These rules apply to apply.pl, the enquiry form and any email you send us. They do not extend to personal data held in our clients' own systems while we run their IT. There the client decides how data is used, and we act as a processor bound by a processing contract (in Polish, umowa powierzenia).
Data controller
Apply acts as controller of your personal data. Full identifying details of the controller are available on request sent to the address below. For anything privacy-related there is a single address: office@apply.pl. Messages on this subject are handled by the person responsible for data protection on our team.
Data we hold
Our rule is simple: only details we genuinely need to reply or to deliver what was agreed. Nowhere on the site will you be asked for a national ID number (PESEL), health information or any other special category data.
- Enquiry form - your full name, contact details (the email address or phone number you choose to give), the subject chosen from the list and whatever you write in the message box.
- Technical details captured on sending - the URL you submitted from, plus the IP and user agent string of your browser. They help us filter out spam and spot abuse.
- Working together - contact people on the client side, invoicing details and contract correspondence.
- Support tickets - the problem description, the conversation around it and the engineer's notes on what was done.
Please keep passwords out of the form and out of ordinary email. Credentials for anything we manage travel only over an encrypted channel agreed in advance.
Why we use it
- To answer your question and put together a quote.
- To agree and fulfil an agreement with you or the company you represent.
- To handle support tickets and document what has been done.
- To issue invoices and meet tax and bookkeeping duties.
- To keep the site safe from spam, bots and attack attempts.
- To establish or defend legal claims should a dispute ever arise.
Lawful grounds and storage periods
For every purpose there is a separate lawful ground under GDPR Article 6, and a separate retention period. We keep data only for as long as necessary.
| Why | Lawful ground | Kept for |
|---|---|---|
| Replying to a form or email enquiry | Article 6(1)(b) GDPR (steps taken before signing) and Article 6(1)(f) (our legitimate interest in answering someone who wrote to us) | For as long as needed to deal with the enquiry and any follow-up, or until a valid objection |
| Delivering the contract and handling tickets | Article 6(1)(b) GDPR (the contract is being carried out) | For the life of the contract, then until the limitation period for claims expires |
| Invoicing and bookkeeping | Article 6(1)(c) GDPR (a duty imposed by tax and accounting law) | As long as tax law requires |
| Keeping spam and abuse out | Article 6(1)(f) GDPR (our legitimate interest in a secure site) | IP and user agent: for as long as needed to detect abuse and keep the site secure |
| Preferences stored in your browser | Essential for the site to function | Until you delete them |
Cookies and local storage
There is no analytics tool, advertising pixel or tracking cookie here. The site sets just two cookies: one to hold your session and one that protects the form against CSRF attacks. Without them an enquiry cannot be sent, and your browser discards both once the session ends.
Three small preferences also sit in your browser's localStorage: the city you selected, your theme (light or dark) and a note that you have already dealt with the cookie banner. None of these values reach our server, and you can wipe them from your browser settings whenever you like. Should we ever add analytics, this notice will be revised first and you will be asked for consent.
Who receives your data
We do not sell data or use it for advertising. Access is limited to the few providers we cannot operate without.
- Hosting provider - runs the server behind the website, where form submissions are stored.
- Email provider - hosts the office@apply.pl mailbox and our correspondence.
- Public authorities - only where the law requires it, for instance the tax office during an audit.
Providers process data under data processing agreements and only on our instructions. If any of them were to transfer data outside the European Economic Area, this would happen only with the safeguards required by the GDPR, such as standard contractual clauses.
Deletion and safeguards
Once data is no longer needed for the purposes in the table, we erase it or anonymise it so it can no longer be linked to anyone.
- Only people whose job requires it can open the data.
- We use named accounts and two-factor authentication wherever the system supports it.
- All connections use encryption, and backups live apart from production systems.
- We do not collect fields that are not needed to answer an enquiry or perform a contract.
Your rights
Under the GDPR you can do the following at any time, without giving a reason unless the law asks for one.
- See your data and receive a copy (Article 15).
- Have anything inaccurate or out of date corrected (Article 16).
- Have it erased, often called the right to be forgotten (Article 17).
- Have its use restricted, for example while a disagreement is being resolved (Article 18).
- Take it elsewhere in a machine-readable format (Article 20).
- Object where we rely on our legitimate interest (Article 21).
We respond without undue delay, and no later than one month after receiving your request. Should you believe we are handling your data unlawfully, you have the right to complain to the President of the Polish Personal Data Protection Office (UODO): uodo.gov.pl.
Bookkeeping documents must be kept for the full period set by tax law, so we cannot delete them early, even if you ask. After that we delete them.
Contacting us about your data
Anything about this notice, as well as requests to see, fix or erase your data, goes to office@apply.pl. The mailbox is monitored Monday to Friday, 8:00-18:00 CET. Other ways to reach us are listed on the contact page.