Personal Data Controller
The controller of personal data collected via the fern-leopard.com website is fern leopard with its registered office in Warsaw, ul. Dobroczynna 15/3, 00-001 Warsaw.
For data protection matters, you can contact us by email: [email protected]
Scope of Data Collected
As part of using the service, we may collect the following personal data:
- First and last name — for identifying the contact person
- Email address — for responding to inquiries and conducting correspondence
- Organization name — for better tailoring of the offer
- Content of the message — for responding to the inquiry
- Technical data — IP address, browser type, visit time — for analytical and security purposes
Purposes of Data Processing
We process personal data for the following purposes:
- Responding to inquiries via the contact form
- Providing offers and information about services
- Conducting negotiations and concluding contracts
- Fulfilling legal obligations of the controller
- Asserting claims or defending against claims
- Analyzing website traffic and optimizing the service
Legal Basis for Processing
We process personal data based on:
- Consent of the data subject (Art. 6 sec. 1 lit. a GDPR) — when using contact forms
- Necessity for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract (Art. 6 sec. 1 lit. b GDPR)
- Legitimate interest of the controller (Art. 6 sec. 1 lit. f GDPR) — for analysis and security
- Fulfillment of a legal obligation (Art. 6 sec. 1 lit. c GDPR)
Data Retention Period
We store personal data for the period necessary to achieve the purposes for which it was collected:
- Data from contact forms — for the duration of correspondence and up to 3 years after its completion
- Data related to contract performance — for the duration of the contract and up to 6 years after its termination (statute of limitations for claims)
- Analytical data — up to 26 months
Rights of Data Subjects
In connection with the processing of personal data, you have the following rights:
- Right to access your data and obtain a copy of it
- Right to rectification (correction) of data
- Right to erasure of data (right to be forgotten)
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority (President of the Personal Data Protection Office)
Recipients of Data
Personal data may be shared with the following categories of recipients:
- Hosting and IT service providers
- Analytical service providers
- Legal and accounting service providers
- State authorities — solely based on legal provisions
Data Transfer Outside the EEA
Personal data is not transferred to third countries (outside the European Economic Area) or international organizations, unless required by applicable law or necessary for the provision of services (e.g., when using analytical tools). In this case, the transfer takes place in compliance with the appropriate safeguards provided for in the GDPR.
Automated Decision-Making
Personal data is not used for automated decision-making, including profiling, that would have legal effects or similarly significantly affect the data subject.
Data Security
We apply appropriate technical and organizational measures to ensure the security of personal data, including protection against unauthorized access, loss, destruction, or damage.
Changes to the Privacy Policy
The Privacy Policy may be updated periodically. We will inform about material changes through appropriate notices on the website. The current version of the Privacy Policy is always available on this page.
Last updated: December 2025