Privacy Policy
This policy explains what data I collect through obieg.tech, for what purpose and on what legal basis I process it, and what rights you have regarding that processing.
1. Data controller
The controller of personal data collected through obieg.tech is Karol Lidacki, operating as a freelance automation (n8n) and AI implementation specialist, based near Legionowo, Poland. Contact for data protection matters: obieg.tech@gmail.com.
2. What data I collect and why
I only collect personal data that you provide yourself — in particular through the contact form on the site. The form collects: name, email address, subject of the inquiry, and message content. I use this data solely to reply to your inquiry, prepare a quote, or deliver the service you requested.
The form also contains a hidden anti-spam field (a "honeypot") — it is not visible to users and does not collect any data about you.
3. Legal basis for processing
I process data based on Article 6(1)(b) GDPR (steps taken at your request prior to entering into a contract, e.g. a quote) and Article 6(1)(f) GDPR (my legitimate interest in responding to inquiries and conducting business correspondence).
4. Who receives the data
Messages from the contact form are delivered to me via a webhook running on my own infrastructure (self-hosted n8n) and forwarded to my Gmail inbox (Google Ireland Limited) so I can reply. The site is hosted on Cloudflare infrastructure, which has technical access to network traffic as part of hosting. No data from the form is sold or shared with third parties for marketing purposes.
Purchases of n8n templates take place on the Gumroad platform — clicking "Buy on Gumroad" takes you off obieg.tech and you become subject to Gumroad's own privacy policy (Gumroad, Inc.), independent of me as the controller of this site.
5. Data retention
I keep contact-form correspondence and emails for as long as needed to handle your inquiry, and afterward for the period required by tax and accounting regulations if the contact resulted in a paid engagement. You may ask me to delete the correspondence earlier, as long as this does not conflict with a legal obligation.
6. Cookies and Google Analytics
The site uses Google Analytics (Google LLC) for visit statistics — number of users, pages visited, and traffic sources. Google Analytics is loaded and sets cookies only after you give consent in the banner shown on your first visit (Art. 6(1)(a) GDPR). Without consent, the Google script is not loaded at all. You can change or withdraw your decision at any time via the “Cookies” link in the page footer — withdrawal does not affect the lawfulness of processing before it. Your choice is stored locally in your browser (localStorage). The site’s fonts are hosted on obieg.tech, so loading them does not send any data to Google. Details on how Google processes data are available in Google's privacy policy.
7. Your rights
Under the GDPR you have the right to access your data, correct it, request its deletion, restrict its processing, receive a copy in a portable format, and object to processing based on legitimate interest. You may also withdraw consent at any time where processing was based on it, without affecting the lawfulness of processing carried out beforehand. You also have the right to lodge a complaint with a data protection supervisory authority (in Poland: UODO).
To exercise these rights, write to obieg.tech@gmail.com.
8. Data security
The site is available only over an encrypted HTTPS connection. Data from the contact form is transmitted to my own automation infrastructure, to which only I have access.
9. KSeF Assistant
If you register your company with the KSeF Assistant (obieg.tech/en/ksef), I process: the company name, NIP, the email address given at registration, the email addresses of invoice approvers and of the accounting office set in the panel, the KSeF token, and the purchase invoices downloaded from KSeF together with the data they contain (including seller details and bank account numbers). I also keep a history of settings changes and account activation.
I process this data to provide the service — retrieving purchase invoices from KSeF and sending them for approval and to your accounting office (Art. 6(1)(b) GDPR). For personal data contained in invoices I act on behalf of your company as a processor; we agree the terms of this processing before retrieval is switched on.
The KSeF token is encrypted (AES-256) as soon as you paste it into the panel and is stored in the database only in that form. It is never sent by email or shown again. You can revoke the token at any time in the KSeF Taxpayer App. Data and invoices are stored on my own infrastructure (self-hosted n8n and a PostgreSQL database on a VPS), and emails with invoices go only to the addresses you set in the panel. When you stop using the service, I delete the token and the downloaded invoices, except for data I am required to keep by law.
10. Changes to this policy
This policy may be updated, for example due to changes in the law or in the site's functionality. The current version is always available at this address, and the last-updated date is shown at the top of the document.
11. Contact
Questions about this policy can be sent to obieg.tech@gmail.com.