1. Controller and scope of the policy
The controller of personal data is Artur Januszczyk, conducting business under the name ARTUR JANUSZCZYK USŁUGI INFORMATYCZNE IN4SYSTEM, ul. Grodzieńska 9/65, 19-300 Ełk, Poland, Tax ID (NIP): 8481600751, REGON: 281090809, operating under the in4system brand (the “Controller”, “in4system”, “we”). You can contact us at info@in4system.com.
This policy covers the in4system.com website, contact and quotation forms, newsletter, business communication, contracts, project delivery, support, invoicing, user accounts and the admin/client portal. It explains processing performed by in4system as a controller. If we process a client’s data solely on that client’s instructions, the client remains the controller and the processing is governed by the relevant agreement under Article 28 GDPR.
All data protection matters can be submitted directly through the privacy contact above.
2. Principles and categories of data
We process data lawfully, fairly and transparently, only for specified purposes and to the extent necessary. We aim to keep data accurate, limit retention and protect confidentiality, integrity and availability.
Depending on your relationship with us, data may include identity and contact details, company and billing details, inquiry and project content, contractual correspondence, service and support history, invoices and payments, user account and role information, login/session data, IP address and technical security logs, newsletter address, language, consent status and dates.
- Please do not send special-category data, passwords, private keys, production credentials, customer databases or confidential documents through the public contact form.
- If such data is required for a project, we agree on an appropriate secure transfer method and access rules first.
3. Purposes, legal bases and retention
The exact basis and retention period depend on why the data was provided. The table below describes the main situations. A longer period applies only where required by law, necessary to establish, exercise or defend claims, or needed to investigate a security incident.
| Purpose | Legal basis | Typical retention |
|---|---|---|
| Inquiries and quotations | Article 6(1)(b) GDPR when you request steps before a contract; Article 6(1)(f) for ordinary business correspondence and communication with a company contact. | Normally up to 12 months after the last meaningful contact if cooperation does not begin; longer when needed for a contract or claims. |
| Contracts, projects, support and the client portal | Article 6(1)(b) GDPR for performance of a contract with an individual; Article 6(1)(f) for B2B contact persons, service operation, documentation and support. | For the relationship and then until relevant claims expire; business-related claims are generally subject to a three-year limitation period unless a specific rule applies. |
| Accounts, authentication and security | Article 6(1)(b) and Article 6(1)(f) GDPR: access requested by the user, prevention of abuse, system security and accountability. | Account data while access is active; session cookies normally up to 8 hours; security data for as long as reasonably necessary to investigate incidents and protect the service. |
| Invoices, tax and accounting records | Article 6(1)(c) GDPR in connection with tax, accounting and record-keeping duties. | As required by applicable law, generally five years counted under the relevant tax or accounting rules; longer if proceedings suspend or extend that period. |
| Newsletter and email marketing | Article 6(1)(a) GDPR (consent) and prior consent required by Article 398 of the Polish Electronic Communications Law. | Until consent is withdrawn. A limited suppression record and evidence of consent may be retained to respect the withdrawal and demonstrate compliance or defend claims. |
| Claims and compliance | Article 6(1)(c) GDPR where a legal duty applies and Article 6(1)(f) GDPR to establish, exercise or defend claims. | Until the duty ends or the relevant claim and enforcement periods expire. |
4. Contact forms and newsletter
Providing data in the contact form is voluntary, but name, a valid email address and inquiry content are necessary for us to respond. Sending an inquiry is not treated as consent to unrelated marketing and we do not require you to “accept” this policy.
Newsletter subscription is separate and voluntary. Selecting “Subscribe” after entering an email address is an affirmative request to receive the in4system newsletter, including commercial information and direct marketing by email. Consent may be withdrawn at any time through the unique unsubscribe link in each campaign or by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.
5. Cookies and similar technologies
The website currently uses only first-party technologies necessary to provide requested functions, maintain security, remember interface settings and manage cookie information. No analytics, advertising, profiling or social-media tracking cookies are loaded by the website at the date of this update.
Necessary storage is used under Article 399(3) of the Polish Electronic Communications Law because it is required to provide the service requested by the user or transmit a communication. If optional technologies are introduced, they will remain disabled until valid prior consent is obtained under Article 399(1).
You can review the current cookie list at any time using “Cookie settings” in the footer. Browser settings can also delete or block storage, although some portal and preference functions may then stop working correctly.
| Name | Purpose | Typical lifetime |
|---|---|---|
| cc_cookie | Stores the cookie notice state and user choices. | 182 days |
| in4_access_token | HTTP-only token securing an authenticated admin or client session. | Normally up to 8 hours or until logout |
| in4_user | Basic display data needed by the authenticated portal interface; it is not used to authorize access. | Normally up to 8 hours or until logout |
| in4system-ui-settings-v2 | Remembers layout, theme and interface preferences. | Browser session or until deleted |
| colorPref | Remembers the light or dark color preference. | Browser session or until deleted |
6. Recipients and service providers
We do not sell personal data. Access is limited to authorized persons and providers that need data for a defined task. Depending on the service, recipients may include hosting and infrastructure providers, email and SMTP providers, IT maintenance and security providers, accountants, legal or tax advisers, payment or integration providers selected for a project, and public authorities where disclosure is legally required.
Providers processing data on our behalf are bound by contracts, confidentiality and documented instructions. In client projects, roles are determined by the actual data flow: in4system may act as an independent controller, joint controller or processor, and the relevant contract takes precedence for that processing.
7. Transfers outside the EEA
We select European processing locations where reasonably available. Some technology providers or project integrations may nevertheless involve access from or transfer to a country outside the European Economic Area.
Where this occurs, we use a lawful GDPR mechanism appropriate to the destination and provider, such as an adequacy decision, Standard Contractual Clauses under Article 46 GDPR and supplementary safeguards. Information about the safeguards relevant to a specific processing activity can be requested from us.
8. Sources of data and whether provision is required
We usually receive data directly from you. We may also receive business contact data from your employer, client, authorized representative, project partner or a public business register when this is necessary to verify a company or communicate about a project.
Providing data for an inquiry or newsletter is voluntary. Contract, account and invoicing data may be necessary to enter into or perform an agreement, grant access, comply with law or issue a correct invoice. If required data is not provided, we may be unable to respond, contract, provide portal access or complete the requested service.
9. Automated decisions and external links
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects, and we do not profile website visitors for advertising. The project estimator only calculates a non-binding preliminary range from the options selected by the user; a person reviews every actual inquiry.
Links to social networks, WhatsApp and other external websites are ordinary links. The external provider begins processing under its own policy when you choose to open that service; the website does not load its tracking tools merely by displaying the link.
10. Security, changes and legal framework
We apply technical and organizational safeguards appropriate to the risk, including access controls, role separation, HTTP-only authentication cookies, encrypted transport, server-side validation and restricted administrative access. No internet service can guarantee absolute security, so users must protect credentials and avoid sharing them with unauthorized persons.
We review this policy when the website, providers, processing or law changes. A material change will be published here with an updated date and, where required, communicated directly. A new purpose based on consent will not be introduced without obtaining the required consent.
Privacy contact
For questions about this policy or your personal data, contact the controller at info@in4system.com
