Privacy Policy of the DemystifAI Service
Effective from: May 17, 2026
§ 1
General provisions
- This Privacy Policy (hereinafter: the "Policy") contains information on the processing of your personal data in connection with the use of the website operated at https://tomasz.gusciora.pl/en (hereinafter: the "Website").
- All capitalized terms not defined otherwise in the Policy have the meaning given to them in the Terms and Conditions, available at: https://tomasz.gusciora.pl/en/en/terms.
- Use of the Website is voluntary. The provision of personal data within the scope required by a specific functionality (e.g. contact form, meeting booking, placing an order) is voluntary; however, failure to provide such data makes it impossible to use that functionality.
§ 2
Personal Data Controller
- The Controller of your personal data is Tomasz Guściora conducting business activity under the name DemystifAI Tomasz Guściora, registered in the Central Register and Information on Business Activity (CEIDG), with its registered office at Górczewska 90A/38 st, 01-117 Warsaw, Poland, tax ID: PL5222887609, REGON: 142537402 (hereinafter: the "Controller").
- In all matters related to the processing of personal data, you may contact the Controller via e-mail: [email protected], telephone: +48 508 830 667, or by traditional mail sent to the registered office address of the Controller.
- The Controller has not appointed a Data Protection Officer, as it is not obliged to do so under Article 37 of the GDPR. All data protection matters should be addressed directly to the Controller.
§ 3
Personal data protection measures
- The Controller applies modern organizational and technical safeguards to ensure an appropriate level of protection of your personal data, in particular: encryption of the connection to the Website (TLS/HTTPS), restriction of access to data to authorized persons only and regular updates of server software.
- The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the "GDPR"), the Polish Act of 10 May 2018 on the protection of personal data, and other provisions on the protection of personal data.
§ 4
Purposes and legal bases of processing
Conclusion and performance of an Agreement for the delivery of a Digital Product or for the provision of a Service
- Scope of data: first name and surname, e-mail address, telephone number, address of residence or business activity, and in the case of an Entrepreneur also the company name and tax ID.
- Legal basis: Art. 6(1)(b) GDPR (processing is necessary for the performance of a contract to which the data subject is party or in order to take steps prior to entering into a contract).
- Nature of provision: voluntary but necessary to conclude and perform the Agreement - without the data the Controller cannot process the order or perform the Service.
- Retention period: until claims arising from the Agreement become time-barred.
Handling of meeting bookings via the Calendar
- Scope of data: first name and surname, e-mail address, optionally time zone and additional information you provide in the booking form.
- Legal basis: Art. 6(1)(b) GDPR (steps taken prior to entering into an Agreement) and Art. 6(1)(f) GDPR (legitimate interest of the Controller in handling contact with a potential Customer).
- Nature of provision: voluntary but necessary to make a booking.
- Retention period: until the end of the conversation or conclusion of the Agreement, and after its conclusion - in accordance with the retention period applicable to the Agreement.
Recording and transcription of consultation meetings (Fireflies.ai)
- Scope of data: audio/video recording of the meeting, transcription of statements, first name and surname of participants visible in Google Meet, meeting metadata (date, time, duration).
- Purpose: producing notes, transcripts and summaries of the consultation in order to properly perform the Service and to document outcomes.
- Limited scope: only meetings scheduled in advance through the Google Calendar module on the Website are recorded. Ad-hoc meetings and phone calls are not recorded.
- Legal basis: Art. 6(1)(a) GDPR (consent to recording given by participants at the beginning of the meeting) and Art. 6(1)(f) GDPR (legitimate interest of the Controller in documenting consultation outcomes, after consent has been obtained).
- Nature of provision: voluntary; refusal of consent means that the Fireflies bot will not be admitted to the meeting or will be removed - the meeting will still take place without recording.
- Retention period: recordings and transcripts are kept for the period necessary to achieve the purpose, no longer than 12 months from the date of the meeting, unless a longer period is necessary to establish, exercise or defend against claims.
Handling of inquiries submitted via the contact form
- Scope of data: first name, e-mail address and other data contained in the message sent to the Controller.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller in responding to the inquiry received).
- Nature of provision: voluntary but necessary to receive a response.
- Retention period: until the end of the correspondence or, in the event of an objection, promptly after it is effectively raised.
Handling of complaints
- Scope of data: first name and surname, e-mail address and other data provided in the content of the complaint.
- Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation to which the Controller is subject, in particular obligations under the Polish Act of 30 May 2014 on consumer rights).
- Nature of provision: a condition for receiving a response to the complaint.
- Retention period: for the duration of the complaint procedure and subsequently until claims become time-barred.
Fulfillment of tax and accounting obligations
- Scope of data: first name and surname or company name, address of residence or registered office, tax ID.
- Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation to which the Controller is subject, in particular obligations under tax law and the Polish Accounting Act).
- Nature of provision: necessary to issue an invoice or other accounting document.
- Retention period: 5 years from the end of the calendar year in which the tax payment deadline expired.
Exercising GDPR rights and fulfilling data protection obligations
- Scope of data: first name and surname, contact details provided by the data subject.
- Legal basis: Art. 6(1)(c) GDPR (compliance with a legal obligation to which the Controller is subject under provisions on the protection of personal data).
- Nature of provision: necessary to properly exercise the rights granted by the GDPR.
- Retention period: until the expiry of the limitation periods for claims arising from violations of data protection law.
Establishment, exercise or defense of claims
- Scope of data: first name and surname or company name, e-mail address, address of residence or registered office, tax ID and other data resulting from the concluded Agreement.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller in establishing, exercising or defending against claims).
- Nature of provision: necessary to achieve the above purpose.
- Retention period: until the expiry of the limitation periods for claims that may arise in connection with the performance of Agreements concluded with the Controller.
Analysis of activity on the Website (GA4, Microsoft Clarity)
- Scope of data: date and time of visit, IP address of the device, approximate location, type of operating system and browser, time spent on the Website, visited subpages, interaction events and session recordings (Microsoft Clarity).
- Legal basis: Art. 6(1)(a) GDPR (your consent given through the cookie consent panel).
- Nature of provision: voluntary; the absence of consent does not limit your ability to use the Website.
- Retention period: until consent is withdrawn, an objection is effectively raised, or the purpose of processing is achieved, whichever occurs first.
Administration of the Website (server logs and security)
- Scope of data: IP address, date and time of the request to the server, information about the browser and operating system. This data is recorded automatically in server logs and in Cloudflare logs.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller in ensuring the proper and secure operation of the Website).
- Nature of provision: no active provision of data is required - the data is collected automatically as you use the Website.
- Retention period: until an objection is effectively raised or the purpose of processing is achieved, but no longer than 12 months for standard access logs.
§ 5
Profiling for marketing purposes
- In order to better match content and marketing activities to your preferences, the Controller may process your personal data by automated means, including by profiling. Profiling does not produce legal effects concerning you nor similarly significantly affect you.
- The scope of personal data subject to profiling corresponds to the scope indicated in § 4 with respect to the analysis of activity on the Website, data provided in messages and bookings, and data relating to Digital Products and Services purchased.
- The legal basis for the processing is Art. 6(1)(f) GDPR (legitimate interest of the Controller in conducting marketing activities tailored to the preferences of recipients), and with respect to the use of analytics and marketing cookies - Art. 6(1)(a) GDPR (your consent).
- The Controller will process personal data for the purpose of profiling until an objection is effectively raised, consent is withdrawn, or the purpose of processing is achieved.
§ 6
Recipients of personal data
Entities cooperating with the Controller (processors)
- VPS hosting - provider: UW-TEAM.org Jakub Mrugalski, Tax ID: 6821639338 (CEIDG); country: Poland. Scope: operation of the VPS on which the Website physically runs. Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller - delivery of the Website).
- Cloudflare - provider: Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; country: USA (transfer based on Commission Implementing Decision (EU) 2023/1795 - EU-US Data Privacy Framework). Scope: CDN, DDoS protection and optimization of the delivery of the Website to end users. Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller - security and performance of the Website).
- Formspark - provider: Studio Wildhive Limited (operator of submit-form.com), United Kingdom; country: United Kingdom (European Commission adequacy decision of 28 June 2021). Scope: receipt and forwarding to the Controller of messages submitted through the contact form on the Website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest of the Controller - handling correspondence with Customers).
- Google Calendar Appointment Scheduling - provider: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; country: USA / EEA (transfer to the USA based on Commission Implementing Decision (EU) 2023/1795 - EU-US Data Privacy Framework). Scope: handling meeting bookings via the Google Calendar module embedded in the Website, including accepting bookings and sending confirmations. Legal basis: Art. 6(1)(b) GDPR (steps taken prior to entering into an Agreement) and Art. 6(1)(f) GDPR (legitimate interest - enabling contact with the Controller).
- Google Analytics 4 - provider: Google Ireland Limited and Google LLC, USA; country: USA / EEA (transfer based on Commission Implementing Decision (EU) 2023/1795 - EU-US Data Privacy Framework). Scope: analysis of traffic on the Website, statistics on the use of individual subpages, assessment of content effectiveness. Legal basis: Art. 6(1)(a) GDPR (consent given through the cookie consent panel).
- Microsoft Clarity - provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA; country: USA (transfer based on Commission Implementing Decision (EU) 2023/1795 - EU-US Data Privacy Framework). Scope: analysis of user behavior on the Website (heatmaps, session recordings, user paths) in order to improve usability (UX). Legal basis: Art. 6(1)(a) GDPR (consent given through the cookie consent panel).
- Fireflies.ai - provider: Fireflies AI, Inc., 333 Bush St, Suite 2300, San Francisco, CA 94104, USA; country: USA (transfer based on Commission Implementing Decision (EU) 2023/1795 - EU-US Data Privacy Framework; where the recipient does not participate in the framework, EU standard contractual clauses). Scope: recording and transcription of meetings scheduled via the Calendar (Google Meet) only, for the purpose of producing notes, transcripts and summaries of the consultation; the Fireflies bot joins the meeting after it starts and the Controller informs participants of the recording and obtains their consent at the beginning of the meeting. Ad-hoc meetings and phone calls are not recorded.. Legal basis: Art. 6(1)(a) GDPR (participant's consent given at the beginning of the meeting to recording and transcription) and Art. 6(1)(f) GDPR (legitimate interest of the Controller in documenting consultation outcomes, after consent to recording has been obtained).
Other recipients
- Personal data may be transferred to public or private entities where such an obligation arises from generally applicable provisions of law, a final court judgment or a final administrative decision (e.g. to tax authorities, courts, law-enforcement bodies).
- Personal data may be transferred to the accounting firm servicing the Controller and to the law firm servicing the Controller - only to the extent and for the period necessary to fulfill the relevant obligations or perform services for the Controller.
§ 7
Transfer of personal data to third countries
- In connection with the use of services provided by Google LLC, Microsoft Corporation and Cloudflare, Inc., your personal data may be transferred to the United States of America.
- The basis for the transfer of data to the USA is Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU-US Data Privacy Framework, provided that the relevant recipient participates in that framework.
- In cases where the recipient does not participate in the EU-US Data Privacy Framework, data is transferred on the basis of standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
- In connection with the use of Formspark (Studio Wildhive Limited), your personal data may be transferred to the United Kingdom - a country for which the European Commission has issued an adequacy decision.
- You may obtain a copy of the data transferred to a third country from the Controller by contacting [email protected].
§ 8
Your rights
- Right of access - you may obtain from the Controller information as to whether and which personal data concerning you are being processed and receive a copy of such data. The first copy is provided free of charge; for further copies the Controller may charge a reasonable fee corresponding to administrative costs.
- Right to rectification - if your data is outdated, incomplete or otherwise incorrect, you have the right to request its rectification or completion.
- Right to erasure ("right to be forgotten") - in the situations indicated in Article 17 of the GDPR, in particular where the data is no longer necessary for the purposes for which it was collected, you withdraw consent on which the processing is based, or the processing is unlawful.
- Right to restriction of processing - you may request that the Controller perform no operations on your data other than storing it, in the situations indicated in Article 18 of the GDPR.
- Right to data portability - with respect to data processed on the basis of consent or contract, you may receive such data in a structured, commonly used, machine-readable format and transfer it to another controller.
- Right to object - with respect to data processed on the basis of the legitimate interest of the Controller, including profiling. Upon effective objection, the Controller will cease processing the data for the relevant purpose.
- Right to withdraw consent - at any time, with respect to data processed on the basis of consent. Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal.
- Right to lodge a complaint with the supervisory authority - the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland), if you consider that the processing of your personal data infringes the GDPR.
- To exercise the rights above, please contact the Controller at [email protected].
§ 9
Cookies and the consent panel
General information
- The Website uses cookies - small text files stored on your end device. These files may be read by the Controller's systems as well as by systems of third parties whose services are used by the Controller (in particular Google, Microsoft, Cloudflare).
- The Controller manages consent to cookies through a panel based on the open-source vanilla-cookieconsent library. On your first visit to the Website, a panel is displayed enabling you to accept or reject individual categories of cookies. You may change your choice at any time by clicking the privacy settings link in the footer of the Website.
- Cookies strictly necessary for the operation of the Website (e.g. Cloudflare security cookies) are stored without the need to obtain consent, as they are a condition for providing the information-society service requested by the user.
- Analytics and marketing cookies (GA4, Microsoft Clarity) are stored only after consent is granted through the cookie panel.
- Data collected via cookies does not by itself allow the Controller to identify you directly.
List of cookies used
- Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA) - necessary security cookies (e.g. __cf_bm, cf_clearance) preventing abuse and automated bots. Retention: from 30 minutes to approx. 1 year depending on the cookie type. Status: necessary for the operation of the Website - no consent required.
- Google Calendar Appointment Scheduling (Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) - Google cookies required for the operation of the embedded calendar and protection of the user session. Retention: session cookies or up to 24 months (in accordance with Google's policy). Status: necessary for the operation of the Website - no consent required.
- Google Analytics 4 (Google Ireland Limited and Google LLC, USA) - analytics cookies (e.g. _ga, _ga_*) collecting anonymized information about the session, device and visited subpages. Retention: up to 14 months. Status: requires consent given through the cookie panel.
- Microsoft Clarity (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA) - cookies (e.g. _clck, _clsk, CLID) storing an anonymized session identifier and page-interaction data. Retention: session cookies up to 1 year. Status: requires consent given through the cookie panel.
Browser-side control
- Independently of the cookie panel, you may at any time check, delete or block cookies through the settings of your web browser. Disabling cookies may cause limitations in using the Website, in particular non-functioning of certain features (e.g. the embedded booking calendar).
§ 10
Final provisions
- In matters not regulated by the Policy, the generally applicable provisions on the protection of personal data shall apply, in particular the GDPR and the Polish Act of 10 May 2018 on the protection of personal data.
- The Controller may amend the Policy for important reasons, in particular in the event of changes in law, changes in the scope of data processed, changes in the recipients of data or the launch of new functionalities of the Website.
- The current version of the Policy is published on the Website at https://tomasz.gusciora.pl/en/privacy-policy and is effective as of the date of its publication, unless a later effective date is indicated.
- This Policy is effective from: May 17, 2026.
Tomasz Guściora
DemystifAI Tomasz Guściora
Górczewska 90A/38 st, 01-117 Warsaw, Poland
Tax ID: PL5222887609 | REGON: 142537402
E-mail: [email protected] | Phone: +48 508 830 667
Last updated: May 17, 2026