Skip to main content

Privacy Policy

Last updated: 2026-08-03

This Policy explains data processing on the Explore-IT website (the “Service”), including technical logs, meeting booking, the request form, abuse prevention, the optional chat and - after consent - Google Analytics 4 and, when that feature is active, advertising measurement.

1. Controller

The controller is Explore-IT Adrian Zdankiewicz (sole proprietorship), M. Konopnickiej 39/8, 84-240 Reda, Poland (the “Controller”).

Privacy contact: kontakt@explore-it.pl. The Controller has not appointed a Data Protection Officer.

2. Data, purposes and legal bases

2.1. Logs and security

The server may automatically record the IP address, request time and method, requested URL, response status, user-agent and referrer supplied by the browser. We use this data to operate the Service, diagnose errors, prevent abuse and handle security incidents.

Legal basis: Article 6(1)(f) GDPR - the Controller's legitimate interest in maintaining the security and availability of the Service.

2.2. Meeting booking

The Controller's booking system may process the name supplied, e-mail address, a short required call topic and technical booking metadata. Do not include special-category data, passwords, access credentials or information that is not needed to prepare the meeting.

Legal basis: Article 6(1)(b) GDPR and, for optional information and meeting organisation, Article 6(1)(f) GDPR.

2.3. Request form, correspondence and client relationship

The form may include a name or contact person, company, e-mail, optional phone number, the selected request type and situation description, optional attachments, the remote delivery mode, a website or system link and - for development work - an optional approximate budget. The Polish form may additionally request a service town when on-site support is selected; it does not request a full address. The fields change depending on the selected path: one-off support, ongoing care, system development or a request submitted without identifying the appropriate solution. We also process subsequent correspondence.

The draft remains only in the running application's memory. It is not automatically stored in cookies, localStorage or sessionStorage. After submission, the backend retains a minimal idempotency record for 24 hours: submission identifier, status, non-personal lead identifier, completion time and response type. It does not duplicate the form contents.

If you act on your own behalf, the legal basis is Article 6(1)(b) GDPR - steps taken at your request before entering into a contract or performance of a contract. If you contact us as an employee or representative of an organisation, the basis is Article 6(1)(f) GDPR - the legitimate interest in handling business contacts and establishing cooperation terms. Once cooperation starts, data may be processed to perform the contract, meet accounting and tax duties, and establish, pursue or defend claims.

A name or contact person, company, e-mail and description are required to submit the form. Phone number, link, attachments and budget are optional, and the budget field is shown only for development work. Do not enter or attach passwords, access keys, special-category data or client data that is not needed for the initial assessment.

2.4. Cloudflare Turnstile and chat

The form, meeting booking and chat use Cloudflare Turnstile to distinguish users from automated traffic. Cloudflare, Inc. may process an IP address, browser and device information, and technical or behavioural signals. The Controller does not retain the Turnstile token after verification. See the Cloudflare Privacy Policy.

The optional chat forwards the message and session identifier through the Controller's server to Cloudflare AI Search. Do not provide personal or confidential data in chat. Minimized logs may include the message, reply, language, a hashed session identifier, sources and technical flags. Obvious contact details and secrets are masked on a basic level. Chat history also remains in sessionStorage until the browser tab or session is closed.

Legal basis: Article 6(1)(f) GDPR - Service protection, providing information, diagnostics and improving answer quality.

2.5. Google Analytics 4 and optional advertising measurement

Only after voluntary consent does the Service load Google Tag and use Google Analytics 4. Before a choice or after rejection, no Google tag is downloaded and the Service sends no measurement request to Google.

Depending on your choice, we may process online cookie identifiers, approximate device and browser data, the visited page address including URL parameters subject to redaction, the page title, and the referring address to the extent provided by the browser. GA4 automatically measures the initial view and SPA view changes based on browser history, outbound link clicks and file downloads. Interaction metadata may include the link domain and URL, link text, identifier or classes, and the downloaded file name and extension.

We manually send only business events with a closed parameter set: clicking a defined CTA, choosing phone or e-mail, opening the calendar or chat, starting the form, successful backend acceptance of a request, interacting with a service or case study, and using the calculator. Form-related parameters may include only controlled categories such as request type, route identifier, form variant and delivery mode. We do not send form contents, names, e-mail, phone, company, service towns, description, entered website addresses, calculator results, budgets or the backend lead identifier to GA4. Automatic form, scroll, site-search and video-interaction measurement is disabled.

If an advertising-measurement category is available in cookie settings, Google may use attribution identifiers present in the URL after separate consent, including gclid, dclid, gbraid, wbraid, gclsrc, _gl and supported gad_* parameters. When that consent is denied, we use the ads_data_redaction signal to request additional advertising-data redaction to the extent supported by Google. Conversion events may be measured in GA4 and imported into Google Ads. We do not use remarketing, Google Signals, ad personalisation, Enhanced Conversions or user-provided data.

The current availability of advertising measurement is shown in cookie settings. Rejecting analytics or advertising measurement does not limit Service functionality.

Legal basis: Article 6(1)(a) GDPR and Article 399 of the Polish Electronic Communications Law. You can withdraw consent at any time through “Cookie settings” in the footer without affecting prior lawful processing.

2.6. Consent records

To demonstrate the user's choice, our backend records a random consentId, notice version, selected categories, operation, interface language and server time. The receipt does not contain form data, e-mail, IP address, user-agent, URL, referrer or Google identifiers.

Legal basis: Articles 7(1) and 5(2) GDPR. Withdrawal is handled under Article 7(3) GDPR.

3. Recipients and transfers outside the EEA

Recipients may include hosting, e-mail and IT infrastructure providers, Cloudflare, technical, accounting or legal support providers and authorised public bodies. After consent, Google Ireland Limited and other Google group entities receive measurement data. An authorised analytics or campaign support provider may receive limited GA4 or Google Ads access through a separate account and appropriate contractual arrangements.

Cloudflare and Google may process data outside the EEA, including in the United States. Transfers rely on GDPR mechanisms such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses, depending on the processing. See how Google uses data from partner sites and the Google Privacy Policy.

4. Retention

  • server and security logs: normally 60 days, longer only for an incident or claims;
  • unqualified enquiries and pre-contract correspondence: 12 months after discussions end;
  • bookings: generally 3 months after the meeting;
  • form idempotency record: 24 hours;
  • minimized chat logs: normally 60 days; active chat anti-abuse timestamps for the applicable rate-limit window;
  • pseudonymised form and consent API rate-limit records: no more than 24 hours;
  • consent records: history for up to 24 months after the latest decision, then the entire record is deleted;
  • GA4: user and event data available in explorations for 14 months, without resetting on new activity; standard aggregated reports are not governed by that setting in the same way;
  • client data: for the relationship and then until applicable tax, accounting and claim-limitation duties expire;
  • data independently retained by Cloudflare and Google: according to their terms, service settings and legal duties.

5. Cookies and browser storage

  • exploreit_consent - remembers and enforces privacy choices; necessary, host-only, Secure, SameSite=Lax, Path=/; 6 months;
  • lang - language selected by the user; 12 months;
  • _ga, _ga_<id> - GA4, only after analytics consent; no more than 12 months from being set, without renewal on activity;
  • _gcl_* - Google advertising attribution, only when advertising measurement is active and after consent to that category; according to the Google configuration actually used;
  • navigation sessionStorage - only the path and scroll position required for an intentional return from a standalone page; until used or the session is closed;
  • chat sessionStorage - chat history and session identifier; until the browser tab or session is closed.

The exploreit_consent cookie is necessary to remember requested privacy settings. The application reads it, so it cannot use HttpOnly. An invalid, incomplete or outdated cookie is treated as no decision: Google remains blocked and the Service asks again.

You can change consent through “Cookie settings” in every page footer. Withdrawal blocks new events and removes GA4 cookies and, where applicable, advertising-attribution cookies used by the Service. Cookies can also be deleted in browser settings.

6. Your rights

You may request access, rectification, erasure, restriction, portability where provided by law, object to processing based on Article 6(1)(f) GDPR, and withdraw consent.

Send requests to kontakt@explore-it.pl. You may also lodge a complaint with the President of the Personal Data Protection Office (Poland) or another competent supervisory authority.

The Controller does not make decisions about users based solely on automated processing that produce legal or similarly significant effects.

7. Policy updates

We may update this Policy when the Service, providers or legal requirements change. The current version and update date are published in the Service.