Privacy Policy
Last Updated: 22 July 2026
This Privacy Policy describes how Nayeze Guguya ("we", "us", "our"), operating from Al. Adama Mickiewicza 10, Łódź, Poland, processes personal data collected through the website nayeze-guguya.info and through the provision of consulting services. This policy is issued in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation, "GDPR") and the Polish Act of 10 May 2018 on the Protection of Personal Data (Ustawa o ochronie danych osobowych).
1. Data Controller
The data controller responsible for personal data processed through this website and in connection with our services is:
Nayeze Guguya
Al. Adama Mickiewicza 10
Łódź, Poland
Email: [email protected]
Phone: +48 603 480 080
2. What Data We Collect and Why
The table below describes the categories of personal data we process, the purpose of processing, and the legal basis under GDPR Article 6.
| Data Category | Specific Data Points | Purpose | Legal Basis (GDPR Art. 6) | Retention Period |
|---|---|---|---|---|
| Contact enquiry data | Name, company name, email address, phone number, message content | Responding to business enquiries and assessing service fit | Art. 6(1)(b) – steps prior to entering a contract; Art. 6(1)(f) – legitimate interests | 24 months from last contact, or until deletion is requested |
| Service delivery data | Business information shared during consulting engagements, correspondence | Providing contracted data audit consulting services | Art. 6(1)(b) – performance of a contract | 5 years from end of engagement for accounting purposes (Polish accounting law) |
| Website analytics data | IP address (anonymized), browser type, pages visited, session duration | Understanding how the website is used to improve content and navigation | Art. 6(1)(a) – consent (where analytics cookies are accepted) | As per cookie settings; see Cookie Policy |
| Technical logs | Server access logs including IP address and request timestamps | Security monitoring and error detection | Art. 6(1)(f) – legitimate interests in website security | 90 days |
3. How We Use Your Data
We use personal data exclusively for the purposes described in the table above. We do not use personal data for automated decision-making or profiling as defined under GDPR Article 22. We do not sell, rent, or share personal data with third parties for marketing purposes.
4. Data Sharing and Third Parties
We may share personal data with carefully selected processors who assist in operating this website and delivering our services. Any such processor is bound by a data processing agreement and may only process data according to our instructions. Categories of processors include:
- Web hosting providers (for website operation)
- Email service providers (for business correspondence)
- Accounting software providers (for invoicing and records)
We do not transfer personal data outside the European Economic Area. Where a processor operates infrastructure outside the EEA, we ensure appropriate safeguards are in place in accordance with GDPR Chapter V.
5. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR, which you may exercise by contacting us at [email protected]:
| Right | Description |
|---|---|
| Right of access (Art. 15) | You may request a copy of personal data we hold about you and information about how it is processed. |
| Right to rectification (Art. 16) | You may request correction of inaccurate or incomplete personal data. |
| Right to erasure (Art. 17) | You may request deletion of your personal data where there is no longer a lawful basis for processing. |
| Right to restriction (Art. 18) | You may request that we restrict processing of your data in certain circumstances. |
| Right to data portability (Art. 20) | Where processing is based on consent or contract, you may request your data in a structured machine-readable format. |
| Right to object (Art. 21) | You may object to processing based on legitimate interests, including for direct marketing. |
| Right to withdraw consent (Art. 7) | Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing. |
We will respond to requests within 30 days. Where requests are complex or numerous, this may be extended by a further 60 days, and you will be notified accordingly.
6. Supervisory Authority
You have the right to lodge a complaint with the Polish supervisory authority for data protection: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, Poland. Website: uodo.gov.pl.
7. Cookies
This website uses cookies. The types of cookies used, their purposes, and your options for managing them are described in our Cookie Policy. You can manage your cookie preferences at any time using the cookie consent tool on this website.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction. These include access controls, encrypted transmission (HTTPS), and regular review of our data handling practices. No transmission over the internet is entirely secure; however, we take commercially reasonable precautions.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Where changes are material, we will update the "Last Updated" date at the top of this page. Continued use of this website following an update constitutes acknowledgment of the revised policy. We encourage you to review this page periodically.
10. Contact
For any questions, requests, or concerns relating to this Privacy Policy or our data practices, please contact us at:
Email: [email protected]
Post: Al. Adama Mickiewicza 10, Łódź, Poland
Phone: +48 603 480 080