Skip to content
iOchronaSecurity Architect
01

Privacy

Privacy policy

How personal data are handled during the first contact, pre-contract discussions and an agreed engagement.

01

data minimisation

02

sensitive material through an agreed channel

03

human review of each enquiry

04

updated: 25 September 2026

01

Policy

Plain information about personal data.

The Polish legal pages remain the primary reference. This English version is provided for international clients.

01

Children and other individuals

An initial enquiry about a child should come from a parent or legal guardian. A general outline is enough: do not submit the child’s identity, school, address, detailed routine or health information through the form.

Before collecting information needed for the service, I establish its scope, legal basis and access rules and provide the appropriate privacy information. A contract with the client does not automatically provide a sufficient basis to process another person’s data or special-category data.

02

Controller

The controller is Good Solutions House Łukasz Słociak, correspondence address: Kineskopowa 1G/113, 05-500 Piaseczno. Privacy enquiries may be sent to iochrona@icloud.com.

This policy covers data shared through the form, email, phone calls, pre-contract discussions and data needed to prepare, conclude and perform an agreed service.

03

Data collected

Providing personal data is voluntary, but contact details are needed to reply. Any information required for a contract or billing is identified before collection.

For the first contact, a name or short contact name, email or phone number, subject, preferred reply and short outline are sufficient.

A later engagement may involve billing data, contact people, dates, locations, travel, procedures, incidents and agreed actions. Collection is limited to information needed for the assessment or delivery.

Documents, detailed routes, building plans, access data and other sensitive material should be shared only through a channel agreed after the first contact.

04

Purposes and legal bases

Form, email and phone-contact data are used to answer, assess the matter, prepare a proposal and take steps before a contract. The legal basis is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR, depending on the contact.

Data required to deliver and document a service are processed to perform the contract. Accounting and tax data are processed to comply with legal obligations.

Data may also be processed for communication security, abuse prevention, accountability and the establishment, exercise or defence of legal claims, based on legitimate interests.

05

Recipients and providers

Data may be processed by providers needed for the website and communication, including hosting, DNS, Resend API, Apple iCloud, technical maintenance, accounting and legal advisers.

Operational, technical, medical, transport or digital specialists receive data only where their involvement has been agreed and the information is necessary for the task.

Form content is delivered to the contact mailbox without being stored in a local website database.

06

Transfers outside the EEA

Some technology providers may process data outside the European Economic Area. Their contractual safeguards, data-processing agreements and transfer mechanisms apply to those services.

Resend stores account data, metadata, logs and API records in the United States regardless of sending region. Its data processing agreement includes standard contractual clauses. Information on the safeguards and a copy can be requested from the controller at the privacy email above.

A more suitable channel may be agreed for material requiring higher confidentiality.

07

Retention

First-contact enquiries are kept for the period needed to handle correspondence, normally no longer than six months. Offers and pre-contract correspondence may normally be kept for up to 12 months from the last contact, subject to legitimate claim-protection needs.

Resend states that email and log data are retained for 30 days on its Free, Pro and Scale plans. This is separate from retention in the contact mailbox.

Contract, accounting and tax records are retained for the periods required by law. Server logs are limited and rotated. The standard technical-log period is seven days.

08

Rights

Subject to the applicable legal basis, you may request access, a copy, rectification, erasure, restriction, portability or object to processing.

Requests may be sent to iochrona@icloud.com. You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office.

Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal. The form acknowledgement is not marketing consent.

The website does not use automated decision-making that produces legal or similarly significant effects.

09

Security and updates

The form uses validation, rate limits, body-size limits and anti-spam controls. Technical logs omit the content of the form.

This policy may be updated when the technical configuration, providers, services or law changes. Individually agreed NDAs or contracts may provide stronger confidentiality rules.