Privacy Policy
Last updated: February 2026
Your Privacy is Our Priority
We are committed to protecting your personal information and being transparent about how we collect, use, and protect your data.
Data Controller
The controller of your personal data is:
- Lucid Web Development Albert Szczepański
- ul. Narcyza Gieryna 1 lok. 81, 85-795 Bydgoszcz, Poland
- NIP: 5542970252
- EU VAT: PL5542970252
- REGON: 381202553
- Email: [email protected]
Information We Collect
We only collect information necessary to provide our services:
- Name, email address, and any other contact details you provide
- Details about your work, website goals, timeline, and requirements
- Our conversations, emails, and project-related communications
- Basic website analytics (if you visit our site) such as browser type, device information, and pages visited
How We Use Your Information
Your information is used exclusively for:
- Providing our website creation services
- Communicating about your project and our services
- Delivering the website and related services you've requested
- Improving our services based on your feedback
- Complying with legal obligations
Legal Basis for Processing
We process your personal data on the following legal grounds under GDPR:
- Contact form inquiries — your consent (Art. 6(1)(a))
- Project delivery and service fulfilment — performance of a contract (Art. 6(1)(b))
- Project-related communication — performance of a contract (Art. 6(1)(b))
- Invoicing and accounting — legal obligation (Art. 6(1)(c))
- Website analytics (Google Analytics 4) — legitimate interest (Art. 6(1)(f))
- Website security and fraud prevention — legitimate interest (Art. 6(1)(f))
- Marketing communications — your consent (Art. 6(1)(a))
Legitimate Interests
Where we rely on legitimate interest as the legal basis, we have identified the following specific interests:
- Understanding how visitors use our website to improve our services and user experience
- Ensuring the security and integrity of our website and protecting against fraud
- Managing and improving our business operations and service quality
You have the right to object to processing based on legitimate interest at any time. See "Your Rights" below for details.
Information Sharing
We may share your information only in these limited circumstances:
- With trusted service providers who help us deliver our services (e.g., hosting providers, email services) under strict confidentiality agreements
- When required by law or to protect our legal rights
- With your explicit consent
International Data Transfers
Some of your personal data may be transferred to and processed in countries outside the European Economic Area (EEA):
- Google Analytics 4 (Google LLC, USA) — website usage data is processed by Google in the United States
- Web3Forms (Web3Forms, USA) — contact form submissions may be processed in the United States
These transfers are protected by appropriate safeguards, including the EU-U.S. Data Privacy Framework (for Google) and Standard Contractual Clauses (SCCs) approved by the European Commission.
You may request a copy of the safeguards in place by contacting us at the email address provided below.
Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- Encrypted data transmission (SSL/TLS)
- Secure data storage with access controls
- Regular security assessments and updates
- Limited access to personal information on a need-to-know basis
Your Rights (GDPR)
Under GDPR and other applicable privacy laws, you have the right to:
Access & Portability
Request a copy of your personal data in a portable format
Rectification
Correct any inaccurate or incomplete information
Erasure
Request deletion of your personal data
Restriction of Processing
Request that we limit how we use your data while issues are being resolved
Right to Object
Object to the processing of your data based on legitimate interests, including profiling. We will stop processing unless we demonstrate compelling legitimate grounds
Withdraw Consent
Withdraw consent for data processing at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal
Lodge a Complaint
Lodge a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland — the supervisory authority in Poland
Data Retention
We retain your personal information only as long as necessary:
- Throughout the duration of our working relationship
- Up to 3 years for support and legal purposes
- Until you unsubscribe or request deletion
- As required by applicable laws
Obligation to Provide Data
Whether providing your personal data is required depends on the context:
- Contact form submissions — voluntary, but required to receive a response to your inquiry
- Contract-related data (name, email, address) — necessary for entering into and performing a contract with us
- Invoicing data (name, address, NIP) — required by law for accounting and tax purposes
- Website analytics data — collected automatically; you can opt out via cookie settings
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. All decisions regarding our services are made by humans.
Cookies and Tracking
Our website uses minimal, essential cookies and tracking:
- Required for website functionality (theme preferences, language settings)
- Basic, anonymized website usage statistics to improve our services
- We use Google Analytics 4 to understand how visitors use our website, with IP anonymization and privacy-focused settings
Contact Us
If you have any questions about this Privacy Policy or want to exercise your rights, please contact us:
- Email: [email protected]
- Response Time: We will respond to all privacy requests within 30 days
- Data Protection Officer: Available for GDPR-related inquiries
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a prominent notice on our website. The "Last updated" date at the top of this policy indicates when it was last revised.