Privacy policy
Current version effective from:
This Privacy Policy sets out the rules for the processing of personal data by Cloudsintegrator sp. z o.o. with its registered office in Katowice, Poland (the "Controller").
Definitions
- Controller
- Cloudsintegrator spółka z ograniczoną odpowiedzialnością, a Polish limited liability company, with its registered office at ul. Jana III Sobieskiego 12/1, 40-001 Katowice, Poland, entered in the Register of Entrepreneurs of the Polish National Court Register under KRS 0000728196, tax ID NIP 6342927996, statistical ID REGON 369988971.
- Personal data
- Any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
- Policy
- This Privacy Policy.
- Data subject
- A natural person whose personal data is processed by the Controller.
- GDPR
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).
- Site
- The website at cloudsintegrator.com together with any subdomains operated by the Controller.
Processing by the Controller
In the course of our business we collect and process personal data in accordance with applicable law, in particular the GDPR.
As Controller, we are committed to transparency, in particular by informing data subjects of processing at the time the data is collected, including the purposes and legal bases. We ensure that personal data is collected only to the extent necessary for the stated purpose and processed only for as long as necessary.
We safeguard the security and confidentiality of personal data and ensure access to information about processing for data subjects. We maintain incident-response procedures for data breaches. Where required, we notify data subjects of such events in line with the law.
Contacting the Controller
For matters relating to the protection and processing of your personal data you can contact us:
- By email
- rodo@cloudsintegrator.com
- By post
- Cloudsintegrator sp. z o.o., ul. Jana III Sobieskiego 12/1, 40-001 Katowice, Poland
Our Data Protection Coordinator is available at rodo@cloudsintegrator.com.
Security of personal data
To ensure the integrity and confidentiality of data, the Controller has implemented procedures so that personal data is accessible only to authorised persons and only to the extent necessary for their tasks. We use TLS encryption, role-based access control (RBAC) through Microsoft Entra ID, SIEM-based activity logging, regular backups and vulnerability testing.
The Controller takes all necessary steps to ensure that subcontractors and other cooperating entities likewise guarantee appropriate security measures whenever they process personal data on the Controller's behalf.
The Controller performs ongoing risk analysis related to personal-data processing and monitors the adequacy of safeguards. Where required, the Controller implements additional measures to enhance data security.
Purposes and legal bases
Email and postal correspondence
If you contact us by email or post on a matter unrelated to a contract or any other existing relationship, the personal data contained in the correspondence is processed solely for the purpose of communication and resolving the matter. The legal basis is the legitimate interest of the Controller (Art. 6(1)(f) GDPR).
Contact form and meeting booking
If you submit our contact form or book a consultation through our Microsoft Bookings calendar (part of Microsoft 365), we process the data you provide (name, company, email, phone, message, meeting notes) to respond to the inquiry and, if a contract follows, to perform it. The booking calendar opens in a new tab on outlook.office.com; Microsoft Ireland Operations Ltd. is the controller of the data entered on the Microsoft side. The legal basis is taking steps before entering into a contract at the data subject's request and contract performance (Art. 6(1)(b) GDPR) and, after closure, the Controller's legitimate interest in defending against potential claims (Art. 6(1)(f) GDPR).
Phone contact
For phone contact on matters unrelated to an existing contract, we ask for personal data only when necessary to handle the matter. The legal basis is the Controller's legitimate interest (Art. 6(1)(f) GDPR).
Service delivery and contracts
When collecting data to perform a specific contract (e.g. advisory services, Azure migrations, managed care, Aiversum deployment, AI Academy programmes), we provide the data subject with detailed information about the processing at the time the contract is concluded or the data obtained. The legal bases are contract performance (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR), including under Polish tax and accounting law.
Personnel of business partners
Where we receive personal data of persons involved in performing a contract with a business partner (e.g. contact persons placing orders), the scope of data is limited to what is necessary and typically does not include information beyond name and business contact details. Such data is processed on the basis of Art. 6(1)(f) GDPR.
Networking and business contacts
We also collect personal data through building and maintaining lasting business contacts (networking) — at industry events or through the exchange of business cards — for purposes related to initiating and maintaining contact. The legal basis is the Controller's legitimate interest (Art. 6(1)(f) GDPR).
Marketing of our own services
Where you give us a separate consent, we may send commercial communications about our own services (e.g. newsletter, webinar invitations). The legal basis is consent (Art. 6(1)(a) GDPR, Art. 10 of the Polish Act on the Provision of Electronic Services, and Art. 172 of the Polish Telecommunications Act). You may withdraw consent at any time without affecting the lawfulness of prior processing.
Cookies and tools on cloudsintegrator.com
On cloudsintegrator.com we use cookies and similar technologies for functional, analytics and marketing purposes. Consent is managed by our in-house Consent Manager — at your first visit we display a banner where you can grant or refuse consent for each category. You can change your choices at any time using the "Cookie settings" link in the footer.
We use three categories:
- Necessary (always active)
- Store language preference and cookie choices. Without them the Site does not work correctly. Legal basis: the Controller's legitimate interest (Art. 6(1)(f) GDPR).
- Analytics (after consent)
- Vercel Analytics and Vercel Speed Insights — anonymous traffic and performance measurements. Activated only after consent.
Under Article 173 of the Polish Telecommunications Act, accessing information stored on your terminal equipment (other than strictly necessary) requires consent.
Inventory of cookies and local-storage mechanisms
The table below lists the specific cookies, localStorage keys and other mechanisms used on cloudsintegrator.com.
| Name | Category | Mechanism | Retention | Purpose |
|---|---|---|---|---|
| NEXT_LOCALE | Necessary | HTTP cookie (1st-party) | 365 days | Remembers your chosen language version (PL/EN). |
| cint_consent_v2 | Necessary | localStorage (1st-party) | Until manually cleared | Stores your analytics cookie consent decision. |
| _va, _va_session, va_id | Analytics | Cookie / localStorage (Vercel) | Up to 13 months | Vercel Analytics — anonymous traffic measurements. Loaded only after analytics consent. |
| Vercel Speed Insights (beacon) | Analytics | HTTP beacon | None (single-request measurement) | Performance measurements (Core Web Vitals). Loaded only after analytics consent. |
Tools we use
- Vercel Inc.
- Application hosting and CDN. Also Vercel Analytics and Speed Insights — only after analytics consent.
- Cloudflare Inc.
- DNS, DDoS protection and Web Application Firewall (WAF).
- Resend Inc.
- Transactional email delivery for messages submitted through the contact form.
- Microsoft Ireland Operations Ltd.
- Microsoft 365 and Microsoft Azure — the infrastructure on which we conduct business correspondence, store operational documents (EU/EEA), run video meetings (Microsoft Teams) and accept consultation bookings (Microsoft Bookings). The Bookings calendar opens in a new tab on outlook.office.com; we receive booking confirmations in our company mailbox.
- Accounting office
- Bookkeeping and tax filings — only data necessary to issue and reconcile invoices.
Recipients of data
In connection with our business, personal data may be disclosed to external entities, in particular IT and infrastructure providers, legal or accounting service providers, couriers and recruitment agencies. Data may also be disclosed to entities related to the Controller by capital or personal ties (including SecIQ sp. z o.o. — for jointly delivered cybersecurity services, under a separate data processing agreement).
The Controller reserves the right to disclose selected information about data subjects to the competent authorities or third parties that request such information on an appropriate legal basis and in accordance with applicable law.
Transfers outside the EEA
The level of protection for personal data outside the European Economic Area ("EEA") differs from that ensured by European law. Some of our processors (Vercel, Cloudflare, Resend) are established in the United States. We transfer personal data outside the EEA only when necessary and with an appropriate level of protection, in particular through:
- European Commission adequacy decisions
- Cooperation with processors established in countries covered by an adequacy decision.
- Standard Contractual Clauses (SCC)
- Use of standard contractual clauses issued by the European Commission.
- Binding Corporate Rules
- Use of binding corporate rules approved by the competent supervisory authority.
- EU-U.S. Data Privacy Framework
- For transfers to the United States — cooperation with entities certified under the EU-U.S. Data Privacy Framework approved by a Commission decision.
The Controller will always inform you of the intention to transfer personal data outside the EEA at the time of collection.
Retention periods
- Contact inquiries
- 12 months from the last contact
- Contracts and billing documents
- 5 years from the end of the financial year (Polish Tax Ordinance and Accounting Act)
- Site security logs
- 90 days
- Analytics cookies
- up to 13 months
- Cookie consent records
- 12 months from the last decision
- Marketing data
- until consent is withdrawn or an objection is raised
The processing period may be extended where necessary to establish or defend against claims; afterwards, only to the extent required by law.
Your rights
- Right to information about processing
- We inform you about the processing, including purposes, legal bases, scope, recipients and planned erasure dates.
- Right to obtain a copy
- We provide a copy of the data we process about you.
- Right to rectification
- We correct inaccuracies and complete incomplete data.
- Right to erasure (right to be forgotten)
- You may request erasure of data whose processing is no longer necessary for any of the purposes for which it was collected.
- Right to restriction of processing
- A temporary halt of operations on the data, except those to which you have consented.
- Right to data portability
- Where data is processed by automated means under a contract or consent, we provide it in a machine-readable format.
- Right to object to marketing
- You may object to processing for marketing purposes at any time, with no need to give reasons.
- Right to object to other processing
- You may object — for reasons related to your particular situation — to processing based on the Controller's legitimate interest; this objection should include reasons.
- Right to withdraw consent
- If data is processed on the basis of consent, you may withdraw it at any time, without affecting the lawfulness of processing prior to withdrawal.
- Right to lodge a complaint
- If you believe that processing infringes the GDPR or other personal-data laws, you may complain to the President of the Personal Data Protection Office (PUODO, ul. Stawki 2, 00-193 Warsaw, Poland).
Submitting requests
Requests related to data-subject rights can be submitted:
- In writing
- Cloudsintegrator sp. z o.o., ul. Jana III Sobieskiego 12/1, 40-001 Katowice, Poland
- By email
- rodo@cloudsintegrator.com
If we cannot identify the requesting natural person on the basis of the request, we will ask for additional information. The request may be submitted in person or through a proxy. We respond within one month of receipt; if an extension is necessary, we inform the applicant of the reasons.
Automated decisions and profiling
The Controller does not make decisions producing legal effects on you solely by automated means. We do not engage in profiling that would require additional consent under Art. 22 GDPR.
Amendments
This Policy is reviewed on an ongoing basis and updated where necessary. The current version was adopted on 2026-05-16.
Cloudsintegrator sp. z o.o. | KRS 0000728196 | NIP 6342927996 | REGON 369988971
ul. Jana III Sobieskiego 12/1, 40-001 Katowice, Poland
Manage your cookie consent
You can change or withdraw your cookie consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.