owlet.studio ← Back to the site
Legal document

Privacy policy

Below we set out what personal data we process, on what legal basis, for what purpose, how long we keep it and what rights you have. We try to write in plain language while keeping the document fully compliant with the GDPR and Polish data protection law.

Last updated: 25 May 2026

1. Data controller

The controller of your personal data is:

owlet.studio
a business operated by SOWINS Kornel Sowiński
Orchów 159, 98-100 Łask, Poland
Tax ID (NIP): 8311640361
Business register no. (REGON): 386815540
e-mail: hello@owlet.studio

You can contact us about any data protection matter at the e-mail address above. We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR.

2. Data we collect and why

2.1. Using the website

Simply visiting owlet.studio requires no personal data at all. The site uses no Google Analytics, no Meta Pixel, no Hotjar and no other analytics, tracking or advertising tools.

The only things we store in your browser are those without which the site would not work the way you expect. Here is every single one of them:

  • owlet.theme (localStorage): the colour theme you chose, light or dark,
  • owlet.lang (localStorage): the interface language you chose,
  • owlet.themeV2 and owlet.themeV3 (localStorage): technical flags that migrate theme settings after a redesign,
  • owlet.booted (sessionStorage, gone when you close the tab): a note that the intro animation has already played in this session,
  • owlet.lead.draft (sessionStorage, gone when you close the tab): a working copy of the free demo form. It holds what you typed into the fields: name, email address, phone number, VAT number, company name, website address, business description and any links you gave. We do this so that refreshing the tab does not wipe out the brief you filled in. This copy never leaves your browser, does not include uploaded files, and is deleted automatically the moment the request is sent.

None of the entries above is sent to our server or shared with third parties, and none is used for tracking or profiling. You can delete them at any time in your browser settings. Section 7 explains why we do not ask for consent for them.

2.2. Server logs (hosting provider)

To keep the service secure and running correctly, our hosting provider (Cloudflare) may process technical access data (including IP address, browser type, operating system, date and time of the visit). We process this data under Art. 6(1)(f) GDPR (the controller's legitimate interest in keeping the site secure and protected against abuse).

2.3. Contact by e-mail

When you write to hello@owlet.studio, you provide us with your e-mail address, your name (if it appears in your signature) and the content of your message, along with any other data you choose to include in the correspondence.

We process this data to reply and to handle the correspondence, under Art. 6(1)(f) GDPR (the controller's legitimate interest in responding to enquiries) or Art. 6(1)(b) GDPR (where the correspondence leads to a contract).

2.4. Clients and business partners

Where a contract or an order is concluded, we process the data needed to carry out the cooperation: company details (name, registered address, tax and register numbers), details of the client's contact persons (first name, surname, e-mail, phone, position) and the data required to issue an invoice.

The legal basis is Art. 6(1)(b) GDPR (performance of a contract), Art. 6(1)(c) GDPR (tax and accounting obligations under Polish accounting and VAT law) and Art. 6(1)(f) GDPR (the controller's legitimate interest in establishing, pursuing or defending claims).

2.5. The free demo form

The home page carries a form where you can ask for a free demo version of your website. It collects your name, email address and VAT number, plus, if you choose to give them: phone number, company name, current website address, a description of what you do, the scope you ticked, links to your online profiles, links to video and photo material (a cloud drive, for example) and any files (logo, photos, a PDF, a short video). Along with the request we also receive the country code determined by our hosting provider from the IP address, the language version of the page and the date and time of sending.

Giving your name, email address and VAT number is voluntary, but without them we cannot prepare the demo or reply. All other fields and all attachments are entirely optional.

We process this data in order to prepare the demo and answer your request. The legal basis is Article 6(1)(b) GDPR, that is, steps taken at your request before entering into a contract. Ticking the box under the form confirms that you want to be contacted about this and that you have read this policy; it is not a separate legal basis. Separately, on the basis of Article 6(1)(f) GDPR, we protect the form against spam and automated submissions.

We do not store requests in any database of ours or in a CRM. We do send them as two emails: a notification to us and a confirmation to you. Delivery is handled by the external provider named in section 4, on whose servers the message and its attachments remain for a limited time. Because that provider operates in the United States, please also read section 5.

If the materials you send contain other people's data, for example photos of staff or clients, please make sure you are allowed to pass them on to us. We use them solely to prepare the demo.

2.6. Protecting the form against bots (Cloudflare Turnstile)

The form is protected by Cloudflare Turnstile. It only loads at the final step of the form, right before sending, so if you are merely browsing the site it never runs at all.

Turnstile's job is to check whether a human is filling in the form. Cloudflare states that it uses the IP address, the encrypted connection signature, the browser header and our site identifier for this, and declares that this is not used to identify, profile or target ads at anyone. This information goes straight to Cloudflare and is not stored on our server. When verifying the submission on the server side we pass your IP address to Cloudflare once more, to confirm that the test result is genuine.

The legal basis is Article 6(1)(f) GDPR, our legitimate interest in protecting the form and our mailbox from abuse. Cloudflare describes Turnstile's privacy rules at cloudflare.com/turnstile-privacy-policy.

3. How long we keep the data

  • E-mail correspondence: for as long as needed to reply and handle the matter, and then until any claims become time-barred (as a rule, up to 6 years).
  • Client and partner data: for the term of the contract and for 5 years from the end of the calendar year in which the last accounting document was issued (tax obligation), and for the limitation period for claims arising from the contract.
  • Sign-ups for post notifications: we run no automated newsletter, so we keep no mailing list.
  • Server logs: in line with the hosting provider's policy, as a rule up to 30 days.
  • Requests from the free demo form: we keep the message and its attachments in our mailbox for 3 years from the last contact in the matter. After that the request is no longer useful to us and any claims arising from the enquiry itself are time-barred. If the request leads to a project, the data falls under the rules for clients described above.
  • Copy of the message at the delivery provider: the notification and the confirmation remain available in the panel of the provider named in section 4 for a limited time under its own policy, and its infrastructure backups for up to 30 days.
  • Logs of the function handling the form: up to 7 days at the hosting provider. They contain no content of the request and no contact details, only the fact that the submission succeeded, the country code, the language version and the number of attachments.

4. Who receives the data

We do not sell your data and we do not share it with anyone for marketing purposes. We entrust it only to those providers we need in order to run the site and to receive your message. A data processing agreement compliant with Article 28 GDPR is in place with each of them. We would rather name them than hide behind generalities:

  • Cloudflare, Inc. (USA) - site hosting, protection against attacks and the function that handles the form. It processes technical access data including the IP address, as described in section 2.2.
  • Cloudflare, Inc. (USA) - the Turnstile service that protects the form against bots, described in section 2.6. When checking the submission limit we also pass it the email address entered in the form, solely so that nobody can use it to flood someone else's inbox.
  • Resend (USA) - delivery of the emails sent from the form. The entire content of the request goes there together with the attachments and both email addresses: yours and ours.
  • the email provider for the owlet.studio domain - this is where your message arrives and stays,
  • our accounting office - strictly for accounting documents,
  • providers of project management tools - strictly to the extent needed to deliver a specific project,
  • competent public authorities, if they make a request on a legal basis.

Our providers use their own sub-processors. Resend publishes its current list at resend.com/legal/subprocessors.

5. Transfers outside the European Economic Area

Yes, some data goes outside the EEA and we say so plainly. Our hosting provider (Cloudflare, Inc.) and our email delivery provider (Resend) are US companies and process data in the United States among other places. This applies to every request sent through the free demo form, as well as to the technical access data described in section 2.2 and the form protection described in section 2.6.

The basis for this transfer is European Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 finding an adequate level of protection under the EU-U.S. Data Privacy Framework (Article 45 GDPR). Independently of that, standard contractual clauses approved by the European Commission in Decision 2021/914 (Article 46(2)(c) GDPR) apply to both providers and protect the transferred data even if the adequacy decision were to cease to apply.

We will provide a copy of these safeguards on request sent to hello@owlet.studio.

If a specific project requires another tool that processes data outside the EEA, we will say so plainly and use only a provider offering an adequate level of protection on one of the bases above, limiting the scope of transferred data to the necessary minimum.

6. Your rights

In connection with the processing of your personal data you have the following rights:

  • the right of access to your data and to receive a copy of it (Art. 15 GDPR),
  • the right to rectification (Art. 16 GDPR),
  • the right to erasure, the so-called "right to be forgotten" (Art. 17 GDPR),
  • the right to restriction of processing (Art. 18 GDPR),
  • the right to data portability (Art. 20 GDPR),
  • the right to object to processing (Art. 21 GDPR), in particular to processing based on the controller's legitimate interest,
  • the right to withdraw consent at any time where processing is based on consent (Art. 7(3) GDPR); withdrawal does not affect the lawfulness of processing carried out before it,
  • the right to lodge a complaint with a supervisory authority, either in your country of residence or with the Polish President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl), if you consider that the processing infringes the GDPR.

To exercise any of these rights, please contact us at hello@owlet.studio. We answer requests without undue delay and no later than one month from receipt.

7. Cookies and similar technologies

owlet.studio sets no cookies at all. We use no analytics, statistics, advertising or tracking tools. The only things we store in your browser are the localStorage and sessionStorage entries listed one by one in section 2.1.

Storing information on a user's device is governed by Article 399 of the Polish Act of 12 July 2024, the Electronic Communications Law (Journal of Laws 2024, item 1221), which on 10 November 2024 replaced the former Article 173 of the Telecommunications Law. Consent is not required where the storage is necessary to provide a service the user has themselves requested (Article 399(3)(2)).

Every entry listed in section 2.1 falls within that exemption: each one remembers either your own choice or what you typed into the form you are filling in. None of them leaves your browser and none is used for tracking. That is why we do not ask for consent and do not display a separate cookie notice. You can delete all of these entries at any time in your browser settings, and the site will still work if your browser blocks the mechanism entirely.

8. Data security

We apply appropriate technical and organisational measures to protect the data we process, in particular against unauthorised disclosure, loss, destruction or alteration. These include encrypted connections (HTTPS), multi-factor authentication for the tools where data is processed, and regular software updates.

9. Profiling and automated decisions

We do not take decisions about you based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect you (Art. 22 GDPR).

10. Changes to this privacy policy

We update this policy when needed, in particular in the event of legal or technological changes or changes in the way we run the business. Each time we change the "last updated" date shown at the top of the document. We encourage you to review the current version from time to time.

This is a translation of the Polish original. In the event of any discrepancy, the Polish version available at owlet.studio/polityka-prywatnosci prevails.

owlet.studio

Studio, które buduje strony, aplikacje i automatyzacje dla firm w Polsce i nie tylko.

Nawigacja
  • Usługi
  • Proces
  • Portfolio
  • O nas
  • Blog
  • Polityka prywatności
Kontakt
  • hello@owlet.studio
  • Orchów 159
  • 98-100 Łask, Polska
  • NIP: 8311640361
  • REGON: 386815540
© 2026 owlet.studio. Wszelkie prawa zastrzeżone. Made in Polska