Legal
Privacy Policy
Last updated: 2026-09-15
1. Who is the data controller?
The controller of your personal data is:
TW Consulting (trading as WebForge Studio)
ul. Romańska 1/3, 01-451 Warszawa, Poland
NIP (Tax ID): 5272599137
Website: webforgestudio.eu
Contact: office@webforgestudio.eu
2. What data do we collect and why?
a) Contact form and enquiries
When you submit the contact form, we collect: name, email address, phone number (optional), website URL (optional), message text, your stated needs, your budget, and the language you filled the form in. Legal basis: legitimate interest (Article 6(1)(f) GDPR) - to respond to your enquiry. We do not use this data for marketing unless you explicitly consent. Some of this data also goes to our internal CRM and to our team on Telegram - the scope differs between the two, see the exact breakdown in points k) and l) below.
When you submit the contact form, and when you subscribe to blog notifications, we additionally remember your IP address for one hour. It is used solely to limit how many submissions come from a single address and to protect the form from abuse - for no other purpose, and it is not combined with anything else. The address is held in the running program's memory only: after an hour it stops counting towards the limit, and it is removed from memory by a cleanup task that runs every minute, regardless of whether any further submissions arrive. It also disappears sooner whenever the service restarts. Legal basis: legitimate interest (Article 6(1)(f) GDPR) - abuse prevention.
b) Website Audit purchase (online checkout)
When you order the Website Audit, we collect: your email address (to deliver the report), the URL of the website to be analysed, and the data needed to process payment. We do not process card data ourselves - it goes directly to our payment processor, Stripe (see section 4). Legal basis: performance of a contract (Article 6(1)(b) GDPR). We keep your email address and URL indefinitely and delete them on request - email office@webforgestudio.eu. If you request an invoice, billing data is kept for up to 5 years (tax requirements).
c) Free Core Web Vitals Audit
When you order the free Core Web Vitals audit, we collect: your email address (to deliver the report), the URL to be analysed, and the IP address the request was sent from. The IP address is used solely to limit how many free reports a single address can request in a short period, and for no other purpose. Legal basis: legitimate interest (Article 6(1)(f) GDPR) - abuse prevention. Email and URL are kept indefinitely and deleted on request (see section 3); the IP address is kept as part of the same record.
d) Facebook Ads Audit purchase (online checkout)
When you order the Facebook Ads Audit, we collect: your email address, the ad account or page, and the name of the campaign you want audited, plus the data needed to process payment (see section 4, Stripe). Legal basis: performance of a contract (Article 6(1)(b) GDPR). Email address, account/page and campaign name are kept indefinitely and deleted on request (see section 3).
e) Marketing contact sign-ups
If you sign up for marketing contact (notifications about new articles, services and tools), we collect your email address, the language of the form, and the consent text you accepted - its version, its literal wording and the date of sign-up, plus which form the sign-up came from. We record this so we can show what exactly you consented to, not merely that you consented. Legal basis: consent (Article 6(1)(a) GDPR). You can withdraw consent at any time by clicking unsubscribe in any email - unsubscribing removes your address from the list entirely. We do not store your IP address as consent evidence.
f) Website analytics (cookieless, no consent required)
We use Plausible Analytics - a privacy-first, self-hosted analytics tool running on our own server (stats.webforgestudio.eu). Plausible does not use cookies and does not track visitors across sessions or websites. By default it records: the URL of the page being viewed (needed to attribute the visit to a specific page - this is how every tool of this kind works), referrer, country (derived from IP - IP is never stored), browser type, and device category. We also record individual conversion events (e.g. checkout started) - their own parameters contain only the event name and, for the Facebook Ads Audit, a service label; we do not pass the URL of the site being audited, or anything else you typed into the form, in these parameters. On thank-you pages we strip the Stripe session identifier from the address bar before any event is recorded - otherwise it would be captured as part of the current page's URL. Legal basis: legitimate interest (Article 6(1)(f) GDPR). No cookie consent banner is needed. Our instance is self-hosted on a server within our own hosting infrastructure (Hostinger, see section 4) - data doesn't reach an external provider (Plausible Ltd.); the dashboard shows it in aggregated form, but the tool also stores individual events - we have not checked how long individual records are kept in our database.
g) Microsoft Clarity - on-site behaviour analytics (cookieless, no consent required)
Our pages load a Microsoft Clarity script that records your in-browser behaviour: clicks, scrolling, input events, and the page's DOM structure, tied to a session identifier. It runs in "cookieless" mode (it does not set cookies), which does not mean the data collected is aggregated or anonymous - Clarity records the course of an individual browsing session. Legal basis: legitimate interest (Article 6(1)(f) GDPR) - improving the usability of the site. Data is processed by Microsoft Ireland Operations Limited and may be further transferred to Microsoft Corporation (USA) under Standard Contractual Clauses (SCCs). Microsoft's privacy policy: privacy.microsoft.com.
h) AI-based analysis - Website Audit and Facebook Ads Audit
When you order the Website Audit, our system automatically retrieves (crawls) the publicly available HTML of the website you specified - this happens on our own infrastructure. We pass to Google LLC (PageSpeed Insights API) only the URL of the analysed page - not the raw HTML. We pass to the Anthropic, Inc. (Claude) AI model not the raw HTML, but a curated set of content generated by our crawler: text samples, headings, calls to action (CTAs), technical analysis results (including from PageSpeed), and structured data, together with the page's URL. We do not share your personal data with either provider. Anthropic, Inc. is based in the USA; transfers rely on Standard Contractual Clauses (SCCs). Anthropic's privacy policy: anthropic.com/privacy. Legal basis: performance of a contract (Article 6(1)(b) GDPR). The free Core Web Vitals audit does not use this flow - it only retrieves a PageSpeed Insights result (see point c) above), without fetching page content and without any AI model involved.
As part of the Facebook Ads Audit, we pass data of the selected campaign from your ad account to the Anthropic, Inc. (Claude) AI model: campaign, ad set and ad settings, creative copy, and performance statistics. We do not pass personal data of the people your ads reach - Meta does not make it available to us. Transfers to the USA rely on Standard Contractual Clauses (SCCs). Legal basis: performance of a contract (Article 6(1)(b) GDPR).
i) Meta Pixel (Facebook) - advertising
On every page of the site, a small local script loads (part of our shared page template) that collects nothing on its own - it only checks whether you've consented to marketing. Only after you consent in our cookie banner does this script load the external Meta library (fbevents.js, Meta Platforms Ireland Ltd.) and record a page-view event (PageView) on every page you visit from that point on; on pages related to purchasing an audit it additionally records checkout-initiated and purchase events. The Pixel helps us measure the performance of our Facebook and Instagram ads. Data is shared with Meta Platforms Ireland Ltd. (EU) and may be further transferred to Meta Platforms, Inc. (USA) under SCCs. You can manage your ad preferences on Facebook via ad settings. Legal basis: consent (Article 6(1)(a) GDPR).
j) Email delivery
Every email you get from us - the PDF audit report and the marketing messages you signed up for (notifications about new articles, services and tools) - is sent via Google LLC (Gmail/SMTP). For this purpose Google processes: your email address, the message content, and - for the Website Audit and free Core Web Vitals audit - the attached PDF report. Legal basis: performance of a contract (Article 6(1)(b) GDPR) or consent for the marketing messages. Transfers outside the EU rely on SCCs.
k) Internal operational notifications (Telegram)
Our system sends notifications to our team via Telegram (Telegram FZ-LLC) - these are three independent flows, with a different scope of data:
- Website Audit, free Core Web Vitals audit, Facebook Ads Audit: when an audit fails, a new Facebook Ads Audit order comes in, or someone rates a report - the notification contains the customer's website or ad account URL and a shortened order identifier. It never contains the customer's email address.
- Contact form: when you submit the contact form, the notification contains your name, your full email address, phone number (if provided), website (if provided), what you're looking for, your budget range, and up to 500 characters of your message.
- Payment without complete order data: when a payment succeeds but the session is missing what we need to fulfil it (for example the address of the site to audit) - the notification contains a shortened payment session identifier, the amount with its currency, and the names of the missing fields. It contains neither the customer's email address nor a website address - we pass on neither of them, even when one of them is present in the session data.
Legal basis for all three flows: legitimate interest (Article 6(1)(f) GDPR) - order handling, enquiry handling, and incident response. We have no mechanism on our side to delete these messages; we have not checked the provider's retention policy.
l) Internal CRM (Twenty)
From the contact form, our CRM system (Twenty) receives: your name, email, phone (if provided), the language of the form, your needs and website (folded into the sales-opportunity's name), and - only for the budget ranges our system currently recognises as a specific amount - an indicative deal value. Your message text also goes into the CRM - we store it as a note linked to the sales opportunity, together with your phone number, website, what you are looking for and your budget. We do this because the message previously had no durable, complete record: it went into an operational notification and, if that failed, in shortened form into a technical log, which is not a data store. A message longer than 4000 characters is not accepted at all - the form rejects it with an error, so you know immediately that it did not reach us. We do not store it in any form, truncated or otherwise - that's a different scope than Telegram (see point k) above). If the CRM record is created but the note holding your message cannot be saved, we write the full set of form data (name, email, phone, website, form language, what you are looking for, budget and the message text) into a fallback file on the same server, so that your enquiry is not lost. If an earlier step fails, the form returns an error and no fallback file is written, but what remains depends on where the failure occurred: if saving your contact details to the CRM fails, nothing is stored at all; if your contact details were saved but creating the linked sales opportunity failed, then your contact details (name, email, phone if provided, form language) remain in the CRM - without the message text. The fallback file is accessible only to us; entries are moved into the CRM by hand and removed from the file at that point. There is no automatic deletion. This tool is self-hosted on our own infrastructure (Hostinger, see section 4) - data is not shared with an external Twenty provider. Legal basis: legitimate interest (Article 6(1)(f) GDPR) - handling your enquiry and any further cooperation. Retention - see section 3, "Contact enquiries".
m) Technical data
Our hosting provider (Hostinger) processes your IP address and browser information for security and performance purposes. Legal basis: legitimate interest. We have not verified how long Hostinger retains these logs.
3. How long do we keep your data?
- Contact enquiries (including data in our CRM, see point 2l): Contact form data is kept indefinitely and deleted on request (email office@webforgestudio.eu). We do not declare any period after which the data disappears on its own - we have no such mechanism and deliberately do not build one; deletion is manual, on request.
- IP address from the contact form and from blog-notification sign-ups: One hour, in the running program's memory only (abuse prevention - see point 2a). After an hour it stops counting towards the limit and a cleanup task running every minute removes it from memory; it also disappears on every service restart. We do not write it to any file or database.
- Marketing sign-up data (address, language, consent version and wording, source of sign-up, date): Until you unsubscribe.
- Order data (Website Audit, free Core Web Vitals audit, Facebook Ads Audit): Email address, URL (or, for the Facebook Ads Audit, the ad account/page and the campaign name), and - for the free Core Web Vitals audit only - the IP address are kept indefinitely and deleted on request (email office@webforgestudio.eu). We do not promise automatic deletion after a fixed period - we have no such mechanism today; deletion is manual, on request. If you request an invoice, billing data is kept for up to 5 years (tax requirements).
- Analytics data (Plausible): Our instance is self-hosted - data does not reach Plausible Ltd., but it is stored on hosting infrastructure provided by Hostinger (see section 4). The dashboard shows it in aggregated form, but the tool also stores individual events; we have not checked how long individual records are kept in our database.
- Microsoft Clarity data and Telegram notifications: We have not checked these providers' retention policies; we have no mechanism on our side to delete them.
- Client project data: For the duration of the contract plus 5 years (for tax/legal compliance).
4. Who do we share data with?
We do not sell your data. We share it only with processors necessary to deliver our services:
- Hostinger - web hosting (EU servers)
- Google LLC - Calendar (meeting scheduling), with EU data processing addendum; transfers outside the EU rely on Standard Contractual Clauses (SCCs)
- Stripe Inc. - online payment processor (Website Audit, Facebook Ads Audit, and the free Core Web Vitals audit where applicable). Stripe processes payment data (card number, billing details) as an independent controller under GDPR. We pass Stripe the customer's email address and, in the order metadata (so payments can be matched to the right order), the website URL - or, for the Facebook Ads Audit, the ad account/page address and the campaign name. Transfers outside the EU rely on SCCs. Stripe's privacy policy: stripe.com/privacy
- Plausible Analytics - self-hosted on a server within our own hosting infrastructure (Hostinger, see above); no data is sent to the external provider Plausible Ltd. It records the current page's URL with every event (standard mechanism) - on thank-you pages we strip the Stripe session identifier from it before the event is recorded. The dashboard aggregates data for display, but the tool also stores individual events; we have not checked their retention.
- Twenty (our CRM) - self-hosted on our own infrastructure; we save there: name, email, phone (if provided), form language, needs and website (folded into the sales-opportunity name), and, for some budget ranges, an indicative amount, together with your message text - stored as a note linked to the sales opportunity (see point 2l). Not shared with an external Twenty provider.
- Anthropic, Inc. - AI model (Claude) used as part of the Website Audit and Facebook Ads Audit services. Based in the USA. Transfers rely on SCCs. For the Website Audit we do not share raw HTML - only a curated set of content generated by our crawler (text samples, headings, CTAs, technical analysis results, structured data) together with the page URL. For the Facebook Ads Audit - data of the selected campaign: campaign, ad set and ad settings, creative copy, and performance statistics. In neither case do we share the ordering customer's personal data. Policy: anthropic.com/privacy
- Google LLC - PageSpeed Insights API (Core Web Vitals analysis). We share only the URL of the analysed page. Google Calendar (meeting scheduling). Transfers outside the EU rely on SCCs.
- Google LLC - email provider (Gmail/SMTP) used to send every email we send: PDF reports and the marketing messages you signed up for. Contact-form submissions no longer generate any email to you - you see the confirmation on the page right after sending the form. We share: the recipient's email address, the message content, and - for reports - the full PDF. Transfers outside the EU rely on SCCs.
- Meta Platforms Ireland Ltd. - Meta Pixel. A local consent-check script is on every page of the site (shared template), but the external library (
fbevents.js) and events (including PageView) load and record only after you consent in the cookie banner. Data may be transferred to Meta Platforms, Inc. (USA) under SCCs. - Microsoft Corporation / Microsoft Ireland Operations Limited - Microsoft Clarity (on-site behaviour analytics: clicks, scrolling, input events, DOM structure, session identifier). Transfers outside the EU rely on SCCs. Policy: privacy.microsoft.com
- Telegram FZ-LLC - internal operational notifications for our team, three independent flows: (1) audit/CWV/FB Ads - the customer's website or ad account URL and a shortened order identifier, no email address; (2) contact form - name, full email address, phone, website, what you're looking for, budget, and up to 500 characters of your message; (3) payment without complete order data - a shortened payment session identifier, the amount and currency, and the names of the missing fields, with no email address and no website address. We have no mechanism on our side to delete these messages; we have not checked the provider's retention policy.
All processors are required to comply with GDPR. We have not checked the providers' own retention periods (Stripe, Google, Microsoft, Meta, Telegram, Hostinger) - their own policies and agreements apply.
5. Your rights under GDPR
You have the right to:
- Access - request a copy of the data we hold about you
- Rectification - correct inaccurate data
- Erasure - request deletion ("right to be forgotten")
- Restriction - limit how we process your data
- Portability - receive your data in a machine-readable format
- Objection - object to processing based on legitimate interest
- Withdraw consent - at any time, where processing is based on consent
To exercise any of these rights, email office@webforgestudio.eu. We respond within 30 days.
6. Complaints
If you believe we have handled your data unlawfully, you have the right to lodge a complaint with the supervisory authority in your country. In Poland, this is the Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw. In Germany: www.bfdi.bund.de.
7. Cookies
The site currently sets no essential cookies - there is no login, session, or cookie-stored preference. We'll update this section if that changes. Our analytics tools (Plausible and Microsoft Clarity) are cookieless - no consent banner is required for them, though Clarity processes the data described in sections 2g and 4. A local consent-check script for Meta Pixel (see section 2i) loads on every page of the site, but the external library only loads, and only records events or sets cookies, after you consent to marketing in the cookie banner - you can grant or decline it there. See our Cookie Policy for a full list of cookies used.
8. Changes to this policy
We may update this policy as our services change or to comply with new legal requirements. Material changes will be announced on this page. The "last updated" date at the top reflects the most recent revision.
9. Contact
For any privacy-related questions or requests:
WebForge Studio
Email: office@webforgestudio.eu
Website: webforgestudio.eu