← All rules

Privacy Policy

Notice on processing in Reports, editorial Q&A and the Waitlist. Cookie and active-recipient sections form part of this Policy. This Policy is not a consent statement and is not part of the Terms acceptance checkbox.

Version 1.0 · effective from 2026-09-18

Download an HTML copy

1. Controller and contact

The data controller is Leksio sp. z o.o., with its registered office in Warsaw at ul. Żurawia 6/12 lok. 745, 00-503 Warszawa, Poland, entered in the Polish commercial register by the District Court for the Capital City of Warsaw in Warsaw, XII Commercial Division of the National Court Register, under KRS 0001264046, tax ID (NIP) 7011330213, REGON 545666406, share capital PLN 10,000. Personal-data enquiries may be sent to [email protected] or the registered-office address.

The Controller has not appointed a data protection officer. Messages are handled by a person authorised for privacy matters.

This Policy is version 1.0 and applies from 2026-09-18. The Polish version is binding.

2. Scope, principles and sources

This Policy covers public Reports and editorial Q&A, the Waitlist, notifications, security and support, as well as accounts created before version 1.0 took effect. It does not cover other planned features that are not publicly active.

Data comes directly from the person, their device and technical logs. The Controller applies minimisation, purpose limitation, accuracy and storage limitation. Data marked as required is needed for the selected function or agreement; failure to provide it prevents that function but does not affect browsing public materials that do not require it.

3. Processes, data, purposes and legal bases

The table states the people and process, data and source, purpose and Article 6(1) GDPR basis, whether provision is required, and retention.

Processing activity table
People and processData and sourcePurpose and basisRequired?Retention
Visitors - public contentRequested URL, IP, headers, time, security events and selected language/theme; from the device and logs.Website delivery, protection and diagnostics; Article 6(1)(f), or (b) where needed for the requested service.Transmission data is required; language and theme are voluntary.Security logs up to 12 months; preferences until changed or cleared.
WaitlistEmail, role, language, address confirmation, Terms acceptance, voluntarily profession, city and case topic and - only after analytics consent - broad source and UTM, referrer domain and signup-page context; from the person, entry address and device.Accept the entry, confirm the address and announce launch; point (b), duty evidence - (c), claims - (f); signup-source measurement after consent - (a).Email and role are required; other fields and source data are voluntary, and source data is neither stored nor sent without analytics consent.Unconfirmed entry 30 days; confirmed entry until the launch notification or leaving the list plus 3 years; minimal agreement evidence 6 years.
Notifications about new ReportsEmail, notification choice, consent/withdrawal time and delivery status; from the person and system.Send information about new Reports; point (a).Voluntary.Until consent is withdrawn; unnecessary identifiers within 30 days; minimal claims evidence no more than 6 years.
Accounts created before version 1.0Email, identifier, role, language, settings, Terms acceptance and data previously entered in the profile; from the person and the authentication system.Keep the account until it is deleted or covered by new documents and handle the holder’s requests; point (b), duty evidence - (c), claims - (f).No new data is collected; the account can be deleted on request.Until account deletion plus 3 years; minimal agreement evidence 6 years.
Support and complaintsContact, category, description, correspondence and necessary technical data; from the reporter and system.Response, contract, duties and claims; point (b), (c) or (f), depending on the matter.Needed to handle the request.Full content through closure plus 3 years; technical email outbox up to 90 days.
SecurityIP, headers, session/device identifiers, time, form-protection result and sign-in events; from the device, protection provider and logs.Confidentiality, integrity, availability, attack detection and claims; point (f), or (c) for security duties.Technically required.Generally up to 12 months.
First-party measurement after consentRandom pseudonym, event type, general page context, performance and time; from the device, without form content, email or full URL.Statistical service improvement; point (a).Voluntary.Raw events 1 day; irreversible aggregates 25 months.
Google Analytics after consentIdentifiers from the _ga and _ga_* cookies, IP address (Google Analytics 4 does not store it in reports), approximate location, device and browser type, pages visited and entry source; from the device.Visit statistics and service improvement; Article 6(1)(a). Google signals and ad personalisation are disabled.Voluntary.Cookies 13 months or until consent is withdrawn; event data in Google Analytics 14 months.
Meta Pixel after marketing consentIdentifier from the _fbp cookie, IP address, browser and device information, pages visited and events (such as a page view); from the device. Meta may link them to an account in its services.Measure the effectiveness of Leksio ads and show them to people who visited the website; Article 6(1)(a).Voluntary and independent of analytics consent._fbp cookie 90 days or until consent is withdrawn; data held by Meta under its privacy policy.
Cookie decisionsBrowser pseudonym, categories, notice/Policy version, hash, method and decision time; from the device.Apply and demonstrate the choice; point (a) for measurement and (c)/(f) for evidence.The optional-purpose choice is voluntary.Setting 12 months; server evidence 5 years.

4. Individual rights

Subject to GDPR, a person has rights of access/copy, rectification, erasure, restriction, portability of data supplied under consent/contract, objection to legitimate-interest processing, and withdrawal at any time without affecting prior lawfulness.

Send requests to [email protected]. The Controller asks only for identity-confirming information and normally responds within one month; for a complex request it may lawfully extend and explain.

Complaints may be lodged with the President of the Polish Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, uodo.gov.pl. Other remedies remain available.

5. Deletion, evidence and backups

After the period, full data is deleted or irreversibly aggregated. When an agreement ends, Leksio separates minimal evidence: Terms version/hash, language, context/time and claim events. It may remain for 6 years and is not used for further contact.

One-time session markers expire with the session or earlier after use. Leaving the Waitlist or withdrawing consent to Report notifications stops further sending.

Longer storage occurs only for a documented duty or legal hold concerning a specific claim/proceeding. Data removed from the active system disappears from backups under the confirmed provider cycle and is not restored to ordinary use meanwhile.

6. Security, transfers and automation

Leksio uses role-based access, encryption in transit, event logs, environment separation, backups, minimisation, and incident/deletion procedures. No safeguard eliminates all risk, so Users should protect devices and credentials.

A provider may process outside the EEA only after a GDPR Chapter V basis is confirmed, especially adequacy or standard contractual clauses with assessment and supplementary measures. The Recipient Register gives details.

The current pre-launch service makes no solely automated decision producing legal or similarly significant effects. A technical security rule may stop a request, but the issue can be reported to a human in support.

7. Cookies and device technologies - rules

This Policy covers cookies, localStorage, sessionStorage and similar identifiers. Essential technologies serve requested transmission, security, language, theme, decision storage and sign-in to previously created accounts under the necessary-technology exception in Article 399 of Polish Electronic Communications Law.

Optional analytics covers Leksio first-party measurement and Google Analytics. It is off by default and starts only after prior voluntary consent. Refusal does not limit use of the website. A separate marketing category (Meta Pixel) is also off by default and runs only after separate consent.

The panel allows the optional purpose to be accepted or rejected. “Cookie settings” in the footer reopens it. Withdrawal is as easy as consent, operates prospectively and stops later optional events.

8. Active technology table

The table lists cookies and similar browser technologies (localStorage, sessionStorage) used on the Leksio site. The case form and Google One Tap are disabled during pre-launch, so they are not listed.

Active device technology inventory
NameProviderPurposeCategoryWhen it runsLifetime
Leksio settings, sign-in and statisticsLeksioSign-in to previously created accounts, remembering language, theme and your cookie decision, completing a waitlist signup, protection against page-loading errors and - after consent - Leksio’s own site statistics and entry source when joining the list, without form content or email.Essential; statistics - analyticsUsing the site; statistics only after analytics consent.From a few minutes to 12 months; cookie decision evidence 5 years; raw statistics 1 day, aggregated 25 months.
Google AnalyticsGoogle Ireland LimitedVisit statistics: how many people visit the site and which pages they use.AnalyticsOnly after analytics consent.Cookies up to 13 months.
Meta PixelMeta Platforms Ireland LimitedMeasuring how well Leksio ads on Facebook and Instagram work and showing them to people who visited the site.MarketingOnly after marketing consent.Cookie up to 90 days.
Sign-in with GoogleGoogleSigning in with a Google account when you choose that method. Google does not set cookies on the Leksio domain.EssentialClicking the Google sign-in button.Not applicable.
Site protectionCloudflareDelivering the site securely and checking that a form is sent by a person.EssentialVisiting the site or sending a form.Usually up to 30 minutes, at most one year; logs up to 12 months.

9. Recipient Register

The Register includes only providers required by the pre-launch architecture and confirmed in the audit preceding publication. A new recipient must not receive data before updating the register, contract and, where needed, consent.

Courts, law-enforcement, tax, supervisory or other authorised authorities may receive only data required by a valid legal duty or request. They are not standing service recipients and therefore are not presented as an active provider in the Register.

Active Recipient Register
Full legal nameRoleServiceData categoriesProcessing regionTransfer basisProvider information
SupabaseProcessorDatabase, authentication and server functions.Waitlist, Report notifications, previously created accounts, consents, support and logs.European UnionProcessing in the EU. Should the provider or its sub-processor access data from outside the EEA, the basis is a GDPR Chapter V mechanism under the processing agreement: an adequacy decision or standard contractual clauses.https://supabase.com/privacy
CloudflareProcessor and provider of its own security operationsCDN, DNS, traffic protection and Turnstile.IP, headers, requested URL, time, security identifiers/signals and request content (including form data) processed in transit.Global networkGlobal network. Transfers outside the EEA rely on a GDPR Chapter V mechanism under the processing agreement: an adequacy decision or standard contractual clauses.https://www.cloudflare.com/privacypolicy/
AhaSend B.V.ProcessorTransactional email without open/click tracking.Recipient address, sender name/address, subject, full technical message, tokenised functional URLs and delivery metadata. Content and metadata retention: 1 day.EEA, possibly including Norway; optional US infrastructure is disabledNot applicable - processing in the EEA; the recipient controls the location of the final mail server.https://ahasend.com/privacy
GoogleIndependent controllerGoogle sign-in starts only after the user deliberately selects that method; One Tap is disabled during pre-launch.Google account identifier, email, basic profile, authentication result and technical redirect parameters.Google global infrastructureGoogle acts as a separate controller and applies its own GDPR Chapter V mechanisms described in its privacy policy.https://policies.google.com/privacy
Google Ireland LimitedProcessorGoogle Analytics 4 - visit statistics only after analytics consent; Google signals and ad personalisation are disabled.Cookie identifiers, IP address, approximate location, device and browser, pages visited, entry source and events.Google global infrastructure, including the USAEuropean Commission adequacy decision (EU-US Data Privacy Framework, Google LLC) and standard contractual clauses in the Google data processing terms.https://business.safety.google/adsprocessorterms/
Meta Platforms Ireland LimitedJoint controller for collecting and transmitting Pixel data; independent controller thereafterMeta Pixel - measuring and targeting Leksio ads only after marketing consent.Cookie identifier, IP address, browser and device information, pages visited and events.Meta global infrastructure, including the USAEuropean Commission adequacy decision (EU-US Data Privacy Framework, Meta Platforms, Inc.) and standard contractual clauses in the Meta terms.https://www.facebook.com/legal/controller_addendum

10. Separate controllers, changes and new functions

Leksio is controller for data processed to operate the website. The sign-in provider named in the Recipient Register is a separate controller for its own users’ data. Public data sources cited in Reports operate under their own law.

The Controller does not sell data. Meta Pixel data reaches Meta only after marketing consent, and Google Analytics runs only after analytics consent. An integration present only in code is not a recipient; actual production activation recorded in the Register decides.

Functional expansion is planned for the beginning of the fourth quarter of 2026. Those future processes are outside Policy 1.0; before activation Leksio will establish purposes, data, bases, roles, retention, transfers and recipients, publish new documents and obtain any required acceptance or consent. Leksio will announce a material change before application where required, and version history will remain. Consent needs a separate active choice and cannot follow from silence. Questions and requests: [email protected].