Back to websiteData protection
Privacy Policy
This policy explains how personal data is handled in connection with this website, email correspondence and the internal Amazon Ads API integration.
Last updated: 23 July 2026
1. Data controller
The controller of personal data is Krzysztof Chmiołek, an independent sole proprietor based in Kraków, Poland, NIP 6762432669, REGON 380303430.
Privacy enquiries and requests can be sent to contact.sovinus@gmail.com.
2. Website visitors
The website does not include a contact form and the controller does not use advertising or analytics cookies. Hosting and infrastructure providers may process limited technical data needed to deliver and secure the website, such as an IP address, browser and device information, request time and security logs.
This processing is based on the controller's legitimate interest in providing a secure and reliable website under Article 6(1)(f) of the GDPR.
3. Email correspondence
When a person contacts the controller by email, the sender's email address, name and message content are processed to respond, maintain business correspondence and, where applicable, take steps requested before entering into a contract.
Data is retained only for as long as required for the conversation, business records or the establishment, exercise or defence of legal claims.
4. Amazon Ads API data
The Amazon Ads API integration is intended for the controller's internal use as a direct advertiser. It is used only for advertising accounts owned or administered by the controller and is not offered or licensed to third parties.
Data that may be processed
- Amazon advertising profile and account identifiers;
- campaign settings, budgets, bids, targeting and performance reports;
- authorization tokens and technical information required to authenticate API requests;
- operational logs needed for security, troubleshooting and reliability.
Purposes
The data is used for internal advertising reporting, campaign analysis, campaign management, optimisation, security and troubleshooting. Access is limited to permissions needed for these purposes.
5. Recipients and transfers
Personal data is not sold. It may be processed only by service providers needed to operate the website, email, hosting, infrastructure and Amazon API integration, as well as by Amazon in accordance with its own terms and privacy information.
Where a provider processes data outside the European Economic Area, the transfer is handled using an applicable legal mechanism and safeguards required by data protection law.
6. Retention and security
Data is retained for no longer than necessary for the purpose for which it was collected, subject to applicable legal obligations and Amazon requirements. Authorization tokens are retained only while access remains required and may be revoked.
Appropriate organisational and technical measures are used to restrict access and protect data against unauthorised access, alteration, loss or disclosure.
7. Individual rights
Depending on the circumstances, a person may request access, rectification, erasure, restriction of processing, data portability or object to processing based on legitimate interests. Requests can be submitted using the email address above.
A person also has the right to lodge a complaint with the competent supervisory authority. In Poland, this is the President of the Personal Data Protection Office.
8. Automated decisions and updates
Personal data covered by this policy is not used to make decisions producing legal or similarly significant effects solely by automated means.
This policy may be updated when the website, API integration or legal requirements change. The current version and update date will remain available on this page.