← Back to home

Privacy policy.

Last updated: 11 October 2026.

Data controller

FrameMatter operates within PIEKARNIA ZAKLIKÓW - KRZYSZTOF WIERZBIŃSKI. The personal data controller is Krzysztof Wierzbiński, who operates this business.

Address: ul. Wesoła 1/1A, 37-470 Zaklików. Polish tax identification number (NIP): 8621001922. Business register number (REGON): 830449499.

Privacy contact: hello@framematter.pl.

Form and email contact

When you select “Send message”, the form sends your name, email address, optional company name, selected services and project description to a server function at Cloudflare. The server validates the details and the anti-spam verification result. Typing a message does not send its contents to our mailbox.

After successful checks, your enquiry is sent over an encrypted mail connection to hello@framematter.pl, hosted by OVHcloud Zimbra. We do not store the form contents in the website database or its own application logs. You can also email this address directly.

Providing information is voluntary. Sending the form requires your name, email address and project description; company name and service selection are optional. Without contact details, we may be unable to reply. Do not include sensitive data, national identification numbers, passwords or unnecessary information about other people.

Validation and anti-spam checks do not establish the sender’s identity or authority to represent a company. Where needed, we confirm arrangements directly with an authorised person.

Spam protection

The form uses Cloudflare Turnstile. Verification starts as you approach or interact with the form. Cloudflare analyses signals including IP address, browser and connection characteristics, and the site identifier. Our legal basis is our legitimate interest in preventing abuse (Article 6(1)(f) GDPR).

Cloudflare acts as a processor when protecting our form and as a separate controller when improving bot detection. Our verification request contains no message contents or email address. The document below describes Cloudflare’s processing.

We do not use Turnstile pre-clearance, which issues the cf_clearance cookie. A verification token is single-use and valid for up to five minutes; this is not the retention period for all data handled by Cloudflare. You can send a regular email instead of using the form.

Cloudflare — Turnstile privacy

Purposes and legal bases

We use information received in correspondence to answer questions, understand your needs and prepare proposals. When you request steps before entering into a contract on your own behalf, the basis is Article 6(1)(b) GDPR. For other matters, including contact with a company representative, the basis is Article 6(1)(f) GDPR: our legitimate interest in handling enquiries and business communications.

Delivering the website and preventing misuse require handling technical data such as IP address, request time and URL, and browser and error information. The basis is Article 6(1)(f) GDPR: keeping the website operational and secure.

Where correspondence becomes part of contract or billing records, we also process necessary data to perform the contract (Article 6(1)(b) GDPR) and meet legal obligations, such as accounting requirements (Article 6(1)(c) GDPR). Necessary evidence may be retained to establish, exercise or defend legal claims (Article 6(1)(f) GDPR). An enquiry does not subscribe you to a newsletter or give consent to marketing.

Providers and data recipients

OVHcloud provides our domain and email services; we use hello@framematter.pl on Zimbra. The provider processes messages, sender and recipient details, and technical information needed to deliver, store and secure email.

Cloudflare, Inc. provides Pages hosting, the form processing function, the D1 anti-spam counter database and Turnstile. The provider handles submitted form data, traffic and technical information needed to deliver and protect the service.

The controller and people authorised to handle your enquiry can access correspondence received. Data may be disclosed to technical support providers, advisers or competent authorities only where handling the matter or the law requires it. We do not sell contact details.

OVHcloud — personal data protection

Cloudflare — privacy policy

Processing outside the EEA

Cloudflare uses international infrastructure. Data submitted to the form function and technical information may be processed outside the European Economic Area, including in the United States. The provider’s documents provide for adequacy decisions, including the EU–US Data Privacy Framework for covered transfers, and standard contractual clauses where applicable.

Information about Cloudflare’s safeguards is available at the links below. You can request information and a copy of the safeguards applicable to your data by emailing hello@framematter.pl.

Cloudflare — data processing addendum

Cloudflare — standard contractual clauses

Cookies, fonts and external links

The website code does not set its own cookies or save form data in localStorage or sessionStorage. We do not use Google Analytics, Meta Pixel or advertising trackers. Fonts and animation libraries are served with the website: loading them does not require a browser connection to Google Fonts or an external library server.

Your browser may cache website files and suggest form values according to your settings. Links to projects and other services open separate websites whose operators set their own privacy rules. We do not use website data for automated decisions with legal or similarly significant effects on you, or to profile visitors.

How long data is kept

Unsent form details remain in the open page; our code does not create a persistent copy. Submission counters contain a pseudonymous, secret-key-protected digest of the IP address, an attempt count and a time window, without message contents or email addresses. Limits expire no later than the end of the hourly window. Expired records are deleted during the next rate-limit check. Technical D1 copies may remain in Cloudflare’s recovery window for up to 30 days.

We retain correspondence received while handling the enquiry and discussing cooperation. An ordinary enquiry closes after the reply and follow-up discussions are complete; a request for a proposal closes when it is declined, expires or results in a contract. Once the matter closes, we delete data that is not needed for a contract, accounting records or a specific claim.

We retain records subject to a legal obligation for the period required for the particular record, and data needed for claims until the applicable limitation period expires, taking ongoing proceedings into account. This does not mean retaining every enquiry for the full period of possible claims.

Your rights

Where the GDPR provides for it, you may request access to, rectification, erasure or restriction of processing of your data. Portability applies to data processed by automated means on the basis of a contract or consent, within the limits set by the GDPR. You may also object to processing based on legitimate interests on grounds relating to your particular situation.

Send data protection requests to hello@framematter.pl or by post to the controller’s address above. If you believe processing infringes data protection rules, you can lodge a complaint with the President of the Polish Personal Data Protection Office.

Polish Personal Data Protection Office