Now booking enterprise content platform builds for 2026. Contact us

Legal

Privacy notice

Last updated 5 August 2026

This notice describes how WAYF Digital sp. z o.o. handles personal data processed through this website — the contact form, the call-booking embed, the anti-spam challenge, and the analytics layer. We collect the minimum we need to reply, and we share it only with the sub-processors named below. Personal data WAYF processes as a processor on behalf of a paying client during a delivery engagement is governed by a separate, signed DPA — not by this page.

  1. 01

    Who controls the data

    The data controller for personal data processed via this website is WAYF Digital sp. z o.o., registered at the address shown at the foot of this page. The GDPR contact for data-protection matters can be reached at the address revealed on click below.

  2. 02

    What this notice covers

    This notice covers personal data WAYF processes through this website — what visitors send via the contact form, what the booking embed captures, what gets logged when you load a page, what the anti-spam check passes to Cloudflare.

    It does NOT cover personal data WAYF processes as a data processor on behalf of a paying client during a delivery engagement. That processing is governed by a separate data processing agreement (DPA) signed at the start of the engagement, not by this page.

  3. 03

    What we collect

    From the contact form at /contact — when you submit it: name, work email, the message you write, the NDA opt-in preference (a yes/no flag), and any file you choose to attach. The submission is delivered to the WAYF inbox via Resend and stored there for the duration set out in section 06.

    From the Cloudflare Turnstile anti-spam check on the contact form: a challenge response token, your IP address, and the standard browser fingerprint Turnstile uses to score the request. The token is verified server-side and not retained.

    From the cal.com booking embed at /contact#book-a-call — when you schedule a call: name, email, scheduled time, time zone, and any message you add in the cal.com form. Cal.com processes this on WAYF's behalf and the calendar event is delivered to the WAYF team's calendar.

    From visiting this website (any page): pseudonymous traffic and interaction data, including pages viewed, browser, country, referrer, request timing, session identifiers, reading engagement, and interactions with calls to action. No third-party advertising cookies, no behavioural advertising, and no cross-site tracking.

    After a contact form submission succeeds, PostHog also receives the submitted work email as the analytics identity, a filtered and length-limited copy of the message, its character and word counts, the form language and page, the NDA preference, and whether an attachment was included. Common email addresses, web addresses, and phone numbers are removed from the analytics copy. When the NDA option is selected, the message copy is not sent to PostHog. Attachment contents and filenames are not sent to PostHog.

  4. 04

    Why we collect it

    Contact form data is used to read your message and reply to it. Legal basis: GDPR Art. 6(1)(b) (steps taken at the request of the data subject prior to entering into a contract) and Art. 6(1)(f) (legitimate interest in responding to inbound enquiries).

    Turnstile data is used to block automated form abuse. Legal basis: Art. 6(1)(f) (legitimate interest in keeping the contact channel usable for humans).

    Cal.com booking data is used to schedule, confirm, and run the booked call. Legal basis: Art. 6(1)(b) (the booking is the start of a possible engagement) and Art. 6(1)(f) (operating the scheduling channel).

    Analytics data is used to understand how the site is used, which pages contribute to enquiries, and which recurring needs or content gaps appear in successful contact submissions. It is not used for automated decision-making. Legal basis: Art. 6(1)(f) (legitimate interest in operating and improving the website and responding effectively to inbound enquiries).

  5. 05

    Who we share it with

    WAYF does not sell or rent personal data. Data is shared only with sub-processors that are necessary to operate the website and that have been reviewed for GDPR compliance.

    Current sub-processors used by this website: Resend (delivers email notifications from the contact form, including any attachment), Cloudflare (hosts and serves this website, and runs the Turnstile anti-spam check on the contact form), Cal.com (handles the 25-minute call bookings made from /contact), and PostHog Cloud EU (provides website analytics, session replay with form inputs masked, and analysis of successful contact submissions).

    Engagement-specific sub-processors — used when WAYF is acting as a data processor under a signed contract with a client — are listed in the relevant DPA, not on this page.

  6. 06

    How long we keep it

    Contact form messages: retained while the conversation is active and for up to 24 months afterwards, unless we agree differently with you in writing.

    Files attached to a contact form submission: retained alongside the message they were sent with, on the same 24-month schedule. Deleted earlier on request.

    Cal.com booking data: retained in the calendar for as long as the appointment is relevant (typically through the meeting and a short follow-up window).

    Turnstile challenge data: not retained by WAYF; processed transiently by Cloudflare per their own retention schedule.

    PostHog session recordings are retained for 30 days. Other analytics events, including the filtered contact-submission analysis copy, follow the PostHog project retention schedule, currently up to 84 months. Data may be deleted earlier in response to a valid data-subject request.

  7. 07

    Your rights

    Under GDPR (and the Polish RODO act that implements it) you have the right to access the personal data we hold about you (Art. 15), correct inaccurate data (Art. 16), erase data subject to legal retention obligations (Art. 17), restrict processing (Art. 18), receive your data in a portable format (Art. 20), object to processing based on legitimate interest (Art. 21), and withdraw consent where consent is the legal basis.

    You also have the right to lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw.

    Requests should be sent to the data-protection address revealed on click below. We reply within 30 days, as required by GDPR Art. 12(3).

  8. 08

    Cookies and analytics

    This site uses PostHog Cloud EU through a same-origin relay. PostHog uses a first-party identifier to connect visits and, after a successful contact submission, associate the journey with the submitted work email. Form inputs are masked in session recordings. No marketing or advertising cookies are set, and the data is not used for cross-site advertising. If we add anything in the future that requires consent under ePrivacy rules, a cookie banner will appear before the relevant cookie is set.

  9. 09

    International transfers

    Where a sub-processor (e.g. Resend, Cloudflare) processes data outside the European Economic Area, the transfer is covered by appropriate safeguards under GDPR Chapter V (Standard Contractual Clauses or equivalent). Details are available on request at the address revealed below.

  10. 10

    Changes to this notice

    WAYF may update this notice as the website evolves. The current version is always at this URL and the date at the top of the page is the date of the most recent change. Continuing to use the site after a change means you accept the updated notice.

  11. 11

    Contact

    For privacy or data-protection questions, write to the address revealed below, or use the form on the contact page.


Data controller
WAYF DIGITAL SP. Z O.O.
Złota 75A/7
00-819 Warsaw, Poland
VAT-EU (NIP)
PL7831824606
REGON
387099056
KRS
0000861621