Privacy policy

This is an English translation provided for information purposes. The binding version is the Polish privacy policy.

This document explains how PGMS Jakub Porycki (the Controller) processes personal data.

You can contact the Controller by e-mail at iod@veyrahr.pl or by post at: al. Jana Pawła II 27, 00-867 Warszawa, Poland.

I. Definitions

Controller – PGMS Jakub Porycki, Tax ID (NIP) 524-237-55-51, address: al. Jana Pawła II 27, 00-867 Warszawa, Poland.

Personal data – information relating to an identified or identifiable natural person, identifiable by one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity, including a device IP address, location data, an online identifier and information collected through cookies and similar technologies.

Policy – this Privacy policy.

GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

Website – the website run by the Controller at https://www.veyrahr.pl.

Application – the VeyraHR HR analytics platform (Client panel), linked from the Website via “Log in” and “Get started”.

User – any natural person visiting the Website or using one or more of the services or functions described in this Policy.

II. Processing of personal data – purposes and legal bases

The Controller carries out an ongoing risk analysis to ensure that personal data is processed securely – above all, that only authorised persons have access to the data, and only to the extent necessary for their tasks. The Controller ensures that all operations on personal data are recorded and carried out only by authorised employees and associates. The Controller takes all necessary steps to ensure that its subcontractors and other cooperating entities also guarantee appropriate security measures whenever they process personal data on the Controller’s behalf.

When a User uses the Website, the Controller collects data to the extent necessary to provide the individual services offered, as well as information about the User’s activity on the Website. The detailed rules and purposes of processing personal data collected when the User uses the Website are described below.

Use of the Website

The personal data of all persons using the Website (including the IP address or other identifiers and information collected through cookies or similar technologies) is processed by the Controller:

  • to provide electronic services consisting in making the content of the Website available to Users – the legal basis is the necessity of processing for the performance of a contract (Art. 6(1)(b) GDPR);
  • for analytical and statistical purposes – the legal basis is the Controller’s legitimate interest (Art. 6(1)(f) GDPR), consisting in analysing Users’ activity and preferences in order to improve the functions and services provided;
  • to establish, pursue or defend against possible claims – the legal basis is the Controller’s legitimate interest (Art. 6(1)(f) GDPR), consisting in protecting its rights.

Contact forms

The Controller provides electronic contact forms. Using a form requires providing the personal data necessary to contact the User and answer the enquiry: first and last name, company name, e-mail address and the content of the message. The message from the form is delivered to the Controller’s mailbox via Amazon Simple Email Service (servers in Frankfurt).

Personal data is processed:

  • to identify the sender and handle their enquiry sent through the form, on the basis of Art. 6(1)(f) GDPR, where the legitimate interest is responding to the enquiry.

Google Map on the contact page

The Contact page embeds an interactive Google map (Google Maps; provider in the EEA: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) showing the location of the Controller’s office. When the Contact page is displayed, the User’s browser connects to Google servers, which receive, among other things, the IP address, information about the browser and the page visited, and Google may store its own cookies on the device.

  • The purpose is to help the User find the Controller’s office, and the legal basis is the Controller’s legitimate interest (Art. 6(1)(f) GDPR) in presenting the office location.
  • Data may be transferred to Google LLC in the USA on the basis of the European Commission’s decision on the EU-US Data Privacy Framework.
  • Google’s data processing rules: https://policies.google.com/privacy.

The User has the right to object to such processing. To avoid connecting to Google servers, you can refrain from opening the Contact page and use the address details provided in this Policy.

Registration and account in the Application

Creating a company account in the Application requires providing company details (Tax ID, name, REGON, KRS, registered address – for sole traders these may be the entrepreneur’s personal data) as well as the e-mail address and password of the account administrator. Company details may be filled in automatically from public registers (the National Court Register and the VAT taxpayer list). The password is stored only in encrypted form (as a cryptographic hash).

Personal data is processed:

  • to conclude and perform the agreement for the use of the Application, including account management, sign-in and service-related communication – on the basis of Art. 6(1)(b) GDPR;
  • to comply with obligations under tax and accounting law – on the basis of Art. 6(1)(c) GDPR;
  • to ensure the security of the Application and to establish, pursue or defend against claims – on the basis of Art. 6(1)(f) GDPR.

HR data processed in the Application

Employee data that a Client imports into the Application for HR analytics is processed by the Controller solely on the Client’s behalf, as a processor within the meaning of Art. 28 GDPR. The controller of this data is the Client (the employer), and the rules for processing it are set out in the data processing agreement concluded with the Client. This data is stored on Amazon Web Services servers in the eu-central-1 region (Frankfurt, Germany). Data subjects should address their requests first to their employer.

Direct marketing

The User’s personal data may also be used by the Controller to send marketing content through various channels, i.e. by e-mail. The Controller does so only if the User has consented, and the consent may be withdrawn at any time.

In some cases, the Controller may also conduct direct marketing by traditional post. The User will be informed separately of the intention to conduct such marketing. The legal basis for processing personal data will then be Art. 6(1)(f) GDPR. The User has the right to object to this type of marketing.

Collecting data in business contacts

In the course of its business, the Controller also collects personal data in other situations – e.g. during business meetings or by exchanging business cards – for purposes related to initiating and maintaining business contacts. The legal basis for processing is the Controller’s legitimate interest (Art. 6(1)(f) GDPR) in building a network of contacts in connection with its business. Personal data collected in such cases is processed only for the purpose for which it was collected, and the Controller ensures its appropriate protection.

Providing data is voluntary but necessary for the above purposes.

III. Cookies

Collection of data (including personal data) through cookies or similar technologies, including the processing of personal data.

General information

Cookies are small text files placed on your computer by the websites you visit. They are widely used to make websites work or work more efficiently, and to provide information to website owners. Below we explain which cookies we use and why.

We use the following categories of cookies: session and persistent.

  • session cookies – remain on the user’s device until they leave the website or close the software (web browser);
  • persistent cookies – remain on the device for the time specified in the cookie parameters or until they are deleted manually by the user.

Why does the Controller use cookies?

Depending on their purpose, the Controller uses two categories of cookies: “necessary” and “optional”. They are used for the following purposes:

“Necessary” cookies – for the purpose and to the extent necessary to display the website correctly. This covers basic functions such as security, network management and accessibility. They can be disabled by changing your browser settings, but this may affect how the website works. This category also includes the browser storage (localStorage) entry veyra_consent, in which we store your cookie choices, and – in the Application – the veyra_token entry, which keeps the logged-in user’s session.

“Optional” cookies: analytical – to study the preferences of people using the website. The results are used to improve the quality of the website. The use of this category of cookies is based on the user’s consent.

This data is not combined with information such as first and last name, e-mail address or other data that would make it easy to identify the person visiting the website.

Analytical cookies (third-party)

CookieFile namePurposeDuration
Google Analytics 4 / Provider: Google Ireland Limited_ga, _ga_<identifier>These cookies are used to collect information about how visitors use our website. We use this information to compile reports and to help us improve the website. The cookies collect information in a way that does not directly identify anyone, including the number of visitors to the website, the pages they came from and the pages they visited. They are set only after consent is given.up to 2 years

Read Google’s overview of privacy and data protection: https://support.google.com/analytics/answer/3379636

You can withdraw your consent at any time and stop cookies from being set and data from being collected – in the “Cookie settings” in the page footer. Withdrawing consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

Google Maps cookies

When the Contact page is displayed, Google may store its own cookies on the device (e.g. NID) related to the embedded map. The map loads regardless of consent to analytical cookies – see part II, “Google Map on the contact page”.

Controlling and deleting cookies

Most browsers allow you to accept or reject all cookies. You can also easily change your cookie settings in your browser. Please note that blocking all cookies from the Website may cause problems or make it impossible to use some of its functions.

Managing and deleting cookies differs depending on the browser. You can find detailed information in your browser’s Help function or at https://www.allaboutcookies.org, which explains how to control and delete cookies in most browsers.

You can find information about individual browsers on their help pages:

  • Google Chrome
  • Apple Safari
  • Microsoft Edge
  • Mozilla Firefox
  • Opera

To opt out of Google Analytics on all websites, visit: https://tools.google.com/dlpage/gaoptout

Operational data

Even if no cookies are set, the website administrator may access the following data describing how the website is used (hereinafter: other operational data):

  • the ID number assigned to the visitor’s device,
  • identifiers of the telecommunications network termination point,
  • the IT system (device type, operating system, web browser) used by the visitor,
  • information about the start, end and scope of each use of the website.

To ensure the highest quality of the website, we occasionally analyse log files to determine which pages are visited most often, which web browsers are used, whether the website structure contains errors, etc.

Operational data is not combined with information such as first and last name, e-mail address or other data that would make it easy to identify the person visiting the website.

Protection of personal data

Information obtained through cookies and operational data may, in certain exceptional situations, constitute personal data within the meaning of the GDPR. If such information qualifies as personal data, its controller is the Controller. Even where it is unclear whether a certain category of information is personal data, the Controller applies mechanisms that protect it as personal data.

Processing of the above categories of data to the extent necessary to display the website correctly (“necessary” cookies) is based on the website administrator’s legitimate interest (Art. 6(1)(f) GDPR). For this purpose, we may:

  • occasionally analyse log files to determine which browsers visitors use, which tabs, pages or subpages are visited or viewed most or least often, and whether the website structure contains errors;
  • prevent unauthorised access to the website and the distribution of malicious code, stop denial-of-service attacks and prevent damage to computer and electronic communication systems.

In the above cases, you have the right to object (where processing is based on Art. 6(1)(f) GDPR).

If you consent to “optional” cookies (analytical, e.g. provided by Google Analytics), the information collected in this way will be used to study the preferences of people using our website, and the results will be used to improve the quality of the website. In this case, the basis for storing information and accessing it on the User’s device is Article 399 of the Polish Electronic Communications Law of 12 July 2024, and the basis for processing personal data is the User’s consent (Art. 6(1)(a) GDPR).

You can withdraw your consent and delete cookies from your device at any time. Withdrawing consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

Recipients of the data: the entities listed in part VI.

Deletion of data collected through cookies and operational data

Personal data will be deleted or anonymised at the latest after the limitation period for potential claims related to the use of the website expires (no later than 12 months from the date it was recorded), or earlier if you lodge an effective objection. Providing data is voluntary but necessary for the above purposes.

IV. Data retention periods

The retention period depends on the type of service and the purpose of processing. As a rule, we process data for as long as the website is used. If you send an enquiry using the contact form, your personal data will be kept for as long as necessary to respond to it. Application account data is kept for the duration of the agreement and then for the period required by tax and accounting law or until the limitation period for claims expires. For direct marketing, personal data is processed until an objection is lodged. Where processing is based on consent – until the consent is withdrawn.

The processing period may be extended where processing is necessary to establish, pursue or defend against possible claims, and after that only if and to the extent required by law. After the processing period, the data is irreversibly deleted or anonymised.

V. Data subject rights

The User has the right to access their data and to request its rectification, erasure or restriction of processing, the right to data portability and the right to object to processing. Where processing is based on consent, it may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.

You also have the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Moniuszki 1A, 00-014 Warszawa, Poland.

Requests concerning data subject rights can be sent by e-mail to iod@veyrahr.pl or in writing to: al. Jana Pawła II 27, 00-867 Warszawa, Poland.

VI. Who we share data with

Only authorised employees and associates of the Controller have access to personal data.

In connection with the provision of services, personal data may be disclosed to external entities that process it on the Controller’s behalf, in particular:

  • Amazon Web Services EMEA SARL (Luxembourg) – hosting of the Website and the Application, database and e-mail delivery; data is stored in the eu-central-1 region (Frankfurt, Germany);
  • Google Ireland Limited (Ireland) – visit statistics (Google Analytics, with consent) and the map on the Contact page (Google Maps);
  • providers of e-mail, accounting and legal services – to the extent necessary to provide them.

The Controller reserves the right to disclose selected information about the User to competent authorities or third parties who request such information on an appropriate legal basis and in accordance with applicable law.

VII. Transfers of personal data outside the EEA

Website and Application data, including HR data imported by Clients, is stored on servers located in the European Union (AWS, Frankfurt). However, some of our providers belong to groups headquartered in the USA, so data may be transferred outside the European Economic Area:

  • to Google LLC (USA) – in connection with the use of Google Analytics and Google Maps;
  • to Amazon Web Services, Inc. (USA) – to a limited extent, e.g. for technical support of cloud services.

Such transfers are made with an adequate level of protection, on the basis of:

  • the European Commission’s implementing decision of 10 July 2023 on the adequate level of protection of personal data under the EU-US Data Privacy Framework – both providers participate in this framework;
  • and, additionally, standard contractual clauses approved by the European Commission.

VIII. Updates to the privacy policy

This Policy is reviewed on an ongoing basis and updated where necessary.

Last updated 26.09.2026.