Data Protection

Privacy Policy

Rules for processing personal data on www.adwokatkedzierski.pl

This Privacy Policy sets out the rules for processing personal data of persons using the website available at: www.adwokatkedzierski.pl ("Website"), operated by attorney-at-law (adwokat) Romuald Kędzierski.

1. Data Controller

The Data Controller of personal data is: Adwokat Romuald Kędzierski

  • Address: ul. Strzegomska 3b/3c lok. 34, 53-611 Wrocław, Poland
  • E-mail: [email protected]
  • Phone: +48 575 572 003
  • Tax ID (NIP): 6972161337

For any matters concerning personal data, you may contact the Controller via the e-mail address or postal address provided above.

2. Scope and Sources of Data

The Controller processes personal data provided by the User in connection with contacting the Controller, in particular:

  • first and last name;
  • e-mail address;
  • phone number;
  • information contained in e-mail correspondence or phone conversations;
  • company name, job title, registered address, tax ID, and other details necessary for contract execution;
  • data submitted through the contact form.

Providing data is voluntary, but may be necessary to answer an inquiry, provide an offer, enter into or perform a legal services agreement, or handle a request.

The Controller requests that initial messages do not contain data beyond what is strictly necessary to establish contact. This applies in particular to information concerning health, criminal record, private life, or other sensitive categories of data.

3. Purposes and Legal Grounds for Processing

  • Answering inquiries, correspondence, and telephone contactArt. 6(1)(f) GDPR (legitimate interest of the Controller in business communication and client handling; where contact aims at contract conclusion – also Art. 6(1)(b) GDPR).
  • Pre-contractual steps, concluding and executing a legal representation agreementArt. 6(1)(b) GDPR.
  • Fulfilling statutory legal obligations, including tax, accounting, archiving, and statutory duties governing the advocacy profession — Art. 6(1)(c) GDPR.
  • Establishing, pursuing, or defending legal claimsArt. 6(1)(f) GDPR (legitimate interest of the Controller).

Special categories of personal data (Art. 9(2) GDPR) are processed only when a valid statutory derogation applies to the specific case. The Controller does not process User data for marketing or unsolicited promotional purposes.

4. Data Recipients

Data may be disclosed to trusted third parties supporting the Controller's business operations only to the necessary extent:

  • hosting, email, IT infrastructure, and cybersecurity providers;
  • law practice management, accounting, or document management software providers;
  • accounting offices, banks, payment operators, and professional advisors;
  • authorized public bodies, courts, administrative authorities, and law enforcement agencies when mandated by law.

5. Data Retention Period

Data is retained for the period strictly necessary to fulfill the purpose of collection:

  • inquiry data where no engagement was concluded — for the duration needed to resolve the inquiry, not exceeding 12 months, unless further retention is justified for defense against potential claims;
  • client contract and matter data — for the duration of the engagement, and thereafter for the period required by statutory retention laws or applicable limitation of claims periods;
  • accounting and tax documentation — for statutory statutory tax retention periods;
  • consent-based data — until consent is withdrawn, without affecting the lawfulness of processing prior to withdrawal.

6. International Data Transfers (outside EEA)

The Controller utilizes reputable cloud and IT service providers whose infrastructure may be located outside the European Economic Area ("EEA"), notably in the United States.

Transfers outside the EEA occur exclusively under lawful transfer mechanisms compliant with Chapter V GDPR, including European Commission adequacy decisions (such as the EU-US Data Privacy Framework) or Standard Contractual Clauses (SCCs). Information on the safeguards applied and a copy thereof can be obtained by contacting the Controller at: [email protected].

7. Data Subject Rights

Under the GDPR, you have the following rights:

  • right to access your personal data;
  • right to rectification;
  • right to erasure ("right to be forgotten");
  • right to restriction of processing;
  • right to data portability (where processing is based on consent/contract and automated);
  • right to object to processing based on legitimate interest;
  • right to withdraw consent at any time;
  • right to lodge a complaint with the supervisory authority (in Poland: Prezes Urzędu Ochrony Danych Osobowych - PUODO).

To exercise these rights, please contact the Controller at: [email protected]. The Controller may request information necessary to confirm the identity of the person making the request.

8. Automated Decision-Making and Profiling

The Controller does not employ automated decision-making or profiling producing legal effects or similarly significant consequences for Users.

9. Cybersecurity and Professional Legal Privilege

The Controller applies appropriate technical and organizational measures to safeguard data against unauthorized access, loss, destruction, or disclosure. In legal practice, all client communications and documents are strictly protected by professional attorney-client privilege (tajemnica adwokacka) pursuant to the Polish Advocates Act and Code of Professional Ethics.

10. Changes to Privacy Policy

This Privacy Policy may be updated to reflect changes in legal regulations, processing practices, or website features. The current version is published on the Website with the effective date.

Questions regarding data processing?

Contact the data controller directly.

Write emailor call: 575-572-003
Law office address: ul. Strzegomska 3b/3c lok. 34, 53-611 Wrocław
Privacy Policy | Advocate Romuald Kędzierski