Privacy policy
How we process personal data on this site, under the GDPR and Polish law.
Last updated: 27 September 2026
Version 1.0
1. Data controller
The data controller is Adrian Wojtyła, wirelab (wirelab.pl), address: Krefeld. Privacy contact: nairda [at] wirelab [dot] pl.
No data protection officer has been appointed. Write to the address above for privacy requests.
2. What we process
The scope depends on what you use. We do not collect data “just in case” and we do not profile visitors.
Contact form and email. If you write via the form or directly to nairda [at] wirelab [dot] pl, we process: your name or sign-off, email address, message body and the date received. The form does not accept attachments. Alongside the message we store proof of consent: the date, the clause version, a user-agent string and an irreversible hash of your IP address (the address itself is not kept). We also forward the message to ourselves by email through our own mail server.
Technical logs. The server and hosting provider may keep standard logs (IP address, date and time, requested URL, user agent) for security and diagnostics.
Admin panel. Only the site owner can sign in at /admin. A session cookie is set after login. Public visitors do not receive it.
Cookies and local storage. Details are in the cookie policy. Saving the light/dark theme needs consent. We store the consent choice itself so we do not ask on every visit.
Visit statistics. We keep them ourselves, on the same server and without cookies. We record the page path, language, device type, response code and the domain you came from — never the full referring URL. Instead of an IP address we store a hash derived from a secret that rotates daily and is never kept, so after a day visits cannot be linked to the same person or traced back to an address. We build no profiles and do not combine this with contact messages.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Reply to an enquiry | name, email, message | GDPR Art. 6(1)(b) (steps at your request before a contract) and Art. 6(1)(f) (legitimate interest — correspondence) |
| Site security | technical logs | GDPR Art. 6(1)(f) |
| Admin session | session cookie | GDPR Art. 6(1)(b) and (f) — only after the owner signs in |
| Record and remember consent | localStorage wirelab-consent | GDPR Art. 6(1)(c) and Art. 399 of the Polish Electronic Communications Law |
| Remember light/dark theme | localStorage wirelab-theme | GDPR Art. 6(1)(a) and Art. 399 of the Electronic Communications Law — only with consent |
We do not profile you or take automated decisions that produce legal effects.
4. Recipients
We do not sell form data or share it with advertisers. Recipients may include:
- the hosting and database provider — as a processor (GDPR Art. 28), only to keep the site running;
- public authorities, where the law requires disclosure.
5. Transfers outside the EEA
Fonts are hosted on this site — we do not load Google Fonts. We do not use Meta Pixel, ad tags or other tracking scripts. Visit statistics are kept in-house on the same server: no cookies, no stored IP address, nothing sent to third parties. If Google Analytics has been enabled in the admin panel, the Google script loads only after you accept the analytics category — only then does data reach Google (including outside the EEA, under standard contractual clauses). Without consent we send Google nothing.
6. Retention
- Contact messages: until the exchange is finished, no longer than 12 months, unless we need them longer to establish or defend a legal claim.
- Technical logs: typically up to 30 days, following the host’s practice.
- Detailed page views in statistics: 60 days by default (configurable in the panel), after which only daily totals without identifiers remain.
- Log of sent email notifications: 180 days.
- Consent record (wirelab-consent): until you change it or clear site data in the browser.
- Theme (wirelab-theme): until you withdraw consent or clear site data.
- Admin session: 14 days or until sign-out.
7. Your rights
You may request access, rectification, erasure, restriction, portability, object to processing based on legitimate interest, and withdraw consent where consent is the basis — without affecting the lawfulness of processing before withdrawal.
Send requests to nairda [at] wirelab [dot] pl. You may also lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl
8. Voluntary nature
The form is voluntary. Without a name, email and message we cannot reply. Rejecting optional storage does not block the site.
9. Children
This site is not directed at people under 16 and we do not knowingly collect children’s data.
10. Client account
If we invite you to /en/account, we process: name, email, password (hash), ticket contents, job files and stage history. Purpose: delivering the work. Basis: GDPR Art. 6(1)(b). Accounts are invite-only — there is no public sign-up.
Job data is kept for 24 months after close, then archived on request or deleted. Session cookie: wirelab_client or __Host-wirelab_client (14 days). Files are not public — download requires sign-in.
11. Forum
The forum at forum.wirelab.pl runs on separate software (NodeBB) and has its own accounts, independent of the client account. If you sign up there, we process: username, email, password (hash), the content of your posts and messages, any profile details you add, and the IP addresses used to sign in and post. Purpose: running the forum (GDPR Art. 6(1)(b)) and keeping it secure against spam and break-ins (GDPR Art. 6(1)(f)).
Forum posts are public: they can be read without signing in and may appear in search engines. You can delete your account in your profile settings or by asking us by email. Account data is then deleted straight away and disappears from backups within 6 months at the latest. The forum uses one strictly necessary session cookie (express.sid, 14 days) on forum.wirelab.pl.
12. Academy
The Academy (akademia.wirelab.pl) has its own learner accounts, separate from forum accounts and from the client account. If you sign up, we process: email address, name (if you give one), password as a hash (we never know the password itself), language, the date your email was confirmed, account creation and last sign-in dates, the version and date you accepted the Academy terms, and the date you agreed to news about new courses (if you did — you can withdraw it in account settings). When you enrol in a course we store the course, the source and dates of access (granted, expiry, revoked) and your learning progress: completed and recently opened lessons with dates. Account data is not payment for the courses — we do not use it for advertising or profiling.
Points, levels and certificates: we store the points awarded (for which lessons and courses), your study days and the time spent on lessons (to measure progress), the course completion date and the certificate data — the full name you give for the certificate, the course, the date and the code. The certificate verification page is public to anyone who has the code: it shows your first name and the initial of your surname, and your full name only with your consent (a switch in your settings you can turn off). Basis: performance of the contract (Art. 6(1)(b) GDPR), and your full name on the verification page — your consent (Art. 6(1)(a) GDPR). When you delete your account, your certificates are revoked and their data anonymised.
You may create an account on your own from the age of 16; a person aged 13–15 needs a parent’s or legal guardian’s consent. A person under 16 agrees to news about new courses only with a parent’s or guardian’s consent (Article 8 GDPR). If we learn that an account was created by a child under 13 or without the required consent, we will delete it or ask for the guardian’s consent.
Purpose and legal basis: running the account and providing courses — performance of the contract (GDPR Art. 6(1)(b)); account security and abuse prevention — our legitimate interest (GDPR Art. 6(1)(f)); news about new courses — your consent (GDPR Art. 6(1)(a)).
Waitlist: if you leave your email on a course that has not launched yet, we store the address, language, course, the date you agreed to a one-off launch message and the date it was sent. Legal basis: your consent (GDPR Art. 6(1)(a)) — withdraw it by writing to nairda [at] wirelab [dot] pl.
We do not store IP addresses with learner accounts. An IP address is used temporarily for attempt limits (sign-up, sign-in, password reset) and disappears when the limit window ends (one hour at most); failed sign-ins go to the server log with the IP address and a hash of the email address (technical logs, section 2). Email links and sessions are stored only as cryptographic hashes; the email confirmation link is valid for 48 hours and the password reset link for one hour.
The learner session uses one strictly necessary cookie, wirelab_learner or __Host-wirelab_learner (HttpOnly, 30 days or until sign-out), on the Academy host. Lesson videos may be played from the servers of Bunny Stream (BunnyWay d.o.o., Slovenia) — your browser then connects to its servers, which see your IP address.
You can delete your account at any time in account settings or by asking us by email. Account data is then anonymised straight away: email, name, password and consents are removed, and enrolments, progress, sessions, links and waitlist entries are deleted. Data disappears from backups within 6 months at the latest.
13. Changes
The current version is always at this address. The date of the last change is at the top. If processing changes in a material way — including new analytics scripts — we will ask for consent again.