Privacy policy
This site’s own code sets no cookies. Cloudflare, which protects the site against bots, may set a security cookie. Visit statistics run only with your consent.
Last updated:
Below I explain what data I process when you visit the site, write to me through the form or by e-mail, or become my client, and what rights you have. I use no advertising cookies, tracking pixels or tools that track you across sites.
1. Controller
The controller of your personal data is the individual entrepreneur trading as CODELEVEL Przemysław Bińczyk (a natural person running a sole proprietorship), Strączno 78/4, 78-642 Strączno, Poland, Polish tax ID (NIP) 7651699157, REGON 387373646, registered in the Polish Central Register and Information on Economic Activity (CEIDG) (“I”, “me”).
For anything about your data, write to jacob@codelevel.pl. Messages from the English contact form go to this address. The address given on the Polish pages belongs to the same person and business. You can also write to the postal address above.
I have not appointed a data protection officer; I am not required to (Article 37 GDPR).
2. What this policy covers
This policy covers the data I process as controller:
- when you visit codelevel.pl;
- when you send the contact form or write to me by e-mail;
- when you, or the company you work for, become my client.
It does not cover data I process in clients’ systems while providing services (for example in a client’s AWS accounts or servers). There I act on the client’s behalf as a processor, under a data processing agreement with the client (Article 28 GDPR).
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
3. What data I process, why, on what legal basis and for how long
a) Contact form
Data:
- your e-mail address (required);
- anything you choose to add: name, company or website, current infrastructure provider, the kind of help you need, monthly infrastructure cost range, planned start and a description of your situation;
- the time the form was sent.
The message that reaches me does not contain your IP address or country.
Purpose and legal basis:
| Purpose | Legal basis |
|---|---|
| Replying to your enquiry and talks before a contract, when you write on your own behalf and would be the party to the contract yourself (for example as a sole trader) | Article 6(1)(b) GDPR: steps taken at your request before entering into a contract |
| Replying to your enquiry when you write on behalf of a company (as an employee, contractor or director), or when the question is not about a contract | Article 6(1)(f) GDPR: my legitimate interest in answering enquiries and corresponding with businesses |
| Establishing, exercising or defending legal claims related to the correspondence | Article 6(1)(f) GDPR: my legitimate interest in protecting my rights |
For how long:
- if no contract follows: 12 months from the last message in the matter. After that I delete the message from the mailbox. Mail server backups are overwritten within 30 days;
- if a contract follows: as in point f below.
How the message reaches me: the form is handled by the site’s server, which runs on Cloudflare. It hands the message to the e-mail delivery provider Resend, which delivers it to my mailbox on my own server at OVH. Resend keeps a technical copy for up to 30 days. The technical sender is formularz@codelevel.pl, and my reply goes to the address you enter. After you send the form, Resend delivers one automatic confirmation with the date of my reply to that address, without the content of your message.
b) E-mail sent directly
If you write to jacob@codelevel.pl or to the address on the Polish pages, I process your e-mail address, the content of the message, attachments and the details in your signature. The purposes, legal bases and periods are the same as in point a. My mail is stored on my own server at OVH.
c) Protecting the form against bots and abuse
To keep the form from becoming a source of spam, I use:
- Cloudflare Turnstile. It loads only when you start using the form: you click or tap a field, or send the form. Scrolling the page does not start it. Cloudflare then processes your IP address, technical data about your browser and connection (including the User-Agent and TLS connection characteristics) and signals from your browser to tell whether a human is filling in the form. The site’s server sends Cloudflare the verification token from your browser and your IP address, and Cloudflare replies whether the check passed. Turnstile does not read what you type into the form.
- A rate limit. At most 5 submissions per minute from one IP address. The counter runs on Cloudflare servers and disappears after about a minute.
- A hidden field and a timestamp. Submissions filled in by bots are dropped without being sent. The IP address of such an attempt goes to the server’s technical logs.
Legal basis: Article 6(1)(f) GDPR: my legitimate interest in protecting the form, my mailbox and the site against spam and abuse.
For how long: server logs: 3 days; rate-limit counter: about 1 minute; Turnstile data: for the period set by Cloudflare.
Where Cloudflare uses Turnstile data to improve its bot detection, it is a separate controller of that data. Details: Turnstile Privacy Addendum.
d) Serving the site, hosting and security
The site is served by Cloudflare (Cloudflare Workers). Each time a page is displayed, Cloudflare processes your IP address, browser and device data (User-Agent), the address of the page, the time and the country derived from the IP address. Without this the page cannot be sent to your browser or protected against attacks.
The site has Cloudflare’s bot protection (Bot Fight Mode) turned on. To do this, Cloudflare assesses the traffic to the site and may run its bot detection script in your browser or show a security check. It then sets the security cookie cf_clearance (see section 9).
Legal basis: Article 6(1)(f) GDPR: my legitimate interest in running the site and keeping it secure.
For how long: technical logs of the form server: 3 days; Cloudflare network logs: for the period set by Cloudflare.
e) Visit statistics (only with your consent)
With your consent, the site loads the Cloudflare Web Analytics script. It sets no cookies and stores nothing in your browser. It reads page load times and technical data (the page address, the page you came from, browser and device type) from your browser and sends them to Cloudflare. Cloudflare builds no profiles and does not track you across sites. Detailed data is kept for 7 days, then only in aggregate form. I see only totals, not data about individual people.
Legal basis: your consent (Article 399(1) of the Polish Electronic Communications Law and Article 6(1)(a) GDPR). Without consent the script does not load, and the site works the same.
I ask for consent on your first visit, in a small box at the bottom of the page, with two equal buttons: “Accept” and “Reject”. Your choice is remembered in your browser (see section 9), and I ask again after 12 months. You can withdraw consent or change your choice at any time with the “Privacy settings” button in the footer of every page, without affecting the lawfulness of processing before the withdrawal.
f) Clients and clients’ contact persons
If we sign a contract, or you work for a company that is my client or counterparty, I process:
- contact and work details: first name, surname, work e-mail address, phone number, job title, company name;
- correspondence about the contract;
- billing details, if you contract in your own name (for example as a sole trader): business name, address, tax ID.
Where I get the data: from you, or from the company you work for or represent (for example when it names you as a contact person).
| Purpose | Legal basis |
|---|---|
| Entering into and performing a contract with you | Article 6(1)(b) GDPR |
| Contacting you as a person named by a client or counterparty | Article 6(1)(f) GDPR: my legitimate interest in performing the contract with the company you represent |
| Invoicing and tax records | Article 6(1)(c) GDPR: obligations under Polish tax and accounting law |
| Establishing, exercising or defending legal claims | Article 6(1)(f) GDPR |
For how long:
- correspondence and contact details: for the term of the contract and 3 years after it ends, counted to the end of the calendar year (the limitation period for claims related to business activity under Polish law), and, if there is a dispute, until it ends;
- invoices and accounting records: 5 years from the end of the calendar year in which the tax payment deadline passed.
g) Your requests about your data
When you exercise the rights described in section 6, I keep the correspondence about it to show how I handled it. Legal basis: Article 6(1)(c) GDPR in connection with Article 5(2) GDPR (accountability). Period: 3 years after the matter is closed.
4. Who receives the data
I do not sell data or share it for marketing. Data goes only to providers that help me run the site and the business:
| Recipient | Scope | Role |
|---|---|---|
| Cloudflare, Inc. (USA) | serving the site, bot protection, the form server, technical logs, rate limiting, Turnstile, Web Analytics statistics (only with your consent) | processor; for the part of Turnstile used to improve bot detection: separate controller |
| Plus Five Five, Inc., doing business as Resend (USA) | delivering form messages to my mailbox | processor |
| OVH (OVHcloud) | the server that runs my e-mail | processor |
| bookkeeping (an accounting office or invoicing software) | only client data needed for invoices and bookkeeping | processor |
| banks, payment providers | only when settling with clients | separate controllers |
| public authorities | only where the law requires it | separate controllers |
Processors act under data processing agreements (Article 28 GDPR) and may use their own sub-processors on the terms of those agreements.
5. Transfers outside the European Economic Area
Cloudflare and Resend are based in the USA, so some data is transferred to the USA:
- Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework. The transfer relies on Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection (Article 45 GDPR) and, in addition, on the standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR) in Cloudflare’s data processing agreement.
- Plus Five Five, Inc. (Resend) stores account data, including message metadata and logs, in the USA, whatever region it sends from. The transfer relies on the standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR) in Resend’s data processing agreement.
You can get a copy of these safeguards (the standard contractual clauses) by writing to the address in section 1. They are also part of the providers’ data processing agreements: Cloudflare, Resend.
6. Your rights
You have the right to:
- access your data and get a copy (Article 15 GDPR);
- rectification (Article 16 GDPR);
- erasure (Article 17 GDPR);
- restriction of processing (Article 18 GDPR);
- data portability for data I process under a contract, steps before one, or your consent (Article 20 GDPR);
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal (Article 7(3) GDPR); for the statistics, use the “Privacy settings” button in the footer;
- lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, or with the supervisory authority in the EU country where you live or work (Article 77 GDPR).
To exercise your rights, write to jacob@codelevel.pl. I will reply without undue delay and within one month at the latest. In exceptional cases this can be extended by two further months; I will then tell you why (Article 12(3) GDPR). I may ask for information needed to confirm that the request comes from you.
Right to object
You have the right to object at any time, on grounds relating to your particular situation, to processing of your data based on my legitimate interest (Article 6(1)(f) GDPR) (Article 21(1) GDPR). After an objection I will stop processing that data unless I show compelling legitimate grounds that override your interests, rights and freedoms, or the data is needed to establish, exercise or defend legal claims. I do not process data for direct marketing.
7. Do you have to provide data
Providing data is voluntary; no law requires it. Without an e-mail address, however, I cannot reply to the form. The other fields are optional and help me prepare a useful reply. If we sign a contract, billing details are needed to conclude and settle it, and tax law requires them.
8. Automated decisions
I do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you (Article 22 GDPR). Turnstile automatically assesses whether a human is filling in the form and may block the submission. You can then always write directly to jacob@codelevel.pl.
9. Your device: cookies, browser storage and scripts
Polish law (Article 399 of the Electronic Communications Law of 12 July 2024, implementing Article 5(3) of the ePrivacy Directive) requires consent to store information on your device or read it from there, unless this is strictly necessary to transmit the page or to provide a service you asked for. Without your consent the site uses only such necessary mechanisms:
| Mechanism | What it does | When | How long |
|---|---|---|---|
Browser storage (localStorage), key consent | remembers your choice about the statistics (accepted or rejected) and its date. Contains no identifier and is never sent anywhere | when you click “Accept” or “Reject” | 12 months, then I ask again |
| Cloudflare Turnstile (script from challenges.cloudflare.com) | reads signals from the browser to tell a human from a bot (see section 3c). In this configuration it sets no cookies | only when you start using the form | the verification token is single-use and valid for a few minutes |
Security cookie cf_clearance (sometimes also __cf_bm), set by Cloudflare | confirms that your browser passed the bot protection check (Bot Fight Mode) or a security check, so Cloudflare does not check it on every request. Cloudflare sets it, not the site’s code | when Cloudflare checks the browser or shows a security check | usually 15 to 30 minutes |
| Browser cache and HSTS | the browser stores site files so pages load faster, and remembers that the site works only over HTTPS | every visit | per your browser settings; HSTS 2 years |
Only with your consent: the Cloudflare Web Analytics script (from static.cloudflareinsights.com), described in section 3e. It stores nothing on your device; it reads technical data and page load times.
The site’s own code sets no cookies. The only cookies that may appear are set by Cloudflare for security. I use no advertising or analytics cookies, tracking pixels or tools that track you across sites.
The calculator, the “Are you overpaying for AWS?” quiz and the CSV analysis run entirely in your browser. Calculator inputs and quiz answers live only in the page address (after the # sign). The CSV file is not sent or stored anywhere.
You can clear stored data at any time in your browser settings (for example “Clear site data”) or block sites from storing data. The site will still work; it just will not remember your choice about the statistics. If you block all cookies, Cloudflare’s security check may fail and the site may not open.
Personal data read this way (such as your IP address and Turnstile signals) is processed as described in sections 3c, 3d and 3e.
10. Security
The site works only over HTTPS, and the form sends data encrypted.
11. Changes to this policy
I update this policy when the site, its providers or the law change. The current version is always at https://codelevel.pl/en/privacy/, with the date of the last update at the top. If a significant change affects ongoing correspondence, I will tell you by e-mail.
Polish version: codelevel.pl/polityka-prywatnosci/. Both versions have the same content.