- Strona główna
- Privacy and Data Processing Policy
Vis-Sol Privacy and Data Processing Policy.
One policy for the Vis-Sol website, services, Toolbox, VSA, Concept, maintenance and R&D environments.
1. Controller and contact
The controller of personal data processed by Vis-Sol for its own purposes is Kamil Kosiorek, operating under the brand Vis-Sol / Visuals & Solutions.
Vis-Sol provides services primarily remotely and, where required by a project, at the client’s premises. Vis-Sol does not maintain a separate public correspondence address dedicated to customer service.
2. Scope
This policy covers vis-sol.pl and its language versions, contact and enquiries, websites and applications, CRM/WMS and B2B systems, automation and integrations, audits, Vis-Sol Toolbox, AutoAudit, Knowledge Scan, VSA, Concept / Concept Core, support, monitoring, backups, security and R&D environments.
3. Vis-Sol roles
Controller
Vis-Sol acts as controller where it determines the purposes of processing, including enquiries, offers, its own services, accounting, security, diagnostics, public tools and consent-based analytics.
Processor
Where Vis-Sol operates a client system, form, application, integration, knowledge base or VSA instance on documented client instructions, it may act as processor under the relevant service scope, order, agreement or data-processing agreement.
4. Data categories
Depending on the function, Vis-Sol may process contact data, company name, enquiry and project information, data entered into tools, analysed website addresses, uploaded files, generated results, configuration and technical data, logs, IP addresses and technical or session identifiers.
5. Purposes and legal bases
- enquiries and pre-contract steps — GDPR Art. 6(1)(b);
- performance of a service or contract — Art. 6(1)(b);
- legal and accounting obligations — Art. 6(1)(c);
- security, diagnostics, abuse prevention and legal claims — Art. 6(1)(f);
- non-essential analytics — consent where required.
6. Toolbox, AutoAudit and Knowledge Scan
Tools may process a website address, analysis parameters, user-provided information, a file and a generated result. Basic results do not require an account.
Users should not upload personal data, trade secrets or material they are not authorised to provide unless such processing has been agreed. Full context stored on request in temporary VSA memory expires after 2 hours where the function operates in that mode. Where a report is sent by e-mail, the address is used to deliver the report and protect the function against abuse.
7. Concept / Concept Core
Concept may process brief information including business name and sector, business description, target group, project objectives, requested functions, content and visual preferences and other user-provided material.
Prototype, demo, beta, sandbox and experimental environments should not receive confidential or personal data unless explicitly approved for such processing.
8. VSA and client instances
Client data, documents and knowledge are assigned to the relevant instance or project scope. Production instances may have separated configuration, knowledge, roles, sessions and logs. VSA may answer questions, qualify enquiries, collect service information, route users to a process or tool and use knowledge assigned to the relevant instance.
9. Providers and recipients
Data may be disclosed, only where necessary, to categories such as hosting and infrastructure providers, e-mail and communication providers, analytics providers, external AI or computing-service providers, technical service providers and entities authorised by law.
The public policy describes external AI services by category and does not disclose model architecture, a specific model or a temporary backend provider unless naming a provider is required for a particular process.
10. Transfers outside the EEA
If a function uses a provider processing data outside the European Economic Area, the appropriate legal transfer mechanism and safeguards are applied. Details may be specified for the relevant service or process.
11. Cookies, browser storage and analytics
The website uses browser mechanisms including localStorage and sessionStorage for functions such as theme preference, tool state, VSA session/context hand-off and privacy choices.
Google Analytics / Google Tag Manager is used to measure website traffic and events. Analytics is disabled by default and may be enabled after the user’s choice. Refusing analytics does not disable core website functionality. Vis-Sol does not use this layer for ad personalisation.
12. Retention
- temporary Knowledge Scan/VSA memory — 2 hours where applicable;
- enquiries without a project — up to 12 months from the last contact;
- standard web and technical logs — 30 days;
- specific security-incident logs — until closure and then up to 12 months where documentation is necessary;
- one-off report e-mail data — 30 days;
- temporary generator/audit files — up to 24 hours unless a shorter period is stated;
- Concept/test environment data — up to 7 days after the test or last activity unless agreed otherwise;
- working project copies — up to 90 days after completion where no longer operationally required;
- operational backups — 30-day rolling retention by default where backup applies;
- client-instance data — under the agreement, client instructions and legal requirements;
- contract, accounting and tax records — for the period required by law or needed for legal claims.
13. Voluntary provision of data
Providing data is generally voluntary. If information is necessary to answer an enquiry, execute an order or operate a selected function, failure to provide it may make the requested action impossible.
14. Rights
Where applicable, individuals may request access, rectification, erasure, restriction and portability, and may object to processing based on legitimate interests. Where processing relies on consent, consent may be withdrawn at any time without affecting prior lawful processing.
Individuals may also lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).
15. Automated analysis
VSA, Toolbox and Concept may automatically analyse information, classify an enquiry or generate a response, report or recommendation. Public Vis-Sol functions are not intended to independently make decisions producing legal or similarly significant effects unless such a process is separately designed and documented.
16. Security
Depending on the service class, Vis-Sol uses measures such as environment separation, access control, least-privilege access, monitoring, backups, updates, event logging and diagnostic/recovery procedures.
17. Changes
This is the umbrella privacy policy for the Vis-Sol ecosystem. New products, modules and tools are incorporated by versioning and extending this document unless law or the nature of a specific service requires separate rules.
Version 2.0 · 19 August 2026