Privacy & cookie policy

Information about personal data processing and about cookies and similar technologies used on jemforge.pl — in line with the GDPR and applicable privacy rules.

Last updated: 27 August 2026

1. Data controller

The controller of personal data processed in connection with the use of jemforge.pl (the “Service”) is Jakub Solecki, a sole trader operating under the JEm Forge brand, address: ul. Dokerska 28/8, 54-142 Wrocław, Poland, NIP (tax ID): 8943209568 (the “Controller”).

Privacy contact: kontakt@jemforge.pl.

2. Scope of this policy

This policy applies to Service users, including visitors and people who send messages via the contact form.

It does not cover independent third-party services (e.g. SaaS products on other domains), which may have their own privacy policies.

3. What data we process

Depending on how you use the Service, we may process: data submitted in the contact form (name, email, optional company, message content), technical data generated automatically (IP address in server logs, browser type, date and time of the request), and preference data stored locally on your device (e.g. acknowledgement of the cookie notice).

Anonymous traffic analytics (Umami) does not identify you and is not used to build a marketing profile.

4. Cookies and similar technologies

Cookies are small pieces of data stored in your browser. Similar functions may be provided by localStorage or sessionStorage.

On this Service we primarily use technologies that are necessary for operation and for remembering basic preferences. We do not use third-party advertising or profiling cookies.

We currently use, among others:

  • Language prefix in the URL (/pl/…, /en/…) — selecting the Service language without storing it in the browser; legal basis: Art. 6(1)(f) GDPR (legitimate interest — operating the Service).
  • jem-forge-cookie-consent (localStorage) — storing acknowledgement of the cookie notice; legal basis: Art. 6(1)(c) and (f) GDPR (information duties and compliance records).
  • Technical/session cookies of the server or hosting infrastructure — only as needed for security and correct delivery of the site.

5. Analytics (Umami)

We measure traffic with self-hosted Umami. Umami runs without cookies and does not collect data that identifies a person (no marketing fingerprinting, no linking to ad accounts).

We process aggregated page-view information (e.g. URL path, referrer, country at a high level, device type). Legal basis: Art. 6(1)(f) GDPR — the Controller’s legitimate interest in understanding how the Service is used in order to improve it.

Because this analytics stack does not use cookies and does not track users across sites, prior cookie consent is not required; we still describe it in this policy.

6. Contact form

Form data is processed to reply to your inquiry and to handle correspondence related to potential or existing cooperation. Legal basis: Art. 6(1)(b) GDPR (pre-contractual / contractual steps) and Art. 6(1)(f) GDPR (business contact).

Providing data is voluntary but necessary to handle the message. Messages may be transmitted via an email service (e.g. Zoho Mail EU) solely for delivery of correspondence.

7. Legal bases — summary

We process data under: Art. 6(1)(b) GDPR (form / cooperation), Art. 6(1)(c) GDPR (legal obligations, including information duties), Art. 6(1)(f) GDPR (Service security, anonymous analytics, preference persistence).

8. Retention

Contact-form correspondence — for as long as needed to handle the matter, then until claims or accounting/legal obligations expire, where applicable.

Server logs — usually for a period justified by security (typically up to several months, unless a longer period is needed to investigate incidents).

Umami analytics data — in aggregated form for as long as needed for traffic analysis (usually up to 24 months).

Preferences in localStorage — until you remove them or clear browser data.

9. Recipients

Data may be entrusted to providers of hosting, email, and IT infrastructure — only as needed to run the Service and under data-processing agreements where required.

We do not sell personal data or share it with third parties for their marketing.

10. Transfers outside the EEA

We aim to process data within the European Economic Area. If a transfer outside the EEA becomes necessary, we will use an appropriate legal mechanism (e.g. an adequacy decision or standard contractual clauses) and update this policy.

11. Your rights

Under the GDPR you may have the right to:

  • access your data and receive a copy,
  • rectify (correct) your data,
  • erase your data (“right to be forgotten”) where the law allows,
  • restrict processing,
  • data portability — where the basis is a contract or consent and processing is automated,
  • object to processing based on legitimate interests,
  • lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.

12. Security

We apply technical and organisational measures appropriate to the risk, including HTTPS encryption and restricted access to administrative systems.

13. Changes to this policy

This policy may be updated when technology, services, or legal requirements change. The current version is always published on this page with the last-updated date.

14. Contact

For privacy and cookie matters, email: kontakt@jemforge.pl.

This document is informational and is not legal advice. If you need advice on your specific situation, consult a lawyer or UODO.