Skip to content

Privacy Policy

What we collect, why we collect it, and what you can ask us to do about it.

Last updated 8 September 2026

Mykyta Kashcheiev, trading as Awake Agency

1. Who we are

The controller of your personal data is Mykyta Kashcheiev, trading as Awake Agency, an individual entrepreneur registered in the Polish CEIDG register.

NIP (Tax ID): 1133116067

REGON: 526996481

Warsaw, Poland

contact@awakeagency.dev

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Write to the address above for anything concerning your data.

2. What this policy covers

This policy explains how we handle personal data when you:

  • visit awakeagency.dev;
  • contact us, book a call, or discuss a possible project;
  • become a client, or work with us as a contractor or freelancer;
  • receive e-mail from us.

It does not cover personal data we process on behalf of our clients while building or maintaining their websites. In those cases our client is the controller and we act as their processor under a separate agreement. Their privacy policy applies, not this one. See section 9.

3. What we collect, why, and on what legal basis

Who you areWhat we collectWhyLegal basis
Website visitorTechnical data your browser sends: IP address, user agent, pages requested, timestamps, referrer. Held in server logs by our hosting provider.Serving the site, security, diagnosing faultsArt. 6(1)(f). Legitimate interest in a working, secure website
Someone who contacts usName, e-mail address, company, and whatever you put in your message or attach to itAnswering you, preparing a quoteArt. 6(1)(b). Steps at your request before a contract; Art. 6(1)(f) for general enquiries
Someone who books a callName, e-mail, chosen time, time zone, anything in the booking notesScheduling and holding the callArt. 6(1)(b)
Prospect we approachBusiness contact details from public professional sources (company site, LinkedIn, Upwork, Contra) and our notes on the conversationBusiness-to-business outreach about our servicesArt. 6(1)(f). Legitimate interest in direct B2B marketing (Recital 47). Object at any time and we stop.
ClientContact and billing details of your representatives, project correspondence, contract and signature data, payment recordsPerforming the contract, invoicing, records, defending claimsArt. 6(1)(b); Art. 6(1)(c) for tax records; Art. 6(1)(f) for claims
Contractor working with usName, business registration and tax details, contact details, payment details, agreements, task records, hours worked, invoicesEngaging you, assigning and accepting work, paying you, tax recordsArt. 6(1)(b); Art. 6(1)(c)

We do not knowingly collect data from children, and we do not process special categories of personal data (Article 9 GDPR). Please do not send us any. We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.

4. Cookies and analytics

We run no analytics on this site. No Google Analytics, no advertising pixels, no visitor profiling. The only thing that stores anything on your device is the booking calendar on our contacts page, which is hosted by Cal.com, and we do not load it until you say yes. Details are in our Cookie Policy.

5. Who we share your data with

We do not sell personal data and we do not share it for other organisations marketing purposes.

We use service providers who process personal data on our instructions (processors): e-mail and file storage, calendar booking, e-signature, project management, design tools, website hosting and CMS, e-mail delivery, and AI-assisted tools used on business plans that do not use our inputs to train models. Each is bound by a data processing agreement and may use your data only to provide the service to us. The current list of our processors and sub-processors is available on request.

We may also disclose data to our accountant, legal advisers, banks and payment providers, and to public authorities where the law requires it. Contractors who work on a project are bound by written confidentiality and data protection obligations at least as strict as those we owe you.

6. Transfers outside the European Economic Area

Some of our providers are established in the United States or process data there. Where personal data is transferred outside the EEA, we rely on the European Commission adequacy decision for the EU–U.S. Data Privacy Framework where the provider is certified under it; or on Standard Contractual Clauses with additional safeguards where an assessment shows they are needed; or on another mechanism permitted under Chapter V GDPR. Ask us for a copy of the relevant safeguards at any time.

7. How long we keep it

DataRetention
Enquiries that do not lead to a project12 months from the last message, then deleted
Prospect and outreach recordsUntil you object, or 24 months without contact
Client project files and correspondenceThe engagement plus 6 years, to evidence what was delivered and to bring or defend claims
Contracts, IP assignments and signature recordsThe engagement plus 6 years; copyright transfer documents for as long as the rights are exercised
Invoices, accounting and tax records5 years from the end of the calendar year in which the tax became payable, as Polish tax law requires
Booking records12 months
Server logsAs set by our hosting provider, ordinarily no more than 12 months

Where a claim is pending or foreseeable, we keep the relevant data until it is finally resolved.

8. Your rights

Under the GDPR you have the right to:

  • access your data and get a copy of it;
  • have inaccurate data corrected, and incomplete data completed;
  • have your data erased, where one of the grounds in Article 17 applies;
  • restrict how we process it, in the situations listed in Article 18;
  • receive data you gave us in a portable format and have it transmitted to another controller (portability), where processing is based on consent or contract and carried out by automated means;
  • object at any time to processing based on our legitimate interest, and, for direct marketing, to object with no need to give reasons, after which we stop;
  • withdraw consent at any time where processing is based on consent, without affecting the lawfulness of what came before.

To exercise any of these, write to contact@awakeagency.dev. We respond within one month, and will tell you if we need to extend that under Article 12(3).

You may also complain to the Polish supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (UODO)

ul. Stawki 2, 00-193 Warszawa, Poland

uodo.gov.pl

If you are in another EU country, you may complain to your local supervisory authority instead.

9. When we act for our clients

When we design, build or maintain a website or product for a client, we may come into contact with personal data belonging to that client users, while testing a contact form, reviewing a CRM, or migrating content. In those situations our client is the controller and decides why and how that data is processed; we act as a processor and use the data only on the client documented instructions, under a written data processing agreement. If you are a user of a client website and want to exercise your rights, please contact that client. We will pass on any request we receive and support them in answering it.

10. Is providing data required?

Providing your data is voluntary, but some of it is necessary: without contact details we cannot answer you, quote, or enter into a contract; without billing and tax details we cannot lawfully invoice or pay.

11. Changes to this policy

We update this policy when what we do changes, or when the law does. The date at the top always shows the current version. If a change materially affects you, we will say so when we tell you about it.