sysadmin.express ← Back

Privacy Policy

Last updated: July 11, 2026.

This Privacy Policy (the “Policy”) explains what personal data the sysadmin.express website (the “Website”) processes and how we handle it. The Website is first and foremost a brand showcase, so the processing of personal data is kept to a minimum: for the most part, personal data comes into play only when you reach out to us yourself—through the free audit request form or by email.

1. Who processes your data

The data controller—the person who determines the purposes and means of processing personal data on the Website—is Oleksandra Rovnianska, a sole proprietor (jednoosobowa działalność gospodarcza, Poland), ul. Cumowników 75, 80-299 Gdańsk, Poland; NIP 6793311501, REGON 529865182. For any matter concerning personal data, please write to service@sysadmin.express.

In Ukraine, the Sysadmin.Express brand is represented by the private entrepreneur (FOP) Oleksii Rovnianskyi (Kyiv). This brand representation does not change the fact that the data controller for the Website is the entity named above. In the rest of this Policy, “we” refers to the controller.

The data controller is registered in Poland, a European Union country, so this Policy is based on the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679). The competent supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw, Poland. The Website is also aimed at visitors from Ukraine, so for residents of Ukraine the Law of Ukraine “On Personal Data Protection” additionally applies—see section 7 for their rights and the supervisory authority in Ukraine.

2. What data we process, and why

The Website is built around the principle of data minimization. We process the following categories of data:

— Cookies and local storage. The Website uses a single functional cookie, lang, which remembers the language you selected yourself with the switcher and lasts up to a year. Your browser’s local storage holds only your pricing preferences (currency, region). Source markers (UTM tags, referring site, landing page) are not stored in your browser at all — they are read from the page address at the moment you submit a request and reach us together with it. None of this identifies you personally, and none of it travels beyond your browser and our server.

— Free audit request form. The Website includes a form you can use to request a free audit. It has two required fields—your name and email address; optionally, you can add a phone number, the approximate size of your company, and a short free-form description of your task. To make sure the email address is really yours, we send a 6-digit confirmation code to it—a double opt-in mechanism: without the code, your request never reaches us. Requests are handled by our own service, app.sysadmin.express, which runs on our infrastructure in the EU; once the code is confirmed, the request is delivered to us by email at service@sysadmin.express, and unconfirmed requests are automatically deleted after 10 minutes. Filling in the form is voluntary; the data you provide is used strictly to handle your request and to contact you about the audit, and is not shared with third parties for their own purposes.

— Billing-details request form. The Website also includes a form you can use to request our payment details (IBAN) for settling invoices. It has two required fields—your company name and email address; optionally, you can add a phone number. As with the audit form, to make sure the email address is really yours, we send a 6-digit confirmation code to it—a double opt-in mechanism: without the code, your request never reaches us. These requests are handled by the same service, app.sysadmin.express, which runs on our infrastructure in the EU; once the code is confirmed, the request is delivered to us by email at service@sysadmin.express, and unconfirmed requests are automatically deleted after 10 minutes. Filling in the form is voluntary; the data you provide is used strictly to handle your request and send you the details, and is not shared with third parties for their own purposes. The legal basis, retention periods, and your rights for this data are the same as for the audit request form (see sections 3, 4, and 6).

— Email correspondence. If you write to us at service@sysadmin.express, we receive your email address, your name (if you provide it), and the content of your message—exactly as much as we need to reply to you.

Beyond what is described above, the Website uses no advertising or tracking cookies and collects no data for profiling. Anonymized visit statistics (page, country, device type) are gathered by our own analytics system, Umami, running on our server: no cookies, no personal identification, no sharing with anyone. That is exactly why the Website has no cookie banner—the law requires consent only for tracking, and there is none here.

The Website is hosted by Hetzner Online GmbH (Falkenstein, Germany, EU). As with most websites, the hosting infrastructure may automatically record limited technical information in server logs (such as IP address, browser type, and the date and time of each request) in order to operate, secure, and maintain the Website. Where this involves personal data, the legal basis is our legitimate interest in the security and stability of the Website (Article 6(1)(f) GDPR). The logs are retained for a short period and are not used for profiling.

3. Legal basis for processing

— Hosting server logs—our legitimate interest in keeping the Website secure, stable, and operational (Article 6(1)(f) GDPR).

— Audit request form—the processing is necessary to take steps at your request prior to entering into a possible contract (Article 6(1)(b) GDPR). The confirmation code is part of that same process: it merely verifies that the email address belongs to you and protects against requests submitted in someone else’s name.

— Email correspondence—our legitimate interest in handling your inquiry and responding to it (Article 6(1)(f) GDPR).

4. How long we keep your data

— An unconfirmed form request (where the code is never entered) is automatically deleted after 10 minutes.

— Data from a confirmed audit request is kept while we handle your inquiry and for a reasonable period afterward—as a rule, up to 12 months—after which it is deleted unless there is another legal basis for keeping it (for example, a concluded contract).

— Correspondence is kept for as long as needed to handle your inquiry and for a reasonable period afterward—up to 12 months—after which it is deleted unless there is another legal basis for retention.

— Hosting server logs are retained for a short period (see section 2).

5. Do we share your data with third parties

No. We do not sell, transfer, or disclose your data to third parties for advertising, marketing, or analytics purposes.

The Website and the request-processing service app.sysadmin.express run on our own infrastructure at Hetzner Online GmbH (Falkenstein, Germany, EU). Email may be provided by service providers acting as processors: they process data solely on our behalf, to the minimum extent necessary, and in accordance with our instructions. If such a provider processes data outside the EEA, the transfer takes place on the basis of a European Commission adequacy decision (the EU-US Data Privacy Framework) or standard contractual clauses (SCC). If you are a resident of Ukraine, your data is stored on servers within the EEA.

Our entire team with access to personal data works within the European Union — data is not transferred outside the EEA for processing by our own people. For physical work on equipment (installation, cabling, replacement of components) we may engage local contractors: they handle the hardware only and are not granted access to clients' systems, accounts or data.

6. Your rights

Under the GDPR, you have the right:

— to access your personal data and obtain a copy of it (Article 15);

— to have inaccurate data rectified and incomplete data completed (Article 16);

— to have your data erased (the “right to be forgotten”) where there are no grounds for keeping it (Article 17);

— to restrict processing in the cases provided for by the Regulation (Article 18);

— to data portability: to receive the data you have provided in a structured, commonly used, machine-readable format and to transmit it to another controller (Article 20);

— to object to processing based on our legitimate interest (Article 21);

— to lodge a complaint with a supervisory authority (Article 77). The authority competent for us is the President of the Personal Data Protection Office (Prezes UODO), ul. Stawki 2, 00-193 Warsaw, Poland; you may also contact the supervisory authority in the EU/EEA country where you live or work.

We do not make decisions about you based solely on automated processing, and we do not carry out profiling (Article 22).

To exercise any of these rights, write to us at service@sysadmin.express. We will respond without undue delay—at the latest within one month (Article 12).

7. For residents of Ukraine

If you are a resident of Ukraine, the Law of Ukraine “On Personal Data Protection” additionally applies to the processing of your data. Among other things, it gives you the right to know the sources from which your data was collected, where it is kept, and the purpose of its processing; the right to access it; the right to demand that it be corrected or destroyed if it is processed unlawfully or is inaccurate; and the right to object to processing and to withdraw consent where processing is based on it. You may lodge a complaint about the processing of your personal data with the Ukrainian Parliament Commissioner for Human Rights or with a court. For any of these rights, use the same contact: service@sysadmin.express.

8. Data security

We take reasonable organizational and technical measures to protect data against unauthorized access, loss, or disclosure: connections to the Website and to the request service are encrypted (HTTPS), and access to requests and email is limited to a small circle of people. Since the Website processes minimal data, the associated risks are low.

9. Changes to this Policy

We may update this Policy from time to time. The current version is always available on this page; the date of the last update is shown at the top.

For any matter concerning personal data: service@sysadmin.express.