Privacy Policy

Last updated: 19 August 2026

This policy fulfils the information duties under Art. 13 and Art. 14 of Regulation (EU) 2016/679 (GDPR) and takes account of the Polish Act of 18 July 2002 on the provision of services by electronic means, the Polish Personal Data Protection Act of 10 May 2018, and Art. 398 of the Polish Electronic Communications Law of 12 July 2024.

1. Controller and contact

The controller of personal data is LW IT Solutions Company Lukas Wójcik, al. Tadeusza Kościuszki 80/82 lok. 301, 90-437 Łódź, Poland, NIP PL7252266190. Contact for data protection matters: the e-mail address given in the imprint or the contact form.

We have not appointed a data protection officer, because none of the conditions in Art. 37(1) GDPR applies. All data protection matters are handled directly by the controller.

2. Principles we follow

  • Data minimisation. We collect only what the service needs (Art. 5(1)(c) GDPR).
  • Shortened IP addresses. We do not store IP addresses in full. Before storing, we shorten them: for IPv4 the last byte is dropped, for IPv6 everything from the fourth block onwards. The stored address therefore identifies a network, not a connection (Art. 25(1) GDPR, data protection by design).
  • Storage limitation. All data is deleted automatically within the periods in section 14 (Art. 5(1)(e) GDPR).
  • No profiling by us. We build no user profiles and take no automated decisions with legal effect (section 17).

3. Server logs

When a page is requested we store: shortened IP address, browser identifier (user agent), the address requested, the referring page, the language and a timestamp.

Purpose: technical operation, fault diagnosis, abuse prevention and security of the service. Legal basis: Art. 6(1)(f) GDPR – our legitimate interest in secure and functioning operation; additionally Art. 18(5)(1) of the Act on the provision of services by electronic means, which permits the provider to process data characterising how the service is used. Period: 90 days, after which entries are deleted automatically.

We generally do not log automated traffic (bots, scanners); search engine crawlers are the exception, since we need them to judge visibility. This substantially reduces the volume of data stored.

4. Open mailboxes and incoming messages

The service accepts e-mails addressed to freely chosen aliases on the domain getsend.xyz and displays them without login. We store the sender address, the recipient address, the subject, the body and any attachments.

Purpose: supplying the service described in section 3 of the terms of service. Legal basis: Art. 6(1)(b) GDPR – necessity for performance of the contract for the electronic supply of the service. Period: 7 days at most; sooner if you delete the message yourself.

Important: mailboxes are not password-protected. Anyone who knows or guesses the alias can read the messages addressed to it. Do not use the service for confidential content or for special categories of personal data within the meaning of Art. 9 GDPR. Details are in section 7 of the terms of service.

4.1 Data of senders who are not our users

An incoming message contains personal data of a sender that we did not obtain from that sender. Under Art. 14 GDPR we inform you as follows:

  • Source: the body and headers of the e-mail the sender transmitted through the public e-mail network to an alias on our domain.
  • Categories of data: sender address, sender name, subject, message body, attachments and technical header data.
  • Purpose and legal basis: delivery to the recipient who chose the alias – Art. 6(1)(f) GDPR, the legitimate interest of sender and recipient in the correspondence reaching its destination.
  • Period: as in section 4.
  • No individual notification: we do not notify senders individually. Given the number of messages and their seven-day retention, doing so would involve disproportionate effort, and the notification itself would be a further e-mail to a person who did not ask for one. We rely on the exemption in Art. 14(5)(b) GDPR and make this information publicly available here.

4.2 Record of the acceptance

Before we show you a mailbox for the first time in a session, we ask you to confirm the five points in section 8 of the terms of service. We record that confirmation so that we can demonstrate it.

  • Scope: date and time, the language of the version shown, the version label of the terms, and the identifier of the alias being opened at the time. No IP address and no browser identifier – they are not needed to prove the confirmation, and they would be the longest-stored data in the whole service.
  • Purpose and legal basis: demonstrating that the deviations were accepted expressly and separately, as Art. 43k(5) of the Polish Consumer Rights Act requires – Art. 6(1)(f) GDPR, legitimate interest in evidencing the content of the contract, and Art. 6(1)(c) GDPR to the extent that provision creates an obligation.
  • Period: for as long as the confirmation may be needed to establish, exercise or defend legal claims.

The record contains neither message content nor contact details. You choose the alias yourself; it need not identify anyone.

5. Forwarding

When you set up forwarding we store: the target address, the chosen alias, the start and end of the forwarding period, a shortened IP address, the browser identifier and the confirmation and unsubscribe codes.

Purpose: supplying the forwarding service and preventing the entry of addresses belonging to others. Legal basis: Art. 6(1)(b) GDPR for the service itself; Art. 6(1)(f) GDPR for the shortened IP address and browser identifier (abuse prevention). Period: until the chosen period expires or you unsubscribe, after which the record is deleted.

The target address must be confirmed via a verification link; without that, no forwarding runs. Every forwarded message contains an unsubscribe link.

6. Contact form and message sending

Details submitted through the contact form (name, e-mail address, subject, message) are stored together with a shortened IP address and the browser identifier so that we can deal with the enquiry. When a message is sent through the service we store the sender name, recipient address, subject, body, shortened IP address and browser identifier.

Purpose: handling the enquiry, supplying the sending service, checking before delivery, and bringing or defending claims. Legal basis: Art. 6(1)(b) GDPR (enquiry and sending) and Art. 6(1)(f) GDPR (abuse control, security, claims). Period: until the matter is closed; for data needed to defend claims, until the limitation period expires.

Outgoing messages are checked for abuse before delivery. The check consists of an automated assessment of content and metadata and, where needed, a manual review; it has no legal consequences for you other than stopping a sending that breaches the terms.

7. Cookies and access to your device

Storing information on your terminal equipment and gaining access to it is governed by Art. 398 of the Polish Electronic Communications Law, which replaced Art. 173 of the Telecommunications Law on 10 November 2024.

Without your consent we set only what is strictly necessary for the service you requested (Art. 398(3)(2) of that Law):

  • nre_sid – a session cookie assigning the chosen alias to the session; valid for up to 30 days; without it the mailbox is not found again on your next visit;
  • sound – stores the notification sound setting; valid for one year.

All other cookies, in particular Google advertising cookies, are set only after you consent (section 8). You can withdraw consent at any time through the consent management tool in the service; the lawfulness of processing before withdrawal is unaffected. You can also change cookie settings in your browser; restricting necessary cookies may make parts of the service unusable.

8. Google AdSense and consent management

This website is financed by Google advertising. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may set cookies and process usage data, including for personalising adverts and measuring their effectiveness; in that respect Google is a separate controller.

Legal basis: Art. 6(1)(a) GDPR – your consent, collected through the consented.eu consent management tool. Without your consent no adverts are served and no advertising scripts are executed: until then they are embedded as inactive and are additionally blocked by a mechanism in the page head.

You can withdraw consent at any time through the link in the consent management tool. Google information on data processing in adverts: policies.google.com/technologies/ads.

9. Google reCAPTCHA

To protect the forms against automated submissions we use Google reCAPTCHA. The IP address and interaction data are transmitted to Google in the process.

Purpose: distinguishing a human from a program, protection against spam and abuse. Legal basis: Art. 6(1)(f) GDPR – legitimate interest in protecting the service and its users against automated abuse.

10. Stats4U visitor counter

A counter from the Stats4U service, with servers in Poland, is embedded in the footer. It transmits the address visited, the referring page, your screen resolution and your IP address; country and city are derived from the IP address. Mouse movements are not recorded.

Purpose: reach measurement and visit statistics. Legal basis: Art. 6(1)(a) GDPR – your consent; the script runs only once consent has been given in the consent management tool.

11. Determining the language version

To select the language version, the IP address is compared against a database held locally on our server. No transfer to third parties takes place, and the result is kept only in the session. Legal basis: Art. 6(1)(f) GDPR – presenting the service in an intelligible language.

12. Recipients

The website runs on a server we operate ourselves. Beyond that, recipients may be:

  • an external mail provider we use for receiving and sending mail – as a processor under a contract pursuant to Art. 28 GDPR;
  • Google Ireland Limited – for advertising and reCAPTCHA, as a separate controller;
  • Stats4U – for the visitor counter;
  • public authorities – only where a duty to disclose follows from a legal provision or from a final decision or order.

We do not sell or rent data and do not pass it to third parties for marketing purposes.

13. Transfers outside the European Economic Area

Our server is located in Poland. Transfers outside the EEA may occur in connection with the Google services (advertising, reCAPTCHA), in particular to the United States. The basis for such a transfer is the European Commission adequacy decision of 10 July 2023 on the Data Privacy Framework (Art. 45 GDPR), supplemented by the standard contractual clauses adopted by the Commission (Art. 46(2)(c) GDPR). You can request a copy of the relevant safeguards from us.

14. Retention periods

  • incoming messages including attachments: 7 days;
  • uploaded attachments with no message sent: 4 days;
  • server logs: 90 days;
  • forwarding data: until the end of the chosen period or until unsubscription;
  • contact form enquiries: until the matter is closed, and where claims are possible until the limitation period expires;
  • confirmations under section 4.2: until the limitation period expires for the claims they may concern;
  • consents and records of them: until consent is withdrawn, then for as long as proof of it is needed.

Once a period expires the data is deleted permanently and is not recoverable. We keep no archive and no user-retrievable backups of message content.

15. Your rights

You have the right to:

  • access your data and obtain a copy (Art. 15 GDPR);
  • rectification (Art. 16 GDPR);
  • erasure (Art. 17 GDPR);
  • restriction of processing (Art. 18 GDPR);
  • data portability for processing based on consent or contract (Art. 20 GDPR);
  • withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand (Art. 7(3) GDPR).

Right to object. You have the right at any time to object, on grounds relating to your particular situation, to processing based on our legitimate interest (Art. 21(1) GDPR). Following an objection we will no longer process that data unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims.

A practical note: the service runs without registration and we store IP addresses in shortened form. In many cases we therefore cannot link stored data to a particular person and, under Art. 11(2) GDPR, we are not obliged to obtain additional information solely in order to identify you. To exercise your rights, please give us details that let us locate the data concerned, for example the alias and the approximate time.

16. Complaint to the supervisory authority

If you consider that we process your data unlawfully, you may lodge a complaint with the supervisory authority (Art. 77 GDPR):

Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl

You may also complain to the supervisory authority of your habitual residence or place of work.

17. Automated decision-making and profiling

We take no decisions in relation to you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22(1) GDPR. The automated check of outgoing messages serves abuse prevention only and is reviewed manually in case of doubt.

Advertising profiling may take place at Google, and only after you have consented (section 8). We ourselves build no user profiles and do not combine data from different sources into a profile.

18. Whether providing data is voluntary

Providing data is voluntary. There is no statutory or contractual obligation to provide any data, but without certain details the function concerned cannot work: no alias, no mailbox; no target address, no forwarding; no enquiry text, no answer. The only consequence of not providing data is that the function concerned cannot be used.

19. Security

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), in particular transport encryption (HTTPS/TLS), restricted server access, checks on outgoing messages, automatic deletion within the periods in section 14, and shortening IP addresses before storage.

We point out expressly, however, that mailboxes in the service are open and not password-protected, and that e-mail transport across the internet is not encrypted end to end. The measures above do not change this characteristic of the service, described in section 7 of the terms of service.

20. Changes to this policy

We update this policy when the service, the scope of processing or the legal situation changes. The version published here, bearing the date at the top of the page, is the one that applies. The policy exists in Polish, German and English; in the event of discrepancies the Polish version prevails.