Skip to main content

GDPR and cookies — the basics

If you run a practice, a law firm, or a service business in Poland, sooner or later the question of GDPR and cookies comes up. Let's be upfront about who does what: we build the site and can connect technical tools to it, but we don't prepare legal documents and we don't assess whether your site meets legal requirements. That's always a job for a lawyer.

What are cookies, and why the banner?​

Cookies are small files a site saves in a visitor's browser — to remember their preferences, for instance, or to count a visit in a visitor-statistics tool. A consent banner lets the visitor accept or decline those files before anything that isn't essential to the site itself starts running.

A banner isn't a standard part of the site we build for you. If you want one, we recommend a ready-made consent management tool such as Cookiebot or CookieFirst. They work a bit like a hired doorman: they check which cookies show up on the site, ask visitors for consent, and keep a record of their choices.

You don't have to handle any of this yourself. We can create the account with the tool on your behalf, connect the banner to your site and configure it so that, for example, analytics tools only start once a visitor has given consent. Then we hand the account access over to you. One thing to say plainly: the consent tool's subscription is always paid by you. The account is yours, so you pay the provider directly, with your own card — just like your domain. Whether our work connecting the banner is already included depends on your chosen package and add-ons — see our pricing for details.

What's on you​

A few things sit entirely with you as the business owner, not with us as the site's builder:

  • your privacy policy, terms of service and any other legal documents — your lawyer prepares them, not us
  • deciding whether you need a cookie banner and what it should say
  • if you use extra tools, like a booking system or a newsletter, you decide what customer data you actually need to collect
  • you're the data controller for your customers' information — we provide the tool, but your business is legally responsible for how it's used

How to approach it in practice​

The easiest place to start is a conversation with a lawyer who knows your industry — especially if you handle sensitive data, say in a medical practice. Once they hand you your finished terms of service and privacy policy, send them over to us, and during the initial rollout we'll add them to the site before it goes live. If your lawyer recommends a consent banner, we'll connect the tool you've chosen as well.

After that, if your package includes the content editing panel, you make changes to both documents yourself — the panel has separate entries for Terms of service (Regulamin) and Privacy policy (Polityka prywatności), and you paste and format the text in the regular text editor. Your lawyer updated the policy after a change in the law? You swap in the new text and publish, without waiting on us.

We don't take responsibility for the content of those documents or for your site's legal compliance — our role is the technical implementation of what you agree with your lawyer.

Want to connect Cookiebot or CookieFirst to your site? Get in touch — we'll check what your package covers and help you set up the account, which you then pay for yourself.