Legal

Privacy and Cookies Policy

This version of the Policy applies from 21 August 2026. The Polish-language version is the legally binding text; this translation is provided for convenience.

General information

This document sets out the rules for processing personal data on the website https://complywiser.com/

Capitalised terms used in this Privacy Policy have the following meanings:

  • Personal Data
    information about an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person,
  • Cookies
    means IT data, in particular small text files, saved and stored on devices through which the User uses the Service's website,
  • Controller's Cookies
    means Cookies placed by the Controller, related to the provision of electronic services by the Controller through the Service,
  • Third-Party Cookies
    means Cookies placed by the Controller's partners, through the Service's website,
  • Profiling
    means a form of automated processing of personal data consisting of using personal data to evaluate certain personal factors of a natural person, in particular to analyse or predict aspects concerning personal preferences and interests,
  • Service
    the website https://complywiser.com/,
  • User
    any person visiting the Service using a computer, tablet, phone or other mobile device and the Internet.
  • Personal data collected by the Controller is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 119, p. 1), hereinafter: GDPR.

    The Controller ensures an appropriate level of protection for Users' privacy and the data entrusted to it. To this end, it implements adequate technical, IT and organisational measures that effectively protect the processed information against unauthorised access, leakage, loss, damage, unauthorised modification, and unlawful processing.

    Services provided through the Service are addressed to adults with full legal capacity.

    Personal data

    Data Controller (hereinafter the Controller)

    The Controller of the Service is COMPLYWISER spółka z ograniczoną odpowiedzialnością (a Polish limited liability company), with its registered office in Wrocław at ulica Na Ostatnim Groszu 3, 54-207 Wrocław, entered in the Register of Entrepreneurs of the National Court Register under number 0001083620, kept by the District Court for Wrocław-Fabryczna in Wrocław, VI Commercial Division of the National Court Register, Tax Identification Number (NIP): 5273095019, National Business Registry Number (REGON): 527542836.

    The User may contact the Controller:

    1. Postal address: ul. Na Ostatnim Groszu 3, 54-207 Wrocław, Poland
    2. Email address: hello@complywiser.com

    Purposes and legal bases for processing personal data

    The Controller processes personal data provided or made available by the User in connection with use of the Service, for the purposes of:

    1. taking steps prior to entering into a contract at the User's request, including handling enquiries submitted through the contact form (data scope: first name, last name, email address, phone number, Telegram identifier, and other data provided in the content of the message) — pursuant to Article 6(1)(a) GDPR;
    2. concluding and performing a contract, in particular one relating to the provision of legal assistance services (data scope: first name, last name, company, NIP number, PESEL number, residential/registered address, email address, phone number) — pursuant to Article 6(1)(b) GDPR;
    3. conducting marketing and promotional activities (data scope: any data obtained from the User) — pursuant to Article 6(1)(f) GDPR;
    4. fulfilling legal obligations incumbent on the Controller in connection with conducting business activity (data scope: any data obtained from the User) — pursuant to Article 6(1)(c) GDPR;
    5. establishing, pursuing and enforcing claims, and defending against claims (data scope: data indicated in points 1 or 2 above, and any data obtained from the User necessary to prove the existence of a claim or to defend rights) — pursuant to Article 6(1)(f) GDPR.

    Data retention period

    Users' personal data is stored only for the period necessary to achieve the following purposes:

    1. data processed for the purpose of taking steps prior to entering into a contract at the User's request — for the duration of the correspondence/contact, and after its conclusion, for the limitation period of claims arising from the pre-contractual actions;
    2. data processed for the purpose of concluding and performing a contract — for the duration of the contract, and after its termination, for the limitation period of claims arising from the contract;
    3. data processed for the purpose of conducting marketing and promotional activities:
      1. where processed on the basis of consent — until the consent is withdrawn by the User,
      2. where processed on the basis of a legitimate interest — until an effective objection is raised.
    4. data processed for the purpose of fulfilling legal obligations incumbent on the Controller — for the period required by law;
    5. data processed for the purpose of establishing, pursuing and enforcing claims, and defending against claims — until the expiry of the limitation period for the relevant claims or, if proceedings have been initiated, until their final conclusion.

    Upon expiry of the above periods, personal data is deleted.

    Lawfulness of processing

    The Controller processes personal data in accordance with the law, for specified and lawful purposes, and to the extent necessary to achieve them.

    The Controller does not process special categories of personal data.

    The Controller makes every effort to protect Users' personal data against unauthorised access by third parties and, to this end, applies organisational and technical security measures at a high level. The Controller does not disclose personal data to any recipients not authorised to receive it under mandatory applicable law. The Controller may entrust the processing of personal data to another entity, on the Controller's behalf, under a written agreement. Data may be disclosed to entities authorised to receive it under mandatory applicable law.

    Voluntary provision of personal data

    Depending on the purpose of processing, the provision of personal data may be:

    1. a condition for concluding a contract — in such cases, failure to provide personal data will prevent the Controller from providing the service;
    2. a contractual requirement — in such cases, provision of personal data is mandatory only in relation to data marked as such. Provision of other personal data is voluntary;
    3. voluntary.

    Recipients of personal data

    The Controller's business activity requires the transfer of personal data to other business entities and state institutions. Accordingly, the Controller may share data collected from Users with entities including, in particular: employees, associates, entities providing legal services to the Controller, IT support providers, online payment system operators, and the accounting firm handling the Controller's bookkeeping.

    In such cases, the amount of data transferred is limited to the required minimum. In addition, information provided by Users may be disclosed to competent public authorities if required by applicable law.

    Processed personal data is not disclosed externally, to recipients other than those indicated above, in a form allowing identification of Users, unless the User has consented to this.

    The User's personal data will not be transferred outside the European Economic Area (EEA).

    Rights of the data subject

    The User has the right to:

    1. request access to their personal data (Art. 15 GDPR);
    2. request rectification/completion of their personal data (Art. 16 GDPR);
    3. request erasure of their personal data (Art. 17 GDPR);
    4. request restriction of processing of their personal data (Art. 18 GDPR);
    5. request portability of their personal data (Art. 20 GDPR);
    6. object to the processing of their personal data on grounds relating to their particular situation (Art. 21 GDPR);
    7. withdraw consent given (on the basis of Art. 6(1)(a) GDPR) at any time, provided that withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal (Art. 7 GDPR);
    8. lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office (Art. 77 GDPR).

    To exercise the above rights, the User may send an appropriate request by email to: hello@complywiser.com.

    The Controller provides information on the actions taken in response to a request submitted by the User without undue delay, and in any event within one month of receiving the request. If necessary, this one-month period may be extended by a further two months, taking into account the complexity of the request or the number of requests. In such a case, the Controller will inform the User of the extension within one month of receiving the request, stating the reasons for the delay.

    Automated decision-making, including profiling

    In order to provide Users with the most favourable and personalised communication or offer, and for purposes necessary for the conclusion or performance of a contract between the data subject and the Controller, as well as in the case of the data subject's explicit consent, the Controller may apply Profiling.

    The Controller does not make decisions based solely on automated processing that significantly affect the data subject. The Controller implements appropriate measures to protect the rights, freedoms and legitimate interests of the data subject, including at least the right to obtain human intervention from the Controller, to express their own point of view, and to contest a decision resulting from automated processing of data.

    "Cookies" files

    General information

    While browsing the Service, "cookies", hereinafter referred to as Cookies, are used — small pieces of text information saved on the User's end device in connection with use of the Service. Their use is intended to ensure the correct functioning of the Service.

    These files allow the software used by the User to be identified and the Service to be adapted individually to the User's needs.

    "Cookies" usually contain the name of the domain from which they originate, their storage time on the device, and an assigned value.

    Security

    The "cookies" used by the Controller are safe for the User's devices. In particular, it is not possible for viruses or other unwanted or malicious software to enter the User's devices through "cookies".

    Types of "cookies" and purposes of their collection

    The Controller uses two types of cookies:

    1. Session Cookies — stored on the User's device and remain there until the end of the browser session. The saved information is then permanently deleted from the User's device memory. The session cookie mechanism does not allow the collection of any personal data or confidential information from the User's device;
    2. Persistent Cookies — stored on the User's device and remain there until deleted. Ending the browser session or turning off the device does not delete them from the User's device. The persistent cookie mechanism does not allow the collection of any personal data or confidential information from the User's device.

    The following categories of cookies are used within the Service, in particular:

    1. necessary cookies, i.e. those required for the proper functioning of the Service;
    2. functional cookies, i.e. those that allow settings selected by the User (e.g. preferred language) to be remembered, in order to adapt the way the Service is displayed to individual preferences resulting from previous visits;
    3. analytical cookies, i.e. those that allow the Controller to understand how Users use the Service; collected after consent has been given;
    4. marketing cookies, i.e. those that allow the Controller to measure the effectiveness of campaigns and remarketing; collected after consent has been given.

    Using the settings of a web browser, or a service configuration, the User may independently and at any time change settings relating to Cookies, determining the conditions for their storage and access by Cookies to the User's device. The User may change these settings so as to block automatic handling of Cookies in browser settings, or to be informed each time Cookies are placed on the User's device. Detailed information on the possibilities and methods of handling Cookies is available in the settings of the User's software (web browser).

    Legal basis for the use of cookies and consent

    Cookies necessary for the proper provision of services and functioning of the Service are used pursuant to the Act of 12 July 2024 — Law on Electronic Communications, and do not require the User's consent.

    Other cookies, in particular analytical, statistical and marketing cookies, including third-party cookies, are used only after the User has given prior, voluntary consent via the consent management mechanism (cookie banner) displayed on the first visit to the website. Until consent is given, these files are not saved on the User's device.

    The User may change the scope of, or withdraw, consent given at any time — without affecting the lawfulness of processing carried out before its withdrawal — using the settings of the consent management mechanism available on the website. The legal basis for processing personal data resulting from cookies used with consent is Art. 6(1)(a) GDPR.

    Final provisions

    This Policy is reviewed on an ongoing basis and updated as necessary. The current version of the Policy was adopted and applies from 21 August 2026.

    The Controller is entitled to change this document, and the User will be notified in a manner enabling them to review the changes before they take effect, e.g. by posting relevant information on the main pages of the Service.

    Continued use of the Service after publication or dispatch of a notice of changes to this document is considered acceptance of the collection, use and disclosure of the User's personal data in accordance with the updated content of the document.

    This document does not limit any rights to which the User is entitled under generally applicable law.