Privacy policy
Last updated: 30 July 2026
1. General information
This Privacy Policy describes how personal data is processed in connection with the public website available at synlog.pl and www.synlog.pl (the “Site”), including the contact form, visit analytics and technical operation of the Site.
The Policy is intended to fulfil the information obligation under Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and the relevant provisions of Polish law, including the Act of 10 May 2018 on the Protection of Personal Data.
This Policy covers only the public marketing Site. The SynLog SaaS application made available to customers (in particular at app.synlog.pl) and the processing of customer telemetry or account data under B2B contracts are governed by separate documentation and, where applicable, a data processing agreement. If you are a user of the product platform, the information provided by your organisation (the customer) and the terms of that contract also apply.
2. Data controller
The controller of personal data processed in connection with the Site is Radosław Łaba, a natural person conducting business activity under the firm name Radosław Łaba and trading under the brand SynLog, NIP (tax ID) 1133143348, REGON 529433927 (“Controller”, “we”, “us”).
Full registration details (firm name, legal form, NIP, REGON, CEIDG entry, address for service) are published on the Company details page.
Contact for personal-data matters: kontakt@synlog.pl. We have not appointed a Data Protection Officer (DPO); the email address above is the point of contact for data-protection requests.
3. Whose data we process
We process personal data of:
- persons who contact us via the form on the Site or by email (in particular name, email address, optional company name, message content);
- visitors to the Site, to the limited extent of technical and analytical data described below (including IP address in server logs and, in aggregate form, usage statistics);
- persons representing organisations interested in SynLog products or services (B2B contact).
The Site is addressed to professionals and business customers. We do not knowingly offer services to children or intentionally collect data of persons under 16.
4. Purposes, data categories and legal bases
We process personal data only where a legal basis under Article 6 GDPR applies. The processing activities on the Site are as follows.
4.1. Handling enquiries (contact form and email)
Data: name, email address, optional company name, message content, language of the message (locale), and technical metadata of the submission (e.g. approximate time, result of anti-spam checks). Where you write to us by email, we also process the data contained in the correspondence.
Purpose: receiving and answering the enquiry, conducting pre-contractual communication, arranging a sales or pilot conversation, and documenting the exchange.
Legal basis: Article 6(1)(b) GDPR (steps at the request of the data subject prior to entering into a contract) where the enquiry concerns our services; and/or Article 6(1)(f) GDPR (legitimate interest in conducting B2B communication and defending against claims).
Providing name, email and message is voluntary but necessary to handle the enquiry. Company name is optional.
The content of your enquiry and its technical metadata are also written to our application logs and to the observability system described in section 5, and are subject to the log retention period stated in section 7.
Data: name, email address, optional company name, message content, language of the message (locale), and technical metadata of the submission (e.g. approximate time, result of anti-spam checks). Where you write to us by email, we also process the data contained in the correspondence.
Purpose: receiving and answering the enquiry, conducting pre-contractual communication, arranging a sales or pilot conversation, and documenting the exchange.
Legal basis: Article 6(1)(b) GDPR (steps at the request of the data subject prior to entering into a contract) where the enquiry concerns our services; and/or Article 6(1)(f) GDPR (legitimate interest in conducting B2B communication and defending against claims).
Providing name, email and message is voluntary but necessary to handle the enquiry. Company name is optional.
The content of your enquiry and its technical metadata are also written to our application logs and to the observability system described in section 5, and are subject to the log retention period stated in section 7.
4.2. Confirmation of form submission
After a successful form submission we may send a short confirmation email to the address you provided (in Polish or English, according to the language of the Site).
Legal basis: Article 6(1)(b) or (f) GDPR, as above — the confirmation is part of handling the enquiry.
After a successful form submission we may send a short confirmation email to the address you provided (in Polish or English, according to the language of the Site).
Legal basis: Article 6(1)(b) or (f) GDPR, as above — the confirmation is part of handling the enquiry.
4.3. Website analytics (Umami)
For aggregated visit statistics we use a self-hosted instance of Umami (on infrastructure under our control; public hostname umami.synlog.pl, loaded on the Site via a first-party proxy on synlog.pl). Umami is configured without cookies, does not build cross-site advertising profiles, and honours the browser’s “Do Not Track” setting. We use aggregate metrics (e.g. page views, popular pages, approximate country, referral source, conversion events such as a successful form send). We do not use these data to identify a natural person for marketing purposes.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in understanding how the Site is used and improving it). Because no non-essential cookies or similar identifiers requiring consent are used, we do not display a cookie consent banner for this purpose.
For aggregated visit statistics we use a self-hosted instance of Umami (on infrastructure under our control; public hostname umami.synlog.pl, loaded on the Site via a first-party proxy on synlog.pl). Umami is configured without cookies, does not build cross-site advertising profiles, and honours the browser’s “Do Not Track” setting. We use aggregate metrics (e.g. page views, popular pages, approximate country, referral source, conversion events such as a successful form send). We do not use these data to identify a natural person for marketing purposes.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in understanding how the Site is used and improving it). Because no non-essential cookies or similar identifiers requiring consent are used, we do not display a cookie consent banner for this purpose.
4.4. Security, availability and abuse prevention
Data: IP address, date and time of the request, requested URL, HTTP status, user-agent and similar technical log data generated by hosting infrastructure and, where the contact form is used, by the contact API (including rate limiting per IP).
Purpose: ensuring the Site works, diagnosing errors, protecting against attacks, spam and abuse (including a honeypot field on the form that is not intended for humans).
Legal basis: Article 6(1)(f) GDPR (legitimate interest in securing IT systems and the service).
Data: IP address, date and time of the request, requested URL, HTTP status, user-agent and similar technical log data generated by hosting infrastructure and, where the contact form is used, by the contact API (including rate limiting per IP).
Purpose: ensuring the Site works, diagnosing errors, protecting against attacks, spam and abuse (including a honeypot field on the form that is not intended for humans).
Legal basis: Article 6(1)(f) GDPR (legitimate interest in securing IT systems and the service).
4.5. Establishment, exercise or defence of legal claims
Where necessary, correspondence and related technical data may be retained for the establishment, exercise or defence of claims.
Legal basis: Article 6(1)(f) GDPR.
Where necessary, correspondence and related technical data may be retained for the establishment, exercise or defence of claims.
Legal basis: Article 6(1)(f) GDPR.
We do not process data from the Site for automated decision-making that produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR). We do not sell personal data.
5. Recipients of data (processors and other parties)
Personal data may be disclosed only to the extent necessary to the following categories of recipients:
- Hosting of the marketing Site — Netlify, Inc. (and its subprocessors under Netlify’s terms), which delivers the static Site and related edge infrastructure. Netlify processes those data as our hosting provider, under Netlify’s terms of service.
- Email delivery — the provider of the kontakt@synlog.pl mailbox and SMTP service (Neo / neo.space infrastructure), which processes email content and metadata as a processor or telecommunications/email service provider in order to deliver messages.
- Contact API and related infrastructure — where the form posts to our contact endpoint, data are processed on servers we operate at an infrastructure provider whose datacentre is located within the European Economic Area (EEA), solely to validate the request, apply rate limits and send the notification and confirmation emails. That provider processes the data as a processor, on the basis of the data-processing terms it makes available. We do not feed form data into third-party marketing automation or CRM tools from the Site itself.
- Analytics (Umami) — operated by us on infrastructure under our control; visit events are sent to that instance via the first-party proxy on the Site. We do not use Google Analytics or similar third-party advertising analytics on the Site.
- Observability system (logs, traces and metrics) — operated by us, on infrastructure under our control, in a data centre within the EEA. Server and application logs, including the metadata and content of contact-form enquiries (section 4.1), are sent to it for diagnostics and security. We do not use a third-party logging service as a processor.
- Public authorities — only where required by mandatory law (e.g. a lawful request by a court or supervisory authority).
6. Transfers outside the European Economic Area
The primary processing related to answering enquiries and running self-hosted analytics takes place in the European Economic Area (EEA).
Keeping our server infrastructure exclusively in datacentres located within the EEA is a standing rule — it applies across any change of provider or location, which is why we do not tie it to a single country. Should that ever change, we will identify the Chapter V GDPR transfer basis and update this Policy before the change takes effect.
Hosting and delivery of the marketing Site by Netlify, Inc. may involve processing outside the EEA (in particular in the United States), including IP addresses and other technical data in connection with serving the Site. In such cases the transfer relies on safeguards under Chapter V GDPR made available by the provider in its terms of service — in particular the European Commission’s Standard Contractual Clauses (SCCs), and, where applicable, other mechanisms recognised under GDPR (e.g. an adequacy decision or certification under the EU–US Data Privacy Framework for certified entities).
We do not intentionally transfer contact-form message content to recipients outside the EEA for marketing purposes. If a specific tool or subprocess change introduces a new third-country transfer, we will update this Policy.
7. Retention periods
We keep personal data no longer than necessary for the purposes for which they were collected:
- Contact correspondence (form and email): for the time needed to handle the enquiry and related communication, and thereafter for up to 24 months from the last message in the thread, unless a longer period is required to establish, exercise or defend claims (in which case until the end of the relevant limitation period under applicable law) or a longer retention is required by law.
- Server, application and security logs: 30 days in the observability system (section 5), after which they are deleted, unless a longer retention is needed to investigate an incident.
- Umami analytics: aggregate statistics are kept for as long as they remain useful for analysing Site traffic; they are not used to build individual marketing profiles. Detailed retention on the analytics instance is aligned with operational need and can be shortened on request where the data still allow identification of a person.
When the retention period ends, data are deleted or anonymised in a way that prevents identification of the data subject, subject to backups that rotate out according to the backup cycle.
8. Cookies and similar technologies
The Site does not use advertising, marketing or tracking cookies, and does not deploy third-party advertising pixels.
Visit analytics (Umami) operate without cookies and without cross-site tracking. For that reason we do not display a cookie consent banner on the Site.
Your browser or network equipment may still process technical data necessary to display the page (e.g. cache, TLS session). Such technical operation does not serve to profile you for advertising. If in the future we introduce non-essential cookies or similar technologies that require consent under the Electronic Communications Law / ePrivacy rules, we will implement an appropriate consent mechanism and update this Policy before doing so.
9. Your rights
To the extent provided by GDPR, you have the right to:
- access your data and obtain a copy (Article 15);
- rectification of inaccurate data (Article 16);
- erasure (“right to be forgotten”) where the conditions of Article 17 are met;
- restriction of processing (Article 18);
- data portability, where processing is based on consent or a contract and is carried out by automated means (Article 20);
- object to processing based on legitimate interests (Article 21) — including objection to processing for analytics based on Article 6(1)(f), for reasons relating to your particular situation;
- withdraw consent at any time, if processing were based on consent (Article 7(3)) — withdrawal does not affect the lawfulness of processing before withdrawal. (The Site does not currently rely on consent as the primary basis for the processing described above.)
To exercise your rights, write to kontakt@synlog.pl. We may need to verify your identity to a reasonable extent before fulfilling the request. We will respond without undue delay, and in any event within one month of receipt (extendable by two further months in complex cases, with notice to you).
You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. You may also contact the supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
10. Voluntary provision of data
Using the Site does not require creating an account or providing identifying data. Providing data in the contact form or in email is voluntary; without an email address and message content we cannot answer your enquiry. Failure to provide optional data (e.g. company name) does not prevent submission of the form.
11. Security
We apply technical and organisational measures appropriate to the risk, including HTTPS encryption in transit, access control to mailboxes and administration panels, rate limiting and anti-spam measures on the contact channel, and limiting analytics to a self-hosted, cookieless tool without advertising trackers.
No method of transmission or storage is completely secure. If you believe your interaction with us has been compromised, please contact us immediately at kontakt@synlog.pl.
12. Links to third-party sites
The Site may contain links to external websites (e.g. documentation or social profiles). This Policy does not apply to those sites. We encourage you to read the privacy notices of any third-party service you visit.
13. Changes to this Policy
We may update this Policy to reflect changes in processing, law or the Site. The new version takes effect on publication on this page, with the “Last updated” date revised. Material changes will be signalled by updating that date; we encourage periodic review of this page.
The current version is effective as of 30 July 2026.