Legal
Privacy Policy
Preamble
With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") we process, for what purposes and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and in particular on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online offering").
The terms used are not gender-specific.
Last updated: 6 September 2026
Table of Contents
- Preamble
- Controller
- Overview of Processing Operations
- Relevant Legal Bases
- Cookies and Access to Terminal Equipment (§ 25 TDDDG / Art. 399 PKE)
- Security Measures
- International Data Transfers
- General Information on Data Storage and Deletion
- Rights of Data Subjects
- Competent Supervisory Authority
- Provision of the Online Offering and Web Hosting
- Contact and Enquiry Management
- Amendment and Update
- Definitions of Terms
Controller
AI SHIFT Consulting sp. z o. o.
ul. Marszałka Józefa Piłsudskiego 74/320
50-020 Wrocław
Poland
Managing Director: Patrick Meier
Registry court: Sąd Rejonowy dla Wrocławia-Fabrycznej we Wrocławiu, VI Commercial Division of the National Court Register · KRS 0001252250 · NIP 8971975286 · REGON 545195421 · VAT ID PL8971975286 · Share capital PLN 5,000.00
Phone: +49 (0)174 - 4933 563
Email address: info@ai-shift.agency
We have not appointed a data protection officer, as the conditions of Art. 37 GDPR do not apply to us. Please direct any data protection enquiries to the e-mail address above.
Overview of Processing Operations
The following overview summarises the types of data processed and the purposes of their processing and refers to the data subjects concerned.
Types of Data Processed
- Master data.
- Contact data.
- Content data.
- Usage data.
- Meta, communication and procedural data.
- Log data.
Categories of Data Subjects
- Service recipients and clients.
- Communication partners.
- Users.
Purposes of Processing
- Provision of contractual services and fulfilment of contractual obligations.
- Communication.
- Security measures.
- Organisational and administrative procedures.
- Content Delivery Network (CDN).
- Feedback.
- Provision of our online offering and user-friendliness.
- Information technology infrastructure.
- Audience measurement (analytics).
- Measurement of technical performance.
Relevant Legal Bases
Relevant legal bases under the GDPR: Below you will find an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the provisions of the GDPR, national data protection requirements may apply in your or our country of residence or establishment. Should more specific legal bases be relevant in individual cases, we will inform you of these in the privacy policy.
- Consent (Art. 6 para. 1 sent. 1 lit. a) GDPR) — The data subject has given consent to the processing of personal data relating to them for one or more specific purposes.
- Performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sent. 1 lit. b) GDPR) — Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
- Legal obligation (Art. 6 para. 1 sent. 1 lit. c) GDPR) — Processing is necessary for compliance with a legal obligation to which the controller is subject.
- Legitimate interests (Art. 6 para. 1 sent. 1 lit. f) GDPR) — Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
National data protection regulations: As a company established in Poland, we are subject — in addition to the GDPR — to the Polish Data Protection Act (Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych) and the Polish Electronic Communications Act (Prawo komunikacji elektronicznej). Insofar as our online offering is directed at users in Germany, we additionally observe the requirements applicable there, in particular the Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG).
Cookies and Access to Terminal Equipment (§ 25 TDDDG / Art. 399 PKE)
We use the self-hosted c15t consent-management software to obtain, apply and demonstrate your privacy choice. For this purpose, a cookie named c15t and an entry with the same name in your browser's local storage are created on our domain. They contain your choice and a pseudonymous consent identifier. The choice is valid for 180 days. This storage is necessary so that we can respect your decision on later page views and avoid showing the dialog again on every visit.
The language choice is not stored in an additional language cookie. The consent interface uses the language of the page you visit (German or English).
The fonts we use are bundled at build time and served from our own server. When you access our pages, no connection is established to Google or any other font provider.
Vercel Analytics and Vercel Speed Insights are loaded only after you consent to the “Visitor statistics” category. In our configuration, the services do not set their own analytics cookies. Without consent, neither the scripts nor their measurement requests are activated.
Security Measures
In accordance with legal requirements and taking into account the state of the art, implementation costs and the nature, scope, circumstances and purposes of processing, as well as the varying likelihood and severity of the threat to the rights and freedoms of natural persons, we take appropriate technical and organisational measures to ensure a level of protection appropriate to the risk.
Securing online connections using TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted via our online services against unauthorised access, we use TLS/SSL encryption technology.
Protecting our contact form against automated submissions: To prevent spam and abusive bulk submissions, we use an invisible form field (a "honeypot") and a Vercel firewall rule at the network edge. This rule protects only contact form submissions (POST requests); ordinary page views are unaffected by this form-specific rule. These measures are used solely to prevent misuse, are technically necessary and are independent of your visitor-statistics choice. The legal basis is our legitimate interest in preventing misuse (Art. 6 para. 1 sent. 1 lit. f) GDPR.
International Data Transfers
Data processing in third countries: If we transfer data to a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)), or if this occurs in the context of using third-party services or disclosing or transferring data to other persons, bodies or companies, this is always done in accordance with legal requirements. This concerns in particular Vercel (hosting, bot protection, workflow processing, audience measurement and performance measurement), Resend (e-mail delivery), monday.com (enquiry management) and Calendly (external appointment booking).
For data transfers to the USA, the EU-U.S. Data Privacy Framework (DPF, adequacy decision of the EU Commission of 10 July 2023) may serve as a basis, depending on the provider. In addition or as an alternative, we conclude standard contractual clauses with the respective providers in accordance with the requirements of the EU Commission. Further information on the DPF and the list of certified companies can be found at: https://www.dataprivacyframework.gov/
General Information on Data Storage and Deletion
We delete the personal data we process in accordance with legal provisions as soon as the underlying consents are withdrawn or no further legal bases for processing exist.
Retention and deletion of data: As a company established in Poland, we are subject to the following general retention and archiving periods under Polish law:
- 5 years — Tax records, counted from the end of the calendar year in which the tax became due (Art. 86 § 1 Ordynacja podatkowa).
- 5 years — Accounting records and accounting vouchers, counted from the beginning of the year following the financial year (Art. 74 Ustawa o rachunkowości); approved annual financial statements are retained permanently.
- 6 years or 3 years — Data required to take account of potential claims, in line with the general limitation period and the period applicable to business-related claims respectively (Art. 118 Kodeks cywilny).
Insofar as German law applies to a contractual relationship, we additionally observe the commercial and tax retention periods applicable there (in particular § 147 AO and § 257 HGB).
Rights of Data Subjects
Rights of data subjects under the GDPR: As a data subject, you are entitled to various rights under the GDPR, which arise in particular from Art. 15 to 21 GDPR:
- Right to object: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is based on Art. 6 para. 1 lit. e or f GDPR.
- Right to withdraw consent: You have the right to withdraw consent given at any time.
- Right of access: You have the right to request confirmation as to whether data concerning you is being processed and to obtain information about this data as well as further information and a copy of the data in accordance with legal requirements.
- Right to rectification: In accordance with legal requirements, you have the right to request the completion of data concerning you or the rectification of inaccurate data concerning you.
- Right to erasure and restriction of processing: In accordance with legal requirements, you have the right to demand that data concerning you be erased without delay, or alternatively to request a restriction of the processing of the data.
- Right to data portability: You have the right to receive data concerning you which you have provided to us in a structured, commonly used and machine-readable format.
- Right to lodge a complaint with a supervisory authority: You also have the right to lodge a complaint with a supervisory authority. You will find the competent bodies in the following section.
Competent Supervisory Authority
As we are established in Poland, the lead supervisory authority responsible for us is:
Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2
00-193 Warszawa
Poland
https://uodo.gov.pl
Irrespective of this, under Art. 77 GDPR you have the right to lodge a complaint with the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement — for users in Germany, therefore, also with the competent state data protection authority.
Provision of the Online Offering and Web Hosting
We process users' data in order to provide them with our online services. For this purpose, we process the user's IP address, which is necessary to transmit the content and functions of our online services to the user's browser or terminal device.
- Types of data processed: Usage data; meta, communication and procedural data; log data.
- Data subjects: Users.
- Purposes of processing: Provision of our online offering and user-friendliness; information technology infrastructure; security measures; Content Delivery Network (CDN); audience measurement (analytics); measurement of technical performance.
- Legal bases: Legitimate interests (Art. 6 para. 1 sent. 1 lit. f) GDPR).
Further information on processing operations, procedures and services:
Collection of Access Data and Log Files
Access to our online offering is logged in the form of so-called "server log files". The server log files may contain the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, browser type and version, the user's operating system, referrer URL as well as IP addresses and the requesting provider. Log file information is stored for a maximum of 30 days and then deleted or anonymised.
- Legal bases: Legitimate interests (Art. 6 para. 1 sent. 1 lit. f) GDPR).
Vercel
Services in the field of providing information technology infrastructure and related services (e.g. storage space and/or computing capacity).
- Service provider: Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA.
- Legal bases: Legitimate interests (Art. 6 para. 1 sent. 1 lit. f) GDPR).
- Website: https://vercel.com
- Privacy notice: https://vercel.com/legal/privacy-notice
- Data processing agreement: https://vercel.com/legal/dpa
- Basis for third-country transfers: Standard contractual clauses (https://vercel.com/legal/dpa).
c15t and Neon Postgres
We run c15t within our Next.js application on Vercel. Consent data is not transmitted to a cloud service operated by c15t. We store server-side consent evidence in a Neon Postgres database in the AWS Frankfurt region (eu-central-1).
- Data processed: pseudonymous consent identifier; accepted, rejected or customised choice; categories; timestamps; validity period; language used; and the associated consent-policy version and decision.
- Data minimisation: Our c15t configuration does not store the visitor's IP address or User-Agent in the consent evidence. Independently of this, Vercel and the database provider process technically necessary connection and operational data when providing their infrastructure services.
- Purposes: applying your choice; preventing optional measurement without consent; demonstrating consent under Article 7(1) GDPR; and securing and troubleshooting the consent service.
- Legal bases: Article 6(1)(c), in conjunction with the obligation to demonstrate consent under Article 7(1) GDPR, applies to storage of the consent evidence. We process security and troubleshooting data on the basis of our legitimate interests in a secure consent service (Article 6(1)(f) GDPR). Optional visitor statistics and performance measurement are based solely on your consent.
- Retention: The local choice and the corresponding server-side consent evidence are retained for no more than 180 days. Because c15t does not automatically remove expired evidence physically from the database, we delete it manually at regular intervals after its validity expires.
- Neon platform provider: Databricks, Inc., parent company of Neon, LLC, 160 Spear Street, 15th Floor, San Francisco, CA 94105, USA.
- Database region: AWS Europe (Frankfurt),
eu-central-1. - Neon product terms: https://neon.com/platform-terms
- Privacy notice: https://www.databricks.com/legal/privacynotice
- Data processing agreement: https://www.databricks.com/legal/dpa
- Subprocessors: https://www.databricks.com/legal/databricks-subprocessors
- International transfers: The Neon product terms incorporate the Databricks contract and data-protection terms. The data processing agreement provides in particular for the Standard Contractual Clauses where safeguards for a restricted transfer are required.
Vercel Analytics
Vercel Analytics produces aggregated visitor statistics. After your consent, it may process the timestamp, requested path, referrer, approximate location, operating system, browser and device type. Vercel states that Web Analytics does not use cookies, does not associate data points with an individual or IP address, and discards the visitor identifier generated from a request after 24 hours. We load the service only after your explicit consent. You can withdraw it at any time through “Privacy settings” in the footer; withdrawal reloads the page and stops further measurement.
- Service provider: Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA.
- Legal bases: Consent (Art. 6 para. 1 sent. 1 lit. a GDPR).
- Web Analytics privacy information: https://vercel.com/docs/analytics/privacy-policy
- Privacy notice: https://vercel.com/legal/privacy-notice
- Data processing agreement: https://vercel.com/legal/dpa
- Basis for third-country transfers: Standard contractual clauses (https://vercel.com/legal/dpa).
Vercel Speed Insights
Vercel Speed Insights records aggregated website performance data (Core Web Vitals) after your consent. It may process in particular the requested route and URL, network speed, browser, device type, operating system, approximate country, the respective Web Vital values including technical attribution, as well as SDK information and the time the event was received. Vercel states that the data points are anonymous, are not associated with an individual or IP address, and do not enable reconstruction of a browsing session across pages. In our configuration, the service does not set its own cookies. We load the script only after your explicit consent to the “Visitor statistics” category. You can withdraw it at any time through “Privacy settings” in the footer; withdrawal reloads the page and stops further measurement.
- Service provider: Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA.
- Legal bases: Consent (Art. 6 para. 1 sent. 1 lit. a GDPR).
- Speed Insights privacy information: https://vercel.com/docs/speed-insights/privacy-policy
- Privacy notice: https://vercel.com/legal/privacy-notice
- Data processing agreement: https://vercel.com/legal/dpa
- Basis for third-country transfers: Standard contractual clauses (https://vercel.com/legal/dpa).
Contact and Enquiry Management
When contacting us (e.g. via contact form or e-mail) as well as within the scope of existing user and business relationships, the information provided by the enquiring persons is processed to the extent necessary to respond to the contact enquiries and any requested measures.
- Types of data processed: Master data; contact data; content data; usage data; meta, communication and procedural data.
- Data subjects: Communication partners.
- Purposes of processing: Communication; organisational and administrative procedures; feedback.
- Legal bases: Legitimate interests (Art. 6 para. 1 sent. 1 lit. f) GDPR). Performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sent. 1 lit. b) GDPR).
Further information:
Contact Form
The contact form is exclusively for other matters such as organisational questions and partnerships. When you contact us via the form or by e-mail, we process the personal data transmitted to respond to and handle the enquiry. We use this data exclusively to communicate and process the enquiry.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sent. 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sent. 1 lit. f) GDPR).
Vercel Workflows (Reliable Enquiry Processing)
For reliable delivery, Vercel Workflows processes the form fields, language, receipt time and a technical enquiry ID on the server. Inputs and processing steps are stored so interrupted processing can resume and errors can be traced. If transfer to monday.com fails, the enquiry is sent to our inbox via Resend. The IP address is not part of the workflow payload.
- Service provider: Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA.
- Legal bases: Article 6(1)(b) GDPR for contract-related enquiries, otherwise Article 6(1)(f) GDPR (reliable handling of incoming enquiries).
- Storage and deletion: Workflow data and error states are retained only for as long as delivery, troubleshooting and necessary traceability require; statutory retention obligations remain unaffected.
- Data processing and third-country transfer: Vercel DPA including Standard Contractual Clauses.
monday.com (Enquiry Management)
Other form enquiries are recorded in a monday.com board with restricted access. Data includes name, e-mail address, company, an optional telephone number, message, language, receipt time, enquiry ID and handling status. Calendly bookings are not transferred to this board. monday.com is contacted only on the server; no monday.com scripts or cookies are embedded in the website.
- Service provider: monday.com Ltd., Israel.
- Legal bases: Article 6(1)(b) GDPR for contract-related enquiries, otherwise Article 6(1)(f) GDPR (organising and handling correspondence).
- Storage and deletion: Enquiries are deleted according to their handling purpose and general retention obligations. You may contact us with access or deletion requests.
- Privacy policy: monday.com Privacy Policy.
- Data processing and third-country transfer: monday.com DPA including applicable Standard Contractual Clauses. Exclusively European processing is not guaranteed.
Calendly (External Appointment Booking)
For conversations about consulting, an AI audit and SHIFT Academy, we link to an external Calendly booking page. Calendly opens in a new tab only when you follow the link. We load no Calendly scripts, set no Calendly cookies and transfer no form fields to Calendly from our website. Cookies and further processing on the external page are governed by its own notices and settings.
- Service provider: Calendly LLC, USA.
- Legal bases for our appointment handling: Article 6(1)(b) GDPR for pre-contractual conversations, otherwise Article 6(1)(f) GDPR (organising requested conversations).
- Storage: Appointment details are processed to organise and follow up on the conversation; statutory retention obligations remain unaffected.
- Privacy notice and third-country processing: Calendly Privacy Notice. Processing in the USA is possible.
Resend (Email Delivery)
If automatic processing or transfer of an enquiry cannot be confirmed, we use Resend as an e-mail fallback to our inbox. This includes the name, e-mail address, company, an optional telephone number, message, language and a technical enquiry ID. The IP address is not included in the e-mail. After a successful transfer, Resend also sends a short notification containing the board link and enquiry ID to active members of the SHIFT workspace; the message content and the enquirer's contact details are not included.
- Service provider: Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6 para. 1 sent. 1 lit. b) GDPR); legitimate interests (Art. 6 para. 1 sent. 1 lit. f) GDPR) for the prevention of misuse.
- Privacy policy: https://resend.com/legal/privacy-policy
- Data processing agreement: https://resend.com/legal/dpa
- Basis for third-country transfers: Standard contractual clauses.
Amendment and Update
We ask you to inform yourself regularly about the content of our privacy policy. We adapt the privacy policy as soon as changes to the data processing we carry out make this necessary. We will inform you as soon as the changes require an act of cooperation on your part (e.g. consent) or other individual notification.
Where we provide addresses and contact information of companies and organisations in this privacy policy, please note that addresses may change over time and please check the information before making contact.
Definitions of Terms
In this section you will find an overview of the terms used in this privacy policy. Where the terms are defined by law, their statutory definitions apply.
- Master data: Master data comprises essential information necessary for the identification and management of contractual partners, user accounts, profiles and similar assignments, such as names, contact information and customer numbers.
- Content Delivery Network (CDN): A "content delivery network" (CDN) is a service that allows the content of an online offering, in particular large media files such as graphics or program scripts, to be delivered more quickly and securely using regionally distributed servers connected via the internet.
- Content data: Content data comprises information generated in the course of creating, editing and publishing content of all kinds.
- Contact data: Contact data is essential information that enables communication with persons or organisations. It includes, among other things, telephone numbers, postal addresses and e-mail addresses.
- Meta, communication and procedural data: Meta, communication and procedural data are categories that contain information about how data is processed, transmitted and managed.
- Usage data: Usage data refers to information that records how users interact with digital products, services or platforms, including page views, time spent, click paths and device types.
- Personal data: "Personal data" means any information relating to an identified or identifiable natural person.
- Log data: Log data is information about events or activities that have been logged in a system or network, such as timestamps, IP addresses, usage actions and error messages.
- Audience measurement: Audience measurement evaluates how often and for how long an online offering is accessed. It can — as in our case — take place without cookies and without recognising individual users, in which case it provides exclusively aggregated statistics.
- Measurement of technical performance: Measurement of technical performance records aggregated metrics of a website’s loading and rendering quality (in particular Core Web Vitals) without identifying a person.
- Controller: "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processing: "Processing" means any operation or set of operations which is performed on personal data, whether or not by automated means. The term is broad and covers practically any handling of data, be it collection, evaluation, storage, transmission or deletion.