Home · Privacy policy
Privacy policy
Version 1.0 · effective from 17 September 2026. In plain words: what we collect, why, and what your rights are.
1. Data controller
The controller of your personal data is Mientha spółka z ograniczoną odpowiedzialnością (limited liability company) with its registered office in Warsaw, ul. Puławska 39/40, 02-508 Warsaw, Poland, entered in the register of entrepreneurs of the National Court Register under KRS number 0000914133 (District Court for the Capital City of Warsaw, 13th Commercial Division of the National Court Register), VAT ID (NIP) PL5342641986, REGON 389581580, share capital PLN 5,000 ("Mientha", "we").
You can contact us about personal data at [email protected], by phone at +48 22 290 27 27, or in writing to our registered office.
2. What data we process and why
a) Contact form and e-mail correspondence. We process the data provided in the contact form or sent by e-mail: name, e-mail address, optionally company, phone and the content of your message. Purpose: responding to your enquiry and further correspondence about it. Legal basis: Art. 6(1)(b) GDPR (steps taken at your request prior to entering into a contract) and Art. 6(1)(f) GDPR (our legitimate interest: communicating with people who contact us on behalf of their organisations). We keep the data for the duration of the correspondence and then for up to 24 months from the last contact, for relationship continuity and evidentiary purposes.
b) Booking meetings (Microsoft Bookings). When you book a slot on the "Book a meeting" page, you provide data (name, e-mail, optionally a topic) in the Microsoft Bookings service running in our Microsoft 365 environment. Purpose, basis and period – as in point a). The meeting takes place in Microsoft Teams.
c) Technical data (logs). The website runs on Cloudflare infrastructure; standard server logs (IP address, request time, URL, browser) are processed to keep the site secure and reliable (Art. 6(1)(f) GDPR), for periods resulting from the provider's configuration.
d) Visit statistics. We currently use no analytics tools. If that changes, we will choose a cookie-less solution with no cross-site tracking and update this policy before switching it on.
3. Cookies
The site uses no marketing or tracking cookies and shows no ads. We use no cookies that would require consent – which is why you will not see a cookie banner here. Fonts and all assets are served from our own domain.
4. Recipients of the data
We entrust data only to providers necessary to run the site and communicate, under data processing agreements: Cloudflare, Inc. (hosting and protection of the site) and Microsoft Ireland Operations Ltd. (e-mail, calendar and meetings – Microsoft 365, Bookings, Teams). Any transfers outside the EEA are safeguarded by Standard Contractual Clauses (SCC) and, for certified providers, by the EU-U.S. Data Privacy Framework. Where necessary, data may also be received by our legal or accounting service providers. We do not sell data and we do not share it with anyone for marketing purposes.
5. Your rights
You have the right to: access your data, rectify it, erase it, restrict processing, data portability (for data processed under Art. 6(1)(b) GDPR) and to object to processing based on legitimate interest. Send requests to [email protected]. You also have the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw).
6. Voluntary provision of data
Providing data in the form or when booking a meeting is voluntary, but necessary for us to answer your enquiry or arrange the call.
7. Automated decisions and profiling
We make no decisions about you based solely on automated processing and we do not profile users of the site.
8. Changes to this policy
We will announce material changes by publishing a new version on this page with its effective date. Archived versions are available on request.