This is a translation of the original Polish-language document. Our service is governed by Polish law; in the event of any discrepancy, the Polish version prevails.
Privacy Policy
for the "Letter from the future" application · effective as of 01.08.2026
Subject of this Privacy Policy
This Privacy Policy explains how personal data is collected and used in connection with the operation of the "Letter from the future" Application, in particular when completing the Form, generating the Letter from the Future, requesting a Consultation, requesting the preparation of an Offer, and signing up for marketing communications.
The Controller processes data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality.
Data provided in order to generate the Letter is not automatically used for marketing purposes. The use of an email address to send commercial information only takes place once separate legal conditions have been met and the data subject has given their consent.
Data Controller
The controller of personal data is:
- Name (full name / company): Kinga Czerlikowska
- Address: Beskidzka 36, 34-300 Żywiec, Poland
- Tax ID (NIP): 5532291029
- Business registry number (REGON): 241775190
- Email address:
(hereinafter the "Controller"). The Controller independently determines the purposes and means of processing data in connection with the operation of the Application.
For matters concerning personal data, the exercise of rights under the GDPR, or data security, you can contact the address indicated above or write to the Controller's address.
Scope of data processed
In connection with using the Application, the Controller may process:
- the User's first and last name, if required or voluntarily provided;
- the email address;
- the answers given in the Form;
- a description of personal or professional goals;
- information about planned actions, anticipated obstacles, and available resources;
- information about industry, profession, business activity, or career plans;
- information about planned income, earnings, costs, or other amounts;
- names of places and information about the planned way of celebrating the achievement of the goal;
- names or other data of persons indicated by the User;
- other information voluntarily entered in open fields;
- the content of the generated Letter;
- data provided during a Consultation or in connection with the preparation of an Offer;
- data related to complaints and contact with the Controller;
- technical data, such as IP address, device identifiers, browser type, timing of individual operations, and error information;
- information about consents given, their content, the date given, and the date withdrawn.
The scope of data depends on how the Application is used. The Controller does not require information that is not needed to perform the selected service.
The Form is not intended for submitting special categories of personal data or data concerning criminal convictions and offenses.
The User should refrain from providing a national identification number, identity document data, login credentials, medical information, information covered by professional secrecy, or other data whose disclosure could infringe the rights of the User or third parties.
Purposes and legal bases for processing
Data contained in the Form is processed in order to conclude and perform the contract for generating and delivering the Letter. The legal basis for processing is Article 6(1)(b) GDPR.
If the User requests a Consultation, the data will be processed in order to take action at the User's request, prepare for the Consultation, carry out the contact, and provide a response. The legal basis is Article 6(1)(b) GDPR.
If the User requests the preparation of an Offer, the data may be analyzed in order to determine their needs and prepare a suitable proposal. The legal basis is Article 6(1)(b) GDPR, as steps taken at the request of the data subject prior to entering into a possible contract.
Data related to a complaint is processed in order to handle it, perform legal obligations, and protect the User's rights. The legal basis is Article 6(1)(b) and (c) GDPR.
Data may be processed to ensure the security of the Application, prevent abuse, detect failures, create backups, and document the correct operation of the system. The legal basis is Article 6(1)(f) GDPR, with the Controller's legitimate interest being the assurance of the safe and reliable operation of the Application.
Data may be processed in order to establish, pursue, or defend legal claims. The legal basis is Article 6(1)(f) GDPR, with the legitimate interest being the protection of the Controller's rights and demonstrating the correct performance of the contract.
The email address may be used to send commercial information and conduct direct marketing after the required consent has been obtained. The legal basis for processing is Article 6(1)(a) GDPR, in conjunction with Article 398 of the Polish Law on Electronic Communications.
Information about the giving or withdrawal of consent may be stored in order to demonstrate that marketing activities were carried out lawfully. The legal basis is Article 6(1)(c) or (f) GDPR.
If optional analytical or marketing tools using cookies or similar technologies are applied in the Application, data will be processed once the required consent has been obtained.
Generating the Letter using artificial intelligence
The answers given by the User may be processed using an artificial-intelligence-based tool in order to generate a personalized Letter.
The use of the AI tool is auxiliary in nature and serves to prepare the content ordered by the User. This process does not involve decisions producing legal effects for the User or similarly significantly affecting them.
The Controller will take steps to limit the scope of data transferred to the AI tool to information actually needed to generate the Letter.
Where possible, content will be pseudonymized, in particular by limiting the transfer of first and last names, precise contact details, and other identifiers.
Users' data will not be used to train the Controller's own or third-party artificial intelligence models, unless a separate legal basis is established for such use and the User is informed beforehand of the rules governing such processing.
The AI tool used to generate the Letter is OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.), called directly through the provider's API. Data may be processed in the United States and other countries where OpenAI maintains infrastructure, on the basis of standard contractual clauses. Data submitted through the API is not used by default to train models and is retained for a maximum of 30 days for abuse-monitoring purposes, after which it is deleted, unless a longer retention period is required by law. In this respect, OpenAI acts as a processor under a data processing agreement (DPA) concluded with the Controller.
Recipients of data
Data may be transferred to entities supporting the Controller in operating the Application, in particular:
- hosting and server infrastructure providers;
- email service providers;
- the provider of the AI tool used to generate the Letter;
- entities providing IT, service, and cybersecurity services;
- providers of the system used to handle marketing communications;
- providers of analytical tools – if used;
- law firms, accountants, auditors, and other advisors;
- entities authorized to receive data under applicable law.
Entities processing data on the Controller's behalf may use it only on the basis of a contract and in accordance with the Controller's documented instructions, unless an obligation to process it differently arises from the law.
Data will not be sold to third parties or transferred to partners for their own marketing purposes without a separate legal basis.
The technical providers to whom data may be transferred include, in particular: DigitalOcean (FRA1 region, Frankfurt, EU) – hosting of the Application and the managed database; Mailtrap (Railsware Products Studio LLLC) – sending emails containing the Letter and PDF attachments; Google LLC / Google Ireland Limited (Google Analytics GA4) – analysis of Application usage statistics.
Data retention period
Answers given in the Form and the content of the Letter will be stored for the period necessary to generate and deliver the Letter, and then for 1825 days in order to allow for handling technical issues and complaints.
After the indicated period has elapsed, the content of the Form and the Letter will be deleted or anonymized, unless:
- the User has expressly requested longer storage;
- further storage is necessary to establish, pursue, or defend specific legal claims;
- an obligation to retain the data arises from the law.
Data related to a Consultation will be stored for the time needed to carry it out, and then for the period necessary to demonstrate how the contact took place and to defend against claims.
Data related to the preparation of an Offer will be stored until the end of the offer process, and then for a period corresponding to the limitation period for any potential claims, if there is a justified need to retain it.
Data used for marketing purposes will be processed until consent is withdrawn, the relevant marketing activities are discontinued, or the data is found to be out of date.
Information about the giving and withdrawal of consent may be stored for longer than the data used for marketing, if this is needed to demonstrate that the Controller's actions complied with the law.
Technical data and system logs will be stored for 5 years, unless a specific security event justifies retaining them for longer.
Voluntariness of providing data
Providing data marked as mandatory is voluntary, but necessary to conclude and perform the contract for generating the Letter.
Not providing an email address will make it impossible to deliver the Letter, if email is the only planned delivery channel.
Providing information for a Consultation or the preparation of an Offer is voluntary, but its absence may prevent the Controller from providing a response tailored to the User's needs.
Giving marketing consent is voluntary. Refusing to give it, or later withdrawing it, does not affect the ability to generate the Letter or to use the other features of the Application.
Rights of data subjects
A person whose data is processed has the right to request access to the data and to receive a copy of it.
If the data is incorrect or incomplete, the person may request that it be rectified or completed.
In the cases set out in the GDPR, the person may request that the data be erased, in particular where it is no longer needed for the purposes for which it was collected, or where consent has been withdrawn and there is no other legal basis for processing.
The person may request restriction of processing if they contest the accuracy of the data, the lawfulness of the processing, or the need for continued storage.
With regard to data processed on the basis of a contract or consent, by automated means, the person may have the right to data portability.
Against processing based on Article 6(1)(f) GDPR, an objection may be raised on grounds relating to the person's particular situation.
Against the processing of data for direct marketing purposes, an objection may be raised at any time, without the need to demonstrate particular reasons. After receiving an objection, the data will no longer be used for such marketing.
Consent given may be withdrawn at any time. Withdrawing consent does not affect the lawfulness of processing carried out before its withdrawal.
Requests may be directed to . The Controller may ask for additional information necessary to confirm the identity of the person making the request.
The data subject has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
Data of other persons indicated by the User
The Form may allow the User to describe persons with whom the User intends to pursue the goal or celebrate its achievement.
The User should limit the provision of other persons' data to the minimum and, where possible, use a description of the relationship or role rather than the person's full name.
Third-party data will not be used by the Controller to contact those persons or to conduct marketing towards them.
This data will be processed only as an element of the content provided by the User and for the purpose of generating the Letter.
Change of controller and business continuity
If the Controller changes the form of conducting business, contributes the business or the Application to a company, sells the Controller's business, or another entity takes over the operation of the Application, data may be transferred to the entity continuing the business, provided the transfer has an appropriate legal basis and is necessary for:
- the continued performance of existing contracts;
- ensuring the continuity of the Application's operation;
- handling Users' complaints and inquiries;
- performing legal obligations;
- establishing, pursuing, or defending legal claims.
Before, or promptly after, the change, Users will be informed of the identity of the new controller, its contact details, the date of the change, the purposes and legal bases for processing, and the rights available to them.
A change of Controller does not mean an automatic expansion of the purposes of processing. The new controller will not be entitled to use the data for purposes inconsistent with the original purpose for which it was collected.
Existing marketing consents may be used by the new entity only where their content, the manner in which the business was taken over, and applicable law allow this. In other cases, the new entity will ask Users to give new consent.
Information about the possibility of a future change of controller does not, by itself, constitute consent to marketing carried out by future entities or by any affiliated or cooperating entities.
Cookies and similar technologies
The Application may use cookies and similar technologies to ensure proper operation, maintain the session, secure the Form, remember settings, and carry out analytics.
Files necessary for the Application to function may be used without additional consent, to the extent permitted by law.
Analytical, preference, or marketing files will be used once the User's consent has been obtained, if consent is required.
The Application uses the following analytical tool:
- Google Analytics (GA4) – provider: Google Ireland Limited; purpose: analysis of Application usage statistics; data retention period: 14 months; data may be transferred to Google LLC (USA) under the EU-U.S. Data Privacy Framework; advertising features (Google Signals) are not used.
Data security
The Controller applies technical and organizational measures appropriate to the nature of the data, the scope of processing, and the likelihood and severity of the risk of a violation of the rights or freedoms of natural persons.
These measures include, in particular, encryption of data in transit, access control, permission management, backups, event logging, software updates, and incident response procedures.
Access to the data is limited to persons who need it to perform their duties and who have been bound to confidentiality.
The Controller periodically assesses the effectiveness of the security measures applied and adapts them to technological changes and changes in how the Application operates.
Changes to this Privacy Policy
This Policy may be updated in connection with changes in the law, changes in how the Application operates, the implementation of new features, a change of providers, or a change of controller.
If a change materially affects how data is processed or Users' rights, the Controller will provide information about the change in a manner appropriate to the nature of the relationship with the User.