Privacy Policy
Last updated: January 15, 2026
This Privacy Policy describes how EVRG sp. z o.o. ("we", "us", or "our") collects, uses, and protects your personal data when you use our website and services. We are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and applicable Polish data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring that such processing complies with applicable data protection legislation.
2. Data We Collect
We collect and process the following categories of personal data:
2.1 Information You Provide Directly
- Contact Form Data: Name, email address, company name, phone number (if provided), and message content when you submit inquiries through our contact forms.
- Newsletter Subscriptions: Email address and communication preferences when you subscribe to our newsletters.
- Business Communications: Any information you provide when communicating with us via email or other channels.
2.2 Information Collected Automatically
- Device Information: Browser type and version, operating system, device type, and screen resolution.
- Usage Data: Pages visited, time spent on pages, click patterns, and navigation paths through our website.
- Network Information: IP address (anonymized where possible), approximate geographic location (country/region level).
- Referral Data: Information about how you arrived at our website (referral source, search terms used).
2.3 Cookies and Similar Technologies
We use cookies and similar tracking technologies to collect information about your browsing activities. For detailed information about our use of cookies, please refer to the Cookies Policy section below.
3. How We Use Your Data
We process your personal data for the following purposes:
3.1 Service Delivery
- Responding to your inquiries and providing customer support
- Processing and fulfilling service requests
- Communicating with you about our products and services
- Providing access to our website and its features
3.2 Business Operations
- Managing our business relationships and contracts
- Conducting market research and analysis
- Developing and improving our products and services
- Maintaining records required by law
3.3 Marketing and Communications
- Sending newsletters and marketing communications (with your consent)
- Providing information about new products, services, and updates
- Personalizing your experience on our website
3.4 Security and Compliance
- Protecting our website, systems, and users from security threats
- Detecting and preventing fraud and abuse
- Complying with legal obligations and regulatory requirements
- Enforcing our terms of service and other policies
3.5 Analytics and Improvement
- Analyzing website traffic and usage patterns
- Understanding user preferences and behavior
- Improving website performance and user experience
- Generating aggregate statistical reports
4. Legal Basis for Processing
Under the GDPR, we must have a valid legal basis for processing your personal data. We rely on the following legal bases:
4.1 Consent (Article 6(1)(a) GDPR)
We process your data based on your consent for:
- Sending marketing communications and newsletters
- Setting non-essential cookies (analytics, marketing)
- Processing special categories of data (if applicable)
You have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
4.2 Contract Performance (Article 6(1)(b) GDPR)
We process your data when necessary to perform a contract with you or to take steps at your request prior to entering into a contract, including:
- Processing your service inquiries and requests
- Providing our services and products to you
- Managing our business relationship with you
4.3 Legitimate Interests (Article 6(1)(f) GDPR)
We process your data based on our legitimate interests, where those interests are not overridden by your rights and interests. This includes:
- Operating and improving our website and services
- Analyzing website usage and performance
- Ensuring network and information security
- Preventing fraud and protecting our legal rights
- Direct marketing to existing customers (soft opt-in)
4.4 Legal Obligations (Article 6(1)(c) GDPR)
We process your data when necessary to comply with legal obligations, such as:
- Tax and accounting requirements
- Responding to lawful requests from public authorities
- Regulatory compliance and reporting obligations
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are:
| Data Category | Retention Period |
|---|---|
| Contact form submissions | 3 years from submission or until request deleted |
| Newsletter subscriptions | Until unsubscribe or consent withdrawal |
| Business communications | Duration of business relationship + 5 years |
| Contract and transaction records | 10 years (statutory requirement in Poland) |
| Website analytics data | 26 months (anonymized/aggregated thereafter) |
| Cookie data | Varies by cookie type (see Cookies Policy) |
| Server logs | 90 days |
After the retention period expires, we securely delete or anonymize your personal data. In some cases, we may retain data for longer periods if required by law or if there is an ongoing legal claim or investigation.
6. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR. You may exercise these rights by contacting us at info@evrg.ai.
6.1 Right of Access (Article 15)
You have the right to obtain confirmation as to whether we process your personal data and, if so, to request access to that data along with information about how it is processed. You may request a copy of your personal data free of charge.
6.2 Right to Rectification (Article 16)
You have the right to request correction of inaccurate personal data and to have incomplete data completed. We will rectify any inaccuracies without undue delay.
6.3 Right to Erasure (Article 17)
You have the right to request deletion of your personal data ("right to be forgotten") in certain circumstances, including when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw your consent (where consent was the legal basis)
- You object to the processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
6.4 Right to Restriction of Processing (Article 18)
You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or when processing is unlawful but you oppose erasure.
6.5 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller, where processing is based on consent or contract and carried out by automated means.
6.6 Right to Object (Article 21)
You have the right to object to processing based on legitimate interests, including profiling. You also have the absolute right to object to direct marketing at any time.
6.7 Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects. We do not currently engage in such automated decision-making.
6.8 Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. In Poland, the competent authority is:
Response Time: We will respond to your request within one month. This period may be extended by two further months if necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of your request.
8. Third-Party Services
We use the following third-party services that may process your personal data:
8.1 Analytics Services
Google Analytics
We use Google Analytics to analyze website traffic and user behavior. Google Analytics uses cookies to collect information about your use of our website, which is transmitted to and stored by Google.
Privacy Policy: https://policies.google.com/privacy
8.2 Hosting Services
Vercel
Our website is hosted on Vercel, which processes server logs and may collect certain technical data necessary for website delivery.
Privacy Policy: https://vercel.com/legal/privacy-policy
8.3 Communication Services
When you contact us via email, your communication may be processed by our email service providers. We use enterprise-grade email services that comply with GDPR requirements.
8.4 Data Processing Agreements
We have Data Processing Agreements (DPAs) in place with all third-party service providers that process personal data on our behalf. These agreements ensure that our processors implement appropriate technical and organizational measures to protect your data.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
9.1 Technical Measures
- Encryption: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security) protocol.
- Secure Infrastructure: Our hosting infrastructure is protected by firewalls, intrusion detection systems, and regular security updates.
- Access Controls: Access to personal data is restricted to authorized personnel on a need-to-know basis.
- Regular Backups: We maintain secure backups to ensure data availability and recovery capabilities.
9.2 Organizational Measures
- Staff Training: Our team members receive training on data protection and security best practices.
- Security Policies: We maintain and enforce internal security policies and procedures.
- Vendor Assessment: We assess the security practices of our third-party service providers.
- Incident Response: We have procedures in place to detect, report, and respond to data breaches.
9.3 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
10. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place:
10.1 Adequacy Decisions
We may transfer data to countries that the European Commission has determined provide an adequate level of data protection (adequacy decisions).
10.2 Standard Contractual Clauses
For transfers to countries without an adequacy decision, we use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure your data is protected according to GDPR standards.
10.3 Supplementary Measures
Where necessary, we implement supplementary technical, organizational, or contractual measures to ensure an essentially equivalent level of protection for transferred data.
11. Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us:
Data Protection Contact
Company: EVRG sp. z o.o.
Address: Skwierzynska 2, 04-853 Warszawa, Poland
Email: info@evrg.ai
When contacting us about data protection matters, please include sufficient information to identify yourself and describe your request or concern clearly. We may need to verify your identity before processing your request.
12. Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
12.1 Notification of Changes
When we make material changes to this Privacy Policy, we will:
- Update the "Last updated" date at the top of this policy
- Post the updated policy on our website
- Notify you by email or through a prominent notice on our website for significant changes
12.2 Review of Policy
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website after any changes constitutes acceptance of the updated policy.
12.3 Previous Versions
Upon request, we can provide you with previous versions of this Privacy Policy for your reference.
This Privacy Policy is effective as of January 15, 2026. If you have any questions about this policy or our data practices, please do not hesitate to contact us at info@evrg.ai.