Privacy Policy

Last updated: 8 September 2026

This policy explains how COOKIE3 SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ ("Levorys") handles personal data. It is written to comply with Regulation (EU) 2016/679 (GDPR) and the Polish Act of 10 May 2018 on the Protection of Personal Data.

Levorys handles personal data in two distinct capacities, and the difference matters. This policy covers the first. The second is governed by a separate contract.

You areLevorys acts asGoverned by
This website, enquiries, and meetingsA visitor, prospect or contactController — Levorys decides why and how your data is usedThis policy
A client engagementAn employee of a Levorys clientProcessor — the client decides; Levorys acts on instructionsThe Data Processing Agreement between Levorys and that client

If you are an employee of a company that has engaged Levorys and you want to know how your interview responses are handled, that is your employer's decision as controller. Contact your employer, or write to us and we will direct you.


1. Controller

COOKIE3 SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ Aleje Jerozolimskie 89 / 43, 02-001 Warszawa, Poland KRS 0000961763 · NIP 7011080779

Contact for data protection matters: [email protected]

Levorys has not appointed a Data Protection Officer because, based on its current processing activities, it does not consider the appointment of a Data Protection Officer mandatory under Article 37 GDPR. For questions concerning personal data or this Privacy Policy, please contact us using the privacy contact details provided in this policy.

2. What we collect, why, and on what legal basis

2.1 Website visitors

We do not use advertising cookies, tracking pixels or cross-site profiling on this website.

This website does not use analytics software.

2.2 People who contact us or book a meeting

DataPurposeLegal basis
Name, business email, company, job title, and anything you choose to tell us in a message or meetingResponding to you, preparing for and holding the meetingSteps taken at your request prior to entering a contract — Art. 6(1)(b) GDPR
Notes we make about your company's situation and requirementsAssessing whether Levorys is a fit, and preparing a proposalLegitimate interest — Art. 6(1)(f) GDPR: conducting business-to-business sales
Meeting scheduling data (selected time, timezone, email address)Arranging the meetingArt. 6(1)(b) GDPR

Providing this data is voluntary, but without it we cannot respond to you or hold a meeting.

2.3 Client contacts during an engagement

Where Levorys enters into a contract with a client company, we process the business contact details of that company's representatives (name, role, business email, telephone) for the purpose of performing the contract — Art. 6(1)(b) and Art. 6(1)(f) GDPR — and for our own accounting and tax obligations under Art. 6(1)(c) GDPR.

3. Who receives your data

We do not sell personal data. We do not share it for third-party marketing.

We use the following service providers, each acting as a processor on our instructions under a data processing agreement:

ProviderPurposeLocationTransfer safeguard
Calendly LLCMeeting scheduling (the booking widget on this site)United StatesEU Standard Contractual Clauses; EU–US Data Privacy Framework where applicable
Cloudflare, Inc.Website hosting, content delivery, security and network infrastructure.Cloudflare operates a global network. Where applicable and enabled for the services used by Levorys, Cloudflare provides regional data-localization controls, including European Union processing and storage options.Cloudflare applies technical and organizational security measures to protect data. Where personal data is transferred outside the EEA, applicable transfer safeguards under Cloudflare’s Data Processing Addendum apply, including Standard Contractual Clauses where required.
Google Workspace (Google LLC)Business email, communication, calendar and meeting scheduling.Google operates infrastructure globally. For eligible Google Workspace editions and covered services, European data-region controls can be configured for supported data. Data not covered by a configured Data Regions policy may be processed in locations where Google or its subprocessors maintain facilities.Google Workspace is governed by Google’s Cloud Data Processing Addendum and applicable technical and organizational security measures. International transfers of personal data are handled using applicable data-transfer mechanisms and safeguards.

A current list of processors is available on request.

We may also disclose personal data to professional advisers (legal, accounting, audit) bound by confidentiality, and to public authorities where required by law.

4. Transfers outside the European Economic Area

Where a provider processes data outside the EEA, we rely on one of the safeguards permitted under Chapter V GDPR — an adequacy decision of the European Commission, or Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914, together with supplementary measures where a transfer risk assessment indicates they are required.

You may request a copy of the relevant safeguards by writing to [email protected].

5. How long we keep it

DataRetention
Enquiries that do not lead to a contract24 months from last contact, then deleted
Meeting and scheduling records24 months from the meeting
Client contract recordsDuration of the contract plus the statutory limitation period (in Poland, generally 6 years for commercial claims under Art. 118 of the Civil Code)
Accounting records5 years from the end of the tax year, as required by the Polish Accounting Act and Tax Ordinance

6. Your rights

Under Articles 15–22 GDPR you have the right to:

To exercise any of these, write to [email protected]. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month.

Right to complain. You may lodge a complaint with the Polish supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office) ul. Stawki 2, 00-193 Warszawa, Poland uodo.gov.pl

You may also complain to the supervisory authority in your country of residence or place of work.

7. Automated decision-making

We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing, within the meaning of Article 22 GDPR.

Levorys uses AI systems in delivering its services to clients. Where AI is used, findings are reviewed by people before they are acted upon, and the role of AI in producing them is disclosed. Those systems are not used to evaluate, score, rank or monitor individual employees.

8. Cookies

This website does not set cookies. No cookies, scripts or resources are loaded from Calendly, or from any other third party, unless and until you click "Book a conversation."

Clicking that button loads Calendly's scheduling widget, which sets the following cookies on Calendly's domain: __cf_bm (Cloudflare bot management) when the widget loads, and additionally _calendly_session and _cfuvid once you view the booking page itself. These are set by Calendly, not by Levorys, and are governed by Calendly's own privacy policy and cookie notice, available at calendly.com/legal/privacy-notice.

Because these cookies are only set after your own deliberate action, and are necessary for the scheduling feature you have chosen to use, no cookie consent banner is required under Article 173 of the Polish Telecommunications Act.

9. Security

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, access control on a need-to-know basis, and contractual confidentiality obligations on everyone with access.

10. Changes

We may update this policy. The current version is always published at this address, with the date of last update shown at the top. Material changes affecting your rights will be communicated directly where we hold your contact details.