Privacy policy and GDPR

This policy explains in plain language what data Zetflo processes, why it is needed and what rights you have. It covers the website, contact form, AI Diagnosis, marketing communication and optional measurement tools.

Version 2.1 · effective from 28 August 2026

1. Data controller

The controller of personal data is Krzysztof Tarnas, operating under the Zetflo brand in Lublin, Poland (the “Controller”).

For data matters, email [email protected] or call +48 607 419 504.

2. Data we collect

We receive data directly from you when you submit a form, request an AI Diagnosis, contact us or voluntarily agree to marketing. Technical data is also created when you use the website and its security controls.

  • Contact form: name, email address, optional company name, message, technical submission identifier and, where present in the page URL, campaign source and UTM parameters.
  • AI Diagnosis: email address, answers about the process, optional descriptions of tools and context, diagnosis identifier, a voluntary contact request and the generated recommendation. The email address is stored only when you ask to be contacted.
  • Email marketing: email address, consent status, the dates consent was given, confirmed, withdrawn or expired, its source and the version of the consent text shown.
  • Technical and security data: IP address, request time, browser and device information, technical identifiers, error logs, anti-bot result and data required to rate-limit requests.
  • Optional analytics and marketing: page views, visit source, clicks, scrolling, approximate location, device type and conversion events — only after consent in cookie settings.
Do not submit special-category or confidential data. Do not enter health data, personal data about customers or employees, passwords, document numbers, trade secrets or confidential document content. These forms are not designed for such information.

3. Purposes and legal bases

  • Responding to enquiries and pre-contract communication: Article 6(1)(b) GDPR or Article 6(1)(f) GDPR, depending on the context.
  • Preparing and showing one requested AI Diagnosis: Article 6(1)(b) GDPR.
  • One-time contact requested after the AI Diagnosis: Article 6(1)(b) GDPR.
  • Website, form and API security and abuse prevention: Article 6(1)(f) GDPR.
  • Email marketing and optional analytics or advertising tools: Article 6(1)(a) GDPR and the applicable rules on electronic communications.
  • Contracts, accounting, tax duties and legal claims: Article 6(1)(b), (c) or (f) GDPR, as applicable.

Providing data is voluntary, but the required fields are needed to answer an enquiry or provide the AI Diagnosis. Marketing and optional cookies are never required.

4. How the AI Diagnosis works

  1. Answers are first collected in your browser. They are sent to the backend only after you enter an email address and submit the form.
  2. Selected answer categories, the result of explicit rules and an instruction for preparing the explanation may be sent to Amazon Bedrock. The model does not receive your email address, phone number, company name or optional free-text fields.
  3. The model prepares an explanation but does not change the direction selected by the system rules. Processing is designed to use AWS infrastructure and an EU geography profile.

The AI Diagnosis is an automated, initial business recommendation. It is not an audit, legal or financial advice, or a guarantee of results. It does not produce legal or similarly significant effects under Article 22 GDPR.

5. Data recipients and international transfers

Data may be processed by providers that support hosting, security, forms, email, AWS services, analytics or advertising, but only where the relevant service is configured and used. These may include Cloudflare, Amazon Web Services, Google, Microsoft and Meta, as well as accounting, legal or technical providers working within their assigned scope.

Where data is transferred outside the European Economic Area, we use a GDPR-recognised mechanism, such as an adequacy decision, the EU–US Data Privacy Framework for a certified recipient, or Standard Contractual Clauses with additional safeguards.

We do not sell personal data or provide form content to other companies for their own marketing.

6. Retention

  • Contact enquiries: normally up to 12 months after the last message, unless a contract is formed or the data is needed for legal claims.
  • One-time AI Diagnosis: if you do not request contact, your email address is not stored. The diagnosis identifier, direction, opinion and technical metadata may be retained for up to 7 days for error handling, deduplication and cost protection.
  • Requested contact after diagnosis: the email address may be stored in an encrypted record for up to 30 days.
  • Unconfirmed marketing consent: up to 48 hours. Confirmed consent remains active until withdrawal or for up to 24 months, after which renewal is required.
  • Accounting, contract and claims data: for the periods required by law or applicable limitation periods.
  • Optional analytics and advertising data: according to the configured provider and cookie lifetime.

7. Cookies and similar technologies

Essential storage remembers your privacy choice and supports secure form operation. Optional analytics and marketing tools remain disabled until you consent. You can change or withdraw your choice at any time through Cookie settings in the footer.

8. Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction or portability of your data, object to processing based on legitimate interests and withdraw consent at any time without affecting earlier lawful processing.

Email [email protected] to exercise your rights. You may also lodge a complaint with the President of the Personal Data Protection Office in Poland.

9. Security and policy changes

We use measures appropriate to the risk, including encrypted transport, restricted access, data minimisation, anti-abuse controls, backups and software updates. No internet service can guarantee absolute security.

We may update this policy when the website, services or legal requirements change. The current version is always available on this page.