Privacy policy.
Last updated: 11 October 2026.
Data controller
FrameMatter operates within PIEKARNIA ZAKLIKÓW - KRZYSZTOF WIERZBIŃSKI. The personal data controller is Krzysztof Wierzbiński, who operates this business.
Address: ul. Wesoła 1/1A, 37-470 Zaklików. Polish tax identification number (NIP): 8621001922. Business register number (REGON): 830449499.
Privacy contact: hello@framematter.pl.
Form and email contact
When you select “Send message”, the form sends your name, email address, optional company name, selected services and project description to a server function at Cloudflare. The server validates the details and the anti-spam verification result. Typing a message does not send its contents to our mailbox.
After successful checks, your enquiry is sent over an encrypted mail connection to hello@framematter.pl, hosted by OVHcloud Zimbra. We do not store the form contents in the website database or its own application logs. You can also email this address directly.
Providing information is voluntary. Sending the form requires your name, email address and project description; company name and service selection are optional. Without contact details, we may be unable to reply. Do not include sensitive data, national identification numbers, passwords or unnecessary information about other people.
Validation and anti-spam checks do not establish the sender’s identity or authority to represent a company. Where needed, we confirm arrangements directly with an authorised person.
Spam protection
The form uses Cloudflare Turnstile. Verification starts as you approach or interact with the form. Cloudflare analyses signals including IP address, browser and connection characteristics, and the site identifier. Our legal basis is our legitimate interest in preventing abuse (Article 6(1)(f) GDPR).
Cloudflare acts as a processor when protecting our form and as a separate controller when improving bot detection. Our verification request contains no message contents or email address. The document below describes Cloudflare’s processing.
We do not use Turnstile pre-clearance, which issues the cf_clearance cookie. A verification token is single-use and valid for up to five minutes; this is not the retention period for all data handled by Cloudflare. You can send a regular email instead of using the form.
Purposes and legal bases
We use information received in correspondence to answer questions, understand your needs and prepare proposals. When you request steps before entering into a contract on your own behalf, the basis is Article 6(1)(b) GDPR. For other matters, including contact with a company representative, the basis is Article 6(1)(f) GDPR: our legitimate interest in handling enquiries and business communications.
Delivering the website and preventing misuse require handling technical data such as IP address, request time and URL, and browser and error information. The basis is Article 6(1)(f) GDPR: keeping the website operational and secure.
Where correspondence becomes part of contract or billing records, we also process necessary data to perform the contract (Article 6(1)(b) GDPR) and meet legal obligations, such as accounting requirements (Article 6(1)(c) GDPR). Necessary evidence may be retained to establish, exercise or defend legal claims (Article 6(1)(f) GDPR). An enquiry does not subscribe you to a newsletter or give consent to marketing.
Providers and data recipients
OVHcloud provides our domain and email services; we use hello@framematter.pl on Zimbra. The provider processes messages, sender and recipient details, and technical information needed to deliver, store and secure email.
Cloudflare, Inc. provides Pages hosting, the form processing function, the D1 anti-spam counter database and Turnstile. The provider handles submitted form data, traffic and technical information needed to deliver and protect the service.
The controller and people authorised to handle your enquiry can access correspondence received. Data may be disclosed to technical support providers, advisers or competent authorities only where handling the matter or the law requires it. We do not sell contact details.
Processing outside the EEA
Cloudflare uses international infrastructure. Data submitted to the form function and technical information may be processed outside the European Economic Area, including in the United States. The provider’s documents provide for adequacy decisions, including the EU–US Data Privacy Framework for covered transfers, and standard contractual clauses where applicable.
Information about Cloudflare’s safeguards is available at the links below. You can request information and a copy of the safeguards applicable to your data by emailing hello@framematter.pl.
How long data is kept
Unsent form details remain in the open page; our code does not create a persistent copy. Submission counters contain a pseudonymous, secret-key-protected digest of the IP address, an attempt count and a time window, without message contents or email addresses. Limits expire no later than the end of the hourly window. Expired records are deleted during the next rate-limit check. Technical D1 copies may remain in Cloudflare’s recovery window for up to 30 days.
We retain correspondence received while handling the enquiry and discussing cooperation. An ordinary enquiry closes after the reply and follow-up discussions are complete; a request for a proposal closes when it is declined, expires or results in a contract. Once the matter closes, we delete data that is not needed for a contract, accounting records or a specific claim.
We retain records subject to a legal obligation for the period required for the particular record, and data needed for claims until the applicable limitation period expires, taking ongoing proceedings into account. This does not mean retaining every enquiry for the full period of possible claims.
Your rights
Where the GDPR provides for it, you may request access to, rectification, erasure or restriction of processing of your data. Portability applies to data processed by automated means on the basis of a contract or consent, within the limits set by the GDPR. You may also object to processing based on legitimate interests on grounds relating to your particular situation.
Send data protection requests to hello@framematter.pl or by post to the controller’s address above. If you believe processing infringes data protection rules, you can lodge a complaint with the President of the Polish Personal Data Protection Office.