Krämer Agency / Privacy
Privacy
policy.
How we use your data when you visit our website or speak to us about a project.
About cookies1. Who is responsible for your data
The data controllers for the Krämer Agency website are: Kordian Pacierpnik and Nathalie Krämer, trading as the civil law partnership Krämer Language Academy spółka cywilna. Krämer Agency is the brand under which we provide brand identity, website and online shop design services.
Postal address: ul. Fizylierów 20A, 04-497 Warszawa. Polish tax identification number (NIP): 9522227115. Business register number (REGON): 521798925.
For personal data enquiries, including requests to exercise your rights, email office@kraemeragency.com or write to the postal address above.
2. The data we receive
When you submit a brief, we receive the first name or full name, email address, selected services and description of your project’s purpose that you provide. You may also include a phone number, company name, website address, and details of your audience, scope, required features, references, budget, timing and any further comments. We also record your acknowledgement that you have read the privacy policy.
When you contact us by email or WhatsApp, we receive the contact details and message content you send. Please keep the information relevant to your project and do not include health information, identity documents or other information we do not need to discuss working together.
When you connect to the website, the server processes technical data such as your IP address, the time and URL of your request, and information sent by your browser. This is needed to deliver the website and keep it secure. The scope and retention periods for logs are described below.
3. Why we use your data
- Discussing your project and preparing a proposal. If you intend to enter into a contract with us on your own behalf, the legal basis is taking steps at your request before entering into a contract — Article 6(1)(b) of the GDPR.
- Business correspondence and other enquiries. If you represent a business or your enquiry does not concern a contract you intend to enter into personally, the legal basis is our legitimate interest in handling correspondence and communicating with people acting on behalf of our business contacts — Article 6(1)(f) of the GDPR.
- Keeping the website and form secure. The legal basis is our legitimate interest in limiting spam, misuse and excessive requests, and investigating incidents — Article 6(1)(f) of the GDPR.
- Establishing, exercising or defending legal claims. Where necessary, we retain relevant correspondence on the basis of our legitimate interest in protecting our rights — Article 6(1)(f) of the GDPR.
Acknowledging the privacy policy in the form is not marketing consent or the legal basis for processing your brief. Sending an enquiry does not subscribe you to a newsletter.
4. Whether you have to provide data
Sending an enquiry is voluntary. To submit a brief, you must provide the contact details marked as required in the form, select a service and describe your project’s purpose. The brief cannot be submitted without these details, and we cannot reply without contact information. You may leave the other fields blank. Completing the form does not create a contract for the project.
5. What happens to your brief
The form sends your message to the agency’s email inbox. It does not create a client account or save the submission in a form database on the website or in a CRM system. Correspondence remains in the email system used to handle it; the log and backup arrangements described in this policy also apply.
The form’s security mechanism generates a protected hash from the IP address and a technical browser identifier. Short-lived counters limit the number of submission attempts. These counters do not store the IP address in plain text or the contents of your brief. This does not mean that server logs are disabled.
6. Who may receive your data
Data is available to people authorised to handle correspondence and projects, and to hosting and email providers to the extent needed to deliver their services. Where a particular matter requires it, data may also be received by legal advisers or authorities entitled to obtain it under applicable law.
Our Cloud Enterprise website hosting is provided by Hostinger — HOSTINGER INTERNATIONAL LIMITED, 61 Lordou Vironos str., 6023 Larnaca, Cyprus. We use Titan email, supplied through Hostinger, for correspondence. Titan is operated by Titan Solution Ltd SEZC, CO Services Cayman Limited, P.O. Box 10008, Willow House, Cricket Square, Grand Cayman, KY1-1001, Cayman Islands. The providers process the data needed to operate the website, send and store correspondence, and protect these services. They use subprocessors under their data processing terms.
7. Data outside the European Economic Area
Website hosting and email services may involve processing data outside the European Economic Area. Titan’s operator is based in the Cayman Islands, and the providers also use subprocessors outside the EEA. Their data processing terms provide for transfer safeguards, including standard data protection clauses under Article 46(2)(c) of the GDPR where applicable. Contact us using the details at the start of this policy for information about the safeguards and how to obtain a copy.
WhatsApp is a separate service. The link on our website opens it only when you select the link; we do not embed a chat plugin. The provider’s privacy policy explains how it processes data. You can also contact us through the form or by email.
8. How long we keep your data
- Enquiries and project discussions: for as long as needed to reply, prepare a proposal and conclude the discussions. Once the matter is closed, we delete data that is no longer needed for ongoing work or to protect our rights.
- Correspondence relating to a contract or legal claim: to the extent necessary until the relevant limitation period for the claim expires, taking account of any events that affect that period. If a dispute is ongoing, we retain the relevant data until it is finally resolved and any resulting obligations are settled. This does not mean we automatically keep every enquiry in full.
- Form security: the counters expire after one minute and one hour respectively. Expired technical records are subsequently removed by WordPress maintenance processes. The security cookie expires 24 hours after it is created.
Website logs include the IP address, request time, requested resource and browser information. The Hostinger dashboard provides traffic reports covering periods of up to 7 days. This describes the reports available in the dashboard, not a deadline for deleting every log from the provider’s infrastructure. Further retention is governed by the data processing terms and limited to what is needed to provide and secure the service or meet legal requirements.
Titan processes technical email data to operate and protect its service, troubleshoot problems and investigate abuse. Its policies link retention to the time needed for these tasks and to legal obligations. Relevant criteria include the duration of a particular investigation or diagnostic process and the applicable legal requirements.
Hostinger backs up the website files and database so they can be restored. Daily backups on our plan are retained for 7 days. Weekly backups follow the service’s rotation cycle: older restore points are replaced and deleted. Data removed from the live website may remain in earlier backups until the relevant retention cycle ends.
Titan email uses separate infrastructure and copies for disaster recovery. The website backup schedule does not apply to email. Titan’s data retention follows its own policies and depends on service delivery needs and legal obligations. The retention period for correspondence with us depends on its purpose, as described in this policy.
9. Your rights
You may request access to your data and a copy of it, correction, erasure or restriction of processing. The right to data portability covers data you have provided that is processed by automated means on the basis of a contract or consent. These rights apply subject to the conditions set out in the GDPR; for example, a justified need to defend a legal claim may limit the right to erasure.
The right to object: you may object at any time to processing based on legitimate interests, on grounds relating to your particular situation. If you object, we will assess whether there are grounds for continuing the processing.
To exercise your rights, contact us using the details at the start of this policy. We may ask for information needed to confirm your identity. You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office. Information about making a complaint is available at uodo.gov.pl.
10. Analytics, profiling and external content
The website does not use analytics tools or advertising pixels. We do not profile visitors or use data from the form to make decisions based solely on automated processing that produce legal effects or similarly significant effects on you. Automated submission limits protect the form against misuse.
Fonts and videos on the website are served from the website’s own infrastructure. We do not embed YouTube or Vimeo players or external maps. Selecting a link to a portfolio project, WhatsApp or another website takes you to a separate service, which may have different privacy practices.
11. Cookies and updates
You can find information about browser storage in our cookie policy. We update this document when the website’s operation, our data processing or applicable law changes. The current version is available at this address.