J1 OS
ProblemAISolutionFeaturesWho it's forContact
PL Log in Try the app
ProblemAISolutionFeaturesWho it's forContact Log in Polski
← Back to home

Privacy Policy

Last updated: August 4, 2026

This Privacy Policy describes how personal data is processed and how cookies are used in connection with the website available at j1-os.pl (the “Service”).

1. Introduction

The Service is informational and presents the J1-OS application, available at app.j1-os.pl (the “App”), allowing visitors to learn about the product and contact the Controller. This Privacy Policy covers the Service only — use of the App itself is governed by a separate privacy policy made available within the App.

We process personal data in accordance with applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR), the Polish Act of 10 May 2018 on the Protection of Personal Data, and the Polish Act of 18 July 2002 on Providing Services by Electronic Means.

2. Data controller

The controller of personal data processed in connection with the Service is Filip Stasiński, a sole proprietor registered in Poland, tax identification number (NIP): 558-187-48-60 (the “Controller”).

For any matters relating to the protection of personal data, or to exercise your rights, you can contact the Controller at: filip.stasinski@j1-os.pl.

3. Legal basis and purposes of processing

Personal data is processed for the following purposes and on the following legal bases:

  • handling correspondence and responding to inquiries submitted via the contact form — under Article 6(1)(b) GDPR (steps taken at the request of the data subject prior to entering into a contract) and Article 6(1)(f) GDPR (the Controller's legitimate interest);
  • analyzing how the Service is used and measuring traffic and visit statistics — under Article 6(1)(a) GDPR (consent given via the cookie banner), only where you have selected “Accept all”;
  • ensuring the correct and secure operation of the Service, including session recognition and abuse prevention — under Article 6(1)(f) GDPR (the Controller's legitimate interest in the security and stability of the Service);
  • establishing, defending against, and pursuing potential legal claims — under Article 6(1)(f) GDPR;
  • fulfilling legal obligations, including tax and accounting obligations related to running the business — under Article 6(1)(c) GDPR.

4. Scope of data processed

Depending on how you use the Service, the Controller may process the following categories of data:

  • data provided via the contact form: email address and message content (required), plus first name, last name and phone number (optional, if provided);
  • technical and device-identification data: an anonymous correlation identifier stored in a cookie (j1_cid), an IP address irreversibly transformed into a SHA-256 cryptographic hash, browser type and version (user agent), the referring page URL, campaign parameters (UTM), and interface language;
  • activity data within the Service: pages visited, clicks on selected interface elements, and event timestamps — collected only once you have consented to analytics cookies.

5. Cookies and similar technologies

The Service uses cookies (small text files stored on your device) to ensure correct operation and — once you consent — for analytics purposes.

  • j1_cid — a strictly necessary (functional) cookie, stored for up to 12 months. It contains a random, anonymous correlation identifier used to recognize a returning session and link events within the Service. It contains no data that would directly identify you and is inaccessible to browser scripts (HttpOnly attribute);
  • j1_consent — a strictly necessary (functional) cookie, stored for up to 6 months. It records your cookie-consent choice so the consent banner does not reappear on every visit.

Strictly necessary cookies are set regardless of consent, as they serve only to provide the basic functionality of the Service (Article 173(3) of the Polish Telecommunications Law). Analytics cookies — covering page-view and click logging — are set and processed only once you select “Accept all” in the cookie banner. You may change your choice at any time in your browser settings (by deleting or blocking cookies); withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

6. Recipients of data and processors

Personal data may be entrusted for processing to providers that support the Controller in operating the Service, in particular technical infrastructure providers:

  • Netlify, Inc. — hosting of the Service and execution of the server-side functions handling the contact form and analytics mechanisms;
  • Supabase, Inc. (PostgreSQL database) — storage of contact-form data and analytics data.

The Controller has entered into an appropriate data processing agreement with each of the above providers (or relies on equivalent standard data processing terms offered by the provider), ensuring processing in line with the GDPR. The Controller does not transfer personal data to other third parties for marketing purposes and does not sell personal data.

7. Transfers of data outside the European Economic Area

The infrastructure providers listed in section 6 may process data on servers located outside the European Economic Area (e.g. in the United States). In such cases, the transfer relies on mechanisms ensuring an adequate level of protection under the GDPR, in particular the standard contractual clauses approved by the European Commission. The Controller endeavors to work only with providers offering appropriate guarantees of GDPR compliance.

8. Data retention periods

Personal data is retained for the following periods:

  • contact-form data — for as long as necessary to respond to and handle the inquiry, and thereafter for up to 3 years from the last contact, to defend against potential claims, unless you request earlier deletion;
  • analytics data (events, sessions) linked to an anonymous cookie identifier — for up to 12 months from the last activity, after which it is deleted or permanently anonymized;
  • cookies — for the periods indicated in section 5, unless deleted earlier by you;
  • data the Controller is required to retain under law (e.g. tax law) — for the period required by that law.

9. Security of personal data

The Controller applies technical and organizational security measures appropriate to the nature, scope and purpose of processing and to the risk to the rights and freedoms of individuals, in particular:

  • encrypted data transmission — all communication between your device and the Service takes place over an HTTPS/TLS-encrypted connection;
  • data pseudonymization — your IP address is never stored in plain form; before being stored it is irreversibly transformed into a salted SHA-256 cryptographic hash, making it impossible to reconstruct the original IP address;
  • encrypted database connection — communication between the Service and the database requires TLS encryption;
  • data access control — data stored in the database is protected by Row Level Security (RLS); only authorized server-side processes, using dedicated confidential access keys, can access it — public (anonymous) API keys cannot read or write this data;
  • cookie hardening — the j1_cid session cookie carries the HttpOnly and SameSite=Lax attributes, reducing the risk of it being read or exploited by scripts on other websites (XSS/CSRF attacks);
  • data minimization — the Service collects only the data necessary for the stated purposes; the contact form does not require special-category data, financial data, or payment card data, none of which is processed by the Service in any way;
  • restricted internal access — only individuals authorized by the Controller, bound by confidentiality obligations and acting within the scope necessary for their duties, may access personal data;
  • ongoing review and patching — the Controller monitors and updates the technical solutions in use, including software dependencies, to minimize the risk of security vulnerabilities;
  • incident-response procedure — should a personal data breach be detected that is likely to result in a high risk to the rights or freedoms of individuals, the Controller will act in accordance with Articles 33 and 34 GDPR, including notifying the President of the Personal Data Protection Office (UODO) and, where required, informing the affected individuals.

Despite the measures described above, no method of transmitting data over the Internet or of electronic storage is 100% secure. The Controller exercises due diligence in protecting data but cannot guarantee its absolute security.

10. Your rights

In connection with the processing of your personal data, you have the right to:

  • access your personal data (Article 15 GDPR);
  • rectify (correct) your data (Article 16 GDPR);
  • erasure of your data, the so-called “right to be forgotten” (Article 17 GDPR);
  • restrict processing (Article 18 GDPR);
  • data portability (Article 20 GDPR);
  • object to processing based on Article 6(1)(f) GDPR (Article 21 GDPR);
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal, to the extent data is processed on the basis of consent;
  • lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland) — if you believe the processing of your data infringes the GDPR.

To exercise the above rights, contact the Controller at: filip.stasinski@j1-os.pl. Your request will be answered without undue delay, and no later than one month after it is received.

11. Automated decision-making and profiling

The Controller does not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

12. Changes to this Privacy Policy

The Controller reserves the right to amend this Privacy Policy, in particular in connection with changes in law, changes to the functionality of the Service, or changes to data-processing practices. The current version of the Privacy Policy is always available within the Service, together with the date of its last update.

13. Contact

For matters relating to this Privacy Policy and the protection of personal data, you can contact the Controller: Filip Stasiński, NIP: 558-187-48-60, email: filip.stasinski@j1-os.pl.

J1OS

One simple tool to run your entire service business — from first contact to a paid invoice.

Open the app

Product

Problem AI Solution Features Who it's for App

Legal

Privacy policy Terms Contact

© 2026 J1-OS. All rights reserved.

Built for service businesses · Astro · Netlify · Supabase

🍪

We respect your privacy

We use cookies to remember your session and to analyse traffic and improve J1-OS. You can accept all or use only the essential ones.