Privacy and Cookies Policy of the wojtektworkowski.pl website
Last updated: 20 August 2026
1. Data controller
The controller of personal data processed in connection with the use of the wojtektworkowski.pl website is Wojciech Tworkowski, conducting business under the name:
twork.shop Wojciech Tworkowski
ul. Popradzka 17
04-979 Warszawa, Poland
NIP (Polish tax identification number): 8961149753
REGON (Polish statistical business number): 142011380
The Controller can be contacted on matters relating to personal data protection at the e-mail address: data@twork.shop
2. Scope of the policy
This policy describes the rules for processing the personal data of persons who:
1 use the wojtektworkowski.pl website;
2 contact the Controller on business matters;
3 book a meeting through TidyCal;
4 take part in an organisational or commercial meeting with the Controller.
The website presents an offer of training courses, workshops and team and individual coaching. It is addressed to entrepreneurs and to persons acting on behalf of entrepreneurs, in particular employees, managers and representatives of organisations. The offer is not addressed to consumers or to minors.
The policy relates primarily to use of the website, the booking of meetings and contact preceding cooperation. Detailed rules for processing data during the delivery of a specific training course, workshop or coaching process may be set out separately, depending on the nature of the engagement and the contract concluded.
3. What data may be processed
The following data may be processed in connection with the use of the website:
1 technical data, such as IP address, device and browser type, operating system, approximate location, online identifiers, the address of the subpage visited, the entry source and the time spent using the website;
2 data on activity on the website, including information about the pages displayed, clicks and the manner of using the site;
3 data relating to the cookie decision, including the date and scope of consent and any change or withdrawal of it;
4 data provided when booking a meeting through TidyCal: first name, e-mail address, the selected time slot and meeting tool, and, on a voluntary basis, telephone number, company name and information about the intended subject of the conversation;
5 data contained in correspondence;
6 organisational data relating to the meeting, such as the time, the list of invitees, the platform selected and the information necessary to connect.
Data are obtained directly from the data subject, from the entrepreneur or organisation that the person represents, or automatically during the use of the website and online tools.
Users should not provide in the booking form data of special categories, such as information about health, political opinions, religious beliefs or trade union membership, or confidential information, unless this is necessary. If processing such information proves necessary during the delivery of a coaching or training service, its scope and legal basis will be established separately.
4. Purposes and legal bases for processing
4.1. Making the website available and securing it
Technical data are processed in order to display the site correctly, ensure its security, prevent abuse, diagnose errors and administer the website.
The basis for processing is the legitimate interest of the Controller in running a secure and efficient website, pursuant to Article 6(1)(f) of the GDPR.
Technologies used to store information on a user's device, or to gain access to information already stored there, may be applied without separate consent only where they are necessary to transmit a communication or to provide a service expressly requested by the user, pursuant to Article 399(3) of the Electronic Communications Law Act of 12 July 2024 (ustawa – Prawo komunikacji elektronicznej).
4.2. Website usage statistics
Where consent has been obtained, data are processed in order to compile statistics, measure the number of visits, analyse how the site is used and improve its content. Wix Analytics and Google Analytics 4 may be used for this purpose.
The basis for processing is consent, pursuant to Article 6(1)(a) of the GDPR and Articles 399 and 400 of the Electronic Communications Law Act.
Google Analytics is to be used solely to analyse use of the website. The Controller does not intend to enable Google Signals, to send its own user identifiers to Google Analytics, or to link the service with Google Ads for remarketing purposes.
4.3. Advertising performance measurement and remarketing
Where consent has been obtained, data on activity on the website may be processed using Meta Pixel and the LinkedIn Insight Tag. These tools make it possible to measure campaign effectiveness, identify visits originating from advertisements, build audiences and direct advertising to persons who have previously visited the website.
On the Controller's side, the basis for processing is consent, pursuant to Article 6(1)(a) of the GDPR and Articles 399 and 400 of the Electronic Communications Law Act.
4.4. Meeting bookings and B2B contact
Data provided in TidyCal are used to handle the booking, establish the subject of the meeting, communicate with the participant and hold the conversation.
Where a sole trader books a meeting in their own name in connection with the possible conclusion of a contract, the basis for processing is the taking of steps at their request prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR.
Where a person books a meeting as an employee, manager or representative of another entrepreneur, the basis for processing is the legitimate interest of the Controller in maintaining business contacts, presenting its offer and taking steps towards starting or delivering cooperation, pursuant to Article 6(1)(f) of the GDPR.
4.5. Holding online meetings
Organisational data, image, voice and the content of communications may be processed to the extent necessary to hold the meeting using Google Meet, Microsoft Teams or Zoom.
The basis is Article 6(1)(b) of the GDPR where the participant acts in their own name as a party or prospective party to a contract, or Article 6(1)(f) of the GDPR where the participant represents another entrepreneur.
Taking part in a meeting does not in itself constitute consent to its recording. If a meeting is to be recorded, participants will be informed of this separately before recording begins. This policy does not constitute an independent basis for recording meetings.
4.6. Establishment, pursuit and defence of claims
Data may be retained in order to establish, pursue or defend against claims. The basis is the legitimate interest of the Controller, pursuant to Article 6(1)(f) of the GDPR.
4.7. Compliance with legal obligations
If a contract is concluded after the meeting, data may be processed in order to comply with tax, accounting and other obligations arising from law. The basis is Article 6(1)(c) of the GDPR.
5. Cookies and similar technologies
Cookies are small pieces of information saved on a user's device. The website may also use similar technologies, such as pixels, tags and browser local storage.
The website uses the following categories:
Category | Purpose | Example providers
Necessary | Security, stability, display of the site and remembering the cookie decision | Wix, Usercentrics
Analytics | Statistics on visits and on how the website is used | Wix Analytics, Google Analytics 4
Marketing | Advertising measurement, conversions, audience building and remarketing | Meta Pixel, LinkedIn Insight Tag
Necessary technologies run automatically. Analytics and marketing technologies run only once the relevant consent has been given.
Users may accept all categories, reject optional technologies or select individual categories. Consent may be withdrawn or changed at any time using the link or the privacy settings icon available on the website. Withdrawal of consent does not affect the lawfulness of processing carried out before it was withdrawn.
Refusing consent to optional technologies does not prevent the use of the basic content of the website.
6. Key cookies
The table below sets out the main technologies planned for the website. The final list depends on the current Wix configuration and on the solutions used by the providers. An up-to-date list should also be available in the cookie settings panel.
Provider | Example cookies | Main purpose | Typical duration
Wix | XSRF-TOKEN, hs, TS* | Security and abuse prevention | Session
Wix | svSession, wixSession | Stability, security and basic operation of the site | Up to 12 months
Wix | bSession, SSR-caching | Platform operation and performance | About 24 hours
Wix | _wixAB3* | Platform testing | Up to 6 months
Google Analytics | _ga | Distinguishing users or devices | Up to 2 years
Google Analytics | _ga_<identifier> | Maintaining session state and measuring activity | Up to 2 years
Meta | _fbp, _fbc | Advertising measurement, browser identification and remarketing | Up to 90 days
LinkedIn | li_fat_id, lms_ads, lms_analytics | Analytics, conversions and remarketing | Usually up to 30 days
LinkedIn | li_sugr | User identifier matching | Up to 90 days
LinkedIn | bcookie | Device identification, diagnostics and security | Up to 1 year
Durations may be renewed on subsequent visits or changed by the providers. Up-to-date information should be checked in the website's cookie settings and in the documentation of the individual providers.
Users may also delete and block cookies in their browser settings. Blocking all cookies may affect the operation of some online functions.
7. Google Analytics
Google Analytics 4 is a Google service used to compile statistics on the use of the site. It may process, among other things, the browser identifier, information about the device, the entry source and data on the pages visited and events recorded.
The IP address is used during transmission and to determine the user's approximate location. According to information provided by Google, Analytics 4 neither logs nor stores individual users' IP addresses.
The service runs only once consent to analytics cookies has been given. Information on how Google uses data is available at:
https://policies.google.com/technologies/partner-sites
8. Meta Pixel
Meta Pixel is a tool provided by Meta Platforms Ireland Limited. It makes it possible to measure the effectiveness of advertising, record events on the website and build audiences for campaigns run on Meta services.
Meta Pixel may send to Meta, among other things, the address of the page visited, the time of the event, information about the browser and device, the IP address and cookie identifiers. The tool runs only once consent to marketing cookies has been given.
In respect of measurement and analytics services, Meta may act as a processor on the Controller's instructions. In respect of the collection and transfer of event data for targeting purposes, and in the other cases set out in the Meta Business Tools terms, the Controller and Meta Platforms Ireland Limited may act as joint controllers. Once it has received the data, Meta may process them as a separate controller for its own purposes set out in its documents.
The essence of the joint controller arrangements follows from the Meta Controller Addendum, which forms part of the Meta Business Tools terms.
Further information can be found in Meta's documents:
https://www.facebook.com/privacy/policy/
https://www.facebook.com/privacy/policies/cookies/
https://www.facebook.com/legal/terms/businesstools
9. LinkedIn Insight Tag
The LinkedIn Insight Tag is a tool provided by LinkedIn Ireland Unlimited Company. It is used to measure conversions, analyse visits, generate audience insights and carry out remarketing.
The tool may process, among other things, the address of the page visited, the IP address, the time of the visit, information about the device and browser, and cookie identifiers. It runs only once consent to marketing cookies has been given.
In respect of the LinkedIn Marketing Solutions products connected with the Insight Tag, the Controller and LinkedIn act in principle as separate controllers, in accordance with the current LinkedIn Independent Controller Addendum. LinkedIn may use the data it receives to provide, support and improve its services, including remarketing, conversion measurement, reporting and performance analysis.
Further information can be found in LinkedIn's documents:
https://www.linkedin.com/legal/privacy-policy
https://www.linkedin.com/legal/cookie-policy
https://www.linkedin.com/legal/l/cookie-table
https://www.linkedin.com/legal/l/linkedin-independent-controller-addendum
10. Booking a meeting through TidyCal
The booking button leads to the external TidyCal service, operated by Sumo Group Inc. On clicking it, the user leaves wojtektworkowski.pl. TidyCal then receives technical data relating to the connection and may use its own cookies.
To the extent that TidyCal stores a participant's data in order to handle a booking made with the Controller, the Controller remains the controller of the business contact data and TidyCal acts as a processor on the terms set out in its data processing agreement. At the same time, TidyCal may be a separate controller of data processed for its own purposes, as indicated in its privacy policy.
Providing a first name, e-mail address and selected time slot is necessary in order to make and handle a booking. Without these data, booking will not be possible. Providing a telephone number, company name and a description of the intended meeting is voluntary.
TidyCal privacy policy:
https://tidycal.com/privacy-policy
TidyCal data processing agreement:
11. Google Meet, Microsoft Teams and Zoom
When booking, the user may choose Google Meet, Microsoft Teams or Zoom. Depending on the choice, the information needed to create the meeting, such as first name, e-mail address, time and meeting identifier, may be transferred to the relevant provider:
• Google Ireland Limited or the relevant company in the Google group, in the case of Google Calendar and Google Meet;
• Microsoft Ireland Operations Limited or the relevant company in the Microsoft group, in the case of Microsoft Teams;
• Zoom Communications, Inc. or the relevant company in the Zoom group, in the case of Zoom.
Providers may act as processors on behalf of the account holder and as separate controllers in respect of data used for their own purposes, such as security, billing, abuse prevention and compliance with legal obligations.
During a meeting, the provider may process technical data, account data, image, voice, the content of communications and information about how the service is used. Detailed rules are set out in the privacy policy of the provider concerned, its terms of service and the account and meeting settings.
12. Buttons linking to social media services
Under the planned configuration, the YouTube, LinkedIn and Facebook buttons are ordinary links rather than embedded social plug-ins.
Merely displaying an ordinary link should not cause a connection with a social media platform. On clicking, however, the user is taken to an external service whose operator receives at least the technical data necessary to establish the connection, such as the IP address, browser data and potentially information about the referring page.
From that moment, processing also takes place on the terms set by the operator of that service. If the buttons are in future replaced by embedded widgets, posts or players, the policy and the consent settings will require review again.
13. Data recipients
Recipients of data, or processors handling data on the Controller's behalf, may include:
1 Wix.com Ltd. and entities supporting the maintenance, security and operation of the website;
2 the consent management platform provider Usercentrics;
3 Google, in connection with Google Analytics, Google Calendar and Google Meet;
4 Meta Platforms Ireland Limited, in connection with Meta Pixel;
5 LinkedIn Ireland Unlimited Company, in connection with the LinkedIn Insight Tag;
6 Sumo Group Inc., in connection with TidyCal;
7 Microsoft and Zoom, depending on the tool chosen to hold the meeting;
8 providers of e-mail, IT, cybersecurity, legal, accounting and administrative services;
9 competent authorities, where the obligation to disclose data arises from law.
Providers receive data solely to the extent needed to perform specified services or to pursue their own purposes described in their privacy documents.
14. Transfers of data outside the EEA
Some providers belong to international groups and may process data outside the European Economic Area, in particular in the United States or Israel.
Depending on the provider and the place of processing, transfers take place:
1 on the basis of a European Commission decision finding an adequate level of protection;
2 on the basis of the recipient's participation in the EU–US Data Privacy Framework, where the relevant certification covers that entity and that type of data;
3 on the basis of standard contractual clauses approved by the European Commission;
4 on the basis of another mechanism provided for in Chapter V of the GDPR.
Wix.com Ltd. has its registered office in Israel, in respect of which the European Commission has issued a decision finding an adequate level of data protection. Transfers to other countries, including onward transfers within providers' groups, are subject to the safeguards indicated in those providers' documents.
Information about the transfer mechanism applied, or about the possibility of obtaining a copy of the relevant safeguards, can be obtained by contacting the Controller. Some safeguards may be made available in anonymised form or with information constituting trade secrets omitted.
15. Data retention periods
Data are retained for no longer than is necessary to achieve the specified purpose:
1 technical data and security logs are retained for the period resulting from the Wix settings and from needs relating to security, error resolution and abuse prevention;
2 Google Analytics user data will be retained for 14 months, unless the configuration of the service is changed to a shorter period; aggregated reports that do not permit the identification of an individual may be retained for longer;
3 data connected with Meta Pixel and the LinkedIn Insight Tag are processed until consent is withdrawn, the identifiers are deleted, or the period set by the provider expires;
4 data relating to bookings, correspondence and the organisational meeting are retained, as a rule, for 12 months from the last contact, where no cooperation follows;
5 if a contract is concluded, data are retained for the duration of its performance and thereafter until the expiry of the relevant limitation periods for claims and of the periods required by tax and accounting rules;
6 data retained solely for the purpose of establishing, pursuing or defending claims are deleted once the relevant limitation period expires, unless proceedings requiring further retention end earlier;
7 information confirming that consent was given, refused or withdrawn may be retained for the period needed to demonstrate that the Controller has acted lawfully, as a rule for three years from the last consent-related event, unless longer retention is justified by ongoing proceedings.
16. Rights of data subjects
On the terms laid down in the GDPR, data subjects have the right:
1 of access to their data and to obtain a copy of them;
2 to rectification of their data;
3 to erasure of their data;
4 to restriction of processing;
5 to data portability, where processing is carried out on the basis of consent or a contract, by automated means, and the remaining conditions provided for in the GDPR are met;
6 to object to processing based on legitimate interests, on grounds relating to their particular situation;
7 to object at any time to the processing of data for direct marketing purposes, including profiling related to it;
8 to withdraw consent at any time;
9 to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO).
Once an objection to direct marketing has been raised, the data will no longer be processed for that purpose. Withdrawal of consent does not affect the lawfulness of processing carried out before it was withdrawn.
Requests can be sent to the e-mail address indicated in section 1. Before acting on a request, the Controller may ask for the information needed to confirm the identity of the person making it.
17. Profiling and automated decision-making
Meta Pixel and the LinkedIn Insight Tag may enable profiling for advertising purposes. This involves assigning a user to audiences on the basis of a visit to the website or actions taken on it. The result may be that a Twork.shop advertisement is displayed on Meta or LinkedIn.
The Controller does not take decisions in relation to the user based solely on automated processing that would produce legal effects or similarly significantly affect the user.
18. Security
The Controller applies organisational and technical measures to protect data, appropriate to the type of data, the scope of processing and the associated risk. These include, in particular, restricting access to data, securing service accounts, using encrypted transmission and selecting providers that ensure appropriate protection measures.
19. Changes to the policy
The policy may be updated where the functions of the website, the providers used, the manner of processing data or the applicable rules change. The current version is published on the website together with the date of the last update.
20. Language versions
The policy is published in a Polish and an English version. The Polish version is the binding one. In the event of any discrepancy between the versions, the Polish text prevails.
