This is the privacy policy for infigo.dev and infigo.pl. It explains what happens to your personal data when you contact us or read this site. It is written to be read, not to be scrolled past.
Who is responsible for your data
The controller of your personal data is Robert Pakszys, running the sole trader business INFIGO Robert Pakszys, registered in Poland in the CEIDG business register and based in Gdańsk. NIP 839 303 52 57.
For anything to do with your data, including any of the requests listed further down, write to post@infigo.pl. That address reaches the person who runs the company.
We have not appointed a data protection officer, because the law does not require one here. The address above is the right one for every data question.
What we collect, and when
When you send the contact form. Your name, your email address and whatever you write about the project are required, because without them there is no enquiry to answer. Company name, phone number, the type of work, the timeline and the budget band are optional and only help us give you a faster and more honest answer. The message is stored in this site’s database and also sent to our inbox. The site also keeps a log of every email it sends: the recipient address, the subject, which for the contact form contains your name, and whether our mail server accepted the message. The content is not logged.
When you email or call us directly. Whatever the message contains, along with your address, phone number and anything in your signature.
When you simply read the site. The server keeps the usual technical log: IP address, browser and operating system, which pages were requested and when. The security software protecting the site records the same kind of data in order to recognise and block attacks.
Why we are allowed to process it
- To answer you and to work out whether we can do the job. Article 6(1)(b) of the GDPR, covering steps taken at your request before entering into a contract. Where no contract follows, Article 6(1)(f), our legitimate interest in replying to people who contact us.
- To keep the site running and defend it against attacks. Article 6(1)(f), our legitimate interest in the security and stability of our own systems.
- To keep accounting records once you become a client. Article 6(1)(c), a legal obligation under Polish tax and accounting law.
We do not run advertising, we do not build profiles of you, and no decision affecting you is made automatically.
How long we keep it
- Contact form enquiries: 24 months from our last contact, then deleted automatically. That is long enough for a project that comes back a year later, and short enough that we are not sitting on an archive we have no use for. If we do start working together, the records move under the client relationship below.
- Correspondence with clients: for as long as the working relationship lasts, and after that for as long as claims connected with it can still be brought, which under Polish law is three years for business claims.
- Accounting documents: five years from the end of the tax year they belong to, because tax law requires it and we do not get a choice.
- Server and security logs: no longer than 90 days on our server. The two security services named below keep their own records of blocked attacks under their own privacy policies.
- The email log: 60 days, then deleted automatically.
- Backups: a copy of the database is taken every night and kept for 30 days, on our server in Germany and on our own equipment in Poland. Anything deleted from the live site can therefore remain in a backup for up to 30 days longer.
Who else sees it
The list is short on purpose, and every entry on it exists because something has to run somewhere.
- Hetzner Online GmbH (Germany), our hosting provider, which operates the server this site and its database sit on.
- MyDevil.net (Poland), our email provider, which delivers the contact form message to our inbox and carries the correspondence that follows.
- Wordfence (Defiant Inc.) and Sucuri (part of GoDaddy), the security services protecting the site, which process IP addresses and request data in order to detect and block attacks.
Each of them acts on our instructions under a data processing agreement. We do not sell personal data, we do not pass it to advertisers or data brokers, and we do not give it to anyone else unless the law obliges us to.
Transfers outside the European Economic Area
The server this site runs on is in Germany and our email is handled in Poland, so what you send us stays inside the EEA. The two security services are run by US companies, and the data they need in order to recognise an attack, which is the IP address and the request itself, can reach their servers outside the EEA. That happens on the safeguards the GDPR provides for, which in practice means the European Commission’s standard contractual clauses. Write to us at the address above if you want to know exactly where your data sits.
Cookies, and the banner that is not there
This site does not track you.
There is no Google Analytics on it, no tag manager, no advertising pixel and no third-party tracking script of any kind. Because none of that is here, no analytics or marketing cookies are set, and there is nothing to ask your permission for. That is why you are not being made to dismiss a cookie banner in order to read the page.
WordPress sets technical cookies only for people who log in to administer the site. If you are here to read, nothing is stored on your device beyond what your own browser does anyway.
If this ever changes we will change this section with it, and anything that is not strictly necessary will be asked for first, before it runs.
Your rights
You can ask us to:
- tell you what we hold about you and give you a copy of it,
- correct it if it is wrong or incomplete,
- delete it, where we have no remaining obligation or legitimate ground to keep it,
- restrict what we do with it while a dispute about it is being resolved,
- hand it over in a portable format, for the data you gave us yourself,
- stop processing based on legitimate interest, by objecting to it.
Write to post@infigo.pl and we will deal with it within one month, which is the deadline the GDPR sets.
If you think we have handled your data badly, you can complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa. You are entitled to do that whether or not you raise it with us first, although raising it with us first is usually faster.
Do you have to give us your data
No. Sending the contact form is voluntary. But the name, the email address and some description of what you are building are needed to answer at all, so leaving them out means there is nothing we can reply to. Every other field is optional.
Changes to this policy
If we change how any of this works, we update this page and change the date below. Material changes get more than a quiet edit.
Last updated: 9 September 2026.