Privacy Policy

Last updated: January 15, 2026

This Privacy Policy describes how EVRG sp. z o.o. ("we", "us", or "our") collects, uses, and protects your personal data when you use our website and services. We are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and applicable Polish data protection laws.

1. Data Controller

The data controller responsible for your personal data is:

EVRG sp. z o.o.

Skwierzynska 2

04-853 Warszawa

Poland

VAT EU: PL9522279307

Email: info@evrg.ai

As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring that such processing complies with applicable data protection legislation.

2. Data We Collect

We collect and process the following categories of personal data:

2.1 Information You Provide Directly

  • Contact Form Data: Name, email address, company name, phone number (if provided), and message content when you submit inquiries through our contact forms.
  • Newsletter Subscriptions: Email address and communication preferences when you subscribe to our newsletters.
  • Business Communications: Any information you provide when communicating with us via email or other channels.

2.2 Information Collected Automatically

  • Device Information: Browser type and version, operating system, device type, and screen resolution.
  • Usage Data: Pages visited, time spent on pages, click patterns, and navigation paths through our website.
  • Network Information: IP address (anonymized where possible), approximate geographic location (country/region level).
  • Referral Data: Information about how you arrived at our website (referral source, search terms used).

2.3 Cookies and Similar Technologies

We use cookies and similar tracking technologies to collect information about your browsing activities. For detailed information about our use of cookies, please refer to the Cookies Policy section below.

3. How We Use Your Data

We process your personal data for the following purposes:

3.1 Service Delivery

  • Responding to your inquiries and providing customer support
  • Processing and fulfilling service requests
  • Communicating with you about our products and services
  • Providing access to our website and its features

3.2 Business Operations

  • Managing our business relationships and contracts
  • Conducting market research and analysis
  • Developing and improving our products and services
  • Maintaining records required by law

3.3 Marketing and Communications

  • Sending newsletters and marketing communications (with your consent)
  • Providing information about new products, services, and updates
  • Personalizing your experience on our website

3.4 Security and Compliance

  • Protecting our website, systems, and users from security threats
  • Detecting and preventing fraud and abuse
  • Complying with legal obligations and regulatory requirements
  • Enforcing our terms of service and other policies

3.5 Analytics and Improvement

  • Analyzing website traffic and usage patterns
  • Understanding user preferences and behavior
  • Improving website performance and user experience
  • Generating aggregate statistical reports

5. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are:

Data CategoryRetention Period
Contact form submissions3 years from submission or until request deleted
Newsletter subscriptionsUntil unsubscribe or consent withdrawal
Business communicationsDuration of business relationship + 5 years
Contract and transaction records10 years (statutory requirement in Poland)
Website analytics data26 months (anonymized/aggregated thereafter)
Cookie dataVaries by cookie type (see Cookies Policy)
Server logs90 days

After the retention period expires, we securely delete or anonymize your personal data. In some cases, we may retain data for longer periods if required by law or if there is an ongoing legal claim or investigation.

6. Your Rights Under GDPR

As a data subject, you have the following rights under the GDPR. You may exercise these rights by contacting us at info@evrg.ai.

6.1 Right of Access (Article 15)

You have the right to obtain confirmation as to whether we process your personal data and, if so, to request access to that data along with information about how it is processed. You may request a copy of your personal data free of charge.

6.2 Right to Rectification (Article 16)

You have the right to request correction of inaccurate personal data and to have incomplete data completed. We will rectify any inaccuracies without undue delay.

6.3 Right to Erasure (Article 17)

You have the right to request deletion of your personal data ("right to be forgotten") in certain circumstances, including when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw your consent (where consent was the legal basis)
  • You object to the processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

6.4 Right to Restriction of Processing (Article 18)

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or when processing is unlawful but you oppose erasure.

6.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller, where processing is based on consent or contract and carried out by automated means.

6.6 Right to Object (Article 21)

You have the right to object to processing based on legitimate interests, including profiling. You also have the absolute right to object to direct marketing at any time.

6.7 Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produce legal or similarly significant effects. We do not currently engage in such automated decision-making.

6.8 Right to Lodge a Complaint

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. In Poland, the competent authority is:

Prezes Urzedu Ochrony Danych Osobowych (PUODO)

ul. Stawki 2

00-193 Warszawa

Poland

https://uodo.gov.pl

Response Time: We will respond to your request within one month. This period may be extended by two further months if necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receipt of your request.

7. Cookies Policy

Our website uses cookies and similar technologies to provide functionality, analyze traffic, and personalize your experience.

7.1 What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They help websites remember your preferences and understand how you use the site.

7.2 Types of Cookies We Use

Strictly Necessary Cookies

Essential for website functionality. These cookies enable core features such as security, network management, and accessibility. You cannot opt out of these cookies as the website cannot function properly without them.

Duration: Session or up to 1 year

Analytics Cookies

Help us understand how visitors interact with our website by collecting and reporting information anonymously. We use this data to improve our website and services.

Duration: Up to 26 months

Functional Cookies

Enable enhanced functionality and personalization, such as remembering your preferences, language settings, or region.

Duration: Up to 1 year

Marketing Cookies

Used to track visitors across websites to display relevant advertisements. These cookies may be set by our advertising partners to build a profile of your interests.

Duration: Up to 2 years

7.3 Managing Cookies

You can control and manage cookies in several ways:

  • Cookie Consent Banner: When you first visit our website, you can choose which cookie categories to accept.
  • Browser Settings: Most browsers allow you to refuse cookies or delete specific cookies. Note that disabling cookies may affect website functionality.
  • Opt-Out Tools: You can opt out of analytics tracking using tools like Google Analytics Opt-out Browser Add-on.

7.4 Third-Party Cookies

Some cookies on our website are set by third-party services. We do not control these cookies and recommend reviewing the privacy policies of these third parties for more information about their use of cookies.

8. Third-Party Services

We use the following third-party services that may process your personal data:

8.1 Analytics Services

Google Analytics

We use Google Analytics to analyze website traffic and user behavior. Google Analytics uses cookies to collect information about your use of our website, which is transmitted to and stored by Google.

Privacy Policy: https://policies.google.com/privacy

8.2 Hosting Services

Vercel

Our website is hosted on Vercel, which processes server logs and may collect certain technical data necessary for website delivery.

Privacy Policy: https://vercel.com/legal/privacy-policy

8.3 Communication Services

When you contact us via email, your communication may be processed by our email service providers. We use enterprise-grade email services that comply with GDPR requirements.

8.4 Data Processing Agreements

We have Data Processing Agreements (DPAs) in place with all third-party service providers that process personal data on our behalf. These agreements ensure that our processors implement appropriate technical and organizational measures to protect your data.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

9.1 Technical Measures

  • Encryption: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security) protocol.
  • Secure Infrastructure: Our hosting infrastructure is protected by firewalls, intrusion detection systems, and regular security updates.
  • Access Controls: Access to personal data is restricted to authorized personnel on a need-to-know basis.
  • Regular Backups: We maintain secure backups to ensure data availability and recovery capabilities.

9.2 Organizational Measures

  • Staff Training: Our team members receive training on data protection and security best practices.
  • Security Policies: We maintain and enforce internal security policies and procedures.
  • Vendor Assessment: We assess the security practices of our third-party service providers.
  • Incident Response: We have procedures in place to detect, report, and respond to data breaches.

9.3 Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.

10. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place:

10.1 Adequacy Decisions

We may transfer data to countries that the European Commission has determined provide an adequate level of data protection (adequacy decisions).

10.2 Standard Contractual Clauses

For transfers to countries without an adequacy decision, we use Standard Contractual Clauses (SCCs) approved by the European Commission to ensure your data is protected according to GDPR standards.

10.3 Supplementary Measures

Where necessary, we implement supplementary technical, organizational, or contractual measures to ensure an essentially equivalent level of protection for transferred data.

11. Contact Information

For any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us:

Data Protection Contact

Company: EVRG sp. z o.o.

Address: Skwierzynska 2, 04-853 Warszawa, Poland

Email: info@evrg.ai

When contacting us about data protection matters, please include sufficient information to identify yourself and describe your request or concern clearly. We may need to verify your identity before processing your request.

12. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.

12.1 Notification of Changes

When we make material changes to this Privacy Policy, we will:

  • Update the "Last updated" date at the top of this policy
  • Post the updated policy on our website
  • Notify you by email or through a prominent notice on our website for significant changes

12.2 Review of Policy

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data. Your continued use of our website after any changes constitutes acceptance of the updated policy.

12.3 Previous Versions

Upon request, we can provide you with previous versions of this Privacy Policy for your reference.

This Privacy Policy is effective as of January 15, 2026. If you have any questions about this policy or our data practices, please do not hesitate to contact us at info@evrg.ai.