light gray lines

Privacy Policy

1. About this Privacy Policy

This Privacy Policy explains how Neontri processes personal data in connection with its website, business development, marketing, client and partner relationships, recruitment, and related business activities. It also explains the rights available to individuals under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Polish data-protection law.

This Privacy Policy applies to individuals whose personal data Neontri processes as a controller, including website visitors, people who contact us, business prospects, representatives of clients and partners, newsletter or marketing recipients, job candidates, and other business contacts.

Where Neontri processes personal data solely on behalf of a client as a processor, the client determines the purposes and means of that processing and its own privacy information applies to the data subjects concerned.

2. Who Is the Controller?

The controller of your personal data is Neontri sp. z o.o., with its registered office at Puławska 2, 02-566 Warsaw, Poland, entered in the Register of Entrepreneurs of the National Court Register under KRS No. 0000982018, NIP 5213645858, REGON [CONFIRM]. (“Neontri”, “we”, “us”, or “our”).

You can contact us:

by email: contact@neontri.com

by phone: +48 730 007 717

by post: Puławska 2, 02-566 Warsaw, Poland

3. How We Obtain Personal Data

We may obtain personal data in the following ways:

  • directly from you, for example when you submit a contact form, correspond with us, register for or download content, subscribe to communications, enter into a business relationship with us, or apply for a role;
  • through your employer or another organisation with which you are connected, for example where you act as a client, supplier, partner, or project representative;
  • automatically when you use the Website, through server logs, cookies, and similar technologies, subject to applicable consent requirements;
  • from publicly available professional sources, such as company websites, professional networking platforms, public registers, and other lawful public sources;
  • from business-information, sales-intelligence, or prospecting providers used for B2B business development, including Amplemarket where applicable; and
  • from recruitment agencies, referrals, or professional platforms where you have made your profile available for recruitment purposes.

4. Categories of Personal Data We Process

The categories of personal data we process depend on the context. They may include:

  • identity and contact data, such as name, surname, business email address, telephone number, and postal address;
  • professional data, such as employer, job title, department, professional profile, business responsibilities, and professional experience;
  • business-relationship data, such as correspondence, meeting notes, project information, contractual records, and information about interactions with Neontri;
  • website and device data, such as IP address, browser and device information, cookie identifiers, pages viewed, referring pages, and interaction data;
  • marketing data, such as communication preferences, campaign interactions, and engagement with our emails or content;
  • recruitment data, such as CV information, education, employment history, qualifications, portfolio information, salary expectations where provided, and other information submitted during recruitment;
  • billing and compliance data, where relevant to a business relationship, such as tax identifiers, payment or invoice information, and information required to comply with legal obligations; and
  • any other personal data that you voluntarily provide to us in correspondence or through an applicable service.
  • data serving the purpose of confirming identity, such as first and last name, PESEL number, ID document number, date of birth
  • tax identification data

We do not routinely seek to collect national identification numbers, identity-document numbers, financial-condition information, or special-category personal data through the Website. Where such data are required in a specific legal, contractual, employment, or compliance context, we process them only to the extent necessary and on an appropriate legal basis.

5. Categories of Recipients

The data recipients may include the following categories of entities:

  • Software developers, project managers, analysts, testers, and other specialists cooperating with us and taking independent decisions with regards to the purposes and manners of data processing,
  • Entities authorized on the basis of the applicable law regulations (in particular courts and state bodies),
  • Economic information bureaus,
  • Entities providing:
    – Services in the field of IT and new technology,
    – Payment services,
    – Accounting and financial services,
    – Audit and control services,
    – Recovery services,
    – Printing services,
    – Services consisting of destroying documents,
    – Postal and courier services.

We may share necessary data with our partners and third-party service providers, including IBM, to facilitate and improve our services. These entities are obligated to respect the confidentiality of your personal data and process it in accordance with GDPR and other applicable data protection laws.

6. How We Use Personal Data: Processing Scenarios

The table below summarizes the main processing scenarios. The retention periods must match Neontri’s approved retention schedule before publication.

ScenarioPurpose and typical data
Website access and securityOperate, secure, troubleshoot, and maintain the Website. Typical data: IP address, device/browser data, server logs, security events.
Contact forms and enquiriesRespond to enquiries, arrange meetings, assess requests, and follow up. Typical data: name, business contact details, company, role, message content.
Client and partner relationshipsManage contracts, projects, delivery, governance, billing, support, and communications with client/partner representatives.
B2B sales and outbound prospectingIdentify relevant organisations and professional contacts, initiate business conversations, maintain prospect records, and manage sales activity. Typical data: name, role, employer, business contact details, professional profile, interaction history.
Marketing communicationsSend newsletters, event information, service updates, or other marketing where permitted. Typical data: name, email, company, preferences, engagement data.
Analytics and non-essential cookiesUnderstand Website use, measure performance, and improve user experience. Typical data: cookie identifiers, IP/device data, page and interaction data.
Downloadable content and gated resourcesProvide requested e-books, reports, guides, case studies, or other resources and, where permitted, manage related follow-up.
RecruitmentAssess applications, communicate with candidates, conduct interviews, verify qualifications, and take recruitment decisions. Typical data: identity/contact data, CV, education, employment history, qualifications, portfolio and information provided during recruitment.
Legal, compliance, and claimsComply with legal obligations, maintain records, establish or defend legal claims, respond to lawful authorities, and prevent fraud or misuse.

7. Legitimate Interests

Where we rely on Article 6(1)(f) GDPR, we assess whether our legitimate interest is necessary for the relevant purpose and whether your interests, rights, or freedoms override that interest. Depending on the scenario, our legitimate interests may include:

  • responding to and managing business enquiries;
  • developing and maintaining relationships with clients, partners, suppliers, and professional contacts;
  • promoting and developing Neontri’s services;
  • operating, securing, and improving the Website and our IT environment;
  • preventing fraud, misuse, and security incidents;
  • maintaining appropriate business records; and
  • establishing, exercising, or defending legal claims.

You have the right to object to processing based on legitimate interests in the circumstances described in Section 14 below. Where your personal data is processed for direct marketing, you may object at any time and we will stop processing the data for that purpose.

8. B2B Prospecting and Data Obtained from Other Sources

In the course of B2B business development, we may identify professional contacts whose roles appear relevant to Neontri’s services. In these cases, we may obtain professional data from public professional sources, company websites, business databases, professional networking platforms, referrals, or sales-intelligence providers, including Amplemarket where applicable.

The categories of data may include your name, employer, professional role, business email address or telephone number, professional profile information, and information about previous interactions with Neontri.

We use this information to identify relevant organisations and contacts, initiate business discussions, maintain B2B prospect records, and manage sales activity. We generally rely on Article 6(1)(f) GDPR for this processing, based on our legitimate interest in developing and promoting our services. Any electronic marketing communication is also subject to applicable rules governing unsolicited electronic communications.

Where Article 14 GDPR applies, we provide the required privacy information within the applicable time limit, including no later than the first communication with you where required, unless a lawful exemption applies.

9. Cookies, Analytics, and Similar Technologies

The Website uses cookies and similar technologies. Strictly necessary technologies may be used where required for the operation or security of the Website. Analytics, advertising, personalization, or other non-essential technologies are used only where permitted by applicable law and, where required, after obtaining your consent through the Website’s consent-management mechanism.

Depending on the current Website configuration, providers may include Google Analytics, HubSpot, Hotjar, Zapier, and Microsoft Clarity.

You can manage or withdraw cookie consent through the Website’s Cookie Settings. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Detailed information about individual cookies, providers, purposes, and lifetimes should be maintained in the Cookie Policy or consent-management interface.

10. Recipients and Service Providers

We disclose personal data only where necessary for the purposes described in this Privacy Policy. Depending on the context, recipients may include:

  • IT, cloud, hosting, cybersecurity, and technical-support providers;
  • CRM, marketing, analytics, website-experience, and communications providers;
  • automation and integration providers, such as Zapier where used;
  • sales-intelligence and prospecting providers, such as Amplemarket where used;
  • professional advisers, including legal, tax, accounting, audit, and insurance advisers;
  • payment, banking, postal, courier, or document-management providers where relevant;
  • recruitment platforms, agencies, and interview or assessment providers where relevant;
  • clients, partners, subcontractors, or specialists where disclosure is necessary for a defined business purpose and an appropriate data-protection role and contractual framework is in place; and
  • courts, regulators, law-enforcement bodies, and other public authorities where disclosure is required or permitted by law.

Some recipients act as processors on our documented instructions, while others may act as independent controllers where they determine their own purposes and means of processing. We assess these roles based on the actual processing relationship rather than treating all external recipients in the same way.

11. International Transfers

Some of our service providers may process personal data outside the European Economic Area (“EEA”).

Where personal data are transferred to a country for which the European Commission has adopted an adequacy decision, we may rely on that decision. Where no adequacy decision applies, we use an appropriate transfer mechanism under Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where required.

You may contact us to request additional information about the transfer mechanism applicable to your personal data and, where required by law, a copy of the relevant safeguards, subject to appropriate redactions for confidential information.

12. Security

We apply appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. The measures used depend on the nature of the processing, the available technology, implementation costs, and the risks to individuals.

No system or transmission method can be guaranteed to be completely secure. Where a personal-data breach occurs, we assess it and comply with applicable notification and communication requirements under GDPR.

13. How Long We Keep Personal Data

We retain personal data only for as long as necessary for the purpose for which it was collected, taking into account applicable legal obligations, contractual requirements, security needs, and limitation periods for potential claims.

Where no fixed period applies, we use criteria such as the duration of the business relationship, the date of the last meaningful interaction, the status of a request or recruitment process, statutory record-keeping obligations, and applicable limitation periods.

When personal data are no longer required, we delete or anonymize them unless further retention is required or permitted by law.

14. Automated Decision-Making and Profiling

We may use analytics, CRM, marketing, or sales tools to segment contacts, measure engagement, prioritize business follow-up, or understand Website usage. Such activities do not, by themselves, mean that decisions with legal or similarly significant effects are made solely by automated means.

15. Your Data Protection Rights

Subject to the conditions and limitations set out in GDPR, you may have the following rights:

  • Access: to obtain confirmation whether we process your personal data and receive a copy and related information;
  • Rectification: to have inaccurate personal data corrected and incomplete data completed;
  • Erasure: to request deletion of personal data in the circumstances provided by law;
  • Restriction: to request restriction of processing in the circumstances provided by law;
  • Data portability: to receive certain personal data you provided to us in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller where the legal conditions are met;
  • Objection: to object, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f) GDPR;
  • Direct marketing objection: to object at any time to processing of your personal data for direct marketing, including profiling related to such marketing. If you object, we will stop processing your personal data for that purpose;
  • Withdraw consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal; and
  • Complaint: to lodge a complaint with a competent supervisory authority if you believe that your personal data have been processed unlawfully.

For Neontri as a Polish controller, the competent supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – UODO).

16. How to Exercise Your Rights

You may exercise your rights by contacting us at contact@neontri.com or using the contact details in Section 2.

We may request information reasonably necessary to verify your identity before responding to a request. We will respond within the time limits required by GDPR. In certain circumstances, GDPR permits us to extend the response period or refuse a request; where applicable, we will explain the reason and inform you of the available remedies.

17. Is Providing Personal Data Required?

Whether providing personal data is required depends on the context:

  • information requested in a contact form is generally voluntary, but without certain contact details we may be unable to respond;
  • certain data may be necessary to enter into or perform a contract, manage a business relationship, or satisfy legal obligations;
  • information required by employment law may be necessary for a recruitment process, while additional information may be voluntary; and
  • consent to non-essential cookies or marketing is voluntary and may be refused or withdrawn without affecting access to services that do not depend on that consent.

18. Recruitment

If you apply for a role with Neontri, we process the information needed to evaluate your application, communicate with you, conduct interviews or assessments, verify information where appropriate, and make recruitment decisions.

The categories of data may include your name and contact details, CV, education, qualifications, professional history, portfolio or work samples, information from interviews, and other information you choose to provide. Where we need additional information because of legal requirements or the nature of a specific role, we will provide further information at the relevant stage.

If we wish to retain your application for future recruitment beyond the current process, we will do so only where an appropriate legal basis exists and will communicate the relevant retention period.

19. Children

The Website and Neontri’s professional services are directed primarily to businesses and professionals and are not intended for children. If we become aware that personal data relating to a child has been submitted to us without an appropriate legal basis, we will take appropriate steps in accordance with applicable law.

20. Corporate Transactions

If Neontri undergoes a merger, restructuring, acquisition, corporate transformation, financing, or transfer of all or part of its business or assets, personal data may be disclosed or transferred where necessary for that transaction and permitted by applicable law. We will continue to protect personal data and provide any additional information required by GDPR where the controller or purposes of processing materially change.

21. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in law, our processing activities, the Website, or the services and technologies we use. The current version will be published on the Website with its effective date.

Where a change materially affects the way we process personal data, we will provide additional notice where required by applicable law.

22. Contact

Neontri sp. z o.o.
Puławska 2
02-566 Warsaw
Poland

Email: contact@neontri.com

Phone: +48 730 007 717

Effective date: 27.11.2025

Updated: 03.09.2026