Skip to content

Privacy Policy& Cookie Policy

How Tylko Advisors sp. z o.o. collects, uses and protects personal data - and the choices you have.

This is a translation. Polityka prywatności - the Polish version - prevails in the event of a discrepancy.

PRIVACY POLICY AND COOKIE POLICY

Tylko Advisors sp. z o.o. · Version 2.0 · Effective from 20 August 2026 · Replaces the version of 6 February 2025

This is a translation of the Polish-language version. In the event of any discrepancy between the language versions, the Polish version prevails.

1.Who is the controller of your personal data

The controller of your personal data is:

Tylko Advisors spółka z ograniczoną odpowiedzialnością (a Polish limited liability company) with its registered seat in Jodłówka

address: Jodłówka 126, 32-765 Jodłówka, Poland

entered in the Register of Entrepreneurs of the National Court Register kept by the District Court Katowice-Wschód in Katowice, 8th Commercial Division of the National Court Register, under KRS no. 0000867460

Tax identification number (NIP): 6462985387 · Statistical number (REGON): 387421227

Share capital: PLN 20,000.00 (paid up in full)

hereinafter: "Tylko Advisors", "the Company", "we" or "us".

(Identification details provided pursuant to Article 206 § 1 of the Polish Commercial Companies Code.)

Contact for data protection matters:

  • e-mail: info@tylkoadvisors.com
  • postal address: Tylko Advisors sp. z o.o., Jodłówka 126, 32-765 Jodłówka, Poland

2.Data Protection Officer

We have not appointed a Data Protection Officer, as the conditions set out in Article 37(1) GDPR do not apply to us. For all matters concerning the processing of personal data and the exercise of the rights described in section 11 of this Policy, please contact us at info@tylkoadvisors.com.

3.Scope of this Policy and the law we apply

This Policy describes how we process the personal data of individuals who contact us or use our services and our website, including: our clients and contractors and their employees and associates, participants in events and webinars we organise, newsletter subscribers, candidates taking part in our recruitment processes, and website users.

We process personal data in accordance with:

  • the GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;
  • the Polish Personal Data Protection Act of 10 May 2018 (consolidated text: Journal of Laws of 2019, item 1781, as amended);
  • the Electronic Communications Law Act of 12 July 2024 (Journal of Laws of 2024, item 1221, as amended; "PKE"), in particular as regards cookies (Article 399 PKE) and direct marketing carried out using telecommunications terminal equipment (Article 398 PKE);
  • the Act of 18 July 2002 on Providing Services by Electronic Means;
  • the Polish Labour Code – as regards the data of job candidates.

4.Where we obtain personal data from

We obtain personal data:

a) directly from you, when you:

  • give us your business card or contact details at a business meeting,
  • complete the contact form on our website,
  • subscribe to our newsletter,
  • register for a webinar or another event,
  • book a meeting slot through our booking system,
  • apply for an open position,
  • contact us by e-mail, telephone or via social media,
  • use our website (data collected automatically – see section 14);

b) from sources other than you (Article 14 GDPR), i.e.:

  • from your employer or the entity you represent – where you are a designated contact person, a signatory of an agreement, or a member of a project team of our client, contractor or supplier; we typically receive your name, job title, business e-mail address and telephone number,
  • from publicly available sources – public registers (KRS, CEIDG), corporate websites and professional networking services (e.g. LinkedIn) – as regards professional and contact data,
  • from recruitment intermediaries – where your application was forwarded to us by a recruitment agency or job portal.

5.Categories of personal data we process

  • Identification and contact details: first name and surname, name of the entity represented, job title, business and mobile telephone number, e-mail address, postal address.
  • Professional details: employment and career history, education, professional qualifications and licences, membership of professional bodies (this applies in particular to job candidates).
  • Data relating to our cooperation: the content of correspondence, requests for quotation and enquiries, contact history, data necessary to conclude and perform an agreement, settlement and payment data, bank account number, and tax identification number in the case of sole traders.
  • Event participation data: registration details, attendance, participation preferences.
  • Data collected automatically on the website: IP address, cookie and similar technology identifiers, browser type and version, operating system, device type, approximate location derived from the IP address, referral source, date and time of the visit, pages viewed and on-site events.

We do not intentionally process special categories of personal data (Article 9 GDPR), including health data, political opinions or trade union membership. Please do not include such data in application documents or correspondence. If you provide them on your own initiative, the legal basis for processing will be your explicit consent (Article 9(2)(a) GDPR), which you may withdraw at any time.

Our services are not directed at persons under 16 years of age and we do not knowingly collect their personal data.

7.Is providing your data mandatory

Providing personal data is voluntary, however:

  • providing the data marked as mandatory in the contact or registration form is a precondition for responding to your enquiry or registering you for an event – without it we cannot act on your request;
  • providing the data necessary to conclude and perform an agreement is a contractual requirement – failure to provide it prevents the agreement from being concluded or properly performed;
  • providing the data referred to in Article 22¹ § 1 of the Polish Labour Code is a statutory requirement in a recruitment process – failure to provide it prevents participation in the recruitment; providing data beyond that catalogue is entirely voluntary and has no bearing on the assessment of your application;
  • providing your e-mail address for the newsletter is voluntary – if you do not provide it, we simply cannot send you the newsletter;
  • consenting to cookies other than strictly necessary ones is voluntary – refusing does not restrict access to the content of the website, although it may affect the convenience of using certain features.

8.Who we share personal data with

Your personal data may be disclosed to the following categories of recipients:

  • providers of IT, hosting and cloud infrastructure services – in particular Google Ireland Limited / Google Cloud EMEA Limited (website hosting, Firebase, Cloud Functions, Cloud Firestore, Cloud Storage – infrastructure located in the European region) and Microsoft Ireland Operations Limited (e-mail, calendar and the Microsoft 365 meeting booking system);
  • providers of analytics, marketing and consent management tools – Google Ireland Limited (Google Tag Manager, Google Analytics, Google reCAPTCHA Enterprise), Usercentrics GmbH (consent management platform), MailerLite (newsletter service), Meta Platforms Ireland Limited (in relation to our social media profiles and any advertising activities);
  • our professional advisers – law firms, tax advisers, accounting offices, auditors, HR advisers and insurers;
  • subcontractors, consultants and partners involved in delivering projects for you or for the entity you represent;
  • payment service providers and banks – for settlement purposes;
  • postal operators and courier companies;
  • public authorities – courts, tax authorities, law enforcement bodies and other authorised entities, where disclosure is required by law.

We conclude a data processing agreement meeting the requirements of Article 28 GDPR with every entity that processes personal data on our behalf. We do not sell your personal data.

9.Transfers outside the European Economic Area

As a rule, we store personal data on servers located within the European Economic Area (EEA).

However, because we use tools provided by entities established or operating infrastructure outside the EEA (in particular Google, Microsoft, Meta and MailerLite), your personal data may be transferred to third countries, including the United States. Any such transfer takes place solely on the basis of at least one of the following safeguards:

  • an adequacy decision of the European Commission (Article 45 GDPR) – for US entities certified under the EU–U.S. Data Privacy Framework pursuant to Commission Implementing Decision (EU) 2023/1795 of 10 July 2023;
  • standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (Article 46(2)(c) GDPR), supplemented – following a transfer impact assessment (TIA) – by additional technical and organisational measures such as encryption of data in transit and at rest, and pseudonymisation.

You have the right to obtain a copy of the safeguards applied, or information on where they are made available – please contact us at info@tylkoadvisors.com.

10.Automated decision-making and profiling

If you consent to marketing and analytics cookies, we may process your data by automated means, including profiling, for marketing purposes.

  • What data we use: IP address, cookie and similar technology identifiers, approximate location derived from your IP address, device and browser information, your browsing history on our website (pages visited, time spent, clicks), referral source, and your responses to our marketing messages (opens and clicks).
  • What the profiling involves: on the basis of this data we automatically assign you to audience segments with similar professional interests (e.g. people interested in digitalisation in construction), so that we can select the marketing content, advertisements and materials most likely to be relevant to you.
  • What the consequences are: profiling affects only the marketing and advertising content you see and the materials you receive. It has no effect on commercial terms, pricing, or how your enquiry is handled.

We do not take decisions in relation to you based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22(1) GDPR.

You may object to profiling for direct marketing purposes at any time – once you do, we will cease such processing (Article 21(2) and (3) GDPR). You may also withdraw your consent to analytics and marketing cookies at any time in the privacy settings panel on our website.

11.Your rights

In connection with the processing of your personal data, you have the following rights:

  1. The right of access to your data and to obtain a copy of it (Article 15 GDPR).
  2. The right to rectification of inaccurate data and completion of incomplete data (Article 16 GDPR).
  3. The right to erasure ("the right to be forgotten") in the cases set out in Article 17 GDPR.
  4. The right to restriction of processing (Article 18 GDPR).
  5. The right to data portability – as regards data processed by automated means on the basis of consent or a contract (Article 20 GDPR).
  6. The right to object to processing (Article 21 GDPR):
    • to direct marketing, including profiling for that purpose – you may object at any time and without giving reasons; upon receiving your objection we will immediately cease processing your data for that purpose (Article 21(2) and (3) GDPR);
    • to other processing based on our legitimate interest (Article 6(1)(f) GDPR) – you may object on grounds relating to your particular situation; we will cease processing unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or grounds for the establishment, exercise or defence of legal claims (Article 21(1) GDPR).
  7. The right to withdraw consent at any time – to the extent that processing is based on consent (Article 7(3) GDPR). Withdrawing consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
  8. The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you (Article 22 GDPR) – see section 10.
  9. The right to lodge a complaint with a supervisory authority – see section 12.

How to exercise these rights. Send your request to info@tylkoadvisors.com or by post to: Tylko Advisors sp. z o.o., Jodłówka 126, 32-765 Jodłówka, Poland. You can also withdraw your newsletter consent by clicking the "unsubscribe" link in the footer of every message, and manage cookie consents in the privacy settings panel available on our website.

We respond without undue delay and in any event within one month of receiving a request. Where necessary, we may extend that period by a further two months, informing you of the extension and the reasons for the delay (Article 12(3) GDPR). Exercising your rights is free of charge; we may charge a fee or refuse to act only in the case of manifestly unfounded or excessive requests (Article 12(5) GDPR). We may ask you for additional information necessary to confirm your identity in order to handle your request (Article 12(6) GDPR).

12.The right to lodge a complaint with a supervisory authority

If you believe that we process your personal data unlawfully, you have the right to lodge a complaint with the supervisory authority:

President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych)

ul. Stawki 2, 00-193 Warsaw, Poland

tel. +48 22 531 03 00

e-mail: kancelaria@uodo.gov.pl

ePUAP electronic inbox: /UODO/SkrytkaESP

www.uodo.gov.pl

You may also lodge a complaint with the supervisory authority of the EU Member State of your habitual residence or place of work.

13.Data security

In accordance with Article 32 GDPR, we apply technical and organisational measures ensuring a level of security appropriate to the risk to the rights and freedoms of data subjects, in particular:

  • encryption of data transmission (TLS/HTTPS) on our website and in our forms,
  • access control based on the need-to-know and least-privilege principles, and multi-factor authentication in business systems,
  • protection of forms against abuse (Google reCAPTCHA Enterprise),
  • regular updates and security reviews of the software we use,
  • backups and testing of data restoration,
  • confidentiality undertakings from all persons authorised to process data,
  • maintaining a record of processing activities and a personal data breach response procedure (Articles 33 and 34 GDPR).

14.Cookies and similar technologies

14.1 What cookies are

Cookies are small text files saved on your terminal equipment when you use a website. We also use other technologies with similar functions (browser local storage, pixels, tags). By storage duration we distinguish session cookies (deleted when the browser is closed) and persistent cookies (stored for a defined period); by origin we distinguish first-party and third-party cookies.

14.2 Legal basis

Storing information and gaining access to information already stored in your terminal equipment takes place on the basis of Article 399 PKE. This requires your prior consent, except for files necessary to transmit a communication or to provide a service you have expressly requested.

Consent must be freely given, specific, informed and unambiguous – it does not follow from default browser settings or from the mere use of the website. We collect it via a consent banner (the Usercentrics platform) displayed on your first visit; until consent is obtained, we do not activate cookies other than strictly necessary ones. Refusing consent is as easy as granting it.

To the extent that information stored in cookies constitutes personal data, we process it on the basis of Article 6(1)(a) GDPR (consent) and, for strictly necessary files, on the basis of Article 6(1)(f) GDPR (legitimate interest in ensuring the correct and secure operation of the website).

14.3 Categories of cookies we use

CategoryPurposeBasisProvidersIndicative storage period
Strictly necessaryProviding core website functions, security, protecting forms against abuse, remembering your consent choicesArt. 399 PKE (exemption – no consent required); Art. 6(1)(f) GDPRTylko Advisors, Usercentrics GmbH, Google (reCAPTCHA Enterprise)Session – up to 12 months
FunctionalRemembering user preferences and making the website easier to use, operating the newsletter sign-up form and the meeting booking systemconsent – Art. 399 PKE and Art. 6(1)(a) GDPRMailerLite, MicrosoftSession – up to 12 months
Analytics / statisticsMeasuring traffic and how the website is used, producing statistics, improving content and functionalityconsent – Art. 399 PKE and Art. 6(1)(a) GDPRGoogle (Google Analytics, Google Tag Manager)Up to 24 months
Marketing / advertisingPresenting tailored content and advertisements, measuring campaign effectiveness, marketing profiling (see section 10)consent – Art. 399 PKE and Art. 6(1)(a) GDPRGoogle, Meta Platforms Ireland Limited, LinkedIn Ireland Unlimited CompanyUp to 13 months

A complete, up-to-date list of individual cookies, including their names, providers and exact storage periods, is available in the privacy settings panel on our website (the Usercentrics consent banner). The third parties listed in the table process data in accordance with their own privacy policies.

Using tools provided by entities established outside the EEA may involve transfers of data to third countries – the rules governing such transfers are described in section 9.

14.4 How to manage and withdraw consent

  • In the privacy settings panel on the website – you may change or withdraw the consents you have given at any time; withdrawal is as easy as granting consent and does not affect the lawfulness of processing carried out beforehand.
  • In your browser settings – you may block or delete stored cookies. Instructions can be found in your browser's documentation (Chrome, Firefox, Safari, Edge, Opera).
  • Directly with the tool providers – e.g. via a browser add-on that blocks Google Analytics.

Restricting the use of cookies may affect some website features, but it does not prevent you from accessing its content.

15.Social media profiles

We maintain profiles on social networking services (including LinkedIn and Facebook). We process the data of persons who interact with our profiles (followers, commenters, people sending us messages) in order to communicate and promote our services – on the basis of Article 6(1)(f) GDPR. As regards profile statistics, we may be a joint controller together with the operator of the service (Article 26 GDPR); the arrangements for such joint controllership and the scope of the operator's responsibility are set out in the terms and privacy policies of the relevant services. The operator of the social networking service remains a separate controller of the data processed within the service itself.

16.Changes to this Policy

We may update this Policy, in particular in connection with changes in the law, in the tools we use or in the scope of our activities. The current version is always available on our website together with its version number and effective date. We will give advance notice of any material changes on our website and, for those with whom we are in regular contact, also by e-mail. Any changes requiring consent will be introduced only after that consent has been obtained.

17.Contact

If you have any questions concerning the manner or scope of the processing of personal data by Tylko Advisors, please contact us:

Tylko Advisors sp. z o.o.

Jodłówka 126, 32-765 Jodłówka, Poland

e-mail: info@tylkoadvisors.com