
Personal data
Privacy policy
Full information on data processing on the HEREDITAS website, in correspondence and during initial case qualification.
Document version
Version 2.1. Last updated: 19 August 2026. This policy reflects the actual website configuration on that date: WordPress, LH.pl hosting, Google Workspace email, the contact form, an external WhatsApp link, technical security mechanisms and no analytics or marketing tools.
1. Controller and contact
The controller of personal data is Paweł Ciechanowski, prowadzący działalność gospodarczą pod firmą Paweł Ciechanowski, ul. Armii Krajowej 29/30, 30-150 Kraków, Polska, NIP 677-111-07-70. For privacy matters contact kontakt@hereditas.biz, call +48 883 30 93 13, or write to the controller’s postal address.
2. Scope
This policy covers data processed in connection with use of the website, case submission form, email and telephone correspondence, case qualification, entering into and performing cooperation, settlements, website security and protection against claims.
Where HEREDITAS obtains a person’s data from sources other than directly from that person, the separate Article 14 GDPR notice also applies.
3. Categories of data
Depending on the relationship, data may include name, email, telephone number, location and address of the property, type and description of the matter, ownership and share information, family and inheritance information, correspondence, contractual and billing data, and technical website data.
The open form is not intended for national identification numbers, identity document numbers, complete files, health, religion, origin, criminal data or other special categories. Such information may be processed outside the open form only where genuinely necessary and supported by an appropriate legal basis.
4. Form, email, telephone and WhatsApp — purposes and legal bases
Data provided to obtain an offer, initial assessment or cooperation are processed under Article 6(1)(b) GDPR to take steps at the person’s request before entering into a contract or to perform a contract.
Where a message is general or concerns a third party, processing may rely on Article 6(1)(f) GDPR — the controller’s legitimate interests in handling correspondence, assessing the matter, organising work, ensuring security and establishing, exercising or defending legal claims.
The form does not rely on consent as the basis necessary to respond. The checkbox only confirms that the Privacy Policy has been read.
Contact through WhatsApp is voluntary. The website button opens the external WhatsApp service with a prepared message. If the message is sent, the controller receives its content and the profile data made available by the user in that service. The controller relies on Article 6(1)(b) or (f) GDPR, depending on the purpose of contact. WhatsApp processes data under its own terms.
5. Required and optional data
The form requires name, email, property location, type of matter and a brief description. Without these data the submission cannot be sent or meaningfully reviewed.
Telephone number and information about how the person learned about HEREDITAS are optional. Additional information in the description is voluntary and should be limited to what is genuinely needed.
6. Contract, services and accounting
Contract-related data are processed to prepare, enter into and perform cooperation under Article 6(1)(b) GDPR. Accounting and tax data are processed to comply with legal obligations under Article 6(1)(c) GDPR.
Data may also be processed under Article 6(1)(f) GDPR to document arrangements, manage the relationship, control quality, prevent abuse and establish, exercise or defend claims.
7. Technical data, logs and form security
The server may automatically record IP address, date and time, requested URL, browser and device information and technical errors. These data are used for availability, diagnostics, security and abuse prevention under Article 6(1)(f) GDPR.
The form uses a security token, a hidden anti-spam field and a temporary rate limit. After a successful submission, a hash of the IP address is technically retained for approximately 2 minutes to limit automated submissions. The form does not create a separate public database; the message is sent by email.
8. Recipients
Data may be accessed by service providers supporting the controller, in particular LH.pl for hosting and infrastructure, Google Workspace for email and office tools, WhatsApp/Meta only when the user voluntarily chooses WhatsApp contact, and providers of IT support, security, backups, accounting and organisational services.
Where necessary for a specific matter, data may be disclosed to independent lawyers, genealogists, brokers, engineers, valuers or other specialists after defining the scope, legal basis and confidentiality rules. Data are not sold.
9. Transfers outside the EEA
Some technology providers may process data or provide access outside the European Economic Area. In such cases the controller uses mechanisms under Chapter V GDPR, including adequacy decisions, standard contractual clauses or other appropriate safeguards.
Information about safeguards can be requested from the controller.
10. Retention
Submissions and correspondence are retained until the matter is handled and then for the time needed to demonstrate the course of contact and until applicable limitation periods expire, unless there is a basis for earlier deletion.
Contract records are kept for the duration of cooperation and applicable limitation periods. Accounting and tax documents are kept for the period required by law, generally five years counted from the end of the year in which the tax payment deadline expired.
Logs, security data and backups are retained according to providers’ technical cycles and for the time needed to detect, investigate and document incidents. Data may be retained longer where required by law, proceedings or protection of claims.
11. Third-party data
A person submitting a matter should provide data about other persons only where necessary and lawful. HEREDITAS may process data of owners, co-owners, heirs, representatives, family members and other persons connected with the matter.
The categories, sources, purposes and rights of those persons are described in the notice on data obtained from other sources.
12. Special categories and criminal data
The controller does not expect such data to be submitted through the form. If processing becomes necessary in the course of a matter, it will be limited to what is necessary and based on an appropriate condition under Article 9(2) GDPR or applicable rules concerning criminal convictions and offences, with additional safeguards.
13. Rights
Depending on the legal basis and circumstances, a person may request access and a copy, rectification, erasure, restriction, portability, and may object to processing based on Article 6(1)(f) GDPR.
Where particular processing relies on consent, consent may be withdrawn at any time without affecting prior lawful processing. Some rights may be limited where data are needed to comply with law or establish, exercise or defend claims.
Requests may be sent to kontakt@hereditas.biz. The controller may request information necessary to verify the requester’s identity.
14. Complaint
A person may lodge a complaint with the President of the Polish Personal Data Protection Office if they consider that processing infringes the GDPR. Information is available at uodo.gov.pl.
15. Automated decisions and profiling
Data are not used for decisions based solely on automated processing that produce legal or similarly significant effects. The website does not conduct marketing profiling. Initial case qualification involves human review.
16. Cookies and local technologies
Details about technical mechanisms, localStorage and the absence of analytics and marketing can be found in the Cookies and local technologies policy.
17. Security
The controller applies organisational and technical measures appropriate to risk, including access controls, HTTPS, form security, backups and limiting access to persons who need the information for their tasks.
No method of transmission or storage guarantees absolute security. If a breach occurs, the controller takes the actions required by the GDPR.
18. Changes
This policy may be updated when law, website functionality, providers or processing methods change. The current version is published with the update date. Adding analytics, marketing, a newsletter or new integrations requires reassessment and appropriate information and consent mechanisms.