ITC Europe — logo ITC Europe Energy audit · technical advisory
PL EN DE
Home →
Home → Privacy Policy
Legal document

Privacy Policy

Effective date: 24 April 2026 · Version: 1.0

This Privacy Policy sets out the rules for processing personal data collected by ITC Europe Sp. z o.o. in connection with the use of the website itc-europe.com (the "Site") and business communications.

The Policy has been drafted in accordance with:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR),
  • Polish Act of 10 May 2018 on the Protection of Personal Data,
  • Directive 2002/58/EC on privacy in the electronic communications sector (ePrivacy),
  • Polish Act of 16 July 2004 — Telecommunications Law (Art. 173),
  • EU Directive 2022/2555 on cybersecurity (NIS2).

Table of contents

  1. Data controller
  2. Contact for data protection matters
  3. Purposes and legal bases of processing
  4. Retention periods
  5. Recipients of data
  6. Transfers to third countries
  7. Rights of data subjects
  8. Voluntary provision of data
  9. Automated decision-making and profiling
  10. Data security
  11. Cookies
  12. Changes to the Policy

1. Data controller

The controller of your personal data is:

ITC EUROPE Spółka z ograniczoną odpowiedzialnością
ul. Wawelska 78/17
02-034 Warsaw
Poland

National Court Register (KRS): 0000263179
Tax ID (NIP): 5242585596
Statistical ID (REGON): 140685245

2. Contact for data protection matters

For all matters related to the processing of personal data, you may contact the Controller:

  • e-mail: email
  • by post: ITC Europe Sp. z o.o., ul. Wawelska 78/17, 02-034 Warsaw, Poland

A Data Protection Officer has not been appointed — the Controller's activity and scale of processing do not meet the criteria specified in Article 37 GDPR.

3. Purposes and legal bases of processing

3.1. Contact via contact form

  • Scope of data: name, e-mail address, company name (optional), message content, IP address, browser User-Agent, timestamp.
  • Legal basis: Art. 6(1)(f) GDPR — legitimate interest of the Controller in handling enquiries and conducting business correspondence.
  • Purpose: responding to the enquiry, preparing an offer, establishing business contact.

3.2. E-mail and phone communication

  • Scope of data: identification data of the contact party, content of correspondence, contact details.
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest — B2B communication); if a contract is concluded — Art. 6(1)(b) GDPR (necessity for pre-contractual steps and contract performance).

3.3. Site security and protection against abuse

  • Scope of data: IP address, User-Agent, timestamps, Cloudflare Turnstile verification data.
  • Legal basis: Art. 6(1)(f) GDPR — legitimate interest in ensuring Site security, preventing spam and automated attacks.

3.4. Compliance with legal obligations

  • Scope of data: data necessary for issuing invoices, keeping accounting records and archiving.
  • Legal basis: Art. 6(1)(c) GDPR — legal obligations arising from tax law and the Accounting Act.

4. Retention periods

Data category / purposeRetention period
Form enquiries without establishing a business relationship3 years from last contact
Client correspondence (after contract)5 years after end of cooperation
Accounting data (invoices, contracts)5 years from end of tax year (Accounting Act)
Server logs and security data12 months
Technical cookies (Cloudflare Turnstile)Max. 30 minutes (session tokens)

5. Recipients of data

We use trusted entities that process data on our behalf to the extent necessary to provide our services:

5.1. Technical providers

  • Zenbox Sp. z o.o. (SEOHost.pl, Poland) — hosting provider for the website and e-mail. Servers located in Poland.
  • Cloudflare, Inc. (San Francisco, USA) — Turnstile service (form protection against bots).
  • Google LLC (Mountain View, USA) — Google Fonts provider (fonts loaded by the user's browser when displaying the Site).

5.2. Supporting entities

  • Accounting office / tax advisors — for bookkeeping services.
  • Postal and courier operators — for paper correspondence.
  • Law firms — in case of disputes or claims.

All these entities operate under written data processing agreements (Art. 28 GDPR) including confidentiality obligations and appropriate security measures.

6. Transfers to third countries

Some data may be transferred outside the European Economic Area (EEA), in particular to the USA:

  • Cloudflare, Inc. (USA) — as part of the Turnstile service.
  • Google LLC (USA) — as part of Google Fonts.

Transfers are carried out in accordance with Chapter V GDPR on the basis of:

  • EU-U.S. Data Privacy Framework — European Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 finding an adequate level of protection for data transferred from the EU to DPF-certified entities.
  • Standard Contractual Clauses (SCCs) — European Commission Implementing Decision 2021/914.

7. Rights of data subjects

Under GDPR you have the following rights:

RightBasis (GDPR)Description
Right of accessArt. 15Obtain a copy of your data and information about processing.
Right to rectificationArt. 16Correct inaccurate or incomplete data.
Right to erasure ("right to be forgotten")Art. 17Delete data when the processing purpose ceases.
Right to restrictionArt. 18Temporarily suspend the use of data.
Right to data portabilityArt. 20Receive data in a machine-readable format.
Right to objectArt. 21Against processing based on legitimate interest.
Right to withdraw consentArt. 7(3)Without affecting processing carried out before withdrawal.
Right to lodge a complaintArt. 77President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.

To exercise these rights please contact: email. We respond without undue delay, no later than within 30 days of receiving the request (Art. 12(3) GDPR).

8. Voluntary provision of data

Providing data in the contact form is voluntary but necessary to respond to your enquiry. Failure to provide data in fields marked as required will prevent processing of the enquiry.

9. Automated decision-making and profiling

Your data is not used for automated decision-making, including profiling as referred to in Art. 22 GDPR. The only automated operation concerns the form security check (Cloudflare Turnstile), whose sole purpose is to distinguish human traffic from automated (bot) traffic.

10. Data security

We apply appropriate technical and organisational measures to protect personal data, including:

  • HTTPS transmission encryption (TLS 1.3),
  • multi-layered protection of the contact form: Cloudflare Turnstile, honeypot, rate limits, anti-spam filters,
  • regular updates of server software and dependencies,
  • access control (authentication, strong passwords, least-privilege principle),
  • encrypted backups,
  • password and access policies.

As an entity operating in the advisory sector for critical infrastructure and the energy industry, we align our security measures with the guidelines of the NIS2 Directive (Directive (EU) 2022/2555 on measures for a high common level of cybersecurity).

11. Cookies and similar technologies

Information on cookies used on the Site is provided in a separate document: Cookie Policy.

12. Changes to the Privacy Policy

We reserve the right to make changes to this Privacy Policy. Material changes will be communicated by updating this page and dating the new version. Previous versions are archived and made available on request.

13. Final provisions

In matters not regulated by this Policy, the provisions of GDPR, the Polish Personal Data Protection Act and other generally applicable provisions of Polish and EU law shall apply.

ITC Europe
Audit · Optimization · Energy · Infrastructure
Privacy Policy Cookie Policy
PL · EN · DE