Privacy policy
How we handle personal data, why we need it and how you can exercise your rights.
Controller and contact
The controller is Memsec Karol Boguski, trading as CyberON IT, Polish tax ID 7582372328, Grzybowska 87, 00-844 Warsaw, Poland. For data protection enquiries, contact kontakt@cyberon.it or +48 517 745 477.
This policy covers our B2B website and enquiries. Processing personal data as part of client services is governed separately by the relevant agreements.
Enquiries and proposals
We use the information you provide in correspondence: your name, email address, message and, optionally, phone number and topic. We need it to respond and discuss a possible engagement. Do not send passwords, special-category personal data or confidential client information.
The basis is GDPR Article 6(1)(b) when taking steps at your request before entering into a contract. For company representatives and general correspondence, it is Article 6(1)(f): our legitimate interest in handling enquiries and business communications. Providing data is voluntary, but we need contact details and a description to respond.
The form sends your message through our server to kontakt@cyberon.it, hosted in Microsoft 365. You do not need to open an email application. We do not send message contents or contact details to analytics or advertising pixels.
Security, analytics and marketing
When you visit, the infrastructure may record your IP address, time, requested resource, response status and browser information. This supports operation and abuse detection under GDPR Article 6(1)(f), our legitimate interest in protecting the website.
With analytics consent, Google Analytics and Microsoft Clarity may process pages visited, interactions, device and browser information. With marketing consent, Meta Pixel, LinkedIn Insight Tag and Google advertising measurement tools may process visits and events for campaign measurement and advertising audiences. These tools use cookies or similar device storage; providers may receive your IP address. Optional processing is based on your voluntary consent. Refusal does not restrict the website or contact options.
A newsletter is planned, but subscriptions are not yet available. It will require separate consent to data processing under GDPR Article 6(1)(a) and to commercial communications under Article 398 of Polish Electronic Communications Law. Sending an enquiry does not subscribe you to a newsletter.
Recipients and processing outside the EEA
We use infrastructure in Poland or the EU and Microsoft 365 email. Recipients may include infrastructure and email providers, authorised people handling correspondence, advisers assisting with claims and legally authorised authorities. We plan to self-host CRM and newsletter systems; the specific software has not yet been selected.
Hosting location does not mean every provider processes data exclusively in the EEA. Microsoft documents exceptions to its EU Data Boundary. Transfers outside the EEA require applicable GDPR Chapter V safeguards, such as an adequacy decision within its scope or standard contractual clauses. Contact us for information about applicable safeguards and a copy.
After consent to the relevant category, Google, Microsoft, Meta and LinkedIn may receive website usage data as providers of the listed tools. We do not send them contact details or form contents. Their services may involve processing outside the EEA; their privacy policies describe their data protection practices and rights you can exercise with them.
Retention periods
The retention period for correspondence depends on the matter: handling enquiries and negotiations, the duration of our engagement, and the needs of delivering, supporting and settling a project. We retain the history of agreed arrangements while it is needed for these purposes, including long-term engagements. For enquiries that do not lead to an engagement, the criteria are the end of discussions and the end of the need to handle that matter; any subsequent retention of necessary evidence follows the rules below.
Our agreed retention period for ordinary technical logs is 30 days; future newsletter data will be retained until consent is withdrawn or the newsletter ends. Technical enforcement of these periods remains to be verified before the website is published.
Records needed for statutory accounting and tax obligations are retained for the applicable legal periods under GDPR Article 6(1)(c). Data necessary to establish, pursue or defend claims may be retained until the matter ends or the applicable limitation period expires under Article 6(1)(f). This does not justify keeping all CRM data indefinitely.
Your rights
Subject to GDPR conditions, you may request access, rectification, erasure, restriction and portability. You may object to processing based on legitimate interests and may object to direct marketing at any time. You may withdraw consent without affecting the lawfulness of processing before withdrawal.
Email kontakt@cyberon.it. We normally respond within one month; a permitted GDPR extension will be explained to you. You may complain to Poland’s President of the Personal Data Protection Office (uodo.gov.pl) or the competent supervisory authority in the EU.
The enquiry handling described here does not involve solely automated decisions producing legal or similarly significant effects.