Legal information
Privacy and cookies policy.
How PLAN GROUP sp. z o.o. processes data in connection with the PLDM website.

Document
Privacy and cookies policy.
Rules for personal-data processing and the use of cookies on the PLDM website.
Last updated: 7 September 2026.
1. Data controller
The controller is PLAN GROUP sp. z o.o., al. Grunwaldzka 413, 80-309 Gdańsk, Poland, KRS 0000971382, NIP 5842817738, REGON 522004318. For privacy matters contact hello@plangroup.pl.
2. Data we may process
Depending on how you contact us, we may process your name, email address, phone number, company name, website address, enquiry content, correspondence data and information required to prepare or deliver cooperation. The server may also process technical information such as IP address, browser and device data, connection time and security logs.
3. Purposes and legal bases
- handling enquiries and correspondence — Article 6(1)(b) GDPR where the contact aims at entering into a contract, or Article 6(1)(f) GDPR;
- entering into and performing a contract — Article 6(1)(b) GDPR;
- tax, accounting and other legal obligations — Article 6(1)(c) GDPR;
- establishing, exercising or defending claims, website security and abuse prevention — Article 6(1)(f) GDPR;
- Tawk.to chat — only after the user enables functional services, where consent is the applicable basis;
- Google Ads, campaign effectiveness measurement and possible advertising personalisation — only after marketing consent.
4. Contact forms
Providing data is voluntary, but fields marked as required are necessary to handle the enquiry. We do not require marketing consent merely to reply to a message.
5. Retention
- enquiry data that does not lead to cooperation is generally retained for the duration of correspondence and no longer than 12 months after the last meaningful contact, unless a longer period is justified by claims or legal obligations;
- contract-related data is retained for the duration of the contract and then for periods required by law and limitation periods;
- technical and security logs are retained for periods justified by website security and incident diagnosis.
6. Recipients
Data may be processed by providers of hosting, email, IT systems, analytics or advertising tools enabled with consent, security, legal and accounting services, only to the extent necessary for their services.
7. Transfers outside the EEA
Where a provider transfers data outside the EEA, we use mechanisms permitted by Chapter V GDPR, including adequacy decisions or Standard Contractual Clauses as appropriate.
8. Your rights
You may have the right to access, rectify, erase or restrict processing, to data portability, to object, and — where processing is based on consent — to withdraw consent at any time. You may lodge a complaint with the President of the Personal Data Protection Office in Poland.
9. Cookies and local storage
The website uses necessary technical mechanisms and local storage to remember privacy settings. Optional Tawk.to chat is loaded only after functional consent. Google Ads tools are loaded only after marketing consent. Montserrat is hosted locally and does not require a connection to Google Fonts.
10. Consent management
You can change or withdraw optional choices at any time using the “Cookie settings” button in the footer. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
11. Automated decisions and profiling
We do not make decisions producing legal or similarly significant effects solely by automated means. Marketing tools may support advertising measurement or personalisation only where the relevant consent has been given.
12. Security and changes
We use technical and organisational measures appropriate to the risk. This policy may be updated when the website, tools, services or legal requirements change.