Privacy Policy
Version 2.0 · Effective 26 July 2026 · Applies to the crocodata.net website
This site collects almost nothing. No cookies, no analytics, no tracking — the only personal data we handle is what you choose to send us when you get in touch.
Who we are
This website is operated by Crocodata sp. z o.o., Warsaw, Poland (KRS 0001241145, NIP 7582407044, REGON 544746646). We are the data controller for the processing described here. Full statutory details: Legal Notice.
Privacy and data-protection requests: privacy@crocodata.net. General enquiries: contact@crocodata.net.
What this policy covers
This policy covers personal data processed through the Crocodata company website. Our mobile apps have their own separate policies, because they process different data:
If you are outside the EU/EEA, see also Regional privacy rights — United States, United Kingdom, Switzerland, Brazil, Canada, Australia, South Korea, India and others.
What we process, why, and on what basis
| Data | Purpose | Legal basis (Art. 6 GDPR) | Retention |
|---|---|---|---|
| Name, email address, optional company name, message — when you use the contact form or email us | Responding to your enquiry and following up on a possible project | Art. 6(1)(b) — steps prior to a contract; or Art. 6(1)(f) — legitimate interest in answering business enquiries | Up to 24 months from last contact, then deleted, unless a contract follows |
| Language preference | Remembering the language you chose | Stored locally in your browser only (localStorage); strictly necessary for a function you requested, so no consent is required under Art. 5(3) ePrivacy Directive | Until you clear your browser storage |
| Server and CDN logs (IP address, user agent, page requested, timestamp) | Delivering the site, security, abuse prevention, reliability | Art. 6(1)(f) — legitimate interest in a secure, working website | Per our hosting and CDN providers' standard log retention; never used for profiling |
How the contact form actually works
The contact form does not send anything to our servers. When you press Send message, your browser composes a pre-filled email in your own mail application addressed to contact@crocodata.net. Nothing is transmitted until you send that email yourself, and we receive only what you choose to send. There is no form-handling service, no database and no third-party form processor.
Cookies, analytics and tracking
This site uses no cookies, no analytics and no third-party tracking. No advertising pixels, no session recording, no cross-site tracking. We therefore show no cookie banner, because there is nothing to consent to. Web fonts are loaded from Google Fonts, which means your browser contacts a Google server and Google receives your IP address for that request; we do not receive it. If we ever add analytics, we will update this policy and ask for consent where the law requires it.
Who else is involved
| Provider | Role | Location & safeguards |
|---|---|---|
| Google Ireland Ltd / Google LLC — Firebase Hosting | Website hosting | EU and USA · Art. 28 DPA, EU Standard Contractual Clauses, EU–US Data Privacy Framework |
| Cloudflare, Inc. | DNS, CDN, and email routing for our @crocodata.net addresses | Global · Art. 28 DPA, EU Standard Contractual Clauses |
| Google Fonts | Web font delivery | Requested directly by your browser; Google receives your IP for that request |
We do not sell personal data and we do not share it for advertising.
International transfers
Some providers above are established in, or transfer data to, the United States. Those transfers rely on the EU Standard Contractual Clauses under Art. 46 GDPR and, where applicable, on the provider's certification under the EU–US Data Privacy Framework. We have assessed these transfers and keep the assessment on file.
Your rights (GDPR)
If you are in the EU/EEA you may request access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18) and portability (Art. 20), and you may object to processing based on legitimate interest (Art. 21). Write to privacy@crocodata.net; we reply within one month.
You may also lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl — or with the authority in your own country.
Automated decisions and AI
This website makes no automated decisions about you and does not profile you. Where our apps use AI, that is described in each app's own privacy policy and terms.
Children
This is a business website aimed at organisations and professionals. It is not directed at children and we do not knowingly collect their data.
Security
The site is served over HTTPS. To report a security issue, see our security and vulnerability disclosure policy.
Changes
We may update this policy. The version number and effective date above change when we do. Material changes are highlighted on this page.
Change log
- v2.0 — 26 July 2026: added legal-basis and retention table, all four app policies, processor list, transfer basis, regional-rights link, security and AI sections; clarified how the contact form works.
- v1.0 — June 2026: first published.
© 2026 Crocodata sp. z o.o. · Spółka z ograniczoną odpowiedzialnością · KRS 0001241145 · NIP 7582407044