Back to home

Privacy Policy

This English version is a translation provided for your convenience. The legally binding version of this document is the Polish original; in the event of any discrepancy, the Polish version prevails.

Last updated: August 24, 2026.

1. Controller of personal data

The controller of your personal data is ALGREN SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ with its registered office in Olsztyn, ul. Aleja Obrońców Tobruku 7, 10-092 Olsztyn, entered in the Register of Entrepreneurs of the National Court Register under KRS: 0000835284, NIP: 7393938817, REGON: 385835597 (hereinafter: the “Controller”).

You can contact the Controller by e-mail at kontakt@deyee.eu or by phone at +48 604 555 624.

2. Scope of collected data

Through the contact forms available on the website we collect the following personal data:

  • first and last name,
  • phone number,
  • e-mail address,
  • type of business conducted,
  • referral source (how you learned about us).

3. Purposes and legal bases for processing

Your personal data is processed for the following purposes:

  • Handling enquiries and scheduling robot demonstrations – on the basis of Article 6(1)(b) GDPR (taking action at the request of the data subject prior to entering into a contract) and Article 6(1)(f) GDPR (the Controller’s legitimate interest in serving its customers).
  • Replying to enquiries – on the basis of Article 6(1)(f) GDPR (the Controller’s legitimate interest in responding to an enquiry).
  • Fulfilment of legal obligations – on the basis of Article 6(1)(c) GDPR (e.g. tax and accounting obligations).
  • Establishing, pursuing or defending claims – on the basis of Article 6(1)(f) GDPR.
  • Optimising and measuring the effectiveness of advertising campaigns – on the basis of Article 6(1)(f) GDPR (the Controller’s legitimate interest in its own marketing and in spending its advertising budget efficiently). For this purpose we transfer to Meta Platforms Ireland Ltd. events relating to the quality of the leads obtained (so-called Conversions API for CRM). Having carried out a balancing test, we concluded that this processing does not override your rights and freedoms, because it covers only the data necessary to match the event, and we transfer the contact details in an irreversibly encrypted (hashed) form. You have the right to object to this processing (see point 6).
  • Ensuring the security and reliability of the Website – on the basis of Article 6(1)(f) GDPR (the Controller’s legitimate interest in detecting errors, outages and abuse and in keeping the Website working correctly). For this purpose we use the Sentry monitoring tool, which records technical information about errors and response times. Processing is limited to data necessary for diagnosis – without form contents and without session recording. IP addresses are not stored; they are used solely to determine an approximate location (country and city).
  • Maintaining a register of cookie consents – on the basis of Article 6(1)(c) GDPR in connection with Article 5(2) and Article 7 GDPR (the accountability principle – the obligation to demonstrate that consent was given and what it covered). For this purpose we record consent events (granting, changing, withdrawing) in a separate register.

4. Data retention period

Personal data is stored for a period:

  • necessary to achieve the purpose for which it was collected – no longer than until consent is withdrawn or an effective objection is raised,
  • resulting from legal provisions (e.g. tax regulations – 5 years from the end of the calendar year in which the tax payment deadline fell),
  • until any claims become time-barred – as a rule 3 years for claims related to the conduct of business activity.

5. Data recipients

Your personal data may be shared with the following categories of recipients:

  • providers of IT and hosting services,
  • providers of e-mail and communication tools,
  • Functional Software, Inc. (Sentry) – the provider of the error and performance monitoring tool for the Website. The technical data processed (error type, page address, browser and operating system type, response time) is stored in the European Union region (Frankfurt). The tool does not store IP addresses, form contents or session recordings; it records only an approximate location (country and city) derived from the IP address of the connection,
  • the provider of the automation platform Make (Make.com – processing within the European Union) – with respect to maintaining the register of cookie consents, handling contact form submissions, and the technical transfer of lead-quality events to Meta (Conversions API),
  • Meta Platforms Ireland Ltd. (established in Ireland) – as a separate controller with respect to the Meta Business Tools – for the purpose of matching events to the advertising account and optimising and measuring the effectiveness of Lead Ads campaigns,
  • entities providing accounting and legal services,
  • state authorities – in cases provided for by law.

As part of optimising advertising campaigns, we transfer to Meta only: the contact identifier assigned by Meta (Meta Lead ID – relating to persons who submitted their data through an advertising form on Facebook or Instagram), an irreversibly encrypted (SHA-256) digest of the e-mail address and phone number, and the sales-stage status of the contact (e.g. lead acquisition, entering the sales process, conclusion of a contract). We do not transfer the content of notes or other details of the correspondence. Meta uses this data solely to match the event to the advertising account and to optimise campaigns. This applies both to persons who submitted their data through a Meta advertising form (Facebook/Instagram) and through the contact form on the Website.

Save for the exception indicated below, the Controller does not transfer personal data to third countries (outside the European Economic Area). In connection with the use of Meta tools, data (in hashed form) may be transferred to Meta Platforms, including outside the EEA; the transfer takes place with appropriate safeguards referred to in Article 46 GDPR – on the basis of standard contractual clauses (SCC) and the Data Privacy Framework (DPF). We apply analogous safeguards where other IT tools requiring such a transfer are used.

6. Rights of data subjects

In connection with the processing of personal data, you have the following rights:

  • the right to access your data (Article 15 GDPR),
  • the right to rectify your data (Article 16 GDPR),
  • the right to erasure – the “right to be forgotten” (Article 17 GDPR),
  • the right to restriction of processing (Article 18 GDPR),
  • the right to data portability (Article 20 GDPR),
  • the right to object to processing based on a legitimate interest (Article 21 GDPR), including to the transfer of data to Meta for marketing purposes,
  • the right to withdraw consent at any time – without affecting the lawfulness of processing carried out before consent was withdrawn,
  • the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, www.uodo.gov.pl).

To exercise the above rights, please contact us at: kontakt@deyee.eu.

7. Voluntary nature of providing data

Providing personal data is voluntary but necessary to handle your enquiry and schedule a robot demonstration. Failure to provide the data will make it impossible for us to reply and to act on your enquiry.

8. Automated decision-making and profiling

The Controller does not carry out automated decision-making, including profiling, within the meaning of Article 22(1) and (4) GDPR.

9. Cookies and the register of consents

The website uses cookies and the browser’s local storage in three categories: strictly necessary (always active), analytics and marketing. We collect consent for the optional categories through a banner and the “Cookie settings” panel available in the site footer – you can grant, change or withdraw it at any time, and “Accept” and “Reject” carry equal weight. Details can be found in our Cookie Policy.

In order to demonstrate that consent was given (accountability, Article 5(2) and Article 7 GDPR), we maintain a register of consents using the Make platform. In the register we record: a random consent identifier (consentId – which cannot on its own establish your identity), the scope of the consent granted, the policy version, the date and time of the decision, the language and the browser type, as well as an irreversibly encrypted (hashed) digest of the IP address – we do not store the raw IP address. Entries in the register are kept for a period of up to 5 years from the withdrawal or change of consent, in order to demonstrate compliance with the regulations.

10. Changes to the Privacy Policy

The Controller reserves the right to make changes to this Privacy Policy. Users will be informed of any material changes via the website.

Call Now
WhatsApp