Personal data and RODO
Privacy Policy
This policy explains how personal data is handled when you use the REX.LAB website, configure an event setup, request a quote, contact our team, or use optional analytics and marketing features.
Last updated: 21 August 2026
Controller and contact details
The controller of personal data processed through this service is Rex Lab Sp. z o.o., NIP 6751791413, KRS 0001072368, REGON 527065610, with the address 60-782 Poznań, Polska, Grunwaldzka 19 / 4.24, operating under the REX.LAB brand.
Questions about personal data and requests concerning your rights can be sent to [email protected] or made by telephone at +48 (453) 366-654.
Data we process
Depending on how you use the service, we process information you provide and technical information generated when the service is used.
- Contact and business details, such as name, email address, telephone number, company, industry, and preferred contact date or time.
- Event and quote details, such as country, city, event dates, budget, message, selected equipment configuration, estimated price, and submission identifiers.
- An optional voice recording, its metadata and transcript when you choose to send a voice note.
- Attribution data actually present in the link or session: utm_source, utm_medium, utm_campaign, utm_content, and utm_term.
- Technical and security data, including IP address, browser or device user-agent, request time, service logs, cookies, consent preferences, and, where present, Facebook browser and click identifiers (_fbp and _fbc).
Purposes and legal bases
We process data only where there is a legal basis under Article 6 GDPR. You are not required to provide optional information, but the contact details marked as required are needed for us to respond to your request.
- To prepare and discuss a quote, respond to an expert-contact request, and take steps requested before entering a contract: Article 6(1)(b) GDPR.
- To operate the service, route leads, maintain business correspondence, prevent abuse, secure the website, measure service effectiveness, and establish or defend legal claims: our legitimate interests under Article 6(1)(f) GDPR, balanced against your rights.
- To meet accounting, tax, regulatory, or other legal obligations where they apply: Article 6(1)(c) GDPR.
- For optional analytics or marketing storage and related tracking where consent is required: your consent under Article 6(1)(a) GDPR. Consent can be withdrawn through cookie preferences or by contacting us, without affecting earlier lawful processing.
Lead delivery and service providers
A submitted request is processed by the REX.LAB server and may be delivered through the integrations that are configured at that time. Providers receive only the information needed for the relevant function.
- Bitrix24 may receive lead contact, company, event, configuration, quote, attribution, message, and voice-note information for CRM handling.
- Notion may receive lead and request details for internal lead management where that integration is enabled.
- Configured email infrastructure (SMTP and its hosting provider) and Telegram may carry the request to authorised REX.LAB staff as operational notifications.
- Groq may receive an optional voice-note audio file for transcription when voice transcription is configured and you use that feature.
- Hosting, infrastructure, maintenance, and security providers may process technical data needed to run and protect the service.
Analytics, UTM and Facebook identifiers
UTM parameters in the page address are stored for the browser session and included with a form request to identify its source. The site also supports consent-controlled Google Tag Manager, Microsoft Clarity, and Meta/Facebook Pixel. Their availability can depend on the current configuration.
When Meta conversion reporting is configured and marketing consent is granted, a completed lead may be reported through the Meta Conversions API using a submission or event ID, quote value and currency, IP address, user-agent, _fbp and _fbc identifiers where present, and email or telephone data transformed with SHA-256 hashing. Hashing does not make personal data anonymous. Optional analytics and marketing cookies are disabled by default until preferences are recorded, but lead-processing and server security logs are separate from cookie consent.
Retention
We retain personal data only for as long as needed to handle the request, prepare and follow up a quote, manage the resulting business relationship, maintain system security, meet legal obligations, and establish or defend claims. Data kept on the basis of consent is retained until consent is withdrawn or the relevant purpose ends, subject to overriding legal requirements.
Different systems and providers may apply different retention schedules. We determine the period using the purpose of processing, the stage of the request or business relationship, applicable legal duties, and limitation periods for claims. You may contact us for information about the period or criteria applying to your data and may request deletion where the law allows it.
Recipients and international transfers
Data may be accessed by authorised REX.LAB personnel and disclosed to CRM, collaboration, email, messaging, transcription, hosting, analytics, marketing, security, legal, and accounting providers where necessary. It may also be disclosed to public authorities where required by law.
Some providers may process data outside Poland or the European Economic Area. Where GDPR requires it, such transfers must rely on an adequacy decision, Standard Contractual Clauses, or another lawful safeguard, together with supplementary measures where appropriate. Contact us to ask about the safeguard relevant to a specific transfer.
Your rights
Subject to the conditions in data-protection law, you may request access to and a copy of your data, rectification, erasure, restriction, portability, or withdrawal of consent. You may object at any time to direct marketing and may object, on grounds relating to your situation, to processing based on legitimate interests.
You also have the right to lodge a complaint with the competent supervisory authority, including the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) in Poland. We may need to verify your identity before completing a request.
Cookies and technical logs
Necessary cookies and local or session storage support consent preferences, interface state, attribution, and essential service operation. Optional analytics and marketing technologies can be managed in the cookie settings shown on the site. Browser controls can also delete or block storage, although some features may then work differently.
The server creates technical logs for operation, diagnostics, fraud prevention, and security. These may contain IP address, user-agent, request path, timestamps, identifiers, delivery status, and error information. Please avoid putting unnecessary sensitive information in free-text messages or voice notes.
Security, updates and contact
We use technical and organisational measures appropriate to the nature of the service, including access restrictions, input validation, encrypted network connections where supported, and operational monitoring. No internet service can guarantee absolute security.
This policy may be updated when the service, providers, or legal requirements change. The current version and its update date will remain available at /privacy. For any privacy question or rights request, contact [email protected].
Privacy contact
Contact REX.LAB to ask how your data is used or to exercise a data-protection right.