Legal

Privacy Policy

This Privacy Policy (the "Policy") explains how personal data is processed in connection with the use of the website available at https://idenue.pl (the "Website") and in connection with correspondence conducted with the Controller through the email address kontakt@idenue.pl.

The Website is purely informational — it is the company's business card. We do not run user accounts on it, we provide no forms, we sell no products or services, we run no newsletter and we use no cookies and no analytics tools. Everything needed to display the Website, including the web fonts, is served from our own infrastructure.

This Policy does not cover the Controller's products (including TandoRPG and RentCopilot), which have their own separate privacy policies made available within those products.

Wherever this Policy refers to the "GDPR", this means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

This is an English translation provided for convenience. The Policy is issued in Polish and, in the event of any discrepancy between the two language versions, the Polish text available at https://idenue.pl/pl/polityka-prywatnosci prevails.

1. Data controller

The controller of the personal data of visitors to the Website and of people who contact us is Idenue spółka z ograniczoną odpowiedzialnością, with its registered office in Wrocław (registered address: ul. Stanisława Leszczyńskiego 4 lok. 25, 50-078 Wrocław, Poland), entered in the register of entrepreneurs of the National Court Register kept by the District Court for Wrocław-Fabryczna in Wrocław, VI Commercial Division of the National Court Register, under KRS number: 0001217166, holding NIP (tax identification number): 8971965299 and REGON (statistical number): 543765430, with a share capital of PLN 5,000 (five thousand złoty) paid up in full (the "Controller" or "we").

The Controller has not appointed a Data Protection Officer. For matters concerning the processing of personal data, please contact the Controller directly.

2. Contacting the controller

For all matters relating to the processing of personal data you can contact us:

  • by email: kontakt@idenue.pl,
  • in writing, at the postal address: Idenue sp. z o.o., ul. Stanisława Leszczyńskiego 4 lok. 25, 50-078 Wrocław, Poland.

3. What we do not do on this website

We start with what the Website does not do — it is the shortest answer to most privacy questions. On the Website we:

  • do not run user accounts or registration, and require no sign-in;
  • provide no contact forms — contact is by email or postal mail only;
  • store no cookies or other similar information on your device (localStorage, sessionStorage, web beacons);
  • use no analytics tools (such as Google Analytics) and do not measure the behaviour of visitors to the Website;
  • embed no third-party resources — web fonts, images and all other files are served from our own infrastructure, so displaying the Website causes your browser to make no connection to any other party's servers (for example to an external web font service);
  • run no marketing or remarketing, display no advertising and apply no profiling;
  • run no newsletter and send no commercial information;
  • sell no products or services through the Website and process no payment data;
  • do not sell or share personal data with third parties for marketing purposes.

For these reasons the Website displays no cookie consent banner — there is no consent for us to ask for. The data that is nevertheless processed (primarily technical connection data) is described in the next section.

4. What data we process

Below we set out the purposes for which personal data is processed, the scope of the data, the legal bases, and further information including whether providing the data is voluntary.

Serving the website and keeping it secure (server logs)

Data processed: the device's IP address, the date and time of the request, the address of the requested resource (URL) and the server response code, information about the browser and operating system (user agent), the referring page address (referrer), and the approximate location derived from the IP address.

Legal basis: Art. 6(1)(f) GDPR — the Controller's legitimate interest in serving the Website, ensuring it operates correctly and securely, and preventing abuse (including attacks and attempts to overload it).

Further information: this data is recorded automatically by our infrastructure providers when the Website is displayed. Its processing is a technically unavoidable consequence of using the internet — we do not collect it through forms, we do not combine it with other data, and it is not used to identify visitors to the Website.

Handling correspondence (kontakt@idenue.pl and postal mail)

Data processed: your first and last name or company name (if you provide it), email address, telephone number or postal address (if you provide them), the content of your message together with any attachments, the technical data of the message (date sent, headers), and any other data you choose to include in the message.

Legal basis: Art. 6(1)(f) GDPR — the Controller's legitimate interest in replying to you and conducting correspondence; and, where the message concerns the conclusion or performance of a contract, Art. 6(1)(b) GDPR (steps taken at your request before entering into a contract, or performance of a contract).

Further information: providing this data is voluntary but necessary in order to receive a reply. Please do not include in your messages any special categories of data referred to in Art. 9 GDPR (for example health data) — we do not need them in order to reply.

Handling data protection requests

Data processed: first and last name, email address or postal address, the content of the request, and the data necessary to verify the identity of the person making it.

Legal basis: Art. 6(1)(c) GDPR — compliance with a legal obligation to which the Controller is subject (Art. 12 and Art. 15–22 GDPR); and, as regards demonstrating how the request was handled, Art. 6(1)(f) GDPR in conjunction with the accountability principle (Art. 5(2) GDPR).

Further information: providing this data is voluntary but necessary in order for the request to be handled. We keep a record of the requests received and how they were resolved.

Establishing, pursuing or defending claims

Data processed: the data set out above, to the extent necessary to establish, pursue or defend claims — in particular identification and contact details and the content of correspondence.

Legal basis: Art. 6(1)(f) GDPR — the Controller's legitimate interest in establishing, pursuing or defending claims.

Further information: this processing is secondary to the purposes set out above — no data is collected separately for it.


If correspondence leads to a business relationship or the conclusion of a contract, any further processing (including for settlement, tax and accounting purposes) takes place under Art. 6(1)(b) and (c) GDPR and falls outside the scope of this Policy. In that case we will provide separate information about the processing.

5. Cookies and tracking technologies

  1. The Website stores no cookies on your terminal device and uses no other technologies for storing information on the device (localStorage, sessionStorage, web beacons), nor any browser fingerprinting techniques. The consent referred to in Art. 398 of the Act of 12 July 2024 — Electronic Communications Law is therefore not required, and the Website displays no consent banner.
  2. We use no third-party analytics, statistical or advertising tools.
  3. The Website embeds no third-party resources. The web fonts used on the Website are served from our own infrastructure, so displaying it establishes no connection to external providers' servers (such as the Google Fonts service) and discloses your device's IP address to no one.
  4. Should we decide in future to use cookies or analytics tools, we will ask for your consent before enabling them and will update this Policy.

6. Recipients of personal data

Personal data may be disclosed to the following external entities cooperating with the Controller, acting as processors under data processing agreements concluded with the Controller:

  1. Lovable Labs AB (Box 190, 101 23 Stockholm, Sweden) — provider of the platform on which the Website is created, built and published;
  2. Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) — provider of the hosting and edge infrastructure through which the Website's network traffic passes; technical connection data (logs) is processed in this respect;
  3. Hostinger International Ltd (Jonavos g. 60C, 44192 Kaunas, Lithuania) — provider of the email service for the idenue.pl domain; processes the content of correspondence sent to kontakt@idenue.pl and the data of the senders of such messages.

We disclose data to no recipients other than those listed above. In particular, the Website transmits no data to analytics providers, advertising networks or external web font providers.

Personal data may also be disclosed to entities providing accounting, legal and advisory services to the Controller, and may be disclosed to public or private bodies where such an obligation follows from generally applicable law, a final court judgment or a final administrative decision.

7. Transfers to third countries

In connection with our use of services provided by Cloudflare, Inc., personal data — primarily technical connection data, including IP addresses — may be transferred to third countries, in particular to the United States. Such transfers are based on:

  • Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU–US Data Privacy Framework, in respect of entities in the United States that have joined that programme (Art. 45 GDPR);
  • standard contractual clauses ensuring an adequate level of data protection, in accordance with Commission Implementing Decision (EU) 2021/914 of 4 June 2021, in all other cases (Art. 46(2)(c) GDPR), together with additional safeguards where necessary.

You have the right to obtain from us a copy of the data transferred to a third country and information about the safeguards applied, by contacting us at kontakt@idenue.pl.

8. Retention periods

We retain personal data for as long as is necessary to achieve the purposes for which it was collected:

Category of dataRetention period
Technical connection data (server logs)For the period resulting from the configuration and policies of our infrastructure providers, and no longer than is necessary to keep the Website secure — as a rule up to 30 days from collection, and where a security incident is detected, until that incident has been resolved
Correspondence sent to kontakt@idenue.pl and by postal mailFor the duration of the correspondence and for up to 3 years after it ends (the limitation period for claims), or until an effective objection is raised — whichever occurs first
Data protection requests and records of how they were handledFor as long as is necessary to demonstrate accountability, and no longer than until the expiry of the limitation periods for claims arising from breaches of data protection law
Data processed in order to establish, pursue or defend claimsUntil the expiry of the limitation periods for claims

9. Profiling and automated decision-making

Use of the Website involves no profiling within the meaning of Art. 4(4) GDPR and no automated decision-making within the meaning of Art. 22 GDPR producing legal effects or similarly significantly affecting visitors to the Website.

We do not evaluate the behaviour of visitors to the Website, we build no profiles, we apply no behavioural advertising, and we do not combine technical data with data from other sources.

10. Data security

We apply appropriate technical and organisational measures to protect the personal data we process, in particular safeguarding it against disclosure to unauthorised persons, processing in breach of applicable law, and alteration, loss, damage or destruction. These measures include in particular:

  • encryption of the connection to the Website using the SSL/TLS protocol (HTTPS);
  • application of the data minimisation principle — the Website is designed so that browsing it requires no personal data whatsoever;
  • restricting access to the email mailbox and to the Website's administration panel to authorised persons only;
  • using providers that encrypt data at rest and maintain backups;
  • regular updates of the software we use and its dependencies.

The Controller warrants that it processes personal data in accordance with the GDPR, the Polish Act of 10 May 2018 on the Protection of Personal Data, and other data protection legislation.

11. Your rights

In connection with the processing of personal data you have the following rights:

  1. the right of access (Art. 15 GDPR) — the right to obtain information about what personal data we process and to receive a copy of it. The first copy is free of charge; for further copies we may charge a reasonable fee;
  2. the right to rectification (Art. 16 GDPR) — where the data we process is inaccurate or incomplete, you may request its rectification or completion;
  3. the right to erasure (Art. 17 GDPR) — you may request the erasure of your data, for example where it is no longer necessary for the purposes for which it was collected, where the processing is unlawful, or where you have effectively objected to it;
  4. the right to restriction of processing (Art. 18 GDPR) — you may request that, for a defined period (for example while the accuracy of the data is verified), your data is only stored;
  5. the right to data portability (Art. 20 GDPR) — to the extent that data is processed on the basis of consent or a contract and by automated means, you may request that it be transmitted to you or to another controller;
  6. the right to object (Art. 21 GDPR) — on grounds relating to your particular situation, you may object at any time to processing based on our legitimate interest (Art. 6(1)(f) GDPR). Where the objection is effective, we will stop processing your data for that purpose;
  7. the right to lodge a complaint — if you consider that the processing of your data infringes the GDPR, you may lodge a complaint with the supervisory authority: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland, https://uodo.gov.pl).

We process no data on the Website on the basis of consent, so the right to withdraw consent (Art. 7(3) GDPR) does not apply here. Should we introduce processing based on consent in future, we will say so in this Policy.

To exercise the rights above, contact us at kontakt@idenue.pl. We respond without undue delay and no later than one month from receiving the request. We may take steps to verify the identity of the person making the request.

12. Whether providing data is voluntary

Providing personal data is entirely voluntary. Browsing the Website requires no data at all — the processing of technical connection data is an unavoidable consequence of using the internet and takes place on the side of our infrastructure providers.

Providing data in correspondence addressed to us is voluntary but necessary in order for us to reply. The consequence of not providing it is that we cannot respond to your message.

The Website contains links to the websites of our products and to third-party websites. Once you follow a link, the privacy rules set by the operator of that website apply. We are not responsible for the privacy practices of third parties and encourage you to read their privacy policies.

The Controller's products (including TandoRPG and RentCopilot) have their own separate privacy policies describing how data is processed within those services.

14. Data of minors

The Website is informational in nature and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16.

Should we become aware that we have received a child's personal data without the knowledge and consent of a parent or legal guardian, we will promptly take steps to delete it.

15. Changes to this Privacy Policy

We reserve the right to amend this Policy in order to reflect changes in the law, technological changes, or changes in how the Website operates. We will announce any material changes by posting a notice on the Website.

The current version of the Policy is always available at https://idenue.pl/en/privacy, and in Polish at https://idenue.pl/pl/polityka-prywatnosci.

16. Final provisions

Matters not governed by this Policy are subject to generally applicable data protection law.

Policy version: 1.0. This Policy is effective from 25 July 2026.