WĄSIKLEGAL

Privacy policy

This website is designed to minimise data processing. It does not use advertising analytics, tracking pixels or user profiling.

This policy explains what data may be processed when you use the website or contact WĄSIK LEGAL, for what purposes, and what rights are available to data subjects.
Last updated: 7 September 2026

1. Controller

The controller is Marcin Wąsik, operating the law office Kancelaria Radcy Prawnego Marcina Wąsika under the WĄSIK LEGAL brand, Kraków, Poland, tax ID PL6772336157.

Privacy contact: m.wasik@wasiklegal.pl.

2. Data and purposes

Enquiries and correspondence: when you use the contact form or contact us by email, your name, email address, organisation details, selected enquiry type, message and subsequent correspondence may be processed to respond, assess a potential engagement, manage a business relationship and, where relevant, establish, pursue or defend legal claims.

Technical data: the hosting provider and form provider may automatically process IP address, request date and time, browser and operating-system type, requested resource and diagnostic data to keep the services secure, available and functional.

Website settings: your language and theme choices are stored locally in your browser. The website does not receive them as separate analytics data.

3. Legal bases

Enquiry data is processed to take steps at your request before entering into a contract or to perform a contract (Article 6(1)(b) GDPR), and otherwise on the controller’s legitimate interests (Article 6(1)(f) GDPR), including business communication, protection of legal rights and website security.

Where processing is required by law, it is based on Article 6(1)(c) GDPR.

4. Recipients and transfers

Messages submitted through the form are transmitted via Formspree, Inc., which provides form submission and email delivery services. Data may also be entrusted to hosting, email, IT support and other providers necessary to handle communications. It may be disclosed to professional advisers or authorised authorities where required by law.

Formspree may process data in the United States. If a provider processes data outside the European Economic Area, the transfer relies on a GDPR mechanism, in particular an adequacy decision or Standard Contractual Clauses together with required safeguards.

5. Retention

Enquiry correspondence is retained for as long as needed to handle it and then for a period justified by the relationship, limitation periods and legal duties. Security logs are retained for the period set by the hosting provider, no longer than necessary for security and diagnostics.

6. Your rights

You may request access, rectification, erasure or restriction and, where legally applicable, data portability.

You may object, on grounds relating to your particular situation, to processing based on legitimate interests.

You may lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland; uodo.gov.pl) or with the competent supervisory authority in your country.

7. Voluntary data and automation

Providing data in correspondence is voluntary, but without contact information a reply may not be possible. Data is not used for automated decision-making or profiling.

8. Cookies and external services

The website does not use advertising or analytics cookies. The contact form uses Formspree; submitting it transfers the information entered to that provider under its privacy policy available at formspree.io/legal/privacy-policy. The LinkedIn link opens an external service that processes data under its own privacy policy.

Appointments are booked on the external Cal.com website operated by Cal.com, Inc., 2261 Market Street #4382, San Francisco, CA 94114, USA. Merely viewing wasiklegal.pl does not connect to Cal.com or allow it to store cookies; the connection is made only after you select the button leading to the calendar. For a booking, Cal.com processes on the controller’s behalf the information needed to schedule the meeting, in particular your name, email address, selected time and time zone, information entered in any additional fields, and technical data such as your IP address and browser and device information. The controller processes this data to take steps at your request before entering into a contract or to perform a contract (Article 6(1)(b) GDPR), and, for security and abuse prevention, on the basis of legitimate interests (Article 6(1)(f) GDPR). Cal.com acts as a processor for booking data and may act as a separate controller for data it processes for its own purposes. Data may be processed in the United States under the transfer mechanisms identified by the provider, in particular Standard Contractual Clauses or an adequacy decision. After the Cal.com website is opened, the provider may use cookies or local storage needed to operate the service, remember preferences and maintain security. Cal.com states that the booking product does not use third-party advertising cookies. Further information is available at cal.com/privacy.

9. Security and updates

Appropriate organisational and technical safeguards are applied. This policy may be updated if the technology, operation of the website or applicable law changes; the current version is always published here.