This is an English translation of the Polish Polityka Prywatności. In case of any discrepancy between language versions, the Polish version prevails.
1. Data controller
sole proprietor trading under the business name “High Risk Tactics Shooting-Security-Services”, registered in CEIDG (Polish Central Register and Information on Economic Activity)
Trade name: High Risk Tactics (HRT)
Address: ul. Leśna 20, Łaziska, 47-133 Jemielnica, Poland
NIP (tax ID): 7561739539 · REGON: 384041139
Tel: +48 504 329 484
E-mail: info@highrisktactics.com
Website: https://highrisktactics.com
The controller of personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) is the business identified above (“HRT” or the “Controller”). This Privacy Policy informs users of https://highrisktactics.com, as well as clients and training participants, which personal data we process, for what purposes, on what legal basis and for how long, to whom we disclose it, and what rights data subjects have (Art. 13 and 14 GDPR).
For any matter concerning personal data, you can contact the Controller by e-mail at info@highrisktactics.com or by post at the address above.
2. Purposes, legal bases and retention periods
2.1 Contact form and booking inquiries
- Data: name, e-mail address, phone number (optional), country, experience level, preferred date, selected course, message, page language.
- Purpose: answering the inquiry and preparing a booking. The data is stored in our database and sent to us by e-mail; an automatic confirmation of receipt is sent to the e-mail address provided in the form.
- Legal basis: Art. 6(1)(b) GDPR (steps taken at the data subject's request prior to entering into a contract) and Art. 6(1)(f) GDPR (the Controller's legitimate interest in answering inquiries).
- Retention: 24 months from the last contact, after which the data is deleted automatically. If a contract is concluded — as set out in point 2.6.
- E-mail correspondence: messages you send to info@highrisktactics.com and our replies are kept in our database for the same period (24 months from the message), then deleted automatically.
2.2 Newsletter
- Data: e-mail address, language, page or source of sign-up.
- Purpose: sending information about HRT courses, dates and offers. Sign-up must be confirmed by clicking a link in an e-mail (double opt-in); only after confirmation is the address added to the mailing list.
- Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with Art. 398 of the Polish Electronic Communications Law of 12 July 2024 (Prawo komunikacji elektronicznej — consent to direct marketing by e-mail).
- Retention: until consent is withdrawn. Unconfirmed sign-ups are deleted after 30 days.
- Withdrawal of consent: at any time, using the unsubscribe link included in every newsletter or by e-mail to info@highrisktactics.com.
2.3 Waitlist
- Data: name, e-mail address, phone number (optional), message, selected training date.
- Purpose: notifying you when a place becomes available on a fully booked training date.
- Legal basis: Art. 6(1)(b) GDPR (steps taken at the data subject's request prior to entering into a contract).
- Retention: deleted 12 months after sign-up.
2.4 Course reviews
- Data: name as given by the author (published), e-mail address (not published, used only to notify the author that the review has been published), rating, review text, course reviewed.
- Purpose: publishing the review on the website. Reviews are published only after moderation.
- Legal basis: Art. 6(1)(a) GDPR (consent to publication). Consent can be withdrawn at any time — the review will then be removed.
- Retention: for as long as the review is published. Reviews rejected in moderation are deleted.
2.5 Certificates
- Data: participant's name, e-mail address, course, date of issue, certificate number.
- Purpose: issuing the certificate and enabling verification of its authenticity. Anyone who knows the certificate number can verify it on the website — the name, course and date of issue are then displayed; this is the purpose of the certificate. A lookup by e-mail address sends the list of certificates only to that e-mail address — no data is displayed on screen.
- Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR (legitimate interest in enabling verification of certificate authenticity).
- Retention: for as long as the certificate may be verified: 6 years from issue (the general limitation period under art. 118 of the Polish Civil Code), after which the record is deleted automatically; you may ask us to delete it earlier.
2.6 Training contracts, bookings and invoicing
- Data: data needed to deliver the training and for settlement and accounting (in particular name, contact details, selected course and date, invoicing details, payment information).
- Purpose: concluding and performing the training contract, settlements, invoicing and keeping accounting records.
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (obligations under tax and accounting law).
- Retention: until the end of the limitation period for claims under the contract; accounting documents — 5 years from the end of the calendar year, as required by Polish tax law.
Health information. A participant may voluntarily disclose to the instructor health information relevant to safety on the range (see Training Regulations, section 3). The legal basis is explicit consent (Art. 9(2)(a) GDPR). This information is used solely for the safety of that training and is deleted after it. Consent can be withdrawn at any time.
Firearms permit and identity document data. Data on a participant's legal status, including data from a firearms permit and identity documents provided by the participant, is processed only where shooting-range rules or the law require it (in particular the Polish Firearms and Ammunition Act of 21 May 1999, Dz.U. 1999 Nr 53 poz. 549, as amended). The legal basis is Art. 6(1)(c) GDPR (legal obligation) or Art. 6(1)(f) GDPR (legitimate interest in ensuring safety and compliance with range rules). This data is kept only for the period required by those rules or regulations.
2.7 Analytics and marketing
- “Analytics” category (only after consent in the cookie banner): first-party statistics stored in our database (event name, page visited, language, random session identifier — no IP address and no name) and Cloudflare Web Analytics / Analytics Engine; Google Analytics 4 — only if enabled. Purpose: traffic statistics and improving the website. Retention of our own statistics: 90 days; Google Analytics 4 data: 14 months.
- “Marketing” category (only after consent): Meta Pixel and Google Ads conversion tracking — measuring the effectiveness of our advertising (e.g. whether an enquiry came from an ad), and with it Google Consent Mode, which passes your choice to Google.
- Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with Art. 399 of the Polish Electronic Communications Law (consent to storing information on, or accessing information stored in, the end device).
- Strictly necessary storage: remembering the choice made in the cookie banner, and the language you picked (cookie
hrt_lang, 12 months — on your first visit to the homepage it is set from your browser language), does not require consent.
2.8 Security logs
- Data: IP addresses and technical data of requests to the website, processed by the hosting provider.
- Purpose: protecting the website against attacks and abuse.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of the website).
- Retention: short, in accordance with the hosting provider's policy.
3. Voluntary provision of data; no profiling
Providing data is voluntary but necessary to answer an inquiry, sign up for the newsletter or waitlist, publish a review, issue a certificate, and conclude and perform a contract. Without the data marked as required, the relevant function cannot be used.
The Controller does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
4. Recipients of data
We do not sell personal data. Data may be disclosed to the following recipients:
- Cloudflare, Inc. (USA) — website hosting, database, file storage, e-mail routing, protection and security of the website, statistics (Cloudflare Web Analytics / Analytics Engine).
- Resend (USA) — sending e-mails: confirmations, notifications, replies to inquiries and the newsletter.
- Google (Google Ireland Ltd. / Google LLC) — Gmail mailbox receiving forwarded e-mail; Google Fonts (fonts loaded from Google servers); Google Analytics 4 and Google Ads conversion tracking — only if enabled and only after consent (“Analytics” and “Marketing” respectively).
- Meta Platforms Ireland Ltd. — Meta Pixel, only after consent in the “Marketing” category.
- Accounting office and legal advisers — to the extent necessary for their tasks.
- Public authorities — only where disclosure is required by law.
Processors acting on the Controller's behalf do so under data processing agreements (Art. 28 GDPR).
5. Transfers outside the European Economic Area
Using the services of Cloudflare, Inc., Resend, Google LLC and Meta (as regards transfers by Meta Platforms Ireland Ltd. to the USA) may involve transferring data to the United States. Such transfers are based on the European Commission's adequacy decision under the EU-US Data Privacy Framework — for recipients certified under that framework — and otherwise on the standard contractual clauses adopted by the European Commission (Art. 46(2)(c) GDPR). Information on the safeguards applied can be obtained by contacting the Controller.
6. Cookies and similar technologies
On your first visit, a cookie banner is displayed in which you decide on consent for each category:
- Necessary — remembering the choice made in the banner. Always active; no consent required.
- Analytics — the statistics described in point 2.7. Activated only after consent.
- Marketing — Meta Pixel, Google Ads conversion tracking. Activated only after consent.
Without consent, analytics and marketing scripts are not loaded. You can change or withdraw your consent at any time using the “Cookie settings” link in the footer of every page. Withdrawal does not affect the lawfulness of processing carried out before it. You can also delete cookies in your browser settings.
7. Your rights
Under the conditions set out in the GDPR, every data subject has:
- the right of access to their data and to obtain a copy (Art. 15 GDPR);
- the right to rectification (Art. 16 GDPR);
- the right to erasure (Art. 17 GDPR);
- the right to restriction of processing (Art. 18 GDPR);
- the right to data portability (Art. 20 GDPR);
- the right to object (Art. 21 GDPR) — to processing based on the Controller's legitimate interest, on grounds relating to the data subject's particular situation; the right to object to processing for direct marketing purposes applies in every case and is always respected;
- the right to withdraw consent at any time (Art. 7(3) GDPR), without affecting the lawfulness of processing based on consent before its withdrawal.
Requests should be sent to info@highrisktactics.com or by post to the Controller's address. We respond without undue delay and in any event within one month of receiving the request; where necessary, this period may be extended by a further two months, in which case you will be informed. Exercising your rights is free of charge. The Controller may ask for information necessary to confirm the requester's identity.
You have the right to lodge a complaint with the supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office), ul. Stawki 2, 00-193 Warszawa, Poland.
8. Data security and breaches
The Controller applies technical and organisational measures appropriate to the risk, in particular encrypted connections (TLS) and access to the administration panel restricted to authorised persons only.
A personal data breach likely to result in a risk to the rights and freedoms of natural persons is reported to the President of the Personal Data Protection Office within 72 hours of becoming aware of it (Art. 33 GDPR). Where a breach is likely to result in a high risk, the Controller informs the data subjects without undue delay (Art. 34 GDPR).
9. Changes to this Privacy Policy
The current version of this Privacy Policy is published on this page together with the date of the last update.
Data protection questions: info@highrisktactics.com