InfaDrive

Privacy Policy

**Last updated:** 2026-08-04

This Privacy Policy sets out the rules for the processing and protection of personal data of users accessing the website operating at infadrive.com (hereinafter referred to as the "Service"). This document has been created to ensure full transparency of information and legal compliance in accordance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

1. Scope of Application

This policy applies to personal data processed by InfaDrive within the infadrive.com website, in particular data collected via the contact form and incidental email correspondence with users.

2. Data Controller

The data controller of the personal data collected through the Service is InfaDrive (a sole proprietorship / advisory practice run by Wiktor Kowalski), operating in Poland.

Controller contact details

* Email: contact@infadrive.com

* Phone: +48 508 154 642

3. Contact Regarding Data Protection

In order to exercise your rights under the GDPR or to obtain further clarifications, users can contact us directly via email at: contact@infadrive.com. It is recommended to include the prefix "[GDPR]" in the subject line of your message to expedite the processing of your request.

4. Scope of Collected Data

For the purpose of handling inquiries submitted through the contact form, we collect: first and last name, email address, phone number (optional), company name and job title (optional), the content of the message itself, and selected inquiry routing options (recipient / category / service). In addition, the Cloudflare Turnstile service automatically processes data regarding user interaction with the interface to verify the risk of bot presence, solely when the contact form is rendered.

5. Purposes of Processing

Users' personal data is processed for the following purposes

1. Correspondence handling: Responding to inquiries submitted through the contact form or sent directly to the project's email address.

2. Service security: Ensuring the IT security of the Service (preventing spam and abuse) using Cloudflare Turnstile.

3. Transactional notifications: Sending email notifications through the Resend service after form submission (strictly necessary, not marketing).

4. Analytics and Marketing (only after obtaining voluntary Cookie Consent):

* Measuring and optimising marketing campaign performance using Meta Pixel and Conversions API (CAPI).

* Analysing user behaviour, generating session recordings and heatmaps via Microsoft Clarity.

* Measuring web traffic, performance metrics and event tracking via Google Analytics 4 (GA4).

Without consent, no marketing or analytics scripts are loaded.

6. Legal Basis for Processing

* Contact form: Voluntary consent of the user (Art. 6(1)(a) GDPR) or taking steps at the data subject's request prior to entering into a contract (Art. 6(1)(b) GDPR).

* Security and anti-spam (Cloudflare Turnstile): Legitimate interest of the Data Controller (Art. 6(1)(f) GDPR).

* CRM contact records (HubSpot): Legitimate interest of the Data Controller (Art. 6(1)(f) GDPR).

* Marketing and analytics (Meta Pixel / CAPI, Microsoft Clarity, Google Analytics 4): Strictly voluntary Cookie Consent of the user (Art. 6(1)(a) GDPR), expressed through the cookie banner.

7. Data Recipients (Sub-processors)

Recipients of the data are exclusively trusted technology providers acting under data-processing agreements

* Cloudflare (Cloudflare, Inc.) — hosting, CDN and Cloudflare Turnstile bot-mitigation.

* Resend (Resend, Inc.) — transactional email delivery for form notifications.

* HubSpot (HubSpot Ireland Ltd) — CRM data storage and relationship management.

* Meta Platforms (Meta Platforms Ireland Ltd) — Meta Pixel and Conversions API (CAPI) conversion tracking (only with consent).

* Microsoft (Microsoft Ireland Operations Ltd) — Microsoft Clarity behavioural analytics, session recordings and heatmaps (only with consent).

* Google (Google Ireland Limited / Google LLC) — Google Analytics 4 traffic and performance statistics (only with consent).

8. Data Retention Period

* Form and email data: For the duration of the correspondence and up to 12 months after its conclusion for archival and claims-protection purposes.

* Cloudflare Turnstile cookies: For the time specified directly by the technology provider.

* Meta Pixel, Microsoft Clarity and Google Analytics 4 cookies: Retained strictly for the period permitted by the user's Cookie Consent state.

9. User Rights

Every individual has the right to: access their data (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR) and objection (Art. 21 GDPR). Consent may be withdrawn at any time.

10. Right to Lodge a Complaint

The user has the right to lodge a complaint with the supervisory authority: President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland (https://uodo.gov.pl).

11. Cookies

* Strictly necessary and technical: Cloudflare Turnstile cookies that protect the form against bots.

* Marketing and analytics: Meta Pixel, Conversions API (CAPI), Microsoft Clarity and Google Analytics 4 cookies. Loaded and read only after explicit consent in the cookie banner (Cookie Consent).

12. Automated Decision-Making

The Data Controller does not use automated decision-making algorithms or profiling within the meaning of Art. 22 GDPR.

13. Changes to the Policy

Each new version of this document will be marked with the "Last updated" date at the top of the page.

14. Final Provisions

In matters not regulated herein, the relevant provisions of Polish law and the General Data Protection Regulation (GDPR) shall apply.