Personal data protection
Privacy Policy
This policy describes how personal data is processed in connection with the KMD.Legal website, communications with the firm and recruitment.
Last updated: 11 August 2026
Definitions and scope
- Controller — Królikowski Marczuk i Partnerzy adwokaci i radcowie prawni spółka partnerska, ul. Śniadeckich 10, 00-656 Warszawa, Poland, National Court Register (KRS) 0000681768, Tax ID (NIP) 7010700004;
- Website — the KMD.Legal website available at kmd.legal and any test versions made available by the Controller;
- User — a person visiting the Website, using its contact form or following its links to external services;
- GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
This policy applies to data processed through the Website, in correspondence with the firm and in recruitment applications. It does not replace separate notices provided to clients after a matter is accepted or an engagement is entered into.
Controller and data-protection contact
The controller of personal data is Królikowski Marczuk i Partnerzy adwokaci i radcowie prawni spółka partnerska, ul. Śniadeckich 10, 00-656 Warszawa, Poland, National Court Register (KRS) 0000681768, Tax ID (NIP) 7010700004.
Questions about privacy, data-subject rights or data security may be sent to biuro@kmd.legal or by post to the firm's registered address.
Use of the Website
- the server may record technical data transmitted with a connection, including the IP address, request date and time, requested URL, response code and browser or operating-system information contained in connection headers;
- to limit automated or excessive form submissions, a technical identifier derived from the IP address and the number of attempts are retained for 15 minutes;
- technical data is processed to make the Website available, maintain its security, detect abuse, diagnose errors and protect against claims.
The legal basis is the Controller's legitimate interest in the secure and proper operation of the Website and protection of its rights — Article 6(1)(f) GDPR.
Contact and enquiry form
- where a message is intended to lead to an engagement or acceptance of a matter — taking steps at the person's request before entering into a contract, Article 6(1)(b) GDPR;
- in other cases — the Controller's legitimate interest in conducting correspondence connected with the firm's business, Article 6(1)(f) GDPR;
- where necessary to establish, exercise or defend legal claims — Article 6(1)(f) GDPR and, for special categories of data, Article 9(2)(f) GDPR.
The form collects the sender's full name and email address, and optionally their phone number and the subject, together with the message. Correspondence may also contain other data voluntarily provided by the sender, to the extent necessary to respond and handle the matter.
Before the firm confirms that it can accept a matter, please do not send confidential information or documents containing sensitive data. Sending a message does not itself create a lawyer-client relationship or mean that the firm has accepted the matter.
Contact details are not used for marketing without a separate legal basis where one is required.
Recruitment
- data required by Polish employment law — Article 6(1)(b) and (c) GDPR in conjunction with Article 22¹ of the Polish Labour Code;
- additional data provided voluntarily — consent demonstrated by its informed submission, Article 6(1)(a) GDPR;
- data used in future recruitment — separate consent, Article 6(1)(a) GDPR; consent may be withdrawn at any time by emailing biuro@kmd.legal.
Data contained in a CV, cover letter and other application documents is processed to conduct recruitment for a specified position or consider an open application.
Data required by law or specified in a particular vacancy is necessary to participate in that recruitment. Additional data and consent to future recruitment are voluntary, and declining to provide them does not affect the assessment of an application in the current process.
Cookies and external services
- app_cookie_consent — a first-party entry in the browser's localStorage containing the settings version, update date, expiry date and the choice for four categories: necessary, analytics, marketing and preferences;
- necessary — an always-active category required to remember the User's decision;
- analytics — an optional category; once consent is given, the Website runs Cloudflare Web Analytics to measure visits, views of individual paths, referral sources, general device and browser information and page performance;
- marketing — an optional category; the Website does not currently use advertising or marketing-profiling tools;
- preferences — an optional category covering the display of external content, including the embedded Google map.
On the first visit, all optional categories are disabled. The User may accept all categories, reject optional categories or save a custom selection. The decision is retained for no more than one year and contains no identifier used for analytics, advertising or tracking.
Cloudflare Web Analytics and Google Maps are enabled on the basis of the User's freely given consent — Article 6(1)(a) GDPR. Consent can be withdrawn as easily as it was given, without affecting the lawfulness of processing carried out beforehand.
Cloudflare Web Analytics is technically blocked until the User enables the 'Analytics' category. According to the provider's documentation, the service does not use cookies, localStorage or fingerprinting to measure statistics and does not track individuals across websites. The script nevertheless connects to Cloudflare infrastructure and transmits measurement data required to create aggregate Website statistics.
The Google map is technically blocked until the User enables the 'Preferences' category. Once enabled, the browser connects directly to Google Maps. Google may then store or access its own cookies and similar technologies and receive technical data such as the IP address and device or browser information. The Website applies a no-referrer policy to the embed where supported by the browser.
The choice can be changed at any time through the 'Cookie settings' button in the footer. Disabling the 'Analytics' category removes the Cloudflare script and reloads the page, while disabling the 'Preferences' category immediately prevents the Website from loading the map again. The Website cannot itself erase cookies previously stored on Google domains; those can be managed in the browser settings.
Refusing any optional category does not restrict access to the rest of the Website. If new purposes or providers of optional services are added in the future, the settings version will be changed and the User will be asked to make a new choice.
The Website links to KMD.Legal's LinkedIn page. Following that link takes the User away from the Website, and data processing on LinkedIn is governed by the platform operator's terms. KMD.Legal does not use the link to install tracking tools on the Website.
Recipients
Data may be accessed only by authorised lawyers, employees and contractors of the firm and providers of necessary technical services — in particular OVHcloud for hosting and Microsoft for email. Data may also be disclosed to IT support providers, advisers or public authorities where necessary and supported by an agreement or applicable law.
After the User voluntarily enables the 'Analytics' category, measurement data is transmitted to Cloudflare to provide Web Analytics and present the Controller with aggregate Website statistics.
After the User voluntarily enables the 'Preferences' category, technical data associated with displaying the map is transmitted directly to the Google entities providing Google Maps, in accordance with Google's privacy terms.
Processors acting on the Controller's behalf are bound by appropriate agreements and may process data only on its documented instructions.
Transfers outside the EEA
We do not transfer data outside the European Economic Area unless this is necessary in connection with a technology provider's services. Any such transfer relies on a mechanism permitted by the GDPR, in particular a European Commission adequacy decision or standard contractual clauses, together with the required safeguards.
After Google Maps content is enabled, Google may also process data outside the EEA. Information about the transfer mechanisms and safeguards used by Google is available in that provider's privacy materials.
After Cloudflare Web Analytics is enabled, measurement data may also be processed by Cloudflare outside the EEA. Information about the transfer mechanisms and safeguards is available in that provider's privacy policy.
Retention
- the localStorage entry recording privacy settings — no more than one year after the choice is made;
- the technical identifier used to prevent form abuse — 15 minutes;
- server logs — for the period resulting from the hosting provider's configuration and policies, no longer than necessary for security, diagnostics and incident response;
- aggregate Cloudflare Web Analytics statistics — in accordance with the availability period and terms of the Cloudflare service;
- correspondence that does not lead to an engagement — for the time needed to handle it and, as a rule, no longer than 12 months afterwards;
- data connected with an accepted matter — for the duration of the engagement and afterwards for the period required by law, professional rules and applicable limitation periods;
- data relating to a specific recruitment process — until the process ends and any claims are resolved; data for future recruitment — until consent is withdrawn or the purpose ceases, but no longer than six months;
- data needed to establish, exercise or defend claims — until the relevant limitation period expires.
At the end of the applicable period, data is erased or anonymised unless further retention is required by law.
Data-subject rights
Within the limits set by the GDPR, individuals have the right to access and receive a copy of their data, rectify or erase it, restrict processing, receive portable data and object to processing based on legitimate interests. The scope of each right depends on the legal basis and circumstances of the processing.
Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
Requests may be sent to biuro@kmd.legal. Anyone who believes that their data is processed unlawfully may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).
Security and automated decisions
We use organisational and technical measures appropriate to the risk, restrict access to authorised persons and require suitable safeguards from providers processing data on our behalf.
We do not make decisions concerning Website Users, correspondents or candidates based solely on automated processing where those decisions would produce legal or similarly significant effects. We do not conduct marketing profiling of Website Users.
Changes to this policy
This policy is reviewed and may be updated following legal, organisational or technical changes. The current version is published on the Website together with the date of its latest update.
