Privacy Policy
Last updated: 14 August 2026
1. Data controller
The controller of your personal data is CZ Cybersecurity sp. z o.o., with its registered office in Warsaw, ul. Wielicka 40 lok. U1, 02-657 Warszawa, entered in the Register of Entrepreneurs of the National Court Register (KRS) under number KRS: 0000527250, NIP: 1132881297, REGON: 147469817.
Recipients of the data may only be entities processing data on the controller's behalf: the hosting provider and the email service provider, to the extent necessary for the operation of the website and delivery of correspondence. Recipients of data processed for postal marketing are listed in section 10.4.
A separate recipient is Statistics Poland (Główny Urząd Statystyczny, GUS). Using the NIP lookup on the KSC/NIS2 page transmits the number you enter to the REGON register's business search service (BIR, wyszukiwarkaregon.stat.gov.pl), which returns the entity's registry data. In that exchange GUS acts as a separate controller, not as a processor on our behalf. For a sole trader, the NIP and the returned registry data are personal data. The lookup is optional, and the NIP is not stored on the czcyber.pl side.
2. Purpose of data processing
Your personal data is processed for the following purposes:
- Responding to an enquiry submitted via the contact form on czcyber.pl.
- Establishing business contact in connection with the services provided by CZ Cybersecurity sp. z o.o.
- Initial assessment of an entity's status in the context of the Act on the National Cybersecurity System.
- Providing an interactive CRA readiness self-assessment (the CRA readiness check). Answers to the self-assessment questions are processed solely in the user's browser and are not sent to the server unless the user submits the form requesting the report.
- Sending the CRA self-assessment result and report requested by the user to the email address provided.
- Sending commercial information about our own services by electronic means, solely upon separate, voluntary consent (art. 398 of the Polish Electronic Communications Law).
- Scheduling a meeting through the booking form on the Meeting page, including the confirmation message, the reminder about the slot, and sending the proposal concerning the matter discussed at the meeting.
- Receiving and handing over files as part of delivering the service: material sent by a client through the file drop, and files made available to a client through a one-time link.
- Keeping the website secure and available, including limiting the number of submissions from one IP address and preventing form abuse.
- Handling objections to direct marketing and maintaining the objection register (section 11).
2.1. Categories of data processed
- Contact form: name, email address, telephone, company name, subject and message. A submission from the KSC qualifier additionally carries the entity name, the PKD code and the preliminary sector, as returned by the REGON register.
- CRA readiness check report form: email address, optionally name and company, and the answers given in the self-assessment together with the calculated result. The answers reach the server only when the report is requested, and the result is then recalculated server-side.
- Meeting booking form: name, email address, telephone, company name and the chosen slot. The booking record additionally stores whether the optional consent to commercial information was ticked, together with the version of that consent wording in force when it was given.
- File drop: the client name attached to the access code, the IP address the upload came from, timestamps, and the number, sizes and names of the files sent. The access code is stored only as a cryptographic hash, never in the clear. File contents are encrypted on arrival to a public key, and the private key is not held on the server, so reading them on our side is not possible.
- One-time download links: the hash of the link, the name and size of the file shared, the expiry date, the number of download attempts, and the IP address and time of a completed download.
- Objection form: company name, KRS or NIP number and, optionally, an email address.
- IP address. The address a form was sent from is recorded in the message delivered to the controller, is used to limit the number of submissions, and is stored in the booking record until the booking is confirmed. For the submission counter the address is not stored in the clear but as a hash used as a filename; a hash of an IPv4 address should not, however, be treated as durable anonymisation.
3. Legal basis for processing
Personal data is processed on the basis of:
Article 6(1)(a) GDPR, the consent of the data subject given by ticking the relevant box in the contact form, in the CRA readiness check report form (consent to receive the report), or in the commercial-information consent field.Article 6(1)(f) GDPR, the legitimate interest of the controller in responding to enquiries and conducting business correspondence.- For sending commercial information by electronic means, the basis is a separate consent referred to in
art. 398 of the Polish Electronic Communications Law of 12 July 2024. This consent can be withdrawn at any time, e.g. by email. Article 6(1)(b) GDPR, performance of a contract, for receiving and handing over files connected with the service, andArticle 6(1)(f) GDPR, the legitimate interest in preventing abuse, for the IP address, the failed-code counter and the upload audit trail.- Personal data contained in files sent by a client is processed by us as a processor within the meaning of
Article 4(8) GDPR, only on the documented instructions of the client and under a separate data processing agreement concluded in line withArticle 28(3) GDPR. The client remains the controller of that data. Article 6(1)(b) GDPR, steps taken at the request of the data subject prior to entering into a contract, for booking a meeting slot and for sending the proposal concerning the matter discussed at the meeting. Booking requires no consent and none is collected: providing an email address in the booking form in order to receive the confirmation and the proposal discussed corresponds toart. 398(2) of the Electronic Communications Law. Commercial information about the remaining services is sent only where a separate, optional consent box has been ticked.Article 6(1)(f) GDPR, the legitimate interest of the controller in keeping the website secure and available and in preventing form abuse, for the processing of IP addresses.Article 6(1)(c) GDPR, a legal obligation of the controller arising fromArticle 21(3) GDPR, for maintaining the objection register that ensures correspondence is not sent again.
Providing data is voluntary but necessary to use the relevant form. Without an email address we cannot answer an enquiry, send the self-assessment report or confirm a booking. Not providing data has no other consequences.
4. Data retention period
Your personal data will be stored:
- Until consent to processing is withdrawn, where processing is based on consent.
- Until the correspondence is concluded and the purpose for which the data was collected is fulfilled.
- For no longer than 24 months from the date the form was submitted, unless further processing is necessary due to the controller's legal obligations.
- Data submitted in the CRA readiness check report form (without the commercial-information consent): no longer than 6 months from submission. Where the commercial-information consent was given: until it is withdrawn.
- An archive sent through the file drop: until the controller collects it, and at most 14 days from the upload. An upload started and not finished: 2 hours. The upload audit trail, without file contents: 90 days.
- A file shared through a one-time link: until the client downloads it, and at most 7 days from sharing.
- Meeting booking record: 7 days from creation where the booking was not confirmed or has lapsed, and 90 days from creation where it was confirmed. The IP address in the record is removed once the booking is confirmed. Where the consent to commercial information was ticked, the email address and the record of that consent are kept until it is withdrawn.
- Submission-counter data used to limit sending from one IP address: no longer than a few hours from the last submission. The counter files are then deleted.
- Objection register for direct marketing: indefinitely. Deleting an entry would reverse the effect of the objection, because the data would re-enter the database the next time it is drawn from public registers. The register holds only what is needed to recognise the entity and is not used for any other purpose.
Where the above periods overlap, the period that expires first applies, unless further storage is necessary due to the controller's legal obligations.
5. Rights of the data subject
Under the GDPR you have the following rights, in the cases and on the terms set out in the GDPR:
- Right of access, that is, the right to obtain information on whether your personal data is being processed and to obtain a copy of the data (
Article 15 GDPR). - Right to rectification of inaccurate data or completion of incomplete data (
Article 16 GDPR). - Right to erasure of personal data (the "right to be forgotten") in the cases set out in
Article 17 GDPR. - Right to restriction of processing in the cases set out in
Article 18 GDPR. - Right to data portability in a structured, commonly used, machine-readable format (
Article 20 GDPR). - Right to object to processing based on the controller's legitimate interest (
Article 21 GDPR). - Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
6. Contact regarding personal data
For matters relating to the processing of personal data, please contact us:
- E-mail: [email protected]
- Postal address: CZ Cybersecurity sp. z o.o., ul. Wielicka 40 lok. U1, 02-657 Warszawa.
We will respond to your request without undue delay and no later than one month from receipt of the request.
7. Right to lodge a complaint with the supervisory authority
If you consider that the processing of your personal data infringes the provisions of the GDPR, you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO):
- Urząd Ochrony Danych Osobowych
- ul. Stanisława Moniuszki 1A, 00-014 Warszawa
- Website: uodo.gov.pl
8. Automated decision-making and profiling
The controller does not use automated decision-making, including profiling, as referred to in Article 22(1) and (4) GDPR, in relation to personal data collected via the contact form.
The CRA readiness check available on this site generates its result using simple, transparent rules (the average of the user's answers). The result is indicative and informational only, produces no legal effects on the user or similarly significant impact, and does not constitute a decision within the meaning of Article 22 GDPR.
9. Transfers of data to third countries
Your personal data is not transferred to third countries (outside the European Economic Area) or to international organisations.
10. Direct marketing and postal correspondence
CZ Cybersecurity sp. z o.o. may send postal correspondence about its own services to entrepreneurs, healthcare providers, professional practices and the people holding business roles in them, where the addressee's line of work indicates that the service presented may be professionally relevant to them.
Postal correspondence does not constitute consent to marketing by e-mail, telephone, messaging application or any other telecommunications terminal equipment. Those channels are used for marketing only where the required consent has been obtained, or where the recipient initiated the contact.
10.1. Sources of data
Data used for postal correspondence may come only from publicly available sources connected with the addressee's professional activity, in particular:
- the National Court Register (KRS),
- the Central Registration and Information on Business (CEIDG),
- the Register of Entities Performing Medical Activity (RPWDL),
- the addressee's official website,
- a publicly available vendor page or industry directory, where it carries business contact details published in connection with the addressee's activity.
We do not obtain patient data, medical records, health data or any other special category of personal data for this purpose.
10.2. Purpose, legal basis and legitimate interest
The purpose is a single or limited presentation, by post, of our own B2B services, together with handling any reply, objection or business relationship that follows.
The legal basis is Article 6(1)(f) GDPR. The controller's legitimate interest is direct marketing of its own services, in line with recital 47 GDPR. Before a campaign begins, the controller assesses the necessity and proportionality of using the data, the reasonable expectations of the addressees, and the risk of interference with their privacy.
10.3. Categories of data
The following may be processed:
- name,
- business role or position,
- name of the entity or practice,
- business or registered correspondence address,
- the entity's public registry identifiers,
- the source and date the data was obtained,
- the fact that an objection was raised.
10.4. Recipients of the data
Data may be passed only to entities supporting the controller in preparing and delivering the correspondence, such as the postal operator, a printing or hybrid-mail provider, and IT service providers. Entities processing data on the controller's behalf act under agreements compliant with Article 28 GDPR.
We do not make the data available to other entities for their own marketing. We do not transfer the data outside the European Economic Area.
10.5. Retention period
Data used in a given postal campaign is kept until an objection is raised, until the campaign ends, or for a maximum of 6 months from dispatch, whichever comes first.
If the addressee replies to the letter, or a contract is concluded, the data may be processed further on the appropriate basis and for the period proper to the correspondence, the performance of the contract, legal obligations or the defence of claims.
Once an objection is raised the data is removed from the marketing database. A minimal set of data may remain in the objection register for the sole purpose of preventing marketing from being directed at that person or entity again.
10.6. Data subject rights and objection to marketing
The data subject has the rights of access, rectification, erasure and restriction of processing, as well as the right to lodge a complaint with the President of the Personal Data Protection Office.
The data subject has an unconditional right, at any time and free of charge, to object to the processing of their data for direct marketing purposes (Article 21(2) GDPR). Once an objection is received we do not use the data for that purpose.
An objection can be raised:
- using the form below,
- by e-mail to [email protected] with the subject line "SPRZECIW",
- by post to: CZ Cybersecurity sp. z o.o., ul. Wielicka 40 lok. U1, 02-657 Warszawa, Poland.
10.7. Profiling and automated decisions
In connection with postal correspondence we do not use profiling or automated decision-making that produces legal effects concerning the addressee or similarly significantly affects them.
11. Objection form
Data from this form goes into an objection register kept by CZ Cybersecurity sp. z o.o. and is held there indefinitely, for the sole purpose of ensuring that correspondence is not sent again. Basis: Article 21(3) GDPR. Providing an email address is optional and serves only to confirm that the objection was received.
If you do not wish to receive marketing correspondence from us, please complete the form below.
12. Cookies, browser storage and third-party tools
This website does not use cookies. It starts no server-side session, stores no identifier in the browser and uses no tracking tools: there is no analytics, no tag manager, no advertising pixel and no social plugin. That is why the site shows no cookie consent banner: there is nothing to consent to.
Every resource, including the typeface, is served from czcyber.pl. Opening the site does not connect you to any third-party server.
The only browser-side storage concerns the CRA readiness check: your progress and answers are kept in the browser's session storage (sessionStorage) so that refreshing the page does not wipe a part-filled form. That data never leaves your device, carries no user identifier and is discarded when the tab closes. It is storage strictly necessary to provide a service you explicitly requested, within the meaning of art. 399(3) of the Polish Electronic Communications Law, and requires no consent.
Separately, the hosting server keeps standard access logs, which include the IP address and the time of the request. They serve only to keep the service secure and working correctly.