Legal
Pollatir’s Privacy Policy
Pollatir is a boutique consultancy. Our website exists to tell you who we are and what we do — nothing more. We collect very little, we don’t sell anything to anyone, and we’d rather explain that plainly than bury it in legal language.
Here’s exactly what happens to your data.
Who We Are
Pollatir sp. z o.o. (“Pollatir”, “we”, “us”, “our”) is the data controller for the personal data described in this policy.
- Registered office: ul. Żelazna 51/53, 00-841 Warszawa, Poland
- KRS: 0001077206 · NIP: 5273090482 · REGON: 527260658
- Privacy contact: privacy@pollatir.com
We have not appointed a Data Protection Officer, as we are not required to. Privacy questions go to the email address above and reach a person, not a queue.
What This Policy Covers
This policy covers personal data we handle as a controller: visitors to this website and people who contact us.
It does not cover personal data we process on behalf of clients during an engagement. In that situation the client is the controller and we act as a processor under the terms of a written agreement with them. If you’re a client asking about engagement data, your contract and the data processing agreement attached to it govern — not this page.
What We Collect
When you contact us. Our contact form asks for your name, business email address, and a description of the challenge you’re facing. Please use your work email rather than a personal one. You choose what to put in that last field, and if you reach us by email, LinkedIn, or any other channel, we hold whatever you choose to send.
Automatically, when you visit. Our hosting provider records standard server log data: IP address, browser type and version, the pages you viewed, referring page, and timestamp. This is a by-product of running a website securely.
Analytics. We use Google Analytics to understand which pages people find useful. It sets cookies in your browser and runs only if you accept analytics cookies in our banner — refuse, and it doesn’t load. Google processes this data on our behalf, and this involves transferring it to servers outside the EEA under the safeguards described in Data Leaving Europe below.
We do not collect special category data, we do not run a newsletter, and we do not buy contact lists.
Why We Use It, and On What Legal Basis
| What we do | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Reply to your enquiry and discuss whether we can help | You asked us to | Steps at your request prior to a contract — Art. 6(1)(b); or our legitimate interest in responding to business enquiries — Art. 6(1)(f) |
| Keep a record of the conversation that follows | To manage the relationship and know what was discussed | Legitimate interest in running our business and maintaining accurate records — Art. 6(1)(f) |
| Keep the site available and secure (server logs) | To detect abuse and diagnose faults | Legitimate interest in network and information security — Art. 6(1)(f) |
| Understand how the site is used (analytics) | To improve what we publish | Your consent — Art. 6(1)(a), given through our cookie banner |
| Meet accounting, tax, and other legal duties | We have to | Legal obligation — Art. 6(1)(c) |
Where we rely on consent, you can withdraw it at any time. Withdrawing it doesn’t affect anything we did lawfully before you withdrew.
You aren’t obliged to give us any of this. But if you don’t complete the contact form, we can’t answer your enquiry — that’s the only consequence.
However You Reach Us
However you choose to contact us — the form on this website, email, LinkedIn, WhatsApp, Signal, Microsoft Teams, telephone, SMS, or any other digital or voice channel — this Privacy Policy governs how we handle the personal data you share with us. The channel changes. Our commitments don’t.
Two things are worth knowing.
Third-party platforms have their own rules. When you message us on LinkedIn or WhatsApp, that provider processes your data under its own privacy policy, on its own infrastructure, outside our control. This policy covers what we do with your message once it reaches us — not what the platform does on the way there. If that matters to you, use the contact form or email us directly.
Some channels are less secure than others. Standard email and SMS aren’t end-to-end encrypted. Please don’t send confidential business information, credentials, or sensitive personal data through them. Ask us for a secure channel and we’ll set one up.
Whichever route you take, we use what you send only to respond to you and to manage the relationship that follows. We won’t quietly turn an enquiry into a marketing list.
Cookies and Analytics
Strictly necessary cookies keep the site working and secure. These don’t require your consent.
Everything else — analytics in particular — runs only if you agree via our cookie banner. Refusing is as easy as accepting, and you can change your mind at any time through . Full detail of each cookie, its purpose, and how long it lasts is in our Cookie Policy.
Browser settings alone are not how we obtain consent, and we don’t treat continued browsing as agreement.
Who Else Sees Your Data
We share personal data only with service providers who help us run the business, and only as far as they need it:
- Website hosting and security: Cloudflare, Inc.
- Email and business productivity: Microsoft Corporation (Microsoft 365)
- Contact form delivery: Resend (Plus Five Five, Inc.)
- Analytics: Google Ireland Limited (Google Analytics)
- Professional advisers: accountants and legal counsel, where required
Each is bound by a contract restricting them to our instructions. We also disclose data where the law requires it.
We do not sell your personal data, and we never have.
Data Leaving Europe
Some of those providers are based in the United States. Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision under the EU–US Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses together with supplementary safeguards where it isn’t. Write to privacy@pollatir.com and we’ll tell you which mechanism applies to which provider and give you a copy of the relevant safeguards.
How Long We Keep It
| Data | Retention |
|---|---|
| Enquiries that don’t lead anywhere | 12 months from last contact, then deleted |
| Enquiries that become client relationships | Duration of the relationship, then 3 years in line with our contractual and limitation-period obligations |
| Correspondence and records with tax or accounting relevance | 5 years from the end of the relevant tax year (Polish statutory requirement) |
| Server logs | 90 days |
| Analytics data | 12 months, per the tool’s configuration |
When a period ends we delete or irreversibly anonymise the data.
Keeping It Safe
We apply technical and organisational measures proportionate to the risk: encryption in transit (TLS), access limited to those who need it, multi-factor authentication on business systems, vetted providers, and periodic review of our own arrangements.
No system is perfectly secure, and we won’t claim otherwise. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the President of the Personal Data Protection Office (UODO) within 72 hours of becoming aware of it, and we will tell you directly where the risk is high.
Your Rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and get a copy
- correct anything inaccurate or incomplete
- erase it, in the circumstances the law allows
- restrict how we use it while a question about it is resolved
- portability — receive data you gave us in a structured, machine-readable format
- object to processing based on our legitimate interests, including at any time
- withdraw consent where we rely on it
Write to privacy@pollatir.com. We’ll respond within one month. Exercising these rights costs you nothing, and we won’t treat you differently for it.
If you think we’ve handled your data badly, please tell us first — we’d rather fix it. You also have the right to complain to the supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl
If you’re based elsewhere in the EEA, you may complain to your local supervisory authority instead.
Automated Decisions
We don’t make decisions about you by automated means, and we don’t profile you. Any decision about working together is made by people, in conversation with you.
Children
This website is aimed at businesses. It isn’t directed at anyone under 16, and we don’t knowingly collect their data. If you believe a child has sent us personal data, contact us and we’ll delete it.
Changes to This Policy
We update this policy when our practices change or the law does. The date at the top always reflects the current version. Material changes will be flagged on this page before they take effect.
Contact
Questions about this policy, or about how we handle your data:
privacy@pollatir.com
Pollatir sp. z o.o., ul. Żelazna 51/53, 00-841 Warszawa, Poland