← Home

Privacy Policy

Last updated: 14 August 2026

1. Data controller

The controller of your personal data is CZ Cybersecurity sp. z o.o., with its registered office in Warsaw, ul. Wielicka 40 lok. U1, 02-657 Warszawa, entered in the Register of Entrepreneurs of the National Court Register (KRS) under number KRS: 0000527250, NIP: 1132881297, REGON: 147469817.

Recipients of the data may only be entities processing data on the controller's behalf: the hosting provider and the email service provider, to the extent necessary for the operation of the website and delivery of correspondence. Recipients of data processed for postal marketing are listed in section 10.4.

A separate recipient is Statistics Poland (Główny Urząd Statystyczny, GUS). Using the NIP lookup on the KSC/NIS2 page transmits the number you enter to the REGON register's business search service (BIR, wyszukiwarkaregon.stat.gov.pl), which returns the entity's registry data. In that exchange GUS acts as a separate controller, not as a processor on our behalf. For a sole trader, the NIP and the returned registry data are personal data. The lookup is optional, and the NIP is not stored on the czcyber.pl side.

2. Purpose of data processing

Your personal data is processed for the following purposes:

2.1. Categories of data processed

3. Legal basis for processing

Personal data is processed on the basis of:

Providing data is voluntary but necessary to use the relevant form. Without an email address we cannot answer an enquiry, send the self-assessment report or confirm a booking. Not providing data has no other consequences.

4. Data retention period

Your personal data will be stored:

Where the above periods overlap, the period that expires first applies, unless further storage is necessary due to the controller's legal obligations.

5. Rights of the data subject

Under the GDPR you have the following rights, in the cases and on the terms set out in the GDPR:

  1. Right of access, that is, the right to obtain information on whether your personal data is being processed and to obtain a copy of the data (Article 15 GDPR).
  2. Right to rectification of inaccurate data or completion of incomplete data (Article 16 GDPR).
  3. Right to erasure of personal data (the "right to be forgotten") in the cases set out in Article 17 GDPR.
  4. Right to restriction of processing in the cases set out in Article 18 GDPR.
  5. Right to data portability in a structured, commonly used, machine-readable format (Article 20 GDPR).
  6. Right to object to processing based on the controller's legitimate interest (Article 21 GDPR).
  7. Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

6. Contact regarding personal data

For matters relating to the processing of personal data, please contact us:

We will respond to your request without undue delay and no later than one month from receipt of the request.

7. Right to lodge a complaint with the supervisory authority

If you consider that the processing of your personal data infringes the provisions of the GDPR, you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO):

8. Automated decision-making and profiling

The controller does not use automated decision-making, including profiling, as referred to in Article 22(1) and (4) GDPR, in relation to personal data collected via the contact form.

The CRA readiness check available on this site generates its result using simple, transparent rules (the average of the user's answers). The result is indicative and informational only, produces no legal effects on the user or similarly significant impact, and does not constitute a decision within the meaning of Article 22 GDPR.

9. Transfers of data to third countries

Your personal data is not transferred to third countries (outside the European Economic Area) or to international organisations.

10. Direct marketing and postal correspondence

CZ Cybersecurity sp. z o.o. may send postal correspondence about its own services to entrepreneurs, healthcare providers, professional practices and the people holding business roles in them, where the addressee's line of work indicates that the service presented may be professionally relevant to them.

Postal correspondence does not constitute consent to marketing by e-mail, telephone, messaging application or any other telecommunications terminal equipment. Those channels are used for marketing only where the required consent has been obtained, or where the recipient initiated the contact.

10.1. Sources of data

Data used for postal correspondence may come only from publicly available sources connected with the addressee's professional activity, in particular:

We do not obtain patient data, medical records, health data or any other special category of personal data for this purpose.

10.2. Purpose, legal basis and legitimate interest

The purpose is a single or limited presentation, by post, of our own B2B services, together with handling any reply, objection or business relationship that follows.

The legal basis is Article 6(1)(f) GDPR. The controller's legitimate interest is direct marketing of its own services, in line with recital 47 GDPR. Before a campaign begins, the controller assesses the necessity and proportionality of using the data, the reasonable expectations of the addressees, and the risk of interference with their privacy.

10.3. Categories of data

The following may be processed:

10.4. Recipients of the data

Data may be passed only to entities supporting the controller in preparing and delivering the correspondence, such as the postal operator, a printing or hybrid-mail provider, and IT service providers. Entities processing data on the controller's behalf act under agreements compliant with Article 28 GDPR.

We do not make the data available to other entities for their own marketing. We do not transfer the data outside the European Economic Area.

10.5. Retention period

Data used in a given postal campaign is kept until an objection is raised, until the campaign ends, or for a maximum of 6 months from dispatch, whichever comes first.

If the addressee replies to the letter, or a contract is concluded, the data may be processed further on the appropriate basis and for the period proper to the correspondence, the performance of the contract, legal obligations or the defence of claims.

Once an objection is raised the data is removed from the marketing database. A minimal set of data may remain in the objection register for the sole purpose of preventing marketing from being directed at that person or entity again.

10.6. Data subject rights and objection to marketing

The data subject has the rights of access, rectification, erasure and restriction of processing, as well as the right to lodge a complaint with the President of the Personal Data Protection Office.

The data subject has an unconditional right, at any time and free of charge, to object to the processing of their data for direct marketing purposes (Article 21(2) GDPR). Once an objection is received we do not use the data for that purpose.

An objection can be raised:

  • using the form below,
  • by e-mail to [email protected] with the subject line "SPRZECIW",
  • by post to: CZ Cybersecurity sp. z o.o., ul. Wielicka 40 lok. U1, 02-657 Warszawa, Poland.

10.7. Profiling and automated decisions

In connection with postal correspondence we do not use profiling or automated decision-making that produces legal effects concerning the addressee or similarly significantly affects them.

11. Objection form

Data from this form goes into an objection register kept by CZ Cybersecurity sp. z o.o. and is held there indefinitely, for the sole purpose of ensuring that correspondence is not sent again. Basis: Article 21(3) GDPR. Providing an email address is optional and serves only to confirm that the objection was received.

If you do not wish to receive marketing correspondence from us, please complete the form below.

12. Cookies, browser storage and third-party tools

This website does not use cookies. It starts no server-side session, stores no identifier in the browser and uses no tracking tools: there is no analytics, no tag manager, no advertising pixel and no social plugin. That is why the site shows no cookie consent banner: there is nothing to consent to.

Every resource, including the typeface, is served from czcyber.pl. Opening the site does not connect you to any third-party server.

The only browser-side storage concerns the CRA readiness check: your progress and answers are kept in the browser's session storage (sessionStorage) so that refreshing the page does not wipe a part-filled form. That data never leaves your device, carries no user identifier and is discarded when the tab closes. It is storage strictly necessary to provide a service you explicitly requested, within the meaning of art. 399(3) of the Polish Electronic Communications Law, and requires no consent.

Separately, the hosting server keeps standard access logs, which include the IP address and the time of the request. They serve only to keep the service secure and working correctly.