Skip to content
BLUEOCEAN

Privacy policy

Last updated: 27 August 2026

1. Data controller

The controller of personal data processed in connection with the BLUEOCEAN website is:

BLUEOCEAN Paweł Stapf, ul. Promyk 12/1, 62-070 Dopiewiec, Poland.

For privacy and personal data enquiries: helloblueocean.pl

2. Data we may process

The website may process personal data voluntarily submitted through the contact form, including:

  • name and surname,
  • email address,
  • telephone number, if provided,
  • company name, if provided,
  • message content,
  • any additional information voluntarily included in the enquiry.

Basic technical data necessary for the security and proper operation of the website may also be processed, including IP address, browser and device information, request time and information used to protect the contact form against automated spam.

3. Purposes and legal bases

Personal data may be processed for the following purposes:

handling enquiries and correspondence, based on the Controller's legitimate interest in communicating with people interested in BLUEOCEAN, pursuant to Article 6(1)(f) GDPR;

taking steps at the request of the data subject prior to entering into a contract, where the enquiry concerns potential cooperation, pursuant to Article 6(1)(b) GDPR;

ensuring website security and preventing abuse, based on the Controller's legitimate interest pursuant to Article 6(1)(f) GDPR;

establishing, pursuing or defending legal claims, based on the Controller's legitimate interest pursuant to Article 6(1)(f) GDPR.

Personal data is not used for automated decision-making or advertising profiling.

4. Contact form

Providing data through the contact form is voluntary. However, name, email address and message content are required in order to submit an enquiry and receive a response.

Information submitted through the form is used solely to handle the enquiry, respond to the message and, where relevant, discuss potential cooperation.

The sender's email address may be used as the Reply-To address only after successful server-side validation.

5. Spam and abuse protection

The contact form is protected by technical mechanisms designed to reduce automated spam and abuse.

These may include:

  • server-side validation,
  • honeypot mechanisms,
  • submission timing controls,
  • rate limiting,
  • analysis of repetitive or invalid submissions,
  • Cloudflare Turnstile.

Cloudflare Turnstile is used to distinguish automated traffic from legitimate users and protect the form from bots. BLUEOCEAN does not use this mechanism for advertising or user profiling.

6. Hosting and data recipients

The website is hosted using commercial hosting services provided by dhosting.pl Sp. z o.o.

Personal data may be entrusted to service providers necessary for the operation of the website, including:

  • hosting providers,
  • email service providers,
  • security and anti-spam service providers,
  • technical or administrative service providers where required for website maintenance.

These entities process data only to the extent necessary to provide their services and in accordance with applicable law and contractual obligations.

7. Transfers outside the European Economic Area

Because Cloudflare services may be used to protect the contact form, certain technical data may be processed outside the European Economic Area.

Where this occurs, transfers are carried out using mechanisms permitted under the GDPR and applicable to the relevant processing arrangement.

BLUEOCEAN does not send contact form content to Cloudflare Turnstile.

8. Data retention

Information submitted through the contact form is retained for the period necessary to handle the enquiry and related correspondence.

After communication has ended, data may be retained where reasonably necessary to document the course of correspondence or to establish, pursue or defend potential claims, but no longer than required under applicable law and relevant limitation periods.

Technical security data is retained only for the period necessary to maintain website security, perform diagnostics and prevent abuse.

9. Your rights

Subject to the conditions set out in the GDPR, you may have the right to:

  • access your personal data,
  • rectify inaccurate data,
  • request deletion,
  • request restriction of processing,
  • data portability where applicable,
  • object to processing based on the Controller's legitimate interests.

Requests concerning personal data may be sent to: helloblueocean.pl

The Controller may take reasonable steps to verify the identity of the person making the request before fulfilling it.

10. Right to lodge a complaint

If you believe that your personal data is being processed unlawfully, you have the right to lodge a complaint with the competent supervisory authority.

In Poland, this authority is the President of the Personal Data Protection Office.

Current contact details are available on the official UODO website.

11. Cookies, analytics and advertising

The BLUEOCEAN website currently does not use:

  • Google Analytics,
  • Google Tag Manager,
  • Meta Pixel,
  • LinkedIn Insight Tag,
  • other advertising or analytics technologies intended to track users.

The website does not use personal data for advertising profiling.

Only technical mechanisms necessary for website operation, security and contact form abuse protection may be used.

If analytics, advertising or other technologies requiring user consent are introduced in the future, this Privacy Policy will be updated and an appropriate consent management mechanism will be implemented where required.

12. Data security

The Controller applies appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, disclosure or other unlawful processing.

Security is treated as an integral condition of website design and maintenance, not as a separate stage added after implementation.

13. Changes to this Privacy Policy

This Privacy Policy may be updated if the website functionality, technologies, service providers or applicable legal requirements change.

The current version of the Privacy Policy will always be published on this page.