Last updated: July 22, 2026
1. Who we are
Vestigit Sp. z o.o., with its registered office at Rynek 4C, 37-530 Sieniawa, Poland, NIP 7941824926, KRS 0000734359 (“Vestigit”, “we”, “us” or “our”), is the controller of personal data processed through the corporate website available at www.vestigit.com (the “Website”).
This Privacy Policy applies to visits to the Website and enquiries submitted through it. It does not replace privacy or data-processing terms agreed with customers for Vestigit products and services. Processing performed for a customer is governed by the applicable commercial agreement and data processing agreement.
2. Personal data we collect
We may process:
- Contact and enquiry data: business email address and any optional information you choose to provide, such as your name, company, website, role, country, organisation type, content type, project stage, goals, scale, vendors, timeline and message.
- Technical data: IP address, browser and device information, request timestamps, referring URL, pages requested, server logs and information required to operate, secure and troubleshoot the Website.
- Validation and anti-abuse data: the domain portion of an email address used to verify whether the domain can receive email, and, where enabled, a short-lived anti-abuse verification token. We do not send the full email address to the DNS verification service.
- Correspondence data: information contained in subsequent communications relating to an enquiry.
Please do not submit special-category personal data, confidential customer data, credentials or production identifiers through the Website form.
3. Why we process personal data and our legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Responding to enquiries, arranging demonstrations or technical discovery, and taking steps toward a potential business relationship | Contact, enquiry and correspondence data | Steps requested before entering into a contract, Article 6(1)(b) GDPR; and our legitimate interest in conducting B2B communications, Article 6(1)(f) GDPR. |
| Operating, securing and troubleshooting the Website, preventing spam and abuse, and validating business email domains | Technical and validation data | Our legitimate interest in maintaining a secure and reliable corporate website, Article 6(1)(f) GDPR. |
| Establishing, exercising or defending legal claims and complying with legal obligations | Relevant contact, correspondence and technical data | Compliance with legal obligations, Article 6(1)(c) GDPR; and our legitimate interest in protecting our rights, Article 6(1)(f) GDPR. |
| Optional analytics or marketing communications, if introduced and expressly selected by you | Data covered by the relevant consent | Consent, Article 6(1)(a) GDPR. Vestigit does not currently use optional analytics or advertising cookies and does not use Website enquiry data for unsolicited marketing. |
4. Is providing data mandatory?
Providing a valid business email address is necessary if you want us to reply to an enquiry. Other form fields are optional unless clearly marked otherwise. If the required data is not provided, we may be unable to respond or assess the request.
5. Email-domain and anti-abuse verification
To reduce invalid submissions, the Website may check whether the domain portion of an email address has a valid mail route using DNS-over-HTTPS. Only the domain, not the complete email address or message content, is included in that check.
Where enabled, the contact form may also use Cloudflare Turnstile or a comparable anti-abuse service. That service may process technical information and a short-lived verification token solely to distinguish legitimate submissions from automated abuse.
6. Who may receive personal data?
We may disclose data only where necessary to:
- hosting, infrastructure, security and website-maintenance providers;
- communication providers, including Microsoft 365 where it is used to handle enquiries;
- DNS and anti-abuse providers, including Cloudflare where the relevant verification is enabled;
- professional advisers such as legal, accounting or security advisers;
- public authorities or courts where disclosure is required by law.
These recipients process data under their own legal obligations or under agreements requiring appropriate confidentiality and security. We do not sell personal data.
7. International transfers
Some technology providers may process data outside the European Economic Area. Where this involves an international transfer of personal data, Vestigit relies on a lawful transfer mechanism, such as an adequacy decision or appropriate safeguards under Article 46 GDPR, as applicable.
8. How long we keep data
We retain personal data only for as long as necessary for the purpose for which it was collected:
- enquiry and correspondence data is kept while the enquiry or potential business relationship remains active and afterwards for the period reasonably required to document communications, comply with legal obligations, and establish, exercise or defend claims;
- technical and security data is retained according to operational and security needs and the retention settings of the relevant infrastructure provider;
- data processed on the basis of consent is retained until consent is withdrawn or the stated purpose ends, unless another legal basis requires longer retention.
9. Your rights
Subject to the conditions of the GDPR, you may request:
- access to your personal data;
- rectification of inaccurate or incomplete data;
- erasure of data;
- restriction of processing;
- portability of data where applicable;
- withdrawal of consent at any time, without affecting processing carried out before withdrawal;
- objection to processing based on legitimate interests, including an absolute right to object to direct marketing if it is ever used.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO).
10. Automated decision-making
Vestigit does not use personal data collected through the Website for decisions based solely on automated processing that produce legal or similarly significant effects.
11. Security
We use organisational and technical measures appropriate to the nature of the Website and the data processed. No internet transmission or storage system can be guaranteed to be completely secure, so please avoid submitting unnecessary confidential information.
12. Links to other websites
The Website contains links to third-party websites. Their operators are responsible for their own privacy practices. This Privacy Policy does not govern third-party websites.
13. Changes to this Policy
We may update this Privacy Policy when the Website, our processing activities or applicable requirements change. The current version and update date will always be published on this page.
14. Contact
To exercise your rights or ask a privacy question, use the Vestigit contact form or write to:
Vestigit Sp. z o.o.Rynek 4C
37-530 Sieniawa
Poland