Privacy Policy
On this page
Last updated: September 15, 2026
This policy explains how United Solutions Sp. z o.o. handles personal data collected through unitedsolutionsltd.com and related business inquiries, newsletter subscriptions, website communications, and independent-contractor applications. It explains the purposes of processing, the applicable safeguards, and how you can exercise your privacy rights.
Who we are and the scope of this policy
United Solutions Sp. z o.o. ("United Solutions," "we," "us," or "our") is the controller for the corporate website activities described in this policy. Our registered address is Aleja 29 Listopada 130, 31-406 Kraków, Poland. Our registration identifiers are KRS 0001148841, REGON 540628111, and NIP 9452304430. For privacy inquiries and requests, contact contact@unitedsolutionsltd.com.
TimeMe, United Solutions Academy, and customer platforms are outside the scope of this corporate website notice. Their applicable privacy notices govern the activities they describe. The Careers section concerns potential independent-contractor engagements.
When we process personal data solely on a customer's behalf, the customer determines the relevant purposes and instructions. Its privacy notice and our applicable data-processing agreement address that activity. We assist the customer with privacy requests as required by the agreement and applicable law. Our responsibilities depend on our actual role; a contractual label does not override data-protection law.
Information we collect and its sources
Information you provide may include your name, business contact details, organization, role, inquiry details, newsletter preferences, chat messages, and other relevant information you submit. Contractor applications may include a CV, professional history, qualifications, portfolio, availability, and application correspondence.
Technical information may include IP addresses, browser and device details, pages visited, timestamps, referral information, security events, and cookie or similar identifiers. The categories collected depend on the website function and your choices. The Cookie Policy (opens in a new tab) and consent controls provide details of the tracking technologies deployed.
We collect information directly from you and through your use of the website. We may receive business contact details or professional information from someone acting for your organization or submitting an authorized referral. Where required, we explain the source, categories, and purposes to the individual within the applicable legal time limits.
Please submit only accurate information relevant to your inquiry or application and information you are lawfully entitled to share. General website forms and chat are not intended for passwords, payment-card details, unnecessary identity documents, health information, criminal-record information, or confidential customer material. Contact us to arrange an appropriate channel where such information is necessary. We may remove, quarantine, or restrict inappropriate submissions, subject to any duty to preserve relevant records. These instructions do not reduce our responsibilities for information we receive.
Purposes and legal bases
For processing governed by the EU General Data Protection Regulation (GDPR), the following purposes and legal bases apply. Other applicable privacy laws may impose additional requirements, including consent requirements. A purpose listed here does not authorize unrelated uses of personal data.
Business inquiries and website communications
We use relevant contact details and correspondence to answer requests, discuss services, prepare proposals, and manage business relationships. Where you personally request steps toward a contract, we rely on Article 6(1)(b) GDPR. When you represent an organization, or contact us for general business purposes, we rely on our legitimate interests in responding and managing relevant business communications under Article 6(1)(f).
Independent contractor applications
We use relevant professional information to assess an application, communicate with the applicant, and take requested steps toward a potential engagement under Article 6(1)(b). Necessary and proportionate administration, verification of relevant professional information, and protection of legal rights may rely on Article 6(1)(f). Optional future-opportunity talent-pool use requires separate consent under Article 6(1)(a). Declining that consent does not affect consideration for the current opportunity.
Newsletters and marketing
Subscribed newsletters rely on consent under Article 6(1)(a), together with permissions required by applicable electronic-marketing law. You can unsubscribe through the message or contact us. An inquiry, application, or acceptance of this policy does not automatically subscribe you. Limited consent and opt-out records may be retained to respect your choices and demonstrate compliance.
Website operation and security
We process necessary technical information to operate and protect the website, prevent abuse, diagnose faults, and maintain service integrity, relying on Article 6(1)(f). Our legitimate interests are providing a functioning website and protecting information, systems, and users. Optional analytics and tracking rely on consent where required; using a custom-built tool does not itself remove consent requirements.
Cloudflare Turnstile
We use Cloudflare Turnstile, provided by Cloudflare, Inc., to protect website forms and other protected functions against automated abuse. It evaluates technical signals, including your IP address, browser information (User-Agent), TLS connection fingerprint, and the website sitekey and associated origin, to distinguish human visitors from bots. We rely on our legitimate interests in protecting the website and its users under Article 6(1)(f) GDPR, subject to necessity, proportionality, and a balancing of rights.
Cloudflare acts as our processor when providing this protection. It also acts as an independent controller when using signals to improve Turnstile’s bot detection, relying on its own legitimate interests as described in its notice. We do not use Turnstile signals for advertising, lead scoring, or sales profiling. Our international-transfer and retention provisions below apply to processing under our control. For Cloudflare’s independent processing and privacy rights, see its Turnstile Privacy Addendum and main Privacy Policy. Contact us if verification prevents you from submitting a legitimate inquiry.
Cloudflare Turnstile Privacy Addendum · Cloudflare Privacy Policy
Legal obligations and protection of rights
We process necessary information to meet applicable legal obligations under Article 6(1)(c), and to establish, exercise, or defend legal claims under Article 6(1)(f). Legitimate-interest processing is subject to necessity and a balance against your interests, rights, and reasonable expectations. You may contact us for information about the relevant assessment.
AI providers and automated processing
Our business uses services from OpenAI and Anthropic. Where personal data is sent to these services, the relevant inputs and generated outputs can be processed by the provider. The use of an AI tool does not create an additional legal basis or authorize processing for a purpose incompatible with the purpose for which the information was collected.
AI output can be incomplete or inaccurate. You may contact us to correct personal information or challenge an assessment involving your information. Uploading a CV or sending a message does not itself amount to consent to unrelated profiling or model training.
Where automated processing produces a decision with legal or similarly significant effects, the restrictions, information duties, and safeguards required by the applicable law apply. Under the EU GDPR, this includes the protection against solely automated significant decisions, subject to the exceptions and safeguards in Article 22. Where applicable, you may obtain human intervention, express your point of view, and contest the decision.
Recipients and permitted disclosures
Information is accessible to authorized personnel and independent contractors who need it for the relevant purpose and are subject to appropriate confidentiality and data-protection obligations. A contractor engagement does not, by itself, grant access to website personal data.
Relevant information may be processed by providers supporting hosting, infrastructure, communications, customer-relationship management, analytics, security, and AI services. Cloudflare receives the Turnstile security signals described above. OpenAI and Anthropic are recipients when personal information is sent to their services. Where a provider acts as our processor, the processing is subject to the required agreement and our instructions. A provider's own privacy notice does not replace our responsibilities for our disclosures or our use of that provider.
We may disclose necessary information to professional advisers, courts, regulators, or competent authorities where legally required or necessary and proportionate to protect legal rights. Where needed for a proposed or completed corporate transaction, limited disclosure may rely on our legitimate interests in evaluating and carrying out the transaction, subject to the required balancing assessment, confidentiality, and safeguards. Any new controller must provide information required by law.
This policy does not give permission to sell personal data or disclose it for unrelated third-party marketing. Any activity that qualifies as a sale, sharing, or targeted advertising under an applicable privacy law remains subject to the specific disclosures and choices that law requires.
Processing locations and international transfers
Our primary website data storage is in Ireland, and ordinary business access takes place in Ireland and Poland. Both countries are in the European Economic Area (EEA). These locations do not establish the location of every processing operation, provider, subprocessor, or remote support team.
Personal data processed by service providers may be transferred to or accessed from other countries, including the United States in connection with Cloudflare services. A restricted transfer requires the lawful mechanism applicable to that transfer. These mechanisms include a relevant adequacy decision or appropriate contractual safeguards, such as the European Commission's Standard Contractual Clauses, with the required assessment and supplementary measures. UK transfer rules apply separately where relevant.
You may contact us for information about the destinations and safeguards applicable to your information, including a copy of relevant safeguards subject to lawful redactions. Overseas authorities may have lawful access under the laws of the receiving country. Reading or accepting this policy does not provide blanket consent to international transfers.
Cookies and similar technologies
Cookies and similar technologies support website functions and, where enabled, optional features or analytics. Strictly necessary technologies may be used without consent where the law permits. Optional technologies that require consent are activated only after an affirmative choice. Browsing, scrolling, or closing a banner does not give consent.
Cookie Settings in the website footer provides access to cookie preferences, including acceptance or rejection of optional technologies and saving selected preferences. You can change your choices or withdraw consent at any time. Rejecting optional tracking does not prevent access to the general corporate website. Withdrawal applies to future processing and does not affect the lawfulness of earlier processing.
For details of the technologies used, their purposes, providers, durations, and relevant third-party access, consult the Cookie Policy (opens in a new tab) and the information shown with cookie preferences. Browser controls can also block or delete cookies, but deleting cookies may remove saved preferences. Cookie choices do not subscribe you to marketing, authorize talent-pool use, or provide blanket permission for AI processing.
Turnstile normally issues a single-use verification token. If pre-clearance is enabled, it can additionally issue a cf_clearance cookie to remember a successful security check; its duration depends on the configured settings. Any device storage or access is exempt from consent only where the applicable legal conditions are met. A security label alone does not establish an exemption. Where used, cookie details and duration are provided in Cookie Settings and the Cookie Policy (opens in a new tab).
Security and incident handling
We use technical and organizational measures appropriate to the processing and its risks, including controls on authorized access. No transmission, website, or storage system provides absolute security. This does not reduce our obligations to protect personal data or to assess and report personal-data breaches to authorities and affected individuals where required by law.
Please notify contact@unitedsolutionsltd.com if you suspect that information sent to us has been exposed or misused. Include relevant details while avoiding unnecessary sensitive information. We may retain and restrict relevant evidence where necessary to investigate an incident or protect legal rights.
Retention and deletion
We keep identifiable information for a defined purpose and only for the period justified by that purpose and applicable law. Retention does not depend solely on receiving a deletion request. The following criteria determine retention where a fixed period is not stated in the notice for a particular activity.
Inquiries and correspondence
We retain records while answering the request, completing any requested follow-up, or managing an active business discussion. After that purpose ends, continued retention is limited to records needed for a specific legal obligation, complaint, or reasonably anticipated legal claim. The nature of the record, applicable limitation periods, and likelihood of a claim determine any justified extension.
Contractor applications and talent pools
Application information is retained through the relevant selection process and resolution of related queries. After selection, continued retention requires a specific purpose, such as a justified claims record or a separate engagement obligation. An unsuccessful application is not automatically retained for future roles. Separately consented talent-pool information is kept for the period communicated when consent is requested, subject to earlier withdrawal or loss of relevance.
Subscriptions and preference records
Subscription information is used while the subscription remains active and relevant. Unsubscribing ends marketing use. Limited suppression information may remain for as long as necessary to prevent further unwanted contact, and consent evidence may be retained for a justified compliance or claims period. These records are not used to resume marketing.
Analytics and technical records
Identifiable analytics is retained for the measurement period described in the applicable analytics or cookie information. Technical and security records are kept for the period needed to detect faults, investigate misuse, and resolve incidents. Identified incidents or legal claims may justify restricted retention of relevant records beyond the routine period.
Legal holds and backups
Legal, complaint, and compliance records are limited to the information necessary for the obligation or claim and its applicable retention or limitation period, including any lawful interruption or extension. A legal hold restricts use to its justified purpose. When information is no longer needed, it is deleted or irreversibly anonymized. Residual backup copies are restricted from ordinary use and removed through the applicable backup lifecycle; restoration must preserve applicable deletion and restriction requirements. Truly anonymous aggregate information may be retained because it no longer identifies individuals.
Your rights and how to exercise them
Depending on applicable law and the relevant conditions and exceptions, you may request access to your information and a copy, correction, erasure, restriction, and portability. Under the EU GDPR, portability generally applies to information you provided that is processed by automated means on the basis of consent or a contract.
You may withdraw consent at any time without affecting the lawfulness of earlier processing. You may object to legitimate-interest processing on grounds relating to your particular situation. We must stop that processing unless the applicable legal grounds for continuing are met. You may object to direct marketing at any time, including related profiling, and that use must stop.
Send requests to contact@unitedsolutionsltd.com. Where we have reasonable doubts about identity, we may request only the additional information needed to verify it. A duly authorized representative may act where applicable law permits. We may clarify a request where necessary, while continuing to meet the applicable response duties.
Under the EU GDPR, we respond without undue delay and within one month of receipt. Where complexity or the number of requests justifies an extension, the period may be extended by up to two further months, with an explanation within the original month. Requests are generally free. A reasonable fee or refusal is available only where the legal conditions, such as a demonstrably manifestly unfounded or excessive request, are met. Any refusal must explain the reasons and available complaint and judicial remedies.
We may redact information where necessary to protect another person's rights or legally protected confidentiality, applying the relevant law and providing the remaining information where possible. Providing information is generally voluntary, but we may be unable to answer an inquiry or assess an application without the information reasonably needed for it. Optional marketing or talent-pool consent is not a condition of consideration.
Complaints and regional rights
You may raise concerns through contact@unitedsolutionsltd.com. You do not have to contact us before approaching a competent regulator. You may complain to the President of the Personal Data Protection Office (UODO), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland, through the channels at https://uodo.gov.pl/en/p/contact. Under the EU GDPR, you may also complain to the competent authority in the EEA country of your habitual residence, workplace, or the alleged infringement, and pursue available judicial remedies.
Where UK data-protection law applies, you may make a data-protection complaint through the contact details above. We acknowledge complaints within 30 days, take appropriate steps to investigate, keep you informed, and communicate the outcome without undue delay. You may also complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/. UK rights and response rules apply to the extent relevant to your information.
Where Canadian federal or provincial privacy law applies, you may have rights to access and correct personal information, withdraw consent subject to lawful limits, and challenge our handling of your information. Contact us or the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca/, or the relevant provincial regulator. Applicable consent and cross-border requirements are not replaced by GDPR terminology in this policy.
Where a US state privacy law applies to our business and your information, rights may include access, correction, deletion, portability, limiting certain uses or disclosures of sensitive personal information, and opting out of specified sales, sharing, targeted advertising, or profiling. You may use the contact above, including through an authorized agent where permitted. Where an appeal right applies, contact us with the subject "Privacy appeal" and identify the decision you wish us to review. We do not unlawfully discriminate for exercising rights. Legally required opt-out signals, request methods, and additional notices apply where relevant.
Children and external services
The corporate website is intended for business users and adult professional applicants. It is not directed to children, and we do not knowingly seek their personal information. Contact us if you believe a child has submitted information so we can assess and take appropriate action under applicable law.
External websites and independently operated services have their own privacy notices. Their independent processing is governed by those notices and applicable law. This does not exclude our responsibility for information we disclose or for providers processing personal data on our behalf.
Changes to this policy
We may update this policy to reflect changes in processing, services, or applicable law. The date at the top identifies the most recent revision. We provide additional notice and obtain consent where required before introducing relevant changes. An update does not retroactively authorize incompatible use of information already collected, and continued browsing is not consent to optional processing.
Relationship to service agreements
This policy provides information about personal-data practices. It does not establish a service-level commitment or amend a signed services agreement or data-processing agreement. Any allocation of commercial liability between United Solutions and a customer is governed by their applicable agreement, to the extent permitted by law.
Nothing in this policy waives or restricts mandatory privacy rights, remedies, regulatory powers, or responsibilities under applicable law. Descriptions of security measures do not constitute a guarantee of uninterrupted service or absolute security.
Privacy contact: contact@unitedsolutionsltd.com United Solutions Sp. z o.o. KRS 0001148841 | REGON 540628111 | NIP 9452304430 Aleja 29 Listopada 130, 31-406 Kraków, Poland unitedsolutionsltd.com