Our approach
The controller of data on lubisoftware.com is LuBi-Software Łukasz Biedak (NIP 767-165-43-47). We take data protection seriously — both for website contact and client projects. We apply minimisation: we collect only what is needed to answer inquiries and perform contracts, plus technical and organisational measures appropriate to risk (GDPR Art. 32).
This document describes practices for the company website and contact inbox. Detailed security of systems delivered to clients is set out in a separate agreement / project scope.
Technical measures (site and contact)
- Transport encryption (HTTPS / TLS) — browser traffic is encrypted.
- Contact form protection — honeypot, signed time-limited token, per-IP rate limits, simple content filters; messages go to the controller’s Gmail (SMTP), not published publicly.
- Restricted config access — secret files (e.g. API config) are not served publicly; secrets are not committed to the repository.
- MIKR.US hosting — the site runs on hosting in Poland / EU; we keep a reasonable level of updates and web server rules.
- Analytics cookies only with consent — Google Analytics does not load without your decision (see Cookie policy).
Organisational measures
- Access to the contact inbox ([email protected]) and form content is limited to the controller — Łukasz Biedak.
- Passwords and secrets are stored securely (e.g. password manager, app passwords for SMTP instead of the main account password when possible).
- We do not share inquiry content with third parties for marketing and do not use an external CRM / newsletter for site leads.
- For client projects we separate environments (e.g. test / production) when the scope requires it, plus separate contractual terms.
Where may data be processed?
- MIKR.US — website hosting and form handling (PL/EU infrastructure),
- Google (Gmail) — controller’s mailbox,
- Google Analytics — only after analytics cookie consent.
We do not currently use other marketing tools or cloud CRMs for website data.
How long do we keep data?
- form inquiries / lead correspondence — up to 6 months after contact ends,
- contract and billing data — up to 5 years (or as required by law),
- security logs — for the time needed to protect systems.
Details: Privacy policy — retention.
Incidents
In case of a personal data breach we act under the GDPR: we assess risk and, where required, notify the supervisory authority and data subjects within legal deadlines.
Suspected incidents related to our site or cooperation: report to [email protected] (subject: “Data security”).
Your role
Security is a shared responsibility. Please:
- do not send passwords or unnecessary sensitive data through the open contact form,
- use an up-to-date browser,
- be careful with messages impersonating us (you can always verify contact details on this site).