1. Who we are
The controller of your personal data is Mykyta Kashcheiev, trading as Awake Agency, an individual entrepreneur registered in the Polish CEIDG register.
NIP (Tax ID): 1133116067
REGON: 526996481
Warsaw, Poland
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Write to the address above for anything concerning your data.
2. What this policy covers
This policy explains how we handle personal data when you:
- visit awakeagency.dev;
- contact us, book a call, or discuss a possible project;
- become a client, or work with us as a contractor or freelancer;
- receive e-mail from us.
It does not cover personal data we process on behalf of our clients while building or maintaining their websites. In those cases our client is the controller and we act as their processor under a separate agreement. Their privacy policy applies, not this one. See section 9.
3. What we collect, why, and on what legal basis
| Who you are | What we collect | Why | Legal basis |
|---|---|---|---|
| Website visitor | Technical data your browser sends: IP address, user agent, pages requested, timestamps, referrer. Held in server logs by our hosting provider. | Serving the site, security, diagnosing faults | Art. 6(1)(f). Legitimate interest in a working, secure website |
| Someone who contacts us | Name, e-mail address, company, and whatever you put in your message or attach to it | Answering you, preparing a quote | Art. 6(1)(b). Steps at your request before a contract; Art. 6(1)(f) for general enquiries |
| Someone who books a call | Name, e-mail, chosen time, time zone, anything in the booking notes | Scheduling and holding the call | Art. 6(1)(b) |
| Prospect we approach | Business contact details from public professional sources (company site, LinkedIn, Upwork, Contra) and our notes on the conversation | Business-to-business outreach about our services | Art. 6(1)(f). Legitimate interest in direct B2B marketing (Recital 47). Object at any time and we stop. |
| Client | Contact and billing details of your representatives, project correspondence, contract and signature data, payment records | Performing the contract, invoicing, records, defending claims | Art. 6(1)(b); Art. 6(1)(c) for tax records; Art. 6(1)(f) for claims |
| Contractor working with us | Name, business registration and tax details, contact details, payment details, agreements, task records, hours worked, invoices | Engaging you, assigning and accepting work, paying you, tax records | Art. 6(1)(b); Art. 6(1)(c) |
We do not knowingly collect data from children, and we do not process special categories of personal data (Article 9 GDPR). Please do not send us any. We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.
4. Cookies and analytics
We run no analytics on this site. No Google Analytics, no advertising pixels, no visitor profiling. The only thing that stores anything on your device is the booking calendar on our contacts page, which is hosted by Cal.com, and we do not load it until you say yes. Details are in our Cookie Policy.
5. Who we share your data with
We do not sell personal data and we do not share it for other organisations marketing purposes.
We use service providers who process personal data on our instructions (processors): e-mail and file storage, calendar booking, e-signature, project management, design tools, website hosting and CMS, e-mail delivery, and AI-assisted tools used on business plans that do not use our inputs to train models. Each is bound by a data processing agreement and may use your data only to provide the service to us. The current list of our processors and sub-processors is available on request.
We may also disclose data to our accountant, legal advisers, banks and payment providers, and to public authorities where the law requires it. Contractors who work on a project are bound by written confidentiality and data protection obligations at least as strict as those we owe you.
6. Transfers outside the European Economic Area
Some of our providers are established in the United States or process data there. Where personal data is transferred outside the EEA, we rely on the European Commission adequacy decision for the EU–U.S. Data Privacy Framework where the provider is certified under it; or on Standard Contractual Clauses with additional safeguards where an assessment shows they are needed; or on another mechanism permitted under Chapter V GDPR. Ask us for a copy of the relevant safeguards at any time.
7. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that do not lead to a project | 12 months from the last message, then deleted |
| Prospect and outreach records | Until you object, or 24 months without contact |
| Client project files and correspondence | The engagement plus 6 years, to evidence what was delivered and to bring or defend claims |
| Contracts, IP assignments and signature records | The engagement plus 6 years; copyright transfer documents for as long as the rights are exercised |
| Invoices, accounting and tax records | 5 years from the end of the calendar year in which the tax became payable, as Polish tax law requires |
| Booking records | 12 months |
| Server logs | As set by our hosting provider, ordinarily no more than 12 months |
Where a claim is pending or foreseeable, we keep the relevant data until it is finally resolved.
8. Your rights
Under the GDPR you have the right to:
- access your data and get a copy of it;
- have inaccurate data corrected, and incomplete data completed;
- have your data erased, where one of the grounds in Article 17 applies;
- restrict how we process it, in the situations listed in Article 18;
- receive data you gave us in a portable format and have it transmitted to another controller (portability), where processing is based on consent or contract and carried out by automated means;
- object at any time to processing based on our legitimate interest, and, for direct marketing, to object with no need to give reasons, after which we stop;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of what came before.
To exercise any of these, write to contact@awakeagency.dev. We respond within one month, and will tell you if we need to extend that under Article 12(3).
You may also complain to the Polish supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
If you are in another EU country, you may complain to your local supervisory authority instead.
9. When we act for our clients
When we design, build or maintain a website or product for a client, we may come into contact with personal data belonging to that client users, while testing a contact form, reviewing a CRM, or migrating content. In those situations our client is the controller and decides why and how that data is processed; we act as a processor and use the data only on the client documented instructions, under a written data processing agreement. If you are a user of a client website and want to exercise your rights, please contact that client. We will pass on any request we receive and support them in answering it.
10. Is providing data required?
Providing your data is voluntary, but some of it is necessary: without contact details we cannot answer you, quote, or enter into a contract; without billing and tax details we cannot lawfully invoice or pay.
11. Changes to this policy
We update this policy when what we do changes, or when the law does. The date at the top always shows the current version. If a change materially affects you, we will say so when we tell you about it.