Privacy Policy – Brand Boost 2027
Web page www.wedesign.pl/brandboost · We Design Studio Graficzne Aleksander Rokicki
§1. General information
1. This Privacy Policy (the "Policy") sets out the rules for processing personal data in connection with the use of the web page www.wedesign.pl/brandboost (the "Page") and with applications to the "Brand Boost 2027" project (the "Project"), the rules of which are set out in the separate Project Rules available on the Page.
2. This Policy fulfils the information obligation referred to in Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).
3. In matters not covered by this Policy, the general Privacy Policy of the website www.wedesign.pl applies. In the event of any discrepancy regarding the Page and the Project, this Policy prevails.
4. The rules for using cookies and similar technologies (including the Meta and LinkedIn pixels) are described in the separate Cookies Policy available on the Page.
§2. Data controller and contact
1. The controller of your personal data is We Design Studio Graficzne Aleksander Rokicki, with its registered office in Warsaw (01-560), ul. Toeplitza 2/48, Poland, tax ID (NIP) 951-184-66-07 (the "Controller", "we", "us").
2. For any matters relating to personal data, you can contact us by e-mail at studio@wedesign.pl or by post at the registered office address above.
3. The Controller has not appointed a data protection officer, as it is not required to do so under Article 37 GDPR.
§3. Who this Policy applies to
This Policy applies in particular to:
- persons visiting the Page ("Users"),
- persons completing the application form on behalf of an entity applying to the Brand Boost Project (contact persons, representatives),
- applicants and businesses that are sole proprietors, whose data – including tax ID, business name and address – constitute personal data,
- other persons whose data are provided in the form, e.g. team members mentioned in the answer to the question about the team.
§4. Where we obtain data from and what data we process
4.1. Data provided in the application form
We process the data that the applicant provides in the application form, in particular:
- company identification data: name, country of registered office, Polish tax ID (NIP) or foreign tax number, website address and social media profiles;
- contact person’s data: first and last name, position or role in the company, e-mail address, telephone number (optional);
- information about the company, product or service, target group, stage of development, competitors, current visual identity, expectations towards the Project, and how decisions are made and feedback is provided;
- information about the team – to the extent the applicant chooses to provide it (this may include personal data of other persons);
- the content of the declarations and consents given in the form and the date and time of submission.
4.2. Data collected automatically
When you use the Page, the following may be collected automatically: IP address, device and browser identifiers, operating system information, the source of your visit to the Page (e.g. clicking on an ad on LinkedIn or Instagram), pages visited, time of visit and events on the Page (e.g. submitting the form). These data are collected by means of cookies and similar technologies only to the extent that the User has consented in the cookie banner – see the Cookies Policy for details.
4.3. Data obtained from other sources
When considering an application, we may review publicly available information about the applicant (website, social media profiles, public business registers such as the Polish CEIDG/KRS or their foreign equivalents) in order to assess the collaboration potential in accordance with the Project Rules.
4.4. Third-party data provided in the form
If personal data of other persons (e.g. team members, partners) are provided in the form, the applicant is responsible for having a basis to share them and for informing those persons of the content of this Policy. We recommend providing data of other persons only to the extent necessary (e.g. role in the team, without first and last names where not required).
§5. Purposes, legal bases and retention periods
| Purpose of processing | Legal basis | Retention period |
|---|---|---|
| Receiving and considering the application to the Project, contact regarding the application, selection of the Participant | Article 6(1)(b) GDPR – steps taken at the request of the data subject prior to entering into a contract (for businesses that are sole proprietors); Article 6(1)(f) GDPR – the Controller’s legitimate interest in conducting the Project and communicating with the persons representing applying entities | Until the end of the application period and the announcement of the selected Participant, and thereafter for up to 6 months from the announcement of the result – for applications that were not selected |
| Carrying out the Project with the selected Participant (schedule, consultations, delivery of designs, conclusion of the rights transfer agreement) | Article 6(1)(b) GDPR – performance of a contract; Article 6(1)(f) GDPR – contact with the persons representing the Participant | For the duration of the Project and thereafter until the expiry of the limitation period for claims (as a rule, 6 years from the end of the year in which the Project was completed) |
| Fulfilling legal obligations (e.g. accounting and tax obligations – if any arise, e.g. in connection with the cost of external materials) | Article 6(1)(c) GDPR | For the period required by law (as a rule, 5 years from the end of the financial year) |
| Establishing, pursuing or defending against claims | Article 6(1)(f) GDPR – the Controller’s legitimate interest | Until the expiry of the limitation period for claims |
| Presenting the results of the Project in the Controller’s portfolio, on its website and on social media (case study) – applies to the selected Participant only | Article 6(1)(f) GDPR – legitimate interest in promoting the Controller’s own business; with respect to the image of individuals or data going beyond company data – Article 6(1)(a) GDPR (consent) | For as long as the portfolio is maintained, and no longer than until an effective objection is raised or consent is withdrawn |
| Informing about future editions of the Project and other initiatives of the Controller (marketing communication by electronic means) | Article 6(1)(a) GDPR – consent given voluntarily via a separate field in the form; in conjunction with Article 398 of the Polish Electronic Communications Law of 12 July 2024 | Until consent is withdrawn, and no longer than 3 years from the date it was given |
| Measuring the effectiveness of advertising campaigns on LinkedIn and Instagram/Facebook (Meta Pixel, LinkedIn Insight Tag), including recording form submissions as conversions, and ad targeting | Article 6(1)(a) GDPR – consent given in the cookie banner (Article 399 of the Electronic Communications Law) | In accordance with the retention periods of the individual cookies set out in the Cookies Policy; until consent is withdrawn |
| Ensuring the operation and security of the Page, including temporarily storing a draft copy of the answers in the browser | Article 6(1)(f) GDPR – legitimate interest in ensuring that the Page functions properly | Draft copy of the form – until the application is submitted or the browser tab is closed; server logs – 90 days |
| Analysing how the Page is used and improving it (Google Analytics) | Article 6(1)(a) GDPR – consent given in the cookie banner (Article 399 of the Electronic Communications Law) | In accordance with the cookie retention periods set out in the Cookies Policy; statistical data in Google Analytics – 14 months |
§6. Recipients of data
Personal data may be shared with the following categories of recipients, solely to the extent necessary to achieve the purposes set out in §5:
- the hosting provider of the Page: dhosting.pl;
- the application form is our own solution – no external plug-in or third-party form service is used; submitted applications are stored on the hosting infrastructure indicated above;
- the provider of e-mail and office tools: Google Workspace;
- the provider of the cookie consent management tool: Cookiebot;
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) – in connection with Google Analytics, only with the User’s consent;
- Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland) – in connection with the Meta Pixel and ads on Instagram/Facebook, only with the User’s consent;
- LinkedIn Ireland Unlimited Company (Wilton Place, Dublin 2, Ireland) – in connection with the LinkedIn Insight Tag and ads on LinkedIn, only with the User’s consent;
- entities providing accounting, legal or advisory services to the Controller – where necessary;
- subcontractors involved in carrying out the Project (e.g. collaborating designers, copywriters) – only with respect to the selected Participant and on the basis of agreements ensuring confidentiality.
Data are not sold or shared with third parties for their own marketing purposes. Data may be disclosed to competent public authorities at their request based on the law.
§7. Transfers of data outside the European Economic Area
1. As a rule, data are stored on servers located in the European Economic Area (EEA).
2. In connection with the use of Meta, LinkedIn and Google Analytics tools (only with the User’s consent) and of e-mail and office tools provided by entities belonging to corporate groups headquartered in the USA, data may be transferred to the United States.
3. Such transfers take place on the basis of the European Commission’s decision of 10 July 2023 finding an adequate level of protection under the EU-U.S. Data Privacy Framework (DPF) – with respect to entities certified under that programme – or on the basis of standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR), supplemented where necessary by additional safeguards.
4. Information about the safeguards applied and a copy of the standard contractual clauses can be obtained by contacting the Controller.
§8. Meta and LinkedIn tools – joint controllership
1. With respect to the collection of data via the Meta Pixel and its transmission to Meta Platforms Ireland Limited, the Controller and Meta are joint controllers (Article 26 GDPR). The terms of joint controllership are set out in Meta’s "Controller Addendum" (available at www.facebook.com/legal/controller_addendum). Meta is independently responsible for any further processing of the data after receiving it, in accordance with its privacy policy: www.facebook.com/privacy/policy.
2. With respect to the collection of data via the LinkedIn Insight Tag and its transmission to LinkedIn Ireland Unlimited Company, the Controller and LinkedIn are joint controllers. The terms of joint controllership are set out in the "LinkedIn Page Insights Joint Controller Addendum" / the LinkedIn Insight Tag terms (legal.linkedin.com). LinkedIn is independently responsible for any further processing of the data, in accordance with its privacy policy: www.linkedin.com/legal/privacy-policy.
3. The User may exercise their rights both against the Controller and against Meta or LinkedIn. The Controller is the point of contact for data subjects with respect to the joint controllership (contact details in §2).
4. These tools are activated only after consent has been given in the cookie banner. A detailed description of how they work and how to withdraw consent can be found in the Cookies Policy.
§9. Rights of data subjects
Every person whose data we process has – on the terms set out in the GDPR – the right to:
- access their data and obtain a copy of it (Article 15 GDPR),
- rectification of their data (Article 16 GDPR),
- erasure of their data (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability – with respect to data processed by automated means on the basis of consent or a contract (Article 20 GDPR),
- object to processing based on legitimate interest, including the right to object at any time to processing for direct marketing purposes (Article 21 GDPR),
- withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal (Article 7(3) GDPR),
- lodge a complaint with a supervisory authority – in Poland, the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, www.uodo.gov.pl.
To exercise any of the above rights, simply write to studio@wedesign.pl. We respond without undue delay and no later than one month after receiving the request. Consent to cookies can be withdrawn at any time by selecting the relevant options in the cookie plug-in pop-up (cookie settings).
§10. Whether providing data is mandatory
1. Providing the data marked with an asterisk (*) in the form is voluntary but necessary to receive and consider the application – without them, the application will not be taken into account. Providing any other data is entirely voluntary.
2. Giving consent to marketing communication (information about future editions) and consent to marketing cookies is voluntary and does not affect the ability to submit an application or how it is considered.
§11. Automated decision-making and profiling
1. The Project Participant is selected by the Controller’s team. The Controller does not make decisions concerning data subjects based solely on automated processing, including profiling, that would produce legal effects concerning them or similarly significantly affect them (Article 22 GDPR).
2. Meta and LinkedIn may use the data collected via the Pixel and the Insight Tag to profile Users for the purpose of displaying ads on their platforms – only after consent to marketing cookies has been given. Ad settings can be managed in the User’s account on those platforms.
§12. Data security
The Controller applies technical and organisational measures appropriate to the risk, in particular: an encrypted connection to the Page (HTTPS), restricting access to applications to the persons involved in the Project, securing access accounts, and data processing agreements with service providers. The draft copy of the answers in the form is stored solely in the User’s browser (session storage) and is not sent to the server before the application is submitted.
§13. Changes to this Policy
This Policy may be updated, in particular in the event of changes to the tools or providers we use or to the applicable laws. The current version is always available on the Page. We will notify persons who have submitted an application of any material changes by e-mail.
Last updated: 16 September 2026