Privacy policy
Information about personal-data processing, cookies and the rights available to people using the portal.
1. Data controller
The controller of personal data is Nikicomp Katarzyna Marcjaลska, ul. Wiejska 45, 05-850 Oลผarรณw Mazowiecki, VAT ID (NIP): 5792059039, REGON: 365631663. Data protection contact: [email protected].
2. What we process and why
- technical data (IP address, server logs) โ to secure and operate the Portal (Art. 6(1)(f) GDPR โ legitimate interest);
- correspondence data (e-mail, message content) โ to reply to you (Art. 6(1)(f) GDPR);
- data of people presented in profiles and editorial materials (name or professional name, public contact details, area of activity, services, and links to events or organisations) โ to help visitors find publicly offered services, initiatives, and events (Art. 6(1)(f) GDPR โ the legitimate interests of the Controller and Portal visitors);
- preferences stored on your device (filters and the country used to order discovery sections) โ only with your consent (see section 6);
- content of the anonymous feedback survey on the About page โ to improve the Portal (Art. 6(1)(f) GDPR); the survey collects no identifying data and we ask you not to include any;
- event-submission form data (description, link, optional contact e-mail) โ to verify and publish the event and to contact you if needed (Art. 6(1)(f) GDPR); the e-mail is never published.
For registered accounts we process the verified email address, the selected sign-in provider identifier, session data, and profile content edited by the user to create the account, secure access, and perform the requested profile publication and management service (Art. 6(1)(b) GDPR). Optional information that is not necessary for the service is provided voluntarily and can be removed by the user at any time.
3. Data obtained from public sources โ Article 14 notice
Some basic entries may be created from information that a person has made public in connection with their professional activity or event organisation. This also applies to sole traders. Sources may include the person's or organisation's official website, public professional social profiles, public event and venue pages, and public business registers. We provide the specific source on request and, where possible, the entry links to the source page.
In this situation we process only data necessary for the Portal's information function: professional name or personal name, publicly offered services, city or countries of activity, public professional contact details and links, information about an organisation or event, and the source and verification date. We do not automatically publish a home address, private phone number, or private email address. We do not combine multiple sources into an extensive personal profile unless this is necessary to present the person's public activity.
We do not infer religious or philosophical beliefs, health, sex-life, or other special-category data. We do not ask for such information in a profile. Publishing it requires a separate Art. 9 GDPR condition, such as explicit consent or the person's clear affirmative action by which they manifestly made the specific data public themselves (Art. 9(2)(e) GDPR). We rely on that condition for public-source material only after individual review and only where the information is necessary to present the offered activity.
Before relying on Art. 6(1)(f), the Controller assesses whether the purpose is lawful, whether the scope is necessary, and how publication affects the person's rights and reasonable expectations. Where a public professional contact channel is available, we provide an individual notice within a reasonable period, no later than one month, at first contact, or no later than first disclosure โ whichever occurs first. We rely on the impossibility or disproportionate-effort exception only after a documented assessment; in that case this public notice and an easy data-rights contact are safeguards.
4. Recipients
Data marked as public are disclosed to Portal visitors and may be indexed by internet search engines. Other data may be entrusted to hosting and technical providers acting on the controller's behalf under data-processing agreements. Data are never sold and are not used for automated decision-making or profiling.
Federated sign-in is handled by Microsoft Azure and the provider chosen by the user (for example Google or Facebook), under that provider's own privacy policy.
Providers may include Microsoft Azure (hosting, database, file storage, and authentication) and OpenAI (tools assisting the editorial team with content). AI tools do not make decisions producing legal effects for people presented on the Portal, and material is reviewed editorially before publication. If a provider processes data outside the European Economic Area, the transfer uses an appropriate Chapter V GDPR mechanism, such as an adequacy decision or Standard Contractual Clauses; information about the applicable safeguard is available from[email protected].
5. Retention and accuracy
Archived technical logs โ up to 7 days; application console output is not archived. Correspondence โ until the matter is closed and for the limitation period of claims. An account and user-managed profile are retained until the account or profile is deleted, subject to any period needed to establish, exercise, or defend legal claims. Entries created from public sources are reviewed periodically, at least every 90 days; an outdated entry, or one whose accuracy cannot be confirmed, is deleted or reduced to strictly necessary archival data where a separate legal basis permits retention.
Portal sessions expire after 7 days.
6. Cookies & local storage
The Portal uses first-party cookies and browser local storage only. The "preferences" and "analytics" categories operate only after consent given in the banner (changeable any time via "Cookie settings" in the footer).
| Name | Purpose | Category |
|---|---|---|
| unmeshia_user_session | Signed-in user session (7 days) | necessary |
| AppServiceAuthSession | Azure sign-in session with the selected provider | necessary |
| unmeshia_consent | Stores your cookie decision (12 months) | necessary |
| unmeshia_admin_v3 | Editorial panel session (editors only) | necessary |
| NEXT_LOCALE | Remembers the chosen language | necessary |
| localStorage: unmeshia:filters:* | Remembers chosen filters on this device | preferences (with consent) |
| unmeshia_country | Remembers the country used to prioritize discovery sections | preferences (with consent) |
7. Your rights
You have the right of access, rectification, erasure, and restriction. Data portability applies within the scope of Art. 20 GDPR. Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing. Requests: [email protected]. You may also lodge a complaint with the Polish supervisory authority (PUODO, uodo.gov.pl).
Right to object: where we rely on Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the data are needed to establish, exercise, or defend legal claims. In practice, we handle credible requests to remove a basic aggregated entry without undue delay and suppress the source so that an automated process does not add it again.
8. Correcting, claiming, or removing an entry
If the Portal presents your profile or business information, you may ask for the source, rectification, restriction, erasure, or to claim and manage the profile yourself. Write to [email protected]. We may request only the information needed to verify that the request comes from the person concerned.
9. Changes
Significant changes will be announced on this page. Version of 13 July 2026.