This policy explains how the joint controllers process the personal data of users of the Inviterra brand website available at inviterra.pl (hereinafter: the “Website”), in particular data provided via the contact form and data collected using cookies and similar technologies.
The policy has been prepared in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”), the Polish Personal Data Protection Act, and the Act of July 12, 2024 – Electronic Communications Law (“ECL”).
2. Joint Data Controllers
The joint controllers of personal data processed in connection with operating the Website and the activities of the Inviterra brand are:
- PR EXPERT Group spółka komandytowa with its registered office in Wrocław, ul. Przestrzenna 48/3, 50-533 Wrocław, Poland, entered into the Register of Entrepreneurs of the National Court Register (KRS) under number 0000649831, NIP (Tax ID): 8971828355, REGON: 365343792;
- Marek Dąbrowski, conducting business activity under the business name MD Marek Dąbrowski, ul. Boiskowa 21/11, 52-126 Wrocław, Poland, NIP (Tax ID): 6922390515, REGON: 368334977.
The joint controllers jointly develop the Inviterra brand and jointly determine the purposes and primary means of processing personal data obtained through the Website.
3. Joint Controllers’ Arrangements
The joint controllers have concluded the arrangements required by Article 26 of the GDPR. Under these arrangements, they are jointly responsible, in particular, for the lawfulness of processing, fairness and transparency, data security, proper retention, handling personal data breaches, and facilitating the exercise of data subject rights.
Each user may exercise their rights against each of the joint controllers. To facilitate contact, the joint controllers have designated a joint point of contact: info@marekdabrowski.com.
The joint controllers may also be contacted by postal mail at their addresses indicated in Section 2. Using the joint point of contact does not limit the right to contact any joint controller directly.
4. What Data We Process and Where We Obtain It
We obtain data primarily directly from the user and automatically during the use of the Website, to the extent depending on consent settings.
- Data provided in the contact form: name and surname, e-mail address, and telephone number.
- Data contained in the message content and subsequent correspondence, if provided by the user.
- Data regarding consents and preferences, including the date, scope, and method of granting or withdrawing consent.
- Technical data related to the use of the Website, such as cookie identifiers, online identifiers, device and browser information, approximate location derived from the IP address, visit time, traffic source, and usage patterns.
- Data regarding reactions to advertisements and events measured by Google and Meta tools, if the user has given appropriate consent.
5. Purposes and Legal Bases for Processing
| Purpose | Scope | Legal Basis |
|---|---|---|
| Handling the form, contact, and presenting an offer | Form data and correspondence | Article 6(1)(b) GDPR – steps prior to entering into a contract at the request of the user; in other cases, Article 6(1)(f) GDPR – legitimate interest in handling inquiries and conducting business communication. |
| Sending commercial information and direct marketing via e-mail, phone, or SMS | Contact details, scope of consents, and communication history | Article 6(1)(a) GDPR and Article 398 ECL – prior consent of the user. Communication is conducted exclusively via channels covered by consent. |
| Website analytics and performance improvement | Technical data, identifiers, and activity information | Article 6(1)(a) GDPR in conjunction with Article 399 ECL – consent to analytical cookies or similar technologies. |
| Ad performance measurement, remarketing, and ad personalization | Identifiers, information about visits, events, and reactions to ads | Article 6(1)(a) GDPR in conjunction with Article 399 ECL – consent to marketing cookies or similar technologies. |
| Ensuring Website security, diagnostics, and fraud prevention | Server logs and basic technical data | Article 6(1)(f) GDPR – legitimate interest in protecting the Website and its users; regarding strictly necessary technologies, also Article 399(3) ECL. |
| Establishment, exercise, or defense of legal claims and demonstrating compliance | Correspondence, consent history, and case-related data | Article 6(1)(f) GDPR – legitimate interest in protecting the rights of the joint controllers and demonstrating compliance with the law. |
6. Voluntary Provision of Data
Providing data in the form is voluntary; however, failure to provide data marked as required will prevent submitting the form, receiving a response, or presenting an offer. Consent to commercial communication is voluntary and cannot be a condition for receiving a response to an inquiry unrelated to marketing.
7. Data Recipients
Access to data provided in the form is granted to the joint controllers and individuals acting under their authority. Data is not sold or shared with external commercial partners for their own purposes.
Notwithstanding the above, in connection with the technical operation of the Website, data recipients or data processors may include:
- the hosting provider, server, electronic mail, backup providers, and the entity technically maintaining the Website – to the extent necessary to provide these services;
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google group entities – in connection with Google Analytics and Google Ads;
- Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland, and Meta group entities – in connection with Meta Pixel and Meta advertising services;
- public authorities or other authorized entities, if the obligation to disclose data arises under applicable law.
The joint controllers do not share data entered into the form, such as name, surname, e-mail, or telephone number, with Google or Meta, unless an additional feature is implemented in the future, e.g., advanced conversion tracking or Conversions API. In such a case, the policy and consent configuration require prior updating.
8. Data Transfers Outside the European Economic Area
The use of Google and Meta services may involve accessing or transferring data outside the European Economic Area, in particular to the United States. Depending on the recipient and the type of transfer, the legal basis may be an adequacy decision by the European Commission under the EU-US Data Privacy Framework, or standard contractual clauses approved by the European Commission, supplemented where necessary by additional safeguards.
Information regarding the applied safeguards and the possibility of obtaining a copy thereof can be obtained by contacting the joint controllers.
9. Data Retention Period
- Data provided in the form and subsequent correspondence are retained for a period of up to 3 years from the date of collection, unless the purpose of processing ceases earlier or the data is needed longer in connection with entering into a contract, a legal obligation, or claims.
- Data used for commercial communication is processed until consent is withdrawn, an effective objection is raised, or 3 years have elapsed since granting consent – whichever occurs first.
- Minimal information regarding consent withdrawal or objection may be retained longer if necessary to demonstrate compliance with the law and prevent re-use of data for marketing.
- Analytical data available at the user level in Google Analytics is retained for no longer than 14 months. Aggregated reports that do not allow the joint controllers to identify the user may be stored longer.
- Data related to cookies and advertising is stored according to the lifetime of the given identifier, user settings, and Google and Meta policies. Current lifespans of individual cookies are visible in the consent management panel.
10. Profiling and Automated Decision-Making
In connection with Google Ads and Meta Ads services, activity data may be used to build audience segments, measure conversions, conduct remarketing, and tailor ads to user interests. Such activities may constitute profiling.
The joint controllers do not make decisions regarding the user based solely on automated processing that would produce legal effects or similarly significantly affect them within the meaning of Article 22 of the GDPR.
11. User Rights
Within the limits set by the GDPR, the user has the right to:
- access their data and receive a copy thereof;
- rectify inaccurate data and complete incomplete data;
- erasure of data;
- restriction of processing;
- data portability, where processing is based on consent or contract and is carried out by automated means;
- object to processing based on Article 6(1)(f) of the GDPR, including an unconditional objection to direct marketing;
- withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
- lodge a complaint with the President of the Personal Data Protection Office (UODO).
A complaint may be lodged with the President of the Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland. Information on filing complaints is available on the UODO website: https://uodo.gov.pl
A request may be addressed to each of the joint controllers. A response will be provided without undue delay, in principle within one month of receiving the request. In cases provided for by the GDPR, the deadline may be extended by a further two months, of which the user will be informed within the first month.
12. Cookies and Similar Technologies
Cookies are small pieces of information saved on or read from the user’s device while using the Website. Similar functions may also be performed by pixels, tags, and identifiers stored in browser memory.
The Website may use the following categories of technologies:
- strictly necessary – required for the proper operation of the Website, security, handling the form, and remembering consent choices; may operate without consent strictly within the limits of Article 399(3) ECL;
- analytical – used to measure visits and analyze how the Website is used; activated upon obtaining consent;
- marketing – used to measure advertisements, create audience segments, conduct remarketing, and tailor ads; activated upon obtaining consent.
Lack of consent to analytical and marketing cookies should not limit access to the basic functions of the Website. Consent may be withdrawn or modified at any time in the cookie settings panel available on the Website. Withdrawing consent should be as easy as granting it.
13. Google Analytics
The Website uses Google Analytics 4 to compile statistics and analyze how the Website is used. The tool may process, among other things, cookie identifiers, device and browser data, activity information, traffic sources, and approximate location. Google indicates that in Google Analytics 4, IP addresses are neither logged nor stored.
Google Analytics operates as an analytical tool only after obtaining the user’s consent. The joint controllers use it in accordance with the data processing terms provided by Google and configure the tool taking into account available privacy settings.
More information: data protection in Google Analytics
14. Google Ads
The Website uses Google Ads tags to measure campaign effectiveness, track conversions, and – if the feature is enabled – conduct remarketing. Google may combine information from the Website with data associated with the user’s account or other Google services in accordance with user settings and Google policies.
Google advertising and marketing tags are activated upon obtaining consent for marketing technologies.
More information: Google Privacy Policy
15. Meta Ads and Meta Pixel
The Website uses Meta Pixel in connection with campaigns run on Facebook and Instagram. The tool enables ad performance measurement, event tracking, audience creation, and remarketing.
In terms of collecting and transmitting event data via Meta Pixel, the Website joint controllers and Meta Platforms Ireland Limited act as joint controllers within the meaning of Article 26 of the GDPR, in accordance with Meta Business Tools Terms. Meta is responsible for further data processing on the terms set out in its documents.
Meta Pixel is activated upon obtaining user consent for marketing technologies.
More information: Meta Privacy Policy
16. Commercial Communication
Submitting data via the form to receive a response does not automatically imply consent to subsequent marketing. Commercial information may be sent by e-mail, phone, or SMS solely after obtaining prior consent covering the specific communication channel.
Consent may be withdrawn at any time using the contact details of the joint controllers or the opt-out mechanism included in the message. After consent is withdrawn, the given channel will no longer be used for marketing.
17. Data Security
The joint controllers apply appropriate technical and organizational measures tailored to the nature of the data and risk, in particular restricting data access to authorized persons, securing accounts and systems, and ensuring the confidentiality of communications and backups.
18. Changes to the Policy
The policy may be updated in the event of changes in the law, Website functionality, tools used, or the scope of data recipients. The current version will be published on the Website along with the date of the last update. If a change significantly affects users’ rights, the joint controllers will provide appropriate notice.
Date of last update: August 26, 2026.