Privacy Policy
Last updated: 31 July 2026
1. Data controller
The controller of personal data is:
Brillnet Piotr Adamski
ul. Sienkiewicza 73/6
90-057 Lodz, Poland
Tax ID (NIP): PL7321779060
Privacy contact: kontakt@brillnet-app.com
2. Scope
This policy describes data processing on brillnet-app.com, including contact forms, newsletter or product-update subscriptions, information about Brillnet products, and cookie or similar-technology preferences.
The website presents Brillnet's current and planned offer. Detailed rules for individual applications, if made available, may be described in separate terms or contracts.
3. Data we may process
Depending on how the website is used, we may process:
- contact data submitted in a form, such as first name, last name, company name, e-mail address, phone number and message content,
- newsletter and marketing-subscription data, such as e-mail address, first name, last name, company name, source of subscription, subscription date, consent status and unsubscribe history,
- technical data, such as IP address, request identifiers, browser and device information, and basic security logs,
- cookie and similar-technology preferences stored in the user's browser,
- aggregated statistics about website operation and popularity,
- billing and contractual data if a contact leads to an agreement with Brillnet.
We do not ask users to provide special-category data, such as health data, political opinions, religion or sexual orientation.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Handling contact forms, responding to inquiries and preparing offers | Art. 6(1)(b) GDPR where the inquiry concerns pre-contractual steps, or Art. 6(1)(f) GDPR where we respond to ordinary correspondence |
| Sending newsletters, product updates and marketing communication to people who subscribed through our forms or are in a business relationship with Brillnet | Art. 6(1)(a) GDPR where consent is used, or Art. 6(1)(f) GDPR for business contacts in an existing relationship; electronic marketing is sent only where we have the required consent or another permitted basis |
| Maintaining correspondence and documenting arrangements | Art. 6(1)(f) GDPR - legitimate interest in handling inquiries and protecting the controller's interests |
| Website security, form abuse prevention and error diagnostics | Art. 6(1)(f) GDPR - legitimate interest in maintaining a secure website |
| Aggregated website performance measurement through Cloudflare Web Analytics | legitimate interest in maintaining website performance; according to Cloudflare documentation, this tool does not use cookies or localStorage and does not collect visitors' personal data |
| Contract performance, billing and tax obligations | Art. 6(1)(b) and 6(1)(c) GDPR |
| Establishing, pursuing or defending claims | Art. 6(1)(f) GDPR |
5. Cookies and similar technologies
The website uses cookies, browser local storage and similar technologies where needed to operate the website and remember user preferences.
Details are available in the Cookie Policy. Preferences can be changed through the Cookie settings button in the website footer.
6. Recipients and processors
Data may be shared with providers that help us operate the website, handle inquiries and send e-mail messages. We use only providers needed for website operation, security, correspondence and newsletter delivery.
| Provider | Role | Data scope |
|---|---|---|
| Resend / Plus Five Five, Inc. | delivery of form messages, newsletters and product updates | first name, last name, e-mail address, company name, message content, subscription source, consent or unsubscribe status, and technical delivery metadata |
| Cloudflare | CDN, website security and abuse prevention | technical request data, IP address, security signals |
| Accounting, legal or administrative providers | contracts, billing and legal obligations | contact, contractual and billing data where needed |
| Public authorities | legal obligations | data required by applicable law |
Processors acting on our behalf process data under appropriate agreements or other mechanisms required by GDPR.
The current processor list for the Brillnet landing page is available in the Processor List.
7. Transfers outside the EEA
Some technical providers may process data outside the European Economic Area. This applies in particular to Resend / Plus Five Five, Inc., a provider based in the United States that we use for e-mail delivery. Where such a transfer occurs, we rely on GDPR-compliant mechanisms, including adequacy decisions, the EU-US Data Privacy Framework, Standard Contractual Clauses, data processing agreements or other appropriate safeguards.
8. Retention periods
| Data type | Retention period |
|---|---|
| Contact-form correspondence | for the time needed to handle the matter, then generally up to 3 years from the end of the year of the last contact, unless a longer period is needed to establish or defend claims |
| Newsletter and product-update data | until consent is withdrawn, the user unsubscribes or an objection is effective; proof of consent, subscription source and unsubscribe history may be retained longer to demonstrate compliance |
| Contractual and billing data | for the contract term and the period required by tax and accounting rules |
| Technical and security logs | for the period needed for diagnostics and security, generally up to 90 days unless the logs concern an incident |
| Cookie and similar-technology preferences | until settings are changed, consent is withdrawn, browser data is deleted or the consent mechanism version changes |
9. Data subject rights
You have the right to:
- access your data,
- rectify inaccurate data,
- erase data,
- restrict processing,
- data portability where applicable,
- object to processing based on legitimate interest,
- withdraw consent at any time without affecting the lawfulness of earlier processing,
- lodge a complaint with the President of the Polish Data Protection Office.
Requests can be sent to: kontakt@brillnet-app.com.
Each newsletter or marketing e-mail should include a simple unsubscribe option. We do not use newsletter open tracking or link-click tracking unless that feature is separately disclosed and has an appropriate legal basis.
10. Data security
We apply technical and organisational measures appropriate to the risk, including TLS encryption, access restrictions, form protections and monitoring of errors and abuse.
11. Automated decisions
We do not make decisions about website users based solely on automated processing that would produce legal effects or similarly significantly affect them. We do not conduct advertising profiling.
12. Policy changes
This policy may be updated when the website, Brillnet's offer, the tools we use or the law changes. The current version is published on this page.
13. Contact
For privacy questions, contact us:
- Email: kontakt@brillnet-app.com
- Website: brillnet-app.com