in4system software house
Privacy and cookies

Privacy and Cookie Policy

Clear information about how in4system processes personal data on the website, in business relationships, the newsletter and the client portal.

Last updated: September 2, 2026

Privacy policyGDPR and your rights

1. Controller and scope of the policy

The controller of personal data is Artur Januszczyk, conducting business under the name ARTUR JANUSZCZYK USŁUGI INFORMATYCZNE IN4SYSTEM, ul. Grodzieńska 9/65, 19-300 Ełk, Poland, Tax ID (NIP): 8481600751, REGON: 281090809, operating under the in4system brand (the “Controller”, “in4system”, “we”). You can contact us at info@in4system.com.

This policy covers the in4system.com website, contact and quotation forms, newsletter, business communication, contracts, project delivery, support, invoicing, user accounts and the admin/client portal. It explains processing performed by in4system as a controller. If we process a client’s data solely on that client’s instructions, the client remains the controller and the processing is governed by the relevant agreement under Article 28 GDPR.

All data protection matters can be submitted directly through the privacy contact above.


2. Principles and categories of data

We process data lawfully, fairly and transparently, only for specified purposes and to the extent necessary. We aim to keep data accurate, limit retention and protect confidentiality, integrity and availability.

Depending on your relationship with us, data may include identity and contact details, company and billing details, inquiry and project content, contractual correspondence, service and support history, invoices and payments, user account and role information, login/session data, IP address and technical security logs, newsletter address, language, consent status and dates.

  • Please do not send special-category data, passwords, private keys, production credentials, customer databases or confidential documents through the public contact form.
  • If such data is required for a project, we agree on an appropriate secure transfer method and access rules first.

3. Purposes, legal bases and retention

The exact basis and retention period depend on why the data was provided. The table below describes the main situations. A longer period applies only where required by law, necessary to establish, exercise or defend claims, or needed to investigate a security incident.

PurposeLegal basisTypical retention
Inquiries and quotationsArticle 6(1)(b) GDPR when you request steps before a contract; Article 6(1)(f) for ordinary business correspondence and communication with a company contact.Normally up to 12 months after the last meaningful contact if cooperation does not begin; longer when needed for a contract or claims.
Contracts, projects, support and the client portalArticle 6(1)(b) GDPR for performance of a contract with an individual; Article 6(1)(f) for B2B contact persons, service operation, documentation and support.For the relationship and then until relevant claims expire; business-related claims are generally subject to a three-year limitation period unless a specific rule applies.
Accounts, authentication and securityArticle 6(1)(b) and Article 6(1)(f) GDPR: access requested by the user, prevention of abuse, system security and accountability.Account data while access is active; session cookies normally up to 8 hours; security data for as long as reasonably necessary to investigate incidents and protect the service.
Invoices, tax and accounting recordsArticle 6(1)(c) GDPR in connection with tax, accounting and record-keeping duties.As required by applicable law, generally five years counted under the relevant tax or accounting rules; longer if proceedings suspend or extend that period.
Newsletter and email marketingArticle 6(1)(a) GDPR (consent) and prior consent required by Article 398 of the Polish Electronic Communications Law.Until consent is withdrawn. A limited suppression record and evidence of consent may be retained to respect the withdrawal and demonstrate compliance or defend claims.
Claims and complianceArticle 6(1)(c) GDPR where a legal duty applies and Article 6(1)(f) GDPR to establish, exercise or defend claims.Until the duty ends or the relevant claim and enforcement periods expire.

4. Contact forms and newsletter

Providing data in the contact form is voluntary, but name, a valid email address and inquiry content are necessary for us to respond. Sending an inquiry is not treated as consent to unrelated marketing and we do not require you to “accept” this policy.

Newsletter subscription is separate and voluntary. Selecting “Subscribe” after entering an email address is an affirmative request to receive the in4system newsletter, including commercial information and direct marketing by email. Consent may be withdrawn at any time through the unique unsubscribe link in each campaign or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.


5. Cookies and similar technologies

The website currently uses only first-party technologies necessary to provide requested functions, maintain security, remember interface settings and manage cookie information. No analytics, advertising, profiling or social-media tracking cookies are loaded by the website at the date of this update.

Necessary storage is used under Article 399(3) of the Polish Electronic Communications Law because it is required to provide the service requested by the user or transmit a communication. If optional technologies are introduced, they will remain disabled until valid prior consent is obtained under Article 399(1).

You can review the current cookie list at any time using “Cookie settings” in the footer. Browser settings can also delete or block storage, although some portal and preference functions may then stop working correctly.

NamePurposeTypical lifetime
cc_cookieStores the cookie notice state and user choices.182 days
in4_access_tokenHTTP-only token securing an authenticated admin or client session.Normally up to 8 hours or until logout
in4_userBasic display data needed by the authenticated portal interface; it is not used to authorize access.Normally up to 8 hours or until logout
in4system-ui-settings-v2Remembers layout, theme and interface preferences.Browser session or until deleted
colorPrefRemembers the light or dark color preference.Browser session or until deleted

6. Recipients and service providers

We do not sell personal data. Access is limited to authorized persons and providers that need data for a defined task. Depending on the service, recipients may include hosting and infrastructure providers, email and SMTP providers, IT maintenance and security providers, accountants, legal or tax advisers, payment or integration providers selected for a project, and public authorities where disclosure is legally required.

Providers processing data on our behalf are bound by contracts, confidentiality and documented instructions. In client projects, roles are determined by the actual data flow: in4system may act as an independent controller, joint controller or processor, and the relevant contract takes precedence for that processing.


7. Transfers outside the EEA

We select European processing locations where reasonably available. Some technology providers or project integrations may nevertheless involve access from or transfer to a country outside the European Economic Area.

Where this occurs, we use a lawful GDPR mechanism appropriate to the destination and provider, such as an adequacy decision, Standard Contractual Clauses under Article 46 GDPR and supplementary safeguards. Information about the safeguards relevant to a specific processing activity can be requested from us.


8. Sources of data and whether provision is required

We usually receive data directly from you. We may also receive business contact data from your employer, client, authorized representative, project partner or a public business register when this is necessary to verify a company or communicate about a project.

Providing data for an inquiry or newsletter is voluntary. Contract, account and invoicing data may be necessary to enter into or perform an agreement, grant access, comply with law or issue a correct invoice. If required data is not provided, we may be unable to respond, contract, provide portal access or complete the requested service.


9. Automated decisions and external links

We do not use personal data to make solely automated decisions that produce legal or similarly significant effects, and we do not profile website visitors for advertising. The project estimator only calculates a non-binding preliminary range from the options selected by the user; a person reviews every actual inquiry.

Links to social networks, WhatsApp and other external websites are ordinary links. The external provider begins processing under its own policy when you choose to open that service; the website does not load its tracking tools merely by displaying the link.


10. Security, changes and legal framework

We apply technical and organizational safeguards appropriate to the risk, including access controls, role separation, HTTP-only authentication cookies, encrypted transport, server-side validation and restricted administrative access. No internet service can guarantee absolute security, so users must protect credentials and avoid sharing them with unauthorized persons.

We review this policy when the website, providers, processing or law changes. A material change will be published here with an updated date and, where required, communicated directly. A new purpose based on consent will not be introduced without obtaining the required consent.

Privacy contact

For questions about this policy or your personal data, contact the controller at info@in4system.com