kosinski growth
Privacy Policy
Last updated: 22 July 2026
This Privacy Policy explains how personal data is collected, used and protected when you visit the website kosinskigrowth.com or contact its owner.
1. Data Controller
The controller of your personal data is: PPC747 operated by Krystian Kosiński
Tax Identification Number (NIP): 8762433227
ul. prof. Stefana Hausbrandta 32/30
80-126 Gdańsk, Poland
Contact details:
E-mail: contact@kosinskigrowth.com
Phone: +48 791 656 570
────────────────────────────────────────────────
2. Scope of Data Processing
Personal data may be processed when you:
contact the Data Controller by e-mail,
use a contact form or another communication feature available on the website,
enter into discussions concerning potential cooperation,
visit and use the website.
Depending on the way you interact with the website, the processed data may include:
your name and surname,
your e-mail address,
your telephone number,
your company name or professional details,
the content of your message,
your IP address,
technical information concerning your device, browser and use of the website.
Providing personal data is voluntary. However, it may be necessary to respond to your message, prepare an offer or establish cooperation.
────────────────────────────────────────────────
3. Purposes and Legal Basis of Processing
Personal data may be processed for the following purposes:
Responding to enquiries
Data submitted by e-mail, contact form or another communication channel is processed in order to respond to your enquiry and continue correspondence.
The legal basis is the Data Controller’s legitimate interest in communicating with persons interested in contacting or cooperating with the Data Controller.
Where your enquiry concerns a potential agreement, the data may also be processed in order to take steps at your request before entering into a contract.
Performance of agreements
Where cooperation is established, personal data may be processed in order to perform the agreement and manage the business relationship.
Compliance with legal obligations
Data may be processed where required by applicable tax, accounting or other legal obligations.
Website security and administration
Technical data, including IP addresses and server logs, may be processed to ensure the security, stability and correct operation of the website and to prevent abuse.
Analytics and marketing
Analytical or marketing technologies are used only where permitted by law and, where required, after obtaining your consent.
Marketing information may be sent only where there is an appropriate legal basis, including your consent where such consent is required.
────────────────────────────────────────────────
4. Cookies and Similar Technologies
The website may use cookies and similar technologies.
Cookies may be used for the following purposes:
ensuring the correct technical operation of the website,
maintaining security and preventing abuse,
remembering website settings and user preferences,
analysing website traffic and performance,
measuring the effectiveness of marketing activities,
supporting advertising or remarketing activities, where applicable.
Cookies may be divided into the following categories:
Necessary cookies
These cookies are required for the technical operation, security and basic functionality of the website.
Functional cookies
These cookies may remember selected preferences, such as language, appearance or other website settings.
Analytical cookies
These cookies help understand how visitors use the website and support improvements to its content and performance.
Marketing cookies
These cookies may be used to measure advertising activities or provide content based on user interests.
Non-essential cookies are used only after obtaining consent where such consent is legally required.
You may change your cookie preferences through the consent tool available on the website or through your browser settings. Disabling certain cookies may affect some website functions.
────────────────────────────────────────────────
5. Server Logs and IP Addresses
As part of the normal operation of the website, the hosting or website provider may automatically record technical information in server logs.
This information may include:
the public IP address,
the date and time of the request,
the requested URL,
browser and device information,
information about errors and website activity.
Server logs are used only for website administration, security, diagnostics and preventing abuse.
An IP address may constitute personal data where it can be linked to an identifiable person.
────────────────────────────────────────────────
6. Analytics and External Services
The website may use external technology and analytics providers, including services supplied by Google or other website infrastructure, hosting and measurement providers.
Depending on the website configuration, these services may process technical information concerning visits to the website.
Google Analytics does not log or retain individual IP addresses collected from users in the European Union, Switzerland or the United Kingdom. IP data is used to derive approximate geolocation and is then discarded before being logged.
Where analytics or advertising technologies require user consent, they should remain disabled until the appropriate consent is provided. Google’s consent framework distinguishes, among other things, consent for analytics storage, advertising storage, advertising user data and personalisation.
────────────────────────────────────────────────
7. Recipients of Personal Data
Personal data may be disclosed to entities supporting the Data Controller in operating the website and conducting business activities, including:
website, hosting and domain providers,
e-mail and cloud service providers,
analytics and advertising providers,
accounting, legal and IT service providers,
contractors processing data on behalf of the Data Controller,
public authorities or courts, where disclosure is required by law.
Data is disclosed only to the extent necessary for the relevant purpose.
────────────────────────────────────────────────
8. Transfers Outside the European Economic Area
Some technology providers may process data outside the European Economic Area.
Where such transfers occur, they are carried out in accordance with applicable data protection law and based on appropriate safeguards, such as:
an adequacy decision issued by the European Commission,
Standard Contractual Clauses,
another legally recognised transfer mechanism.
Google’s data protection terms provide mechanisms for restricted transfers, including Standard Contractual Clauses where applicable.
────────────────────────────────────────────────
9. Data Retention
Personal data is retained only for as long as necessary for the purpose for which it was collected.
In particular:
correspondence data may be retained for the period necessary to handle the enquiry and protect against potential claims;
data related to an agreement may be retained for the duration of the cooperation and for the period required by tax, accounting and limitation laws;
data processed on the basis of consent may be retained until the consent is withdrawn;
analytical data may be retained according to the settings and retention periods configured in the relevant analytical tools;
server logs may be retained for the period necessary to maintain website security and diagnose technical issues;
recruitment-related data, where applicable, may be retained for the duration of the recruitment process or for up to one year where separate consent has been provided.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
────────────────────────────────────────────────
10. Your Rights
Under applicable data protection law, you may have the right to:
access your personal data,
obtain a copy of your data,
rectify inaccurate or incomplete data,
request deletion of your data,
request restriction of processing,
object to processing based on legitimate interests,
receive your data in a structured, commonly used and machine-readable format,
request the transfer of your data to another controller where technically feasible,
withdraw consent at any time where processing is based on consent,
lodge a complaint with a supervisory authority.
In Poland, the competent supervisory authority is the:
President of the Personal Data Protection Office
Prezes Urzędu Ochrony Danych Osobowych
Requests concerning personal data may be submitted to:
────────────────────────────────────────────────
11. Automated Decision-Making
Personal data collected through the website is not used to make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.
────────────────────────────────────────────────
12. Data Security
The Data Controller applies appropriate technical and organisational measures to protect personal data against:
unauthorised access,
unlawful processing,
accidental loss,
destruction,
alteration,
unauthorised disclosure.
However, no method of transmitting or storing data electronically can guarantee absolute security.
────────────────────────────────────────────────
13. Changes to This Privacy Policy
This Privacy Policy may be updated where necessary, including due to:
changes in applicable law,
changes to website functionality,
the implementation of new analytics or marketing technologies,
changes to the services used by the Data Controller.
The current version of the Privacy Policy will always be available on this website.
────────────────────────────────────────────────
14. Contact
Questions concerning this Privacy Policy or the processing of personal data may be sent to:
Krystian Kosiński
PPC747
ul. prof. Stefana Hausbrandta 32/30
80-126 Gdańsk, Poland
E-mail: contact@kosinskigrowth.com
Phone: +48 791 656 570