We collect only the information required for contact, security and service delivery.
Privacy policy
Privacy built on clear rules.
Below we explain who processes data on the Sigma Vision website, why, for how long and on what legal basis.
You can manage consent, access your data and exercise rights granted by the GDPR.
We use access controls, event logging and technical safeguards for the website.
Version 2.4, effective 5 August 2026.
1. Controller and contact
The controller is Sigma Vision Sp. z o.o., ul. 18 Stycznia 97D, 87-300 Brodnica, tax ID 8741818637, REGON 545191877, KRS 0001252396. Contact kontakt@sigmavision.pl. No data protection officer has been appointed.
2. Controller and processor roles
We control contact, correspondence, billing, training, website-security and first-party analytics data. Where an IT service gives us access to customer data solely on documented instructions, we act as processor under a separate Article 28 GDPR agreement.
3. Enquiries and cooperation
The form requires your name, company name, email address, topic and description of the need; a telephone number is optional. The default “Other” topic can be changed, while arriving from a specific service page may select the relevant category. Depending on the choice, we may also receive the selected plan, training course or service type. We use these data to respond, verify the request, prepare an individual proposal, take pre-contractual steps, deliver services, settle accounts and protect claims. After the message is successfully passed to the contact mechanism, we create a technical enquiry reference and may send confirmation to the supplied email address. After an error, a sanitised draft may remain in the protected session for up to 15 minutes so the form can be corrected. Do not send passwords, access keys, one-time codes or special-category data unless a secure channel has been agreed.
4. Training
We may process participant, employer, group, attendance, optional test, trainer-question and certificate data received from the participant or customer to deliver training, issue a named certificate listing its scope, provide 30-day email contact and prepare an agreed report.
5. Purposes and legal bases
We rely on Article 6(1)(b) GDPR for requested pre-contractual steps and contracts, (c) for legal and accounting duties, (f) for business correspondence, security and claims, and (a) only for optional analytics. Device storage/access is used with consent unless strictly necessary.
6. Security logs and analytics
Regardless of analytics consent, necessary security logs record request time/method, resource, status, device, masked IP, pseudonymous IP hash, referrer and attack indicators. Optional first-party analytics starts only after consent and records pages, anonymous visitor/session identifiers, device and approximate duration. We do not use Google Analytics or advertising profiles.
7. Cookies and browser storage
Essential mechanisms secure sessions and forms, allow short-term restoration of a draft after an error and remember privacy choices. Optional analytics storage starts only after consent. Change or withdraw your choice via the green-blue “C” icon in the bottom-left corner.
8. Recipients and transfers
Authorised people and necessary hosting, email, IT, accounting, legal, trainer, expert, rental-partner, supplier and service providers may receive data as processors or independent controllers. Contact-form data is not passed to a partner automatically. We first tell the customer which entity is to prepare or deliver the agreed partner proposal, then share only the data necessary to prepare it, enter into an agreement or perform the contract. We may disclose data to authorities where required by law and do not sell personal data. Processing is generally in the EEA; any third-country transfer requires a Chapter V GDPR safeguard.
9. Retention
A form draft retained after an error remains for no more than 15 minutes. Enquiries without cooperation are normally kept for up to 12 months. A blocked Client Portal profile is reviewed after no more than 90 days. Closed tickets and chats are normally retained for up to 24 months; closed audits, reports and technical evidence for up to five years. Contracts, invoices and accounting records are retained for the applicable statutory and claims periods. Training lists and certificate registers are retained for up to five years unless another period is required. The rights-request register is retained for three years after closure in a minimised form. Client Portal and administrator operation logs are retained for up to five years, and longer only where necessary for security, a legal duty or claims; an anonymised account is represented by a technical label. Website-security and analytics logs are retained for no more than 93 days, while expired tokens and completed technical queues are removed earlier. Consent evidence is retained until withdrawal, expiry of claims or loss of need, and the analytics choice is requested again after six months. Expiry creates a review task rather than automatic permission to delete business records; a legal duty, claim, incident or documented customer instruction may place the data on hold.
10. Rights
Depending on the basis, you may request access, a copy, correction, erasure, restriction and portability, object to legitimate-interest processing, withdraw consent and complain to the President of the Polish Personal Data Protection Office. Requests may be sent to the address in section 1. We respond without undue delay, normally within one month. A complex request may require an extension of up to two further months, with notice and reasons provided before the first month expires. We may proportionately verify identity. Erasure is not absolute: data required by law or for establishing, exercising or defending legal claims may be retained in a restricted and minimised scope, with the decision explained. Providing data is voluntary, but required form fields are necessary to handle an enquiry; a telephone number is not required.
11. Sources, AI and automation
Data comes from you, your organisation, a customer or public business registers. Inform other people whose data you provide. We do not use enquiry content to train public AI models or provide it to public AI tools without separately agreeing the relevant basis, scope and safeguards. We do not make solely automated decisions producing legal or similarly significant effects.
12. Client Portal, accounts, tickets and chat
After approved onboarding, the nominated user receives a one-time password setup link. The portal processes account roles, access rights, login history, contracts, documents, tickets, messages, chat conversations, work time and asset/location information according to the contract. Chat is an operational channel available only after login. Message content, sender and time are stored and visible only to authorised users of that organisation and the Sigma Vision team. Passwords, private keys and special-category data must not be sent through chat unless an appropriate channel has been agreed. Each customer’s data is logically separated.
13. Audits, photographs, CCTV and technical data
Audits may contain questionnaires, risk ratings, locations, infrastructure descriptions, asset references and photographs. Unnecessary people, screens, documents and identifiers should be excluded from photographs. Evidence is used for the audit, report, recommendations and proof of service.
For CCTV, access-control and time-and-attendance systems, the organisation operating the system normally remains the controller and Sigma Vision follows its documented arrangements. The customer defines purpose, legal basis, authorised people and retention. A recording or log exported for diagnosis is kept only while the task is handled, normally for no more than 30 days after closure, unless the customer instructs us to preserve it or an incident or claim requires longer retention.
14. Breaches and incidents
Incidents are assessed by nature, scope, effects and risk. Where a personal-data breach occurs, Articles 33–34 GDPR are followed according to whether we act as controller or processor. Security-sensitive details are not published.
15. Marketing and commercial communication
We do not send newsletters or electronic marketing without the required legal basis and consent. A response to an enquiry initiated by the sender is not a newsletter. If marketing communication is introduced in the future, it will remain separate from contract handling, include a simple opt-out mechanism and use appropriately documented consent.
16. Minors and third-party data
The website and offer are aimed primarily at businesses and people acting in a professional capacity, not minors. We do not knowingly collect minors’ data through the contact form. A person providing employee, contractor, training-participant or other third-party data must have an appropriate lawful basis and provide those people with the required privacy information.
17. Security, updates and versions
We apply least privilege, access control, secure sessions and forms, encrypted transport, backups, event logging, customer-data separation, updates and retention limits. Safeguards are reviewed periodically, although no transmission or system can guarantee zero risk. Material prospective changes and effective dates are published in the Document Centre. The Polish version governs.