Contact

KAWECKI.LEGAL

Privacy
policy.

Law Office of
Jacek Kawecki
NIP 1182121720
Poland
01

General information

This Privacy Policy explains how personal data is processed when you use the KAWECKI.LEGAL website, submit an enquiry, or establish and continue a professional relationship with the Controller.

It provides the information required in particular by Articles 12–14 of Regulation (EU) 2016/679 (the “GDPR”). It applies to website users, people contacting the Controller, clients, prospective clients, counterparties, their representatives and other people whose data is processed in connection with legal services.

02

Controller and contact

The controller is Kancelaria Adwokacka Adwokat Jacek Kawecki, Polish tax identification number (NIP) 1182121720.

You can contact the Controller at jacek@kawecki.legal or through the contact details provided on the Website. The Controller has not appointed a data protection officer because the statutory conditions requiring such an appointment are not met.

03

Data categories and sources

The Controller may process identification and contact details, professional and business information, information about the represented organisation, billing details, correspondence and information provided in connection with a particular matter.

Data may come directly from the data subject, a client or counterparty, their employees and contractors, an opposing party or another participant in a matter, or from public sources such as official registers, websites and publicly available documents.

Where data is not collected directly from the data subject, the Controller provides information under Article 14 GDPR, subject to the applicable exceptions, including duties of professional secrecy.

04

Contact forms and correspondence

Depending on the type of enquiry, forms on the Website may collect your name, email address, message, company, business profile, subject matter, expected outcome, deadline, cooperation model, store stage and URL, planned market, trade mark, proposed owner and territory of protection.

Fields marked as optional are not required. Form submissions are transferred over a secure connection to Google Apps Script and then handled in the Controller’s Google Workspace email. An automatic acknowledgement is sent to the email address provided.

Enquiries are processed under Article 6(1)(f) GDPR — the Controller’s legitimate interest in communicating with people interested in legal services and handling enquiries. Article 6(1)(b) GDPR also applies where an enquiry seeks steps before entering into a contract. Handling an enquiry is not conditional on consent to data processing.

05

Newsletter

The newsletter form is used to receive information about new KAWECKI.LEGAL publications. Only an email address and a separate consent to receive the newsletter are required. Subscription is not a condition of obtaining legal services.

A double opt-in process is used. After the form is submitted, an email with a confirmation link is sent to the address provided. The address is not used for newsletter delivery until it has been confirmed.

The newsletter is operated through MailerLite, which processes the email address, subscription and confirmation status, delivery, opening and click data, and unsubscribe information. Every message contains an easy unsubscribe link. Consent may also be withdrawn by contacting the Controller.

06

Purposes, legal bases and retention

PurposeLegal basisRetention

Handling forms, emails and other enquiries

Article 6(1)(f) GDPR — the legitimate interest in corresponding, answering enquiries and protecting against claims

until the correspondence is complete and then until the relevant limitation period expires

Newsletter subscription and information about new publications

Article 6(1)(a) GDPR — consent; Articles 398 and 400 of the Polish Electronic Communications Law — prior consent to commercial communications

until consent is withdrawn or the newsletter ends; evidence of consent may be retained until the relevant limitation period expires

Analysis of Website use and published-content performance through Google Analytics 4

Article 6(1)(a) GDPR — user consent; consent also authorises optional technologies on the user's device

user-level and event data is retained in Google Analytics according to the service settings for no longer than 14 months; the user's choice is remembered in the browser for 12 months

Taking steps before a contract and providing legal services

Article 6(1)(b) GDPR — steps at the data subject’s request before entering into a contract and performance of a contract

for the duration of the engagement and then for the period required by law and applicable limitation periods

Tax, accounting and other statutory obligations

Article 6(1)(c) GDPR — compliance with a legal obligation

for the period required by the relevant law

Website security, error diagnosis and abuse prevention

Article 6(1)(f) GDPR — the legitimate interest in securing the website and IT systems

for the hosting retention period and no longer than necessary for this purpose

Establishing, exercising or defending legal claims

Article 6(1)(f) GDPR and, for special-category data, Article 9(2)(f) GDPR

until the relevant limitation period expires or proceedings are finally concluded

07

Sensitive data and criminal-offence data

Some legal matters may require special-category data under Article 9(1) GDPR or data relating to criminal convictions and offences under Article 10 GDPR. Such data is processed only where necessary and supported by an appropriate legal basis, including where required to establish, exercise or defend legal claims.

Please do not use a form to send sensitive data, privileged information or extensive documents unless this is necessary for an initial conflict and matter assessment.

08

Professional secrecy and conflicts

Information connected with legal assistance is protected under the rules governing the legal profession and professional ethics. Access is limited to people who need it.

Submitting an enquiry does not mean that a matter has been accepted or that a lawyer-client relationship has been created. A conflict check may be required before detailed or confidential information is provided.

09

Recipients

To the extent necessary for a particular purpose, data may be disclosed or entrusted to:

  • OpenAI, as provider of the ChatGPT Sites platform on which the current Website operates, and infrastructure providers used by that platform;
  • MailerLite, as provider of the newsletter subscription, confirmation and delivery system;
  • Google Ireland Limited, as provider of Google Workspace and Google Apps Script for forms and email, and of Google Analytics 4 — for Analytics only after consent is given;
  • IT, backup and cybersecurity providers;
  • accountants, tax advisers, insurers, translators, archiving and courier providers;
  • other lawyers, experts, notaries, courts, public authorities and other participants where required by a matter;
  • public bodies legally entitled to receive data.

Processors act under appropriate arrangements and only on the Controller’s documented instructions.

10

Transfers outside the EEA

IT services, including Google Workspace and Google Apps Script, may involve processing outside the European Economic Area. Any such transfer will rely on a mechanism under Chapter V GDPR, in particular an adequacy decision or standard contractual clauses, together with supplementary safeguards where required.

11

Your rights

Subject to the conditions in the GDPR, you may have the right to access and obtain a copy of your data, rectify it, erase it, restrict processing, receive portable data, object to processing based on Article 6(1)(f) GDPR, and withdraw consent where consent is the legal basis.

Right to object

Where processing is based on a legitimate interest, you may object on grounds relating to your particular situation. Processing will stop unless compelling legitimate grounds override your interests, rights and freedoms or the data is needed to establish, exercise or defend legal claims.

These rights may be limited by the GDPR, professional secrecy and other applicable laws.

12

Complaint to a supervisory authority

If you believe that your data is processed unlawfully, you may lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych). Current contact and complaint information is available at uodo.gov.pl.

13

Whether data is required

Providing data is voluntary. Information marked as required is necessary to handle an enquiry or take steps before entering into a contract. Without it, the Controller may be unable to respond or begin an engagement.

14

Server logs and cookies

The server may automatically record technical data such as IP address, request date and time, requested page, response code, browser, operating system, device and referrer. This data is used to secure, operate and diagnose the Website.

The hosting platform may use technologies strictly necessary for transmission, security, load balancing or session maintenance. To the extent necessary to provide a service requested by the user, these technologies do not require consent.

The Website uses browser local storage solely to remember for 12 months whether the user accepted or rejected analytics. This record is necessary to respect the user's choice and is not used to track activity.

Google Analytics 4 is completely off by default. The Google script is downloaded only after the user selects “Accept analytics”. Once consent is given, the service may process visited pages, time and manner of Website use, referral source, approximate location, device and browser type, and selected events such as contact clicks, language changes or a successful newsletter subscription. The Controller does not send form contents or other directly identifying information to Google.

Advertising features and Google Signals are disabled. The user may change their choice at any time through “Privacy settings”. Withdrawing consent prevents further Analytics operation and removes Google Analytics cookies accessible to the Website.

15

Security

The Controller applies technical and organisational measures appropriate to the risk, including access controls, device and account security, backups, and transmission and system protections. Measures are reviewed and adjusted to the data and current threats.

16

Automated decisions and marketing

Data is not used for solely automated decision-making that produces legal or similarly significant effects. The Website does not conduct profiling. The newsletter and related information about new publications are sent only to people who have given and confirmed their consent.

17

Changes to this Policy

This Policy may change if the Website, services, technology providers or applicable law change. The current version is published on this page. Last updated: 10 August 2026.

Back to the home page ↗