Privacy policy

Last updated: 3 August 2026

What this policy covers — and what it does not

This policy describes how CRE8EVE Sp. z o.o. processes personal data of people who visit postvow.eu or contact us by email. It is written to satisfy Articles 13 and 14 of the GDPR (Regulation (EU) 2016/679).

It is NOT the agreement that governs data you send through the Postvow service. When you send transactional email through Postvow, you are the controller and we are your processor — that relationship is governed by a separate Data Processing Agreement, including its Annex 3 subprocessor list. Ask for it at hello@postvow.com; we send it before, not after, you sign anything.

Controller and contact point

The controller is CRE8EVE Sp. z o.o., Tulipanowa 4, 72-003 Dobra, Poland, KRS 0000912669, NIP 8513262229, REGON 389506637.

We have not appointed a Data Protection Officer, because we are not required to under Article 37 GDPR. Instead, data-protection matters — including requests to exercise your rights — go to hello@postvow.com, which is monitored by the management board.

What we collect

This website is a set of static files. It sets no cookies, runs no analytics, embeds no fonts, scripts, videos or widgets from third parties, and makes no network request to any host other than the one serving the page. There is nothing here to consent to, and no consent banner, because there is nothing that would require consent under Article 5(3) of the ePrivacy Directive.

There is also no contact form. That is deliberate: a form is a processing operation on a public surface, and we would rather not run one until we need it.

Two categories of data therefore exist:

  • Server request logs, generated by our hosting provider when your browser requests a page: IP address, timestamp, requested URL, HTTP status, user agent, and referrer. We do not maintain our own copy or archive of these logs, and we do not use them to build any profile of you.
  • The content of email you choose to send us: your address, your name if you give it, and whatever you write, plus the correspondence history of the matter.

Why we process it, and on what legal basis

Each purpose has one basis, and we name it:

  • Delivering the website and keeping it available and secure — including detecting and mitigating attacks and abuse. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in the security and availability of our own service.
  • Answering your email and having the resulting conversation. Legal basis: Article 6(1)(b) GDPR where the exchange is about entering into or performing a contract with you, and otherwise Article 6(1)(f) GDPR, our legitimate interest in responding to people who contact us.
  • Meeting statutory retention and accounting duties where correspondence becomes part of a commercial record. Legal basis: Article 6(1)(c) GDPR.

Who receives the data

Our hosting and DNS provider processes request logs on our behalf, as a processor under Article 28 GDPR. Our email provider processes correspondence you send us, likewise as a processor.

We publish the full subprocessor list for the Postvow service, including processing location and scope, and we keep it consistent with Annex 3 of the customer DPA. We do not sell personal data, and we do not share it for advertising.

Beyond that, we disclose data only where a competent authority compels us under applicable law.

Transfers outside the EEA

The infrastructure that runs the Postvow service, and that processes email content, is located in the European Union (Germany).

One provider in the path is not: Cloudflare, a US company, provides DNS, the edge that serves these static pages, and the authenticated tunnel to our operator console. That means a US entity is technically capable of being addressed under the US CLOUD Act. We state this plainly rather than bury it, because a sovereignty claim that omits its own exception is not a sovereignty claim. Transfers to that provider take place under Article 46 GDPR safeguards, namely the Standard Contractual Clauses contained in the provider's data processing addendum.

Our mail records are configured DNS-only (not proxied), so this provider does not terminate TLS for email traffic. The subprocessor page sets out exactly what it does and does not see.

How long we keep it

Server request logs: retained by the hosting provider for a short, provider-defined period for security and abuse purposes; we do not extend it and we keep no separate archive.

Email correspondence: kept for as long as the matter requires, and afterwards for the period of the applicable statutory limitation and accounting-retention periods, after which it is deleted.

Your rights

Under the GDPR you have the right to:

  • access your data and obtain a copy (Article 15);
  • have inaccurate data corrected (Article 16);
  • have data erased (Article 17);
  • have processing restricted (Article 18);
  • receive your data in a portable, machine-readable format where processing is based on consent or contract and is carried out by automated means (Article 20);
  • object to processing based on our legitimate interest, on grounds relating to your particular situation (Article 21).

Exercising your rights, and complaining

Write to hello@postvow.com. We answer within one month of receiving the request, as required by Article 12(3) GDPR; if a request is complex we may extend that, and we will tell you why within the first month.

If you believe we are processing your data unlawfully, you can lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland. You may also complain to the supervisory authority of your own EU Member State of residence or workplace.

Automated decision-making

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR.

Changes to this policy

If we change this policy we update the date at the top of the page. Changes that affect the Postvow service itself — in particular a new subprocessor — are handled under the DPA, with prior notice to customers and a right to object, not by silently editing a web page.