01. Who we are
The data controller for this website, related software platforms, client engagements, and commercial agreements is:
Xentavi Spółka z ograniczoną odpowiedzialnością
02. What data we collect and why
We adhere to the principle of data minimization (Article 5(1)(c) GDPR). We process only the personal data strictly necessary to evaluate inquiries, deliver senior client partnerships, and ensure platform security.
| Processing Purpose | Data Categories Collected | Legal Basis (GDPR / RODO) |
|---|---|---|
| Respond to inquiries & project discovery | Name, business email address, company name, project brief, inquiry message content | Art. 6(1)(b) GDPR Steps prior to entering into a contract |
| Client delivery & software retainers | Name, business email, job title, corporate billing details, campaign datasets shared under NDA | Art. 6(1)(b) GDPR Performance of a commercial contract |
| Website analytics & performance telemetry | Anonymized IP address, pages visited, session duration, device type, user agent | Art. 6(1)(f) GDPR Legitimate interest in maintaining site stability and speed |
| Direct correspondence & executive briefings | Professional email address, communication history | Art. 6(1)(a) GDPR Explicit consent; Art. 10 UŚUDE (Polish Electronic Services Act) |
| Platform security & attack prevention | Server access logs, timestamp, IP address, request method | Art. 6(1)(f) GDPR Legitimate interest in protecting infrastructure integrity |
| Accounting, statutory & tax compliance | Tax identifiers, invoice records, payment history, contractual documentation | Art. 6(1)(c) GDPR Compliance with Polish tax and accounting obligations |
No Special-Category Data: We do not collect or process sensitive or special categories of personal data (such as health status, genetic or biometric identifiers, political opinions, or religious beliefs) under Article 9 GDPR.
03. Cookies and tracking
We deploy a minimal, transparent cookie architecture that prioritizes user privacy over aggressive tracking:
You have the absolute right to modify or revoke cookie preferences at any time through your browser settings or by clearing stored browser session cookies.
04. Who we share your data with
We never sell, rent, or monetize your personal data. We disclose data exclusively to trusted, contractually bound data processors (sub-processors) under Art. 28 GDPR data processing agreements (DPAs):
Sub-Processors & Infrastructure Providers:
| Entity Role | Provider | Processing Purpose | Hosting Location | Safeguards |
|---|---|---|---|---|
| Cloud Infrastructure | Hetzner Online GmbH | Dedicated server hosting, container orchestration & database | European Union (Germany / Finland) | Direct EU jurisdiction · ISO 27001 |
| Corporate Workspace | Google Ireland Limited | Corporate email, calendar & encrypted document storage | European Union (Ireland) | EU Standard Contractual Clauses (SCCs) · DPA |
| Developer Platform | GitHub Inc. (Microsoft) | Code repositories & CI/CD deployment pipelines | United States / EU | EU-US Data Privacy Framework · SCCs |
| Error Telemetry | Sentry (Functional Software) | Crash diagnostics & application performance monitoring | United States / EU | EU-US Data Privacy Framework · IP masking |
Statutory Disclosure: We may disclose personal data to law enforcement, tax authorities, or regulatory bodies only when strictly required by mandatory Polish or European Union legal provisions.
05. Data retention schedule
We retain personal data only for as long as necessary to fulfill the specific purposes for which it was gathered, in compliance with statutory retention requirements:
| Data Category | Retention Period | Legal Justification |
|---|---|---|
| General Inquiries & Scoping RFPs | 12 months from last communication | Allows follow-up on project scope and commercial evaluations. |
| Client Contracts & Billing Data | 5 years from fiscal year end | Mandatory requirement under Polish Tax Code & Accounting Act. |
| Server Logs & Security Records | 90 days on a rolling basis | Infrastructure threat detection, debugging, and DDoS defense. |
| Analytics & Telemetry Aggregates | 14 months in anonymized form | Year-over-year performance evaluation without identifying individuals. |
Upon expiration of the retention window, data is securely erased or irreversibly anonymized using automated cryptographic standards.
06. Your rights under GDPR
Under Chapter III of the GDPR and the Polish Personal Data Protection Act, you possess comprehensive legal rights regarding your personal information:
- Right of Access (Art. 15 GDPR): Obtain confirmation of processing and request a copy of all personal data held about you.
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal records.
- Right to Erasure / 'To Be Forgotten' (Art. 17 GDPR): Request permanent deletion of your data where legal grounds for processing no longer exist.
- Right to Restriction of Processing (Art. 18 GDPR): Restrict data processing while accuracy disputes or legal objections are evaluated.
- Right to Data Portability (Art. 20 GDPR): Receive your structured personal data in a commonly used, machine-readable format (JSON/CSV).
- Right to Object (Art. 21 GDPR): Object to processing conducted under legitimate interest grounds at any time.
Exercising Your Rights: To exercise any right, submit an email to hm@xentavi.com with the subject 'GDPR Data Subject Request'. We verify identity to protect data confidentiality and respond without undue delay, and at latest within 30 calendar days.
07. Data security and infrastructure safeguards
We implement state-of-the-art technical and organizational measures (Article 32 GDPR) engineered to protect data integrity, confidentiality, and resilience:
- End-to-End Encryption: All web traffic is encrypted in transit using TLS 1.3 with strict HSTS preloading. Databases and backups are encrypted at rest using AES-256.
- Isolated Infrastructure: Dedicated European servers with automated firewall rules, SSH key-only access, and container isolation with zero root privilege execution.
- Air-Gapped Client Vaults: Proprietary software tools run within private execution namespaces. Client datasets and prompts are never fed into public LLM training datasets.
- Strict Least-Privilege Access: Role-based access control (RBAC), multi-factor authentication (MFA) enforced on all admin endpoints, and continuous audit logging.
Incident Protocol: In the unlikely event of a personal data breach, we adhere to Article 33 GDPR protocols, notifying the supervisory authority (UODO) within 72 hours and affected individuals without undue delay where high risk exists.
08. Policy revisions and updates
We reserve the right to revise this Privacy Policy to reflect technical infrastructure evolutions, new proprietary software capabilities, or amendments in statutory data protection regulations.
Current Version: March 2026. Effective Immediately.
09. Direct contact and inquiries
If you have inquiries regarding this Privacy Policy, our data processing protocols, or wish to exercise statutory GDPR rights, contact our privacy officer directly: