Privacy Policy
General Provisions
This Privacy Policy sets out the rules for the processing of personal data of Users of www.flexhouse.pl (hereinafter the “Website”) and the rules for the use on the Website of cookies and tools used to collect statistics and analyse how the Website is used.
The data controller is Flexhouse sp. z o.o., with its registered office in Warsaw, ul. Ostródzka 245b/7b, 03-289 Warsaw, entered in the register of entrepreneurs of the National Court Register by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Division of the National Court Register, under KRS number 0000430927, NIP 5242752901, REGON 146254492, share capital: PLN 5,000.00, hereinafter the “Controller”.
The Controller may be contacted:
- in writing: at the registered office address indicated above,
- electronically at: flexhouse@flexhouse.pl.
The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (GDPR), as well as other applicable Polish and European Union laws.
The Controller may be contacted in all matters related to the processing of personal data and the exercise of rights under the GDPR.
Definitions
- Controller – Flexhouse sp. z o.o., with its registered office in Warsaw, ul. Ostródzka 245b/7b, 03-289 Warsaw, entered in the register of entrepreneurs of the National Court Register by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Division of the National Court Register, under KRS number 0000430927, NIP 5242752901, REGON 146254492, share capital: PLN 5,000.00.
- Website – the website available at www.flexhouse.pl.
- Privacy Policy – this Website privacy policy together with its appendices.
- Data – personal data of persons interacting with the Website within the meaning of the GDPR.
- User – a user of the Website and other persons interacting with the Website and other related websites, communications and services.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
Scope of Personal Data Processed
The Controller may process, in particular, the following categories of data:
-
Data obtained in connection with communication:
data provided in the contact form, data contained in e-mail correspondence, data obtained during telephone conversations -
Data related to the use of the Website and cookies:
IP address, online identifiers, device and browser data, data concerning activity on the Website, data collected through cookies and similar technologies (including analytics and security tools) -
Data related to entering into an agreement/placing an order
Identification data (first name, surname, NIP, series and number of identity card), address data (e-mail address, place of residence, postal code), data of representatives of legal entities
Purposes and Legal Bases for Data Processing
Personal data may be processed for the following purposes:
-
Performance of an agreement/order:
- contact related to the performance of the agreement,
-
Compliance with legal obligations incumbent on the Controller:
- issuing and retaining accounting documents,
- performing obligations arising from tax, accounting and archiving regulations.
-
Contact in current matters, responding to enquiries:
- responding to enquiries submitted via the contact form or by e-mail,
- negotiating terms of cooperation, presenting offers upon request.
-
Direct marketing of own products and services:
- sending commercial and marketing information electronically (e-mail) – after obtaining the relevant consents,
- presenting an offer by telephone – after obtaining the relevant consents.
-
Establishment, pursuit or defence of claims:
- pursuing receivables, defending against claims, conducting court or administrative proceedings.
-
Ensuring Website security, preventing abuse:
- maintaining system logs,
- detecting abuse, attempts at unauthorised access, attacks on the Website,
- use of security tools.
Recipients of Data and Transfers to Third Countries
Personal data may be transferred to the following categories of recipients:
- service providers cooperating with Flexhouse sp. z o.o. in the performance of a service/agreement (i.e. subcontractors, suppliers)
- entities operating ICT systems and providing ICT tools,
- entities providing accounting and tax services,
- entities providing advisory services related to legal assistance and audits.
Data may be transferred to third countries (outside the European Economic Area), in particular in connection with the use of certain providers of IT, analytics or security tools established outside the EEA.
In the event of such a transfer, the Controller ensures the application of appropriate safeguards referred to in Articles 45–46 GDPR, in particular:
- European Commission decisions establishing an adequate level of protection, or
- standard contractual clauses approved by the European Commission.
For analysing how the Website is used, the Controller uses Plausible Analytics, provided by Plausible Insights OÜ, based in Estonia. According to information provided by the tool provider, data concerning website use processed within Plausible Analytics are stored and processed in the European Union and are not transferred outside the European Union.
The User may obtain a copy of the safeguards applied or information on where they are made available by contacting the Controller.
Data Retention Period
- Data processed for the purpose of fulfilling legal obligations are retained for the period required by the applicable regulations.
- Data processed on the basis of the Controller’s legitimate interest are retained until an effective objection is made by the data subject or until that interest has been fulfilled (e.g. until the expiry of the limitation period for claims).
- Data processed on the basis of consent are retained until the consent is withdrawn, restricted or the purpose of processing has been achieved (e.g. the end of a given campaign), unless the law requires a longer retention period.
- Cookies, if used on the Website to ensure its proper operation or security, are retained for a period appropriate to their function and no longer than necessary to achieve the purpose for which they were used. Statistical information collected using Plausible Analytics is retained in accordance with the rules and configuration of that service.
Rights of Data Subjects
The data subject has the following rights:
- right of access to data (Article 15 GDPR) – obtaining information about processing and a copy of the data,
- right to rectification of data (Article 16 GDPR) – correcting or completing inaccurate or incomplete data,
- right to erasure of data (Article 17 GDPR) – in cases provided for by the GDPR (“right to be forgotten”),
- right to restriction of processing (Article 18 GDPR),
- right to data portability (Article 20 GDPR) – with regard to data processed on the basis of consent or an agreement and by automated means,
- right to object (Article 21 GDPR) – to processing based on the Controller’s legitimate interest, in particular to processing for direct marketing purposes,
- right to withdraw consent – at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
To exercise the above rights, please contact the Controller. The contact details are provided above.
The data subject also has the right to lodge a complaint with the President of the Personal Data Protection Office if they consider that the processing of data infringes the GDPR. Address of the Personal Data Protection Office: ul. Stanisława Moniuszki 1A, 00-014 Warsaw.
Information on the Requirement to Provide Data
Providing personal data is voluntary, but in some cases it is necessary to provide specific services (e.g. responding to an enquiry).
Failure to provide the required data may make it impossible to respond to an enquiry.
Source of Data
As a rule, the Controller obtains personal data directly from the data subjects, in particular in connection with:
- sending an enquiry or completing a contact form,
In the case of data of representatives and employees of contractors, data may be provided to the Controller by their employers or obtained from other sources.
In such a case, the Controller provides the data subjects with the information required under Article 14 GDPR within the time limits specified therein, unless statutory exceptions apply.
Cookies and Similar Technologies
The Website may use cookies necessary to ensure its proper operation, security and the proper provision of services available through the Website.
Cookies are small pieces of information stored on the User’s terminal device in connection with use of the Website. The User may manage cookie settings through their web browser settings. Restricting the use of necessary cookies may affect the proper operation of certain Website functions.
For the purpose of collecting aggregate statistics and analysing how the Website is used, the Controller uses Plausible Analytics, provided by Plausible Insights OÜ, based in Estonia.
Plausible Analytics is an analytics tool designed with user privacy in mind. In the standard configuration used by the Controller, the tool does not use cookies or other persistent identifiers to track Users across different websites or devices.
Plausible Analytics enables the Controller to obtain aggregate statistical information concerning use of the Website, such as, in particular, the number of visits and page views, pages visited, sources of traffic to the Website, basic information about the type of browser and device, approximate location determined at a general level, time spent using the Website, occurrence of page errors and activities such as downloading files.
Information collected using Plausible Analytics is used exclusively to create statistics, assess how the Website is used and improve it. The Controller does not use Plausible Analytics for User profiling, behavioural advertising or tracking Users across different websites or devices.
According to information provided by the Plausible Analytics provider, the tool does not collect or store data allowing the direct identification of individual persons visiting the Website, does not use cookies for analytics purposes and does not create persistent User profiles.
More information on how Plausible Analytics works and the privacy protection principles applied by the provider is available in the data protection documentation published on the Plausible Analytics website (https://plausible.io/data-policy).
The Controller currently does not use analytical or marketing cookies on the Website that require the User’s prior consent.
Data Security
The Controller applies appropriate technical and organisational measures ensuring a level of data security appropriate to the risk, in accordance with Article 32 GDPR.
In particular, the Controller:
- uses cryptographic measures (e.g. HTTPS protocol) to ensure the confidentiality of transmission,
- restricts access to data to authorised persons trained in data protection,
- uses solutions protecting the Website against unauthorised access (e.g. authentication systems, intrusion-prevention tools).
The Controller continuously monitors the security measures applied and adapts them to the current state of technical knowledge and the level of threats.
Changes to the Privacy Policy
This Policy may be updated periodically, in particular in the event of:
- changes in data protection legislation,
- changes in data processing processes, tools used or Website functionalities.
The Controller will inform about material changes to the Policy by means of a notice on the Website.
The amended Policy shall apply from the date indicated in its updated version.
Date of last update: 21.09.2026.