Legal information

Privacy Policy

This document explains who processes personal data in connection with this website and communication with our company, for what purposes and on what legal bases, and what rights data subjects have.

Last updated: 13 September 2026

01 Data controller

The controller of personal data is:

CompanyWorld Class Engineering Team
spółka z ograniczoną odpowiedzialnością
Registered addressul. Kłodnicka 97/312
41-706 Ruda Śląska, Poland
KRS (company register)0000765847
NIP (VAT ID)6412545806
REGON382268979
Contact personGrzegorz Fudalej

For all matters relating to the processing of personal data you may contact the controller at office@wceteam.com.

The controller has not appointed a Data Protection Officer. Data protection requests are handled directly by the contact person named above.

02 What data we collect

This website is informational. It contains no contact forms, does not register users and does not sell goods online. Browsing the site requires no personal data.

Data you provide voluntarily

If you write to us by e-mail or call us, we process the data you choose to share — typically your name or company name, e-mail address or phone number, the content of your message, and any attachments you send, such as technical specifications.

Data collected automatically

Technical data recorded in server logs by our hosting provider — see the Server logs section.

03 Purposes and legal bases

We process personal data in accordance with Regulation (EU) 2016/679 (GDPR).

PurposeLegal basis
Responding to enquiries received by e-mail or phone and conducting correspondenceArt. 6(1)(f) GDPR — legitimate interest of the controller in communicating with parties interested in our offer
Preparing and negotiating an offer, concluding and performing a contractArt. 6(1)(b) GDPR — necessary for the conclusion and performance of a contract
Meeting tax and accounting obligations related to the cooperationArt. 6(1)(c) GDPR — legal obligation of the controller
Ensuring the security and correct operation of the website, fault diagnosisArt. 6(1)(f) GDPR — legitimate interest of the controller
Establishing, pursuing or defending against claimsArt. 6(1)(f) GDPR — legitimate interest of the controller

Providing data is voluntary but necessary for us to answer an enquiry or conclude a contract. We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning data subjects.

04 Retention periods

05 Recipients of data

Personal data may be disclosed only to entities we work with, to the extent necessary to run our business:

We conclude data processing agreements under Art. 28 GDPR with all processors acting on our behalf. We do not sell personal data and do not share it with third parties for marketing purposes.

06 Transfers outside the European Economic Area

The website loads external libraries and fonts from providers who may process data outside the EEA — see Cookies and third-party services. Where this happens, the transfer is based on Standard Contractual Clauses approved by the European Commission or on an adequacy decision.

Transfers related to the Amazon Ads API integration are described in section 12.

Apart from the situations described above, we do not transfer personal data to third countries or international organisations.

07 Your rights

In connection with the processing of your personal data you have the right to:

To exercise these rights, write to office@wceteam.com. We respond without undue delay and no later than one month from receiving the request.

Right to lodge a complaint

If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland.

08 Cookies and third-party services

This website sets no cookies of its own and uses no analytics or advertising tools such as Google Analytics, social media pixels or remarketing systems. We do not track user behaviour on the site.

The site does, however, load some resources from external content delivery networks. When these load, your browser connects to the provider’s server, which receives your device’s IP address and basic technical information:

ResourceProviderPurpose
Google Fonts
Inter and IBM Plex Mono typefaces
Google Ireland LimitedCorrect display of the site’s typography
cdnjs
Three.js library
Cloudflare, Inc.Three-dimensional animation on the home page

Use of these resources is based on Art. 6(1)(f) GDPR — our legitimate interest in a consistent presentation and correct operation of the website. Data processing on the providers’ side is governed by their own privacy policies.

You can block external resources through your browser settings or a blocking extension. The site will remain functional, although typography and animation may render in a simplified form.

09 Server logs

Our hosting provider automatically records technical information about each request in server logs: IP address, date and time, the resource requested, response code, volume of data transferred, browser and operating system details, and the referring page.

This data is used solely for server administration, diagnosing technical problems and ensuring security. It is not linked to specific individuals or used to identify users. The legal basis is Art. 6(1)(f) GDPR.

10 Data security

We apply technical and organisational measures appropriate to the risk, including encrypted data transmission over HTTPS, access control to our systems, and limiting access to correspondence to the minimum number of people necessary.

11 Children’s data

The website and the company’s offer are addressed to businesses and are not directed at persons under 16 years of age. We do not knowingly collect children’s personal data. If you believe such data has been provided to us, please contact us — we will delete it promptly.

12 Amazon Ads API and Login with Amazon

The controller uses the Amazon Ads API and the Login with Amazon (LwA) service to automate the management of advertising campaigns on Amazon, optimise them and report on their performance.

What our Login with Amazon application is for

The application registered by the controller in Amazon Developer is used solely to obtain authorised access to Amazon Ads advertising accounts belonging to the controller or to entities that have expressly authorised the controller to do so. The application is not publicly available and is not licensed or resold to third parties.

What data we receive during authorisation

When consent is granted in the Login with Amazon window, we receive:

We never receive your Amazon account password. Authorisation takes place on Amazon’s side; we only receive a token, which the person granting consent can revoke at any time.

What data we retrieve from the Amazon Ads API

Data categoryScope
Campaign datacampaign and ad group structure, advertised products (ASINs), keywords and targeting, budgets, bids, statuses
Performance dataimpressions, clicks, spend, sales, conversions, ACOS, TACOS, search term reports
Account dataadvertising profile identifiers, marketplaces, billing data and invoices for Amazon advertising services

This data relates to the business activity of the controller or of the authorising advertiser and generally does not constitute personal data. The Amazon Ads API does not give us access to shoppers’ personal data — we do not receive names, addresses or contact details of Amazon end customers.

Purposes and legal bases

PurposeLegal basis
Running, optimising and settling our own advertising campaigns on AmazonArt. 6(1)(f) GDPR — legitimate interest of the controller in conducting marketing activity
Managing advertising campaigns for an entity that has granted authorisationArt. 6(1)(b) GDPR — necessary for the performance of a contract
Maintaining and securing the integration, error diagnosticsArt. 6(1)(f) GDPR — legitimate interest of the controller

Use of artificial intelligence tools

Data retrieved from the Amazon Ads API may be processed using large language models and AI assistants in order to analyse campaign performance and prepare optimisation recommendations. The providers of these models act as processors under data processing agreements, and any transfer outside the European Economic Area takes place on the basis of Standard Contractual Clauses approved by the European Commission.

We do not pass access tokens or authentication credentials to AI tools. Campaign decisions are made by a human — we do not use fully automated decision-making producing legal effects for data subjects.

Retention and withdrawal of consent

Compliance with Amazon’s rules

Data obtained through the Amazon Ads API is used solely for the purposes described above and in accordance with the Amazon API License Agreement and the Amazon Data Protection Policy. We do not sell this data, do not share it with third parties for marketing purposes, and do not combine it with data from other sources in a manner inconsistent with Amazon’s policies. We do not disclose our client secret or access tokens to any external party, including agencies and tool providers.

13 Changes to this policy

We may update this policy in connection with changes in legislation, the development of the website or the deployment of new tools. The current version is always available at this address, and the date of the last update is shown at the top of the document.

Document notice

This document reflects the current operation of the website and the services described above. It should be reviewed by a lawyer or data protection adviser, particularly if the AI model provider, the integration scope or the processing arrangements change.