Legal Document
Privacy Policy
Last updated: 16 July 2026
1. About this document
This policy describes what happens to your data when you visit mcoderz.com or write to us through the contact form.
The site belongs to a sole proprietorship trading under the MCoderZ Labs brand. Full company details are in section 2.
In short: we use no analytics, we have no ads and no remarketing, we do not profile visitors and we do not sell data. We process what you type into the form, plus the technical data that any website request produces.
This document applies from 16 July 2026.
2. Who the data controller is
The controller of your personal data is:
Miłosz Gołas, trading as DIGITAL SOLUTIONS MIŁOSZ GOŁAS
Osiedle Na Lotnisku 1 lok. 29
31-801 Kraków, Poland
NIP (tax ID): 6321964756
REGON: 545258825
E-mail: hi@mcoderz.com
MCoderZ Labs is a trading brand of this business, not a separate company. The controller, and your counterparty, is the natural person named above. The address given is the registered place of business and the address for service, matching the CEIDG register entry.
The controller has not appointed a Data Protection Officer, as there is no obligation to do so (art. 37(1) GDPR). For any matter concerning personal data, write to hi@mcoderz.com.
3. What data we collect
We collect data in four areas.
Contact form data, meaning whatever you type in:
• first and last name: required, minimum 3 characters
• e-mail address: required
• message: required, minimum 10 characters, maximum 500
• company name: optional
The form has no phone number field and we do not collect one this way.
Technical data, produced automatically on every page request:
• IP address
• browser and system type and version (the User-Agent header)
• the page requested, the referring page, date and time
• country derived from the IP address, used solely to pick the language version on your first visit
Data collected by the form protection (hCaptcha):
• IP address plus browser and device information
• in-browser behavioural signals: cursor movement, scrolling, keyboard and touch events
• cookies and data stored in the browser
hCaptcha only starts once you begin filling in the form. If you are just reading the site and never touch the form, it does not load at all and collects nothing. Its sole purpose is telling a human apart from a bot.
Data recorded in the cookie decision log:
• truncated IP address and country
• the content and date of your banner decision
• a record identifier
The Cookie Policy covers this in detail; the link is in the site footer.
4. Why we process data and on what basis
Each purpose has its own legal basis. We set them out separately.
1) Answering an enquiry from the form, e-mail or phone.
Basis: art. 6(1)(f) GDPR, our legitimate interest. That interest is communicating with people who contact us and answering the question asked.
Where the enquiry is heading towards working together, the basis is art. 6(1)(b) GDPR, steps taken at your request before entering into a contract, such as preparing a quote or an offer.
2) Protecting the site and the form against spam, bots and abuse.
Basis: art. 6(1)(f) GDPR. Our interest is protection against automated abuse and keeping the site and mailbox working.
3) Delivering the site and making it work, including technical logs on the hosting side and remembering your language version.
Basis: art. 6(1)(f) GDPR. Our interest is running the site securely and reliably, as a visitor would expect.
4) The log of decisions made in the cookie banner.
Basis: art. 6(1)(f) GDPR. Our interest is being able to show what the banner asked and what you answered, and honouring that choice should cookies requiring consent ever appear. Today we base no processing on consent under art. 6(1)(a) GDPR.
5) Establishing, pursuing or defending claims.
Basis: art. 6(1)(f) GDPR. Our interest is being able to evidence the course of correspondence and defend against potential claims.
6) Accounting and tax obligations, if we end up working together and issuing an invoice.
Basis: art. 6(1)(c) GDPR, in connection with the Polish Accounting Act and the Tax Ordinance.
5. Do you have to provide data
Providing data is voluntary. No statute and no contract requires it.
To answer you we need your name, e-mail address and the message. Without an e-mail address we have no way to reply, and without a message we do not know what you are writing about. The consequence of not providing these is that the form cannot be sent, so you get no answer from us.
Company name is optional. Give it if you want us to know straight away who you are writing on behalf of.
You do not have to use the form. You can simply write to hi@mcoderz.com. Then you provide only as much as you see fit.
Please do not send us special category data as referred to in art. 9 GDPR, such as health information. Please also avoid sending other people's data unless necessary. The contact form is not intended for that.
Ticking the checkbox under the form confirms that we gave you this information before you sent the message. It is not consent to processing and not a legal basis for it: the bases are listed in section 4. A privacy policy is not something to accept, only something to read.
6. Who receives your data
We do not sell data and we do not share it with anyone for marketing purposes. We use neither Google Analytics nor any other analytics tool. We have no advertising pixels.
Your data does however reach the providers without which the site and the form would not work. We have a data processing agreement with each of them:
• Vercel Inc. (United States), hosting and site delivery. Receives the IP address and technical data of every request, and stores technical logs.
• Web3Forms, a product of Web3Creative, based in India, contact form delivery. Receives all form data plus your IP address. Uses its own sub-processors, including Amazon Web Services and Cloudflare.
• Intuition Machines, Inc. (United States), owner of hCaptcha, form protection against bots. Receives the data described in section 3.
• CookieYes Limited (United Kingdom), cookie banner and decision log. Receives your IP address when the script loads, plus the record of your decision. Uses sub-processors in India and the United States.
• the e-mail provider hosting the mailbox Web3Forms forwards form messages to.
Intuition Machines also uses interaction data from the protection widget for its own purposes, including developing and training bot-detection models. To that extent it determines the purposes itself and answers for that data as a separate controller, outside our processing agreement. Its own privacy policy covers the detail: hcaptcha.com/privacy.
The form is submitted from your browser straight to Web3Forms. The message body does not pass through our server or our hosting and is not written to hosting logs. That was deliberate, to reduce the number of places this data appears at all.
Beyond that, data may reach:
• our accountant and legal adviser, if we work together or a dispute arises
• public authorities, if they demand data on a legal basis
7. Transfers outside the European Economic Area
Some of the providers we use are established outside the European Economic Area. Your data is therefore transferred to a third country. This concerns:
• Vercel Inc. and Intuition Machines, Inc. (hCaptcha): United States
• Web3Forms: India, and for infrastructure also the United States
• CookieYes Limited: United Kingdom, and for sub-processors also India and the United States
We transfer data outside the EEA only where at least one of the grounds in Chapter V GDPR applies:
1) A European Commission adequacy decision (art. 45 GDPR). For the United Kingdom, the Commission renewed such a decision on 19 December 2025. For the United States, on 10 July 2023 the Commission adopted implementing decision (EU) 2023/1795 on the EU-US Data Privacy Framework. Where a given recipient holds a current certification under that programme, the transfer relies on that basis.
2) Standard contractual clauses approved by the European Commission (art. 46(2)(c) GDPR). We rely on them for recipients not covered by an adequacy decision, in particular in India, for which no such decision has been issued. We also rely on them as a fallback, should an adequacy decision cease to apply or a recipient lose its certification.
3) Other safeguards or derogations provided for in art. 46 and art. 49 GDPR, where applicable.
The basis for a transfer depends on the specific recipient and may change, for instance if the status of an adequacy decision changes. We provide current information on the basis for a given provider, and a copy of the standard contractual clauses, on request. Write to hi@mcoderz.com.
8. How long we keep data
• Correspondence from the form and by e-mail: for as long as the matter is live, then up to 3 years from the last contact. Three years is the limitation period for claims connected with running a business (art. 118 of the Polish Civil Code). If a contract follows, data relating to its performance is kept for up to 6 years from the end of the engagement: six years is the general limitation period under the same provision.
• Accounting records: 5 years, counted from the end of the tax year in which the tax obligation arose (art. 86 § 1 of the Tax Ordinance).
• Cookie decision log: a decision stays valid for 12 months, after which the banner asks again. CookieYes runs the log and deletes it under its own terms. We do not copy that log into any database of ours.
• Server technical logs: produced by the hosting provider (Vercel Inc.), which sets and applies its own retention period under the chosen service plan. We do not download these logs, do not copy them and do not build any database from them. We provide the provider's current period on request.
• Data held by Web3Forms: the provider states in its privacy policy and processing agreement that it deletes submitted form content no later than 3 years after submission.
• Data held by hCaptcha: under the provider's privacy policy, cookies are kept for up to 12 months, and abuse-detection data may be kept longer, for the period the provider specifies. We have no access to that data and no influence over those periods.
After these periods we delete the data. If you ask for deletion sooner we will do it, unless we have grounds to keep it, such as an unsettled matter or an ongoing dispute.
9. Cookies
Cookies are covered separately, in the Cookie Policy. The link is in the site footer. It lists every file, its lifetime and its legal basis.
The essentials:
• we have no analytics, including Google Analytics, no advertising pixels, no remarketing and no marketing cookies
• we do not track you across other sites
• only strictly necessary files operate: remembering the language version, storing the banner decision, and protecting the form
Storing information on your device and accessing information already stored there is governed by art. 399(1) of the Polish Electronic Communications Law of 12 July 2024 (Journal of Laws 2024, item 1221). Strictly necessary cookies operate without consent, under the exemption in art. 399(3) of that act.
You can change the decision stored by the banner at any time: click “Cookie settings” in the site footer.
10. Your rights
You may exercise the following rights at any time:
• access to your data and a copy of it (art. 15 GDPR)
• rectification, if the data is inaccurate or incomplete (art. 16 GDPR)
• erasure, known as the right to be forgotten (art. 17 GDPR)
• restriction of processing (art. 18 GDPR)
• data portability (art. 20 GDPR)
• objection to processing (art. 21 GDPR), covered separately in section 11
Two limits.
The right to data portability applies only where we process data based on consent or in connection with a contract or steps preceding it, and do so by automated means. It therefore does not cover data we process on the basis of legitimate interest, such as technical logs.
The right to erasure is not absolute. We may refuse where the data is needed to establish, pursue or defend claims, or to comply with a legal obligation such as keeping invoices.
Withdrawing consent. Today we base no processing on consent, so there is nothing to withdraw. Should that change, consent will be withdrawable at any time, as easily as it was given, and withdrawal will not affect the lawfulness of processing carried out beforehand (art. 7(3) GDPR).
To exercise any right, write to hi@mcoderz.com. We respond without undue delay and within one month at the latest (art. 12(3) GDPR). We charge nothing for this. We may ask for further information if we cannot identify you, for instance if you write from a different address than the one given in the form.
11. Right to object
We cover this right separately because the GDPR requires it (art. 21(4)).
You have the right to object at any time to processing of your data based on our legitimate interest (art. 6(1)(f) GDPR), on grounds relating to your particular situation. This covers handling enquiries, protecting the site and the form, technical logs and the cookie decision log.
On receiving an objection we will stop processing that data, unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or grounds for establishing, pursuing or defending claims.
Send an objection to hi@mcoderz.com. You need no template and no formal justification. It is enough to say what the objection concerns and why.
We do not carry out direct marketing, so the unconditional objection under art. 21(2) GDPR does not apply here.
12. Complaint to the President of UODO
If you believe we process your data unlawfully, you can lodge a complaint with the supervisory authority (art. 77 GDPR).
In Poland the competent authority is:
Prezes Urzędu Ochrony Danych Osobowych
(President of the Personal Data Protection Office)
ul. Stanisława Moniuszki 1A
00-014 Warszawa, Poland
www.uodo.gov.pl
You may also lodge a complaint with the supervisory authority in the country of your habitual residence, place of work, or the place of the alleged infringement.
Before you do, you are welcome to write to us at hi@mcoderz.com. It is not a precondition for a complaint, but it is often faster.
13. Automated decisions and profiling
We do not take decisions about you based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you (art. 22(1) and (4) GDPR).
We do not profile visitors. We build no behavioural profiles, we do not score you automatically, and we do not combine form data with technical data to analyse your activity. What the hCaptcha provider does with interaction data for its own purposes is its own responsibility as a separate controller: see section 6.
One mechanism does run automatically. hCaptcha assesses whether a human or a bot is filling in the form. That assessment produces no legal or similarly significant effects for you. It decides one thing only: whether the form gets sent. If the protection misfires and you cannot send your message, write to hi@mcoderz.com.
14. Data security
We apply measures proportionate to the size of the site and the risk:
• the whole site runs over HTTPS, and the HSTS header forces an encrypted connection on later visits too
• security headers block framing of the site and browser MIME-type sniffing
• the site has camera, microphone, geolocation and the ad-profiling Topics API switched off
• form content is validated and stripped of HTML before it is sent
• the form is protected by hCaptcha and a hidden honeypot field
• only the controller has access to the mailbox Web3Forms forwards messages to
• we use only providers with whom we have a data processing agreement in place
No safeguard is absolute, so: the contact form is not a channel for passwords, login credentials, payment card numbers or confidential information.
15. Changes to this policy
We update the policy when what we actually do with data changes, for instance when a new tool arrives or an old one goes.
The date of the last update is at the top of the page. We will announce material changes visibly on the site before they take effect.
If a change concerns a new purpose for data we already hold, we will inform you beforehand and provide all the information required by art. 13(3) GDPR. We will not use contact form data for a newsletter or marketing without a separate basis and prior notice.
Should we ever introduce cookies requiring consent, such as analytics or marketing ones, the basis for storing them will be art. 6(1)(a) GDPR and art. 399 of the Electronic Communications Law, and the banner will ask for consent before any such file is stored.
We provide previous versions of the policy on request.
16. Contact about your data
For anything concerning personal data, write to hi@mcoderz.com. That is the fastest route. Requests for access, rectification and erasure, as well as objections, all go there.
You can also:
• write to: DIGITAL SOLUTIONS Miłosz Gołas, Osiedle Na Lotnisku 1 lok. 29, 31-801 Kraków, Poland
• use the contact form on the site
We have not appointed a Data Protection Officer, so every request goes directly to the controller.