Scope
This notice covers the lolisoft.eu corporate website. It presents the brand and its products. It provides an enquiry and quote form. It has no user accounts or contract checkout. Before using a linked product, review the privacy information available on its website.
Data controller
The controller for the website and correspondence is Hayk Jomardyan FHU Real Trade, ul. Henryka Sienkiewicza 101/109, lok. 154, 90-301 Łódź, Poland. Contact info@lolisoft.eu for privacy questions or to exercise your rights.
Contact form and correspondence
When you contact us, we process your name, email address, enquiry topic and message, plus optional company, product, budget and timeline details to respond and manage the correspondence. The basis is our legitimate interest in responding to enquiries under GDPR Article 6(1)(f). Where you request steps before entering a contract, Article 6(1)(b) applies. Providing data is voluntary, but we cannot reply without a return address.
Website delivery and security
Connecting to the website requires your IP address and request data to reach the hosting infrastructure. Depending on configuration, logs may include the request time, resource address, response code and browser information. The purposes are website delivery, diagnostics and protection against misuse. Processing by the controller for these purposes relies on GDPR Article 6(1)(f), subject to confirmation of necessity and assessment of the interests involved.
Providers, retention and transfers
Providers may include hosting, email and website security services. Correspondence should be kept while handling the matter and only as long afterwards as necessary to document arrangements, legal duties or specific claims. We do not claim EU-only data storage. The operator must confirm providers, actual log and email retention, and any transfers outside the EEA and their safeguards before public launch. This part of the notice awaits operator approval.
Cookies and browser storage
The contact form uses the essential LOLISOFT_CONTACT session cookie to protect against forged submissions. It applies to /api/ and expires at the end of the browser session. Form tokens are valid for 30 minutes. Spam counters use a keyed hash of the IP address and timestamps, cover the last hour and remove older entries on the next submission. Messages are handed to email rather than saved in a form database. The code does not use localStorage or sessionStorage. It contains no analytics, advertising pixels, remotely hosted fonts or embedded tracking services. Language selection uses the page address. The form does not subscribe visitors to marketing or require marketing consent. The private preview infrastructure may use its own authentication mechanisms. The production hosting behavior must be checked before public launch.
Your rights
Where the GDPR applies, you may request access, correction, erasure or restriction of processing. You may object to processing based on legitimate interests. Data portability applies in the circumstances set out in GDPR Article 20, including automated processing based on a contract or consent. You may lodge a complaint with the President of the Polish Personal Data Protection Office or your competent supervisory authority.
Profiling and links
The website code does not profile users or make automated decisions with legal effects. Ordinary links to products and GitHub lead to separate websites. We do not send them data through embedded widgets. The destination website’s privacy information applies when you follow a link.