Skip to content
Version 1.0·Effective 1 June 2026

Privacy Policy

How Kepta handles personal data of the people who visit kepta.legal, contact us through the site, or apply to work with us. When the Kepta platform and lawyer-delivered services go live, personal data handled in the course of a client engagement is separately addressed by the engagement terms and, where we act as processor, the DPA.

English is the binding text · Polish is provided for convenience

This Privacy Policy explains how Grasperly Sp. z o.o. ("Kepta", "we", "us"), registered office at ul. Tczewska 4a/78, 01-674 Warszawa, Poland (KRS 0001238012, NIP 7252366483), collects, uses, and shares personal data in its capacity as a controller of that data. We are subject to Regulation (EU) 2016/679 (the "GDPR") and the Polish Personal Data Protection Act of 10 May 2018.

Launch scope. At the launch of this website, kepta.legal is a marketing site with two email-based enquiry forms (a contact form and a startup application form). There is no user account, no customer document workspace, and no automated or AI processing of your data on this site yet. The Kepta platform and the lawyer-delivered services it supports are introduced separately, and the parts of this policy that concern them apply once they are actually available to you.

Whose data this covers. This policy covers personal data we process about (i) visitors to kepta.legal and our other public web properties; (ii) prospective customers and the contact persons at our customers, including people who submit the contact or application forms; (iii) candidates who apply to work at Kepta; and (iv) attendees at events we host or sponsor.

Our role. When we deliver legal services, Kepta determines how the personal data in a matter is handled to produce the work, so we act as a controller (or, together with the customer, a joint controller) of that data, not as a processor only. Separately, once the Kepta platform is live and a customer submits content to it for automated processing, the customer is the controller of that Customer Data and we act as its processor under the Data Processing Agreement. Neither situation arises at the launch of this website. Questions about data in a specific engagement can be raised with us at contact@kepta.legal.

Plain-English summary. We do the minimum necessary to run a business. No advertising trackers on kepta.legal, no profile-building, no sale of personal data. Most processing happens in the EU; where a provider we rely on (for example our email-delivery provider) is outside the European Economic Area, the transfer is covered by an appropriate safeguard. You have the right to access, correct, delete, port, restrict, and object to processing of your personal data, and to complain to the Polish supervisory authority at any time.

1.Controller and contact

Controller: Grasperly Sp. z o.o., ul. Tczewska 4a/78, 01-674 Warszawa, Poland. KRS 0001238012. NIP 7252366483.

Privacy contact: contact@kepta.legal. We have not appointed a Data Protection Officer (DPO), because we do not meet the mandatory thresholds in Article 37 of the GDPR, but the mailbox is monitored by the people at Kepta responsible for data protection. We aim to respond within five (5) business days and, in any event, within the one-month statutory deadline set by Article 12(3) of the GDPR (extendable by two further months for complex or numerous requests under the same provision).

Supervisory authority: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, www.uodo.gov.pl. You have the right to lodge a complaint there at any time concerning the processing of your personal data, particularly if you believe the processing infringes the GDPR.

2.What personal data we collect

We collect only what we need for the purpose for which we are processing.

Website visitors (kepta.legal). Page-view counts, language preference, referrer URL, country at country level only, browser family. Collected through Plausible cookieless analytics. No IP addresses are stored by the analytics. No persistent user identifier is created. No cross-site tracking.

Contact form. When you use the contact form we receive your name, work email, company, and the message you write.

Startup application form. When you use the application form we receive your company, company website, work email, the fund or accelerator that backs you, when you last raised, your headcount, and any note you add.

Prospects and customer-contact persons generally. In addition to what you submit through a form, we keep the notes we make about a conversation with you. Source (Article 14(2)(f) GDPR): we collect this data directly from you when you submit a form, write to us, or speak with us at an event. We do not enrich prospect records from third-party data brokers or scrape public profiles to build them.

Candidates. What you submit in your application (CV, cover letter, work-history details, professional licences), our interview notes, references that you have authorised us to obtain, and the outcome of the recruitment process.

Event attendees. Name, work email, employer, and any dietary or accessibility information you provide for an event.

Server logs. Our web server keeps standard technical logs of requests, which include IP addresses, for the security and stability of the site. None of this is used for advertising or sold to anyone. Account-security telemetry, such as detecting attempted account takeover, will apply only once the Kepta platform and its user accounts are available.

3.Purposes and legal bases

We process personal data only where we have a lawful basis under Article 6 of the GDPR. The table below maps purposes to bases. Where we rely on legitimate interests under Article 6(1)(f) we state the specific interest pursued.

Operating kepta.legal and counting page views. Legitimate interest (Article 6(1)(f)), *specific interest: understanding how visitors use our website so that we can run, secure, and improve it.* The processing is privacy-preserving by design, no cookies, no IP storage, no profiles.

Responding to inquiries and demo requests. Steps prior to entering a contract at the request of the data subject (Article 6(1)(b)) and legitimate interest (Article 6(1)(f)), *specific interest: running a B2B sales pipeline and providing a professional response to commercial inquiries.*

Account administration (once the platform is live). When the Kepta platform becomes available, we will process account-management data to perform our contract with the customer you belong to (Article 6(1)(b)) and to meet our legal record-keeping obligations (Article 6(1)(c)). This does not apply at the launch of this website.

Recruitment. Steps prior to entering an employment relationship at the request of the data subject (Article 6(1)(b)) and legitimate interest (Article 6(1)(f)), *specific interest: identifying suitable candidates for open roles.* Retention of candidate data beyond the current recruitment process for the purpose of considering future opportunities is based on the candidate's explicit consent (Article 6(1)(a)), consistent with Article 22¹ of the Polish Labour Code, which is requested separately and may be withdrawn at any time.

Event management. Performance of an event-attendance contract (Article 6(1)(b)) and legitimate interest (Article 6(1)(f)), *specific interest: ensuring event safety, accessibility, and quality.*

Security and fraud prevention. Legitimate interest (Article 6(1)(f)), *specific interest: protecting kepta.legal, the people who contact us, and Kepta from unauthorised access, abuse, and other security incidents. Platform and account-security processing applies once the Kepta platform is live.*

Compliance with law. Tax, accounting, anti-money-laundering, sanctions screening, and other obligations imposed on us by Polish, EU, or applicable foreign law (Article 6(1)(c)).

Defence of legal claims. Legitimate interest (Article 6(1)(f)), *specific interest: establishing, exercising, and defending legal claims by or against Kepta.*

4.Retention

We do not keep personal data longer than necessary. Specific retention periods are:

  • Plausible analytics: aggregated counts only; no per-visitor record retained.
  • Inquiry and demo data: twenty-four (24) months from last meaningful contact, then deleted from active systems and retained only in audit logs for one further year.
  • Customer-contact-person data (active customers): for the duration of the customer relationship, plus six (6) years for tax and statute-of-limitations purposes.
  • Platform account data: not applicable at the launch of this website. Retention periods for account data will be set out here once the Kepta platform and its user accounts become available.
  • Candidate data (unsuccessful applicants): twelve (12) months from the date of decision, unless you have consented to a longer period for future opportunities.
  • Candidate data (successful applicants): transferred to employee records on hire; that processing is covered by our internal HR notice.
  • Server logs: twelve (12) months, except for incidents under investigation, where logs are kept until investigation is closed plus three (3) years for evidentiary purposes.
  • Records required by law: for the period mandated by the applicable law (e.g. five years for VAT documentation under Polish tax law).

5.Recipients and sub-processors

We share personal data only where necessary and only with recipients bound by appropriate confidentiality and data-protection terms.

Service providers (processors). At launch we use a small number of providers, each bound by a data-processing agreement meeting Article 28 of the GDPR: Resend (delivery of the emails generated by our contact and application forms; the delivery entity is in the United States), Plausible Insights OÜ (Estonia, cookieless website analytics), and Google Workspace (the mailbox that receives the enquiry emails). The current list is published at kepta.legal/sub-processors. The website itself runs on Kepta's own server infrastructure, not on a third-party cloud. Additional providers, including AI model providers, will be engaged only once the Kepta platform is live, and will be listed on the sub-processor page before that happens.

Professional advisors. Our lawyers, auditors, tax advisors, and insurers, where they have a legitimate need to know in their professional capacity and are themselves bound by confidentiality.

Authorities. Public authorities to whom we are required to disclose information by law (e.g. tax authorities, the supervisory authority, courts, prosecutors). We disclose the minimum necessary and require a lawful basis from the authority.

Transactions. In a merger, acquisition, reorganisation, or sale of all or substantially all of our assets, personal data may be transferred subject to standard confidentiality protections in the transaction documents and continued application of this policy or one no less protective.

We do not sell personal data. We do not share personal data with advertising networks, data brokers, or any party for the purpose of independent marketing to you.

6.International transfers

Most of our processing happens in the European Union. The website runs on Kepta's own server infrastructure in the EU, and our analytics provider Plausible is in Estonia.

One part of our processing does involve a provider outside the European Economic Area. Our email-delivery provider, Resend, is established in the United States, and the personal data in a form submission passes through it in order to reach our mailbox. That transfer is made under an appropriate safeguard listed in Articles 45 to 49 of the GDPR, in the ordinary case the European Commission's Standard Contractual Clauses with supplementary measures where needed.

Where any other transfer outside the EEA occurs, for example when a non-EEA professional advisor reviews a matter, it is made only under one of those safeguards: an adequacy decision, the Standard Contractual Clauses with appropriate supplementary measures, or, where strictly necessary, one of the derogations in Article 49.

On request to contact@kepta.legal we will provide a copy of the safeguard in place for any specific transfer.

7.Your rights

You have the rights set out in Articles 15 to 22 of the GDPR. Specifically:

  • Access (Article 15), obtain confirmation whether we process your personal data and, if so, a copy of that data and the information set out in Article 15(1)–(2).
  • Rectification (Article 16), correct inaccurate or incomplete data.
  • Erasure (Article 17), request deletion in the circumstances listed in Article 17(1), subject to the exceptions in Article 17(3).
  • Restriction of processing (Article 18), restrict processing in the circumstances listed in Article 18(1).
  • Data portability (Article 20), receive your personal data in a structured, commonly used, machine-readable format, where the processing is based on consent or on a contract and is carried out by automated means.
  • Objection (Article 21), object at any time, on grounds relating to your particular situation, to processing based on legitimate interest. We will then stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or for the establishment, exercise, or defence of legal claims. You also have an absolute right to object to direct marketing.
  • Automated decisions (Article 22), not to be subject to a decision based solely on automated processing that produces legal effects on you or similarly significantly affects you, subject to the exceptions in Article 22(2). We do not currently take such decisions about website visitors, prospects, or candidates.
  • Withdraw consent (Article 7(3)), where processing is based on consent, withdraw it at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

To exercise any of these rights, email contact@kepta.legal. We will respond without undue delay and in any event within one (1) month of receipt of the request, in line with Article 12(3). Where the request is complex or numerous we may extend that period by a further two months and we will notify you of the extension within the first month.

We do not charge a fee for handling requests unless they are manifestly unfounded or excessive, in particular because of their repetitive character, in which case we may charge a reasonable fee or refuse to act, in line with Article 12(5).

8.Cookies

We do not use non-essential cookies on kepta.legal. The site sets only a single strictly necessary cookie that remembers your language preference (`NEXT_LOCALE`). The Kepta platform, once live, will use only strictly necessary cookies. Full details are in our Cookie Policy.

9.Children

Kepta serves businesses. kepta.legal is not directed to children. We do not knowingly collect personal data from children under sixteen (16). If you believe we have done so, please contact contact@kepta.legal and we will delete the data without undue delay.

10.Security

We apply technical and organisational measures appropriate to the risk in line with Article 32 of the GDPR. For this website that includes serving the site over HTTPS, keeping form-handling secrets out of the codebase and off the browser, and limiting who can access the server that runs the site and receives form submissions.

The fuller set of controls that will govern the Kepta platform and the lawyer-delivered services is described on our trust center and will be committed to in Schedule 3 of the DPA once those services are live.

If we become aware of a personal-data breach we will notify the Polish supervisory authority and affected data subjects in line with Articles 33 and 34 of the GDPR, and our customers in line with the DPA.

11.Changes to this policy

We may update this policy from time to time to reflect changes in our practices, our service, or the law. Material changes will be summarised at the top of this page for at least thirty (30) days, and we will email affected data subjects where they have a reasonable expectation of notice. Continued use of kepta.legal or the Platform after the effective date of an update constitutes acknowledgement of the updated policy.

12.Language

This policy is published in English and in Polish. The English-language version is the binding text; the Polish-language version is a translation provided for convenience. Where mandatory law applicable to a data subject requires another language to govern, the mandatory provisions of that law prevail.

Request a signed copy

Grasperly Sp. z o.o. · KRS 0001238012 · NIP 7252366483 · contact@kepta.legal