Documents
Privacy policy
Last updated: 30 August 2026
This is an English translation of our privacy and cookies policy. The Polish version is the binding one; in case of any discrepancy between the two language versions, the Polish text prevails. You can read it at madmountain.io/polityka-prywatnosci.
This Policy explains how Mad Mountain sp. z o.o. processes the personal data of people who use the www.madmountain.io website (the “Website”) and who contact Mad Mountain through the Website. The Policy also sets out the rules for using cookies and similar technologies, including Google Analytics 4 and LinkedIn Insight Tag, and describes Google Tag Manager as a tool for the technical management of tags on the Website.
The Policy concerns processing connected with the Website. It does not replace separate information about data processing provided in other processes, where their nature requires additional information to be given.
1. Controller of personal data
The controller of personal data is Mad Mountain sp. z o.o. with its registered office at ul. Żelazna 51/53, 00-841 Warsaw, Poland, entered in the register of entrepreneurs of the National Court Register under KRS number 0000630335, NIP 5272775982, REGON 364961996 (referred to below as: “Controller” or “Mad Mountain”).
Contact on privacy and personal data processing matters: [email protected].
2. What data we process and where we obtain it from
The scope of the data depends on how you use the Website. The Controller may process in particular:
- data provided in the contact form or in further correspondence, such as first name and surname, e-mail address, telephone number, company name, job title and information contained in the content of the message;
- technical data generated while the Website is used, in particular the IP address, data about the device, operating system and browser, timestamps, addresses of the subpages visited, the address of the referring page, online identifiers and information about activity on the Website - to the extent resulting from the actual configuration of the Website and the user's privacy choices.
As a rule, the data is obtained directly from the user or automatically from their device while the Website is used. The Controller does not require special categories of personal data referred to in Article 9 GDPR to be provided in the contact form. Such data should not be included in a message unless it is necessary to deal with the matter.
3. Purposes and legal bases of processing
The Controller processes personal data for the following purposes:
Handling enquiries and conducting correspondence - Article 6(1)(f) GDPR - the Controller's legitimate interest in communicating with people interested in Mad Mountain's activities or services. If a natural person makes contact on their own behalf in order to take steps prior to entering into a contract with them, the legal basis for processing may be Article 6(1)(b) GDPR.
Conclusion and performance of a contract - Article 6(1)(b) GDPR, where a natural person is a party to the contract. In the case of data of people representing a business partner, employees or other contact persons, the legal basis is Article 6(1)(f) GDPR - the Controller's legitimate interest in concluding, performing and managing the business relationship.
Compliance with legal obligations - Article 6(1)(c) GDPR - to the extent that the obligation to process follows from the law, in particular from tax, accounting or record-keeping provisions.
Ensuring the correct and secure operation of the Website - Article 6(1)(f) GDPR - the Controller's legitimate interest in maintaining the Website, diagnosing errors, ensuring the security of systems and preventing abuse.
Analytics and statistics using Google Analytics 4 - Article 6(1)(a) GDPR - the user's consent. Consent is also required before analytics technologies are activated, to the extent set out in Article 399 and Article 400 of the Electronic Communications Law.
Measuring the effectiveness of campaigns, establishing whether an advertisement led to a particular action on the Website, creating audience groups and directing advertising to people who have visited the Website (remarketing), using LinkedIn Insight Tag - Article 6(1)(a) GDPR - the user's consent. Consent is also required before marketing technologies are activated, to the extent set out in Article 399 and Article 400 of the Electronic Communications Law.
Documenting choices about cookies and demonstrating compliance - Article 6(1)(c) GDPR in connection with the Controller's obligations arising in particular from Article 5(2) and Article 7(1) GDPR and from Article 399-400 of the Electronic Communications Law. For this purpose the Controller may record information about the choice made, the time it was made and the version of the privacy settings, to the extent necessary to demonstrate whether and when consent was given or withdrawn.
Establishment, exercise or defence of legal claims - Article 6(1)(f) GDPR - the Controller's legitimate interest in protecting its rights and legal interests.
4. Contact form and business contact
Providing data in the contact form is voluntary, but the absence of the data needed to reply may make it impossible to handle the enquiry. If the contact leads to a contract being concluded, providing the data necessary to conclude or perform the contract may be a condition of concluding or performing it.
Handling an ordinary enquiry does not require separate consent to the processing of personal data. The Controller does not base such processing on consent where the correct legal basis is Article 6(1)(b) or (f) GDPR. Any consents relating to analytics, advertising or other separate purposes are independent of the ability to submit the form.
5. Cookies and similar technologies
The Website uses cookies and similar technologies which may allow information to be stored in the user's terminal equipment or access to be gained to information already stored in it. In this respect the Controller applies Article 399 of the Act of 12 July 2024 - the Electronic Communications Law (referred to below as: “the Electronic Communications Law”). Under Article 400 of the Electronic Communications Law, the personal data protection rules on consent apply to the consent required under the Electronic Communications Law.
Technologies other than those necessary to transmit a message or to provide a service expressly requested by the user are activated only after information has first been given and consent obtained. Not giving consent to optional technologies does not limit access to the basic functions of the Website or the ability to send the contact form.
The Controller uses the following categories of technology:
Necessary - technologies required for the correct and secure operation of the Website or to remember privacy choices. They are not a consent category. To the extent that they meet the conditions of Article 399(3) of the Electronic Communications Law, they may be used without separate consent from the user.
Analytics - technologies used to examine how the Website is used and to produce statistics, in particular Google Analytics 4. They are switched off by default and are activated only after consent.
Marketing - technologies used to measure the effectiveness of campaigns, to determine whether an advertisementisement led to a particular action on the Website, to create audience groups and to direct advertising to people who have visited the Website (remarketing), in particular LinkedIn Insight Tag. They are switched off by default and are activated only after consent.
When the banner is first shown, the user may consent to all optional technologies by clicking “Accept and go to the website”, or go to “Privacy settings”. Before the accept button, the user is given information about the use of Google Analytics 4 to analyse traffic and the way the Website is used, and of LinkedIn Insight Tag to measure the effectiveness of campaigns, to check whether an advertisementisement led to a particular action on the Website, to create audience groups and to direct advertising to people who have visited the Website, as well as about the related use of cookies or similar identifiers and of information about activity on the Website, the device and the browser. In “Privacy settings” the user has two optional toggles: “Analytics” for Google Analytics 4 and “Marketing” for LinkedIn Insight Tag. The user may reject all optional technologies or switch each of these two categories on or off independently. Optional categories are switched off by default. Google Tag Manager does not have a separate consent toggle.
The user may at any time reopen the “Privacy settings” panel available on the Website and withdraw or change their consent. Withdrawing consent stops the Controller from activating the relevant tools any further and does not affect the lawfulness of the processing carried out before it was withdrawn. An up-to-date list of the cookies and similar identifiers used is available before consent is given and later in the “Privacy settings” panel. For each technology, the panel gives at least its name, provider, purpose, category and duration. The information in the panel supplements this Policy and reflects the current configuration of the Website.
When analytics and marketing tools are active
Google Analytics 4 and LinkedIn Insight Tag are activated only once the user has given the relevant consent. Google Analytics 4 requires analytics consent, and LinkedIn Insight Tag - marketing consent. Until the appropriate consent is given, the tool concerned remains inactive and does not send any data to its provider through the Website.
6. Google Analytics 4
The Controller uses Google Analytics 4 in order to compile statistics on the use of the Website and to assess how it works. The provider of the service for customers from the European Economic Area (EEA) is Google Ireland Limited.
Once consent has been given, Google Analytics 4 may process, among other things, information about the device and the browser, activity on the Website, the subpages visited, the time of the visit, the source of entry to the Website and the approximate location derived from network data. The scope of the data depends on how the service is configured.
On the Website, Google Analytics 4 is configured as an analytics tool and not an advertisementising one. In the current configuration, the Controller does not use Google Signals, the advertising features of Google Analytics, the sending of user-provided data collected through the form, or a link between GA4 and Google Ads for the purposes of ad personalisation or remarketing.
In the standard Google Analytics 4 property, the Controller sets the retention period for user-level and event-level data to 14 months. This setting need not apply to aggregated reports, which are not used to identify the user.
7. LinkedIn Insight Tag
The Controller uses LinkedIn Insight Tag in connection with running advertising campaigns on LinkedIn. The tag is activated only after consent to marketing technologies has been given.
The LinkedIn Insight Tag may be used to measure the effectiveness of campaigns, to determine whether an advertisementisement led to a particular action on the Website, to create aggregated statistics about the Website's audience, to create audience groups and to target advertisements at people who have visited the Website (remarketing). As part of how this tool works, LinkedIn may receive in particular the URL of the page visited, the referring page address, the IP address, information about the device and the browser, and a timestamp. If the Website Actions function is used for conversion measurement, LinkedIn may additionally record limited information about actions on the Website, such as the page element the user interacts with, the type of action and a pseudonymous session identifier.
According to information from LinkedIn, direct identifiers associated with the data collected by the Insight Tag are deleted within 7 days. The remaining data, once pseudonymised, is deleted within 180 days.
The Controller does not use Enhanced Matching or any other mechanism for passing to LinkedIn an e-mail address, a telephone number or other data provided by the user in the contact form.
LinkedIn Ireland Unlimited Company acts as a separate, independent controller of the data received and processed by LinkedIn in connection with LinkedIn Insight Tag and the services based on that tag. LinkedIn is solely responsible for its own purposes and means of further processing, to the extent following from its terms and privacy information. As regards the processing carried out by LinkedIn, the data subject may also exercise their rights directly with LinkedIn.
8. Google Tag Manager
The Controller uses Google Tag Manager (GTM) for the technical management of tags and scripts used on the Website. Through it, the Controller controls, among other things, the launching of Google Analytics 4 and LinkedIn Insight Tag in line with the user's choice regarding analytics and marketing technologies respectively. Google Tag Manager is not a separate consent category and the user does not give separate consent for it.
According to information from Google, GTM may collect aggregated diagnostic data on the launching of tags; this data does not include users' IP addresses or measurement identifiers linked to a specific person. Google also states that standard HTTP request logs relating to GTM are deleted within 14 days. As regards the limited technical data connected with the operation of GTM, the legal basis for processing on the Controller's side is Article 6(1)(f) GDPR - the legitimate interest of the technical management of the Website and of the consent mechanism.
9. Data recipients and the roles of providers
Data may be passed to entities that support the Controller in running the Website and its business, in particular providers of hosting, IT infrastructure, security services, email, a consent management platform (CMP), analytics and marketing services, as well as entities providing legal or accounting services - only to the extent that access to the data is necessary to achieve a given purpose and has an appropriate legal basis.
In connection with the tools described in the Policy, the data recipients may in particular be Google Ireland Limited and entities in the Google group and, in the case of LinkedIn Insight Tag - LinkedIn Ireland Unlimited Company and entities in the LinkedIn group. Where a provider processes data on behalf of the Controller, the Controller uses that provider on the basis of appropriate processing terms. If a provider acts as an independent controller, it is responsible for its own obligations under the GDPR in respect of its own processing.
Data may also be disclosed to public authorities or other entities if the obligation to pass it on follows from the law or from a legally binding request of an authorised authority.
10. Transfer of data outside the European Economic Area
Because Google and LinkedIn services are global in nature, data may also be processed outside the European Economic Area, in particular in the United States. Data is transferred to a third country only using a mechanism permitted under Chapter V of the GDPR.
If the relevant recipient in the United States holds a current certification under the EU-U.S. Data Privacy Framework and the transfer falls within the scope of that certification, the transfer may be based on a European Commission decision confirming an adequate level of protection. In other cases, the safeguards used may in particular include standard contractual clauses approved by the European Commission and - where required - additional protective measures.
Information about the transfer mechanism used, or a copy of the relevant safeguards, can be obtained by contacting the Controller at [email protected]. The providers also publish their own information about international transfers and the safeguards they use.
11. How long we keep data
The Controller applies retention periods appropriate to the purpose and legal basis of the processing:
- data from the contact form and from ordinary correspondence, if no contract is concluded - for the time needed to handle the enquiry and to carry on the correspondence, and after the matter is closed only for as long as this is justified by its nature or by the need to establish, pursue or defend against claims;
- data connected with a contract - for the period of its performance, then for the period required by the applicable provisions of law and until the limitation period for claims relevant to the given relationship expires;
- user-level and event-level data in the standard Google Analytics 4 property - in line with the setting adopted by the Controller, no longer than 14 months;
- LinkedIn Insight Tag data - in line with the retention rules applied by LinkedIn, direct identifiers are deleted within 7 days, and the remaining data, once pseudonymised, is deleted within 180 days;
- information about choices regarding cookies and consents - for the period necessary to remember the choice and to demonstrate compliance with legal obligations, taking into account the limitation periods for potential claims or liability; once the need ceases, the data is deleted or anonymised;
- technical and security logs - for the period resulting from the configuration of the systems and necessary to ensure the security of the Website, to diagnose errors and to investigate incidents; in the case of data secured in connection with a specific incident - until that incident is clarified or the related matter is closed.
If a valid objection is raised or consent is withdrawn, the Controller stops the processing to the extent required by the GDPR, unless there is a separate legal basis for further processing. Withdrawing consent for cookies stops the Controller from firing the relevant tags in the future; data passed earlier to independent controllers may be processed by them in line with their own obligations and retention periods.
12. Rights of data subjects
Depending on the basis and the circumstances of the processing, the data subject may have:
- the right to access the data and to obtain a copy of it;
- the right to rectification of the data;
- the right to erasure of the data (the so-called right to be forgotten) - in the cases provided for in Article 17 GDPR;
- the right to restriction of processing;
- the right to data portability - in the cases set out in Article 20 GDPR;
- the right to object to processing based on Article 6(1)(f) GDPR;
- the right to withdraw consent at any time, if the processing is based on consent, without affecting the lawfulness of the processing carried out before the withdrawal.
Right of objection
If the Controller processes data on the basis of Article 6(1)(f) GDPR, the user has the right to object at any time on grounds relating to their particular situation. Once an objection has been lodged, the Controller will stop processing the data for that purpose, unless it demonstrates that there are compelling legitimate grounds for further processing which override the interests, rights and freedoms of that person, or grounds for the establishment, exercise or defence of legal claims.
Requests concerning the exercise of these rights can be sent to the e-mail address: [email protected]. If the Controller has reasonable doubts about the identity of the person making the request, it may ask for additional information needed to confirm it.
The data subject also has the right to lodge a complaint with the President of the Personal Data Protection Office if they believe that their data is being processed in breach of the GDPR.
13. Profiling and automated decision-making
Mad Mountain does not take decisions in relation to Website users that produce legal effects concerning them or similarly significantly affect them, based solely on automated processing of data as referred to in Article 22 GDPR.
Once consent to LinkedIn Insight Tag has been given, data on the use of the Website may be used to assign the user to audience groups and to show them ads in LinkedIn services. The detailed rules of such processing, including the available advertising settings, are set out by LinkedIn as an independent controller in its privacy information.
14. Changes to the Policy
The Policy may be updated in particular where the functionality of the Website, the scope of the forms, the technologies used, the service providers or the applicable law change. The current version of the Policy is published on the Website together with the date of the last update.