Legal

Privacy Policy

How KAPUSTA.DEV collects, uses and protects personal data, and what rights you have under the GDPR.

1.1. Data controller and contact

The controller of your personal data is KAPUSTA.DEV by Dmytro Kapusta, ul. Walerego Wróblewskiego 21E/15, 93-578 Łódź, Poland (NIP 7272892890, REGON 542771137).

For any privacy question, access request or complaint, write to sales@kapusta.dev or call +48 791 729 629. We answer privacy requests within 30 days; if a request is complex we may extend this by a further two months and will tell you why.

We have not appointed a Data Protection Officer, because we are not legally required to. Privacy requests are handled directly by the owner of the company.

2.2. Scope of this policy

This policy covers personal data processed through the kapusta.dev website (including all language versions and the /pl, /ru and /ua sections), our contact and quote forms, email, phone and messenger conversations (WhatsApp, Telegram), and the administration panel used by our own staff.

It does not cover websites or applications that we build and hand over to clients. Once a project is delivered and the client operates it, the client becomes the controller for the data collected there; we act only as a processor under a separate data processing agreement.

3.3. Categories of data we collect

We collect only what we need in order to answer you, deliver a project and meet our legal obligations. We never ask for special-category data (health, beliefs, biometrics) and ask you not to send it to us.

  • Contact and enquiry data: name, email address, phone number (optional), company name (optional), selected service, budget range (optional) and the content of your message.
  • Correspondence data: emails, call notes, messenger threads, meeting notes and attachments you send during an enquiry or project.
  • Contract and billing data: company details, NIP/VAT number, billing address, invoice numbers, payment dates and amounts.
  • Project access data: credentials and access tokens you grant us to your systems (hosting, repositories, analytics, ad accounts) — stored only for the duration of the engagement.
  • Technical data: IP address, user agent, referring page, requested URLs, response codes and timestamps written to server logs.
  • Cookie and device data: strictly necessary cookies, your language preference stored in localStorage, and — only with consent — aggregated analytics events.
  • Administration data (staff only): login attempts, IP address, session records, two-factor status and an audit log of changes made in the admin panel.

4.4. Purposes and legal bases

Every processing activity has a defined purpose and a legal basis under Article 6 of the GDPR:

  • Answering your enquiry and preparing an offer or estimate — Art. 6(1)(b) GDPR, steps taken at your request prior to entering a contract.
  • Performing a signed contract: design, development, deployment, SEO, support and maintenance — Art. 6(1)(b) GDPR.
  • Issuing invoices and keeping accounting and tax records — Art. 6(1)(c) GDPR, compliance with Polish accounting and tax law.
  • Keeping our website, backend and admin panel secure, preventing abuse and spam, and investigating incidents — Art. 6(1)(f) GDPR, our legitimate interest in system security.
  • Establishing, exercising or defending legal claims — Art. 6(1)(f) GDPR.
  • Publishing an anonymised or approved case study about work delivered for you — Art. 6(1)(f) GDPR, or your consent where the contract requires it.
  • Sending newsletters, offers or follow-up marketing — Art. 6(1)(a) GDPR, your explicit consent, which you can withdraw at any time.
  • Analytics and performance measurement — Art. 6(1)(a) GDPR, consent expressed through cookie settings.

5.5. Providing data is voluntary

Filling in a form is always voluntary, but name, email and a description of your project are necessary for us to reply — without them we cannot process the enquiry. Phone number, company name and budget range are optional and only help us prepare a more accurate answer.

Where data is required by law (for example invoice details), refusing to provide it means we cannot conclude or continue the contract.

6.6. Retention periods

We keep data only as long as there is a purpose for it, and we delete or anonymise it afterwards:

  • Enquiries that do not lead to a project: up to 24 months from the last contact, then deleted.
  • Contract documentation and project files: 6 years from the end of the contract, matching the general limitation period for business claims under Polish law.
  • Invoices and accounting records: 5 full years from the end of the tax year in which the tax became payable, as required by tax law.
  • Marketing consents: until you withdraw consent, plus a short record of the withdrawal itself as proof of compliance.
  • Server logs: rotated and deleted within 12 months.
  • Admin login attempts, sessions and audit entries: 12 months, for security monitoring and incident investigation.
  • Client access credentials: revoked and removed immediately at the end of the engagement.

7.7. Recipients and processors

We do not sell personal data and we do not share it for third-party advertising. We disclose data only to service providers that process it on our instructions under Art. 28 GDPR data processing agreements, and to public authorities where the law requires it.

  • Hosting, database, storage and serverless infrastructure providers that run the website and backend.
  • Email delivery and business email providers used to receive and answer your messages.
  • Messenger platforms (WhatsApp, Telegram) when you choose to contact us there, under their own terms.
  • Privacy-focused website analytics, where consent has been given.
  • Our accounting office and, when needed, legal advisers, both bound by professional confidentiality.
  • Payment providers and banks handling invoice settlement.

8.8. Transfers outside the EEA

We prefer providers hosting data inside the European Union. Where a provider processes data outside the EEA, the transfer is protected by the European Commission's Standard Contractual Clauses, an adequacy decision, or another mechanism permitted by Chapter V of the GDPR, together with technical safeguards such as encryption in transit and at rest.

You can ask us for a list of current sub-processors and the transfer mechanism applied to each by writing to sales@kapusta.dev.

9.9. Your rights

Under the GDPR you have the right to: be informed about processing; access your data and receive a copy; have inaccurate data corrected; have data erased (the 'right to be forgotten') where no other basis for keeping it applies; restrict processing; object to processing based on our legitimate interest; receive your data in a portable, machine-readable format; and withdraw consent at any time without affecting the lawfulness of processing already carried out.

To exercise any right, email sales@kapusta.dev with a short description of your request. We may ask a question to confirm your identity before acting, purely to avoid disclosing data to the wrong person. Exercising your rights is free of charge unless a request is manifestly excessive or repetitive.

If you believe we process your data unlawfully, you may lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.

10.10. Security measures

We apply technical and organisational measures proportionate to the risk: TLS encryption for all traffic, encrypted storage, row-level access rules in the database, unique named administrator accounts with mandatory two-factor authentication, brute-force lockout on the admin login, session management with the ability to revoke sessions, audit logging of administrative actions, least-privilege access for team members, and regular dependency and security scanning of our codebase.

Backups are encrypted and retained for a limited period. Access to production data is restricted to people who need it to deliver the service.

11.11. Personal data breaches

If a breach occurs that is likely to result in a risk to your rights and freedoms, we notify the Polish supervisory authority within 72 hours of becoming aware of it and inform affected individuals without undue delay, describing what happened, the likely consequences and the steps we have taken.

12.12. Automated decisions and profiling

We do not make decisions about you based solely on automated processing, and we do not carry out profiling that produces legal effects or similarly significantly affects you.

13.13. Children

Our services are addressed to businesses. We do not knowingly collect data from children under 16. If you believe a child has sent us personal data, contact us and we will delete it.

14.14. Changes to this policy

We review this policy at least once a year and whenever our tools or processes change materially. The current version and its date are always published on this page; earlier versions are available on request. Where a change materially affects you, we will inform you by email before it takes effect.