Skip to content
whiteitlab
Services Packages Work About FAQ Contact
PL EN

RODO / GDPR

Privacy & cookie policy

This page explains in plain words what personal data I process when you visit whiteitlab.com or contact me, why, for how long, and what your rights are. I only collect what is necessary — the site has no analytics, ads or tracking.

Last updated: 2026-10-03

1. Data controller

The data controller is Piotr Białas, operating under the whiteitlab brand. For anything related to personal data, contact me: via my GitHub profile: github.com/Pioti2252.

2. Data collected when you visit

The server and the CDN provider automatically log basic information about each request. It is used solely for security (e.g. detecting attacks) and troubleshooting — I don’t build profiles or visit statistics from it.

  • IP address,
  • date and time of the request,
  • requested page and the server response code,
  • browser and system information (User-Agent header),
  • the referring page, if your browser sends it.

3. Data from the form and correspondence

When you write via the form or by email, I process the data you provide: name, email address, optionally company name and budget range, topic and message (and anything you include in it). Form messages go straight to my mailbox — the website server does not store them.

4. Purposes and legal bases

I process data only for these purposes:

  • replying to your inquiry and preparing an offer — Art. 6(1)(b) GDPR (steps taken at your request before entering into a contract),
  • correspondence and establishing, exercising or defending legal claims — Art. 6(1)(f) GDPR (legitimate interest),
  • website security and abuse prevention (logs) — Art. 6(1)(f) GDPR,
  • if we sign a contract: performing it (Art. 6(1)(b) GDPR) and tax and accounting obligations (Art. 6(1)(c) GDPR).

5. How long I keep data

No longer than necessary:

  • server logs — up to 30 days,
  • correspondence without a contract — up to 12 months after the last contact,
  • contract-related data — for the term of the contract and then until claims become time-barred (Art. 118 of the Polish Civil Code),
  • accounting records — for the period required by tax law (generally 5 years from the end of the tax year),
  • data processed on the basis of legitimate interest — until you successfully object.

6. Who receives the data

I don’t sell data or share it for marketing. Data may only be received by providers that technically run the site and email, under data processing agreements:

  • server provider — OVHcloud (EU),
  • CDN and attack-protection provider — Cloudflare,
  • the email provider used to send and receive messages.

I may also disclose data to public authorities where required by law.

7. Transfers outside the EEA

Cloudflare may process data outside the European Economic Area (including the USA). This is based on the European Commission’s adequacy decision (EU–US Data Privacy Framework) or standard contractual clauses that ensure an adequate level of protection.

8. Your rights

Under Articles 15–22 GDPR you have the right to:

  • access your data and receive a copy,
  • rectify or complete your data,
  • erasure (“right to be forgotten”),
  • restriction of processing,
  • data portability,
  • object to processing based on legitimate interest,
  • withdraw consent at any time where processing is based on it (without affecting the lawfulness of earlier processing).

If you believe I process your data unlawfully, you can lodge a complaint with the Polish supervisory authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl). I will also inform recipients of any rectification, erasure or restriction.

9. Profiling and automated decisions

I don’t profile users or make automated decisions about them. The only automated mechanisms are anti-spam and anti-abuse protections (e.g. a limit on form submissions), which have no legal effect on you.

10. Providing data is voluntary

Providing data in the form is voluntary, but without your name, email address and message I can’t reply to your inquiry.

11. Security

The connection to the site is encrypted (HTTPS). The site runs in an isolated container with minimal privileges, does not store form messages on the server, and application logs contain neither message content nor email addresses.

12. Cookies and browser storage

The site uses no analytics, marketing or tracking cookies and no tools such as Google Analytics or ad pixels. Only the strictly necessary items below may appear — which is why the site shows no consent banner (Art. 399(3) of the Polish Electronic Communications Law, implementing Art. 5(3) of the ePrivacy Directive).

NameProviderPurposeRetention
__cf_bmCloudflareDistinguishing humans from bots and protecting against attacks. Set only when bot protection is active.30 minutes
cf_clearanceCloudflareRemembering that you passed a security check (if Cloudflare showed one), so it isn’t shown again.usually 30 minutes (Cloudflare setting)
wl-themewhiteitlab (browser local storage, not a cookie)Remembering your light/dark theme choice. Saved only when you click the toggle; never sent to the server.until you clear browser data

You can delete cookies and site data or block them in your browser settings at any time. The site will keep working — your theme choice just won’t be remembered, and Cloudflare may ask for verification more often.

13. Changes

If the way I process data changes (e.g. I add a new tool), I will update this page and the date at the top.

Back to the homepage

whiteitlab

Services Packages Protocol Work About FAQ Contact

© 2026 whiteitlab

GitHub Privacy policy Cookies Back to top ↑