them or similarly significantly affect them.
The automatic anti-spam check on the form serves solely to tell a human submission from an automated one. It may result in the rejection of an automated submission, but it is not used to make decisions regarding the conclusion or performance of a contract.
17. Data security
The Controller applies technical and organizational measures adapted to the nature of the data, the scope of processing, and the identified risk, including in particular:
- transmission encryption;
- access control;
- authentication mechanisms;
- software updates;
- backup creation;
- protection against malicious traffic and unauthorized access attempts;
- restricting data access to persons who need it to perform specific tasks;
- analyzing and handling security incidents.
Passwords, access codes, cryptographic keys, special categories of personal data, full incident or breach documentation, or confidential organizational files should not be sent via the general contact form.
If the matter requires the transfer of such materials, an appropriate and secure communication channel should first be agreed upon with LabLogic.
18. Policy changes
The policy may be updated, particularly in the event of changes to:
- legal provisions;
- scope or purpose of processing;
- website operation method;
- services and providers used;
- security, statistics, or cookie settings.
The current version of the policy is published on this page along with its effective date.
The Controller may additionally inform about significant changes via a message on the website or another appropriate channel.
This document is version 1.2, in force since 13 September 2026. It replaces version 1.1 of the same day and version 1.0, which was in force from 1 August 2026.
In force since
September 13, 2026