Legal
Privacy Policy
Effective date: August 22, 2026
This Privacy Policy explains how David Parys Tech, trading as Mountain Web Studio, processes personal data when you visit this website or contact us about our services. It is the information notice required by Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”).
1. Data Controller
The controller of your personal data — the party that decides why and how it is processed — is:
David Parys Tech
ul. Limanowskiego 19
39-300 Mielec, Poland
NIP: 8172210271
REGON: 525072409
david@mountain-web-studio.comWe have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Send any privacy question or request to the address above; it reaches the person responsible directly.
2. What Data We Collect
Data you give us:
- Contact inquiries — name, email address, and message content submitted through our contact form or sent to us by email
- Project discussions — details about your business, project scope, or requirements that you choose to share during discovery calls or correspondence
- Contract and billing data — for clients: company name, registered address, tax identification number, and payment details, as required to issue invoices
Data collected automatically when you visit the site:
- Log data — IP address, browser type, referring URL, pages or endpoints requested, and timestamps, recorded by our hosting infrastructure
- Theme preference — a single functional cookie storing your dark or light mode choice. No tracking or advertising cookies are set.
We do not process special categories of data under Article 9 GDPR, and we ask that you do not send such data to us through the contact form.
3. Why We Process It, and on What Lawful Basis
- To answer your inquiry and discuss a possible project — Article 6(1)(b) GDPR, steps taken at your request before entering a contract. Where you write on behalf of a company rather than for yourself, the basis is our legitimate interest in responding to business correspondence, Article 6(1)(f).
- To deliver and manage services under a signed agreement — Article 6(1)(b) GDPR, performance of a contract.
- To issue invoices and keep accounting records — Article 6(1)(c) GDPR, compliance with our legal obligations under Polish tax and accounting law.
- To keep the site secure, available, and free of abuse — Article 6(1)(f) GDPR, our legitimate interest in protecting our infrastructure.
- To establish, exercise, or defend legal claims — Article 6(1)(f) GDPR, our legitimate interest in defending our rights.
- To send updates to existing clients — Article 6(1)(f) GDPR, our legitimate interest in direct communication with clients. You may object at any time by replying to any message.
Providing your data is voluntary, but without a name and email address we cannot reply to a contact inquiry, and without billing details we cannot issue a valid invoice.
4. Who We Share It With
We do not sell, rent, or trade personal data. We share it only with processors acting on our instructions under a data processing agreement, and in the limited cases below:
- Vercel Inc. — hosting and content delivery for this website, which entails processing server log data
- Resend (Plus Five Five, Inc.) — delivery of transactional email, including contact form notifications and confirmations
- Google Ireland Ltd. — the email service on which we receive and store correspondence
- Our accountant — for invoices and accounting records, as required by law
- Public authorities — where disclosure is required by law, and legal or debt-recovery advisers where needed to pursue or defend a claim
5. Transfers Outside the EEA
Vercel and Resend are established in the United States, so some processing takes place outside the European Economic Area. These transfers are covered by the Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR, and, where the provider is certified, by the EU–US Data Privacy Framework adequacy decision under Article 45 GDPR.
You may request a copy of the safeguards in place by writing to the address in Section 1.
6. How Long We Keep It
- Contact inquiries that do not lead to a project — up to 24 months from our last exchange, in case you return with follow-up questions
- Client correspondence and project records — for the duration of the engagement, then for the period in which claims may still be brought under the Polish Civil Code
- Invoices and accounting records — 5 years from the end of the calendar year in which the tax payment fell due, as required by Polish tax law
- Server logs — retained by our hosting provider for a short technical period and not used to build a profile of you
7. Your Rights
Under the GDPR you have the right to:
- Access — obtain confirmation of whether we process your data, and a copy of it (Art. 15)
- Rectification — have inaccurate or incomplete data corrected (Art. 16)
- Erasure — have your data deleted, unless we must keep it to meet a legal obligation or defend a claim (Art. 17)
- Restriction — have processing limited while a dispute over accuracy or lawfulness is resolved (Art. 18)
- Portability — receive data you gave us in a structured, machine-readable format, or have it sent to another controller (Art. 20)
- Objection — object at any time to processing based on our legitimate interest, including direct marketing, which we stop on request (Art. 21)
- Withdraw consent — where processing rests on consent, withdraw it at any time without affecting processing carried out beforehand (Art. 7(3))
To exercise any of these rights, email us at david@mountain-web-studio.com with “Privacy Request” in the subject line. We respond within one month, which may be extended by a further two months for complex requests; we will tell you if that happens. Exercising these rights is free of charge.
8. Right to Lodge a Complaint
If you believe we process your data unlawfully, you may lodge a complaint with the Polish supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych
President of the Personal Data Protection Office
ul. Stawki 2
00-193 Warszawa, Poland
uodo.gov.plIf you live in another EU member state, you may also complain to the supervisory authority there.
9. Cookies and Tracking
We set one functional cookie, which stores your dark or light mode preference. It is strictly necessary to deliver the setting you asked for, so it does not require consent under Article 174 of the Polish Electronic Communications Law.
We do not embed Google Analytics, Meta Pixel, or any other behavioral tracking or advertising script, and we do not build advertising profiles.
10. Automated Decision-Making
We do not make decisions about you based solely on automated processing, and we do not carry out profiling within the meaning of Article 22 GDPR.
11. Security
We apply technical and organizational measures appropriate to the risk, as required by Article 32 GDPR. All data in transit is encrypted over HTTPS, access to inquiry data is limited to people who need it to answer you, and our providers are selected for their data protection standards.
No method of transmission or storage is completely secure. If you have reason to believe your interaction with us has been compromised, contact us immediately at david@mountain-web-studio.com. Where a breach is likely to result in a high risk to your rights, we will notify you in line with Article 34 GDPR.
12. Children
This website and our services are intended for business users and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy — for example, if we change providers or start processing for a new purpose. The effective date at the top of this page reflects the most recent revision, and material changes will be summarized here. We encourage you to review it periodically.
14. Contact
Questions, concerns, or requests regarding this policy? Write to us at david@mountain-web-studio.com or by post at the controller address in Section 1.
Also see our Terms of Service.