On this page
Data controller and website operator
The legal operator, publisher and controller of personal data processed in connection with mirekbygg.no is driwa.pl Łukasz Driwa, Polish tax ID NIP 5842685188, Gdańsk, Poland.
Kot Maurycy is the project’s creative brand. MirekBygg is not a registered construction company and does not offer construction or renovation services.
Legal operator and data controller driwa.pl Łukasz Driwa- NIP
- 5842685188
- Adres / Address
- Gdańsk, Polska
- Reveal email address
- Telefon / Phone
- Reveal phone number
Scope of this policy
This policy covers visits to mirekbygg.no and contact you choose to initiate through an email or phone link. The website has no user accounts, ordering system, newsletter or contact form.
Processing follows the GDPR, which applies in Poland and Norway through the EEA. Contact is voluntary, but we cannot reply without the relevant contact details.
What we process and why
We do not collect more information than is needed to deliver and protect the website or answer an enquiry.
| Situation | Data and purpose | Legal basis | Retention |
|---|---|---|---|
| Website visit | IP address, request time, requested address, HTTP status, referrer, browser and device information. Purpose: security, diagnostics and stable operation. | GDPR Article 6(1)(f) – our legitimate interest in providing a secure and reliable website. | Normally up to 14 days. A relevant extract may be retained for longer when required to investigate a specific security event or establish, exercise or defend a legal claim. |
| Email or phone | Name, contact details, message content and information you voluntarily provide. Purpose: answering and assessing possible cooperation. | GDPR Article 6(1)(b) for steps before a contract, or Article 6(1)(f) for ordinary business correspondence. | Enquiries that do not lead to cooperation: up to 12 months after the last contact, unless longer retention is necessary for a legal claim. |
| Contract and records | Contact, contractual, invoicing and settlement data if cooperation is agreed outside this website. | GDPR Article 6(1)(b) and (c) – contract and statutory accounting/tax duties; Article 6(1)(f) for legal claims. | For the contract and then for the periods required by applicable tax, accounting and limitation rules for the relevant record. |
Cookies and similar technologies
The website currently uses no analytics, personalisation or marketing cookies and stores no user profile in the browser. This is why no consent banner is displayed.
If you choose a language in the legal-information section on the home page, the browser stores only that preference locally under the key mirek-disclaimer-lang. It is not sent to the server or used for tracking and remains until you change the selection or clear browser data.
When you switch the language of the whole website, the browser uses the mirek-language-position key in session storage (sessionStorage) to open the new language version at the corresponding place. The entry contains only the destination path, section ID, relative reading position, language code and creation time. It is not sent to the server and is removed after use or after no more than 15 seconds.
Fonts are served locally from mirekbygg.no. Opening the website does not create an automatic connection to Google Fonts.
If optional technologies are introduced later, they will remain disabled by default. We will first explain their purpose, provider and duration and ask for consent where the law requires it. Refusing and withdrawing consent will be as easy as accepting.
Recipients and external links
Data may be processed by providers of hosting/server infrastructure, email, backups and necessary IT support acting under the controller’s instructions and appropriate data-processing terms. Data may also be disclosed to public authorities where binding law requires it.
Links to driwa.pl, Facebook, Instagram and YouTube are ordinary outbound links, not embedded tracking modules. Displaying MirekBygg does not send data through those links. Once you choose to click, the external service’s own privacy rules apply.
Transfers outside the EEA
MirekBygg does not send visitor data to external analytics or advertising providers. If a provider used for correspondence or technical operations processes data outside the EEA, the transfer must rely on a mechanism permitted by GDPR Chapter V, such as an adequacy decision or the EU Standard Contractual Clauses.
You may request more information about recipient categories and any transfer safeguards through the privacy contact below.
Your rights
Depending on the circumstances, you may request:
- access to and a copy of your personal data,
- correction of inaccurate or incomplete information,
- erasure or restriction of processing,
- to object to processing based on legitimate interests,
- data portability where its conditions are met.
We do not use automated decision-making or profiling. If a future operation relies on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
How privacy requests are handled
- Use the protected email link on this page and describe the right you wish to exercise.
- We record the date and scope and acknowledge the request.
- Only where there is reasonable doubt may we ask for the minimum additional information needed to verify identity.
- We respond without undue delay and normally within one month. Where necessary, the period may be extended by up to two months, taking into account the complexity and number of requests; you will be informed within the first month.
- Requests are generally free. A reasonable fee or refusal may only be considered for a manifestly unfounded or excessive request.
Complaints, security and incidents
If you believe processing infringes data-protection rules, we invite you to contact us first so we can investigate. You may nevertheless complain to the Polish supervisory authority, Prezes Urzędu Ochrony Danych Osobowych (UODO), or to an authority where you live, work or believe the infringement occurred. In Norway this is Datatilsynet.
We use encrypted HTTPS, restricted access, short log retention and proportionate technical and organisational controls. Suspected personal-data breaches are recorded, contained and assessed for risk. Where the legal threshold is met, the supervisory authority is notified without undue delay and, where feasible, within 72 hours; affected people are informed when the incident is likely to create a high risk.
Changes to this policy
We update this policy when purposes, providers, technologies or legal requirements change. A new version receives a new date and version number at the top of the page. A material change requiring consent will not activate an optional technology before valid consent has been obtained.