SMARTER LAB PRIVACY POLICY
§ 1. DEFINITIONS
- Controller – Arkadiusz Janik, a sole trader conducting business under the business name Smarter Arkadiusz Janik and using the Smarter Lab brand, ul. Żelazna 51/53, 00-841 Warsaw, Poland, Tax Identification No. (NIP) PL7342950754, to the extent that he determines the purposes and means of the processing of personal data.
- Policy – this Privacy Policy.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
- Website – the Smarter Lab website available at https://smarterlab.app.
- User – a person using the Website.
§ 2. CONTROLLER AND SCOPE OF THE POLICY
- The controller of personal data processed in connection with the Website is Arkadiusz Janik, a sole trader conducting business under the business name Smarter Arkadiusz Janik, ul. Żelazna 51/53, 00-841 Warsaw, Poland, Tax Identification No. (NIP) PL7342950754.
- For matters concerning personal data protection, the Controller may be contacted in writing at the address indicated above or via the contact form available at https://smarterlab.app/
#contact . - This Policy describes the rules governing the processing of personal data in connection with use of the Website, in particular the contact form, the Website’s technical infrastructure and tools used for security and statistics.
§ 3. DATA WE PROCESS
3.1. Contact form
- If a User uses the contact form, the Controller processes the data provided in the form, in particular the User’s name, email address and the content of the message.
- In connection with submission of the form, technical data necessary to deliver and secure it may also be processed, in particular the IP address, browser and device information, and data used to detect abuse and automated submissions.
- The scope of the data depends on the content of the message. The User should not provide data that is not necessary to handle their matter.
3.2. Technical data and Website logs
- When the Website is used, the Controller or infrastructure providers may process technical data relating to the connection and use of the Website, in particular the IP address, browser type and version, device information, the date and time of the request, the requested resource, and data concerning connection security.
- This data is used to provide the Website, ensure its security, diagnose errors and protect against abuse.
3.3. Website usage statistics
- The Website uses Plausible Analytics in a configuration that does not use cookies to track Users. The tool is used to generate aggregate statistics concerning use of the Website.
- The Controller does not use Plausible Analytics to profile Users or track their activity across different websites.
§ 4. PURPOSES AND LEGAL BASES OF PROCESSING
| Purpose of processing | Legal basis |
|---|---|
| Handling the contact form, correspondence and enquiries | Article 6(1)(f) GDPR – the Controller’s legitimate interest in conducting communications and handling enquiries |
| Ensuring the operation, security and diagnostics of the Website and preventing abuse | Article 6(1)(f) GDPR – the Controller’s legitimate interest in ensuring the security, availability and proper operation of the Website and protecting it against abuse |
| Preparing aggregated statistics on the use of the Website | Article 6(1)(f) GDPR – the Controller’s legitimate interest in analysing how the Website is used and developing the Website |
| Compliance with obligations arising from applicable law | Article 6(1)(c) GDPR – compliance with a legal obligation to which the Controller is subject |
| Establishment, exercise or defence of legal claims | Article 6(1)(f) GDPR – the Controller’s legitimate interest in protecting its rights |
§ 5. DATA RECIPIENTS AND WEBSITE SERVICE PROVIDERS
- To the extent necessary for operation of the Website, data may be processed by service providers used by the Controller, in particular:
- OVH – Website hosting and related technical logs;
- Bunny.net / BunnyWay d.o.o. – CDN, DNS, security and traffic protection;
- Formspark / Trampoline Software SRL (Belgium) – handling and delivery of contact-form submissions;
- Google Workspace / Gmail – handling email and correspondence;
- Plausible Analytics – aggregate Website usage statistics.
- Service providers may act as processors on behalf of the Controller or, where this follows from the nature of a particular service, as independent controllers. The applicable rules of processing may also arise from the terms and privacy policies of those entities.
- Data may also be disclosed to professional advisers, in particular law firms or accounting service providers, as well as to public authorities and other entities entitled to receive data under applicable law.
§ 6. TRANSFERS OF DATA OUTSIDE THE EEA
- Some service providers process personal data outside the European Economic Area or use infrastructure that permits such processing. This applies in particular to Google Workspace, within which data may also be processed by entities and infrastructure located outside the EEA. Contact-form submissions are processed by Formspark on infrastructure located within the European Economic Area (Ireland and Germany).
- Where the Controller is responsible for a transfer of data outside the EEA, the transfer is carried out in accordance with Chapter V GDPR, in particular on the basis of a European Commission adequacy decision or using appropriate safeguards such as Standard Contractual Clauses. Information on the mechanism applicable to a specific transfer may be obtained by contacting the Controller.
§ 7. DATA RETENTION PERIODS
- Correspondence and data provided through the contact form are retained for the period necessary to handle the matter and conduct related correspondence and thereafter, where justified, for the period necessary to protect against claims, as a rule no longer than 3 years after the matter is closed, unless a longer period is required by law or by the nature of the specific relationship.
- Technical data and Website logs are retained for the period necessary to ensure the operation, security and diagnostics of the Website, in accordance with the configuration and retention rules of the relevant infrastructure providers.
- Statistical data is retained in accordance with the configuration of Plausible Analytics in aggregate form, to the extent that the Controller does not need to identify the User.
- Data processed for the establishment, exercise or defence of legal claims may be retained until expiry of the applicable limitation period or final completion of proceedings, if proceedings have been initiated.
§ 8. COOKIES AND SIMILAR TECHNOLOGIES
- The Website does not use cookies or similar technologies for marketing or advertising purposes or to track Users across different websites.
- The Website uses Plausible Analytics in a configuration that does not use cookies to track Users.
- In connection with operation of the contact form and protection against spam, hCaptcha or other security mechanisms may use cookies or similar technologies necessary for the proper operation and security of the form.
- Storing information on the User’s device or accessing information already stored on it, where necessary to transmit a communication or provide a service requested by the User, takes place without prior consent to the extent permitted by applicable law. Other technologies requiring consent will be activated only after consent has been obtained.
- If the Website begins to use analytics technologies requiring consent, or marketing or advertising technologies in the future, the User will be appropriately informed and any consent mechanisms required by law will be implemented before such technologies are activated.
- The User may manage cookies through browser settings; however, restricting technologies necessary for operation of the Website may affect the operation of some Website functions.
§ 9. RIGHTS OF DATA SUBJECTS
- Subject to the conditions set out in the GDPR, the data subject has the rights of access, rectification, erasure, restriction of processing, data portability and the right to object to processing based on Article 6(1)(f) GDPR.
- Where processing is based on consent, the data subject may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
- The data subject has the right to lodge a complaint with the competent supervisory authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office.
§ 10. PROVISION OF DATA AND AUTOMATED DECISIONS
- Providing data through the contact form is voluntary; however, providing an email address and the content of the message is necessary to receive a reply through this channel.
- The Controller does not use personal data processed in connection with the Website to make decisions concerning the User based solely on automated processing that produce legal effects or similarly significantly affect the User.
§ 11. DATA SECURITY
- The Controller applies appropriate technical and organisational measures to protect personal data, taking into account the nature of the data, the scope of processing and the related risk.
- The Website uses infrastructure and security solutions, including hosting services, a CDN and protection of the contact form against spam and automated submissions.
§ 12. CHANGES TO THE POLICY AND CONTACT
- This Policy may be updated in particular in connection with changes to Website functionality, service providers used, applicable law or the manner in which personal data is processed.
- The current version of the Policy is published on the Website. If a change involves a material change in the manner in which personal data is processed, the Controller will provide appropriate information to the extent and in the form required by law.
- For matters concerning this Policy or the processing of personal data, the Controller may be contacted in writing at ul. Żelazna 51/53, 00-841 Warsaw, Poland or via the contact form available at https://smarterlab.app/
#contact . - This Policy is effective from 6 September 2026.