GDPR and privacy

Privacy Policy

We explain what data may be processed when you contact D&V Legal Group, use the form, quiz, booking links, payments and external contact channels.

Last updated: 19 June 2026

Data safety

What not to send and what not to do

For the first contact, a description of your situation is enough. Documents and sensitive data are shared only after case qualification through a secure channel indicated by the consultant.

  • do not send a passport through the standard form
  • do not send decisions or residence cards without the consultant’s instruction
  • do not share passwords, SMS codes or banking data
  • do not share Trusted Profile, banking or government-account access
  • do not choose a path based only on citizenship
  • do not file a risky application without document analysis
  • do not treat the quiz as an office decision

If documents are needed, the consultant will indicate a secure way to provide them after case qualification.

1. Data controller

The data controller is D&V Legal Group. The public site configuration lists the contact details: contact@dvlegalgroup.pl and +48 534 702 425.

Full registration details, correspondence address and formal entity status should be confirmed before a final legal audit.

2. Contact details

For personal data matters, contact contact@dvlegalgroup.pl or call +48 534 702 425.

3. Data we process

We may process your name, e-mail address, message content, contact language, preferred messenger, inquiry source, service interest and technical data needed to operate the website.

If you choose to send the quiz result, we may receive selected answers, risk level, recommended contact scope and data needed to respond to the inquiry.

4. Purposes of processing

Data is processed to handle inquiries, prepare contact, book consultations, coordinate the process, review documents, handle payments, maintain website security and protect possible claims.

5. Legal bases for processing

The legal basis may be taking steps before a contract or performing a contract, legitimate interest in handling inquiries and website security, legal obligations, and consent if it is separately requested in the future for a separate purpose.

6. Contact form and inquiries

The contact form is used only to handle the inquiry. Providing data is voluntary, but without contact details we may be unable to respond.

7. Qualification quiz

The quiz is an initial guide. Answers are processed locally in the browser until you decide to send the result through the form.

After the result is sent, quiz data may be transferred with the inquiry to prepare a response and select the right consultation scope.

8. Calendly or consultation booking

If a booking link is active, the button may lead to an external system such as Calendly or a similar tool. After you move to that service, its own privacy and cookie rules apply.

9. Stripe and payments

Payments may be handled through external Stripe Payment Links. Payment data, such as card numbers, is processed by the payment operator, not by the standard website contact form.

10. Telegram, WhatsApp, phone and e-mail

Telegram, WhatsApp, Viber, phone and e-mail links are used for contact. After using a messenger or phone app, data may also be processed under that provider’s rules.

11. Hosting and technical providers

The website may be hosted by Vercel or a similar technical provider. The hosting provider may process basic technical data such as IP address, request time and device information to maintain website security and availability.

12. E-mail and Google Workspace

The contact mailbox may be handled by an external e-mail provider, including Google Workspace if such configuration is used. Correspondence is processed to maintain contact and handle the matter.

13. Lead API, CRM and Resend

The form uses an internal lead API endpoint. If a CRM or webhook is configured, the inquiry may be forwarded to that system.

The current code does not confirm an active Resend integration. If e-mail sending through Resend or a similar provider is connected later, this policy should be updated.

14. Recipients and processors

Recipients may include hosting, e-mail, CRM, booking, payment and messenger providers, as well as people supporting inquiry handling to the extent necessary for that purpose.

15. Transfers outside the EEA

Some external tools, such as global hosting, e-mail, payment, booking or messenger providers, may involve data transfers outside the European Economic Area. In that case, appropriate GDPR transfer safeguards should apply.

16. Retention period

We keep data for the time needed to handle the inquiry, consultation or process, and then for the period required by law or needed to protect possible claims. Data should not be stored indefinitely.

17. Data subject rights

You may request access, rectification, erasure, restriction of processing, data portability, objection to processing and withdrawal of consent if processing was based on consent.

18. Complaint to the Polish supervisory authority

If you believe your data is processed unlawfully, you may lodge a complaint with the President of the Personal Data Protection Office in Poland.

19. Voluntary provision of data

Providing data is voluntary, but without contact details we may be unable to respond. Do not send passport scans, residence decisions, residence cards or other sensitive documents through the form.

20. Data security

We use organizational and technical safeguards appropriate to the nature of the website. Decisions are issued by the competent authority, and website information does not replace an individual document review.

21. Cookies and similar technologies

The website may use technical cookies or similar technologies needed for the website to work. The current code does not confirm active analytics or marketing scripts that would require a separate consent banner.

Some buttons lead to external services such as Stripe, Calendly, Telegram or WhatsApp. After moving to an external service, its own privacy and cookie rules apply.

22. Changes to this policy

This policy may be updated, especially after changes to technical, payment, booking providers or form handling.