← letitbee.agency

Legal document

Privacy Policy

LetITBee — letitbee.agency

Data Controller: letitbee.agency Bartłomiej Poznański, communicating services under the LetITBee brand

Address: ul. Lipowa 3D, 30-702 Kraków, Poland

Tax ID (NIP): 6751829630 | REGON: 544976412

E-mail: kontakt@letitbee.agency

Phone: +48 455 568 141

This is an English translation provided for convenience only. The legally binding version of this document is the Polish one („Polityka Prywatności”). In the event of any discrepancy between the language versions, the Polish version prevails.

§1 – DATA CONTROLLER

  1. 1.The controller of personal data collected via the letitbee.agency website is letitbee.agency Bartłomiej Poznański, communicating services under the LetITBee brand, ul. Lipowa 3D, 30-702 Kraków, Tax ID (NIP): 6751829630, REGON: 544976412 (hereinafter: the „Controller”).
  2. 2.In all matters concerning the processing of personal data, you may contact the Controller electronically at: kontakt@letitbee.agency or in writing to the registered address indicated above.
  3. 3.This Privacy Policy describes the rules for collecting, processing and storing the personal data of users of the website in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and the supplementary provisions of Polish law.

§2 – SCOPE AND SOURCES OF DATA COLLECTED

  1. 1.The Controller collects personal data solely to the extent necessary to achieve specific purposes and in a lawful manner. Personal data is obtained directly from the data subjects in the following situations:
  2. 2.Contact form – first name and/or company name, e-mail address, phone number (optional), type of project, message content, inspiration links and optional attachments sent by the user.
  3. 3.AI chat – e-mail address, phone number (optional), company name (optional), the content of the conversation conducted with the AI assistant, and optional attachments.
  4. 4.E-mail correspondence – data contained in messages sent to the Controller’s addresses, including the sender’s first and last name, e-mail address and the content of the correspondence.
  5. 5.Technical data – IP address, browser type and version, operating system, referring page, time and duration of the visit, and pages visited on the website. This data is collected automatically and may constitute personal data within the meaning of the GDPR.
  6. 6.Newsletter / LetITBee Club – the e-mail address provided when subscribing to the Club newsletter, language preference or website language version (Polish or English), subscription date, subscription status, consent text/version/source, unsubscribe token or withdrawal status, and technical metadata related to newsletter sending, such as the date of sending and delivery status.

§3 – PURPOSES AND LEGAL BASES OF PROCESSING

  1. Personal data is processed for the following purposes and on the following legal bases:
  2. 1.Handling enquiries and establishing business contact – legal basis: Article 6(1)(b) GDPR (taking steps at the data subject’s request before concluding a contract) or Article 6(1)(f) GDPR (the Controller’s legitimate interest in being able to respond to the enquiry made).
  3. 2.Conclusion and performance of a service agreement – legal basis: Article 6(1)(b) GDPR (processing necessary for the performance of a contract to which the data subject is a party).
  4. 3.Fulfilment of legal obligations (including tax and accounting obligations) – legal basis: Article 6(1)(c) GDPR.
  5. 4.Establishment or defence of claims – legal basis: Article 6(1)(f) GDPR (the Controller’s legitimate interest).
  6. 5.Analysis of the quality of the website and optimisation of its operation – legal basis: Article 6(1)(f) GDPR (the Controller’s legitimate interest in improving the services offered).
  7. 6.Sending the LetITBee Club newsletter together with related educational, product, partner and marketing content by electronic means – legal basis: Article 6(1)(a) GDPR (the data subject’s consent), in conjunction with Article 398 of the Polish Electronic Communications Law of 12 July 2024 (Prawo komunikacji elektronicznej). Consent is voluntary and may be withdrawn at any time, in particular via the unsubscribe link indicated in every message; withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
  8. 7.Documenting newsletter subscription, the content and version of consent, consent withdrawal and suppression of further sending after unsubscription – legal basis: Article 6(1)(f) GDPR (the Controller’s legitimate interest in demonstrating compliance, defending against claims and ensuring that a person who unsubscribed does not receive further newsletter messages).

§4 – DATA RETENTION PERIOD

  1. 1.Personal data is stored for the period necessary to achieve the purposes for which it was collected, taking into account the requirements of generally applicable law.
  2. 2.Data collected via the contact form and the AI chat is stored for the duration of commercial negotiations and thereafter for the time necessary to pursue any claims – but no longer than 3 (three) years from the date of the last contact.
  3. 3.Data processed in connection with a concluded contract is stored for its duration and, after its end, for the period required by tax and accounting law (as a rule, 5 years from the end of the calendar year in which the tax payment deadline fell).
  4. 4.Data processed on the basis of the Controller’s legitimate interest is stored until an effective objection is raised or until the Controller’s legitimate interest ceases to exist.
  5. 5.Technical data (system logs) is stored for a period no longer than 90 (ninety) days.
  6. 6.Data processed for the purpose of sending the newsletter is stored until consent is withdrawn (unsubscription from the LetITBee Club). After unsubscription, the Controller may retain a limited technical record of the e-mail address, consent version/source, withdrawal date and unsubscribe token/status for the period necessary to document the withdrawal, defend against claims and prevent further sending.

§5 – RIGHTS OF DATA SUBJECTS

  1. 1.Every person whose personal data is processed by the Controller has the following rights: a. the right of access to their data and to obtain a copy of it (Article 15 GDPR), b. the right to rectification (correction) of their data (Article 16 GDPR), c. the right to erasure – the „right to be forgotten” (Article 17 GDPR), d. the right to restriction of processing (Article 18 GDPR), e. the right to data portability (Article 20 GDPR), f. the right to object to the processing of data (Article 21 GDPR).
  2. 2.To exercise the above rights, a request should be sent to the e-mail address: kontakt@letitbee.agency or in writing to the Controller’s registered address. The Controller will respond within no more than 30 (thirty) days of receiving the request and, in complex cases, within up to 90 (ninety) days, having first informed the data subject of the extension of the deadline and its reasons.
  3. 3.If a data subject considers that the processing of their personal data infringes the provisions of the GDPR, they have the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, e-mail: kancelaria@uodo.gov.pl.
  4. 4.Providing personal data via the contact form is voluntary but necessary to respond to an enquiry. Failure to provide the data marked as required makes it impossible for the Controller to make contact.

§6 – DATA RECIPIENTS AND PROCESSORS

  1. 1.Personal data may be transferred to the following categories of recipients: a. entities providing technical services to the Controller (hosting, databases, e-mail delivery), b. entities providing accounting and legal services – solely to the extent necessary to provide those services, c. public authorities entitled to receive data on the basis of legal provisions.
  2. 2.The Controller uses the following entities processing data on its behalf (processors): a. Vercel Inc. – application hosting and server infrastructure (USA; safeguard: EU Standard Contractual Clauses), b. Supabase Inc. – database and file storage (USA; safeguard: EU Standard Contractual Clauses), c. Resend Inc. – sending and receiving e-mail, including Club newsletters and unsubscribe handling (USA; safeguard: EU Standard Contractual Clauses), d. Anthropic PBC / Groq Inc. – processing queries within the AI chat function and AI-assisted preparation of administrative drafts, Club articles, newsletters or internal content suggestions, where such tools are used (USA; safeguard: EU Standard Contractual Clauses).
  3. 3.Transfers of data to third countries (outside the European Economic Area) take place solely on the basis of appropriate legal safeguards, in particular Standard Contractual Clauses approved by the European Commission (Article 46(2)(c) GDPR).
  4. 4.The Controller does not sell users’ personal data to third parties and does not make it available for marketing purposes without the explicit consent of the data subjects.

§7 – COOKIES AND TRACKING TECHNOLOGIES

  1. 1.The letitbee.agency website may use cookies – small text files saved on the user’s device to ensure the proper functioning of the website.
  2. 2.The following categories of cookies are used: a. essential – necessary for the proper functioning of the website (session, authentication), b. functional – remembering user preferences (e.g. language), c. analytical – website traffic and usage statistics used to improve the service, d. marketing – campaign measurement, conversion attribution and advertising tools, used only where required after consent.
  3. 3.The user may change cookie settings in their web browser or through the consent-management panel available on the website, including blocking storage or deleting already saved files. However, disabling essential cookies may affect the operation of the website.
  4. 4.The website may use analytics tools from external providers (e.g. Vercel Analytics). These tools may process anonymised technical data on website traffic solely for statistical purposes.

§8 – DATA SECURITY

  1. 1.The Controller applies appropriate technical and organisational measures ensuring the protection of the processed personal data against disclosure to unauthorised persons, loss or destruction, in particular: a. encryption of data transmission using the TLS/HTTPS protocol, b. encryption of data at rest, c. control of access to systems and databases, d. regular security audits of the technological solutions used.
  2. 2.In the event of a personal data breach resulting in a risk to the rights or freedoms of natural persons, the Controller will, without undue delay and no later than within 72 hours of becoming aware of the breach, report it to the President of the Personal Data Protection Office, in accordance with Article 33 GDPR.
  3. 3.Where the breach may result in a high risk to the rights or freedoms of natural persons, the Controller will also notify the data subjects without undue delay, in accordance with Article 34 GDPR.

§9 – AMENDMENTS TO THE PRIVACY POLICY

  1. 1.The Controller reserves the right to amend this Privacy Policy in the event of changes in the law, changes in the scope or manner of data processing, and in order to adapt the Policy to the Controller’s current practices.
  2. 2.Any amendments to the Privacy Policy will be published on letitbee.agency/polityka-prywatnosci with the date of their entry into force. Using the website after the amendments enter into force is tantamount to accepting them.
  3. 3.In the event of significant changes affecting the rights of data subjects, the Controller will make efforts to inform of them in a visible manner – through an appropriate announcement on the website’s home page.

Detailed cookie list

The list below is generated and kept up to date automatically by our consent platform (Cookiebot). It reflects the cookies and tracking technologies actually used on this site, together with their purpose and storage period.

Kraków, 2026 — LetITBee / Bartłomiej Poznański

This document is for informational purposes only. In matters not regulated herein, the provisions of Polish law apply, in particular the GDPR. The Polish-language version of this document is legally binding.

Related documents: Terms of Service