Privacy Policy (GDPR)
Last updated: 23 X 2025
1) Controller
TriIT Bartlomiej Siwek
Radawiec Duży 10a, 21-030 Motycz, Poland
VAT-EU: PL712-28-27-365
Email: Contact@TriIT.eu
We have not appointed a Data Protection Officer. For any privacy matter, contact us at the email above.
2) What personal data we process via this website
Contact data submitted via forms or email (e.g., name, work email, company, role, phone, message content, preferred meeting time, and any files you choose to attach).
Booking data if you schedule a call (meeting subject, name, email, proposed times).
Technical data in security logs created by our server (IP address, date/time, URL, user-agent) for uptime and abuse-prevention.
Contract/billing data (only if you become our client; processed in our accounting records).
We do not knowingly collect special categories of data, nor children’s data. This site targets business users (B2B).
3) Purposes and legal bases (Art. 6 GDPR)
Handling enquiries / pre-contract steps (responding to messages, scheduling a call).
Legal basis: Art. 6(1)(b) GDPR (contract / steps prior).
Providing services to clients (negotiation, delivery, invoicing, archiving).
Legal basis: Art. 6(1)(b) GDPR; for tax/archival duties also Art. 6(1)(c) GDPR.
Operating and securing the website (security logs, availability, incident diagnostics).
Legal basis: Art. 6(1)(f) GDPR (legitimate interests).
Cookies/analytics: we do not use analytics or marketing cookies. If we enable such tools in the future, we will ask for opt-in consent first and provide details in our Cookies Policy, in line with EU ePrivacy/GDPR requirements.
4) Source of data
Directly from you (forms, email, booking).
Technical data from your browser is generated automatically when visiting the site.
5) Processors (service providers)
We use only vendors necessary to run this site and communications. Each acts as our processor under a Data Processing Agreement (DPA).
- Web hosting & server administration: home.pl S.A. (website hosting for triit.eu).
- Online booking: Microsoft Bookings (Microsoft 365) in our organization.
- Email service: business mailbox for Contact@TriIT.eu (part of our Microsoft 365 tenant).
We disclose additional vendors (if any) in the Cookies Policy or upon request.
6) International transfers
We aim to keep processing within the EEA. With Microsoft 365 services used for Bookings and email, personal data is stored and processed within Microsoft’s EU Data Boundary for enterprise online services (subject to Microsoft’s service documentation). If exceptionally a transfer outside the EEA were necessary, we would use a permitted transfer mechanism (e.g., Standard Contractual Clauses) and appropriate safeguards; you can request details at any time.
7) Retention
Enquiries (email/form/booking): up to 12 months from last contact, unless you request earlier deletion (unless we must keep data to establish/exercise/defend legal claims).
Contracts, invoices, accounting: for the statutory retention period required by law.
Security logs: up to 12 months (or shorter if no longer needed).
8) Your rights (Art. 12–22 GDPR)
You have the right to access, rectify, erase, restrict, portability, object, and to withdraw consent at any time (if consent is used). To exercise rights, email Contact@TriIT.eu.
You can lodge a complaint with your supervisory authority. In Poland: President of the Personal Data Protection Office (UODO/PUODO). EU guidance on data protection rights is available on the European Commission portals.
9) Security
We apply HTTPS/TLS, MFA for admin access, least-privilege roles, regular updates, and backups. We assess and mitigate incidents promptly; where risks arise to your rights and freedoms, we notify per GDPR.
10) Automated decision-making
We do not use automated decision-making, including profiling, that produces legal or similarly significant effects.
11) Mandatory vs. optional data
Providing basic contact data is necessary to respond to your enquiry or schedule a meeting. All non-essential cookies/analytics (currently none) are optional and would require your opt-in.
12) Third-party links
Our website may link to third-party sites. Their privacy practices are outside our control; review their privacy policies.
13) Changes to this Policy
We may update this Policy when we change tools or legal requirements. The latest version is always on this page; the “Last updated” date shows the current version.
Contact
Questions about privacy: Contact@TriIT.eu