Privacy and data

Privacy Policy

We explain what data Coderise processes, why they are needed, where they go and what rights people using the website have.

Last updated: August 26, 2026

01

Data controller

The personal data controller is Coderise Michał Ziembiński, a sole proprietorship registered at: Kasprzaka 31A, 01-234 Warszawa, NIP: 9671207017, REGON: 360451815, hereinafter referred to as the "Administrator".

In matters relating to privacy and the exercise of rights, you can contact us at: kontakt@coderise.pl.

02

What data do we process and why

Contact form

Data processed
Name and surname, e-mail address, optional company name, selected subject, message content, confirmation of reading the policy, date and technical identifier of the submission.
Purpose
Receiving an inquiry, providing an answer, preparing a conversation or offer and taking action before concluding a contract.
Legal basis
Art. 6 section 1 letter b GDPR, when the contact concerns activities before concluding a contract at the request of a person, and Art. 6 section 1 letter f GDPR in the field of B2B communication, ensuring security and establishing, pursuing or defending claims.
Retention
Up to 12 months from the end of contact if no cooperation occurs. When the inquiry leads to the conclusion of a contract, the data may be stored for the duration of the contract and the appropriate settlement and limitation period for claims.

The submission is stored in PostgreSQL. It is not automatically copied to the mailbox or the analytics system.

Direct e-mail correspondence

Data processed
Sender's address and name, subject, content, date, information needed to maintain the thread and voluntarily uploaded attachments.
Purpose and basis
Handling correspondence and inquiries pursuant to Art. 6 section 1 letter b or f of the GDPR, depending on the nature of the case.
Retention
As a rule, up to 12 months from the end of contact, and longer if the correspondence is part of the contractual documentation or is needed to protect claims.

Messages remain in the mailbox. The administration panel reads them directly and does not create copies in PostgreSQL.

Website analytics

Data processed
Page views and path without query parameters and address fragments, referrer, language, browser type, operating system, device type, country, screen resolution, page title, and basic performance metrics.
Events
Clicking on the main contact link, clicking on the email address and successfully submitting the form. We do not attach data entered by the user to events.
Purpose and basis
Assessment of the usability, effectiveness of the content and efficiency of the website - legitimate interest of the Administrator, Art. 6 section 1 letter f GDPR.
Retention
Maximum 24 months, unless the data is deleted earlier.

Security and operation of the website

The infrastructure can process the IP address, request time, requested resource, response code, and basic technical information. Standard web server access logging is not currently enabled. Application and container logs are automatically rotated when they reach the configured size.

The basis is Art. 6 section 1 letter f GDPR - ensuring security, reliability and the ability to diagnose errors. Technical data is not used for marketing.

Protected portal

In the case of persons with authorized access to the portal, we process the username, roles and session data necessary for authentication and access protection. The token is stored in the browser session and expires when its validity period or the session ends.

03

Cookies and similar technologies

The public part of the website does not use marketing cookies. The analytical tool does not use cookies or fingerprinting, it respects your settings Do Not Track and does not work on protected portal routes.

After manually changing the language, the public part of the website saves a functional cookie coderise_language for 12 months. It is only used to remember the Polish or English version and is not used for analytics, advertising or tracking.

After signing in to the portal, sessionStorage stores the access token needed to maintain a secure session. It is not used for advertising or cross-site tracking.

If the scope of technologies used changes, this policy and, where required, the consent mechanism will be updated accordingly.

04

Data recipients

Data may be entrusted only to the extent necessary to provide services to the following categories of recipients:

  • hosting, cloud infrastructure and backup providers,
  • the provider maintaining the domain and mailbox,
  • privacy web analytics providers,
  • entities providing technical, legal or accounting support, if necessary,
  • authorized bodies when required by law.

Processors act on the Controller's instructions and under appropriate data-protection terms or agreements.

05

Transfer of data outside the EEA

The application infrastructure and database currently run in the AWS region us-east-1 in the United States. This means that your form data and backup copies may be processed outside the European Economic Area.

AWS uses mechanisms intended for international transfers, including the Data Processing Addendum and standard contractual clauses approved by the European Commission, and participates in the EU-U.S. Data Privacy Framework.

The analytics account is configured in the EU region and the service provider is based in the United States. Any access or further transfer takes place on the basis of appropriate contractual safeguards, in particular standard contractual clauses.

Information about the security measures used or a copy thereof can be obtained by writing to kontakt@coderise.pl.

06

Rights of the data subject

To the extent provided for by the GDPR, you have the right to:

  • access to personal data and a copy of it,
  • rectification of personal data,
  • erasure of personal data,
  • restriction of processing,
  • data portability where processing is based on a contract and carried out by automated means,
  • object to processing based on a legitimate interest.

The request can be sent to kontakt@coderise.pl. You also have the right to lodge a complaint with the President of the Personal Data Protection Office.

Providing data in the form is voluntary, but without fields marked as required it will not be possible to send an inquiry and provide an answer.

07

Automated decisions

The data is not used to make decisions that have legal effects solely in an automated manner, nor is it used for profiling for such purposes. Aggregated analytics do not identify specific individuals.

08

Security, contact and changes

We use technical and organizational measures adapted to the risk, including encrypted connections, limited access to the panel, separation of the application network and the database, and storing secrets outside the application code.

Privacy questions and requests should be sent to kontakt@coderise.pl.

The policy may be updated as website features, suppliers or regulations change. The current version is published at the same address along with its effective date.