Privacy policy
Last Updated: 30 July 2026
1. Introduction
This Privacy Policy describes the rules for processing personal data and the use of cookies on the website www.atp-aviation.com, operated by AT-P Aviation Sp. z o.o.
We respect your privacy and ensure that personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR).
2. Data Controller
The controller of your personal data is:
AT-P Aviation Sp. z o.o.
ul. Poligonowa 1/2
04-051 Warsaw, Poland
Email (data protection matters): info@atp-aviation.com
The Controller has not appointed a Data Protection Officer (DPO/IOD) because there is no legal obligation to do so under Article 37 GDPR.
3. Scope of Data Collection
3.1 Data Provided Voluntarily by the User
Contact Form
When contacting us via the contact form, we process:
- first and last name,
- email address,
- phone number (optional),
- message content.
Providing data is voluntary but necessary to receive a response.
Newsletter Subscription (MailerLite)
When subscribing to the newsletter, we process:
- email address,
- information confirming consent,
- technical data related to subscription confirmation.
Providing an email address is voluntary but necessary to receive the newsletter.
3.2 Automatically Collected Data (Technical Data)
When visiting the website, the following may be collected automatically:
- IP address (shortened/anonymized),
- browser type and version,
- operating system,
- website activity data,
- pages visited and time spent on the website.
4. Purposes and Legal Basis for Processing
Personal data is processed based on Article 6 GDPR:
4.1 Contact Handling
Purpose: responding to inquiries.
Legal basis:
- Art. 6(1)(f) GDPR – legitimate interest of the Controller (general contact),
- Art. 6(1)(b) GDPR – taking steps prior to entering into a contract (business or offer inquiries).
4.2 Newsletter
Purpose: sending newsletters and marketing information.
Legal basis:
- Art. 6(1)(a) GDPR – consent.
Consent may be withdrawn at any time.
4.3 Website Analytics
Purpose: analyzing traffic and improving website functionality using Google Analytics 4.
Legal basis:
- Art. 6(1)(a) GDPR – user consent expressed via cookie banner.
4.4 Legal Obligations
Purpose: compliance with applicable laws.
Legal basis:
- Art. 6(1)(c) GDPR.
5. Cookies and Analytics Technologies
Cookies are small text files stored on your device. The website uses the following types:
Necessary Cookies
Required for proper website functioning and security.
Example:
- session cookies.
These cookies do not require consent.
Analytical Cookies (Google Analytics 4)
Used only after user consent. Google Analytics helps us understand how users interact with the website.
Features:
- IP anonymization is applied automatically,
- data retention occurs in accordance with Google Analytics settings,
- data is processed in aggregated statistical form.
You can withdraw consent at any time via cookie settings.
Presentation Access Cookies
Used only on the individual presentation pages described in section 6. They store confirmation that a correct password was entered and recognise a device that has already opened a given presentation.
Features:
- they contain no personal data, only a value derived cryptographically from the page identifier,
- the password cookie expires together with the password it was issued for, and never later,
- they are necessary for the security and correct operation of those pages, and therefore do not require consent.
6. Individual Presentation Pages
We share business and investor presentations through individual pages hosted on this website, available at addresses in the form of atp-aviation.com/p/{code}. Each recipient receives a separate address that cannot be guessed, and these pages are excluded from search engine indexing and from the sitemap.
6.1 Data Processed
In connection with an individual presentation page we process:
- the name of the recipient and of their organisation, as entered by us when the page is created,
- the date and time of each visit,
- the time spent on the page,
- a shortened (anonymised) IP address,
- the approximate location derived from that address, limited to city and country,
- the device type and browser,
- the source from which the page was opened (referrer).
We do not record which slides were viewed or for how long. The presentation itself is displayed by Canva and is governed by Canva’s own privacy policy.
6.2 Purpose and Legal Basis
Purpose: keeping control over confidential business materials, confirming that a presentation reached the intended recipient, identifying situations in which a link has been passed on to third parties, and assessing interest in the subject of the conversation.
Legal basis: Art. 6(1)(f) GDPR, the legitimate interest of the Controller in protecting confidential business information and in managing an ongoing business relationship. These pages are not part of general website analytics and are not used for marketing purposes.
6.3 Access Protection
An individual page may additionally be protected by a password, by an expiry date, or by a limit on the number of devices from which it may be opened. Where a password is used, we record the moment it was first entered correctly, in order to apply the validity period of that password.
6.4 Retention
Visit records are kept for 12 months from the date of the visit and are deleted afterwards. A full IP address is never stored: only its shortened form is retained, together with the city and country determined from it.
7. Newsletter Provider – MailerLite
Newsletter services are provided by MailerLite, acting as a data processor. MailerLite processes data solely on our instructions and in accordance with GDPR requirements.
8. Data Recipients
Personal data may be shared with trusted service providers, including:
- hosting providers,
- IT support and website administrators,
- MailerLite (newsletter delivery),
- Google (analytics services),
- Canva (display of presentations embedded on individual pages),
- an IP geolocation provider, used solely to determine the city and country of a visit to an individual presentation page.
Data is shared only to the extent necessary to provide services.
9. International Data Transfers
Some providers (e.g., Google, MailerLite, Canva) may process data outside the European Economic Area, including the United States.
Transfers are based on:
- the EU-US Data Privacy Framework (DPF), or
- other safeguards approved by the European Commission.
10. Data Retention Period
Personal data is stored only as long as necessary:
- Contact inquiries – for the duration of correspondence and up to 12 months after completion,
- Newsletter data – until consent is withdrawn,
- Analytical data – in accordance with Google Analytics settings,
- Visit records for individual presentation pages – 12 months from the date of the visit,
- Data processed under legal obligations – for periods required by law.
11. Social Media Profiles
The Controller maintains profiles on:
- LinkedIn,
- Facebook,
- Instagram.
The website contains only links redirecting users to these platforms. Clicking a link transfers the user to external services governed by their own privacy policies. The Controller does not transfer data to these platforms automatically.
12. Profiling and Automated Decision-Making
Data collected through analytics tools may be used for statistical analysis and improving website usability.
The Controller:
- does not perform profiling producing legal effects,
- does not make automated decisions within the meaning of Article 22 GDPR.
13. Obligation to Provide Data
Providing personal data is voluntary, but:
- necessary to receive a response via the contact form,
- necessary to subscribe to the newsletter.
Failure to provide data may prevent service delivery.
14. Data Subject Rights
You have the right to:
- access your data,
- rectify data,
- erase data,
- restrict processing,
- object to processing,
- withdraw consent at any time,
- data portability (where applicable).
Requests may be sent to: info@atp-aviation.com
You also have the right to lodge a complaint with:
President of the Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland.
15. Security Measures
We implement technical and organizational safeguards including:
- SSL encryption,
- restricted access to data,
- secure hosting infrastructure.
16. Changes to This Privacy Policy
The Controller may update this Privacy Policy. The current version is always available on this website with an updated revision date.
