Privacy Policy
Effective date: 30 June 2026
Last updated: 28 July 2026 (Microsoft Clarity added)
Version 1.1
This Privacy Policy describes how personal data and cookies are processed on the teamcoandfriends.orgwebsite operated by Fundacja TeamCo & Friends (TeamCo & Friends Foundation). It covers in particular: the report download form, cookies, Google analytics tools, Salesforce CRM, and all other data-processing mechanisms described below.
1. Data Controller
The controller of your personal data is: Fundacja TeamCo & Friends(TeamCo & Friends Foundation)
- Address: Północna 129, 20-818 Lublin, Poland
- KRS (Court Register): 0001132658
- NIP (Tax ID): 7123483057
- REGON (Statistical ID): 529932197
- Contact for data protection matters: hello@teamcoandfriends.org
The Controller has not appointed a Data Protection Officer (DPO). For any matters relating to the processing of personal data, please contact the Controller directly at the e-mail address listed above.
2. Data Processors
The Controller has entrusted the processing of personal data to the following entities under data-processing agreements concluded pursuant to Art. 28 GDPR:
2.1 TeamCo Cloud sp. z o.o.
Role: data processor — provides the hosting infrastructure for the website and operates the Salesforce CRM organisation that receives leads from the form.
- Address: ul. Północna 129, 20-818 Lublin, Poland
- KRS: 0001021732
- NIP: 5252946133
- REGON: 524624858
2.2 Google LLC
Role: data processor — provides the following services that involve processing of users' personal data:
- Google Tag Manager (GTM) — tag container (ID: GTM-MSXX75D2) loaded on every page of the website; manages deployment of analytics tags.
- Google Analytics 4 (GA4) — website traffic analytics (measurement ID: G-HQ1TG288TD); processes pseudonymous identifiers (_ga, _gid), IP addresses (anonymised by Google), and page paths. GA4 tags fire only after the user grants analytics consent in the cookie banner. Where consent is not given, GA4 runs in cookieless mode — it stores no cookies on the device and sends only anonymous, identifier-free pings used for traffic modelling (no profiling or remarketing).
- Google Ads— Google's advertising system (account ID: AW-16994557796) used to measure advertising campaign effectiveness and record conversions (e.g. report download, form submission). Google Ads tags, including conversion tracking and remarketing, fire only after the user grants the "marketing" consent category (ad_storage, ad_user_data, ad_personalization) in the cookie banner. The gclid (Google Click ID) identifier is used to link a conversion to an ad click.
- Google reCAPTCHA v3— bot and spam protection for the report download form. The reCAPTCHA script runs silently on the form page, collecting behavioural signals (mouse movements, timing, interaction patterns), browser fingerprint, and IP address. This data is transmitted to Google independently of the user's cookie analytics consent choice. Legal basis: the Controller's legitimate interest (Art. 6(1)(f) GDPR) — protecting the security and integrity of the website.
- Firebase Hosting (Google Cloud Platform) — hosting of the static website; primary region: europe-central2 (Warsaw, Poland). Server access logs contain IP addresses, HTTP headers (User-Agent, Referer, request URL, timestamps).
- Firebase Authentication — user authentication for the private beta version of the website (applies only to hosts: beta.teamcoandfriends.org and teamco-org-test.web.app). Processes Google account e-mail address and Google account UID.
- Google Workspace / Gmail— the Controller's e-mail service (mailbox: hello@teamcoandfriends.org). Messages submitted via the contact form are delivered to and stored within this service; the data processed is the information provided by the User in the form (first name and last name, e-mail address, optionally company name, message content).
Google LLC is headquartered in the USA. Transfers of data to Google are made on the basis of the European Commission's Implementing Decision of 10 July 2023 (EU–US Data Privacy Framework — DPF) and Standard Contractual Clauses (SCC).
Google's Privacy Policy: policies.google.com/privacy
2.3 Salesforce, Inc.
Role: data processor — CRM system (Web-to-Lead) that receives, directly from the user's browser, the data submitted in the report download form.
Salesforce, Inc. is headquartered in the USA. The transfer is made on the basis of the EU–US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCC).
Salesforce Privacy Policy: salesforce.com/company/privacy
2.4 Microsoft Corporation
Role: independent data controller (contracting entity: Microsoft Ireland Operations Limited; transfers to Microsoft Corporation in the US under Standard Contractual Clauses and the EU–US Data Privacy Framework) — provides Microsoft Clarity, a behavioural analytics tool (session recordings and heatmaps). Clarity records a pseudonymised picture of how the user interacts with the website: cursor movements, scrolling, clicks, and pages visited. Recordings are retained for up to 30 days. Data typed into form fields is masked by Clarity by default and is not recorded. The Clarity script runs only after the user grants the "analytics" consent category (analytics_storage: granted) in the cookie banner; without that consent the script is not loaded at all. Legal basis: consent (Art. 6(1)(a) GDPR).
Microsoft Privacy Statement: privacy.microsoft.com/privacystatement
3. Purposes of Processing and Legal Bases (GDPR)
We process personal data solely for the purposes described below, on the stated legal bases:
3.1 Report download form
Purpose: delivery of the Salesforce Ecosystem Report Poland 2026 and building the Salesforce community — establishing a business relationship and keeping users informed about the activities of Fundacja TeamCo & Friends.
Legal basis: the data subject's consent (Art. 6(1)(a) GDPR). Consent is given by ticking the dedicated consent checkbox in the form before submission.
Data fields collected by the form:
- First name (first_name)
- Last name (last_name)
- E-mail address (email)
- Phone number (mobile)
- Company name (company)
- Job title
- Consent flag (required checkbox — form cannot be submitted without it)
This data is transmitted directly from the user's browser to the Salesforce CRM (webto.salesforce.com) via HTTPS.
3.2 UTM parameters and advertising click identifiers
If a user arrives at the site via a tracked link or advertisement, the form automatically reads from sessionStorage and appends the following technical data to the Salesforce lead record:
- utm_source, utm_medium, utm_campaign, utm_content — standard UTM campaign parameters
- gclid (Google Click ID) — a pseudonymous identifier linking the lead to a specific Google Ads click, used for conversion attribution.
- fbclid (Meta/Facebook Click ID) — a pseudonymous identifier linking the lead to a specific Meta/Facebook Ads click, used for campaign attribution. Note: this website does not run a Meta/Facebook Pixel — fbclid is captured from the URL and passed only to Salesforce CRM for attribution purposes.
Legal basis for UTM parameters and click identifiers: the consent given via the form checkbox (Art. 6(1)(a) GDPR) — these data points accompany the lead record and are processed under the same consent.
3.3 Contact form
Purpose: handling enquiries and messages submitted by the User via the contact form (page /kontakt) — providing a response and conducting correspondence regarding the enquiry.
Legal basis: the data subject's consent (Art. 6(1)(a) GDPR), expressed by ticking the dedicated consent checkbox in the form before submission; for the purpose of responding to the enquiry, the legal basis also includes the Controller's legitimate interest in handling correspondence (Art. 6(1)(f) GDPR).
Data fields collected by the contact form:
- First name and last name
- E-mail address
- Company / organisation name (optional)
- Message content
- Consent flag (required checkbox — form cannot be submitted without it)
The message submitted via the form is delivered to the Controller's e-mail inbox (hello@teamcoandfriends.org) operated within the Google Workspace / Gmail service provided by Google LLC (a data processor — see section 2.2). The form is protected by the Google reCAPTCHA v3 mechanism (see section 3.6). Data is processed for the period necessary to handle the enquiry and provide a response, and thereafter until the expiry of any potential claims or withdrawal of consent.
3.4 Traffic analytics — Google Analytics 4 & GTM
Purpose: statistical analysis of website traffic and conversion measurement to improve the website.
Legal basis: consent (Art. 6(1)(a) GDPR). Analytics tags fire only after the user grants the "analytics" consent category in the cookie banner (Google Consent Mode v2, default: denied).
Through GA4 (via Google Tag Manager) the following anonymous technical and behavioural data is collected:
- System data: device type, screen resolution, operating system, browser type, approximate geolocation (based on an anonymised IP address, to city/region level), and traffic source (including utm_source, utm_medium campaign parameters).
- Interface interactions:page views (page_view), scroll depth (scroll — typically once 90% of the page length is passed), clicks on call-to-action buttons such as "Download report", "Contact" (cta_click), clicks on footer links (footer_click), clicks on e-mail links (e.g. mailto addresses), and video player interactions (video_start, video_progress, video_complete).
- Business events / conversions:successful report PDF download / report form submission (report_download_complete), successful contact form submission (contact_form_success), sales lead generation (lead), and interface errors such as form validation errors (error_tracked), recorded solely to improve the website's operation and user experience (UX).
Behavioural data is not used to identify a specific natural person or for profiling within the meaning of Art. 22 GDPR.
3.5 Advertising and conversion measurement — Google Ads
Purpose: measuring the effectiveness of Google Ads campaigns (account AW-16994557796), recording conversions (e.g. report download, form submission), and — where campaigns are active — remarketing.
Legal basis: consent (Art. 6(1)(a) GDPR). Google Ads tags fire only after the user grants the "marketing" consent category (ad_storage, ad_user_data, ad_personalization) in the cookie banner. The gclid (Google Click ID) identifier is used to link a conversion to an ad click.
3.6 Google reCAPTCHA v3
Purpose: protection of forms against bots and spam.
Legal basis: the Controller's legitimate interest (Art. 6(1)(f) GDPR) — ensuring the security of the website and integrity of collected data. The reCAPTCHA script processes behavioural signals, IP address, and browser fingerprint in the background on the form page, independently of the user's cookie analytics decision.
3.7 Firebase Hosting — access logs
Purpose: technical operation of the website, security, diagnostics.
Legal basis: the Controller's legitimate interest (Art. 6(1)(f) GDPR). Logged data: IP address, User-Agent, request URL, request timestamp.
3.8 Firebase Authentication (beta version)
Purpose: access control for the private beta version of the website.
Legal basis: the Controller's legitimate interest (Art. 6(1)(f) GDPR) and performance of the beta-access terms (Art. 6(1)(b) GDPR). Applies only to hosts: beta.teamcoandfriends.org and teamco-org-test.web.app.
4. Cookies and Local Storage
The website uses various mechanisms to store data on the user's device. A full inventory is provided below.
4.1 First-party cookies and localStorage
- teamco_cookie_consent(localStorage) — stores the user's cookie consent preferences (categories: ad_storage, analytics_storage, ad_user_data, ad_personalization, personalization_storage, functionality_storage, security_storage). Purpose: GDPR consent management. Legal basis: legal obligation (Art. 6(1)(c) GDPR). Retention: until manually cleared by the user.
- theme (localStorage) — stores dark/light mode preference. Contains no personal data; purpose: user experience.
- utm_source, utm_medium, utm_campaign, utm_content, gclid, fbclid (sessionStorage) — UTM parameters and advertising click identifiers captured from the URL. Cleared when the browser tab is closed. Purpose: campaign attribution.
4.2 Google Analytics cookies (after consent is given)
- _ga — pseudonymous GA4 client identifier; expires after 2 years.
- _gid — GA4 session identifier; expires after 24 hours.
- _ga_[container] — GA4 session data; expires after 2 years.
GA4 cookies are set only after the user grants the "analytics" consent category (analytics_storage: granted) in the cookie banner.
4.3 Google reCAPTCHA v3 cookies
The reCAPTCHA script sets its own Google cookies (e.g., __Secure-ENID, NID, SOCS). These cookies serve bot-detection purposes and are not gated on the user's analytics consent decision.
4.4 Google Ads cookies (after marketing consent)
After the user grants the "marketing" consent category, Google Ads (account AW-16994557796) may set its own Google cookies (e.g. _gcl_au, NID, IDE) used for conversion measurement and — where campaigns are active — remarketing. These cookies are set only after consent to ad_storage, ad_user_data, and ad_personalization in the cookie banner; without consent they are not stored.
4.5 Cookie categories used on this website
- Necessary — required for the website to function correctly (cookie consent preference, theme preference). No consent required.
- Functional — remembering user preferences.
- Analytics — Google Analytics 4 (traffic data collection). Require consent.
- Marketing — Google Ads tags and cookies (conversion measurement, remarketing) and campaign parameters and click identifiers (gclid, fbclid). Require consent (ad_storage, ad_user_data, ad_personalization).
4.6 Managing cookie consent
On your first visit, a cookie banner is displayed allowing you to grant or decline consent by category. We use Google Consent Mode v2 — all analytics and marketing tags are denied by default until consent is given.
You can withdraw or modify your consent at any time using the "Cookie settings" option available in the website footer. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
You may also manage cookies through your browser settings — blocking cookies may limit some website functionality.
5. International Data Transfers
Some personal data is transferred to entities located outside the European Economic Area (EEA), in particular to the USA — to Google LLC and Salesforce, Inc.
Transfer basis: the European Commission's Implementing Decision of 10 July 2023 establishing an adequate level of protection for data transferred to the USA under the EU–US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCC) approved by the European Commission. Both Google LLC and Salesforce, Inc. hold active DPF certifications.
Firebase Hosting serves static assets from the europe-central2 (Warsaw) region; user IP addresses may be processed by Google CDN nodes located outside the EEA.
6. Data Retention Periods
- Form data (Salesforce CRM): a maximum of 2 years from the date of form submission, or until consent is withdrawn — whichever occurs first.
- Contact form data (Google Workspace / Gmail): for the period necessary to handle the enquiry and provide a response, and thereafter until the expiry of any potential claims or withdrawal of consent. The Controller will respond within one month of receiving the enquiry.
- Pseudonymous analytics data (Google Analytics 4): 14 months (configured in the GA4 admin panel).
- Firebase Hosting access logs: in accordance with the Google Cloud Platform log retention policy (typically up to 30 days unless configured otherwise).
- reCAPTCHA data:in accordance with Google's privacy policy.
- Cookie preferences (localStorage teamco_cookie_consent): until manually cleared by the user or changed in the cookie settings.
- UTM parameters and click identifiers (sessionStorage): until the browser tab is closed.
7. Your Rights as a Data Subject
Under GDPR (Art. 15–22), you have the following rights:
- Right of access (Art. 15) — the right to obtain information about what data we process and on what basis.
- Right to rectification (Art. 16) — the right to request correction of inaccurate or completion of incomplete personal data.
- Right to erasure (Art. 17)— the "right to be forgotten"; you may request deletion of your data, e.g., after withdrawing consent or when data is no longer needed for the purpose it was collected.
- Right to restriction of processing (Art. 18) — you may request restriction of processing of your data in certain circumstances.
- Right to data portability (Art. 20) — the right to receive your data in a structured, commonly used format and transfer it to another controller.
- Right to object (Art. 21)— the right to object to processing based on the Controller's legitimate interest.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. For cookies — use the "Cookie settings" option in the website footer or clear your browser data.
- Right to lodge a complaint (Art. 77) — you have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland; www.uodo.gov.pl.
To exercise any of the above rights, please contact the Controller at: hello@teamcoandfriends.org. The Controller will respond within 30 days of receiving your request.
8. Data Security
The Controller applies appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction:
- Encryption of data in transit using TLS/SSL (HTTPS certificate).
- Two-factor authentication (2FA) on administrative accounts of systems that process personal data.
- Regular software updates and access-control policies to minimise the risk of unauthorised access.
- Brand fonts (Megabyte) are self-hosted on Firebase Hosting — they are not loaded from external CDNs (Google Fonts, Adobe Fonts), eliminating additional data transfers to third parties.
9. Automated Decision-Making and Profiling
The website does not use automated decision-making, including profiling within the meaning of Art. 22 GDPR, that produces legal effects or similarly significantly affects individuals.
UTM parameters and click identifiers (gclid, fbclid) are used solely for campaign attribution within the CRM system — they are not used for behavioural profiling or ad targeting by this website.
10. Links to External Websites
The website contains links to external social media services (Instagram, Facebook, LinkedIn, YouTube). These links open the pages of third-party providers in a new tab — the Controller is not responsible for those providers' privacy policies. The website does not embed any widgets, pixels, or tracking scripts from social media platforms — only plain HTML links are used.
11. Changes to This Privacy Policy
The Controller reserves the right to amend this Privacy Policy. Any changes will be published on this page with an updated effective date. In the event of material changes affecting the way personal data is processed, users will be informed in a manner appropriate to the circumstances. We recommend checking this page regularly.
Last updated: 28 July 2026 (Version 1.1)
