KUZDRO.COM

Privacy and Cookie Policy

This document explains how personal data, cookies and similar technologies may be used when you visit KUZDRO.COM, contact the controller, use forms, view embedded content or consent to analytics and marketing tools.

Last updated: 24 June 2026Website: https://kuzdro.com
Important: non-essential cookies and tracking technologies may only be activated after the user has provided the required consent. Refusing consent should not prevent access to the website’s basic functions.

1. Data controller

The controller is Grzegorz Kuzdro, a sole trader, Tax Identification Number (NIP): 813 330 30 57.

Correspondence address: 5C Kaletnicza Street, 35-103 Rzeszów, Poland.

Privacy contact: gkuzdro@gmail.com.

2. Scope

This policy applies to use of the website and its language versions, email and form contact, project and recruitment enquiries, contracts and billing, comments or user accounts if enabled, server security, analytics, marketing and embedded third-party content.

3. Categories of data

Contact dataName, email address, phone number, company, role and message content.
Project and business dataInformation supplied in briefs, forms, files, attachments and correspondence.
Technical dataIP address, date and time, device, operating system, browser, language, URLs, referral source, cookie identifiers and website activity.
Billing dataCompany details, tax number, address, payment, contract and accounting information.

Please do not submit health data or other special-category data through ordinary forms or email unless the controller has specifically provided a secure and lawful channel.

4. Purposes and legal bases

  • replying to enquiries and pre-contractual steps — Article 6(1)(f) or 6(1)(b) GDPR,
  • performing contracts — Article 6(1)(b) GDPR,
  • tax and accounting duties — Article 6(1)(c) GDPR,
  • website security and logs — Article 6(1)(f) GDPR,
  • analytics, marketing and non-essential technologies — Article 6(1)(a) GDPR and the user’s consent,
  • establishing, exercising or defending legal claims — Article 6(1)(f) GDPR.

Data is retained only as long as necessary for the relevant purpose, legal obligations, security, contract performance or applicable limitation periods.

5. Cookies and similar technologies

The website may use cookies, local storage, pixels, tags, device identifiers and tracking links.

Categories

  • Strictly necessary — core operation, security, consent records, administrator login and session management.
  • Functional — language, preferences and interface settings.
  • Analytics — traffic measurement, sources, interactions and content effectiveness.
  • Marketing — campaign measurement, remarketing and audience creation.
  • Third-party content — videos, maps, social media elements and external forms.

Non-essential categories should be blocked until consent. Consent may be withdrawn at any time through the cookie settings panel or browser settings.

Typical technologies that may be used

Technology / example Purpose Category Typical duration Activation
wordpress_test_cookie Tests whether the browser accepts cookies necessary session WordPress login-related functions
wordpress_logged_in_* Maintains a logged-in session necessary session / login period after login
wp-settings-* / wp-settings-time-* Stores WordPress interface preferences functional / necessary for logged-in users up to 12 months logged-in users
consent cookie Stores cookie-category preferences necessary usually 6–12 months after saving choices
_ga / _ga_* Google Analytics 4 traffic measurement analytics usually up to 24 months only after consent, if enabled
_fbp Meta campaign measurement and remarketing marketing usually up to 3 months only after consent, if enabled
li_gc / bcookie / lidc LinkedIn consent, security and measurement marketing / functional session to about 12 months after consent, if enabled
YouTube identifiers Video playback and interaction measurement third-party / marketing session to about 6 months after consent and content activation
reCAPTCHA / anti-spam Form security and abuse prevention security / functional provider-dependent when a protected form is used

Cookie names, durations and providers may change when WordPress, plugins, consent tools or integrations are updated. The active list should also be available in the cookie consent panel.

6. External services

WordPress and hosting

WordPress and the hosting provider may process technical cookies, server logs, backups, errors and security events.

Google Fonts

If fonts are loaded directly from Google servers, Google may receive technical information including the IP address and requested resource. Locally hosted fonts may be used to reduce such transfers.

Google tools

If enabled, Google Analytics and Google Tag Manager may process traffic, device and campaign data. Google Search Console is used to understand search visibility and does not itself require marketing cookies on the visitor’s device.

Embedded content

YouTube, Vimeo, maps, social media or external forms may receive IP address, device information, identifiers and interaction data. Consent-requiring content should remain blocked until consent.

Comments, Gravatar and anti-spam

If comments are enabled, form data, IP address and browser information may be processed. A hash of the email address may be sent to Gravatar, and comments may be checked by an anti-spam service.

Email

Messages may be processed through Google or another email/hosting provider as required for transmission, storage and security.

7. Recipients and international transfers

Data may be shared with hosting, domain, email, IT, security, analytics, advertising, consent-management, accounting, legal, payment and project-support providers, as well as public authorities where required by law.

International providers may process data outside the EEA. Such transfers should rely on an adequacy decision, standard contractual clauses or another GDPR-compliant mechanism.

The controller does not sell personal data as a database.

8. Profiling and automated decisions

Analytics and marketing data may be used for statistical audience segments, campaign measurement and communication adjustment. The controller does not make solely automated decisions that produce legal or similarly significant effects.

9. Your rights

  • access and a copy of your data,
  • rectification, erasure or restriction,
  • data portability where applicable,
  • objection to processing based on legitimate interests,
  • withdrawal of consent at any time,
  • complaint to the President of the Polish Personal Data Protection Office.

Requests: gkuzdro@gmail.com. Supervisory authority: https://uodo.gov.pl/.

10. Security, children and policy updates

The controller applies proportionate technical and organisational safeguards, including access controls, updates, backups, HTTPS, limited permissions and incident-response procedures.

The website is not directed at children and the controller does not intentionally collect data from persons under 16 without appropriate parental or guardian involvement where legally required.

This policy may be updated when the law, website functions, providers or tools change. The current version is published with its update date.

11. Contact

Grzegorz Kuzdro

NIP: 813 330 30 57

Correspondence address: 5C Kaletnicza Street, 35-103 Rzeszów, Poland

Email: gkuzdro@gmail.com

Website: https://kuzdro.com