Privacy policy

How we process your personal data under GDPR.

1. Data controller

The controller of your personal data is TreffikAI (hereafter: "we", "us"). Contact: privacy@treffikai.com.

2. What data we collect

  • Server logs: IP address, browser type, timestamp (Art. 6(1)(f) GDPR — legitimate interest: site security).
  • Newsletter data: email address, first name (optional), signup date (Art. 6(1)(a) GDPR — consent).
  • Contact form data: name or organization, email address, subject and message content (Art. 6(1)(f) GDPR — legitimate interest: handling correspondence).
  • Cookies: see the Cookie policy.

3. Purposes

  • Deliver content and newsletter.
  • Handle messages sent through the contact form.
  • Aggregate anonymised analytics.
  • Prevent abuse and protect security.

4. Retention

  • Server logs: 30 days.
  • Newsletter addresses: until consent is withdrawn.
  • Contact messages: for as long as needed to handle the request, then up to 12 months for administrative and evidence purposes.

5. Your rights

You have the right to access, rectification, erasure, restriction, portability, objection, and to withdraw consent at any time. You may also lodge a complaint with the Polish Data Protection Authority (UODO).

6. Recipients

Data may be entrusted to processors (hosting, email delivery provider) under data processing agreements.

7. Transfers outside the EEA

We do not transfer data outside the European Economic Area without safeguards required by GDPR (standard contractual clauses).

8. Changes

We may update this policy. The date of the last update is shown above.