BudujPC.pl Privacy Policy
Effective date: 28 June 2026 Last updated: 12 July 2026
1. Introduction
1.1. This Privacy Policy explains how we handle the personal data of people who use the website at budujpc.pl (the "Site"). It follows Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the "GDPR") and applicable Polish law.
1.2. Using the Site is voluntary. By using it, you confirm that you have read this Privacy Policy.
1.3. We take care to protect the interests of the people whose data we handle. In particular, we process data lawfully, accurately, and only to the extent we actually need it.
2. Who controls your data
2.1. The controller of your personal data is:
Tomasz Synowski, trading as FTC Tomasz Synowski, of ul. Agrestowa 12, 58‑100 Świdnica, Poland, registered in the Polish Central Registration and Information on Business (Centralna Ewidencja i Informacja o Działalności Gospodarczej, "CEIDG"), Polish tax identification number (NIP) 8842614103, statistical number (REGON) 022521207 (the "Controller", "we", "us").
2.2. You can reach us about anything concerning your personal data:
- by email: kontakt@budujpc.pl
- by post: at the address in section 2.1.
2.3. We have not appointed a Data Protection Officer, because none of the conditions in Article 37 GDPR apply to us. We handle data protection enquiries ourselves, at the contact details above.
3. Definitions
- Personal data — information about an identified or identifiable natural person.
- User ("you") — an individual using the Site.
- Account — the individual set of resources and settings assigned to you once you register.
- Processing — any operation performed on personal data, such as collection, storage or erasure.
4. What data we process
We process only the data we need for the purposes set out in section 5. Depending on how you use the Site, that means:
4.1. Account data (if you create an Account):
- email address,
- password (stored only in hashed form — we cannot read your password),
- your first and/or last name, if you choose to give them.
4.2. Saved configuration data (if you save PC builds):
- the name you give a configuration,
- its contents (the components you selected, prices, parameters),
- creation and modification dates.
4.3. Technical and usage data (collected automatically as you use the Site, only to the extent needed):
- IP address,
- browser and device information,
- server logs (date and time of the request, the resource requested, the response status),
- session identifiers stored in cookies (see the Cookie Policy).
4.4. Correspondence data — the content of your message and your contact details, if you write to us.
4.5. Anonymous usage statistics. The Site collects aggregated, anonymous visit statistics and anonymous records of feature use — for example, that a configuration was generated for a given budget, or that a link to a shop was clicked. These statistics contain no IP address, no user identifier and nothing else that could identify a person. To the extent they are fully anonymous, they are not personal data under the GDPR. We describe them here for transparency.
We do not process special categories of data (so-called sensitive data), and we never ask you for them.
5. Why we process data, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your Account and providing services electronically, including saving configurations | Article 6(1)(b) — necessary to perform our contract with you |
| Verifying your email address and handling password resets | Article 6(1)(b) and (f) — performance of the contract, and our legitimate interest in account security |
| Keeping the Site secure, preventing abuse, rate‑limiting requests, diagnostics | Article 6(1)(f) — our legitimate interest |
| Answering enquiries and correspondence | Article 6(1)(f) — our legitimate interest in replying to you |
| Establishing, exercising or defending legal claims | Article 6(1)(f) — our legitimate interest |
| Meeting our legal obligations, for example tax and accounting duties | Article 6(1)(c) — legal obligation |
| Keeping aggregated, anonymous visit statistics (self‑hosted, cookieless analytics) and anonymous records of feature use | Article 6(1)(f) — our legitimate interest in statistics, improving the Site, and affiliate settlement; to the extent the data is fully anonymous, it is not personal data |
| Using cookie‑based analytics or marketing tools (planned — not currently active) | Article 6(1)(a) — consent given through the cookie banner |
You do not need an Account, or to identify yourself, simply to browse the Site.
6. Who receives the data
6.1. We may entrust data to trusted providers acting on our instructions (processors), only as far as providing the service requires, and always under a data processing agreement compliant with Article 28 GDPR. These are:
- our server and database provider (DigitalOcean) — application hosting and the PostgreSQL database; both the infrastructure and the database are located in the European Union (Frankfurt data centre, Germany),
- our content delivery network and frontend hosting provider (Cloudflare),
- our transactional email provider (Resend) — for messages such as account verification and password resets,
- our mailbox provider for correspondence (mailbox.org — Heinlein Hosting GmbH, Germany/EU) — for messages sent to our contact address.
6.2. Links to external shops. The Site contains links, including affiliate links, to third‑party online shops. A click may pass through a redirect on our side, which records nothing but an anonymous click statistic — no personal data (see section 4.5). Once you arrive at the shop's website, that shop and any affiliate network involved handle your data on their own terms and their own responsibility, as independent controllers. We have no control over third‑party privacy practices and are not responsible for them.
6.3. We may disclose data to public authorities entitled to receive it under applicable law.
6.4. We do not sell your personal data.
7. Transfers outside the European Economic Area (EEA)
7.1. The Site's core infrastructure, and the database holding Account and saved configuration data, are located within the European Economic Area (European Union, Frankfurt). Some of our other services — in particular the CDN and frontend hosting provider and the transactional email provider — may nonetheless involve a transfer to a country outside the EEA, including the United States.
7.2. Where that happens, the transfer is made with the safeguards the GDPR requires: either an adequacy decision of the European Commission (including the EU‑US Data Privacy Framework, where the provider is certified under it) or Standard Contractual Clauses approved by the European Commission. You can obtain a copy of the safeguards we rely on by contacting us.
8. How long we keep data
8.1. Account data — for as long as you have an Account. Once you delete it, we erase or anonymize the data, subject to sections 8.4–8.5.
8.2. Saved configuration data — until you delete the configuration or your Account.
8.3. Technical and usage logs — up to 12 months.
8.4. Data kept to meet legal obligations, including accounting records relating to affiliate income — for the periods the law requires, in particular tax law (as a rule 5 years from the end of the calendar year in which the obligation arose).
8.5. Data kept in connection with legal claims — until the relevant limitation periods expire (as a rule up to 6 years).
8.6. Correspondence — up to 12 months after the matter is closed, unless we need to keep it longer for the purposes in sections 8.4–8.5.
8.7. Data processed on the basis of consent, such as future cookie‑based analytics — until you withdraw that consent.
8.8. Anonymous statistics (see section 4.5) — aggregated statistics are kept indefinitely, as they are not personal data; raw anonymous usage events are deleted or aggregated after 24 months at the latest.
9. Your rights
9.1. You have the right to:
- access your data and obtain a copy of it (Article 15 GDPR),
- have inaccurate data corrected (Article 16 GDPR),
- have your data erased — the "right to be forgotten" (Article 17 GDPR),
- restrict processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- object to processing based on legitimate interest (Article 21 GDPR),
- withdraw consent at any time, without affecting the lawfulness of processing carried out before you withdrew it (Article 7(3) GDPR).
9.2. To exercise any of these rights, contact us using the details in section 2.2. We will respond without undue delay and no later than one month after receiving your request. Where a request is particularly complex, or where we receive a large number of requests, we may extend that period by a further two months; we will tell you about the extension and the reasons for it within one month of receiving the request (Article 12(3) GDPR).
9.3. Right to lodge a complaint. You have the right to complain to the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, "PUODO"), the Polish data protection regulator, at ul. Stawki 2, 00‑193 Warsaw, Poland.
10. Is providing data mandatory?
10.1. Providing your data is voluntary. That said, certain data — an email address, for instance — is necessary to create an Account and use the features that require signing in. Without it, those features are unavailable to you.
11. Profiling and automated decision‑making
11.1. The Site provides an automated mechanism that selects and recommends PC components (the configurator). It works from the parameters you supply, such as budget and intended use, together with product data drawn from external sources.
11.2. The configurator's recommendations are informational only. They are not automated decision‑making that produces legal effects concerning you, or similarly significantly affects you, within the meaning of Article 22 GDPR. The decision to buy anything remains entirely yours.
12. Data security
12.1. We apply technical and organizational measures appropriate to the risk, in particular:
- encryption of data in transit using TLS (HTTPS),
- storing passwords in hashed form only,
- storing session tokens in cookies with the
httpOnlyandSecureattributes, which puts them out of reach of browser‑side scripts, - restricted access to data, and rate‑limiting of requests,
- regular database backups.
13. Cookies
13.1. The Site uses cookies. A separate document covers this in detail: the Cookie Policy, available on the Site at /cookies.
14. Changes to this Privacy Policy
14.1. We may change this Privacy Policy. We will announce any material change by publishing the updated version on the Site with a new effective date and, for Account holders, by email as well.
14.2. The current version of this Privacy Policy is always available on the Site at /privacy.
15. Contact
For anything concerning the processing of personal data, please write to kontakt@budujpc.pl.