Legal information

Privacy policy

How we handle the personal data of people who contact Polonia Iuris through this website.

What this policy covers

This document covers poloniaiuris.com in both language versions, and the correspondence that follows once you contact us through the site. It describes what actually happens: which data reaches the firm, by what route, and how long we keep it. Last updated: September 10, 2026.

Who is the data controller?

The controller of your personal data is Polonia Iuris Sp. z o.o. - the Polish limited liability company that operates the firm and this website (“Sp. z o.o.” is the Polish equivalent of an LLC).

Registered office: ul. Ignacego Mościckiego 6D/1, 05-080 Lipków, Poland. The company is entered in the register of entrepreneurs of the Polish National Court Register (Krajowy Rejestr Sądowy, the company register kept by the Polish courts) under number KRS 0001262196. Its tax number is NIP 1182335409, its statistical number REGON 545558450, and its share capital PLN 5,000.

For anything concerning your data, write to biuro@poloniaiuris.com or call +48 780 680 106 (Poland) or +1 (412) 542 2576 (United States). Both numbers work on WhatsApp.

We have not appointed a data protection officer. Every request about personal data goes to the address above and is answered by the firm.

We process personal data under the European General Data Protection Regulation (GDPR) and under the Polish Personal Data Protection Act of May 10, 2018 (Journal of Laws of 2018, item 1000, as amended). We keep it confidential and protect it against access by people who are not authorized to see it.

What data do we collect?

The site collects nothing in the background. Everything that reaches us, you give us yourself - through the form or by writing directly.

The contact form

The form has five fields - your name, email address, phone number, the type of matter chosen from a list, and a description of your situation (up to 4,000 characters) - plus a consent box you have to tick before sending. We automatically attach the date and time of submission and the address of the page the form was sent from, so we know which area of law you are asking about before we even read the description.

The form stores nothing on the server. This website has no database. What you write goes only into an email sent to biuro@poloniaiuris.com, and from that moment it lives like any other message in the firm's mailbox.

Please do not send documents through the form

The first message is for an initial assessment, not for handing over a file. Do not type identity document numbers or details about health, religion or court judgments - describing the situation in your own words is enough. When documents are needed, we will agree on a secure way to send them.

Spam protection

The form is protected by Cloudflare Turnstile, which tells a person apart from an automated script. During that check your IP address and basic browser information go to Cloudflare. Without this step the form will not send anything.

Contacting us directly

If you write to our email address, call, or reach us on WhatsApp, we process the data you provide on that occasion, including the content of your message.

Data you give us as the case proceeds

If you engage us, running the case takes more than what fits into a first message. Depending on the type of matter, that may include:

  • identifying details - your name, date and place of birth, parents’ first names, company name,
  • contact details - home address, phone number, email address,
  • registry numbers - PESEL (the Polish national identification number), NIP (tax number), REGON (statistical number), identity document number,
  • employment and financial circumstances - where they matter to the case,
  • bank account number - for billing and for transferring funds recovered in the case,
  • anything else you pass on during the case, including what the documents contain.

We ask for each of these only when the case actually needs it, and we tell you a secure way to send it. The contact form collects none of it.

Server logs

The server that hosts the site records standard access logs: IP address, the date of the request, the page address and the browser type. The hosting provider keeps them for security and diagnostics; we do not combine them with any other data and do not use them to identify visitors.

Why do we process it, and on what legal basis?

The firm is based in Poland, so the GDPR applies. The legal bases are:

  • Answering your inquiry and assessing the matter - steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).
  • Handling the case once you engage us - performance of the engagement contract (Article 6(1)(b) GDPR).
  • Statutory obligations - tax and accounting duties, and the obligations imposed on law firms (Article 6(1)(c) GDPR).
  • Protecting the form from spam and keeping the server secure - our legitimate interest (Article 6(1)(f) GDPR).
  • Establishing, pursuing or defending claims - our legitimate interest (Article 6(1)(f) GDPR).

The matters we handle - inheritance, family, property - sometimes involve sensitive data: the health of a deceased relative, religion in church marriage nullity cases, court judgments. We process such data where it is necessary to establish, pursue or defend legal claims (Article 9(2)(f) GDPR).

Providing your data is voluntary, but without a name, an email address or phone number, and a description of the matter, we cannot answer your inquiry.

How long do we keep it?

  • An inquiry that does not lead to an engagement - we delete the correspondence 12 months after the last message. People often come back to a matter months later, and the earlier exchange saves them explaining everything again.
  • A case the firm handles - for as long as it runs, then for the limitation period applying to claims under the engagement, and for as long as the rules on keeping case files require.
  • Accounting records - 5 years, counted from the end of the calendar year in which the tax payment fell due.
  • Server logs - for the period applied by the hosting provider; we have no interest of our own in them and do not copy them.

Who has access to it?

Inside the firm - the lawyers and staff who need the data to handle your matter. All of them are bound by professional secrecy.

Outside the firm, data may reach:

  • the hosting provider (LH.pl, Poland) - its servers run the website and the firm's mailbox,
  • Cloudflare - it operates the anti-spam check on the form,
  • Google - only the measurement described below, and only once you have consented to it,
  • Meta - the pixel described below, but only once you have consented to measurement,
  • an accounting office - for billing and tax records,
  • courts, public authorities and other bodies - where the law or your case requires it.

We do not sell data. Apart from the traffic measurement described below, which runs only with your consent and which you can switch off at any time, we pass data to no one for marketing purposes.

Transfers outside the European Economic Area

Cloudflare, Google and Meta are U.S. companies, so part of the processing may take place outside the European Economic Area. Those transfers rely on the mechanisms set out in Chapter V of the GDPR - a European Commission adequacy decision or standard contractual clauses.

If you live in the United States, one thing is worth knowing: the case runs in Poland and that is where we process the data connected with it. The correspondence itself passes through your own email provider in the U.S., whose rules are outside our control.

Cookies and measurement

We use Google Analytics 4 - a tool that shows us which pages people read and where they arrive from. It stores cookies in your browser containing a randomly assigned number. They hold no name and no email address, but under the GDPR they are still personal data, because they let the same browser be recognized on a later visit.

Until you consent, your browser does not connect to Google Analytics at all. The measurement script is not loaded up front - it loads only after you select “I agree” on the bar shown on your first visit. If you select “I do not agree,” we learn nothing about your visit.

The legal basis is your consent (GDPR Article 6(1)(a)). You may withdraw it at any time and without giving a reason; withdrawal does not affect the lawfulness of processing carried out beforehand.

The recipient of this data is Google Ireland Limited, and the data may reach the United States, where Google runs part of its infrastructure. The transfer relies on a European Commission adequacy decision or on standard contractual clauses, depending on which mechanism Google relies on at the time. We have no control over how Google processes the data on its side.

Your choice is stored in your own browser (the localStorage mechanism, under a key named pi-zgoda-analityka). It is the one thing the site stores regardless of consent - without it we would have to ask you again every time you open the page. Clearing your browser data removes it, and the bar appears again.

We also use the Meta pixel - a tool from the company behind Facebook and Instagram. It shows us which of our advertisements brought a visitor to this site, and it allows us to show a follow-up advertisement to someone who has already been here. Like Google Analytics, it does not load until you consent: until then your browser does not connect to Meta at all.

What the pixel sends is the address of the page you opened, the time, technical details of your browser, and an identifier stored in a cookie. If you are signed in to Facebook or Instagram in the same browser, Meta can link that information to your account there. We do not send Meta your name, your email address, your telephone number, or anything you type into the contact form.

The recipient is Meta Platforms Ireland Limited, and the data may reach the United States, where Meta runs part of its infrastructure. That transfer relies on the mechanisms set out in Chapter V of the GDPR. The legal basis on our side is your consent (GDPR Article 6(1)(a)); the bar covers both tools together, and you may withdraw it at any time using the button above.

We do not combine traffic measurement with the details you enter in the contact form.

Two further elements of the page connect to outside servers regardless of your measurement choice:

  • Cloudflare Turnstile - the anti-spam check on the form. It may store technical information in your browser in order to run that check.

Privacy policies commonly divide cookies into performance cookies, which collect information on how a site is used, and functional cookies, which store a user’s settings. This site sets only performance cookies - the ones Google Analytics places after you consent - plus the technical files the Cloudflare Turnstile check needs. We set no advertising cookies and none that build a profile for marketing.

You can manage stored files yourself in your browser settings: review them, delete them, or block them up front. Blocking them does not make the site harder to use.

We run no newsletter and send no marketing messages. We write to you only in reply to your inquiry, or about a matter we are handling for you.

What are your rights?

In relation to your data you have the right to:

  • access it and receive a copy,
  • have inaccurate or incomplete data corrected,
  • be told the source your data came from, if we did not receive it from you,
  • have your data erased,
  • have the processing restricted,
  • have your data transferred to another controller,
  • object to processing based on our legitimate interest,
  • withdraw your consent at any time - without affecting what we did before you withdrew it.

Professional secrecy limits some of these rights. A lawyer may not disclose or erase information covered by professional secrecy, even at the request of the person it concerns - this applies in particular to files of cases run for other clients. If such a limit applies in your case, we will explain it when we answer your request.

You also have the right to lodge a complaint with the Polish supervisory authority - the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl. This is the Polish regulator for personal data; a complaint can be filed from abroad.

Do we make automated decisions?

No. We do not profile anyone and we make no automated decisions - a lawyer assesses the matter by reading what you wrote. The only automated step on this site is the check that tells a person apart from a bot when the form is sent, and its result decides one thing only: whether the message goes through.

How to contact us about your data

Write to biuro@poloniaiuris.com or call +48 780 680 106 (Poland) or +1 (412) 542 2576 (United States). Both numbers work on WhatsApp, which is often easier given the time difference between the U.S. and Poland.

We answer requests about personal data within one month. If a request turns out to be complex, we will tell you before that month is up that we need longer.

Postal address for written correspondence: Polonia Iuris Sp. z o.o., ul. Ignacego Mościckiego 6D/1, 05-080 Lipków, Poland.

Changes to this policy

If the way the site works changes - we add an analytics tool, we move to a different email provider - we will update this document and change the date given at the top. We do not announce changes separately, so it is worth checking that date the next time you get in touch.

Contacting the firm through this website does not create an attorney-client relationship. That relationship arises only once an engagement is confirmed in writing. This policy describes how personal data is handled and is not legal advice.