Policy Privacy:
Last updated: 31.07.2026
1. General Provisions
a) This Privacy Policy sets out the rules for processing and protecting personal data of persons using the Afixo website, contacting the Contractor, and using services provided by the Contractor.
b) In particular, this Privacy Policy specifies:
– what personal data is collected,
– for what purposes it is processed,
– on what legal basis it is processed,
– how long the data is stored,
– to whom it may be disclosed,
– what rights are available to data subjects.
c) The controller of personal data is Artur Przybył, operating under the name Afixo (hereinafter: the “Controller” or the “Contractor”).
d) The Controller may be contacted regarding personal data matters via:
– general e-mail address: contact@afixo.pl,
– e-mail address for matters concerning Orders: orders@afixo.pl.
e) The Controller processes personal data in accordance with:
– Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter: the “GDPR”),
– the Polish Act of 10 May 2018 on the Protection of Personal Data,
– other applicable laws concerning personal data protection.
f) The Controller applies the principle of data minimisation, which means that it collects only such data as is necessary for specified purposes.
g) Detailed rules concerning fulfilment of Orders, cooperation, payments, copyright, and archiving of materials related to Orders are set out in the Order Terms and Conditions available on the Afixo website.
2. Definitions
a) Controller / Contractor / Afixo – Artur Przybył, providing services specified in the Order Terms and Conditions and responsible for processing personal data.
b) Client – a natural person, company, or other entity contacting the Controller or using Afixo services.
c) User – any person using the Afixo website or contacting the Controller.
d) Personal Data – information relating to an identified or identifiable natural person.
e) Order – an individually agreed service performed by the Contractor for the Client.
f) Materials – all content provided by the Client for the purpose of fulfilling an Order, in particular texts, files, graphics, descriptions, sketches, documentation, and materials relating to worldbuilding.
g) Client Code – an individual identifier assigned to a specific Client, recorded in the format C-XXXX, where XXXX represents a randomly generated four-digit number.
h) Order Code – an individual identifier assigned to a specific Order, recorded in the format O-XXXX, where XXXX represents a randomly generated four-digit number.
i) Archiving – temporary storage of data or materials after completion or cancellation of an Order.
j) Subcontractor – a person or entity occasionally cooperating with the Controller in carrying out part of an Order.
k) Cookies – small files stored on a User’s device while using the website.
3. Personal Data Controller
a) The controller of all personal data processed in connection with Afixo’s activities is Artur Przybył.
b) The Controller independently determines the purposes and means of processing personal data.
c) The Controller has not appointed a Data Protection Officer because, under applicable law, the Controller is not required to appoint one.
d) The Controller may use services of external technical service providers supporting operation of the website, electronic mail, data storage, or fulfilment of Orders.
e) The Controller does not sell personal data or disclose it to third parties for marketing purposes.
4. Scope of Personal Data Processed
a) The Controller may process the following personal data:
– name or first and last name provided by the User,
– e-mail address,
– contact details voluntarily provided by the User,
– content of messages,
– files submitted through the contact form,
– information relating to an Order,
– information concerning payments and settlements,
– data contained in materials provided by the Client,
– data relating to submission of a review.
b) When fulfilling an Order, the Controller may store additional information necessary for its performance, in particular:
– description of the Order,
– scope of work,
– agreed price,
– completion deadlines,
– provided materials,
– information concerning the course of cooperation.
c) The Controller may create internal organisational notes concerning cooperation with the Client.
d) Organisational notes may contain only information relating to cooperation, such as:
– order history,
– communication preferences,
– arrangements concerning cooperation,
– organisational information, such as country or time zone relevant to communication,
– information concerning timeliness,
– information concerning the course of communication.
e) The Controller does not record in organisational notes any special categories of personal data referred to in Article 9 of the GDPR, in particular information concerning health, political opinions, religion, philosophical beliefs, sexual orientation, or other data unrelated to performance of the cooperation.
f) Organisational notes are intended exclusively for internal use by the Controller and are not disclosed to third parties, except where required by law.
5. Purposes and Legal Bases for Data Processing
a) Personal data is processed only for specified and legally justified purposes.
b) The Controller processes personal data in particular for the purposes of:
– contacting the User,
– responding to messages and enquiries,
– preparing a quotation,
– fulfilling Orders,
– maintaining documentation concerning cooperation,
– processing payments,
– providing technical support,
– handling complaints and claims,
– maintaining a portfolio,
– ensuring website security,
– compiling website traffic statistics.
c) Legal bases for processing personal data include in particular:
– Article 6(1)(b) GDPR – processing necessary for performance of a contract or to take steps prior to entering into a contract,
– Article 6(1)(c) GDPR – processing necessary for compliance with legal obligations to which the Controller is subject,
– Article 6(1)(f) GDPR – legitimate interests pursued by the Controller, in particular maintaining documentation concerning cooperation, protection against claims, ensuring security, and organisation of work,
– Article 6(1)(a) GDPR – consent of the User, where such consent is required, in particular in connection with publication of reviews or use of certain cookies.
d) Provision of data required for fulfilment of an Order is voluntary; however, failure to provide such data may make it impossible to perform the service or provide a response.
6. Processing of Data During Contact
a) Contact with the Controller may take place through:
– the contact form available on the website,
– electronic mail,
– agreed communication channels used during fulfilment of an Order,
– other methods of contact accepted by the parties.
b) The contact form requires provision of:
– name,
– e-mail address,
– message subject,
– message content.
c) Submission of files through the contact form is voluntary and serves solely to provide additional materials relating to the enquiry.
d) Data submitted during ordinary contact that does not result in commencement of cooperation or placement of an Order is not copied to the Controller’s internal data storage system.
e) Messages sent by electronic mail or through the form may remain stored in relevant communication systems, such as an e-mail inbox or form management system, for the period resulting from operation of those systems and from the Controller’s needs relating to correspondence management.
f) The Controller uses data from correspondence solely for the purposes of:
– responding to the message,
– conducting further arrangements,
– handling the enquiry,
– preserving the ability to demonstrate the course of communication.
7. Processing of Data Relating to Orders
a) When cooperation begins, the Controller creates individual documentation for the Order.
b) Order documentation may include:
– Client Code,
– Order Code,
– Client name,
– contact details,
– description of the Order,
– project arrangements,
– price,
– completion deadlines,
– information concerning the course of cooperation,
– materials provided by the Client,
– materials created by the Controller or Subcontractors.
c) Client Codes and Order Codes are used exclusively for organisation of work and identification of specific persons or projects, in particular when providing technical support, carrying out archiving, or resuming contact.
d) A Client Code or Order Code alone is not intended for public identification of a person and does not contain direct information enabling identification of the Client.
e) The Controller stores documentation concerning the Client and the Order in a secured location on a working drive.
f) Access to documentation is available exclusively to the Controller, unless disclosure of part of the information is necessary to fulfil the Order in accordance with the rules set out in this Privacy Policy.
8. Processing of Materials Relating to an Order
a) In connection with fulfilment of an Order, the Controller may store:
– materials provided by the Client,
– materials prepared by the Controller,
– materials created by Subcontractors,
– working files,
– project versions,
– final files.
b) Materials relating to an Order are stored:
– on the working drive during fulfilment of the Order,
– for 7 calendar days following completion of the Order,
– subsequently for 14 calendar days in the archive.
c) In the event of payment problems, lack of contact from the Client, premature termination of cooperation, or other situations described in the Order Terms and Conditions, materials may be transferred directly to the archive.
d) The period for which materials are stored on the working drive may be extended by the time necessary to make changes or provide technical support specified in the Order Terms and Conditions.
e) After expiry of the archiving period, materials may be permanently deleted.
f) The Controller may retain selected materials created independently by the Controller or with participation of Subcontractors for a longer period where necessary for maintaining a portfolio.
g) Materials retained as part of the portfolio do not include:
– confidential information concerning the Client,
– Client personal data not required for presentation of the project,
– non-public information concerning the Client’s project, lore, or creative concepts.
9. Personal Data Retention Period
a) The Controller stores personal data only for the period necessary to achieve the specified purposes.
b) Data concerning Clients and Orders, in particular:
– Client name,
– contact details,
– information concerning Orders,
– history of cooperation,
– organisational information,
– notes concerning cooperation,
is stored:
– until receipt of an effective request for deletion of the data,
– or for a maximum of 24 months following completion of the most recent Order.
c) The data retention period may be shortened where the data is no longer necessary for the purpose for which it was collected.
d) The data retention period may be extended where required by law or necessary for establishment, exercise, or defence of legal claims.
e) Placement of another Order by the same Client starts a new data retention period calculated from completion of the most recently fulfilled Order.
f) Data contained in settlement-related documents is stored for the period required by applicable law.
g) Data contained in backup copies may be deleted through automatic overwriting in accordance with the backup cycle.
10. Subcontractors and Data Disclosure
a) The Controller may occasionally use support from trusted Subcontractors when carrying out part of an Order.
b) Subcontractors receive only information and materials necessary to perform the scope of work entrusted to them.
c) As a rule, Subcontractors do not receive data identifying the Client, such as name, e-mail address, or other contact details.
d) If disclosure of Client data proves necessary for proper fulfilment of an Order, the Controller will inform the Client before commencement of the relevant work.
e) Subcontractors are required to maintain confidentiality regarding the project and Client Materials.
f) Subcontractors delete received data relating to the Order and Client data, with the exception of materials created by them as part of the project, no later than within 7 business days following completion of the entrusted work.
g) Business days are understood as Monday through Friday, excluding Saturdays, Sundays, public holidays, and other days recognised as non-working days under applicable law.
11. Recipients of Personal Data
a) Personal data may be disclosed only to entities that require access to the data for proper operation of the Controller’s services or performance of legal obligations.
b) Recipients of personal data may include in particular:
– hosting service providers,
– electronic mail service providers,
– providers of technical tools used to operate the website,
– analytics tool providers,
– Subcontractors participating in fulfilment of Orders,
– entities providing accounting or legal services, where their involvement is necessary,
– public authorities where an obligation to disclose data results from applicable law.
c) The Controller uses in particular the following services:
– SeoHost – website hosting and related services,
– DirectAdmin – electronic mail management,
– WordPress – website content management system,
– Forminator – contact form management,
– CookieYes – management of cookie consent,
– Google Analytics 4 – statistical analysis of website traffic,
– Google reCAPTCHA v2 – protection of forms against automated submissions.
d) Data may be transferred to service providers outside the European Economic Area where use of a given service involves such transfer.
e) When personal data is transferred outside the European Economic Area, the Controller applies appropriate mechanisms required by the GDPR, in particular adequacy decisions of the European Commission or Standard Contractual Clauses.
12. Transfer of Data to Google
a) The Controller uses Google services, in particular Google Analytics 4 and Google reCAPTCHA v2.
b) Google Analytics 4 is used exclusively for statistical purposes relating to analysis of website usage.
c) The Controller does not use Google Analytics to create individual User profiles or make decisions concerning specific individuals.
d) Before consent is given for use of analytical cookies, analytics tools are restricted in accordance with settings of the consent management system.
e) Google reCAPTCHA v2 is used to protect forms against automated submissions and abuse.
f) Detailed information concerning how Google processes data is available in Google’s documentation and privacy policy.
13. Rights of Data Subjects
a) Every person whose data is processed by the Controller has rights arising from the GDPR.
b) A data subject may in particular request:
– access to their personal data,
– information concerning the manner in which it is processed,
– receipt of a copy of their data,
– rectification of inaccurate or outdated data,
– erasure of data,
– restriction of data processing,
– data portability, where possible under applicable law,
– objection to processing based on the legitimate interests pursued by the Controller,
– withdrawal of consent previously given for data processing.
c) Withdrawal of consent does not affect lawfulness of processing carried out before its withdrawal.
d) The right to erasure is not absolute. The Controller may refuse to erase data where continued storage is required by law or is necessary for establishment, exercise, or defence of legal claims.
e) Where erasure is requested, the Controller may delete data from its working systems, subject to rules concerning backup copies and legal obligations.
f) A data subject has the right to lodge a complaint with the supervisory authority competent in matters of personal data protection.
g) In Poland, the supervisory authority is:
Personal Data Protection Office.
14. Exercise of User Rights
a) Requests concerning personal data should be sent to the following e-mail address: contact@afixo.pl
b) In matters directly connected with an ongoing or planned Order, contact may also be made through: orders@afixo.pl
c) The Controller may request additional information allowing confirmation of the identity of the person submitting the request where necessary to protect personal data.
d) The Controller makes efforts to respond to a request within 14 business days.
e) Where the nature of a request requires additional analysis or other circumstances provided for by law occur, a response will be provided within the period required by the GDPR, no later than within one month of receipt of the request.
f) Business days are understood as Monday through Friday, excluding Saturdays, Sundays, public holidays, and other non-working days under applicable law.
15. Reviews and Publication of Data
a) The Controller allows Clients to voluntarily submit reviews concerning cooperation.
b) Data relating to a review may be submitted through a form available on the website or through another agreed communication channel.
c) A review may include:
– name provided by the Client,
– title,
– content of the review,
– rating on a scale from 1 to 5,
– profile picture, where voluntarily provided.
d) The default title of a review is “Satisfied Client”, unless the Client provides their own title.
e) Publication of a review together with Client data takes place only after the Client has given voluntary consent.
f) Consent to publication of a review may be withdrawn at any time.
g) The Client may request deletion of a published review or selected data associated with the review by contacting the Controller.
h) Deletion of a review does not affect lawfulness of earlier publication carried out on the basis of consent previously given.
16. Portfolio and Presentation of Completed Materials
a) The Controller may store and present selected results of its work as part of a portfolio.
b) The portfolio may in particular be published:
– on the Afixo website,
– on social media,
– in presentation materials,
– during discussions with potential Clients,
– in recruitment or professional processes,
– in other situations connected with presentation of experience and completed work.
c) The Controller may publish only materials in respect of which it holds appropriate rights or permission for their use.
d) The Controller does not publish in the portfolio:
– confidential information provided by the Client,
– non-public project concepts,
– detailed lore or Client project documentation,
– Client personal data where it is not necessary for presentation of the project.
e) Where the nature of a project or arrangements with the Client require restrictions on publication, the Controller respects individual confidentiality rules agreed before commencement of the Order.
f) Publication of materials in the portfolio may take place on the basis of the Controller’s legitimate interest consisting in presentation of its own activities and professional experience.
g) The Client may contact the Controller regarding restriction or removal of materials presented in the portfolio where there are justified grounds resulting from arrangements between the parties or applicable law.
17. Cookies
a) The Afixo website uses cookies and similar technologies to ensure proper operation of the website and analyse its use.
b) Cookies are small files stored on the User’s device while using the website.
c) The Controller uses the following types of cookies:
– technical cookies – necessary for proper operation of the website,
– analytical cookies – used for statistical analysis of website traffic.
d) The Controller does not use cookies for:
– creation of individual advertising profiles,
– tracking Users for marketing purposes,
– automated decision-making concerning Users.
e) Analytics data is used exclusively to check basic information concerning use of the website, such as:
– number of visits,
– manner in which the website is used,
– general statistical information concerning Users.
f) Google Analytics 4 may process, among other things, information concerning:
– website visits,
– source from which the website was accessed,
– country or region from which the website was accessed,
– basic technical information concerning the device.
g) The Controller restricts use of analytical cookies until the User gives appropriate consent, in accordance with operation of the cookie consent management system.
h) The User may change cookie settings at any time through the consent management panel available on the website or through browser settings.
i) Disabling certain cookies may affect some website functions.
18. Forms and Technical Security Measures
a) Forms available on the website are intended to enable contact with the Controller and handling of enquiries.
b) The Controller uses Google reCAPTCHA v2 to limit automated submissions and protect forms against abuse.
c) The contact form allows files to be submitted in accordance with current technical limitations of the website.
d) Submitted files may contain personal data; therefore, the User should provide only materials necessary to achieve the purpose of contact or fulfilment of the Order.
e) The Controller applies appropriate technical and organisational measures intended to protect personal data against:
– accidental loss,
– unauthorised access,
– alteration,
– disclosure,
– destruction.
f) In particular, the Controller uses:
– secured devices and data storage systems,
– restricted access to data,
– regular website backups,
– updates to software in use.
g) The Controller performs regular website backups at least once per month.
h) Backup copies are used to restore operation of the website in the event of a failure or data loss.
i) Data contained in backup copies is subject to the same protection rules as data contained in primary storage systems.
19. No Profiling or Automated Decision-Making
a) The Controller does not use User profiling.
b) The Controller does not use automated systems making decisions concerning data subjects.
c) All decisions concerning cooperation, fulfilment of Orders, contact, and Client service are made individually by a human.
20. Data of Minors
a) Afixo services may also be addressed to minors.
b) A minor may enter into an agreement concerning fulfilment of an Order only with consent of their legal representative, in accordance with the rules set out in the Order Terms and Conditions.
c) The Controller does not direct its services specifically to children and does not carry out activities aimed at intentionally obtaining data concerning minors.
d) If the Controller becomes aware that data has been provided without the required consent of a legal representative, the Controller may take steps to delete the data or clarify the situation.
21. Erasure and Restriction of Data Processing
a) The Controller erases personal data where:
– the data retention period has expired,
– the data is no longer necessary for the purposes for which it was collected,
– the data subject effectively requests erasure and continued storage is not required by law,
– consent is withdrawn where processing was based on consent and no other legal basis exists for continued processing.
b) Erasure of data may include:
– deletion of data from working documentation,
– deletion of data from systems used to fulfil Orders,
– deletion of contact details,
– deletion of published reviews where their publication was based on Client consent.
c) The Controller may limit the scope of data erasure where continued storage is necessary:
– to comply with legal obligations,
– to preserve evidence of cooperation,
– to establish, exercise, or defend legal claims.
d) Erasure of data from working systems does not mean that data must be immediately deleted from backup copies where deletion requires automatic overwriting in accordance with the backup cycle.
22. Confidentiality of Client Information
a) The Controller treats information and materials provided by the Client as confidential.
b) Confidentiality covers in particular:
– project materials,
– documentation,
– descriptions of ideas,
– worldbuilding elements,
– sketches,
– information concerning planned projects,
– arrangements concerning cooperation.
c) The Controller does not use Client information for purposes other than:
– fulfilment of the Order,
– management of cooperation,
– protection of rights and obligations arising from the agreement.
d) The confidentiality obligation also applies to Subcontractors who receive access to information or materials in connection with fulfilment of part of an Order.
e) The Controller may disclose information concerning the Client only:
– with the Client’s consent,
– to persons involved in fulfilment of the Order, to the extent necessary to perform the work,
– to entities authorised under applicable law.
23. Data Processed in Connection with Payments
a) The Controller may process data necessary for settlement of cooperation.
b) Depending on the selected payment method, the following data may be processed, among other things:
– data concerning the person making the payment,
– information concerning the bank transfer,
– information allowing confirmation that payment has been made.
c) The Controller does not store payment card details or other data that is not necessary to confirm settlement.
d) Available payment methods include in particular:
– bank transfer,
– BLIK as a direct transfer,
– other individually agreed payment methods.
e) The Controller does not use external payment service providers that independently process online payments.
24. Data Relating to Unregistered Business Activity
a) The Controller conducts business in the form of unregistered business activity in accordance with applicable law.
b) In connection with its business activity, the Controller may process data necessary for:
– documenting cooperation,
– settlements,
– compliance with legal obligations,
– demonstrating proper performance of services.
c) A document summarising an Order may contain information concerning the service performed, arrangements between the parties, and settlement.
d) Data contained in settlement-related documents is stored for the period resulting from applicable law.
25. Amendments to the Privacy Policy
a) Administrator może aktualizować niniejszą Politykę prywatności w przypadku:
– zmiany sposobu działania strony internetowej,
– zmiany wykorzystywanych usług,
– zmiany zakresu przetwarzanych danych,
– zmian przepisów prawa,
– konieczności doprecyzowania istniejących zasad.
b) Aktualna wersja Polityki prywatności jest dostępna na stronie internetowej Afixo.
c) Każda wersja Polityki prywatności posiada oznaczenie daty ostatniej aktualizacji.
d) Zmiany nie wpływają na sposób przetwarzania danych dokonany przed ich wejściem w życie, chyba że wymagają tego obowiązujące przepisy prawa lub osoba, której dane dotyczą, wyrazi zgodę na nowe zasady.
26. Final Provisions
a) This Privacy Policy takes effect on the date of its publication on the Afixo website.
b) In matters not regulated by this Privacy Policy, applicable provisions of law shall apply, in particular the provisions of the GDPR and the Polish Act on the Protection of Personal Data.
c) Provisions of this Privacy Policy shall be interpreted in accordance with the principles of personal data protection and transparency of data processing.
d) If any provision of this Privacy Policy is found to be invalid or ineffective, the remaining provisions shall remain in force.
e) Detailed rules concerning cooperation, fulfilment of Orders, copyright, liability of the parties, and archiving of materials are set out in the Order Terms and Conditions.
f) This Privacy Policy supplements the Order Terms and Conditions with respect to the rules concerning processing and protection of personal data.
