Legal

Privacy Policy

Last updated: May 2026

Who we are

FitOut Insider is operated by Dariusz Kubies Services, a sole trader (JDG) registered in Poland with the Central Register and Information on Economic Activity (CEIDG).

Business name: Dariusz Kubies Services NIP (tax ID): 7532202127 REGON: 544086256 Country of registration: Poland CEIDG-registered since: 24 February 2026

Data controller: Dariusz Kubies Services Contact: hello@fitoutinsider.com

We operate this website and provide PM consulting services, practitioner guides, and related digital resources primarily for the UK fit-out and construction industry.

What data we collect and why

Contact form: When you submit the contact form on this site, we collect your name, email address, and message. We use this information solely to respond to your enquiry. Lawful basis: legitimate interests (Art. 6(1)(f) GDPR / UK GDPR - responding to your direct enquiry).

Newsletter or guide updates: When you sign up to receive updates, we collect your first name and email address to notify you when new guides are published. You can unsubscribe at any time. Lawful basis: consent (Art. 6(1)(a) GDPR / UK GDPR - you opted in via the sign-up form).

Digital product purchases: When you purchase a practitioner guide, your payment is processed by Stripe. We receive your name and email address to fulfil the order. Payment card details are handled entirely by Stripe and are not stored by us. Lawful basis: performance of a contract (Art. 6(1)(b) GDPR / UK GDPR - fulfilling your purchase).

Consulting enquiries: If you book a call via Cal.com, Cal.com's privacy policy applies to that booking.

Analytics: If you accept cookies, we collect anonymised usage data via Google Analytics 4. Lawful basis: consent (Art. 6(1)(a) GDPR / UK GDPR - granted via the cookie banner on your first visit).

How we store your data

Website hosting is provided by Vercel, Inc., with servers located in the EU (Ireland). Server logs (including IP addresses) are processed by Vercel for the purpose of operating the website and protecting against abuse.

Email delivery is handled via Resend. Your data is processed in accordance with Resend's data processing terms.

Purchase records are stored in a Supabase database (hosted in the EU) to facilitate order fulfilment and support.

Who we share data with

We do not sell or share your personal data with any third party for marketing purposes. Data is shared only with the processors listed above (Resend, Stripe, Supabase, Cal.com, Vercel) to the extent required to provide the service you have requested.

How long we keep your data

Contact form submissions are retained for up to 12 months, then deleted.

Newsletter subscribers are retained until you unsubscribe.

Purchase records are retained for 7 years in accordance with applicable tax and accounting obligations.

Your rights

You have the right to: access the personal data we hold about you, correct inaccurate data, request erasure of your data (where no legal obligation requires us to retain it), restrict or object to processing, and request data portability.

To exercise any of these rights, contact hello@fitoutinsider.com. We will respond within one month.

You also have the right to lodge a complaint with the Urząd Ochrony Danych Osobowych (UODO) if you believe your data has been mishandled.

We do not engage in automated decision-making or profiling.

Supervisory authority

As a Polish-registered business, our primary supervisory authority is the Urząd Ochrony Danych Osobowych (UODO) - the Polish data protection authority.

UODO website: uodo.gov.pl

If you are based in the United Kingdom, you also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, in respect of processing that affects you as a UK resident.

UK GDPR representative

As a non-UK-established controller processing personal data of UK residents, we have assessed whether Article 27 of UK GDPR requires us to appoint a UK representative.

We are exempt from this requirement under Article 27(2)(a) of UK GDPR: our processing of UK residents' personal data is occasional, does not include large-scale processing of special category data or data relating to criminal convictions, and is unlikely to result in a risk to the rights and freedoms of natural persons.

If this assessment changes, we will appoint a UK representative and update this policy accordingly.

Cookies and analytics

This site uses the following cookies:

cookie_consent - a first-party cookie that stores your privacy preference. This is essential for the site to remember that you have accepted this notice.

If you accept cookies, we also load Google Analytics 4 (GA4). GA4 sets the following cookies: _ga (expires 2 years - distinguishes unique users) and _ga_FR2TKJRN9T (expires 2 years - stores session state for GA4). These cookies collect anonymised information about how visitors use this site - including which pages are visited, how long visitors stay, and what country they are in. IP addresses are anonymised before being sent to Google. No data is shared with advertising networks.

Google Analytics data is processed by Google LLC in accordance with Google's privacy policy (policies.google.com/privacy). You can opt out of Google Analytics across all websites by installing the Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout).

If you do not accept cookies, Google Analytics is not loaded and no tracking takes place.

You can clear your cookies at any time through your browser settings. Doing so will cause the cookie notice to reappear on your next visit.

CookiePurposeTypeLifespan
cookie_consentStores your cookie consent choiceFirst-party1 year
_gaGoogle Analytics - distinguishes usersThird-party (Google)2 years
_ga_FR2TKJRN9TGoogle Analytics - session persistenceThird-party (Google)2 years

International data transfers

We are based in Poland (EU) and process most data within the EU. Some of our service providers process data in the United States.

Stripe, Inc. is based in the United States. Stripe processes payment data under Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework.

Resend, Inc. is based in the United States. Resend processes email delivery data under Standard Contractual Clauses.

Google LLC (Google Analytics) is based in the United States. Google processes analytics data under Standard Contractual Clauses and participates in the EU-US Data Privacy Framework where applicable.

Vercel, Inc. provides website hosting with servers in the EU (Ireland). Vercel processes hosting and server log data within the EEA; no international transfer outside the EEA applies.

All transfers are safeguarded by appropriate mechanisms as required under GDPR Article 46 and UK GDPR Article 46.

Changes to this policy

We may update this policy from time to time. The date at the top of this page shows when it was last updated.