Legal
Privacy Policy
Last updated: September 2026
Controller
The controller of your data is Rafał Syryczyński Management (trading as RS Management), ul. Konstancińska 2/102, 02-942 Warsaw, Poland, VAT ID PL5213714594. Contact: contact@rsmanagement.ai.
Data We Process
Through the contact form we process the data you provide: first name, e-mail, company name and message content. The form does not ask for a surname, because a first contact does not need one. We also record the fact and time of your confirmation that you have read how your data is handled. If we later start a paid engagement we also process invoice details and payment status. We do not store card numbers on this website.
When you book a call through the Microsoft Bookings scheduling page, we process the data provided in the booking form: name, e-mail address and meeting time, plus optional details: the topic you would like to discuss and, for the working session, company name and role. A booking creates a calendar event in Microsoft 365 together with confirmation and reminder messages.
Client meetings take place over Microsoft Teams. With the participants' consent, requested at the start of the call, a meeting may be recorded and transcribed. The recording is used solely to prepare the summary and materials for the client; we keep it until the engagement ends and no longer than 12 months from the meeting, and delete it earlier on request. The legal basis is contract performance (Art. 6(1)(b) GDPR) and, for participants who are not party to the contract, legitimate interest (Art. 6(1)(f) GDPR).
On every visit, the hosting provider processes technical connection data, including the IP address, to deliver the site and to protect it against abuse and excessive requests. The legal basis is legitimate interest (Art. 6(1)(f) GDPR). We do not build our own dataset from this data and we do not link it to submissions; the form's rate protection may rely on short-lived counters keyed by a hash of the address, not the IP address itself.
Purpose and Legal Basis
We process data to answer enquiries, provide consulting services, issue invoices and comply with tax and accounting obligations. The legal bases are steps taken at your request before a contract and contract performance (Art. 6(1)(b) GDPR), our legitimate interest in responding to enquiries (Art. 6(1)(f) GDPR) and legal obligation (Art. 6(1)(c) GDPR).
Processors and International Transfers
We keep the number of processors to a minimum. Currently: Cloudflare (website hosting, delivery and aggregate traffic logs) and Microsoft 365 (e-mail, calendar, appointment booking, Teams meetings and delivery of form submissions). We have data processing agreements in place with both. Invoices are issued in our invoicing system and submitted to the Polish National e-Invoicing System (KSeF) as required by law. When preparing client materials we use AI tools from OpenAI, Anthropic, Google and Perplexity under business terms that exclude training on the submitted content; we share only what the engagement requires and personal data only where the engagement makes it necessary.
Some of these providers are established in the United States. Cloudflare and Microsoft participate in the EU-US Data Privacy Framework (a European Commission adequacy decision) and additionally rely on standard contractual clauses provided for in their data processing terms. AI tool providers established in the United States rely on the same framework or on standard contractual clauses. We share the details of the transfer basis for a specific provider on request.
We do not sell your data and we do not share it with third parties for marketing purposes. We use no third-party font providers and no analytics scripts, so simply visiting the site sends your data to no one beyond the hosting provider.
AI and Your Data
We do not use your data, or any client data, to train AI models, and we do not feed confidential client information into public model training. Where AI tools support our own work, we use them under terms that exclude training on the submitted content.
Security Measures
We apply technical and organizational measures appropriate to the risk under Art. 32 GDPR, including encryption in transit, access control, multi-factor authentication and minimization of the data we collect. A detailed list of safeguards is provided to business clients as part of the data processing agreement.
Cookies and Analytics
This website does not set marketing cookies, does not use tracking and runs no analytics scripts in your browser. Traffic is measured server-side only, on the hosting provider's aggregate logs (Cloudflare): request counts, page addresses, country and client type, including bots. No consent banner is required because we read nothing from your device beyond what is needed to display the page.
Retention
Enquiry data is retained for the time needed to handle the conversation and, if no engagement follows, for up to 24 months from the last contact. Accounting and tax documents are retained for the period required by Polish law.
Your Rights
You may request access, rectification, erasure, restriction, portability, or object to processing based on our legitimate interest. Where processing relies on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal. A message to contact@rsmanagement.ai is enough.
You may also lodge a complaint with the Polish data protection authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland.
Providing Your Data Is Voluntary
Providing your data is voluntary but necessary for us to answer your enquiry, schedule a meeting or enter into a contract. Without it we cannot do those things. When you buy a service, providing billing details follows from tax law.
Automated Decisions and Profiling
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. This also covers the AI tools we use in our work: they support our own tasks.
Data Protection Officer
We have not appointed a data protection officer, as the conditions in Art. 37 GDPR do not apply. For all matters concerning personal data, please write to contact@rsmanagement.ai.
Data Processing Agreement
For business clients whose engagement involves processing personal data on their behalf, a Data Processing Agreement (Art. 28 GDPR) is available on request before the work starts.