1. Administrator and contact

The service provider and data controller is Bartłomiej Mech, a sole trader operating under the registered name BXM MULTIMEDIA APLIKACJE INTERNETOWE BARTŁOMIEJ MECH, registered in the Polish CEIDG business register, ul. Korzystna 7, 03-626 Warszawa, Poland, tax identifier NIP 1132479129, REGON 142112170. SEO Certyfikacja is a project of BXM Multimedia.

Contact, complaints and personal data matters: [email protected], telephone +48 537 48 48 44. Paper correspondence can be sent to the above address.

In matters regarding personal data, please contact the administrator directly at the above e-mail address or by correspondence. The information below relates to SEO Certyfikacja; after consciously switching to another website, the rules of its operator also apply.

2. What data and from where

  • Browsing: the server receives the data needed to handle the connection, including: IP address, requested address, date and technical details of the request. The scope of the logs depends on the infrastructure.
  • Analysis: we process the provided public URL, the response of the examined page, headers, robot rules and data needed to calculate and display the observations. Public content may contain third party data; its source is the indicated website.
  • Protection against abuse: we save technical counters along with a hash calculated from the IP address. This is not a declaration of full anonymization.
  • Contact and complaints: we process data that we actually receive, e.g. name, e-mail, message content, company details and the submitted report.
  • Device memory: after you choose to remember dismissal for the session, we store only the notice version for the browser tab session. Details are provided in the cookie policy.

Do not include confidential data in addresses or messages. When you click “Send message”, the form transmits your details to BXM through the mail server. We include the language, page path without parameters and enquiry identifier; enquiries from reports also include the displayed analysis summary. We do not store message contents in the website database or subscribe you to a newsletter.

3. Purposes and grounds for processing

  • Implementation of the ordered analysis and action before concluding the contract: Article 6(1)(b) GDPR, insofar as necessary to fulfil your request when you are a party to a contract or request steps before entering into one.
  • Website provisioning, security, anti-abuse and other correspondence: Article 6(1)(f) GDPR. The legitimate interest is to provide the service efficiently and securely and respond to enquiries received. This also covers analysing the necessary parts of a website’s public response where they contain third-party data.
  • Legal obligations, including the processing of data requests and obligations related to complaints: Article 6(1)(c) GDPR, to the extent required by the applicable legal provisions.
  • Establishing, pursuing or defending claims: Article 6(1)(f) GDPR, to the extent necessary.

We do not use analysis data for marketing or advertising profiling. Selecting the regulations does not constitute marketing consent. Enabling the optional PageSpeed ​​is a request for additional measurement; We do not treat it as a universal consent to all Google activities.

4. Recipients and Google PageSpeed

The data may be received by authorized persons operating the website, hosting and e-mail providers, technical support entities and entities authorized by law. We limit the scope of disclosure to the purpose of the service and obligations. Connection data is handled by hosting and network infrastructure providers. Their actual settings and retention periods require confirmation before public launch.

The website being examined receives a request from our server; We do not provide it with data from the contact form or the user's IP address in the intermediary header for this purpose. We have no influence on the own logs of the operator of the website being examined.

If you enable PageSpeed or request measurement from a report, we share the public page address and selected device type with Google. Google also receives our server's connection data and can download the specified website. We do not send him your contact report, mail or local login details. For this reason, we do not run Google analytics in your browser.

Processing by Google is described Google privacy policy and principles of data transfers. The supplier's infrastructure may cover countries outside the EEA; the supplier's documentation describes the transfer bases and safeguards used. Do not send addresses with personal or confidential data through this module.

Opening a link to Google, BXM or another external site simply connects your browser to that site. This is a separate activity from the measurement performed by our server.

Cloudflare: a Cloudflare traffic handling and protection layer is provided for the public domain. If traffic is forwarded through its proxies, Cloudflare receives, among other things: IP address, requested URL, and technical request data to deliver resources and protect against abuse. Just using DNS does not mean proxying all HTTP connections. The specific scope depends on your domain configuration. The supplier uses global infrastructure; contains information on processing and transfers outside the EEA Cloudflare privacy policy. We do not declare exclusive processing in Poland or the EEA.

5. Retention periods

  • Website responses and the report: processed during the request and kept in the memory of the open page. The application does not create a report history database. The downloaded JSON or PDF remains on your device until you delete it.
  • Protection counters: grouped into minute and daily windows. The previous IP hashes are replaced on the next request after the window changes. If there is no next request, the last record remains in the private file until it is deleted. Automatic cleaning target and period must be confirmed before publication; we do not declare an unactivated mechanism.
  • Infrastructure logs: the storage period on the target hosting has not been confirmed yet; this part of the document requires completion before publication. Data extracted to clarify a specific incident may be stored until the case is concluded, and in the event of claims, for the necessary period of their investigation or defense.
  • Correspondence: for the time of handling an inquiry or complaint; after its completion, only to the extent necessary to fulfill legal obligations or to establish, pursue and defend specific claims, until the relevant deadlines have expired. Further paid cooperation requires separate information corresponding to its scope.
  • Remembering the message: for the browser tab session, unless you remove the setting earlier. The browser’s session restoration feature may restore this state.

Contact form protection stores hashes of tokens, request data and IP addresses, the time and the attempt status. A token permits a send attempt for 30 minutes; the per-client counter covers 10 minutes and the site-wide limit covers one day. Attempt records are removed on the next request after 24 hours. Without a subsequent request, they remain in a private file until server cleanup. They contain neither message contents nor plain-text email addresses. Received correspondence remains in the mail system under the correspondence retention rules.

6. Your rights

Under the terms and limits of the GDPR, you have the right to access your data and obtain a copy of it, rectify it, delete it, limit processing and - if the basis is a contract or consent and the processing is automatic - transfer the data. You may object to processing on the basis of legitimate interest for reasons related to your particular situation.

If processing was based on consent, you can withdraw it at any time without affecting the compliance of previous processing. The current version of the website does not collect marketing consents. Deleting a message does not undo a measurement that has already been performed or delete data processed independently by a third-party provider.

Send request to [email protected]. We respond without undue delay, generally within one month; We inform you about the permissible extension and the reasons in accordance with the GDPR. We may ask for proportionate proof of identity. We do not require you to provide your password to the website you are examining.

You have the right to lodge a complaint with the President of the Personal Data Protection Office. Information about your complaint and your rights can be found at uodo.gov.pl.

Information about processing, response deadlines and rights results from GDPR, in particular Art. 12–22. We consider rights in relation to the data we actually process; we do not collect additional data solely for the purpose of assigning an anonymous report to a specific person.

7. Voluntary, automation and change

Providing the URL is voluntary, but necessary to analyze the selected website. The contact requires data to respond. Protective processing of connection data is needed to provide the service securely. Opting out of PageSpeed ​​does not block basic analysis.

We do not make decisions regarding persons based solely on automated processing that produce legal effects or similarly significantly affect them within the meaning of Art. 22 GDPR. Automatic technical monitoring of the website is not an assessment of its owner or contractor.

When functions or data recipients change, we update the information accordingly. Version of this policy: 2026-09-21.3. Privacy settings are available in the footer of each subpage.