Home/Privacy policy

Privacy policy

This Privacy Policy defines the rules for processing personal data of users of the website operated by gaminco (“Website”). The document has been prepared in line with GDPR requirements.

1. Data controller and contact

The controller of personal data is gaminco sp. z o.o., with registered office in Katowice, ul. Zelazna 2, 40-851 Katowice, KRS 0000550925, NIP 2220898808, REGON 362302415, hereinafter referred to as the Controller.

The Controller has not appointed a Data Protection Officer.

Contact regarding personal data processing: E-Mail: p.kaczmarzyk@gaminco.eu, phone: +48 32 723 23 21.

The person designated for organizational matters related to information security and data protection in the Service is Mr. Pawel Kaczmarzyk, using the contact data indicated above. This role is not equivalent to the Data Protection Officer.

2. Scope of processed data

The Controller processes personal data only to the extent necessary to achieve specific purposes, in particular: identification and contact data (full name, E-Mail address, phone number), company data (company name, tax number), data related to meeting booking (date, selected consulting service, meeting topic, description of needs), payment and settlement data (booking identifier, amount and currency, payment status, transaction identifiers), and technical data (IP address, session identifiers, timestamps, device and browser data).

As part of consultation booking, data provided in the form and checkout is processed in particular: full name, E-Mail address, address (if provided), phone number, meeting topic, answers to Bookings form questions (for example company name, main challenge, number of employees, consultation goal description), selected staff member, selected service (30/60 minute variant), meeting date and time, time zone, and consents required to complete the booking.

3. Purposes of data processing

Personal data is processed for the following purposes: handling inquiries and correspondence, booking meetings with business consulting experts, performance of the consulting services agreement, payment processing for meeting bookings, transaction settlement, handling payment refunds and complaints, fulfillment of legal obligations (including accounting and tax obligations), newsletter (with consent), Service security and abuse prevention, statistics and analytics (with consent), and measurement of marketing effectiveness (with consent).

4. Legal bases for processing

Personal data is processed on the basis of: Article 6(1)(a) GDPR (consent, in particular newsletter and analytics/marketing cookies), Article 6(1)(b) GDPR (performance of a contract or actions prior to conclusion of a contract, in particular meeting booking, consultation delivery, and payment handling), Article 6(1)(c) GDPR (legal obligation of the Controller), and Article 6(1)(f) GDPR (legitimate interest of the Controller, in particular Service security, abuse prevention, establishment or defense of claims, and contact handling).

E-Mail and phone contact concerning offer inquiries, consultation organization, and post sales support is generally based on Article 6(1)(b) GDPR (steps prior to contract conclusion and contract performance) or Article 6(1)(f) GDPR (legitimate interest of the Controller consisting in correspondence and customer relationship handling).

5. Data recipients

Personal data may be transferred only to the extent necessary to achieve processing purposes: IT, hosting, Service maintenance, E-Mail, and security providers; accounting and legal service providers; entities providing booking and communication tools, for example Microsoft 365 and Microsoft Bookings; payment operator as described in section 6; and entities authorized to receive data under applicable law. The Controller does not sell personal data.

Examples of service providers used by the Controller: OVHcloud (server infrastructure and VPS hosting), Microsoft 365 / Microsoft Bookings / Microsoft Teams (booking and communication support), PayU (online payment processing), and the proprietary telemetry backend hosted by the Controller (event analytics after consent).

6. Payments for meeting bookings, PayU

Payments for meeting bookings may be processed via PayU and connected payment methods.

For payment processing, the Controller transfers to the payment operator data necessary to handle the transaction, in particular: booking identifier, amount and currency, payer E-Mail address, data necessary to identify the transaction, and technical data required for security and settlement (for example IP address, session identifiers, and timestamps).

The Controller receives from the payment operator information about payment status and transaction identifiers (for example pending/paid/expired status, payment identifier, order identifier) and may process such data for payment settlement, refund handling, and payment complaint handling.

If online payment is temporarily disabled, booking may be processed without an active online transaction. In such case, booking and organizational meeting data is processed without transfer of data to the payment operator.

The legal basis for payment related processing is Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.

7. Transfers outside the European Economic Area

As a rule, the Controller does not transfer personal data to third countries outside the European Economic Area.

If, in connection with use of IT provider tools, data is transferred outside the European Economic Area, the Controller ensures safeguards required by GDPR, including standard contractual clauses.

8. Data retention period

Personal data is retained: for the duration of correspondence and the purpose for which it was collected; for the duration of contract performance and settlements related to meeting booking; for the period required by law, in particular accounting and tax law; until expiry of limitation periods if data is needed to establish or defend claims; and until consent withdrawal where processing is based on consent.

9. Rights of data subjects

Each person has the right to: access data, rectify data, erase data where permitted by law, restrict processing, data portability, object to processing based on Article 6(1)(f) GDPR, withdraw consent at any time, and lodge a complaint with the President of the Personal Data Protection Office.

10. Voluntary provision of data

Providing data is voluntary, but necessary for contact, meeting booking, conclusion and performance of the agreement, and payment processing. Failure to provide data may prevent booking, service delivery, or payment handling.

11. Cookies and similar technologies

The Service uses cookies and similar technologies to ensure proper operation of the website, improve service quality, analyze statistics, and measure marketing effectiveness.

Necessary cookies are always active because they are required for proper Service operation and core functionalities.

Analytics and marketing cookies are enabled only after user consent given in the cookie banner or cookie settings.

Currently used identifiers: `gaminco_vid` cookie (HttpOnly, SameSite=Lax, default retention up to 365 days; purpose: pseudonymous visitor identification, security, and abuse control), `cookie-consent` in localStorage (until removed by the user; purpose: consent preference storage), and `language` in localStorage (until removed by the user; purpose: storing selected language).

Cookie categories and purposes: necessary (Service operation and consent handling), functional (settings memory and convenience), analytics (traffic and behavior measurement after consent), performance (speed and quality measurement), advertising (campaign personalization). Functional, performance, and advertising categories remain disabled by default and do not store additional identifiers without active consent and implementation of relevant tools.

Legal basis for necessary cookies is Article 6(1)(f) GDPR. Legal basis for analytics and marketing cookies is Article 6(1)(a) GDPR.

The user may change settings or withdraw cookie consent at any time in Service cookie settings or browser settings.

12. Profiling and behavior analysis

If consent for analytics or marketing cookies is given, the Controller may perform pseudonymized analysis of user behavior.

The purpose is to improve Service usability, tailor content and offers, and measure effectiveness.

Profiling does not produce legal effects for the user and does not constitute automated decision making within the meaning of Article 22 GDPR.

The user has the right to withdraw consent for analytics or marketing cookies at any time.

13. Data security

The Controller applies appropriate technical and organizational measures. Communication with the Service is protected with TLS. Only authorized persons have access to data.

Measures include, among others: encryption in transit and available mechanisms for data at rest protection at infrastructure and database level, regular backups, strong password policy and multi factor authentication where available, access segmentation based on least privilege principle, and security monitoring and event logging.

14. Privacy Policy changes

The Controller may change this Privacy Policy in case of legal changes or Service functionality changes. The current version is available in the Service. Last update date: March 11, 2026.

Home

Get updates, event news, and new insights from us.

gaminco

gaminco sp. z o.o.

Face 2 Face V

ul. Żelazna 2

PL 40851 Katowice

ul. Z. Augusta 5/2

PL 31504 Kraków

kess&partner

Gotengasse 7

DE 97070 Würzburg

Registration data

NIP: 2220898808

REGON: 362302415

KRS: 0000550925

What we do
Resources
Who we are
Our experts
Who we help
Consultation
© 2026•All rights reserved
Privacy Policy|GDPR Clause|Terms||General Terms