Privacy Policy
Last updated: 25 June 2026
1. Data controller
The controller of personal data collected through devsentinel.pl is devsentinel Krzysztof Jaroński, ul. Wiosenna 22 lok. 1, 83-032 Skowarcz, Poland, tax ID (NIP): 9571051805 (the “Controller”).
For data protection matters, contact the Controller at kontakt@devsentinel.pl or via the contact form on the homepage.
2. Scope and purposes of processing
2.1. Contact form and email correspondence
When you submit the contact form or email us, we process the data you provide: name, email address, phone number (if provided — this field is optional) and message content.
Purpose: responding to your inquiry, preparing an offer or establishing cooperation.
Legal basis: your consent (Art. 6(1)(a) GDPR) — given via the form checkbox — and the Controller’s legitimate interest in handling correspondence (Art. 6(1)(f) GDPR) when you contact us directly by email.
2.2. Offer assistant (on-site chatbot)
The interactive assistant on the homepage collects answers only in your browser during the current session. After the conversation, answers may be inserted into the contact form message field — they are then processed like form data (section 2.1), after your consent to submit the form.
The assistant does not require registration or login and does not store conversations on the Controller’s server.
2.3. IT security quiz
The self-assessment quiz runs locally in your browser. Results are not automatically sent to the Controller — unless you choose to contact us (e.g. via the form) and describe your situation.
2.4. Technical data and logs
When using the site, technical data necessary for operation and security may be processed: IP address, date and time of request, browser type, operating system, visited URL.
Purpose: ensuring proper site operation, error diagnostics, abuse prevention.
Legal basis: legitimate interest of the Controller (Art. 6(1)(f) GDPR).
3. Retention period
Contact form and correspondence data are kept for as long as needed to respond and handle the inquiry, no longer than 24 months from the last contact, unless you withdraw consent or object earlier.
After that period, data is deleted or anonymised unless law requires longer retention.
Technical logs are kept as long as necessary for security purposes — typically up to 12 months.
4. Your rights
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), object (Art. 21), and lodge a complaint with the Polish Data Protection Authority (UODO).
Where processing is based on consent, you may withdraw it at any time by contacting the Controller. Withdrawal does not affect the lawfulness of processing before withdrawal.
5. Recipients and subprocessors
Data may be entrusted to entities supporting the Controller, under GDPR-compliant agreements:
| Entity | Purpose | Location / EEA |
|---|---|---|
| EmailJS | Delivering contact form messages to the Controller’s email | USA (SCC) |
| Google Analytics | Traffic analytics — only after analytics cookie consent | USA (SCC) |
| Hosting provider | Website hosting, server logs | Poland / EEA |
Data is not sold or shared with third parties for marketing. Public authorities may access data where required by law.
6. Transfers outside the EEA
We use services of entities located outside the European Economic Area (e.g. EmailJS, Google). Transfers comply with GDPR requirements — in particular Standard Contractual Clauses (SCC) or other lawful mechanisms.
8. Security
We apply technical and organisational measures appropriate to the risk (including HTTPS, access restrictions, contractor agreements). In case of a personal data breach, we act in accordance with Arts. 33–34 GDPR.
9. Policy changes
This policy may be updated due to legal or operational changes. Material updates will be announced on devsentinel.pl. The current version is always available at this address.
10. Contact
For personal data matters: kontakt@devsentinel.pl or the contact form on the homepage (Contact section).