Legal

Privacy Policy

How DSecure.me Sp. z o.o. collects, uses and protects personal data under the GDPR, which third parties process data on our behalf, and how to exercise your rights.

Last updated: 2026-08-25

1. Who is the data controller

The controller of your personal data is DSecure.me Sp. z o.o., with its registered office at ul. Na Grobli 12 bud. L3 pok. 021, 50-421 Wrocław, Poland, entered in the Polish National Court Register (KRS) under number 0000887405, tax identification number (NIP) 8971889380, REGON 38836074600000.

For any question about this policy or about how we handle your data, write to [email protected]. We have not appointed a Data Protection Officer, so enquiries are handled by the management board.

2. What data we collect and why

We collect only what we need to answer you and to deliver the services you ask for.

  • Enquiry data. When you use the contact form or email us, we receive your name, email address, and whatever you choose to put in the message, such as your company name and a description of the system you want tested. Lawful basis: our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR), and steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
  • Client and engagement data. If we work together, we process the contact details of your staff, contractual details, and any information generated during the engagement. Lawful basis: performance of a contract (Art. 6(1)(b) GDPR) and compliance with our legal obligations, including tax and accounting law (Art. 6(1)(c) GDPR).
  • Website analytics. We use Google Analytics to understand which pages are read and how visitors reach the site. This involves cookies and similar identifiers set by Google. Lawful basis: your consent where required, otherwise our legitimate interest in operating and improving the site (Art. 6(1)(f) GDPR).
  • Server and delivery logs. Our hosting and CDN providers process technical data such as your IP address, user agent and requested URL in order to deliver pages and to protect the service from abuse. Lawful basis: legitimate interest in security and availability (Art. 6(1)(f) GDPR).

We do not sell personal data, we do not use it to train machine learning models, and we do not make automated decisions producing legal effects concerning you.

3. Testing data during engagements

Penetration testing can expose personal data held in your systems. We treat that data as a processor acting on your documented instructions, under a written agreement. We work on non-production environments and anonymised data wherever it is technically possible, we retain evidence only for as long as it is needed to demonstrate a finding, and we securely destroy engagement artefacts once the report has been accepted and any retest is complete.

4. Third parties that process data for us

The site and our operations rely on the following processors. Each is bound by its own data processing terms.

  • GitHub, Inc. (GitHub Pages) - hosting and serving the static website.
  • Cloudflare, Inc. - DNS, CDN delivery and protection against abusive traffic.
  • Google Ireland Ltd. (Google Analytics, Google Tag) - website usage analytics.
  • Google Ireland Ltd. (Google Fonts) - delivery of the Inter web font.
  • Zapier, Inc. - hosting the embedded contact form and delivering submissions to us.
  • flagcdn.com - delivery of the language-switcher flag images.

Some of these providers are established outside the European Economic Area. Where that is the case, transfers are made under the European Commission's Standard Contractual Clauses or another transfer mechanism permitted by Chapter V of the GDPR.

5. How long we keep data

  • Enquiries that do not lead to a contract: up to 12 months from the last message.
  • Contractual and accounting records: 5 years from the end of the tax year in which the transaction took place, as required by Polish law.
  • Engagement evidence and reports: for the period agreed in the engagement contract, and by default no longer than 12 months after delivery.
  • Analytics data: according to the retention period configured in Google Analytics.

6. Your rights

Under the GDPR you have the right to access your data, to rectify it, to erase it, to restrict or object to its processing, and to data portability. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out beforehand.

To exercise any of these rights, email [email protected]. We will respond within one month. If you believe we handle your data unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.

7. Cookies

The site uses cookies and similar technologies that are strictly necessary for it to work, plus analytics cookies set by Google Analytics as described above. You can block or delete cookies in your browser settings; the site remains usable without analytics cookies.

8. Security

We apply the technical and organisational measures you would expect from a security company: encryption in transit, least-privilege access to client material, multi-factor authentication on business systems, and internal review of our own infrastructure. No measure is perfect, and we will notify you and the supervisory authority of a personal data breach where the GDPR requires it.

9. Changes to this policy

We update this policy when our processing changes. The current version is always published at this address, with the date of the last change shown at the top.