Szczecin.co
Privacy Policy of Szczecin.co
Last updated: 20.04.2026
This Privacy Policy contains information regarding the processing of personal data and other information concerning Users of the Szczecin.co website (hereinafter: the "Service"). This Privacy Policy aims to ensure compliance of personal data processing with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter "GDPR").
1. Data Controller
The controller of personal data is Michał Woźniak operating under the business name HEXGRID Michał Woźniak with its registered office in Szczecin (ul. Bagienna 36C, 70-772 Szczecin, Poland), registered in the Central Registry and Information on Business Activity (CEIDG) of the Republic of Poland, Tax ID (NIP): 9552112428, REGON: 320190228, email: kontakt@szczecin.co, hereinafter the "Controller".
2. Contact with the Controller
- Email: kontakt@szczecin.co
- Address: ul. Bagienna 36c, 70-772 Szczecin
- Phone: +48 537 357 057
3. Data Protection Officer
Email: iod@szczecin.co
Address: HEXGRID Michał Woźniak, ul. Bagienna 36c, 70-772 Szczecin
Phone: +48 537 357 057
4. Personal Data Security
The Controller implements modern technical measures and organizational solutions to ensure the protection of processed personal data, in particular securing data against disclosure to unauthorized persons, acquisition by an unauthorized person, processing in violation of applicable regulations, and alteration, loss, damage or destruction. The Controller processes personal data in accordance with the GDPR and Polish data protection regulations, including the Act of 10 May 2018 on the Protection of Personal Data.
5. Purposes, Legal Bases, and Retention Period
Each purpose of personal data processing is described below together with information on the scope of processed data, legal basis, retention period, and the voluntariness of providing data:
Scope: first name, email address, password (hashed). Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Retention: for the duration of the account, then 3 years after deletion. Voluntary: required to create an account.
Scope: name or entity name, email address, content of the listing or submission, business data (optional). Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Retention: for the duration of publication and 3 years thereafter. Voluntary: required to publish content.
Scope: content of queries entered by the User. Legal basis: Art. 6(1)(f) GDPR (legitimate interest, providing the AI service). Retention: queries are not permanently stored after the session ends. Voluntary: use of the AI assistant is optional.
Scope: email address, first name (optional). Legal basis: Art. 6(1)(b) GDPR (newsletter subscription contract) and Art. 6(1)(f) GDPR (legitimate interest, direct marketing). Retention: until unsubscription or effective objection. Voluntary: entirely optional.
Scope: name, email address, phone number, complaint content. Legal basis: Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(b) GDPR (contract performance). Retention: until the complaint is resolved, then until claims are time-barred. Voluntary: required to process the complaint.
Scope: name, email address, message content, phone number (optional). Legal basis: Art. 6(1)(f) GDPR (legitimate interest, communication with Users). Retention: until the inquiry is resolved, then until claims are time-barred. Voluntary: required to receive a response.
Scope: name, email address, data included in the request. Legal basis: Art. 6(1)(c) GDPR (legal obligation under GDPR) and Art. 6(1)(f) GDPR (legitimate interest). Retention: until the request is fulfilled, then until claims are time-barred.
Scope: name, email address, Service usage data and any other data necessary to establish or defend claims. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Retention: until claims are time-barred.
Scope: date and time of visits, IP address, device type, screen resolution, OS type, approximate location (country, region, city), browser type, time spent on pages, visited subpages, entry source. Legal basis: Art. 6(1)(f) GDPR (legitimate interest, improving the Service). Retention: 26 months. Data collected automatically.
Scope: IP address, server date and time, browser information, OS information, recorded automatically in server logs. Legal basis: Art. 6(1)(f) GDPR (legitimate interest, administration and security). Retention: no longer than 90 days. Collected automatically.
6. Profiling
The Controller declares that it does not make decisions based solely on automated processing, including profiling, which would produce legal effects or similarly significantly affect Users. The Controller may use profiling for analytical purposes, i.e. tailoring displayed content to a User's interests based on their activity in the Service. Such profiling is automated but does not produce legal effects or significantly affect the User's situation. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
7. Recipients of Personal Data
In connection with carrying out activities requiring the processing of personal data, Users' personal data may be disclosed to external entities, including in particular the following categories of recipients:
- Hosting company, for storing data on the server
- IT and technology service providers (including software providers, email service providers)
- Analytics service providers (Google Analytics)
- AI model providers, for operating the AI assistant (query content is passed without identifying data)
- Law firms, for establishing or defending against claims
- State authorities and other entities authorized by law, when required by applicable regulations
8. Transfer of Data to Third Countries
Some Users' personal data may be transferred to third countries (outside the European Economic Area). This applies in particular to the following entities:
9. User Rights Regarding Personal Data Processing
Each User whose personal data is processed by the Controller has the following rights under the GDPR:
- Right of access (Art. 15 GDPR), the right to obtain confirmation as to whether personal data concerning the User is being processed, and if so, access to that data and related information.
- Right to rectification (Art. 16 GDPR), the right to request immediate correction of inaccurate personal data and completion of incomplete data.
- Right to erasure ("right to be forgotten") (Art. 17 GDPR), the right to request immediate deletion of personal data where one of the grounds in Art. 17(1) GDPR applies.
- Right to restriction of processing (Art. 18 GDPR), the right to request restriction of processing in the cases set out in Art. 18(1) GDPR.
- Right to data portability (Art. 20 GDPR), the right to receive personal data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR), the right to object at any time to processing of personal data based on Art. 6(1)(e) or (f) GDPR, including profiling.
- Right to withdraw consent (Art. 7(3) GDPR), the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR), the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).
To exercise the above rights, the User should contact the Controller at kontakt@szczecin.co or in writing at the Controller's registered office. The Controller responds without undue delay, no later than one month from receipt of the request.
10. Cookies and Analytics
The Service uses cookies, small text files stored on the User's end device (computer, tablet, smartphone). Cookies may be read by the Controller's own IT systems (first-party cookies) or third-party IT systems (third-party cookies).
Essential cookies, necessary for the Service to function properly; enable the use of services such as authentication and session cookies. Retention: until the browser session ends or up to 1 year.
Google Tag Manager, manages analytics and marketing tags; collects no data without active tags. Provider: Google LLC (USA). Retention: up to 2 years.
Google Analytics, analytics cookies from Google LLC, used to analyze how Users use the Service, generate statistics and reports. Retention: _ga, 2 years, _ga_*, 2 years, _gid, 24 hours, _gat, 1 minute.
The User can change cookie settings at any time by clicking the cookie icon in the bottom left corner of the Service, or directly in the browser settings. Essential cookies required for the proper functioning of the Service cannot be disabled.
11. Final Provisions
The Controller reserves the right to make changes to this Privacy Policy, of which Users will be notified no later than 7 days before the changes take effect. Changes may result from changes in the law, changes in the Service's functionality, or changes in the scope of services provided. This Privacy Policy has been in effect since 11 June 2026.