Privacy Policy
Last updated: August 19, 2026
1. Who is the controller of your personal data?
The controller of your personal data is Tomasz Miszkin, conducting business under the name Tomasz Miszkin Services, NIP 9182127046, REGON 529783509, registered address: ul. Kościelna 59F/23, 05-135 Wieliszew, Poland.
Syncrvm is the brand under which Tomasz Miszkin Services provides its services.
Whenever this Privacy Policy refers to “Syncrvm”, “we”, “us” or “our”, it refers to the controller identified above.
2. How can you contact us about privacy?
For questions regarding personal data, privacy or the exercise of your data protection rights, contact us at:
We have not appointed a Data Protection Officer. Privacy-related matters are handled directly by the controller.
3. What personal data may we process?
The categories of personal data we process depend on how you interact with Syncrvm.
They may include:
your first and last name;
email address;
company name and professional role;
information you provide through our contact form;
information relating to meetings you book with us;
email addresses of guests you choose to invite to a meeting;
information contained in correspondence and other communications with us;
information relating to a potential or existing business relationship;
information stored in our CRM, such as relationship status, communication history and the date of the last meaningful business interaction;
your communication and marketing preferences;
information concerning consent and privacy choices;
technical information relating to your use of our website, such as IP address, browser and device information, referring source, pages visited and online identifiers;
information required for contracts, invoicing, accounting and legal compliance where you become a client.
We do not ask you to provide special categories of personal data through our website.
4. Where do we obtain your personal data?
In most cases, we receive personal data directly from you.
This happens, for example, when you submit our contact form, book a meeting, send us an email, communicate with us or enter into a business relationship with Syncrvm.
Certain technical information is collected automatically when you use our website. Some of this information is necessary to deliver, secure and maintain the website. Other analytics and advertising information is collected or accessed according to the privacy choices you make through our cookie consent mechanism.
If you add another person as a guest to a meeting, we may receive that person's email address from you.
5. Why do we process your personal data and what is the legal basis?
The GDPR permits personal data to be processed on several distinct legal grounds, including consent, steps taken before entering into a contract, performance of a contract, compliance with legal obligations and legitimate interests.
Website operation and security
We process technical information necessary to deliver, maintain and secure our website, including information generated when your browser connects to our website infrastructure and technical resources used by the website. The legal basis is our legitimate interest in operating a reliable and secure website, pursuant to Article 6(1)(f) GDPR.
Contact form
When you submit our contact form, we process the information you provide in order to receive, review and respond to your inquiry.
Where the form presents a notice stating that submission constitutes consent to storage and processing, the legal basis for this processing is your consent under Article 6(1)(a) GDPR.
We also ask separately for permission to send one-to-one communications in response to your inquiry.
If your inquiry concerns taking steps at your request before entering into a contract, further processing necessary for those steps may be based on Article 6(1)(b) GDPR.
Booking and managing meetings
When you book a meeting with Syncrvm, we process the information you provide in order to schedule, organise and manage the meeting and to communicate with you about matters directly related to that meeting.
The legal basis is our legitimate interest in handling user-initiated business enquiries and managing prospective business relationships, pursuant to Article 6(1)(f) GDPR.
Where the meeting leads to specific steps requested by you before entering into a contract, the legal basis for those subsequent steps may be Article 6(1)(b) GDPR.
Managing prospective client relationships
We may store relevant information about prospective business relationships in our CRM in order to maintain business context, keep track of previous meaningful interactions and manage potential cooperation.
The legal basis is our legitimate interest in organising and managing B2B relationships, pursuant to Article 6(1)(f) GDPR.
Providing services and managing client relationships
Where you become a client, we process personal data necessary to provide our services, communicate regarding the engagement and perform our contractual obligations.
The legal basis is Article 6(1)(b) GDPR.
Where you act on behalf of a company or another organisation that is our client, processing may instead be based on our legitimate interest in communicating with representatives and personnel of our business partners under Article 6(1)(f) GDPR.
Marketing communications
If you choose the optional Marketing Information subscription, we may send you emails concerning Syncrvm services, insights, resources and updates.
Marketing communications are sent only where the required consent has been obtained.
The legal basis for processing personal data for this purpose is Article 6(1)(a) GDPR. Electronic direct marketing is additionally subject to the consent requirements of Article 398 of the Polish Electronic Communications Law (Prawo komunikacji elektronicznej).
You can withdraw your marketing consent at any time.
Website analytics
With your consent, we use analytics technologies to understand how visitors use our website, evaluate website performance and improve our content and services.
The legal basis for processing personal data for analytics is Article 6(1)(a) GDPR.
Where analytics technologies store information on or access information from your device, we also rely on your consent under Article 399 of the Polish Electronic Communications Law.
Advertising and campaign measurement
With your consent, we use advertising technologies to measure campaign effectiveness, attribute conversions and support advertising activities.
The legal basis for processing is Article 6(1)(a) GDPR, together with the applicable consent requirements for accessing or storing information on your device.
Accounting and legal obligations
Where required, we process personal data for accounting, tax and other legal compliance purposes.
The legal basis is Article 6(1)(c) GDPR.
Establishing, exercising or defending legal claims
We may retain and process information where necessary to establish, pursue or defend legal claims.
The legal basis is our legitimate interest in protecting our legal rights under Article 6(1)(f) GDPR.
Data protection compliance
We process personal data where necessary to respond to requests relating to privacy rights and to demonstrate compliance with our obligations as a controller.
The legal basis is Article 6(1)(c) GDPR and, where appropriate, Article 6(1)(f) GDPR.
6. Is providing personal data mandatory?
Providing personal data through the website is generally voluntary.
However, certain information is necessary for us to perform the action you request.
For example, without an email address we cannot respond to an inquiry or send information relating to a booked meeting.
Fields marked as required in our forms must therefore be completed in order to submit the relevant form or complete the booking.
Consent to receive marketing communications is optional and is not required in order to submit an inquiry or use our services.
7. How long do we retain your personal data?
We do not retain personal data for longer than reasonably necessary for the purpose for which it is processed.
Prospective clients
Personal data relating to a prospective client is generally retained for up to 12 months from the last meaningful interaction relating to an active or potential business relationship.
If there has been no meaningful interaction after the data was provided, the retention period may instead be calculated from the date the data was collected.
After that period, the record may be reviewed and deleted unless another legal basis or retention purpose applies.
Active clients
Data required to provide services is retained for the duration of our business relationship.
After the relationship ends, relevant information may continue to be retained for the period necessary to comply with legal obligations or until the expiry of applicable limitation periods for claims.
Accounting and tax records
Records required under accounting or tax law are retained for the periods required by applicable law.
Marketing
Data processed for marketing communications is retained until:
you withdraw your consent;
you unsubscribe;
the relevant purpose ceases to exist; or
we otherwise determine that continued processing is no longer justified.
We may retain limited information documenting the granting or withdrawal of consent where necessary to demonstrate compliance with legal obligations.
Analytics and advertising data
Retention depends on the relevant tool, its configuration, the lifetime of applicable identifiers and your consent choices.
Withdrawing consent stops future consent-dependent processing, including the use of optional cookies and similar identifiers. Certain consent-aware technologies may continue to transmit cookieless signals when consent is denied, as described in Section 12.
8. Who may receive your personal data?
We use third-party service providers to operate our website and business.
Depending on how you interact with Syncrvm, recipients of personal data may include:
Provider / category
Purpose
Framer
Website hosting, delivery and website infrastructure
HubSpot
CRM, contact forms, meeting scheduling, privacy consent management, website tracking and business relationship management
Google Analytics, Google Ads, Consent Mode and Google Fonts
Meta Platforms
Meta Pixel, campaign measurement and advertising
Microsoft
Business email and related Microsoft 365 services
Accounting and tax service providers
Accounting, tax and statutory obligations
Professional advisers
Legal, accounting or other professional advice where necessary
IT and technical service providers
Maintenance, security and operation of systems used by Syncrvm
HubSpot's current DPA governs its processing of customer data and includes mechanisms for international transfers. Framer's current DPA describes Framer acting as a processor for customer data processed in connection with its service.
Providers may act as processors on our behalf, independent controllers or, in certain contexts, joint controllers.
For example, Meta's Business Tools terms provide for joint controllership in relation to certain collection and transmission of personal information through tools such as the Meta Pixel.
9. Do we transfer personal data outside the EEA?
Some of the technology providers we use operate internationally. As a result, personal data may be processed outside the European Economic Area.
Where such transfers occur, they are made using an appropriate transfer mechanism required by applicable data protection law, which may include:
an adequacy decision adopted by the European Commission;
the EU–US Data Privacy Framework where applicable;
Standard Contractual Clauses approved by the European Commission; or
another lawful transfer mechanism.
HubSpot's current DPA states that HubSpot, Inc. participates in the Data Privacy Framework. Google also maintains Data Privacy Framework certification and provides contractual transfer mechanisms for applicable services. Meta states that Meta Platforms, Inc. and relevant US subsidiaries participate in the EU–US Data Privacy Framework.
10. Do we use cookies and similar technologies?
Yes.
Our website uses cookies and similar technologies, including tags, pixels and online identifiers.
Some technologies are necessary to operate the website or privacy management mechanisms. Optional storage, access to information on your device and consent-dependent functionality are controlled according to your privacy choices. Certain consent-aware technologies may still transmit cookieless signals when consent is denied, as described in Section 12.
Under Article 399 of the Polish Electronic Communications Law, storing information on or accessing information already stored on a user's terminal device generally requires prior information and consent, subject to statutory exceptions for technologies necessary to provide a requested service.
During your first visit, our HubSpot privacy banner allows you to:
accept optional technologies;
decline optional technologies; or
manage your choices by category.
You can change these choices later through Cookie Settings available on the website.
11. What cookie categories do we use?
Necessary
These technologies are required for essential website functionality, security and privacy preference management.
They remain active where their use is necessary for the operation of the service.
Analytics
With your consent, analytics technologies help us understand how visitors interact with the website and how the website performs.
This category includes Google Analytics 4 and relevant HubSpot analytics functionality.
Functionality
This category may cover optional technologies used to provide additional website functionality or remember preferences.
Technologies assigned to this category are used according to the choice recorded in our consent mechanism.
Advertisement
With your consent, advertising technologies are used for campaign measurement, advertising attribution and related advertising functionality.
This category includes Google Ads and Meta Pixel.
12. Google Analytics, Google Ads and Consent Mode
We use Google Analytics 4 to analyse use of our website and Google Ads to measure and support advertising activity.
Google tags on the Syncrvm website are configured using Google Consent Mode.
Before you make a choice, the relevant consent states for analytics and advertising storage are set to denied. They are subsequently updated according to the preferences you select in our privacy banner.
Our implementation uses Google's advanced consent mode. Google states that when consent is denied, Google tags may still send cookieless pings, while Analytics cookies are not set, accessed or read in that state.
Such signals may be used by Google for measurement and modelling in accordance with Google's documentation and terms.
13. Meta Pixel
With your consent to advertising technologies, we use the Meta Pixel.
The Pixel helps us measure interactions associated with advertising campaigns and may support attribution, audience measurement and advertising functionality within Meta's services.
The Meta Pixel is not activated by our website before consent to the advertising category has been given.
Meta's Business Tools terms govern the relevant processing and provide for joint controllership for certain stages of data collection and transmission.
14. HubSpot
HubSpot is our primary CRM and privacy-consent platform.
We use HubSpot for purposes including:
contact forms;
meeting booking;
recording privacy and communication preferences;
CRM records;
managing prospective and existing client relationships;
website tracking;
consent banner functionality.
HubSpot may use cookies and other technologies depending on the relevant service and the privacy choices you make.
HubSpot maintains a current Data Processing Agreement and publishes information concerning its sub-processors.
15. Framer
The Syncrvm website is built and hosted using Framer.
Framer processes technical information necessary to deliver and secure the website.
Framer also provides built-in website analytics. According to Framer, its own analytics system does not use cookies and does not generate persistent identifiers.
16. Google Fonts
The privacy banner delivered through HubSpot currently loads the Lato font using Google Fonts.
When the banner is loaded, the browser may request a stylesheet and font files from Google's infrastructure. Google's technical documentation confirms that the Fonts API delivers browser-specific stylesheets and then the browser downloads the relevant font file.
As with ordinary web requests to third-party infrastructure, technical connection information is necessarily transmitted in order for the request to be served.
We do not use Google Fonts for analytics or advertising purposes.
17. Do we use profiling or automated decision-making?
We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
Advertising providers may process information in order to measure campaigns, create or select audiences or personalise advertising where you have consented to advertising technologies.
This does not result in Syncrvm making legally significant automated decisions about you.
18. What rights do you have?
Subject to the requirements and limitations set out in the GDPR, you may have the right to:
access your personal data and obtain a copy;
have inaccurate personal data corrected;
request deletion of your personal data;
request restriction of processing;
receive certain data in a portable format;
object to processing based on legitimate interests;
withdraw consent at any time where processing is based on consent;
object to direct marketing;
lodge a complaint with a supervisory authority.
These rights arise principally from Articles 15–22 GDPR.
Where processing is based on consent, withdrawing consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
Requests concerning your personal data can be sent to:
If you believe that your personal data is being processed unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) in Poland or another competent supervisory authority.
19. How can you manage your privacy?
You can manage optional website technologies directly through the Cookie Settings mechanism available on our website.
Depending on the technology, you may also:
withdraw a marketing subscription through the unsubscribe mechanism included in our communications;
contact us at
privacy@syncrvm.com;delete or block cookies using your browser;
adjust privacy and advertising settings offered by the relevant external platform.
Where supported by our consent-management platform, browser privacy signals may also be taken into account.
20. How do we protect personal data?
We apply organisational and technical measures appropriate to the nature of the information we process and the risks associated with that processing.
These measures include limiting access to systems containing personal data, managing user access, using established technology providers, maintaining privacy preferences and applying internal data-retention rules.
No method of storing or transmitting information can guarantee absolute security.
21. Can this Privacy Policy change?
Yes.
We may update this Privacy Policy, in particular where:
the way Syncrvm operates changes;
we introduce or remove services or technologies;
our providers change;
our data-processing practices change; or
applicable legal requirements change.
The current version of this Privacy Policy will be available at:
syncrvm.com/privacy-policy
The date of the latest update is shown at the beginning of the document.