Skip to content

Legal

Privacy Policy

Last updated: 12 July 2026

1. Who we are (Controller)

The controller of your personal data is Decodely Daniel Glejzner (sole proprietorship registered in Poland), with its registered address at Sudecka 89 lok. 56, 58-500 Jelenia Góra, Poland, NIP 6112795976, registered in the Central Registration and Information on Business (CEIDG); REGON 380577564 ("we", "us").

For any privacy matter you can reach us at contact@aicontextengineering.eu.

2. Scope

This policy explains how we process personal data collected through https://aicontextengineering.eu/, our sign-up forms, our checkout process, and our workshop and consulting services. We sell to businesses (B2B), including sole proprietors and freelancers.

3. What data we collect

  • Newsletter / interest list: your email address and any name you provide when you subscribe to our newsletter or request price-change alerts.
  • Purchases: your name, email, company name, billing address, order and payment status, and, where applicable, VAT ID. Card data is entered directly with our payment provider and is never stored or seen by us.
  • Discovery calls: the booking details (name, email, chosen time slot, and any notes) you submit through our scheduling tool.
  • Correspondence: the content of emails, contact forms, or messages you send us.
  • Technical data: technical information automatically collected when you access the website, including your IP address, browser type, request timestamps, device data, and security logs needed to serve the site securely.

Source of data: We generally collect data directly from you. If your personal data (such as your name and business email address) is provided to us by your employer or another organization for the purpose of registering you for a workshop or arranging a business meeting, we process only the professional contact details necessary for that purpose. Where applicable, we will provide the information required under Article 14 GDPR.

Mandatory and voluntary provision of data: Providing your personal data is entirely voluntary. However, the provision of certain data is required by law (for example, billing data under Polish tax and accounting regulations). Failure to provide mandatory billing information prevents us from issuing invoices required under Polish law. In other cases, providing data is a contractual requirement or a condition necessary to enter into a contract or receive our services. If you choose not to provide the required data, we will be unable to conclude the contract, reply to your query, or provide the requested service.

4. Why we process it and on what legal basis

  • To take steps at your request prior to entering into a contract and to perform a contract - to process your order, deliver workshops and materials, and run discovery calls - Art. 6(1)(b) GDPR.
  • To meet legal obligations - to issue invoices, handle potential complaints, and keep tax/accounting records - Art. 6(1)(c) GDPR.
  • For our legitimate interests - to respond to your enquiries, to analyze email campaign engagement (open rates and link clicks, where such statistics are available) to improve our business communications, and to maintain the server logs for the explicit purpose of ensuring network and information security - Art. 6(1)(f) GDPR (in accordance with Recital 49 GDPR).
  • Based on your consent - to send the requested outline, newsletter, and price-change alerts by email - Art. 6(1)(a) GDPR. You can withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Automated decision-making: We do not use your personal data for automated decision-making, including profiling that produces legal effects or similarly significantly affects you as described under Art. 22 GDPR.

5. Marketing and electronic communication

In compliance with applicable Polish laws regarding electronic communication, we send commercial and marketing emails only where you have given us your prior, explicit consent. For existing business contacts, we may process data for direct marketing and basic segment profiling under our legitimate interest, but the actual delivery of messages via electronic channels remains subject to your electronic communication consent.

You have the right to object to direct marketing at any time. Every marketing email includes an unsubscribe link, and you can opt out at any time by using it or by emailing us.

6. Recipients of personal data

We share personal data only to the extent necessary for the purposes described in this Privacy Policy. Your data may be shared with the following categories of recipients:

Data Processors (acting strictly on our behalf under data-processing agreements):

  • Email delivery, automations, and lead forms: beehiiv (beehiiv, Inc., United States; personal data transfers to the US are covered by the EU Standard Contractual Clauses).
  • Scheduling infrastructure and email infrastructure: Google LLC (Google Calendar and Google Workspace).
  • Website infrastructure, CDN, and security services: Cloudflare, Inc. (content delivery network, website security, and DDoS protection).
  • Privacy-friendly, cookieless website analytics: Plausible Analytics (EU-hosted; processes limited technical data such as IP address and browser type transiently to produce aggregated, non-identifying statistics).
  • Live workshop delivery: the video-conferencing platform used to run the online sessions (name, email, and any content you share during the session).
  • Workshop labs and materials: the code-repository hosting service used to distribute the kit and lab repositories to Participants.

Independent Service Providers & Authorities:

  • Payment provider: Stripe Payments Europe, Limited and affiliated Stripe entities involved in payment processing.
  • Professional services: Our external accounting service provider, and external legal counsel (if required to defend or establish legal claims).
  • Public authorities: Tax offices and law enforcement authorities, only where legally required by binding regulations.

7. International transfers

Some providers listed above may process data outside the European Economic Area (EEA), particularly in the United States. Where they do, transfers are safeguarded by mechanisms permitted under the GDPR, such as the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the provider's active certification under the EU-U.S. Data Privacy Framework. You may request more information about these safeguards.

8. How long we keep it

  • Accounting and tax records: for the period required by Polish law - 5 years counted from the end of the calendar year in which the tax became due.
  • Contract and claim-related data: for as long as needed to perform the contract and until the relevant limitation periods for claims (3 years for business-related claims under the Polish Civil Code) expire.
  • Newsletter and lead magnet subscribers: until consent is withdrawn or the mailing list is discontinued.
  • Discovery call records: for as long as reasonably necessary to follow up on potential cooperation, but no longer than 12 months afterwards, unless further commercial cooperation follows.
  • General enquiries and correspondence: for as long as needed to fully handle and resolve the matter, and for up to 12 months for our related legitimate interest.

9. Your rights

Under the GDPR you have the right to access your data; to rectify it; to erase it; to restrict processing; to data portability; and to withdraw consent at any time. To exercise any right, email us at contact@aicontextengineering.eu. We will respond to your request without undue delay and in any event within one month of receiving it, unless the GDPR permits a longer period.

Specific Rights to Object:

  • Direct Marketing: You have an absolute and unconditional right to object at any time to the processing of your personal data for direct marketing purposes.
  • Legitimate Interest: You have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data based on our legitimate interests (Art. 6(1)(f) GDPR). If you object to processing necessary for the security or core operations of our website, we may no longer be able to provide the requested services.

You also have the right to lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office), ul. Stanisława Moniuszki 1A, 00-014 Warszawa.

10. Cookies and analytics

The site aims to run with minimal tracking. We use only strictly necessary technical cookies and local browser storage scripts that are essential to serve the site securely, maintain network infrastructure (such as security tokens from Cloudflare), prevent fraud during checkout (such as technical security cookies deployed directly by Stripe), and remember your local light/dark theme preference.

For audience measurement we use Plausible Analytics, a privacy-friendly, cookieless analytics service. It does not set cookies, does not use local storage for tracking, and does not build cross-site profiles of you; it produces only aggregated, non-identifying statistics (such as page views, referrers, and conversion goals). Because it relies on no cookies or device identifiers, it does not require prior consent under the e-Privacy Directive.

We do not use advertising or behavioural tracking cookies. In accordance with the e-Privacy Directive, the essential technical cookies and local storage parameters described above do not require your prior consent because they are strictly necessary for the operation, security, and basic functionality of the website. If we introduce non-essential tracking in the future, we will update this policy and request your explicit consent via a cookie banner.

11. Changes to this policy

We may update this policy as our services or legal obligations change. The current version is always published on this page with its effective date.