UR UnaidedRecall ← Back to site

Privacy

Last updated 26 August 2026

In short I collect only what you type into a form on this site, and only to do the thing you asked for. Nothing is sold, rented, or added to a list you did not ask to be on. There are no advertising or analytics trackers on any page. If you want your details deleted, email me and they are gone.

Who is responsible

The data controller is Mateusz Filochowski, acting as a sole trader in Warsaw, Poland, trading as UnaidedRecall. Contact: mateusz@unaidedrecall.com. That address is read and answered personally, not by a shared support desk.

Postal address for formal requests: [virtual office address, Warsaw].

The business is not yet entered in the Polish business register, so there is no NIP or REGON to quote. When that changes, the details appear here and the date at the top changes with them.

There is no data protection officer. At this scale the law does not require one — the processing here is neither large-scale monitoring nor special-category data.

If you filled in a form on this site

Only what the form asks for, and only once you choose to send it.

NameSo a reply is addressed to a person rather than an inbox.
Work emailTo send back what you asked for. It is the only address used, and it is not added to a mailing list.
Company name and websiteTo identify the company being measured.
Your category, competitors and buyer rolesTo build the buying questions the measurement is run against. These describe a market, not a person.
Anything you type in a free-text boxWhatever you decide to tell me. Please do not put confidential or personal details there that the work does not need.

The lawful basis is Article 6(1)(b) of the GDPR — taking steps at your request before entering into a contract. Where a particular enquiry falls outside that, the basis is legitimate interest under Article 6(1)(f): you asked for an analysis of your own company, and the data is used for nothing else.

The fields marked required are required because the work cannot be produced without them. There is no obligation to submit the form at all, and not submitting it has no consequence beyond not receiving the analysis.

No account is created and no password is stored. Card and bank details are never seen or held by me — where a payment is taken online it is handled end to end by [payment provider], who receive that data directly and are responsible for it.

If I contacted you first

Part of how this business finds clients is direct email to named people at companies that fit what it does. If that is how you arrived here, this section is the one that applies to you, and you are entitled to it under Article 14 of the GDPR.

  • What is held — your name, job title, work email address, and the company you work for. Nothing about you personally beyond your professional role.
  • Where it came from — a commercial business-contact database (Apollo.io), your employer's public website, and your public professional profiles. It was not bought from a list broker and it did not come from anyone you gave it to in confidence.
  • Why — to make a single relevant business approach about a service your role would plausibly evaluate. The lawful basis is legitimate interest under Article 6(1)(f). The balance is that the contact is professional rather than personal, it concerns your work, and it stops the moment you say so.
  • How long — deleted within 12 months of the last contact if there is no reply, immediately on request, and permanently suppressed if you ask not to be contacted again.

You can object at any time, and objection is absolute. Reply with "remove" — one word is enough — or email the address above. No reason is needed, nothing further will be sent, and your details are removed rather than merely flagged.

Who else sees it

Running the site and producing the work involves third-party services. Each one gets only what it needs to do its job, and each one that handles data on my behalf is covered by a data processing agreement. Apollo.io is the exception and is named as such below: it runs its own business-contact database as an independent controller, not as my processor.

  • Email — Google Workspace (Google Ireland Ltd / Google LLC). Handles the mailbox, so it processes anything you send or that is sent to you.
  • Form handling — Formspree (Formspree, Inc., United States). Receives what you type into a form and passes it to the mailbox. Data is encrypted at rest and the service is SOC 2 Type II audited.
  • Hosting — Cloudflare, which serves the site and processes standard server logs, including your IP address, for security and to keep the site online.
  • Payments[payment provider], where an engagement is paid online. They receive your payment details directly; I never see them.
  • Business research — Apollo.io, an independent controller of its own business-contact database, used to research companies and their publicly listed contacts for outreach, as described in the section above. Data you submit through a form on this site is not sent to Apollo.
  • AI assistants — the buying questions are put to commercial generative models from OpenAI, Anthropic, Google and Perplexity. Those questions are about your category and your company. Your name, your email address and anything personal are never placed in a prompt.

Your details are not sold, rented, shared for anyone else's marketing, or added to any list you did not ask to be on. Nobody is paid for access to them.

Where it is processed

The business is operated from Warsaw, Poland, inside the European Economic Area.

Several of the providers above are based in the United States, so some of your data is transferred outside the EEA. Those transfers rest on the European Commission's adequacy decision for the EU–US Data Privacy Framework where the provider is certified under it, and on the Commission's standard contractual clauses where it is not. Formspree, which handles the forms, relies on standard contractual clauses. You can ask for a copy of the safeguard relied on for any named provider.

If the place this business is operated from changes, this section changes with it before the move, not after.

How long it is kept

  • Enquiries that go nowhere: deleted after 24 months.
  • Outreach contacts who do not reply: deleted after 12 months.
  • Enquiries that become clients: kept for the life of the engagement, then for as long as Polish tax and accounting law requires the records to be retained — currently five years from the end of the tax year in which the invoice was issued.
  • Deletion on request: acted on within 30 days and usually far sooner, except for records the law requires to be kept.

Cookies, and what this site puts on your device

Every page loads entirely from this site's own server. Typefaces are served from here rather than from Google Fonts, so no third party is told your IP address just because you opened a page.

This site sets no cookies of its own. There are no advertising pixels, no analytics, no session tracking, and nothing from a social network. Cloudflare may set one strictly necessary cookie (__cf_bm) to tell real visitors apart from bots; it carries nothing that identifies you to me and cannot follow you to other sites.

One thing is stored locally in your browser: if you switch the site between light and dark mode, that choice is saved on your own device so the next page keeps it. It never leaves your browser, it identifies nobody, and clearing your browser data removes it.

How it is kept secure

  • The site is served over HTTPS, so anything you submit is encrypted in transit.
  • The domain registrar account, the mailbox and every service listed above have two-factor authentication enabled.
  • Client material and enquiry data are held in the mailbox and in encrypted storage, accessible only to me. Nothing is kept on a shared or public drive.
  • No card or bank details are stored anywhere in this business. Online payments are handled entirely by the payment provider named above; invoices are paid to a bank account. Either way the money moves between your bank and mine, not through this site.
  • Access is reviewed whenever a provider changes, and old data is deleted on the schedule above rather than kept indefinitely "just in case".

If a breach occurs that is likely to put your rights at risk, I will report it to UODO within 72 hours of becoming aware of it, and tell you directly and without delay where the risk to you is high. This is a commitment, not just a legal requirement.

No automated decisions

Nothing here profiles you or makes an automated decision that produces a legal or similarly significant effect. The AI assistants are the subject of the measurement, not a tool used to make decisions about you. Every judgement in every report is made by a person.

Your rights

Under the GDPR you can ask for a copy of what is held about you, ask for it to be corrected or erased, ask for processing to be restricted, object to it, and ask to receive it in a portable format. Where processing rests on legitimate interest — including all outreach — you can object and it stops.

Email the address above. No particular form of words is needed, there is no charge, and you will get an answer within one month.

If that answer is unsatisfactory you can complain to the Polish supervisory authority, the Urząd Ochrony Danych Osobowych (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl), or to the authority in your own country.

Changes

If this policy changes materially, the date at the top changes with it. Anyone who has submitted a form and is still within the retention period will be told by email.