Legal information
Privacy policy
Last updated: 2026-05-02
1. Data controller
The controller of your personal data is Semafi, an engineering studio based in Białystok, Poland.
Contact: hello@semafi.pl · +48 530 525 958
2. Data we process
We process the following categories of personal data:
- Contact data — name, email, phone, company name (if provided in the form)
- Communication content — project descriptions, email correspondence
- Technical data — IP address, browser type, operating system (server logs)
- Cookies — details below
3. Purposes and legal grounds
- Responding to inquiries — Art. 6(1)(b) GDPR (steps prior to entering a contract)
- Performance of service contract — Art. 6(1)(b) GDPR
- Marketing of our services — Art. 6(1)(f) GDPR (legitimate interest)
- Newsletter — Art. 6(1)(a) GDPR (consent)
- Accounting / tax obligations — Art. 6(1)(c) GDPR
4. Retention period
- Contact form data — up to 24 months from last contact
- Client data — for the contract duration + 6 years (claim limitation period)
- Accounting data — 5 years (tax obligations)
- Newsletter — until you unsubscribe (one click)
5. Recipients
Your data may be shared with:
- Hosting and server providers (entrusted processing)
- Email and form service providers (Web3Forms, Resend, Cloudflare)
- Accounting office (when invoicing)
- Public authorities if required by law
6. Your rights
You have the right to:
- Access your data
- Rectify, erase, or restrict processing
- Data portability to another controller
- Object to processing
- Withdraw consent at any time (without affecting the lawfulness of processing before withdrawal)
- Lodge a complaint with the Polish DPA (uodo.gov.pl)
To exercise any of these rights, write to hello@semafi.pl.
7. Cookies
The site uses the following cookie types:
- Essential — required for the site to function (session, language preference)
- Analytics — help us understand how you use the site (if consent given)
You can manage cookies through browser settings. Disabling cookies may affect some features.
8. Security
We apply technical and organizational data protection measures:
- HTTPS / TLS encryption across the entire site
- Encrypted storage of passwords and API tokens
- Regular backups with encryption at rest
- Restricted data access (authorized personnel only)
- Monitoring and audit logs
9. Policy changes
We reserve the right to update this policy. Significant changes will be announced on the homepage and via email (if subscribed to the newsletter).
10. Contact
Privacy-related questions: hello@semafi.pl.