Privacy policy
Effective from 21 July 2026.
This Privacy Policy (the “Policy”) explains how we process your personal data when you use the d6.pl website at https://d6.pl (the “Service”) and the d6 studio services — designing, launching, hosting and caring for simple websites for small businesses.
Data controller
The controller of your personal data is O3 Prosta Spółka Akcyjna, with its registered office in Rzeszów (address: ul. Fryderyka Szopena 35C, apt. W164, 35-055 Rzeszów, Poland), entered in the Register of Entrepreneurs of the National Court Register kept by the District Court in Rzeszów, 12th Commercial Division, under KRS number 0001234088, NIP (tax ID) 8133950638, REGON 54445106900000 (the “Controller”).
Contacting the Controller
For matters related to personal data processing, you may contact the Controller by:
- e-mail — hello@d6.pl;
- phone — +48 455 564 235;
- post — ul. Fryderyka Szopena 35C, apt. W164, 35-055 Rzeszów, Poland.
Security measures
The Controller applies organisational and technical measures appropriate to the risk to protect your personal data, and processes data in accordance with Regulation (EU) 2016/679 (the “GDPR”), the Polish Act of 10 May 2018 on the protection of personal data, and other applicable laws.
Information on processed personal data
Below you will find the purposes and legal bases of processing, retention periods, and whether providing data is obligatory or voluntary.
“Request a free preview” form
Data processed: e-mail address; optionally phone or WhatsApp number; optionally a link to a current website, map or profile; description of the business and needs; form language / locale; technical submission metadata.
Legal basis: Article 6(1)(b) GDPR — steps prior to entering into a contract at your request; and Article 6(1)(f) GDPR — the Controller’s legitimate interest (responding to enquiries and preparing a proposal).
Providing an e-mail and business description is voluntary but required to handle the request. Data are processed until the sales correspondence ends and thereafter until claims become time-barred or a successful objection is raised, depending on the basis.
E-mail and phone contact
Data processed: name or business name, e-mail address, phone number, content of correspondence.
Legal basis: Article 6(1)(f) GDPR — legitimate interest (responding to enquiries).
Providing data is voluntary but necessary to receive a reply. Data are processed until the purpose is achieved or a successful objection is raised.
Preparing and presenting a website preview
Data processed: business details (name, industry, location, offer), content and materials you provide (texts, logo, photos, links), feedback on the design.
Legal basis: Article 6(1)(b) GDPR — pre-contractual steps or performance of arrangements preceding the Contract.
Providing data is voluntary; without it the preview may be limited. Data are processed until the sales process ends or the Contract is concluded and performed, and then according to the periods below.
Concluding and performing a website services contract
Data processed: full name / company name, e-mail, phone, correspondence or registered address, NIP/VAT ID (if applicable), domain details, content and materials for publication, arrangements on scope, hosting and care.
Legal basis: Article 6(1)(b) GDPR — performance of a contract for design, launch, hosting and care (the “Contract”).
Data necessary for the Contract are required to conclude and perform it. The Controller processes them for the term of the Contract and until related claims become time-barred.
Payments
Data processed: full name / company name, e-mail, order identifiers, payment status and date, amount and currency. Card data are processed only by an external payment provider — the Controller does not store card details.
Legal basis: Article 6(1)(b) GDPR — Contract performance; Article 6(1)(c) GDPR — accounting and tax obligations for billing records.
Tax and accounting obligations
Data processed: full name / company, address, NIP/VAT ID (if applicable), invoice and payment data.
Legal basis: Article 6(1)(c) GDPR — obligations under tax and accounting law.
Data are kept for the period required by law, typically 5 years from the end of the year in which the tax payment deadline expired.
Complaints
Data processed: full name / company name, e-mail, complaint description and attachments.
Legal basis: Article 6(1)(c) GDPR — duty to handle complaints; Article 6(1)(b) GDPR — where related to the Contract.
Data are processed for the duration of the complaint procedure and then until claims become time-barred.
Establishing, exercising or defending legal claims
Data processed: data necessary to protect the Controller’s rights (including identification and contact data, correspondence and Contract content).
Legal basis: Article 6(1)(f) GDPR — legitimate interest.
Data are processed until the relevant limitation periods expire.
Operating the Service (technical logs)
Data processed: IP address, date and time of the request, browser and operating system information, requested URL — recorded automatically in server or hosting logs.
Legal basis: Article 6(1)(f) GDPR — legitimate interest (security and proper operation of the Service).
Data are kept for as long as needed for security and diagnostics, usually no longer than a few months, unless a longer period is needed to investigate an incident.
Compliance with data-protection obligations
Data processed: full name, contact details and the content of a GDPR rights request.
Legal basis: Article 6(1)(c) GDPR.
Data are processed until claims related to data-protection breaches become time-barred.
Recipients of personal data
Recipients may include processors acting on behalf of the Controller or independent controllers for their own services:
- contact-form provider (e.g. Formspree, Inc.) — when the Service uses an external form endpoint;
- hosting and infrastructure providers for the Service and client websites;
- payment providers — for payments for the Services;
- e-mail and communication tool providers;
- accounting, legal or IT service providers — to the extent needed;
- public authorities — where required by law, a court judgment or an administrative decision.
Transfers to third countries
Some providers (e.g. form or hosting vendors) may process data in the United States or other countries outside the EEA. Transfers rely in particular on Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914 and, where applicable, the EU–US Data Privacy Framework.
You may request a copy of information about transfer safeguards from the Controller.
Your rights
In connection with the processing of personal data, you have the right to:
- Access — information about your data and a copy (the first copy free of charge);
- Rectification — if data are inaccurate or incomplete;
- Erasure (“right to be forgotten”) — in cases provided for by the GDPR;
- Data portability — where processing is based on consent or a contract and is carried out by automated means;
- Withdraw consent — where processing is based on consent (withdrawal does not affect lawfulness before withdrawal);
- Restriction of processing;
- Object — to processing based on the Controller’s legitimate interests;
- Complaint — to the President of the Personal Data Protection Office (UODO) in Poland, or another supervisory authority in your EU/EEA country of residence, if you believe processing violates the GDPR.
To exercise your rights, write to hello@d6.pl.
Cookies
- The Service may use cookies or similar technologies on your device.
- The Controller currently does not use analytics or marketing cookies.
- Only strictly necessary technical cookies may be used for the proper operation of the Service (e.g. security or hosting infrastructure), if required by infrastructure providers.
- Most browsers allow you to view, delete or block cookies. Blocking necessary cookies may impair use of the Service.
- If non-essential cookies (e.g. analytics) are introduced later, the Controller will update this Policy and — where required — obtain consent before use.
Final provisions
Matters not covered by this Policy are governed by applicable data-protection law.
This Policy applies from 21 July 2026.