This translation is provided for information only. The binding version is the Polish one, available at cookieofficer.pl/polityka-prywatnosci.
Key information
Before you move on to the detailed information, below you will find the key information in brief. It does not replace the full text below, but it conveys its main meaning.
| Question | Answer |
|---|---|
| Who processes my data? | Your data is processed by Wojciech Bednarski DataWolves, with its principal place of business at ul. Fabryczna 3/9, 97-545 Wojciechów, Poland, NIP (Polish tax identification number): 7722307415. |
| Do you sell my data? | No, we do not sell personal data and we do not work with data brokers. We share data for advertising purposes only with your consent given in the banner, which you can withdraw at any time. |
| Do you have access to the data of users visiting your customers' websites? | We process this data only on the customer's instructions, acting as a processor under a data processing agreement (DPA). We do not use this data for our own purposes. |
| Do you store the content of my cookies? | No, the scanner records only the name, domain, expiry time and attributes of a cookie. We store only a fragment of the cookie's value in masked form, as an example. |
| Is data transferred outside the European Union? | We process the consent log and scan results on servers in Warsaw, and their encrypted backups are kept with a provider whose data storage location is in the European Union. Data related to the panel, user accounts, backups, email and payments is processed by service providers that may transfer it to the United States on the basis of Standard Contractual Clauses (SCC) or the Data Privacy Framework (DPF). Detailed information on this is provided in section 9. |
| How can I exercise my rights? | To exercise your rights, please contact us at kontakt@cookieofficer.pl. We respond to all requests within one month. |
1. Who is the controller of your personal data?
The controller of your personal data is Wojciech Bednarski DataWolves, with its principal place of business at ul. Fabryczna 3/9, 97-545 Wojciechów, Poland, NIP (Polish tax identification number) 7722307415, REGON 382702660. You can contact us by email at kontakt@cookieofficer.pl (in Polish) or contact@cookieofficer.com (in English). If you prefer to contact us by phone, call +48 515 166 748.
We have not appointed a Data Protection Officer, because we are not required to do so under Article 37 GDPR. We handle all matters relating to personal data directly at the email address indicated above, treating them as a priority.
2. Scope and purpose of the Privacy Policy
This Privacy Policy applies to: our websites cookieofficer.com and cookieofficer.pl, together with all their subdomains (together referred to as the Website); the CookieOfficer Service, a comprehensive cookie management platform (CMP) comprising a cookie and tracking technology scanner, a cookie declaration generator, a cookie banner editor and a consent log; all forms of contact with us (e.g. email, the contact form, a product demo); marketing consents and future marketing communications; the Partner Programme for agencies.
Please note that this Policy does not cover our customers' websites or third-party websites on which we may place links. If you have reached this page through a cookie banner displayed on another website, the controller of your data is the owner of that website, not us. Detailed explanations are provided in sections 3 and 6.
3. When are we the controller, and when are we the processor?
This is the key distinction in the whole document, because it determines to whom you should address your requests.
3.1 We are the controller (we decide on the purposes and means of processing) in the following situations:
When you visit our Website; when you create an Account on the Website or represent an entity that creates one; when you contact us by email, through the contact form or by phone; when you sign up for the newsletter or book a product demo; when we settle payments for the Service with you; when you apply to the Partner Programme; when you use our free demonstration scan, which is publicly available on the website. In these cases we are responsible for your data, and requests concerning access, erasure or objection should be addressed to us.
3.2 We act as a processor (we process data only on the customer's documented instructions) in the following situations:
When we scan a website indicated by a customer and save the results in its account; when we display a cookie banner on a customer's website and record visitors' decisions in the consent log; when we store a customer's banner configuration, categorisation of tracking technologies and scan history. In these cases the controller of the data is our customer, the owner of the website on which CookieOfficer operates. We process the data under a data processing agreement (DPA) that meets the requirements of Article 28 GDPR. The DPA is an integral annex to the Terms of Service and is concluded when the Account is created. Its text is available at cookieofficer.pl/umowa-powierzenia. Corporate customers may conclude a separate DPA.
If you are a visitor to a website that uses CookieOfficer and you want to exercise your rights concerning the recorded consent, you should contact the owner of that website directly. If you contact us, we will pass your matter on to the relevant controller (provided we are able to identify it) and inform you of this, but we cannot decide on other parties' data ourselves.
3.3 Intermediate situations
In some situations we are the controller of technical data that is generated while we provide our Service to a customer. This applies in particular to security logs and to data on performance and the number of requests. We process this data as the controller on the basis of Article 6(1)(f) GDPR, which means that the processing is necessary for the purposes of our legitimate interests, such as ensuring security and optimising the operation of the system.
We use data entrusted to us by a customer for product development only after it has been aggregated and irreversibly anonymised. After anonymisation it no longer constitutes personal data and is not subject to the GDPR. The right to aggregate and anonymise follows from the controller's documented instruction contained in the DPA (Article 28(3)(a) GDPR), not from our own decision. This data does not allow specific visitors to our customers' websites to be identified.
4. Where do we get your data from?
| Source | Examples |
|---|---|
| Directly from you | Account registration, filling in the contact form, signing up for the newsletter, applying to the Partner Programme, correspondence with us, technical support requests. |
| Automatically, when you use the Website | IP address, device information (e.g. model, operating system), browser data, server logs, activity in the application (e.g. clicks, pages visited), cookies. |
| From our customer | If you represent a company that is our customer and has added you as a user in its team. |
| From public sources | Company registration data (e.g. from KRS, CEIDG, VIES), which we use only to verify the contracting party and to issue an invoice. |
| From login providers | If you log in to our Website with a Google account, we receive your email address, first and last name and account identifier from Google. |
5. Purposes, legal bases and data retention periods
We process personal data only when we have an appropriate legal basis for it under Article 6 GDPR. A detailed summary is provided below.
5.1 Visits to the Website
| Scope of data | Truncated IP address (used only for statistical purposes), browser type and version, operating system, referring page, date and time of the request and approximate location at country level. |
| Purpose of processing | Making the website available, ensuring the security and stable operation of the Website, and detecting abuse and attacks. |
| Legal basis | Article 6(1)(f) GDPR, that is, our legitimate interest in maintaining and protecting the Website. |
| Retention period | We overwrite server logs as the allocated disk space fills up, which in practice gives about a month of history. We keep security logs relating to detected incidents for up to 12 months. |
5.2 Website statistics and analytics
| Scope of data | Events on the Website, the navigation path, the session identifier assigned by the analytics tool and device data. |
| Purpose of processing | Analysing user traffic on the website and improving the content and usability of the Website. |
| Legal basis | Article 6(1)(a) GDPR, that is, your consent given in the cookie banner (analytics tools start only after you give consent). |
| Retention period | We store the data in accordance with the settings of the analytics tool, for a maximum of 14 months. You can withdraw your consent at any time by changing the cookie settings in the website footer. |
5.3 Contact form, email, booking a product demo
| Scope of data | First and last name, email address, company name, phone number (if provided), website address and the content of the message. |
| Purpose of processing | Responding to the enquiry, handling the request and conducting the product demo. |
| Legal basis | Article 6(1)(b) GDPR, because the processing is necessary in order to take steps at your request prior to entering into a contract. Otherwise, the basis is Article 6(1)(f) GDPR, that is, our legitimate interest in conducting correspondence and defending against possible claims. |
| Retention period | For the time needed to handle the matter, and then until the limitation period for claims expires. If the correspondence leads to the conclusion of a contract, the data will be processed in accordance with point 5.5. |
When you click the “Send message” button, the form sends your message to our server in Warsaw, hosted by OVH. There, the request is added to the enquiry register. Two emails are then sent from the same server: a notification to us (with the reply-to address set to yours, so that we can reply to you directly) and, if you are signing up for the newsletter, a request to confirm the subscription, sent to your address.
Sending is handled by the transactional email provider referred to in point 8.2, so both your address and the content of the message pass through its system. The inbox to which our notification is delivered is also hosted in Poland, in Warsaw, by OVH.
To prevent abuse, the form is protected in several ways: it contains an invisible trap field, measures the time taken to fill it in, controls the intervals between requests from the same address and uses reCAPTCHA v3. Requests identified as automated are rejected and are not saved in the register.
5.4 Newsletter and marketing communications
| Scope of data | Email address, first name (optional) and the marketing consent recorded in your profile. |
| Purpose of processing | Sending content about our product, changes in the law and news. |
| Legal basis | Article 6(1)(a) GDPR, consent to the processing of data for marketing purposes; where telecommunications terminal equipment and automated calling systems are used for direct marketing, consent in accordance with Article 398 of the Polish Electronic Communications Law of 12 July 2024. |
| Retention period | We store the data until consent is withdrawn or an objection is raised. After that, the email address remains on the suppression list so that no further marketing messages are sent. |
Signing up for the newsletter requires confirmation of the address (double opt-in): after the form is filled in, we send a message with a confirmation link. Only clicking this link constitutes giving consent and creates our proof that it was given. The confirmation message, like all system correspondence, is sent by our transactional email provider, so your email address passes through its system and through those of any subcontractors (in accordance with point 8.2). We keep the list of subscriptions on our own server in Warsaw.
To unsubscribe from the newsletter, simply click the relevant link in the footer of any message you receive.
5.5 Account on the Website and provision of the Service
| Scope of data | Identification and contact data, login data, company data and billing data, data on the use of the Service and technical data from the panel, including sign-in history with the IP address and browser information. |
| Purpose of processing | Creating and maintaining the Account, providing the Service, technical and service contact, and notifications about changes to the Service. |
| Legal basis | Article 6(1)(b) GDPR, that is, performance of the contract. |
| Retention period | We store the data for the term of the contract. After it ends, we provide a 30-day window for exporting data, and then we delete the Account data within a further 30 days. The exceptions are data covered by a legal obligation (point 5.6) and data necessary to defend against claims, which we store until the limitation period expires; this period is up to 6 years, and 3 years for claims related to business activity. |
After the contract ends, we allow you to export the data from the account (including the consent log) for 30 days. After that time the data is permanently deleted, and it disappears from backups when the backup itself expires, after 6 months at the latest.
5.6 Payments, invoices and accounting
| Scope of data | Company billing data (name, address); tax identification number (NIP); transaction history; the last four digits of the payment card together with its type (we do not store full card details; they are handled only by the payment operator). |
| Purpose of processing | Billing for the services provided; issuing and storing invoices; keeping accounting records. |
| Legal basis | Article 6(1)(c) GDPR, a legal obligation under the Tax Ordinance Act and the Value Added Tax Act; Article 6(1)(b) GDPR, as regards performance of the contract concluded. |
| Retention period | The data retention period is 5 years from the end of the calendar year in which the tax payment deadline expired. |
5.7 Technical support
| Scope of data | The content of the request, email address, account identifier and technical data sent with the request, such as screenshots or system logs. |
| Purpose of processing | Resolving the reported problem, improving the quality of the services provided and building an internal knowledge base. |
| Legal basis | Article 6(1)(b) GDPR as regards performance of the contract, and Article 6(1)(f) GDPR for the purpose of improving the functionality of the service. |
| Retention period | For the time needed to handle the matter, and then until the limitation period for claims expires. |
Our technical support is based on direct email communication, without the use of external ticketing systems. The mailbox through which we handle requests is hosted in Poland. The content of your request is not passed on to any external providers. We access your account only when this is absolutely necessary to resolve the reported problem.
5.8 Partner Programme
| Scope of data | The first and last name of the agency's representative, business email address, the agency's name and website, billing data, information about assigned customers and commission history. |
| Purpose of processing | Handling participation in the programme, calculating and paying commissions, and presenting the agency's data in the partner directory (with separate consent). |
| Legal basis | Article 6(1)(b) GDPR as regards performance of the contract, Article 6(1)(c) GDPR for the purpose of fulfilling settlement obligations, and Article 6(1)(a) GDPR in the case of consent to publication. |
| Retention period | The retention periods for this data are the same as in points 5.5 and 5.6. |
5.9 Free website scan
If you use the free website scan available on our website, we are the controller of your data, not the owner of the scanned domain.
| Scope of data | The address of the scanned domain; your email address (only if you ask for the scan report to be sent); the IP address of the device from which you run the scan; the scan result, including any threats or problems detected. |
| Purpose of processing | Performing the domain scan at your request; sending the scan report to the email address provided (if you ask for it); with your additional consent, contact for commercial purposes concerning our services. |
| Legal basis | Article 6(1)(b) GDPR, the processing is necessary to perform the domain scanning service that you order; Article 6(1)(a) GDPR, processing for marketing purposes is based on your voluntary consent; Article 6(1)(f) GDPR, processing to prevent abuse and fraud related to the use of the scanner, which is in our legitimate interest as the controller. |
| Retention period | Domain scan result: 90 days from the date of the scan; email address: until you withdraw your consent to marketing contact (if you gave such consent). After these periods, your data will be deleted or anonymised in accordance with data protection principles. |
Our domain scanner works as follows: we scan only publicly available websites that do not require logging in, and we always observe the set request limits so as not to overload servers.
By using our scanner, you represent that you have the right to scan the domain indicated and that you are not breaching the terms of use of that domain. You also confirm that you are not using the scanner for unlawful or unethical purposes.
5.10 Recruitment
If you apply to us for a job or for another form of collaboration, we process the data contained in your application. The legal bases for processing are: Article 6(1)(b) GDPR (steps taken before entering into a contract), Article 6(1)(c) GDPR (requirements of labour law) and Article 6(1)(a) GDPR (consent to the processing of data beyond what the law requires).
The data retention period is 6 months from the end of the recruitment process. If you consent to taking part in future recruitment processes, we store your data for 12 months. You can withdraw your consent to data processing at any time. We delete your data in accordance with the periods indicated, unless the law requires it to be stored for longer.
6. Data processed within the Service
This section describes in detail what happens to data in the course of providing our service.
To the extent described in points 6.1 to 6.3, we act as a processor on behalf of our customers, in accordance with the rules set out in section 3.2. This means that we process data on behalf of and on the instructions of our customers, in accordance with the agreements concluded and the applicable law.
6.1 Cookie and tracking technology scanner
The cookie and tracking technology scanner works by opening the selected website in an automated browser based on the Chromium engine. This process is carried out in three stages: before any interaction with the consent banner, after the user accepts consent and after consent is rejected. In each of these scenarios, the scanner records precisely which tracking technologies are activated by the website.
For each detected tracking technology, the following data is collected: the full name; the domain and path from which it is sent; the type of technology (e.g. cookie, local storage, browser database, tracking pixel); the validity period, that is, how long the technology remains active; security attributes, such as HttpOnly, Secure or SameSite, which affect how the browser handles the technology; the method by which it was set (whether it was added through an HTTP header or by a JavaScript script, together with the full function call stack); the specific phase of the consent process in which the technology was detected (before acceptance, after consent is accepted or after it is rejected); the assigned category and the identifier of the technology's vendor.
We do not record the full values of cookies or of entries kept in browser storage (e.g. localStorage, sessionStorage). The values of these items often contain users' personal data, such as session identifiers or unique user IDs, which is why we store only masked fragments that make it possible to recognise the format of the data but not to identify a specific person. Deduplication of tracking technologies (that is, grouping similar items) is based only on the combination of type, name, domain and path, never on the stored values.
Our scanner simulates the behaviour of an ordinary user visiting the website. It does not perform any actions that require authentication (e.g. logging in to the customer's systems) and does not search protected areas.
Scan results are stored for the term of the agreement with the customer, which makes it possible to monitor changes on the website and to compare historical data.
6.2 Cookie declaration and cookie categorisation
On the basis of the data collected from the website scan, our tool generates a clear cookie declaration in the selected languages. The categorisation of tracking technologies is based on a multi-layered approach that includes: curated rules, that is, a set of rules developed by experts; the Open Cookie Database (Apache 2.0 licence), an open data set co-created by the community; domain rules, that is, rules specific to individual domains; heuristics, that is, simplified classification methods based on analysis of metadata.
For each tracking technology, we record the source on the basis of which it was classified, which ensures full transparency and makes it possible to audit the decisions. Importantly, the entire categorisation process is based only on the technology's metadata (such as its name, domain or vendor) and does not involve analysing any personal data of users visiting the website.
6.3 Cookie banner and consent log
The consent log is part of ensuring compliance with the accountability principle under the GDPR (Article 5(2) and Article 7(1)). For each user decision concerning consents on a customer's website, we record the following information: a unique consent identifier, a randomly generated pseudonymous identifier stored in the user's browser; the exact time of the decision; the scope of the consent given, that is, which categories of tracking technologies were accepted and which were rejected; the version and language of the consent banner and the version of the cookie declaration that the user saw when making the decision; how consent was expressed, that is, whether the user clicked the accept button or the reject button, or used the detailed settings option; the truncated IP address and the country from which the user is connecting, in order to determine which legal provisions applied; information about the browser from which the decision was sent; the domain on which consent was collected.
In the consent log we do not record personal data such as the user's first and last name or email address. We also do not store the full IP address; instead, we use a truncated version that prevents direct identification of a person. The consent identifier generated for each user is used only to manage their decisions and is not used for any form of tracking. If a customer enables consent sharing within a group of its domains, the same identifier is carried across the domains of that group, so that the user does not have to answer the banner separately on each of them. Outside such a group, identifiers are not linked to one another. This allows us to ensure full protection of users' privacy while meeting the legal requirements for documenting consents.
In addition to the consent log, which we keep on our side, the banner stores some information in the browser of the visitor to the customer's website. A full list is given below. None of this information contains a first and last name or an email address.
| Record | Where | What it contains | How long |
|---|---|---|---|
co_consent | cookie on the customer's domain | the scope and time of the decision, the pseudonymous consent identifier, the project identifier, a Global Privacy Control signal flag | the period set by the customer, 365 days by default |
__coQ | browser storage on the customer's domain | a queue of consent proofs that could not be sent, up to five entries | 30 days |
co-geo-<id> | browser storage on the customer's domain | the visitor's country code, determined on our side | 24 hours |
co-cfg-<id> and two auxiliary keys | browser storage on the customer's domain | a copy of the banner settings, without any visitor data | until the settings change |
co-bulk-<id> | browser storage on our domain | created only when the customer has enabled consent sharing within a domain group | 30 days |
The retention period for data in the consent log depends on the plan chosen by the customer: on the Free plan: 3 months; on the Basic plan: 12 months; on the Pro plan: 36 months; on the Enterprise plan: 60 months.
If a user withdraws consent, the original record is marked as no longer current, and a new record documenting the withdrawal (containing the consent identifier, the timestamp and the scope of the consents withdrawn) is saved alongside it. Both records, the original one and the withdrawal, are kept for the period following from the plan, counted separately for each of them from the date on which it was saved, so that the customer can prove that the user's decision was recorded and properly implemented. The customer, as the controller, is responsible for choosing the plan that best suits the purpose for which it collects consents.
6.4 Our own cookie banner
On our Website we use our own cookie management solution. It works as follows: analytics and marketing technologies (e.g. tracking scripts, analytics tools) are blocked by default and start only after you give your informed consent; the option to withdraw consent: you can change your settings at any time by clicking the “Cookie settings” link in the website footer. Withdrawing consent is as easy as giving it and does not affect the operation of the basic functions of the Website; details on managing consents and the full cookie policy are available in section 10.
7. Summary of data retention periods
| Data category | Period |
|---|---|
| Server logs | Overwritten as the allocated disk space fills up, which in practice gives about a month of history. |
| Security logs (incidents) | 12 months, kept in order to analyse and prevent future threats. |
| Website analytics data | Up to 14 months, used to optimise the Website. |
| Correspondence and enquiries | For the time needed to handle the matter, and then until the limitation period for claims expires. |
| Marketing consent | Until consent is withdrawn or an objection is raised. After that, the email address remains on the suppression list so that no further marketing messages are sent. |
| Account and Service data | The term of the contract, 30 days for exporting data and up to 30 days for complete deletion. |
| Backups | Data disappears from a backup when the backup itself expires, after 6 months at the latest. After a backup is restored, we again delete from it the data that had previously been erased. |
| Accounting and tax documents | 5 years from the end of the calendar year in which the tax payment deadline expired, in accordance with legal requirements. |
| Data for defending against claims | Until the limitation period expires (3 or 6 years), depending on the type of claim. |
| Support requests | For the time needed to handle the matter, and then until the limitation period for claims expires. |
| Free scan results | 90 days, kept in order to ensure continuity of the service. |
| Consent log (as a processor) | Depends on the customer's plan, counted separately for each entry from the date on which it was saved: Free 3 months; Basic 12 months; Pro 36 months; Enterprise 60 months. |
| Recruitment documents | 6 months (or 12 months if the candidate has consented to future recruitment processes). |
8. Data recipients, sub-processors and joint controllers
We do not sell or share your personal data with data brokers. Access to it is given only to those entities that we need in order to provide the service, to fulfil our legal obligations or to establish, pursue or defend claims, and only to the extent necessary for these purposes.
8.1 Categories of recipients
Your data may be passed on to various entities, depending on the purpose of processing. Providers of infrastructure, hosting and content delivery networks receive it to ensure the stability and security of our services. The transactional email provider needs it to send important messages related to our service. The payment operator processes the data to handle financial transactions. The provider of protection for forms against abuse (reCAPTCHA) uses it to protect against spam and unauthorised access. Providers of analytics and advertising tools receive data for statistical and marketing purposes, with respect for your privacy. The accounting office and legal and tax advisers process data to the extent necessary to fulfil legal and accounting obligations. Public authorities may receive data only on the basis of applicable law, when this is necessary. Each of these entities processes the data only to the extent necessary to perform its tasks and in accordance with our data protection guidelines.
8.2 Sub-processors, entities that process data on our instructions
We work with sub-processors that process data only on our instructions and in accordance with our directions, under data processing agreements that meet the requirements of Article 28 GDPR. Within the scope of the entrusted processing, these entities may not use the data for their own purposes. Entities that, in addition to the entrusted processing, also act as independent controllers are described in point 8.3.
| Legal entity | What it covers | Registered office and registration details | Transfer outside the EEA |
|---|---|---|---|
| OVH sp. z o.o. | We work together on hosting the engine of the cookie management platform, the consent log, scan results and the contact mailbox. | The company's registered office is at ul. Swobodna 1, 50-088 Wrocław, Poland. Registration details: KRS 0000220286, NIP 899-25-20-556, REGON 933029040. The data is processed in a data centre located in Warsaw. | There is no transfer of data outside the European Economic Area (EEA). |
| Google Ireland Limited | We work together on hosting the customer panel and the website (Firebase Hosting), authentication and the account database (Firebase Auth, Firestore), Google Tag Manager, Google Consent Mode, Google Analytics 4 and reCAPTCHA v3, which protects the forms. In this respect Google acts as a processor. | The company's registered office is at Gordon House, Barrow Street, Dublin 4, Ireland. Registration details: registration number 368047 and VAT IE6388047V. | Data is transferred to Google group companies in the United States. |
| Cloudflare, Inc. | We work together on the CDN, DNS, WAF protection and backups (Cloudflare R2). | The company's registered office is at 101 Townsend Street, San Francisco, CA 94107, USA. The contracting party is the US company, and Cloudflare does not contract through an entity in the European Economic Area (EEA). | Data is transferred outside the EEA on the basis of Standard Contractual Clauses (SCC) in accordance with Article 46 GDPR. The data processing agreement is supplemented by a declared DPF (Data Privacy Framework) certification. |
| Plus Five Five, Inc. (Resend brand) | We work together on transactional email and system emails. | The company's registered office is at 2261 Market Street #5039, San Francisco, CA 94114, USA. | Data is transferred outside the European Economic Area (EEA) on the basis of Standard Contractual Clauses (SCC) in accordance with Article 46 GDPR. This operational basis is indicated in the data processing agreement. |
| Stripe Payments Europe, Limited | We work together on processing payments and subscriptions on our instructions (for its role as an independent controller, see point 8.3). | The company's registered office is at One Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland. Registration details: CRO 513174 and LEI 549300DSKP4KJP52XY61. | Data is transferred outside the European Economic Area (EEA). The basis for the transfer is the Data Privacy Framework, and the recipient in the USA is the certified entity Stripe, LLC. Standard Contractual Clauses (SCC), covering Modules 1 and 2, are used as a fallback mechanism. |
According to the provider's list of 15 July 2026, the chain of further sub-processors of the transactional email provider comprises 22 entities established in the United States, including providers of cloud infrastructure, monitoring and artificial intelligence services. Email addresses and the content of system messages pass through this chain. The current list of sub-processors is published by the provider at resend.com/legal/subprocessors.
We give notice of a new sub-processor before it starts processing. The detailed notice periods and the right to object to a new sub-processor are set out in the DPA (Data Processing Agreement).
8.3 Independent controllers in our service ecosystem
Some of the entities we work with process part of the data for their own purposes, over which we have no influence. To that extent, they act as independent controllers and apply their own privacy policies. If you want to exercise your rights with regard to that processing, you should address your requests directly to those entities.
| Entity | Role with regard to the data | What its own processing as a controller covers |
|---|---|---|
| Stripe Payments Europe, Limited | It plays a dual role in processing data: it acts as a processor when it carries out transactions on our behalf (in accordance with point 8.2), and as an independent controller in other cases. This follows directly from the data processing agreement, in which Stripe reserves the exclusive right to determine the purposes and means of processing data as a controller. | As part of its own processing as a controller, Stripe deals with: preventing fraud and abuse on its payment platform; fulfilling obligations related to anti-money laundering (AML) and customer due diligence (KYC); meeting other regulatory requirements that apply to payment institutions; developing and securing its services; managing its relationship with us as a merchant. |
| Google Ireland Limited, Google Ads (remarketing tag, conversion tracking) | Google acts as an independent controller under the Google Ads Controller-Controller Data Protection Terms, in which it expressly states that each party is an independent controller of personal data and determines the purposes and means of its processing on its own. | The scope of Google's own processing as a controller includes: building and maintaining advertising profiles; measuring the reach of ads across the Google network; developing targeting algorithms; detecting and preventing abuse related to ads. |
| LinkedIn Ireland Unlimited Company, LinkedIn Insight Tag | LinkedIn acts as an independent controller. The joint controllership arrangements published by LinkedIn cover only Page Insights and the statistics of the company page on LinkedIn, and they expressly state that, to that extent, LinkedIn does not share personal data with us. The Insight Tag is not covered by these arrangements, and LinkedIn processes the data sent by this tag as an independent controller for the purposes of its advertising platform. | The scope of LinkedIn's own processing as a controller includes: matching website visits to LinkedIn members' profiles; building demographic data about visitors; targeting and measuring the effectiveness of advertising campaigns on the LinkedIn network. |
| Meta Platforms Ireland Limited, to the extent going beyond the collection and transmission of data (see point 8.4) | Meta acts as an independent controller. | The scope of Meta's own processing as a controller includes: further use of the data in its own advertising network. |
| Accounting office, legal and tax advisers | They act as independent controllers within the scope of their professional obligations. | The scope of their own processing as controllers includes: archiving documentation required by professional and tax regulations. |
| Public authorities | They are independent controllers. | The scope of their own processing as controllers includes: conducting proceedings on the basis of applicable law. |
If you want the payment operator (e.g. Stripe) to delete data it processes as part of its anti-money laundering (AML) obligations or other regulatory requirements, you cannot ask us to do this; you must address such a request directly to the operator. We handle data processed by the operator only on our instructions, in order to carry out transactions, in accordance with the standard procedure described in section 12.
8.4 Joint controllership and advertising tools
If you consent to marketing cookies, measurement tools are activated on our website. In accordance with the judgment of the Court of Justice of the European Union in case C-40/17 (Fashion ID), as regards the collection and transmission of data, both the website operator (us) and the tool provider (e.g. Google, Meta, LinkedIn) are joint controllers within the meaning of Article 26 GDPR. Whether this is the case is determined by how the specific tool works, that is, whether we decide together with the provider on the purposes and means of collecting the data. Where a provider makes an arrangement under Article 26 GDPR available, we indicate it as the document describing the division of responsibilities. Providers that act as independent controllers for a given processing operation are described in point 8.3.
| Entity | Tool | Scope of joint controllership | Transfer outside the EEA |
|---|---|---|---|
| Meta Platforms Ireland Limited (address: Merrion Road, Dublin 4, D04 X2K5, Ireland) | Meta Pixel / Business Tools | Covers the collection of data on events on our Website (e.g. visits, clicks) and its transmission to Meta, in accordance with the terms set out in the Meta Controller Addendum. Further processing of this data on Meta's side is no longer covered by joint controllership; to that extent, Meta acts as an independent controller. | Takes place on the basis of the Data Privacy Framework, which concerns the transfer of data from the EU to Meta Platforms, Inc. (USA). |
| LinkedIn Ireland Unlimited Company (address: Wilton Place, Dublin 2, Ireland) and Meta Platforms Ireland Limited | Statistics about our company pages on LinkedIn (LinkedIn Page Insights) and Facebook (Meta Page Insights), if we maintain such pages | Covers the collection and processing of statistics on views, interactions (e.g. likes, comments) and other data related to our page on the social network concerned. This takes place on the terms set out in the documents: LinkedIn Page Insights Joint Controller Addendum; Meta's equivalent concerning Page Insights. This type of joint controllership concerns only our page on the social network, not our website. | Takes place on the basis of Standard Contractual Clauses (SCC) and additionally on the basis of the Data Privacy Framework (in the case of Meta Platforms, Inc. and LinkedIn). |
| Google Ireland Limited and LinkedIn Ireland Unlimited Company | Google Ads remarketing tag (for Google) and LinkedIn Insight Tag (for LinkedIn) | These tools are not covered by joint controllership; both Google and LinkedIn act as independent controllers in this case (see point 8.3). We, as the website operator, are responsible for obtaining the user's valid consent before these tags are activated on our website. | Takes place on the basis of Standard Contractual Clauses (SCC) and additionally on the basis of the Data Privacy Framework (in the case of Google and LinkedIn). |
In the case of joint controllership with advertising platforms (e.g. Google, Meta, LinkedIn), our role as the website operator is to collect and demonstrate the user's valid consent before tracking tools such as Google Ads, Meta Pixel or LinkedIn Insight Tag are activated. We are also responsible for the content of the information provided to the user in the cookie banner and in the Privacy Policy, and for enabling consent to be withdrawn. The advertising platforms are responsible for further processing of the data after they receive it, including profiling, displaying ads, and storing and deleting the data, and for handling the user's rights in this respect. The user may contact us or the platform directly and exercise their rights against each of the joint controllers. The processing is based on the user's consent (Article 6(1)(a) GDPR), which can be withdrawn at any time.
If you do not consent to marketing cookies, none of the tracking tools (such as Google Ads, Meta Pixel or LinkedIn Insight Tag) will be activated on our website, and consequently there will be no joint controllership of data as regards its collection and transmission.
8.5 Change of ownership
In the event of a merger, acquisition or sale of our business, users' data may be transferred to the new owner. Such a transfer will take place only in compliance with the rules set out in this Privacy Policy. We will inform users of such a change in advance and, where required by law, will enable them to object to the transfer of their data.
9. Transfers of data outside the European Economic Area
Data of particular importance for regulatory compliance, such as the users' consent log and the results of compliance analyses, is processed in Poland, in a data centre located in Warsaw. We entrust its encrypted backups to Cloudflare, Inc., with the data storage location in the European Union. This entrustment is based on Standard Contractual Clauses, supplemented by a declared Data Privacy Framework certification.
The other components of our platform are hosted with providers that may transfer data outside the European Economic Area (EEA).
| What | Where | Transfer basis |
|---|---|---|
| The engine of the cookie management platform, the users' consent log, compliance scan results and the contact mailbox for users | Data processed in Poland, in the OVH data centre located in Warsaw; encrypted backups are kept with a provider whose data storage location is in the European Union | Production data is not transferred outside the European Economic Area (EEA); backups are entrusted to a provider, with the data storage location in the European Union, on the basis of Standard Contractual Clauses (SCC) |
| Customer panel, website, authentication system and user account database | Hosted by Google Ireland Limited, with intra-group transfers to Google LLC in the USA | Main basis: the Data Privacy Framework (a data protection mechanism agreed between the EU and the USA), indicated in the Firebase terms of service; fallback mechanism: Standard Contractual Clauses (SCC), used if the Data Privacy Framework does not apply. |
| CDN (Content Delivery Network), DNS (Domain Name System) and WAF (Web Application Firewall) services, and backups | Provided by Cloudflare, Inc., established in the USA | Standard Contractual Clauses (SCC); declared certification under the Data Privacy Framework (DPF), which is a data protection mechanism agreed between the EU and the USA. |
| Transactional email services | Provided by Plus Five Five, Inc. (Resend), established in the USA | Standard Contractual Clauses (SCC) |
| Payment services | Provided by Stripe Payments Europe, Limited, established in Ireland, with data transfers to Stripe, LLC in the USA | Main basis: the Data Privacy Framework (a data protection mechanism agreed between the EU and the USA); fallback mechanism: Standard Contractual Clauses (SCC), including SCC Modules 1 and 2, used if the Data Privacy Framework does not apply. |
| Analytics and advertising tools (activated after the user gives consent) | Provided by Google, Meta and LinkedIn, through subsidiaries established in Ireland, with data transfers to the USA | Main basis: the Data Privacy Framework, in which, as at the date of publication, Google LLC, Meta Platforms, Inc. and LinkedIn Corporation are listed; fallback mechanism: Standard Contractual Clauses (SCC), used if the Data Privacy Framework does not apply. |
Personal data is transferred outside the European Economic Area (EEA) on the basis of the following legal mechanisms: a European Commission adequacy decision (Article 45 GDPR): for providers that have joined the EU-US Data Privacy Framework (as at the date of publication, these are Google LLC, Meta Platforms, Inc. and LinkedIn Corporation), the transfer of data to the USA is based on this decision; Standard Contractual Clauses (SCC) adopted by the European Commission (Article 46(2)(c) GDPR): used as a fallback mechanism where a provider has not joined the Data Privacy Framework. These clauses may be supplemented by additional safeguards resulting from a transfer impact assessment (TIA).
You have the right to obtain a copy of the safeguards applied to the transfer of your data outside the European Economic Area (EEA). To do so, contact us by email at kontakt@cookieofficer.pl.
Despite these safeguards, the transfer of data to third countries may involve the risk of access to the data by the authorities of those countries under local law (e.g. FISA 702 in the USA) and potentially narrower legal remedies than those available in the EU.
10. Cookies on our Website
We use cookies and related technologies (e.g. localStorage, tracking pixels), which we divide into different categories depending on their function and purpose.
| Category | What they are used for | Legal basis |
|---|---|---|
| Necessary | Proper functioning of the website; ensuring secure use of the website; maintaining the user's login session; remembering your decision in the cookie banner (e.g. acceptance or rejection); protecting forms against automated abuse: reCAPTCHA v3 runs on pages with forms, analyses information from your device and sends your IP address and data on your behaviour in the browser to Google. | Article 6(1)(f) GDPR (the controller's legitimate interest). Cookies in this category do not require the user's consent, because they are necessary to provide a service by electronic means that the end user has explicitly requested. This is in line with the exception set out in Article 399(3)(2) of the Electronic Communications Law. |
| Functional | Remembering the user's preferences, such as the selected language of the website. | The user's consent (Article 6(1)(a) GDPR); you can withdraw consent at any time by changing the settings in the cookie banner or in your browser settings. |
| Analytics | Measuring traffic on the website (e.g. the number of visits, the traffic source); analysing how users use the website (e.g. time spent on the website, subpages visited). | The user's consent (Article 6(1)(a) GDPR); you can withdraw consent at any time by changing the settings in the cookie banner or in your browser settings. |
| Marketing | Measuring the effectiveness of advertising campaigns; remarketing (displaying ads to users who have previously visited the website); targeted advertising (matching ads to the user's interests) with our advertising partners. | The user's consent (Article 6(1)(a) GDPR); you can withdraw consent at any time by changing the settings in the cookie banner or in your browser settings. |
Storing information, and gaining access to information already stored, in your terminal equipment takes place on the basis of Article 399(1) of the Electronic Communications Law, with your consent, except in the situations indicated in Article 399(3) of that Law, where this is necessary for the transmission of a communication or for the provision of a service explicitly requested by you. We base the processing of personal data that follows such access on Article 6(1)(a) or (f) GDPR, depending on the category of cookies, as indicated above.
We activate cookies other than necessary ones only after you give consent. You can change or withdraw your consent at any time using the “Cookie settings” link in the website footer. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
You can also manage cookies in your browser settings (e.g. Chrome, Firefox, Safari, Edge; each browser has a privacy section). Blocking cookies that are necessary for the website to work may prevent you from using some of the website's features, such as access to the Account.
If you consent to marketing cookies, data about your activity on our website, such as the advertising identifier and subpages visited, may be passed on to our advertising partners in order to show you personalised ads on other websites.
We remember your cookie consent decision for 12 months. After that time, we will ask you for consent again. We may ask earlier only if the scope of the cookies we use changes.
The current list of all cookies in use (together with their retention periods and providers) can be found in the cookie banner, in the tab labelled “Details”. This list is generated automatically by our internal scanner.
11. Automated decision-making and profiling
We do not make decisions about you based solely on automated processing of data that would produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. In our product we use automatic classification of cookies, but it applies only to tracking technologies, not to people: algorithms assign a category and a vendor on the basis of the name, domain and signatures, and these results are marked with their source and can be modified manually.
12. Your rights
To the extent that we are the controller of your data, you have the right to:
| Right | Basis | What it means |
|---|---|---|
| Access to data and obtaining a copy of it | Article 15 GDPR | You can request information about what data of yours we process, for what purpose, to whom we disclose it and for how long it is stored. You also have the right to receive a copy of your data in a commonly used format (e.g. JSON, CSV). |
| Rectification of data | Article 16 GDPR | If the data about you that we process is inaccurate or incomplete, you can request that it be corrected or completed. |
| Erasure of data (“right to be forgotten”) | Article 17 GDPR | You can request the erasure of your data if there is no legal basis for its further processing (e.g. consent has been withdrawn and there is no other purpose of processing). Exceptions: we will not erase data if we are required to store it because of legal obligations (e.g. tax obligations) or the need to pursue claims. |
| Restriction of processing | Article 18 GDPR | You can request that the processing of your data be suspended, for example while its accuracy is verified, if you contest its accuracy or believe that the processing is unlawful. |
| Data portability | Article 20 GDPR | You can request that we provide your data in a structured, commonly used and machine-readable format (e.g. JSON, CSV) or transmit it directly to another controller, where this is technically feasible. |
| Objection to processing | Article 21 GDPR | You can object to the processing of your data: in the case of direct marketing, you can always object, and we will stop the processing immediately; in other cases (e.g. when we process data on the basis of legitimate interest), you can object to the processing on grounds relating to your particular situation. We will consider your objection and stop the processing unless we demonstrate compelling legitimate grounds for further processing. |
| Withdrawal of consent | Article 7(3) GDPR | If we process your data on the basis of consent, you can withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing carried out before its withdrawal. |
To exercise your rights, send a request to kontakt@cookieofficer.pl. We will respond within one month, and in complex cases we may extend this period by a further 2 months, informing you of the reasons. Requests are handled free of charge, unless they are manifestly unfounded or excessive, in which case we may charge a fee or refuse. We may also ask for additional information to verify your identity. If you have doubts about whether the processing complies with the law, you have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw). If we are the processor, address your requests to the owner of the website on which your data was collected, and we will support them in fulfilling the requests.
13. Data security
We apply technical and organisational measures appropriate to the level of risk. They include: encryption in transit (TLS 1.2+) on all connections to our Website and to the engine of the cookie management platform (CMP); data minimisation at source: we do not record the full values of cookies (we store only a masked fragment that makes it possible to recognise the format), and we do not store full IP addresses in the consent log or full payment card details; secure password storage: passwords are stored only as cryptographic hashes. Authentication is provided by Firebase Auth, and we have no access to passwords in plain text; separation of environments: the production and test environments are separated from each other, and production data is not used in testing; local data storage: we store the consent log and scan results in Poland, and their encrypted backups with a provider whose data storage location is in the European Union, on the terms described in section 9; confidentiality obligations: all persons with access to the data are obliged to keep it confidential.
Personal data breaches. In the event of a personal data breach that poses a risk to the rights and freedoms of individuals, we report it to the President of the Personal Data Protection Office (UODO) within 72 hours, in accordance with Article 33 GDPR. If the risk is high, we also inform the data subjects, in accordance with Article 34 GDPR.
Where we act as a processor, we notify our customer without undue delay, in accordance with the time limits set out in the data processing agreement (DPA).
Reporting suspected security vulnerabilities. Suspected security vulnerabilities can be reported to kontakt@cookieofficer.pl. We do not take legal action against persons acting in good faith who: report the vulnerability only to this address; do not access other users' data; do not disrupt the operation of our services; do not publicly disclose the vulnerability before it has been fixed.
14. Children's data
Our service is aimed at businesses and is not intended for persons under the age of 16. We do not knowingly collect children's data. If we learn that we have obtained such data without the required consent, we will delete it without delay.
If you are a parent or guardian and suspect that your child has provided us with their data, please contact us at kontakt@cookieofficer.pl.
We do not process the special categories of personal data referred to in Article 9 GDPR, or data relating to criminal convictions (Article 10 GDPR). Please do not send us such data in your requests.
15. Voluntary provision of data
Providing data is voluntary, but without the data marked as mandatory you will not be able to create an account or conclude a contract with us. Without billing data we will not be able to issue an invoice or activate a paid plan, and without an email address we will not be able to reply to your enquiry or send you the newsletter.
16. Links to external websites
Our Website may contain links to third-party websites, such as documentation, social media or our partners' materials. We are not responsible for their privacy policies; we encourage you to read them separately.
17. Changes to the Privacy Policy
We reserve the right to update this Policy, for example in the event of changes in the law, the launch of new features or a change of processor. Each version will be marked with its effective date and number, and we will make previous versions available on request; simply write to kontakt@cookieofficer.pl. We will inform registered users by email of material changes, such as an extension of the purposes of processing, new categories of data recipients or a change of controller, before they take effect, at least 14 days in advance. Editorial changes and clarifications will take effect immediately upon publication.
18. Contact
| Matter | How to contact us |
|---|---|
| Data protection rights | If you have questions or want to exercise your data protection rights, write to us at: kontakt@cookieofficer.pl. |
| Security vulnerability reports | For reports concerning potential security vulnerabilities, please also contact us at the same address: kontakt@cookieofficer.pl. |
| General and commercial matters | For general and commercial matters, you can contact us at the same address: kontakt@cookieofficer.pl. |
| Correspondence in English | If you prefer to communicate in English, write to: contact@cookieofficer.com. |
| Data processing agreement (DPA) and Terms of Service | Documents such as the data processing agreement (DPA) and the terms of service can be found on our website: cookieofficer.pl/umowa-powierzenia and cookieofficer.pl/regulamin. |
| Postal correspondence | For postal correspondence, please send letters to: Wojciech Bednarski DataWolves, ul. Fabryczna 3/9, 97-545 Wojciechów, Poland. |