Privacy Policy
Notice on processing in Reports, editorial Q&A and the Waitlist. Cookie and active-recipient sections form part of this Policy. This Policy is not a consent statement and is not part of the Terms acceptance checkbox.
1. Controller and contact
The data controller is Leksio sp. z o.o., with its registered office in Warsaw at ul. Żurawia 6/12 lok. 745, 00-503 Warszawa, Poland, entered in the Polish commercial register by the District Court for the Capital City of Warsaw in Warsaw, XII Commercial Division of the National Court Register, under KRS 0001264046, tax ID (NIP) 7011330213, REGON 545666406, share capital PLN 10,000. Personal-data enquiries may be sent to [email protected] or the registered-office address.
The Controller has not appointed a data protection officer. Messages are handled by a person authorised for privacy matters.
This Policy is version 1.0 and applies from 2026-09-18. The Polish version is binding.
2. Scope, principles and sources
This Policy covers public Reports and editorial Q&A, the Waitlist, notifications, security and support, as well as accounts created before version 1.0 took effect. It does not cover other planned features that are not publicly active.
Data comes directly from the person, their device and technical logs. The Controller applies minimisation, purpose limitation, accuracy and storage limitation. Data marked as required is needed for the selected function or agreement; failure to provide it prevents that function but does not affect browsing public materials that do not require it.
3. Processes, data, purposes and legal bases
The table states the people and process, data and source, purpose and Article 6(1) GDPR basis, whether provision is required, and retention.
| People and process | Data and source | Purpose and basis | Required? | Retention |
|---|---|---|---|---|
| Visitors - public content | Requested URL, IP, headers, time, security events and selected language/theme; from the device and logs. | Website delivery, protection and diagnostics; Article 6(1)(f), or (b) where needed for the requested service. | Transmission data is required; language and theme are voluntary. | Security logs up to 12 months; preferences until changed or cleared. |
| Waitlist | Email, role, language, address confirmation, Terms acceptance, voluntarily profession, city and case topic and - only after analytics consent - broad source and UTM, referrer domain and signup-page context; from the person, entry address and device. | Accept the entry, confirm the address and announce launch; point (b), duty evidence - (c), claims - (f); signup-source measurement after consent - (a). | Email and role are required; other fields and source data are voluntary, and source data is neither stored nor sent without analytics consent. | Unconfirmed entry 30 days; confirmed entry until the launch notification or leaving the list plus 3 years; minimal agreement evidence 6 years. |
| Notifications about new Reports | Email, notification choice, consent/withdrawal time and delivery status; from the person and system. | Send information about new Reports; point (a). | Voluntary. | Until consent is withdrawn; unnecessary identifiers within 30 days; minimal claims evidence no more than 6 years. |
| Accounts created before version 1.0 | Email, identifier, role, language, settings, Terms acceptance and data previously entered in the profile; from the person and the authentication system. | Keep the account until it is deleted or covered by new documents and handle the holder’s requests; point (b), duty evidence - (c), claims - (f). | No new data is collected; the account can be deleted on request. | Until account deletion plus 3 years; minimal agreement evidence 6 years. |
| Support and complaints | Contact, category, description, correspondence and necessary technical data; from the reporter and system. | Response, contract, duties and claims; point (b), (c) or (f), depending on the matter. | Needed to handle the request. | Full content through closure plus 3 years; technical email outbox up to 90 days. |
| Security | IP, headers, session/device identifiers, time, form-protection result and sign-in events; from the device, protection provider and logs. | Confidentiality, integrity, availability, attack detection and claims; point (f), or (c) for security duties. | Technically required. | Generally up to 12 months. |
| First-party measurement after consent | Random pseudonym, event type, general page context, performance and time; from the device, without form content, email or full URL. | Statistical service improvement; point (a). | Voluntary. | Raw events 1 day; irreversible aggregates 25 months. |
| Google Analytics after consent | Identifiers from the _ga and _ga_* cookies, IP address (Google Analytics 4 does not store it in reports), approximate location, device and browser type, pages visited and entry source; from the device. | Visit statistics and service improvement; Article 6(1)(a). Google signals and ad personalisation are disabled. | Voluntary. | Cookies 13 months or until consent is withdrawn; event data in Google Analytics 14 months. |
| Meta Pixel after marketing consent | Identifier from the _fbp cookie, IP address, browser and device information, pages visited and events (such as a page view); from the device. Meta may link them to an account in its services. | Measure the effectiveness of Leksio ads and show them to people who visited the website; Article 6(1)(a). | Voluntary and independent of analytics consent. | _fbp cookie 90 days or until consent is withdrawn; data held by Meta under its privacy policy. |
| Cookie decisions | Browser pseudonym, categories, notice/Policy version, hash, method and decision time; from the device. | Apply and demonstrate the choice; point (a) for measurement and (c)/(f) for evidence. | The optional-purpose choice is voluntary. | Setting 12 months; server evidence 5 years. |
4. Individual rights
Subject to GDPR, a person has rights of access/copy, rectification, erasure, restriction, portability of data supplied under consent/contract, objection to legitimate-interest processing, and withdrawal at any time without affecting prior lawfulness.
Send requests to [email protected]. The Controller asks only for identity-confirming information and normally responds within one month; for a complex request it may lawfully extend and explain.
Complaints may be lodged with the President of the Polish Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, uodo.gov.pl. Other remedies remain available.
5. Deletion, evidence and backups
After the period, full data is deleted or irreversibly aggregated. When an agreement ends, Leksio separates minimal evidence: Terms version/hash, language, context/time and claim events. It may remain for 6 years and is not used for further contact.
One-time session markers expire with the session or earlier after use. Leaving the Waitlist or withdrawing consent to Report notifications stops further sending.
Longer storage occurs only for a documented duty or legal hold concerning a specific claim/proceeding. Data removed from the active system disappears from backups under the confirmed provider cycle and is not restored to ordinary use meanwhile.
6. Security, transfers and automation
Leksio uses role-based access, encryption in transit, event logs, environment separation, backups, minimisation, and incident/deletion procedures. No safeguard eliminates all risk, so Users should protect devices and credentials.
A provider may process outside the EEA only after a GDPR Chapter V basis is confirmed, especially adequacy or standard contractual clauses with assessment and supplementary measures. The Recipient Register gives details.
The current pre-launch service makes no solely automated decision producing legal or similarly significant effects. A technical security rule may stop a request, but the issue can be reported to a human in support.
8. Active technology table
The table lists cookies and similar browser technologies (localStorage, sessionStorage) used on the Leksio site. The case form and Google One Tap are disabled during pre-launch, so they are not listed.
| Name | Provider | Purpose | Category | When it runs | Lifetime |
|---|---|---|---|---|---|
| Leksio settings, sign-in and statistics | Leksio | Sign-in to previously created accounts, remembering language, theme and your cookie decision, completing a waitlist signup, protection against page-loading errors and - after consent - Leksio’s own site statistics and entry source when joining the list, without form content or email. | Essential; statistics - analytics | Using the site; statistics only after analytics consent. | From a few minutes to 12 months; cookie decision evidence 5 years; raw statistics 1 day, aggregated 25 months. |
| Google Analytics | Google Ireland Limited | Visit statistics: how many people visit the site and which pages they use. | Analytics | Only after analytics consent. | Cookies up to 13 months. |
| Meta Pixel | Meta Platforms Ireland Limited | Measuring how well Leksio ads on Facebook and Instagram work and showing them to people who visited the site. | Marketing | Only after marketing consent. | Cookie up to 90 days. |
| Sign-in with Google | Signing in with a Google account when you choose that method. Google does not set cookies on the Leksio domain. | Essential | Clicking the Google sign-in button. | Not applicable. | |
| Site protection | Cloudflare | Delivering the site securely and checking that a form is sent by a person. | Essential | Visiting the site or sending a form. | Usually up to 30 minutes, at most one year; logs up to 12 months. |
9. Recipient Register
The Register includes only providers required by the pre-launch architecture and confirmed in the audit preceding publication. A new recipient must not receive data before updating the register, contract and, where needed, consent.
Courts, law-enforcement, tax, supervisory or other authorised authorities may receive only data required by a valid legal duty or request. They are not standing service recipients and therefore are not presented as an active provider in the Register.
| Full legal name | Role | Service | Data categories | Processing region | Transfer basis | Provider information |
|---|---|---|---|---|---|---|
| Supabase | Processor | Database, authentication and server functions. | Waitlist, Report notifications, previously created accounts, consents, support and logs. | European Union | Processing in the EU. Should the provider or its sub-processor access data from outside the EEA, the basis is a GDPR Chapter V mechanism under the processing agreement: an adequacy decision or standard contractual clauses. | https://supabase.com/privacy |
| Cloudflare | Processor and provider of its own security operations | CDN, DNS, traffic protection and Turnstile. | IP, headers, requested URL, time, security identifiers/signals and request content (including form data) processed in transit. | Global network | Global network. Transfers outside the EEA rely on a GDPR Chapter V mechanism under the processing agreement: an adequacy decision or standard contractual clauses. | https://www.cloudflare.com/privacypolicy/ |
| AhaSend B.V. | Processor | Transactional email without open/click tracking. | Recipient address, sender name/address, subject, full technical message, tokenised functional URLs and delivery metadata. Content and metadata retention: 1 day. | EEA, possibly including Norway; optional US infrastructure is disabled | Not applicable - processing in the EEA; the recipient controls the location of the final mail server. | https://ahasend.com/privacy |
| Independent controller | Google sign-in starts only after the user deliberately selects that method; One Tap is disabled during pre-launch. | Google account identifier, email, basic profile, authentication result and technical redirect parameters. | Google global infrastructure | Google acts as a separate controller and applies its own GDPR Chapter V mechanisms described in its privacy policy. | https://policies.google.com/privacy | |
| Google Ireland Limited | Processor | Google Analytics 4 - visit statistics only after analytics consent; Google signals and ad personalisation are disabled. | Cookie identifiers, IP address, approximate location, device and browser, pages visited, entry source and events. | Google global infrastructure, including the USA | European Commission adequacy decision (EU-US Data Privacy Framework, Google LLC) and standard contractual clauses in the Google data processing terms. | https://business.safety.google/adsprocessorterms/ |
| Meta Platforms Ireland Limited | Joint controller for collecting and transmitting Pixel data; independent controller thereafter | Meta Pixel - measuring and targeting Leksio ads only after marketing consent. | Cookie identifier, IP address, browser and device information, pages visited and events. | Meta global infrastructure, including the USA | European Commission adequacy decision (EU-US Data Privacy Framework, Meta Platforms, Inc.) and standard contractual clauses in the Meta terms. | https://www.facebook.com/legal/controller_addendum |
10. Separate controllers, changes and new functions
Leksio is controller for data processed to operate the website. The sign-in provider named in the Recipient Register is a separate controller for its own users’ data. Public data sources cited in Reports operate under their own law.
The Controller does not sell data. Meta Pixel data reaches Meta only after marketing consent, and Google Analytics runs only after analytics consent. An integration present only in code is not a recipient; actual production activation recorded in the Register decides.
Functional expansion is planned for the beginning of the fourth quarter of 2026. Those future processes are outside Policy 1.0; before activation Leksio will establish purposes, data, bases, roles, retention, transfers and recipients, publish new documents and obtain any required acceptance or consent. Leksio will announce a material change before application where required, and version history will remain. Consent needs a separate active choice and cannot follow from silence. Questions and requests: [email protected].