01 Data Controller
The controller of your personal data is:
Marcin Trochimiak
Trading as: TROMAR Technology
Address: Krzywa 18, 17-300 Siemiatycze, Poland
NIP (Tax ID): 5441490711
REGON: 367662716
Phone: +48 606 597 516
LinkedIn: Marcin Trochimiak
For any questions regarding the processing of your personal data, you may contact us directly using the details above.
02 What Data We Collect
We collect only the data that you voluntarily provide. We do not track you, purchase databases, or engage in profiling. We process only what is necessary to provide our services.
Data collected through direct contact (LinkedIn, phone, email):
- Name and surname — for identification and communication
- Email address — for correspondence and delivering project materials
- Phone number — for direct communication regarding projects
- Company name and role — to understand project requirements and scope
- Project-related information — technical requirements, business context shared during consultations
03 Purpose and Legal Basis
Your data is processed for specific, defined purposes only:
- Contract performance — communication, project delivery, invoicing. Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual steps)
- Tax and accounting obligations — invoice storage and bookkeeping. Legal basis: Art. 6(1)(c) GDPR (legal obligation)
- Responding to inquiries — when you reach out but no contract is established. Legal basis: Art. 6(1)(f) GDPR (legitimate interest)
04 Data Retention
We retain your data only as long as necessary for the purpose for which it was collected:
- Project data — for the duration of the contract and 3 years after completion (for potential civil claims)
- Invoices and accounting records — 5 years from the end of the calendar year in which the document was issued (Polish tax law requirement)
- Inquiry data (no contract established) — 6 months from the last contact, after which it is permanently deleted
After these periods, your data is permanently deleted or anonymized.
05 Data Sharing
We do not sell, rent, or trade your personal data. Your data may only be shared with entities that help us deliver our services:
- Hosting providers — for website hosting and storage, operating under their own GDPR-compliant privacy policies
- Accounting/invoicing services — only data necessary for issuing invoices
- Google LLC — Google Analytics (website traffic analysis, only with your consent). Data processed under Standard Contractual Clauses
Your data is not transferred outside the European Economic Area, except for Google services (USA) — which operate under Standard Contractual Clauses approved by the European Commission.
06 Your Rights
Under the GDPR, you have the following rights regarding your personal data. You may exercise them at any time by contacting us (see Section 09):
- Right of access — request confirmation of whether we process your data and receive a copy
- Right to rectification — request correction of inaccurate or incomplete data
- Right to erasure (right to be forgotten) — request deletion of data when no longer needed
- Right to restriction — request suspension of processing in certain situations
- Right to data portability — request your data in a structured format (e.g. CSV)
- Right to object — object to processing based on legitimate interest
- Right to lodge a complaint — with the supervisory authority: President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl
07 Cookies
This website does not use cookies for remarketing or profiling. We do not use Facebook Pixel or similar advertising tools.
The website uses only essential technical cookies required for proper functionality. These do not require your consent.
After giving consent via the cookie banner, the website may use Google Analytics 4 (provider: Google LLC, USA) for anonymous traffic analysis. Google Analytics collects:
- Anonymous visit data (pages viewed, time on site, traffic source)
- Approximate location (based on anonymized IP address)
- Device and browser information
Analytics data is processed on the basis of Art. 6(1)(a) GDPR (your consent). Analytics are activated only after you click "Accept All" or enable "Analytics" in cookie settings. Without your consent, no analytical data is collected.
You may withdraw consent at any time by clicking "Cookie Settings" in the website footer.
08 Data Security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, or destruction:
- Communication via encrypted HTTPS / SSL connection
- Limited data access — data is processed only by the data controller personally
- Data stored on devices with up-to-date software and security measures
- Regular review and update of security practices
In the event of a data breach that could pose a risk to your rights and freedoms, you will be notified in accordance with GDPR requirements (Art. 34) — without undue delay, no later than 72 hours from discovery.
09 Contact
For matters relating to data protection, exercising your rights, or any questions regarding this privacy policy, contact us directly:
You may also file a complaint with the supervisory authority: President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.