Privacy Policy for mateuszufel.com / tworcow.forum
Version: 2 · Publication date: 12 August 2026
1. Data Controller and contact details
The Data Controller is Mateusz Szufel, Tax Identification Number (NIP) 7952485304, National Business Registry Number (REGON) 386948174, ul. Wesoła 6, 97-371 Siomki, Poland. Contact: trudnesprawy@mateuszufel.com or trudnesprawy@tworcow.forum.
2. Scope and abbreviated definitions
This Policy applies to services available in the mateuszufel.com and
tworcow.forum domains, together with all their subdomains, including:
- the Store and websites,
- the Community (including the members’ area), also when operated using the external Circle and Imker platforms,
- services delivered by email (the mateuszufel x forum twórców Newsletter, lead magnets and AI Assistants),
- AI Applications operated by the Controller, such as Zakład Spełniania Marzeń (“ZSM”, zsm.tworcow.forum).
Abbreviated terms: “Store”, “Forum”, “User”, “Subscription” and “Digital Product” have the meanings assigned to them in the Store and Community Terms; “Service”, “Newsletter” and “AI Application” have the meanings assigned to them in the Terms for Digital Services, Newsletter and Reviews.
3. Principles and legal bases
We process data in accordance with Article 5 of the GDPR (including lawfulness, data minimisation and accountability). The legal bases are: Article 6(1)(b) (contract), Article 6(1)(c) (legal obligation), Article 6(1)(a) (consent) and Article 6(1)(f) (legitimate interest). For electronic communications, we apply Article 398 of the Polish Electronic Communications Law (Prawo komunikacji elektronicznej, “PKE”).
4. Purposes of processing, scope of data, legal bases and retention periods
4.1 Purchases and performance of a contract
Scope: identification and contact details, delivery/billing address, Tax Identification Number (NIP) where an invoice is issued, order details and payment data. Legal basis: performance of a contract or steps taken prior to entering into a contract [Article 6(1)(b) GDPR], tax and accounting obligations [Article 6(1)(c) GDPR]. Retention period: until performance has been completed and the limitation period for claims has expired; accounting documents are retained in accordance with tax law.
4.2 Account and Subscription
Scope: email address, hashed password or code-based login, technical identifiers, Subscription status and data required to provide the digital service. This also applies to accounts in AI Applications. Legal basis: contract for the provision of a digital service [Article 6(1)(b) GDPR]. Retention period: for as long as the account exists and for the applicable limitation period.
4.3 Handling enquiries and correspondence
Scope: contact details and the content of messages. Legal basis: legitimate interest in conducting correspondence and protecting against claims [Article 6(1)(f) GDPR]. Retention period: until the matter has been closed and for the period necessary to defend against claims.
4.4 Newsletter and services delivered by email
Scope: email address, time and source of signup, service status, and open and click statistics. Legal basis: performance of the contract for the supply of digital content described in the Terms for Digital Services [Article 6(1)(b) GDPR], as well as our legitimate interest in marketing our own products and services and in demonstrating that the signup was valid [Article 6(1)(f) and Article 5(2) GDPR]. We send commercial communications and direct marketing on the basis of prior consent expressed through an affirmative action - providing an address and clicking the delivery button while the relevant information is displayed - in accordance with Article 398 PKE. Retention period: until you cancel the service; we retain a record of the fact and circumstances of the signup and cancellation for a longer period for accountability purposes and to defend against claims.
4.5 AI Applications and conversations (e.g. ZSM)
Scope: email address, account and session identifiers, first name (as a label in the interface and administrator panel), versions of accepted documents and the times at which acceptance was confirmed, the content of conversations with the AI system, time, status, use of limits and technical cost. Legal basis: performance of a contract [Article 6(1)(b) GDPR] and legitimate interest in quality control, service development and security [Article 6(1)(f) GDPR]. Retention period: the full conversation content - 30 days, followed by automatic deletion; other periods are set out in Section 11.
You are conversing with an AI system; messages are sent to the model provider in order to generate a response. Conversation content is not used to train models, profile Newsletter subscribers, qualify leads or tailor offers. An authorised administrator may access a conversation only to the extent necessary for quality control and development, support, security, handling your request or compliance with a legal obligation; every instance of access requires the purpose to be stated and is logged. Do not enter special category data, other people’s data or information that you do not want to disclose to us into a conversation.
4.6 Analytics and optimisation
Scope: online identifiers, IP address, device and browser data, events on the website and recordings of UX interactions. Tools: Google Analytics and Microsoft Clarity. Legal basis: legitimate interest in basic statistics [Article 6(1)(f) GDPR], but consent for analytics cookies and similar technologies [Article 6(1)(a) GDPR]. Retention period: in accordance with the cookie configuration and our retention schedule.
4.7 Marketing, remarketing and measurement
Scope: cookie identifiers and marketing events. Tools: Meta Pixel, Google Ads, TikTok Pixel, LinkedIn Insight Tag, Pinterest Tag and AffiliateWP (affiliate referral tracking). Legal basis: consent to marketing cookies [Article 6(1)(a) GDPR], as well as our legitimate interest [Article 6(1)(f) GDPR]. Retention period: until consent is withdrawn or the cookies expire.
4.8 Social media and joint controllership
Scope: data visible on profiles and transmitted by plugins; platform statistics. Legal basis: legitimate interest in maintaining social media profiles [Article 6(1)(f) GDPR]. For certain platform functions, we may act as joint controllers (Article 26 GDPR). Good practice: we recommend logging out of your profile and using incognito mode if you do not want the platform to link the data.
4.9 Automation of social media communications - Linktree and ManyChat
Use: automated messages on social media; providers may act as controllers or processors and have their own data processing agreements and subprocessors. Legal basis: consent to receive messages through these tools and Newsletter consent for email communications.
4.10 Public-law obligations, including the DSA
Scope: handling reports and requests from public authorities, and metadata associated with user content. Legal basis: legal obligation [Article 6(1)(c) GDPR] connected with Regulation (EU) 2022/2065 (Digital Services Act, DSA).
4.11 Special category data
As a rule, we do not require such data and ask you not to enter it into conversations with AI Applications either. If you nevertheless provide such data yourself and it is necessary, we process it solely on the basis of your explicit consent [Article 9(2)(a) GDPR].
5. Data recipients and categories of entities
Payments: TPay, PayU and Stripe. Newsletter and email: MailerLite and/or Substack - processors; the system may record subscriber activity. Resend - transactional messages containing login codes. AI Applications: OpenAI - generating responses on the basis of the instructions and materials provided; Supabase - login, sessions and database. Hosting: Vercel - websites and applications. Analytics/UX: Google Analytics and Microsoft Clarity - statistics; cookies. Marketing/remarketing: Meta Pixel (Facebook/Instagram), Google Ads, TikTok Pixel/Analytics, LinkedIn Insight Tag and AffiliateWP. Plugins and embedded content: YouTube and Vimeo. Community platform: Circle / Imker - cookies required for the Forum to operate and, where applicable, for other purposes in accordance with Circle’s / Imker’s policies. Communication automation: Linktree. ManyChat - automated conversations and signups in Messenger and on Instagram.
6. Transfers of data outside the EEA
If a provider is established outside the EEA, we use the compliance mechanisms provided for under the GDPR - in particular, an adequacy decision or Standard Contractual Clauses.
7. Cookies and similar technologies
We use necessary, analytics and marketing cookies. On your first visit, you see a consent banner that divides cookies into categories and allows you to change your decision later. You can also manage cookie settings in your browser.
AI Applications use only the mechanisms necessary for login, security and session continuity; they do not activate analytics or marketing cookies.
Social plugins and embedded materials from external services may store their own cookies; if you do not want this activity to be linked to your profile, use incognito mode.
8. Rights of data subjects
You have the right to: access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw consent at any time. The right to object to direct marketing is absolute. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. You have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO). [Article 7(3), Articles 15-22 and Article 77 GDPR]
9. Automated decision-making and profiling
We do not make decisions producing legal effects solely by automated means; this also applies to conversations with AI Applications. Marketing profiling based on cookies takes place only with your consent. [Article 22 GDPR]
10. Security
We apply organisational and technical measures appropriate to the risk, enter into data processing agreements, maintain records of processing activities, encrypt data in transit and restrict access. Administrative access to conversations in AI Applications requires the purpose to be stated and is logged. [Articles 24, 25, 28 and 32 GDPR]
11. Retention periods - summary
Contract data: until the limitation period for claims has expired [Article 6(1)(b) and (f) GDPR]. Accounting documents: for the period required under tax law [Article 6(1)(c) GDPR]. Newsletter/marketing: until cancellation or an effective objection; a minimal record proving the conclusion of the contract, consent and cancellation - for no longer than 3 years after the contract ends, unless a longer period is required by law or an ongoing dispute. AI Applications: login code - up to 10 minutes and only until first use; full conversation content - 30 days; technical security and limit logs - up to 30 days; administrator access logs - 12 months. Technical and statistical data: in accordance with the settings of the tools and our retention schedule.
12. Social media - clarification of functions
Meta - advertising pixel; joint controllership of statistics may apply to activities on the profile. TikTok - tracking script for measurement and personalisation; the provider may combine this information with other data. LinkedIn - Insight Tag and conversion reporting. Google - tracking pixel, cookies and video playback data. Vimeo - cookies and video playback data.
13. Contact regarding personal data
For data protection matters: trudnesprawy@mateuszufel.com or trudnesprawy@tworcow.forum. For content and moderation matters on the Forum - use the contact details specified in the Community Terms.
14. Amendments to this document
This Policy may change as our services evolve and the law changes; we will notify you of material changes on the website and by email if you have an account or Subscription or use services delivered by email. [Article 5(2) GDPR]