Version 1.2 · effective from 09.06.2026
Privacy Policy — neuroedge.pl
At a glance:
You're on neuroedge.pl, our company website. This policy explains what data we collect when you use the site — in particular when you subscribe to our newsletter, fill in a contact form, book a meeting, download a resource, or take our free assessment.
Key facts:
- The data controller is Neuroedge Consulting and Training Dominika Pikul — we decide how your data is processed.
- We only collect the data you choose to give us through our forms: typically your name, work email address, and — depending on the form — your company name, role, or the content of your message.
- The site does not use marketing cookies or advertising trackers. We use an analytics tool configured without cookies and without identifying users, and we limit the processing of technical operational data to the strict minimum necessary.
- The free assessment available on the site collects no data from you — everything runs in your browser, and the resulting PDF never reaches us.
- We do not sell your data, and we do not share it with data brokers.
- You have the right to access, rectify, erase, restrict, transfer your data, and object to processing — details in section 8.
1. Who controls your data
The data controller is:
Dominika Pikul, trading as Neuroedge Consulting and Training Dominika Pikul ul. Krańcowa 4/2, 30-223 Kraków, Poland NIP (Polish tax ID): 8711673571
Contact for data protection matters: hello@neuroedge.pl
Throughout this policy, "Neuroedge", "we" or "the Controller" refers to the entity above.
2. What data we collect
We collect only the data you choose to give us by filling in forms on the site. Specifically:
2.1. Contact form ("Let's talk")
- first name and surname,
- email address,
- company or organisation name (optional),
- the content of your message.
2.2. "Request a demo" / "Get a workshop quote" form
- first name and surname,
- email address,
- company or organisation name,
- role or position (optional),
- approximate team size or other information helpful for preparing an offer (optional).
2.3. Newsletter
- first name (optional),
- email address.
2.4. Resource download (whitepaper / e-book)
- first name (optional),
- email address,
- optionally, consent to receive further educational materials (opt-in, optional).
2.5. Booking a meeting via Calendly
- first name and surname, email address, and any additional information (e.g. company name, meeting topic) — to the extent you enter them when booking a slot in Calendly.
2.6. Technical data
Simply visiting the site generates minimal technical data (e.g. IP address, browser type, time of visit) visible to our hosting provider. We do not use this data to identify you or to build any profile of you.
2.7. Free assessment
We offer a free demonstration assessment on the site. It is designed so that we collect no data from you in connection with taking it:
- You do not need to provide a name, email, or any other data to start or complete the assessment.
- Your answers never leave your browser. The entire assessment, the scoring, and the generation of the PDF report happen locally, on your own device. No answers or results are sent to us or to any of our providers.
- The PDF report is generated on your device and downloaded directly from your browser. We neither save nor receive a copy of it.
- We do not use your data for automated decision-making, including profiling, that would produce legal effects concerning you or similarly significantly affect you.
The only data relevant to us in connection with the assessment is general, anonymous traffic data described in section 7.2 (e.g. how many people opened the assessment page) — with no link to any individual person.
If, after completing the assessment, you would like to receive our newsletter, you may voluntarily and separately subscribe to it by entering your email. Newsletter subscription is independent of the assessment — you receive the PDF report regardless of whether you subscribe.
Providing your data is generally voluntary. However, in some cases it is necessary for us to respond to your message, send you a resource, subscribe you to the newsletter, or arrange a meeting. If you do not provide data marked as required, we may be unable to carry out those actions.
3. Why we process your data (purposes and legal bases)
Purpose
Legal basis
Responding to your enquiry sent through the contact form or "Request a demo" form — including preparing a quote, arranging a meeting, and further commercial correspondence
Steps necessary at your request prior to entering into a contract (Art. 6(1)(b) GDPR), or our legitimate interest in conducting business and communicating with prospective clients (Art. 6(1)(f) GDPR)
Sending newsletters with information about our activities, articles, and educational materials
Your consent to the processing of your personal data (Art. 6(1)(a) GDPR, together with your prior consent to receive commercial information by electronic means, in accordance with Art. 398 of the Polish Electronic Communications Law you may withdraw consent at any time via the "unsubscribe" link in the footer of every newsletter
Providing you with a downloaded resource (whitepaper / e-book) and, where you have separately consented, sending related educational materials
Performance of your request to download the resource (Art. 6(1)(b) GDPR); for further materials, your consent (Art. 6(1)(a) GDPR)
Arranging a meeting via Calendly
Performance of your booking request (Art. 6(1)(b) GDPR)
Analysing traffic and use of the site — through a privacy-respecting analytics tool that does not process personal data in a way enabling identification of individuals
Our legitimate interest in improving the site (Art. 6(1)(f) GDPR) — to the extent the tool involves any personal data at all
Complying with our legal obligations (e.g. tax duties, responses to requests from supervisory authorities)
Legal obligation (Art. 6(1)(c) GDPR)
Establishing, exercising, or defending legal claims
Our legitimate interest (Art. 6(1)(f) GDPR)
4. Who receives your data
Your data is accessible to a narrow set of providers we work with to deliver our services. They act on our instructions, under data processing agreements compliant with Art. 28 GDPR, and they do not use your data for their own purposes:
4.1. IT and marketing providers
- Mailchimp (The Rocket Science Group LLC, USA) — newsletter and educational material delivery. Mailchimp is certified under the EU–US Data Privacy Framework.
- Calendly LLC (USA) — meeting scheduling. Calendly is certified under the EU–US Data Privacy Framework.
- Webflow Inc. (USA) — hosting of the neuroedge.pl site. Webflow is certified under the EU–US Data Privacy Framework.
4.2. Other recipients
Your data may also be disclosed to:
- public authorities (law enforcement, courts, supervisory authorities) — only on a clear legal basis and only to the extent required by law,
- our professional advisers (e.g. legal, accounting) where necessary for our business operations.
We do not sell your data and we do not share it with data brokers or any other entities engaged in data trading.
5. Transfers outside the European Economic Area
Some of our providers (Mailchimp, Calendly) are US-based companies. Transfers of your data to them are made on the basis of:
- the EU–US Data Privacy Framework (DPF) — for providers certified under this scheme (Mailchimp and Calendly are both certified — you can verify this in the DPF list maintained by the US Department of Commerce),
- where applicable, Standard Contractual Clauses (SCCs) approved by the European Commission, as an additional safeguard.
You may request a copy of the relevant safeguards by writing to hello@neuroedge.pl.
6. How long we keep your data
Type of data
Retention period
Data from the contact form / "Request a demo" form — where no contract was concluded
Up to 24 months from your last contact, in order to address any further questions and to nurture the business relationship
Newsletter subscriber data
Until consent is withdrawn (unsubscribed); after unsubscription, we keep minimal information about the fact of past subscription and its withdrawal for 3 years to demonstrate GDPR compliance, in line with UODO guidance
Data of those who downloaded a resource (whitepaper / e-book)
12 months, unless you are also a newsletter subscriber — in which case the row above applies
Calendly booking data
Up to 24 months from the meeting date (or the planned date, if the meeting did not take place)
Data required for accounting and tax purposes (invoices, settlements)
For the period required by law (Polish accounting law: 5 years from the end of the financial year)
Data needed to defend legal claims
Up to the limitation period under the Polish Civil Code
After these periods, the data is deleted or anonymised.
7. Cookies and similar technologies
7.1. Cookies used on neuroedge.pl
The neuroedge.pl site uses only strictly necessary cookies required for the site to function (e.g. remembering a language choice, if such an option exists, or anti-spam protection for forms). Strictly necessary cookies do not require your separate consent where they are necessary for the transmission of a communication or for providing a service expressly requested by the user, in line with Art. 399(3) of the Polish Electronic Communications Law.
We do not use:
- marketing or advertising cookies,
- tracking pixels (Facebook Pixel, LinkedIn Insight Tag, Google Ads Pixel, etc.),
- cookie-based analytics tools (Google Analytics, Hotjar, etc.),
- session recording or heatmap tools.
7.2. Site analytics
We use a privacy-respecting analytics tool that does not set cookies and does not process data in a way enabling identification of individuals. It aggregates only general traffic information (number of visits, most popular pages, country of origin — without precise location), which helps us improve the site.
7.3. Third-party cookies
Some forms and widgets on the site (e.g. Calendly embedded as a widget) may set their own third-party cookies once you start interacting with them. These cookies are described in the relevant providers' privacy notices:
- Calendly: https://calendly.com/privacy
- Mailchimp: https://www.intuit.com/privacy/statement/
If we introduce advertising or analytics tools relying on third-party cookies in the future (e.g. LinkedIn Insight Tag, Google Ads), we will implement an appropriate consent mechanism (cookie consent banner) and update this policy before such tools go live.
8. Your rights
Under GDPR you have the following rights. You can exercise any of them by writing to hello@neuroedge.pl — we will respond within 30 days (with the option to extend by up to 60 further days in complex cases, which we will inform you about).
- Right of access (Art. 15 GDPR) — you can request a copy of all data we hold about you.
- Right to rectification (Art. 16 GDPR) — if your data is incorrect or incomplete.
- Right to erasure ("right to be forgotten", Art. 17 GDPR) — you may request that we erase your data in the cases provided for by law, subject to the exceptions allowed under applicable law.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR) — where the processing is based on consent or on a contract and is carried out by automated means, you may request your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21 GDPR) — to processing based on our legitimate interest (section 3).
- Right to withdraw consent — where processing is based on consent (newsletter, further educational materials), you may withdraw it at any time. The easiest way is to click "unsubscribe" in the footer of any email. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Right to lodge a complaint with a supervisory authority — for matters concerning the Controller, this is the President of the Personal Data Protection Office (Prezes UODO) in Poland (ul. Stanisława Moniuszki 1A, 00-014 Warszawa, www.uodo.gov.pl). If you reside in another EU/EEA country, you may also lodge a complaint with your local supervisory authority.
9. Data security
We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, alteration, or disclosure. In particular:
- TLS encryption between your browser and our servers,
- secured access to email and mailing systems (two-factor authentication, strong passwords),
- access control based on the principle of least privilege,
- data processing agreements with providers that process personal data on our behalf as processors.
Your contact details and our correspondence with you are stored in email systems and in Mailchimp. Given the nature of these tools (mailbox, mailing system), please note that you have full right to request deletion of all this data — see section 8.
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in line with Art. 34 GDPR.
10. Changes to this policy
We may update this policy when the way we process data changes (e.g. introducing new marketing tools, launching advertising campaigns with tracking pixels) or when required by law. The version and effective date are shown at the top of this document.
We will inform you of material changes:
- on the homepage of neuroedge.pl,
- by email to newsletter subscribers (where the change affects them).
Version 1.20 · 09.06.2026
For any questions about this policy, please write to hello@neuroedge.pl
