Skip to content
Document. Personal data. GDPR.

Privacy policy

What data we collect, why we need it and how long we keep it. No clauses written just in case. If any point is unclear, write to us and we will clarify it in the document.

DOCUMENT STATUS
EFFECTIVE FROM[DATE]
UPDATED[DATE]
SCOPEWebsite and correspondence
VERSION1.0
00. In short

Three sentences to start

The summary does not replace the document. The full wording of points 01 to 10 below is binding.

01

We collect the minimum.

Data from the contact form, from intro call bookings and basic technical data about the site. Nothing more.

02

We do not trade in data.

We do not sell your data or share it for advertising purposes. It goes only to our service providers under a data processing agreement.

03

You are in control.

At any time you can ask for access to your data, its correction or deletion. One e-mail is enough.

01

Who is the controller of your data

The controller of the personal data collected on this website and in correspondence is EBMT Consulting Krzysztof Sadurski. Contact for any matter concerning your data: details below. We reply within one working day.

CONTROLLEREBMT Consulting Krzysztof Sadurski
ADDRESSul. Henryka Biernackiego 26, 58-250 Pieszyce, Poland
TAX ID (NIP)PL7162312354
E-MAILcontact@ebmtconsulting.com
DATA PROTECTION OFFICERNot appointed, matters are handled by a partner
02

What data we collect

We collect only the data you provide yourself and the technical data needed for the site to operate securely. Providing data is voluntary, but without an e-mail address we cannot reply to your enquiry. Call booking details are entered in the TidyCal calendar embedded on the Contact page; the provider of that tool collects them on our behalf.

CONTACT FORMCALL BOOKINGTECHNICAL DATA
Full nameFull nameIP address
E-mail addressE-mail addressBrowser type
Company and roleSelected slotDate and time of visit
Phone, if providedTime zonePages visited
Message contentMeeting noteReferral source
03

Purposes, legal bases and retention periods

Each purpose has its own legal basis under the GDPR and its own retention period. Once the period expires, we delete or anonymise the data.

PURPOSELEGAL BASISPERIOD
Replying to an enquiry from the formArt. 6(1)(b) and (f) GDPR12 months from the end of correspondence
Booking and holding an intro callArt. 6(1)(b) GDPR12 months from the meeting date
Performance of an advisory or training contractArt. 6(1)(b) GDPRDuration of the contract and 6 years after it ends
Settlements, invoices, accountingArt. 6(1)(c) GDPR5 years from the end of the tax year
Establishing and defending claimsArt. 6(1)(f) GDPRUntil the limitation period expires
Sending materials and information about servicesArt. 6(1)(a) GDPR, consentUntil consent is withdrawn
Site statistics and securityArt. 6(1)(f) GDPR12 months, server logs 3 months
The legitimate interest of the controller, that is point (f), means for us: handling your enquiry, defending claims and maintaining the site.
04

Who we share data with

Data goes only to the partners of EBMT Consulting and to the providers who run our tools. Each of them acts under a data processing agreement and may process data only to the extent we specify.

Website hosting providerHostinger (hostinger.com)
Business e-mail providerGoogle Workspace (Google), United States
Call booking calendar and online meeting linkTidyCal (tidycal.com), United States
Legal advisers, when neededON REQUEST

The booking calendar on the Contact page is embedded from TidyCal and loads when you open that page. TidyCal processes the booking details (full name, e-mail address, selected slot, meeting note) and technical browser data, including for its reCAPTCHA protection. The provider's policy: <a href="https://tidycal.com/privacy-policy" target="_blank" rel="noopener noreferrer">tidycal.com/privacy-policy</a>.

We do not sell, exchange or share data with advertising networks. We disclose it to public authorities only where required by law.

05

Transfers of data outside the EEA

Some of the tools we use have servers outside the European Economic Area. In such cases the transfer takes place on the basis of standard contractual clauses approved by the European Commission or an adequacy decision. Tools involving transfers outside the EEA: TidyCal, call booking calendar (United States), and Google Workspace, business e-mail (United States). If the list changes, we will update this point.

06

Your rights

You can exercise each of these rights with a single e-mail. We reply without undue delay, and at the latest within one month of your request.

RIGHTWHAT IT MEANS
Access to dataWe will tell you what data we hold about you and where we got it.
RectificationWe will correct inaccurate data and complete incomplete data.
ErasureWe will delete your data unless we are required by law to keep it.
RestrictionWe will suspend processing while the matter is clarified.
PortabilityWe will provide your data in a machine-readable format.
Objection and consentYou can object to processing under point (f) and withdraw consent at any time.

If you believe we process data unlawfully, you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

07

Cookies

We always use essential cookies, because the site does not work without them. The others are activated only after your consent in the banner. The exception is the booking calendar on the Contact page, embedded from TidyCal: it loads when you open that page and may set that service's own cookies. You can change your consent at any time and delete cookies in your browser settings.

CATEGORYPURPOSEDURATIONCONSENT
EssentialSession handling, remembering your cookie banner choice, form securitySession up to 12 monthsNot required
AnalyticsAggregate statistics on visits and page popularity, without identifying individualsUp to 12 monthsRequired
FunctionalLanguage version selection and site settingsUp to 6 monthsRequired
Third party: TidyCalEmbedded booking calendar on the Contact page, including reCAPTCHA protectionAs per the TidyCal policyLoads when Contact opens
MarketingNot used. If that changes, we will add them here and in the bannerNoneNone
08

Data security

The site runs over an encrypted connection. Only the partners have access to mailboxes and documents, on accounts protected by two-factor authentication. We keep client materials separately for each project and delete them once the period stated in point 03 has passed. Technical documentation and production data we receive during an audit are covered by a confidentiality agreement.

09

Profiling and automated decisions

We do not make decisions based solely on automated processing and we do not profile visitors. Enquiries are read and assessed by a partner, not an algorithm.

10

Changes to this document

We update this policy when we change our tools or the scope of our services. The date of the last change and the version number are shown at the top of this page. Earlier versions are available on request. If a change is significant, we will inform the people we are in correspondence with.

Data requests

One e-mail and it is done

Tell us what your request concerns: access, correction, deletion or withdrawal of consent. You do not need to give a reason or fill in a form.

E-MAIL FOR DATA REQUESTScontact@ebmtconsulting.com
RESPONSE TIME1 working day, one month at most
SUPERVISORY AUTHORITYPresident of the Personal Data Protection Office (UODO), Warsaw