Privacy policy.
Last updated: 3 October 2026
This notice explains how personal data is handled when you visit naais.tech or contact NAAIS. It covers website enquiries and related correspondence.
Who is responsible
Piotr Chrzanowski, the founder operating this website under the NAAIS name, is the data controller responsible for the purposes and handling of your personal data. NAAIS is not currently an incorporated company. For privacy questions, requests or complaints, contact Piotr at:
What we collect
When you submit an enquiry, we collect your name, email address, optional company name, message and any information you include in later correspondence. Our hosting provider may also process technical information such as your IP address, browser information, request time and submission metadata to operate the website and prevent abuse. Name, email and message are required to send the form; company is optional. If you do not provide the required details, we cannot process the form. Please do not submit passwords, identity documents, sensitive personal information or confidential client material.
Why we use your information
We use enquiry details to respond, understand your request and discuss a possible engagement. Technical information is used to deliver the website, maintain security and filter spam. We do not sell enquiry data, add enquirers to marketing lists, or use it for automated decisions that produce legal or similarly significant effects.
Where GDPR applies, we rely on steps taken at your request before entering a contract when you are the prospective contracting party. For other enquiries, including those made on behalf of an organisation, we rely on legitimate interests in responding to requests and developing appropriate professional relationships. Website security and abuse prevention rely on legitimate interests in protecting the service. We also process data where necessary to meet applicable legal obligations. Under Singapore's PDPA, collection, use and disclosure are limited to the notified purposes, with consent where required or another applicable permission under the law.
Service providers and international processing
Netlify hosts the website and processes and stores contact-form submissions, including spam submissions. Email notifications and subsequent correspondence are handled through Microsoft 365. Access is limited to Piotr and authorised service providers as needed for these purposes. We may disclose information where required by law or necessary to establish, exercise or defend legal claims. If you choose a LinkedIn link, LinkedIn handles your visit and information under its own privacy notice.
Netlify, Microsoft and their service providers may process data outside Singapore or the European Economic Area, including in the United States. International processing must be covered by the safeguards required under applicable law, including contractual protections and, where appropriate, the EU Standard Contractual Clauses. You can contact us to request information about the transfer arrangements and relevant safeguards for your data.
How long we keep information
Unsuccessful enquiries are retained for six months after the last contact, then deleted from Netlify submission storage and enquiry email copies. If an enquiry becomes an engagement, relevant correspondence may form part of the engagement records and is retained according to the applicable contractual and legal requirements. A specific record may be kept longer where necessary for a legal obligation or an actual or reasonably anticipated legal claim; retention is limited to that need. Technical logs and provider backup copies follow the relevant service's retention and deletion arrangements. Contact us for details of those arrangements.
Your rights and privacy requests
Depending on the law that applies and the circumstances, you may request access to your data, correction, deletion, restriction of processing or a portable copy. Where processing relies on legitimate interests, you may object. Where it relies on consent, you may withdraw that consent without affecting the lawfulness of earlier processing. Some rights are subject to legal exceptions. We may ask for proportionate information to verify your identity and will respond within the time limits required by applicable law.
Send your request to GDPR@naais.tech.
You may also complain to the relevant regulator, including Singapore's Personal Data Protection Commission or, where GDPR applies, your relevant European data protection authority.
Protecting your information
We limit collection and access to what is needed for the stated purposes and use appropriate technical and organisational measures to protect personal data. No internet service can guarantee absolute security. If a personal-data breach occurs, we assess it and notify affected individuals and regulators where required by applicable law.
Cookies and tracking
The website does not use advertising trackers or analytics cookies. Hosting and security services may process technical information needed to deliver and protect the website. External websites linked from this website have their own cookie and privacy practices.
Changes to this notice
We will update this notice when the operator or the way information is handled changes, including after incorporation. The updated date appears above. Where required, we will provide additional notice of a material change.