ALM Legal
Privacy policy
Last updated: 23 August 2026
1. Controller
The controller of personal data is Aleksandra Łucja Musielewicz, attorney-at-law, practising as ALM Legal. For data protection matters, write to a.musielewicz@almlegal.pl.
2. Enquiries and correspondence
Enquiries are taken through the contact form on the homepage and through the consultation request. In the contact form we process your name, email address, optionally a company or role, and the message, in order to reply. In the consultation checkout we also process the chosen format and length, a matter category and a short outline of the context, in order to assess whether the matter can be accepted and agree the terms of any engagement.
The legal basis is taking steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR) and, where relevant, the controller’s legitimate interest in handling correspondence and defending against claims (Article 6(1)(f) GDPR).
Submitting a request does not mean the matter has been accepted, that legal advice has been given, or that a contract has been formed. Do not send confidential documents or information about urgent procedural deadlines.
3. Consultation requests and booking
In the consultation checkout we process the chosen format and length of the conversation, your name, email address, optionally a phone number and company or role, a general matter category and a short outline of the context. We do not ask for documents, PESEL or special-category data. The data is used to assess whether the matter can be accepted, to share an available time and to create the booking.
Rejected, expired and inactive requests are intended for deletion no later than after 12 months, subject to a shorter period where the data is no longer needed, and to exceptions required to establish, exercise or defend legal claims. Final retention will be confirmed before production go-live.
4. Recipients and providers
To the extent necessary, technical data or the content of correspondence may be processed by providers supporting the website and email:
- Cloudflare — DNS, proxy, site protection, Turnstile and aggregated Web Analytics;
- Outsider (Mikrus / DirectAdmin) — domain mailboxes and SMTP delivery of consultation confirmations;
- the Mikrus hosting provider — server operation and technical logs;
- Google — the firm’s email; font files are hosted locally and the browser does not need to connect to Google Fonts;
- Google Calendar — availability and a private event with the neutral title “Konsultacja”, without the matter category;
- n8n and PostgreSQL — acceptance automation, secure storage of process state, hashed tokens and slot locking;
- Autopay — settlement of the consultation reservation fee (amount, email and order identifier);
- UptimeRobot — external checks of public site addresses.
We do not sell data and we do not use the form for marketing. If a provider processes data outside the European Economic Area, the transfer uses GDPR mechanisms, in particular standard contractual clauses or an adequacy decision of the European Commission.
5. Retention
Messages that do not lead to an engagement are as a rule kept for no longer than 12 months after correspondence ends, unless earlier deletion is possible or longer storage is needed to establish, exercise or defend legal claims. Data related to a concluded contract is kept for the period required by law and the professional rules for attorneys-at-law.
Consultation booking state is stored in PostgreSQL. The server may keep limited technical logs needed for security and diagnostics.
6. Analytics, Turnstile and browser storage
If Cloudflare Web Analytics is enabled, it provides aggregated statistics without visitor profiling. The analytics script does not load until you accept cookies.
Cloudflare Turnstile analyses technical signals needed to distinguish a person from an automated program. It may set strictly necessary security cookies. The verification result is checked on the server before a form is sent.
The site stores theme, language and cookie choice in localStorage. We do not use advertising cookies. The site does not publish an office address or phone number until they are confirmed for a Google Business Profile.
7. Rights
Within the limits of the GDPR you have the right of access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interest.
You may also lodge a complaint with the President of the Personal Data Protection Office in Poland.
8. Security and changes
We apply technical measures that limit access to the form and the data, including HTTPS, anti-bot verification, request limits and separation of the form service from the site publishing mechanism.
This policy may be updated when the site’s functions, providers or legal requirements change. The current version is always available at this address.
This document describes the technical configuration being deployed on the site. The final retention period, legal basis and transfer information should be approved by the firm’s principal before the form goes live.