Skip to content

Privacy policy

Last updated: 2026-09-27

This policy describes what personal data we collect through the BLIND SPOT website, what for, on what legal basis and how long we keep it. It fulfils the information obligation under Article 13 GDPR.

1. Who the controller is

The controller of your personal data is Innovatika sp. z o.o., ul. Emilii Plater 53/1447, 00-113 Warsaw, Poland, VAT ID 9512129612, company number (KRS) 0000224718.

For any matter concerning personal data you can write to welcome@innovatika.com or to the registered address. We have not appointed a data protection officer, as we are not required to under Article 37 GDPR.

2. What this policy covers

This policy covers the blindspotscore.com website: browsing it, reading articles and sending the contact form.

The BLIND SPOT diagnosis itself is delivered to companies under a separate contract. That contract sets out confidentiality and how information is processed during the diagnosis.

3. What data we collect

This website collects personal data in one place only: the contact form. These are the details you give us yourself so that we can reply:

  • company name
  • name of the contact person
  • email address
  • phone number, if you provide one (the field is optional)
  • product, line or category, if you provide it (optional)
  • the content of your message
  • the form language and the date of the enquiry

4. Visit statistics

To know which pages and articles are read, we use Cloudflare Web Analytics. It stores no cookies or other identifiers in your browser, does not track visitors across websites and does not build profiles of them.

We see aggregate numbers only: page views, visited addresses, referring sources, country, and device and browser type. The legal basis is our legitimate interest in assessing whether the website is useful (Article 6(1)(f) GDPR).

5. What we do not collect

We do not store the IP address of the person sending the form, nor their browser headers. Abuse protection runs on counters held in server memory, and the address is turned into an irreversible hash with a random key created at application start-up, so it is never stored permanently.

We do not collect data on health, origin, opinions or any other special category data under Article 9 GDPR.

6. What for and on what basis

We process the data from the form in order to answer your enquiry, arrange a conversation and present an offer. The legal basis is steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).

We also process it in our legitimate interest (Article 6(1)(f) GDPR), namely conducting correspondence and establishing, pursuing or defending against claims.

Providing the data is voluntary, but without an email address we have no way to reply. Before you send the form, we ask you to confirm that you have read this policy and to accept the website terms of use.

7. Who processes data on our behalf

We use providers who process data on our instructions, under data processing agreements:

  • Railway Corp. - application hosting and database. Data is processed in a European region
  • Cloudflare, Inc. - domain handling, traffic protection and visit statistics
  • Functional Software, Inc. (Sentry) - application error monitoring. Events are scrubbed before they are sent and never contain the content of the form

8. Transfers outside the European Economic Area

The application and the database run in a European region. The remaining providers, supporting domain handling, statistics and error monitoring, may also process data outside the European Economic Area. Where that happens, the transfer is based on standard contractual clauses approved by the European Commission.

9. How long we keep it

We keep enquiries from the form for 24 months from the last contact on the matter, and then delete them.

If an enquiry leads to a contract, data related to its performance is kept for the period required by tax law and for the limitation period for claims.

10. Your rights

In relation to your data you have the right to:

  • access your data and receive a copy of it
  • have inaccurate data corrected
  • have your data erased
  • restrict processing
  • data portability
  • object to processing based on legitimate interest
  • lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland

11. Cookies

The website stores no cookies in visitors’ browsers: no analytics, marketing or technical cookies. That is why we do not ask for cookie consent.

A session cookie appears only after signing in to the panel used by the Innovatika team.

12. Security

The site is served over an encrypted connection with a strict content security policy. Enquiries from the form are accessible only to Innovatika team members after signing in. Database backups are encrypted.

13. Automated decisions

We do not take decisions about you based solely on automated processing, including profiling, that would produce legal effects.