Privacy Policy
1. Data Controller
The controller of your personal data is nex-IT IT Services (hereinafter: "Controller").
For matters related to personal data protection, please contact us at: biuro@nex-it.pl
2. Purposes and Legal Bases for Processing
Your personal data is processed for the following purposes:
- Responding to inquiries – based on Art. 6(1)(a) GDPR (consent) and Art. 6(1)(f) GDPR (legitimate interest of the Controller in communicating with clients)
- Contract performance – based on Art. 6(1)(b) GDPR (necessity for contract performance or pre-contractual steps)
- Legal obligations – based on Art. 6(1)(c) GDPR (tax and accounting obligations)
- Marketing of own services – based on Art. 6(1)(f) GDPR (legitimate interest of the Controller)
3. Scope of Processed Data
Depending on the purpose of processing, we may collect the following data:
- First and last name
- Email address
- Phone number
- Company name
- Business address
- Tax identification number
- Message and correspondence content
4. Data Retention Period
Your personal data is stored for the following periods:
- Contact inquiries – until the end of correspondence, then for the limitation period for potential claims (maximum 3 years)
- Contracts and invoices – for the period required by tax and accounting law (5 years from the end of the calendar year)
- Data processed based on consent – until consent is withdrawn
5. Rights of Data Subjects
You have the following rights:
- Right of access – to obtain information about processed data
- Right to rectification – to correct inaccurate data
- Right to erasure – to request deletion of data ("right to be forgotten")
- Right to restriction of processing – in certain circumstances
- Right to data portability – to receive data in a machine-readable format
- Right to object – to processing based on legitimate interest
- Right to withdraw consent – at any time, without affecting the lawfulness of processing before withdrawal
To exercise these rights, please contact us at: biuro@nex-it.pl
6. Data Recipients
Your data may be shared with the following categories of recipients:
- Hosting and IT service providers
- Accounting and legal service providers
- Artificial intelligence service providers – to the extent described in section 7
- Government authorities (when required by law)
Transfers outside the European Economic Area
Some of the services supporting this website are provided by suppliers established in the United States. This applies in particular to:
- Vercel, Inc. (USA) – website hosting and visit analytics
- Groq, Inc. (USA) – processing of conversations held with the AI assistant
Transfers to these providers are based on Standard Contractual Clauses approved by the European Commission (Art. 46(2)(c) GDPR) and on data processing agreements concluded with them.
7. AI Assistant (Chatbot)
On our homepage we provide an assistant based on artificial intelligence. In accordance with Art. 50(1) of Regulation (EU) 2024/1689 of the European Parliament and of the Council (AI Act), we inform you that you are interacting with an artificial intelligence system, not with a human.
How the assistant works:
- Purpose and legal basis – providing preliminary information about our services, based on Art. 6(1)(f) GDPR (legitimate interest of the Controller in handling inquiries)
- Scope of data – solely the content of the messages you type, and the IP address used to limit abuse
- Recipient – the conversation content is transferred to Groq, Inc. (USA), which provides the language model generating the responses
- No model training – under our agreement with Groq, conversation content is not used to train or fine-tune artificial intelligence models
- Storage – we do not maintain our own database of conversation history; the transcript exists only in your browser's memory until the page is refreshed or closed. Groq processes the conversation content only to the extent necessary to generate a response
- No automated decisions – the assistant does not make decisions producing legal effects, nor does it carry out profiling within the meaning of Art. 22 GDPR
The assistant's responses are generated automatically, may contain errors and do not constitute an offer within the meaning of the Polish Civil Code. Binding information on the scope and price of services is always provided through direct contact.
Please do not enter personal data, passwords, login credentials or confidential information into the chat window.
For matters requiring such data, please contact us by phone at +48 531 425 277 or by email: biuro@nex-it.pl
8. Cookies and Visit Analytics
This website stores on your device only information that is strictly necessary for its operation. We do not use marketing, tracking or profiling cookies.
- NEXT_LOCALE (cookie) – stores your selected language version of the website
- aerix-announcement-dismissed (localStorage) – records that you closed the announcement bar so that it is not shown again
Both items are strictly necessary to provide a service explicitly requested by the user, and therefore storing them does not require consent within the meaning of Directive 2002/58/EC. Neither contains data that could identify you.
Visit analytics
We use Vercel Web Analytics to collect anonymous visit statistics. This tool does not store any cookies or other information on your device and does not allow identification of an individual user or tracking across websites. Only aggregated traffic data is collected, such as page view counts and device type, on the basis of Art. 6(1)(f) GDPR (legitimate interest in analysing how the website is used).
You can manage cookie settings in your web browser.
9. Data Security
The Controller applies appropriate technical and organizational measures to ensure the security of processed personal data, including:
- Data transmission encryption (SSL/TLS)
- Data access control
- Regular backups
- Security system updates
10. Right to Lodge a Complaint
If you believe that the processing of personal data violates GDPR provisions, you have the right to lodge a complaint with the supervisory authority:
President of the Personal Data Protection Office
ul. Stawki 2, 00-193 Warsaw, Poland
www.uodo.gov.pl
11. Changes to Privacy Policy
The Controller reserves the right to make changes to this Privacy Policy. Users will be informed of any changes through publication of the updated version on this page.
Last updated: August 12, 2026