Switch colour mode

Privacy policy

Last updated: 7 September 2026

This Privacy and Cookie Policy explains how we process personal data relating to people who use hypercon.pl, contact us, submit enquiries or briefs, take part in projects, or complete project questionnaires.

1. Data controller

The controller of your personal data is HYPERCON PATRYK PAWLIK, ul. Władysława Orkana 43/50, 42-229 Częstochowa, Poland, Tax Identification Number (NIP): 5732902383, National Business Registry Number (REGON): 380678354 (“Hypercon”, “we”, “us”).

For privacy enquiries or to exercise your rights, contact us:

2. Personal data we process

Depending on how you use the website, we may process:

  • identity and contact details, in particular your name, email address, telephone number, company name and job title;
  • the content of your message, enquiry or brief, the selected project scope, budget, deadlines and any attachments you choose to provide;
  • answers provided in client questionnaires and information connected with project delivery;
  • contract and billing details if we enter into a business relationship;
  • technical and usage data, such as your IP address, cookie or similar identifiers, device and browser type, operating system, approximate location, pages visited, traffic source, events and time spent using the website;
  • the status and date of your cookie choices.

We do not ask you to provide special-category data such as health information, political opinions, religious beliefs or information about ethnic origin. Please do not include such data in messages, briefs or questionnaires unless this is necessary and has been agreed with us in advance.

3. Purposes, legal bases and retention periods

3.1. Contact, requests for proposals and starting a project

We process data to respond to you, clarify your needs, prepare an offer and take steps at your request before entering into a contract. The legal basis is Article 6(1)(b) GDPR. If you contact us as an employee or representative of an organisation, we also rely on Article 6(1)(f) GDPR; our legitimate interest is to conduct business communications and manage our relationship with that organisation.

We retain the data while handling the enquiry and any negotiations and then, as a rule, for no more than 3 years after the last substantive contact, in order to preserve a record of arrangements and defend against claims. If a contract is concluded, the data becomes part of the project records described below.

3.2. Contract and project delivery, including client questionnaires

We process data to perform a contract or take steps before entering into one (Article 6(1)(b) GDPR). We process the data of a client’s representatives, employees and contractors under Article 6(1)(f) GDPR; our legitimate interests are to deliver the project properly, communicate, document arrangements and manage the client relationship.

We retain working data, briefs and questionnaire answers throughout project delivery and then for the period needed to settle the engagement and protect against claims — usually up to 3 years in business relationships and, where a longer limitation period applies, no longer than until that period expires. We erase or anonymise data that is no longer needed for these purposes earlier.

3.3. Billing and legal obligations

We process data in contracts, invoices, accounting and tax records to perform the contract (Article 6(1)(b) GDPR) and comply with legal, in particular accounting and tax, obligations (Article 6(1)(c) GDPR). We retain these records for the period required by law — as a rule, 5 years from the end of the calendar year in which the relevant tax deadline expired — and for longer only where necessary to establish, exercise or defend legal claims.

3.4. Security, diagnostics and abuse prevention

We process technical data, logs and information associated with spam and abuse detection under Article 6(1)(f) GDPR. Our legitimate interest is to protect the website, forms, infrastructure and communications and to diagnose errors.

We retain this data only for as long as needed for diagnostics and security, normally no longer than 12 months. Data concerning a specific incident may be retained until that incident has been resolved and the limitation period for related claims has expired.

3.5. Analytics, website improvement and advertising

With your consent, we use tools that provide analytics, help us understand how the website is used and measure advertising effectiveness. Personal data is processed under Article 6(1)(a) GDPR, and information is stored on or accessed from your device in accordance with the choice you make in the cookie banner.

We process this data until you withdraw consent, it is no longer useful for the relevant purpose, or the identifier reaches the expiry period stated in the cookie section — whichever occurs first. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

3.6. Direct marketing

Where we conduct marketing of our own services on the basis of legitimate interests, we rely on Article 6(1)(f) GDPR; our interests are to present and develop our services and maintain business relationships. Where consent is required by law, in particular for commercial communications by email or marketing involving terminal equipment, we act only with prior consent (Article 6(1)(a) GDPR and Article 398 of the Polish Electronic Communications Law).

We use the data until you withdraw consent, object to direct marketing or we end the marketing activity — whichever occurs first. We may retain a limited record of an objection or withdrawn consent so that we can respect the choice and demonstrate that it was handled.

3.7. Recruitment

If you send us a job application, we process data needed for the current recruitment under Article 6(1)(b) or (c) GDPR, depending on the intended form of engagement and the required data. We process additional data provided voluntarily on the basis of consent (Article 6(1)(a) GDPR). We use data for future recruitment only if you give separate consent.

We retain data until the current recruitment ends and for a longer period — no more than 12 months — only where you have consented to future recruitment. We may retain the minimum data needed until the limitation period for potential recruitment-related claims expires.

3.8. Legal claims and compliance

Where necessary, we process data to establish, exercise or defend legal claims and to demonstrate compliance with law. We rely on Article 6(1)(f) GDPR; our legitimate interest is to protect our rights and document proper conduct. We retain the data until the matter has been finally resolved or the applicable limitation period has expired.

4. Whether you must provide data

Providing data is not a statutory requirement. Fields marked as required in a form are, however, needed to submit that form, contact you, prepare an offer or complete the requested project step. Without them, we will be unable to handle the enquiry or perform the requested action. Other fields are optional.

After a contract is concluded, certain data may be contractually or legally required, in particular to enter into and perform the contract and issue accounting documents. We provide information about such requirements in the relevant process.

5. Sources of data

We usually receive data directly from you. If you represent a client, supplier or another organisation, your data may be provided by that organisation or by another person involved in the project. Technical data is generated when you use the website and may be provided by the service providers described below.

6. Recipients of personal data

We may disclose data, only to the extent necessary for the relevant purpose, to:

  • authorised people working with Hypercon and involved in handling an enquiry or delivering a project;
  • hosting, server, email, backup, web-tool and IT support providers;
  • providers of consent-management, security and abuse-prevention solutions;
  • providers of analytics, usability research and marketing-effectiveness measurement services — only after the relevant consent has been obtained;
  • accounting, legal, audit, postal and courier service providers;
  • public authorities and other entities where disclosure is required by law.

Entities acting on our behalf process data under contracts and in accordance with our instructions, unless the law assigns them an independent controller role.

7. Transfers outside the EEA

Some technology providers may have registered offices, infrastructure or subprocessors outside the European Economic Area.

Where such a transfer occurs, we use a mechanism available under Chapter V GDPR, as appropriate: a European Commission adequacy decision, the recipient’s participation in a recognised adequacy framework, or European Commission-approved Standard Contractual Clauses, supplemented by additional safeguards where required. You may contact us for information about the relevant mechanism or a copy of the applicable safeguards.

8. Cookies and similar technologies

Cookies are small pieces of information stored in your browser. The website also uses localStorage and sessionStorage, which may remember settings or session state. We divide these technologies into necessary and optional categories. Optional analytics and advertising tools are activated only after you give consent in the cookie banner.

8.1. Necessary and security-related technologies

Necessary technologies maintain the session, protect the website and forms, prevent abuse and remember cookie choices. They may operate for the current session or for the period needed to retain consent settings. They are not used for advertising.

8.2. Preferences and functionality

Functional technologies may remember the selected language version, appearance settings and the state of interface elements. They operate until the relevant setting expires, website data is cleared in the browser or the website configuration changes.

8.3. Analytics and website-use research — with consent

With your consent, we may use analytics tools, including Hotjar, to measure traffic, understand how the website is used and improve usability. Data is retained for the period stated for the relevant technology in the consent-management panel and no longer than needed for the analysis.

8.4. Advertising and conversion measurement — with consent

With your consent, we may use technologies that measure campaign effectiveness, attribute conversions and tailor marketing communications. These technologies may recognise a browser or device and combine information about activity on the website with data held by their providers. Current technologies, their purposes and operating periods are listed in the “Manage consent” panel.

8.5. Managing consent

On your first visit, you can accept all optional technologies, reject them or select specific categories. You can withdraw or change your consent at any time by reopening the “Manage consent” panel. You can also remove or block cookies and website data in your browser settings. Blocking necessary technologies may prevent some features from working correctly.

9. Detailed information about technologies

A list of the cookies and similar technologies currently in use, their categories, purposes and operating periods is available in the “Manage consent” panel. The panel is the appropriate place for information that may change with the technical configuration of the website.

10. Your rights

Where provided by the GDPR, you have the right to:

  • access your data and obtain a copy;
  • rectify your data;
  • erase your data;
  • restrict processing;
  • data portability;
  • object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation;
  • object to direct marketing at any time; after such an objection, we will no longer process your data for that purpose;
  • withdraw consent at any time where processing is based on consent;
  • lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych). Current contact details are available at uodo.gov.pl. You may also contact the data protection authority in the EU or EEA country where you live, work or believe an infringement occurred.

To exercise your rights, email hello@hypercon.pl. We may ask for information needed to verify your identity before acting on a request. We will respond without undue delay, normally within one month.

11. Profiling and automated decisions

After you give consent, analytics and advertising providers may combine information about your activity on the website with other identifiers and assign you to advertising audiences, which may affect the ads you see. Hypercon does not, however, make decisions about users based solely on automated processing that produce legal effects or similarly significantly affect them.

12. Data security

We use technical and organisational measures appropriate to the risk, including encrypted connections to the website, access controls, backups and measures that protect forms and infrastructure. Data is accessible only to people and entities that need it to perform specified tasks.

13. Changes to this policy

We may update this Policy when the law, the operation of the website or the services we use change. The current version is published on this page together with the date of the latest update. If a change is material, we may also provide an additional notice on the website.