Privacy Policy
Last updated: 9 August 2026
Contents
1. Data controller
The controller responsible for the processing of personal data on this website within the meaning of the General Data Protection Regulation (GDPR) and the Polish Act on the Protection of Personal Data is:
Baltic Compliance Partners sp. z o.o.
ul. Grunwaldzka 472, 80-309 Gdańsk, Poland
KRS: 0000912345 · NIP: 5842123456
Email: privacy@balticcompliance.eu · Phone: +48 58 301 24 70
2. Scope of this policy
This Privacy Policy explains how we collect, use, store and protect personal data when you visit this website, submit an enquiry through our contact form, or otherwise interact with us in connection with our audit and controlling services. It does not apply to the internal processing of personal data collected during an on-site audit at a client's premises, which is governed separately by the relevant audit engagement agreement.
3. What data we process and why
| Purpose | Data categories | Source |
|---|---|---|
| Responding to enquiries submitted via the contact form | Name, company, email address, phone number, message content | Provided directly by you |
| Operating and securing the website | Technical data strictly necessary for the site to function (e.g. language preference) | Collected automatically, technically necessary |
| Optional usage statistics (only with consent) | Aggregated, anonymised usage information | Collected only after explicit consent via the cookie banner |
4. Legal basis for processing
We process personal data on the following legal bases under Article 6(1) GDPR:
- Consent (Art. 6(1)(a)): for optional cookies and for the processing of contact-form data where consent is required.
- Contract or pre-contractual measures (Art. 6(1)(b)): where your enquiry relates to a potential or existing audit engagement.
- Legitimate interest (Art. 6(1)(f)): for the secure and functional operation of this website.
5. Recipients of your data
Personal data submitted through this website is accessible only to authorised personnel of Baltic Compliance Partners and to carefully selected technical service providers who process data on our behalf under a data processing agreement (e.g. hosting and infrastructure providers). We do not sell personal data and do not share it with third parties for their own marketing purposes.
6. International data transfers
Where data is processed by service providers located outside the European Economic Area, we ensure an adequate level of protection through appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission.
7. Retention periods
Contact-form enquiries are retained for as long as necessary to process your request and for a reasonable period thereafter to handle any follow-up communication, and are then deleted or anonymised, unless a longer retention period is required by law (e.g. accounting or engagement-related documentation).
8. Your rights
Under the GDPR, you have the right to: access the personal data we hold about you; request rectification or erasure; request restriction of processing; object to processing; request data portability; and withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), or with the supervisory authority of your habitual residence or place of alleged infringement.
9. Cookies and similar technologies
This website uses cookies. Strictly necessary cookies are used without prior consent, as permitted by law. All other categories of cookies are loaded only after you have given explicit, granular consent via the cookie banner. Details are provided in our separate Cookie Information page, where you can also review and change your consent at any time.
10. Data security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, proportionate to the risk associated with the processing activity.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect legal, technical or organisational changes. The current version is always available on this page, with the date of the last update shown above.
12. Contact regarding data protection
For any questions regarding this Privacy Policy or the processing of your personal data, please contact us at privacy@balticcompliance.eu.