Last updated: 27 August 2026

This Privacy Policy explains how Hazards Control sp. z o.o. processes personal data when you use this website or contact us. We keep the scope of processing limited to what is necessary to operate the website, respond to enquiries and provide our professional services.

1. Data controller

The controller of your personal data is Hazards Control sp. z o.o., with its registered office at 8 Miła Street, Unit 13, 00-174 Warsaw, Poland, entered in the National Court Register under KRS 0001221457, NIP 5253077691.

For privacy-related matters, contact us at hazardscontrol@hazardscontrol.pl or by post at the registered-office address above.

2. What data we process

The public website does not currently use an online contact form. If you contact us by email or telephone, we may process your name, contact details, organisation or role, the content of your enquiry and any information or documents you choose to provide. Please do not send personal data that is unnecessary for your enquiry.

The website contains a basic search function. A search term is sent as part of the requested website address. Like most websites, the server may also record technical information needed to deliver and protect the service, such as an IP address, date and time of a request, requested address, response status, browser or device information and referring page.

We do not use personal data for automated decision-making or profiling.

3. Purposes and legal bases

  • Answering enquiries and taking steps before a contract — Article 6(1)(b) GDPR or, where you contact us on behalf of an organisation, our legitimate interest in conducting business correspondence under Article 6(1)(f) GDPR.
  • Performing contracts and managing professional assignments — Article 6(1)(b) GDPR.
  • Meeting accounting, tax and other legal duties — Article 6(1)(c) GDPR.
  • Operating, securing and diagnosing the website and preventing misuse — our legitimate interest under Article 6(1)(f) GDPR.
  • Keeping necessary business records and establishing, exercising or defending legal claims — our legitimate interest under Article 6(1)(f) GDPR.

4. How long we keep data

  • Enquiries that do not lead to an assignment are normally kept for up to 12 months after the correspondence ends, unless a longer period is necessary to protect against or pursue a claim.
  • Data connected with an assignment or contract is kept for its duration and afterwards for the periods required by law. Accounting and tax records are generally retained for five years, calculated in accordance with applicable Polish law.
  • Information needed for legal claims may be kept until the relevant limitation period has expired.
  • Technical logs are kept for the shortest period needed to maintain security, availability and diagnostics. A relevant log entry may be retained longer where necessary to investigate an incident, comply with law or protect a legal claim.

5. Who may receive data

Data may be made available, only where necessary, to providers supporting website hosting and administration, email and telecommunications, IT security, accounting or legal services. These providers act under appropriate contractual and confidentiality obligations. Data may also be disclosed to public authorities where required by law.

We do not sell personal data and do not disclose website visitor data to advertising networks or data brokers. If a service provider processes data outside the European Economic Area, we use a lawful transfer mechanism required by the GDPR, such as an adequacy decision or Standard Contractual Clauses, together with appropriate safeguards.

6. Cookies and external tools

As of the last update of this Policy, the public website does not use analytics or advertising tools, marketing pixels, social-media trackers, reCAPTCHA, third-party maps or embedded third-party media. Its fonts, theme files and scripts are served from the hazardscontrol.com domain. Public pages do not set analytics or marketing cookies.

WordPress may use strictly necessary session or security cookies for restricted administrative functions, such as administrator sign-in. These are not used to profile public visitors. Because the public website currently uses no cookies or similar technologies that require consent, no cookie-consent banner is displayed. If this changes, we will update this Policy and introduce a consent mechanism before any non-essential technology is activated.

The website may contain ordinary links to external websites. Their operators process data under their own privacy rules only after you choose to follow such a link.

7. Your GDPR rights

Depending on the circumstances, you have the right to request access to your data, rectification, erasure, restriction of processing and data portability. You may object, on grounds relating to your particular situation, to processing based on our legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing.

To exercise a right, contact us using the details in section 1. We may need to verify your identity before acting on a request.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), the Polish supervisory authority.

8. Is providing data required?

Providing data is voluntary, but without the information needed to understand and answer an enquiry we may be unable to respond or enter into a contract. Where data is required by law or for a contract, we will explain this when relevant.

9. Security and changes

We apply organisational and technical measures appropriate to the nature of the data and the risks involved. This Policy may be updated when the website, our services or legal requirements change. The current version will always be available at this address.