Privacy Policy
Last updated: 8 September 2026
This policy explains how COOKIE3 SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ ("Levorys") handles personal data. It is written to comply with Regulation (EU) 2016/679 (GDPR) and the Polish Act of 10 May 2018 on the Protection of Personal Data.
Levorys handles personal data in two distinct capacities, and the difference matters. This policy covers the first. The second is governed by a separate contract.
| You are | Levorys acts as | Governed by | |
|---|---|---|---|
| This website, enquiries, and meetings | A visitor, prospect or contact | Controller — Levorys decides why and how your data is used | This policy |
| A client engagement | An employee of a Levorys client | Processor — the client decides; Levorys acts on instructions | The Data Processing Agreement between Levorys and that client |
If you are an employee of a company that has engaged Levorys and you want to know how your interview responses are handled, that is your employer's decision as controller. Contact your employer, or write to us and we will direct you.
1. Controller
COOKIE3 SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ Aleje Jerozolimskie 89 / 43, 02-001 Warszawa, Poland KRS 0000961763 · NIP 7011080779
Contact for data protection matters: alex.wolf@levorys.com
Levorys has not appointed a Data Protection Officer because, based on its current processing activities, it does not consider the appointment of a Data Protection Officer mandatory under Article 37 GDPR. For questions concerning personal data or this Privacy Policy, please contact us using the privacy contact details provided in this policy.
2. What we collect, why, and on what legal basis
2.1 Website visitors
We do not use advertising cookies, tracking pixels or cross-site profiling on this website.
This website does not use analytics software.
2.2 People who contact us or book a meeting
| Data | Purpose | Legal basis |
|---|---|---|
| Name, business email, company, job title, and anything you choose to tell us in a message or meeting | Responding to you, preparing for and holding the meeting | Steps taken at your request prior to entering a contract — Art. 6(1)(b) GDPR |
| Notes we make about your company's situation and requirements | Assessing whether Levorys is a fit, and preparing a proposal | Legitimate interest — Art. 6(1)(f) GDPR: conducting business-to-business sales |
| Meeting scheduling data (selected time, timezone, email address) | Arranging the meeting | Art. 6(1)(b) GDPR |
Providing this data is voluntary, but without it we cannot respond to you or hold a meeting.
2.3 Client contacts during an engagement
Where Levorys enters into a contract with a client company, we process the business contact details of that company's representatives (name, role, business email, telephone) for the purpose of performing the contract — Art. 6(1)(b) and Art. 6(1)(f) GDPR — and for our own accounting and tax obligations under Art. 6(1)(c) GDPR.
3. Who receives your data
We do not sell personal data. We do not share it for third-party marketing.
We use the following service providers, each acting as a processor on our instructions under a data processing agreement:
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Calendly LLC | Meeting scheduling (the booking widget on this site) | United States | EU Standard Contractual Clauses; EU–US Data Privacy Framework where applicable |
| Cloudflare, Inc. | Website hosting, content delivery, security and network infrastructure. | Cloudflare operates a global network. Where applicable and enabled for the services used by Levorys, Cloudflare provides regional data-localization controls, including European Union processing and storage options. | Cloudflare applies technical and organizational security measures to protect data. Where personal data is transferred outside the EEA, applicable transfer safeguards under Cloudflare’s Data Processing Addendum apply, including Standard Contractual Clauses where required. |
| Google Workspace (Google LLC) | Business email, communication, calendar and meeting scheduling. | Google operates infrastructure globally. For eligible Google Workspace editions and covered services, European data-region controls can be configured for supported data. Data not covered by a configured Data Regions policy may be processed in locations where Google or its subprocessors maintain facilities. | Google Workspace is governed by Google’s Cloud Data Processing Addendum and applicable technical and organizational security measures. International transfers of personal data are handled using applicable data-transfer mechanisms and safeguards. |
A current list of processors is available on request.
We may also disclose personal data to professional advisers (legal, accounting, audit) bound by confidentiality, and to public authorities where required by law.
4. Transfers outside the European Economic Area
Where a provider processes data outside the EEA, we rely on one of the safeguards permitted under Chapter V GDPR — an adequacy decision of the European Commission, or Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914, together with supplementary measures where a transfer risk assessment indicates they are required.
You may request a copy of the relevant safeguards by writing to alex.wolf@levorys.com.
5. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not lead to a contract | 24 months from last contact, then deleted |
| Meeting and scheduling records | 24 months from the meeting |
| Client contract records | Duration of the contract plus the statutory limitation period (in Poland, generally 6 years for commercial claims under Art. 118 of the Civil Code) |
| Accounting records | 5 years from the end of the tax year, as required by the Polish Accounting Act and Tax Ordinance |
6. Your rights
Under Articles 15–22 GDPR you have the right to:
- access your personal data and receive a copy
- rectify inaccurate or incomplete data
- erase your data ("right to be forgotten"), where one of the grounds in Art. 17 applies
- restrict processing in the circumstances set out in Art. 18
- data portability — receive data you provided in a structured, machine-readable format, where processing is based on consent or contract and is automated
- object to processing based on legitimate interest, on grounds relating to your particular situation (Art. 21). Where you object to direct marketing, we will stop without exception.
- withdraw consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these, write to alex.wolf@levorys.com. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.
Right to complain. You may lodge a complaint with the Polish supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office) ul. Stawki 2, 00-193 Warszawa, Poland uodo.gov.pl
You may also complain to the supervisory authority in your country of residence or place of work.
7. Automated decision-making
We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing, within the meaning of Article 22 GDPR.
Levorys uses AI systems in delivering its services to clients. Where AI is used, findings are reviewed by people before they are acted upon, and the role of AI in producing them is disclosed. Those systems are not used to evaluate, score, rank or monitor individual employees.
8. Cookies
This website does not set cookies. No cookies, scripts or resources are loaded from Calendly, or from any other third party, unless and until you click "Book a conversation."
Clicking that button loads Calendly's scheduling widget, which sets the following cookies on Calendly's domain: __cf_bm (Cloudflare bot management) when the widget loads, and additionally _calendly_session and _cfuvid once you view the booking page itself. These are set by Calendly, not by Levorys, and are governed by Calendly's own privacy policy and cookie notice, available at calendly.com/legal/privacy-notice.
Because these cookies are only set after your own deliberate action, and are necessary for the scheduling feature you have chosen to use, no cookie consent banner is required under Article 173 of the Polish Telecommunications Act.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, access control on a need-to-know basis, and contractual confidentiality obligations on everyone with access.
10. Changes
We may update this policy. The current version is always published at this address, with the date of last update shown at the top. Material changes affecting your rights will be communicated directly where we hold your contact details.