Jedra Partners

Legal

Privacy policy

Last updated: 21 August 2026

This site is a business card, not a service you sign up for. The contact form is the only place where we ask you for personal data. Two things happen without you filling anything in: when the form is sent, your IP address is checked against a spam limit, and visits are counted without cookies. Both are described below, along with what happens to what you send us, how long we keep it, and what you can ask us to do with it.

1. Data controller

Jedra Partners Jacek Jędrasiewicz (jednoosobowa działalność gospodarcza — a sole proprietorship registered in Poland), of ul. Melchiora Wańkowicza 18/5, 58-500 Jelenia Góra, Polska, tax identification number (NIP) 6112651556, is the controller of the personal data collected through this site. We are a small team of senior SAP and data engineering consultants, based in Poland and working for clients across the European Union.

We have not appointed a data protection officer, so anything you write about your data goes straight to the people who run the company: to jacekjedrasiewicz@gmail.com, through the contact form on this site, or by phone, +48 533 494 786.

2. What data we collect

The contact form asks for your name, your company, your email address and your message. The phone number is optional. We also record which language version of the site you wrote from, so that we reply in the same language.

When the form is submitted, our server sees your IP address. In the form itself it serves one purpose only: counting how many messages come from the same address within ten minutes, so that bots cannot flood us. Used that way, the address stays in the memory of the server instance that handled the submission, never reaches a database, never appears in the logs of our application, and is never attached to your inquiry. Separately from that, the provider hosting this site records IP addresses in its technical logs for every request it serves, which is a standard part of keeping a service running and secure.

Two more things travel with your message: the box you tick to confirm you have read this policy, and a hidden technical field belonging to the anti-spam filter described further down, which stays empty for anyone filling the form in a browser. Nothing else. This site has no accounts, no logins, no newsletter and no payments, so we do not ask for data we have no use for. Please do not send confidential documents or credentials through the form. Once we are talking, we will agree on a safer channel.

3. Why we process it, and on what legal basis

Each purpose has its own legal ground under the GDPR:

  • Reading your message, replying to it and carrying on the conversation that follows. Legal ground: our legitimate interest (Article 6(1)(f) GDPR), which is being able to answer someone who contacted us.
  • Preparing an offer and agreeing terms, if the conversation goes that way. Legal ground: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).
  • Keeping the form usable and free of automated spam: the ten-minute limit on messages from one IP address described above, and a hidden field in the form that only bots fill in. Legal ground: our legitimate interest (Article 6(1)(f) GDPR) in the security of the site.
  • Keeping business correspondence that could matter if a dispute arises. This covers only contacts that turned into working together: an inquiry that leads nowhere is deleted after the 12 months described below and is not kept for this purpose. Legal ground: our legitimate interest (Article 6(1)(f) GDPR) in establishing, pursuing or defending claims. Period: the limitation period for such claims, three years under Polish law.

We do not use anything from the form for marketing. You will not be added to a mailing list, and you will not get offers you did not ask for.

The box you tick under the form only confirms that you have read this policy. It is not a consent form: we do not rely on consent here, so there is nothing for you to withdraw. What you do have is the right to object, described further down.

4. Statistics and cookies

We use Vercel Web Analytics to see how many people visit the site and which pages they open. Besides the page opened, each visit is described by a few general details: the site or search engine you arrived from, the country worked out from your IP address, and your operating system, browser and device type. It works without cookies: nothing is stored on your device and no profile of you is built. Each visit is reduced to a hash computed on the server, and that hash is discarded within 24 hours.

The site also counts a handful of technical events, for example a click on the phone number or a successful form submission. These counters carry no content from the form and are not linked to your identity.

The site sets no cookies of its own, and no advertising or tracking cookies at all, which is why you will not see a cookie banner here. Legal ground for the statistics: our legitimate interest (Article 6(1)(f) GDPR) in knowing whether the site does its job.

5. Who else handles your data

We do not sell data and we do not pass it to anyone for their own purposes. Getting your message to us and keeping this site running does involve providers that process the data on our behalf. We use only providers that do so under a data processing agreement, and having those agreements in place is a condition of this site being live:

  • Resend, Inc. delivers the message from the form to our mailbox.
  • Vercel Inc. hosts this site and provides the statistics described above.
  • The provider of our business mailbox. Our email is hosted externally, as it is in most companies, so that provider stores your message, with everything you wrote in it, for as long as we keep the correspondence. The condition above applies to it exactly as it does to the two named here. Ask through the contact form and we will tell you which provider it is.

There is no database of inquiries behind this site. Your message travels over an encrypted connection and lands in our mailbox as an ordinary email, handled like the rest of our business correspondence.

We will also hand over data where the law requires it, for example to an authority acting within its powers.

6. Transfers outside the European Economic Area

Resend and Vercel are companies based in the United States, so the data they process for us may be processed outside the European Economic Area.

Both are certified under the EU-U.S. Data Privacy Framework, covered by the European Commission's adequacy decision of 10 July 2023, and our agreements with them additionally include the Standard Contractual Clauses approved by the Commission. To get a copy of these safeguards, or a link to where the providers publish them, ask through the contact form or call +48 533 494 786.

The provider of our mailbox may likewise store correspondence outside the European Economic Area. We use such a provider only where the transfer rests on the same kind of safeguard: an adequacy decision covering that provider, or the Standard Contractual Clauses. Ask through the contact form and we will tell you which provider it is and how to get a copy of those safeguards.

7. How long we keep it

Correspondence from the form is kept for up to 12 months after the exchange ends. If nothing comes of it, we delete it.

If the contact turns into working together, we keep the correspondence for as long as the engagement lasts, and then for the limitation period for related claims, which under Polish law is three years. Accounting documents from that work are kept for as long as tax law requires, currently five years counted from the end of the tax year they belong to.

The IP address used for the anti-spam limit is held only in the memory of the server instance that handled the submission, and our application writes it nowhere else. Once its ten-minute window has passed, the address is wiped by the next submission that reaches the counter on that instance, meaning one the hidden-field filter has not already discarded, and it is gone in any case as soon as the instance is restarted or replaced. The IP addresses in the hosting provider's technical logs are a separate matter: they are kept for a period that follows from that provider's own settings.

8. Your rights

In relation to the data we hold about you, you can ask us to:

  • tell you what we have and give you a copy of it,
  • correct anything that is wrong or out of date,
  • delete it,
  • put its use on hold while we look into a request or an objection,
  • give you the data you provided in a commonly used, machine-readable format, or send it straight to another controller where that is technically possible, as far as we process it in order to prepare or perform a contract,
  • stop processing it, on the ground described in the next section.

Ask through the contact form or call +48 533 494 786. We answer within one month. If a request turns out to be complicated, we will say so and take up to two months more, which is what the GDPR allows.

If you think we are handling your data badly, you can also complain to the supervisory authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).

9. Your right to object

Most of what we do rests on our legitimate interest, so you can object to that processing at any time, on grounds relating to your particular situation. Article 21 GDPR gives you this right, and the information about it has to be presented clearly and separately from everything else. Hence this box.

An objection needs no form and no lengthy justification. Tell us through the contact form or by phone and we will stop, unless we can demonstrate compelling legitimate grounds that override your interests, for example a claim that is already being pursued.

10. Do you have to give us your data

No, writing to us is entirely up to you. The form will not send, though, without your name, your company, an email address, the message itself and the tick confirming you have read this policy. The first four we need in order to reply; the tick is there so that nobody writes to us without knowing what happens to their data. The phone number is optional and we use it only when calling back is quicker than writing.

11. Automated spam filtering, no profiling

We do not profile anyone, and we take no decisions about you by automated means that would produce legal effects concerning you or similarly significantly affect you, in the sense of Article 22 GDPR. What does run automatically is a spam filter, and it works in two ways.

First, the form contains a hidden field. It is invisible on screen and skipped by screen readers, so for anyone filling the form in a browser it always stays empty, while automated scripts fill it in along with everything else. A submission that arrives with something in that field is discarded on the server before any email is created, and the screen still shows the usual confirmation, so that whoever sent it gets no hint about how the filter works. Second, a fourth message from the same IP address within ten minutes is rejected automatically, this time with a visible error.

Both mechanisms work without anyone looking at them, so a submission classified as spam may never reach a person. An ordinary message written in a browser is not affected, because nobody fills in a field they cannot see. If you are ever unsure whether your message got through, call +48 533 494 786 and we will check.

12. Changes to this policy

If the way this site handles data changes, we update this page and change the date at the top. When a change is significant, we describe what changed instead of quietly replacing the text.

13. Contact

For anything to do with your data, including requests and objections, use the contact form or call +48 533 494 786. Both reach the same people.