This policy explains what personal data salecki.digital collects through this website, why it is collected, and how it is used, stored, and protected. Please read it before submitting any personal information.
01Data Controller
The controller responsible for personal data collected through this website is:
Mikołaj Salecki, sole trader registered in Poland, trading as salecki.digital
ul. Gen. Jasińskiego 11/51, 05-500 Piaseczno, Poland
NIP: 1231052003 · REGON: 361948200
Email: hi@salecki.digital · Phone: +48 780 607 707
As controller, Mikołaj Salecki determines the purposes and means of processing your personal data and is responsible for ensuring that processing complies with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Polish data protection law. In this policy, "salecki.digital" refers to the controller.
salecki.digital has not appointed a Data Protection Officer (DPO). Under GDPR Art. 37, sole traders are not required to designate a DPO unless their core activities consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale. salecki.digital's processing does not meet that threshold.
02Personal Data Collected
salecki.digital collects only data you actively provide and does not purchase, rent, or obtain personal data from third-party sources.
Contact form
When you submit the contact form, salecki.digital collects:
- Required: first name, email address, message content
- Optional: last name, phone number, website URL, file attachment (TXT, PDF, DOC, DOCX, PNG, JPG, max 20 MB)
- Record: the date and time of the inquiry and the version of the data notice shown next to the form
There is no consent checkbox for the inquiry itself: sending the form is a request to be answered, and answering it is the processing (see §03). Providing the required fields is not a statutory or contractual requirement, but without them salecki.digital cannot reply. The message and any attachment reach salecki.digital as a notification email sent through Resend and are kept with that email. Your name and email address are also saved as a contact at Resend, with the record listed above. The optional newsletter box on the contact form works exactly like the newsletter signup below, including the confirmation step.
Newsletter subscription
When you subscribe, salecki.digital collects your email address. A double opt-in process is used: you receive a confirmation email, open the link inside, and press the confirm button on the page it opens, within 48 hours. Only then are you added to the mailing list, together with a consent record: the date and time of confirmation, the version of the consent text you agreed to, and the form you used. Opening the link alone confirms nothing, so a security scanner that checks links in your mailbox cannot subscribe you. The confirmation link is signed with HMAC-SHA256 and is stateless: no database stores pending subscriptions. The part of the link that identifies you sits after the "#" sign, which browsers never send to a server, so it does not appear in access logs.
Lead magnets: the ADAM Framework Playbook and the Tymbre case study
When you request one of the two PDFs (on /adam or /tymbre-case-study), salecki.digital collects your email address, the date and time of the request, the PDF and its version, and the version of the data notice shown with the form. You receive an email with a download link, valid for 14 days; the link identifies the PDF, not you. The contact is added to a dedicated "Lead magnet" audience at Resend, separate from the newsletter.
If you tick the optional newsletter box alongside your request, salecki.digital also sends you the newsletter confirmation email described above. You are added to the newsletter only after you confirm, and you may withdraw that consent at any time via the unsubscribe link in any newsletter email.
AI browser agents (WebMCP)
The three forms are also available to AI assistants running in your browser, through the WebMCP interface. A request made that way is processed exactly like one made by hand. A newsletter subscription still requires you to press the confirm button in the confirmation email yourself.
Website analytics (Kehai)
Page-view statistics are measured with Kehai, analytics software that runs on salecki.digital's own server in Warsaw, at stats.kehai.io. No data about your visit goes to Google or to any other analytics company.
What it does not do. It sets no cookie. It writes nothing into your browser's storage and reads nothing from it. It cannot recognize you on any other website. It builds no profile, feeds no advertising audience, and its numbers are neither sold nor shared.
What it does. Your browser sends the address of the page (never its title), the hostname of the site you arrived from (never the full address), your window and screen size, your browser language, how long the page was visible, and the four named actions this site counts: a file request, a contact message sent, a newsletter signup and its confirmation. The server adds what it reads from the request itself: browser, operating system, device type, and the country, region and city your Internet address belongs to. The address itself is never stored or logged.
How one visitor is told from another. There is no identifier for you, on your device or in the database. The server derives a one-way hash from the site, your Internet address and your browser's user agent, together with a secret it replaces every midnight UTC, so a person is counted once a day and nothing connects one day to the next. The hash cannot be reversed and points at nobody.
How to switch it off. Two ways, both honored. Turn on Do Not Track in your browser and nothing is sent. Or block stats.kehai.io in a content blocker. The site works exactly the same either way.
Server logs and error reports
The web server and the API keep technical logs on the server provided by OVH Sp. z o.o. (see §05): the time of each request, the address and method requested, the response status, the browser's user agent and the referring page, and, for the API, a request ID and the error when something fails. They do not contain your IP address: the servers sit behind Cloudflare and the hosting proxy, and see only their addresses. The logs are used only for security, debugging, and abuse prevention, and are not linked to other data or used for statistics.
If a script on this website fails in your browser, or your browser blocks something under the site's security policy, it sends a short technical report to the server: the error message, the script and position, and the page path. The report contains no form data and nothing that identifies you, and it is kept with the server logs.
Embedded third-party content
The /now page embeds:
- YouTube and Spotify · neither player is added to the page on its own. In place of each one you see a button, and nothing is requested from YouTube or Spotify until you press it. Once you do, the YouTube embed loads from the privacy-preserving
youtube-nocookie.comdomain, Spotify loads its standard embed, and each service applies its own terms and cookies from that point on
Data not collected
salecki.digital does not collect payment card data, government identification numbers, or any special categories of personal data under GDPR Article 9, including health data, political opinions, religious beliefs, trade union membership, genetic data, or biometric data.
03Legal Bases for Processing
Every processing activity is based on a valid legal basis under GDPR Article 6:
| Processing activity | Legal basis | GDPR Art. 6 |
|---|---|---|
| Responding to your contact inquiry | Steps taken at your request: you ask to be answered, and answering is the processing | 6(1)(b) |
| Follow-up on an active business inquiry | Legitimate interest: maintaining professional communication you initiated | 6(1)(f) |
| Newsletter delivery | Consent: the newsletter box or signup, confirmed by double opt-in | 6(1)(a) |
| Website statistics (Kehai) | Legitimate interest: knowing how the site is used, measured without cookies, identifiers, or profiles | 6(1)(f) |
| Delivery of a requested PDF (ADAM Playbook, Tymbre case study) | Performance of contract: you requested the file, delivery is the agreement | 6(1)(b) |
| Form rate limiting, error and security reports | Legitimate interest: keeping the forms available and the site working | 6(1)(f) |
| Network security, anti-DDoS, anti-fraud (Cloudflare) | Legitimate interest: protecting site availability and integrity | 6(1)(f) |
| Server logs & debugging | Legitimate interest: debugging, abuse prevention, infrastructure security | 6(1)(f) |
| Legal and accounting obligations | Legal obligation: Polish Accounting Act and applicable tax law | 6(1)(c) |
Where processing is based on consent, you may withdraw it at any time without giving a reason. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Where salecki.digital relies on legitimate interest (Art. 6(1)(f)), a balancing test has been conducted confirming that the legitimate interest does not override your rights and freedoms. You may object to legitimate-interest processing at any time (see §09 Right to object).
04Data Retention
salecki.digital retains data only as long as necessary for the purpose it was collected, and no longer than required by law:
| Data category | Retention period | Reason |
|---|---|---|
| Contact form submissions (Resend "Contact form leads" audience) | 24 months from last correspondence | Maintaining business relationship |
| Contact form messages and attachments (Resend email) | Per Resend's transactional email retention | Email delivery and audit trail |
| Newsletter subscriber email (Resend "Newsletter" audience) | Until unsubscription. Suppression list retained indefinitely. | Active consent. Suppression prevents accidental re-mailing. |
| Lead magnet recipients (Resend "Lead magnet" audience) | 24 months from request. Suppression on opt-out. | Knowing who received which PDF, for support and follow-up |
| Consent records (date, consent text version, source) | 5 years from consent date | Demonstrating GDPR compliance (Art. 7(1)) |
| Website statistics (Kehai) | 10 years | Long-term traffic trends. The visitor hash in each record is made with a secret replaced every midnight UTC, so a record cannot be linked to a person or to another day (see §02). |
| Anti-spam hashes (server memory) | 1 hour | Rate limiting (see §06) |
| Server logs and error reports | Rotated by size, at most 30 MB per service, and deleted whenever the service is redeployed | Security, debugging, abuse prevention |
| Cloudflare security event logs | Per Cloudflare retention | Anti-DDoS / anti-fraud audit trail |
| Accounting and legal records | 5 years from end of relevant calendar year | Polish Accounting Act (ustawa o rachunkowości) |
After the applicable period, data is securely deleted or anonymized so it can no longer be linked to any individual. The exact wording of every consent text and data notice this site has shown, by version, is archived in the site's source code.
05Recipients and International Transfers
salecki.digital shares data with the following processors acting on its behalf. Personal data is never sold or rented. All processors have appropriate data processing agreements (Art. 28 DPAs) in place.
Cloudflare, Inc. · USA / global edge network
Role: CDN, DNS provider, reverse proxy, TLS terminator, web application firewall, anti-DDoS / anti-bot protection.
Data processed: IP address, request URL, HTTP method, headers, user agent, geolocation derived from IP, security event data (only when triggered by a challenge or rate limit).
Cookies: cf_clearance when a security challenge is presented, and __cf_bm from its bot protection (see §07). Both are strictly necessary.
Transfer: Cloudflare is headquartered in the USA, and data may transit the global edge network. Transfers are covered by Cloudflare's participation in the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (GDPR Art. 46(2)(c)) where applicable.
cloudflare.com/privacypolicy
OVH Sp. z o.o. (OVHcloud) · Poland (EU/EEA)
Role: Infrastructure (dedicated server hosting). The salecki.digital website and API server run inside Docker containers managed by Coolify on an OVHcloud dedicated server.
Data processed: IP address (in server logs), application logs (HTTP requests, errors), all data transmitted to or stored by the application during processing.
Transfer: The server is located in OVHcloud's Warsaw data centre (Poland) and OVH Sp. z o.o. is established in Wrocław, Poland. Processing takes place entirely within Poland. No third-country transfer.
ovhcloud.com/personal-data-protection
Resend, Inc. · USA (data hosted in the EU)
Role: Email service provider. Sends transactional emails (contact-form notification, newsletter confirmation, download link) and stores audience contact records (email, name, and the records described in §02).
Data processed: Email addresses, names (first/last), phone (if provided in contact form), website URL (if provided), message content, contact-form attachments, consent records.
Transfer: Resend, Inc. is incorporated in the United States. salecki.digital configures its Resend account to use the EU sending region (eu-west-1, Ireland), so email content and audience data are processed and stored within the EU/EEA. Transfers to the US (control-plane, billing) are covered by Standard Contractual Clauses (GDPR Art. 46(2)(c)) under Resend's Data Processing Agreement.
resend.com/legal/privacy-policy
Website statistics (Kehai) · no third party
Role: Kehai, the software that counts page views, runs on salecki.digital's own server (see OVH Sp. z o.o. above, which provides the machine and nothing else). The statistics are not shared with anyone.
YouTube (Google LLC) and Spotify AB · embedded media on /now
Click to load: Neither player is added to the page on its own. In place of each one you see a button, and until you press it your browser sends nothing to YouTube or Spotify and neither service sets a cookie.
YouTube (after you press the button): The /now page embeds YouTube videos via the privacy-preserving youtube-nocookie.com domain. From that point Google's standard YouTube terms and privacy practices apply.
Spotify (after you press the button): The /now page embeds Spotify content. Spotify AB (Sweden, EU/EEA) is the data controller for embedded interactions.
YouTube/Google policy · spotify.com/legal/privacy-policy
No advertising or social-media tracking
This website uses no advertising, retargeting, social-media, or cross-site profiling technology, and no third-party analytics.
06Anti-spam Protection
To protect the forms from abuse and keep email delivery working, salecki.digital limits how often the contact form, the newsletter form, and the download form can be used. For each form it counts submissions per pseudonymized hash of your IP address and per pseudonymized hash of the email address you enter. The hashes are created with SHA-256 and a server-secret salt, which makes them non-reversible without that salt.
The limits are 10 submissions per hour from one IP address and 3 per hour for one email address, per form. The hashes are held in server memory only, discarded after one hour, and never written to disk, included in logs, or shared with third parties. A hidden field that people never see, but form-filling bots do fill, is the second check: a submission with it filled is accepted and silently dropped.
Legal basis
Legitimate interest under GDPR Art. 6(1)(f): preventing form abuse, protecting transactional email service quotas, and maintaining service availability for legitimate users. salecki.digital has conducted a balancing test: the impact on data subjects is minimal (pseudonymized identifiers with a one-hour life, no profiling, no third-party sharing), while the risk of unprotected forms (spam abuse, service disruption, blocked email reputation) materially affects salecki.digital and other users of the service.
Right to object
You can object to this processing under GDPR Art. 21 by contacting hi@salecki.digital. salecki.digital will balance any objection against the legitimate interest in maintaining anti-spam protection. Note that disabling rate limiting would compromise the forms' availability for everyone.
08Security Measures
salecki.digital implements appropriate technical and organizational measures to protect personal data against unauthorized access, accidental loss, alteration, or disclosure (GDPR Art. 32):
- TLS 1.2+ encryption on all connections, with HSTS enabled and preloaded (
max-age=31536000; includeSubDomains; preload) - A strict Content Security Policy: the site runs only its own scripts and the analytics script named in §02
- Cloudflare's reverse proxy and web application firewall in front of the server, and per-form rate limits in the application (see §06)
- Containerized application infrastructure on an OVHcloud dedicated server in Warsaw, with the API running as an unprivileged user
- HMAC-SHA256-signed confirmation and download links, stateless, with no database of pending requests
- Restricted access to Resend (email service) and the Cloudflare and OVHcloud control panels
- Dependency vulnerability scanning and periodic security audits
In the event of a personal data breach likely to result in a risk to your rights and freedoms, salecki.digital will notify the Polish supervisory authority (UODO) within 72 hours where feasible (GDPR Art. 33) and notify affected individuals without undue delay where required (GDPR Art. 34).
09Your Rights Under GDPR
- Right of access (Art. 15): request a copy of personal data salecki.digital holds about you, and how it is processed.
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): request deletion when data is no longer necessary, when you withdraw consent, or when processing is unlawful.
- Right to restriction (Art. 18): request that salecki.digital pause processing while you contest accuracy or object.
- Right to data portability (Art. 20): where processing is based on consent or contract and carried out by automated means, request your data in a structured, machine-readable format (e.g. CSV).
- Right to object (Art. 21): object to processing based on legitimate interest. Processing stops unless compelling grounds are demonstrated that override your interests.
- Right to withdraw consent (Art. 7(3)): withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right not to be subject to automated decision-making (Art. 22): see §12. salecki.digital does not perform automated decision-making.
10How to Exercise Your Rights
Email: hi@salecki.digital
Subject line: "GDPR request: [specify right]"
Postal mail: ul. Gen. Jasińskiego 11/51, 05-500 Piaseczno, Poland
Response time: Within one month of receiving your request. Complex or numerous requests may take up to two further months; if so, you are told within the first month (GDPR Art. 12(3)).
To protect your privacy, salecki.digital may ask you to verify your identity, typically by confirming the email address associated with your data. No fee is charged unless requests are manifestly unfounded, repetitive, or excessive (GDPR Art. 12(5)).
11Right to Lodge a Complaint
If you believe salecki.digital is processing your data in violation of GDPR, you may lodge a complaint with the Polish supervisory authority:
Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
uodo.gov.pl · kancelaria@uodo.gov.pl · +48 606 950 000
You may also lodge a complaint with the supervisory authority of the EU member state where you reside, work, or where the alleged infringement occurred. salecki.digital encourages you to make contact first. Data protection concerns are taken seriously and resolved promptly.
12Automated Decision-Making and Profiling
salecki.digital does not use automated decision-making or profiling as defined in GDPR Article 22. No decisions with legal or similarly significant effects are made solely by automated means based on data collected through this website.
salecki.digital also does not engage in profiling or behavior-based targeting. Personal data is not analyzed to predict aspects concerning your performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
13Minors
This website targets business professionals and is not directed at individuals under 16. salecki.digital does not knowingly collect data from minors. If such collection is discovered, the data will be deleted promptly. Please notify hi@salecki.digital if you believe this has occurred.
14Updates to This Policy
salecki.digital may update this Privacy Policy to reflect changes in data practices, applicable law, or services used. The "Effective" date at the top shows when it was last revised. Material changes will be communicated to newsletter subscribers before taking effect, and a notice will appear on the website homepage. Reviewing this policy periodically is recommended.
For information about your obligations and limitations when using this Website, see the Terms of Use.