Privacy and Cookies Policy
Last update: 2026-03-27
1. Personal Data Controller
The personal data controller is:
UKF CONSULTING Karolina Myszkiewicz
address: ul. gen. Józefa Zajączka, nr 9b, lok. U6, 01-518 Warszawa, Polska
Tax ID (NIP/KRS): 5252421123
Contact for matters related to data protection: prywatnosc@ukfconsulting.pl
The Controller processes data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the Act of July 12, 2024 – Electronic Communications Law (PKE).
2. Purposes and Legal Bases for Processing
We process personal data for the following purposes:
| Purpose of processing | Legal basis (GDPR) | Description |
|---|---|---|
| Handling inquiries via form, email or phone call | Art. 6(1)(f) | Legitimate interest – providing a response to the inquiry and communication with the user. |
| Security and protection against bots | Art. 6(1)(f) | Legitimate interest – protecting infrastructure against attacks and spam (Cloudflare Turnstile). |
| Hosting and content delivery | Art. 6(1)(f) | Legitimate interest – ensuring the technical functioning of the website (Firebase Hosting). |
| Direct marketing | Art. 6(1)(a) | Voluntary consent of the user (if granted) in accordance with Art. 398 PKE. |
3. Scope of Processed Data
Processed data may include: first and last name, e-mail address, phone number (in case of a phone call), message content, IP address, and technical data of the device and browser (User-Agent). This data is necessary for the technical handling of your inquiry and for securing the site against abuse.
4. Data Recipients and Transfer Outside the EEA
To provide our services, we use trusted providers:
-
Cloudflare, Inc.: Bot protection system (Turnstile). Technical data is processed for traffic verification.
-
Google Ireland Ltd. / Google LLC: Provider of hosting services (Firebase) and electronic mail (Workspace).
-
Resend, Inc.: Infrastructure provider for sending e-mail messages from the form.
Transfer to the USA: The indicated providers are certified under the EU-U.S. Data Privacy Framework, which ensures a level of data protection recognized by the European Commission as adequate (Art. 45 GDPR).
5. Data Retention Period
-
Form inquiries: For the duration of the communication and up to 2 years after its conclusion for the purpose of securing potential claims.
-
Security logs (IP): For the period necessary to analyze incidents (usually up to 90 days).
-
Marketing data: Until you withdraw your consent.
6. Rights of the Data Subject
In accordance with the GDPR, you have the right to:
-
Access your data and receive a copy thereof.
-
Rectify (correct) your data.
-
Delete data ("the right to be forgotten").
-
Restrict data processing.
-
Object to processing (when the basis is a legitimate interest).
-
Data portability – this right applies only to data processed on the basis of consent (marketing) or a contract, in an automated manner.
-
Withdraw consent at any time (if processing is based on consent) without affecting the lawfulness of processing based on consent before its withdrawal.
-
Lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw).
7. Voluntary Nature of Providing Data
Providing personal data in the contact form is voluntary, but necessary to provide a response to your inquiry. Failure to provide data will make it impossible for us to establish contact and handle the submitted message.
8. Automated Decision-Making and Profiling
As part of the form protection, we use the Cloudflare Turnstile service, which performs an automated analysis of device signals and the IP address to classify the user as a human or a bot.
-
This processing is carried out in an automated manner, but it does not constitute profiling within the meaning of Art. 22 GDPR and does not produce legal effects concerning you or similarly significantly affect you.
-
The purpose of this operation is exclusively to ensure site security and protection against spam.
9. Cookies
The website uses exclusively technical and necessary cookies.
| Cookie name | Provider | Purpose | Validity |
|---|---|---|---|
| cf_clearance / __cf_bm | Cloudflare | Bot protection and security verification. | Up to 12 months |
The use of these files is permissible without separate consent based on Art. 399(3)(2) PKE, as they are necessary to ensure security and the proper operation of the service requested by the user (protection against spam and attacks).
10. Marketing Consents (PKE)
All marketing communication by electronic means (e-mail) takes place exclusively on the basis of your voluntary and prior consent, in accordance with Art. 398 PKE.


