Free Phishing Test

Effective date: 17 July 2026

Introduction and data controller

Key information

  • The data controller is SECAWA sp. z o.o., with its registered office in Poznań.
  • We respond to inquiries without requiring marketing consent. Marketing consent is voluntary and may be withdrawn at any time.
  • We activate analytics and advertising cookies and similar technologies only after obtaining the appropriate consent, except for technologies that are strictly necessary.
  • We do not sell personal data. We do, however, use IT, CRM, communications, analytics and advertising service providers that may process data on our behalf or act as separate controllers.
  • You may, among other things, access your data, correct it, have it deleted, restrict its processing, obtain data portability, withdraw consent or object to processing.

Data controller and contact

1. The controller of personal data is SECAWA sp. z o.o., with its registered office at ul. Ku Cytadeli 2/36, 61-722 Poznań, Poland, entered in the Register of Entrepreneurs of the National Court Register (KRS) under number 0000776434, NIP 7831799067, REGON 382815625 (“SECAWA”, “we”).

2. For privacy-related matters, you can contact us at [email protected] or by post at our registered office: ul. Ku Cytadeli 2/36, 61-722 Poznań, Poland.

3. This Policy applies to data processed in connection with the use of secawa.com, forms, correspondence, webinars and educational materials, business relationships, marketing communications and SECAWA profiles on social media. It does not cover the processing of data of participants in services delivered for clients where SECAWA acts solely as a processor on the client’s instructions.

Data processing

What data we process and where we obtain it

1. We may process the following categories of data, to the extent appropriate for the particular relationship:

  • identification and professional data, such as first name, last name, job title, company, industry and organization size;
  • contact details, such as business email address and telephone number;
  • the content of inquiries and correspondence, meeting notes, preferences and the history of the business relationship;
  • data related to webinars and materials, such as registration, attendance, questions, topic preferences and actions necessary to deliver the material;
  • technical and usage data, such as IP address, online identifiers, device and browser information, approximate location, referral source, pages visited, clicks, scrolling, visit duration and events;
  • data concerning consents given or withdrawn, objections and privacy preferences;
  • publicly available professional and company data, as well as data obtained from event organizers, partners or licensed business-information providers.

2. We receive data directly from you, from your organization or its representatives, through interactions with the Website and our messages, from event organizers or partners—where there is an appropriate legal basis—and from public professional sources and commercial B2B databases. If we did not obtain the data directly from you, we provide the information required under Article 14 GDPR no later than at first contact, within one month of obtaining the data or within another period specified by the GDPR.

3. Please do not provide special categories of personal data, data concerning criminal convictions or offences, or confidential information in forms or correspondence unless this is necessary and has been agreed with SECAWA in advance.

ProcessPurposeLegal basisRetention
Inquiries, contact and demosResponding, understanding needs, arranging a call, preparing an offer and taking steps before entering into a contract.Article 6(1)(b) GDPR when you act on your own behalf; otherwise Article 6(1)(f) GDPR—handling inquiries and developing B2B relationships.For the duration of the relationship; if no further relationship arises, for as long as required by a contract, applicable law or potential claims.
Contracts and customer relationshipsEntering into and performing a contract, service delivery, settlements and contact with people representing the customer.Article 6(1)(b), (c) and (f) GDPR.For the duration of the relationship and then for the periods required for tax and accounting purposes and until claims become time-barred.
Webinars and materialsRegistration, delivering materials or links, organizing the event, operational messages and handling questions.Article 6(1)(b) GDPR or Article 6(1)(f) GDPR.Until consent given in connection with participation in the event is withdrawn, unless further retention follows from the relationship, consent or potential claims.
Email marketingNewsletters, industry insights, invitations and information about services and offers.Article 6(1)(a) GDPR and the consent required under Article 398 of the Polish Electronic Communications Law (PKE).Until consent is withdrawn, an effective objection is made or the programme ends; we periodically review inactive consents.
Telephone/SMS marketingTelephone and SMS contact regarding services, events, content and offers.Article 6(1)(a) GDPR and the consent required under Article 398 of the PKE.Until consent is withdrawn, an effective objection is made or the programme ends.
CRM and B2B relationshipsManaging leads and relationships, contact history, needs qualification, and planning and measuring sales activities.Article 6(1)(f) GDPR—organizing sales and developing the business; electronic marketing communications only after the requirements of Article 398 of the PKE have been met.Usually for up to three years from the last material interaction, unless a contract, consent, objection or a justified need connected with claims exists.
Analytics and UXMeasuring traffic, sources, events and conversions; diagnosing errors; and improving the Website.Article 6(1)(a) GDPR and Article 399 of the PKE for non-essential technologies; Article 6(1)(f) GDPR for strictly necessary logs.In accordance with the tools’ settings and the cookie table; we store your consent choice for the period specified in the settings panel.
Advertising and remarketingMeasuring effectiveness, tailoring ads, creating audiences, limiting frequency and attributing conversions.Article 6(1)(a) GDPR and Article 399 of the PKE; sharing data with a communications channel may also require consent under Article 398 of the PKE.Until consent is withdrawn or in accordance with the lifetime of identifiers and platform settings.
SecurityProtecting the Website, detecting abuse, diagnostics, business continuity and incident response.Article 6(1)(f) GDPR—information, system and user security; sometimes Article 6(1)(c) GDPR.Operational logs are usually retained for up to 12 months; incident data is retained for as long as required for analysis, by law or for potential claims.
Claims and complianceDemonstrating consent, exercising rights, defending or pursuing claims, audits and legal obligations.Article 6(1)(c) and (f) GDPR.Until the applicable limitation periods expire or proceedings end; a minimum record of an objection may be retained longer in order to respect it.

The periods stated are maximum or typical periods. We may delete or anonymize data earlier. Backups are overwritten in accordance with the recovery cycle, and access to them is restricted.

Marketing, communications and cookies

Contact and marketing

1. Submitting an inquiry does not constitute consent to a newsletter or to marketing unrelated to that inquiry. We may respond through the channel you indicate and provide the information necessary to handle the specific request. If you ask for a quote, demo or contact regarding a specific service, a response for that purpose is not treated as a separate marketing subscription.

2. For marketing communications concerning our services, educational content, webinars, events and offers, we obtain prior consent to the extent required under Article 398 of the PKE. Consent may cover contact by email and—if you provide your telephone number—by telephone or SMS. Consent is voluntary, is not a condition for receiving a response to an inquiry or basic materials, may be withdrawn at any time and does not affect the lawfulness of processing carried out before withdrawal. Every marketing email contains a simple unsubscribe mechanism.

3. You can withdraw consent or object by using the unsubscribe link or by contacting [email protected]. We may retain limited information on a suppression list so that we do not send further communications.

Cookies and similar technologies

1. The Website uses cookies, browser storage, pixels, tags and similar technologies. Some are necessary for the Website to operate, for security, to handle forms and to remember privacy choices. We activate the remaining analytics, functional or marketing technologies only after consent has been given.

2. On your first visit, we display a consent-management panel. You can accept or reject non-essential categories, choose detailed settings and later change your decision using the “Privacy/cookie settings” link available on the Website. Rejecting non-essential technologies should be as easy as accepting them and does not block the Website’s basic content.

ToolPurposeCategoryProvider
CookieYesRecording and documenting user choices and blocking tools until consent is given.NecessaryCookieYes Limited (United Kingdom)
Google Tag ManagerTechnical container for managing tags. It does not itself constitute a basis for enabling tools without appropriate consent.Depends on the tag being activatedGoogle Ireland Limited / Google LLC
Google Analytics 4Analytics, traffic sources, events and conversions.AnalyticsGoogle Ireland Limited / Google LLC
Microsoft ClarityUX analysis, click maps, session recordings and troubleshooting. Form fields should be masked.AnalyticsMicrosoft Ireland Operations Limited / Microsoft Corporation
Pipedrive Web VisitorsAnalysis of organizational visits, sources and viewed content, and assessment of interest.Analytics/marketingPipedrive and the provider of the Web Visitors feature
Google Ads, Meta, LinkedInAd and conversion measurement, advertising audiences, personalization and remarketing.MarketingGoogle, Meta Platforms Ireland, LinkedIn Ireland
YouTubePlayback of embedded content; enhanced privacy mode or activation after consent is recommended.Functional/marketingGoogle Ireland Limited / Google LLC

CRM, webinars, newsletters and automations

1. Data from forms may be transferred automatically to the Pipedrive CRM system. The system is used to record the source of contact, correspondence history, relationship status, preferences and consents, and to automate agreed communications. Automation does not change the legal basis or the scope of consent.

2. Newsletters and email campaigns may be sent through Pipedrive. We may analyze deliveries, clicks and unsubscribes to the extent permitted by law and the consents given. We do not individually track opens where we do not have an appropriate legal basis and have not provided clear information about it.

3. Webinars may be hosted in Microsoft Teams. We send organizational messages, links and reminders necessary for participation. Marketing after an event requires a separate legal basis. If an event is recorded, we inform you before it begins; a participant’s questions, chat messages, image or voice are published only on an appropriate legal basis and after applying suitable settings or redaction.

4. If we launch a chatbot, live chat, Pipedrive forms or new integrations, before activating them we will determine the parties’ roles, legal bases, data scope, retention, transfers and consent configuration, and update this Policy and the cookie panel where necessary.

Data sharing and transfers

Data recipients

Data may be received only by entities that need it for a specific purpose, in particular:

  • hosting, email, security, website maintenance, backup and IT-support providers;
  • CRM, forms, automation, newsletter, communications and webinar-service providers, including Pipedrive and Microsoft;
  • analytics, consent-management and advertising providers, including CookieYes, Google, Microsoft, Meta and LinkedIn, depending on consent and configuration;
  • law firms, auditors, accountants, insurers and other advisers bound by confidentiality;
  • event organizers or co-organizers where their involvement and the rules for sharing data have been clearly indicated;
  • public authorities and other entities where required by law or necessary to protect rights.

We enter into agreements compliant with Article 28 GDPR with providers acting as processors. We do not permit them to use data for their own purposes, except where they act as separate controllers on the basis of law and their own terms.

Transfers of data outside the EEA

1. Some providers or their subcontractors may process data outside the European Economic Area, in particular in the United States or the United Kingdom. In such cases, we use an appropriate transfer mechanism, such as an adequacy decision of the European Commission, the EU–U.S. Data Privacy Framework for a certified recipient, or Standard Contractual Clauses together with a transfer impact assessment and supplementary safeguards where necessary.

2. Information about the safeguard used, or a copy of it, can be obtained by contacting us. Some details may be restricted to the extent necessary to protect confidential information, security or the rights of others.

Profiling and advertising

1. We may assign contacts to segments based on professional information, interest in content, the source of contact, relationship history or activity on the Website. Advertising platforms may match ads, create lookalike audiences and measure conversions in accordance with the consents given and their own rules.

2. These activities may affect which content or advertisements you see and when our sales team contacts you. We do not make decisions concerning Website visitors based solely on automated processing that produces legal effects or similarly significant effects on them.

Your rights

Depending on the legal basis and the circumstances, you have the right to:

  • access your data and receive a copy of it;
  • rectify inaccurate data and complete incomplete data;
  • have data deleted or processing restricted;
  • data portability for data processed automatically on the basis of consent or a contract;
  • withdraw consent at any time;
  • object to processing based on our legitimate interests on grounds relating to your particular situation;
  • object at any time to direct marketing, including related profiling—after an objection, we no longer process data for those purposes;
  • lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, uodo.gov.pl.

You can submit a request to [email protected] or in writing to our registered office. We may ask for information necessary to verify your identity, but we do not request excessive data. As a rule, we respond within one month.

Voluntary provision of data

Providing data is voluntary; however, data marked as required are needed to handle the relevant form or service. Failure to provide them may make it impossible to respond, register you or deliver materials. Marketing consent is not required to submit a general inquiry.

Security

1. We apply technical and organizational measures appropriate to the risk, scope and context of processing. Depending on the system, these include encryption in transit, access control and the principle of least privilege, multi-factor authentication, vulnerability and patch management, backups, event logging and monitoring, incident-response procedures, training, confidentiality and supplier assessments.

2. We design processes in accordance with the principles of privacy by design and privacy by default, limit the scope and retention period of data, and periodically review permissions and configurations. No method provides absolute security, however, so we continuously improve our safeguards in proportion to the risk.

Social media and external sites

1. We operate profiles on LinkedIn, Facebook, X and YouTube across the channels currently active. The operator of each platform processes data in accordance with its own policy and may be a separate controller or—in certain contexts involving statistics and advertising—a joint controller. Interactions, comments and messages may be visible in accordance with the user’s account settings.

2. Links from secawa.com may lead to external services. Their privacy practices are outside our control; before providing data, please read the relevant operator’s information.

Minors

The Website and our offering are directed at professionals and organizations, not children. We do not knowingly collect children’s data for marketing purposes. If you believe that we have received such data without an appropriate legal basis, please contact us.

Policy changes and contact

Policy changes

We may update this Policy when the law, our processes or our tools change. The update date will be indicated at the beginning of the document. If a change materially affects the way data is processed, we will provide appropriate information on the Website or through another appropriate channel. An update to the Policy does not replace consent where the law requires consent to be obtained again.

Contact

SECAWA sp. z o.o. has appointed a Data Protection Officer. If you have any questions about our Privacy Policy or your personal data, please contact us:

  1. by sending an email to [email protected]

    or
  2. by post to:

    Personal Data Protection
    SECAWA sp. z o.o.
    ul. Ku Cytadeli 2/36
    61-722 Poznań
    Poland.