Privacy Policy — masar.
A brand of Nexia Global Sp. z o.o.
Last updated: [DATE] · Version 1.1
1. Who we are
masar. is a brand of Nexia Global Sp. z o.o., a company registered in Poland. Nexia Global Sp. z o.o. is the controller (administrator danych osobowych) of the personal data described in this policy — it is the entity that contracts with you and issues invoices.
| Controller | Nexia Global Sp. z o.o. |
| Registered seat | ul. Technologiczna 2, 45-839 Opole, Poland |
| NIP | 7543363294 (EU VAT: PL7543363294) |
| REGON | 526545471 |
| KRS | 0001061540, Sąd Rejonowy w Opolu, VIII Wydział Gospodarczy Krajowego Rejestru Sądowego |
| Share capital | 10 000 PLN |
| ahmed@masar.ceo | |
| Phone | +48 452 071 804 |
This policy covers masar.ceo and the pages linked from it — the fit check, the Founder-CEO Dependency Scorecard, the report it produces, and the booking flow for the founder call.
For anything to do with your personal data — a question, a request, or a complaint — write to ahmed@masar.ceo. It reaches the person who decides, not a queue.
2. What we collect, and why
a) The fit check (3 questions)
Team size, approximate annual revenue, and which seat you hold. These are answered before you identify yourself and are used only to route you. They travel with you into the scorecard as part of your firm profile.
b) The scorecard (20 statements)
Your answer to each of the twenty statements, the five domain scores calculated from them, your total Independence Score, and the band it places you in.
c) The gate (to unlock your report)
First name, last name, work email, company. A phone number, only if you choose to give one — it is optional, and leaving it blank does not change your report.
d) Automatically
Your IP address, browser and device type, the pages you visit and when, and similar diagnostic data generated by visiting the site. Cookies and similar technologies — see section 8.
We do not collect special-category data
No health, biometric, political, religious or similar data. Please do not put any into the free-text fields; if you do, we will delete it.
3. Legal basis for each purpose
| Purpose | Legal basis | Notes |
|---|---|---|
| Producing your scorecard and showing you your report | art. 6(1)(b) RODO — steps taken at your request before a contract | You get the report whether or not you consent to anything else. |
| Emailing you a copy of your report | art. 6(1)(b) | Only if you asked for it to be sent. |
| Sending you commercial information about masar. programmes by email | art. 6(1)(a) RODO — your consent, and art. 398 Prawo komunikacji elektronicznej | Separate, unticked opt-in. Withdraw any time. |
| Calling or texting you about your scorecard | art. 6(1)(a) + art. 398 PKE | Separate, unticked opt-in, and only if you gave a number. |
| Booking and running the founder call | art. 6(1)(b) | |
| Analytics cookies, and what we learn from them | art. 6(1)(a) RODO — your consent, and art. 399 PKE for the storage itself | Its own switch in the cookie bar. Refusing changes nothing about the report you get. |
Advertising measurement: the Meta Pixel, and the matching Lead event we send Meta from our server | art. 6(1)(a) RODO — your consent, and art. 399 PKE for the storage itself | A separate switch from analytics. See section 5 on why Meta is a joint controller here rather than a processor. |
| Keeping a record that you did or did not consent | art. 6(1)(c) — our legal obligation under art. 7(1) RODO | We must be able to prove consent. |
| Security, abuse prevention, and defending legal claims | art. 6(1)(f) — our legitimate interest | |
| Invoicing and accounting, if you become a client | art. 6(1)(c) — Polish tax and accounting law |
Consent is never bundled. Under art. 18 ust. 4 ustawy o świadczeniu usług drogą elektroniczną and art. 7 ust. 4 RODO, we may not make the service conditional on marketing consent — and we don't. Each channel has its own unticked checkbox, and withdrawing is as easy as giving (art. 7 ust. 3 RODO).
4. Profiling — what the scorecard actually does
We want to be explicit about this because it is the heart of the service.
Your twenty answers are scored automatically. The score produces five domain figures, a total Independence Score out of 100, and a band. The band informs how we follow up — for example, the highest-scoring bands are not sold to at all; they get an invitation to a fireside conversation instead. This is profiling within the meaning of art. 4(4) RODO, and we disclose it under art. 13 ust. 2 lit. f RODO.
It is not an automated decision with legal or similarly significant effect under art. 22 RODO: nothing is decided about you by the machine alone. A person reads your result, and any conversation that follows is with a person. You can ask us how your score was produced, and we will tell you.
5. Who else sees your data
We do not sell your personal data. We never have and we have no plans to.
Most of the companies we share it with act as our processor: they handle it on our instructions and for no purpose of their own, under a written agreement required by art. 28 RODO. Those are in the table immediately below. Meta is the exception, and it gets its own subsection after the table because calling it a processor would be inaccurate.
Processors
| Provider | What it does | Where your data sits |
|---|---|---|
| Make.com — operated by Make Technologies s.r.o., a wholly owned subsidiary of Celonis SE (Munich, Germany) | Moves your submission from the website to the tools below | EU zone (eu2.make.com) — Dublin, Ireland, on AWS eu-west-1 |
| MailerLite (UAB "MailerLite") | Email delivery and list management | Lithuania (EU) |
| Brevo (Sendinblue SAS) | Booking and scheduling the founder call | France (EU) |
| Google Cloud Poland Sp. z o.o. | Google Sheets, as our record of submissions | Google Cloud region europe-central2 (Warsaw, Poland) |
| Namecheap | Hosting this website | Namecheap European datacentre, Amsterdam (Netherlands) |
| Google Analytics 4 (Google Ireland Ltd) | Counting visits and telling a bounce apart from a completed scorecard — only if you accept the analytics purpose | EU, with onward transfer to the US under the safeguards in section 6 |
Our automation provider sits under EU jurisdiction end to end: Make.com belongs to Celonis SE, a German enterprise-software company, and our workspace runs in the EU zone, so your submission does not leave the Union on its way between our website and the tools above.
Meta: a joint controller, not a processor
Only if you accept the advertising purpose, we use the Meta Pixel and Meta's Conversions API. Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland) is the counterparty.
Meta is not our processor. It uses what it receives for its own purposes as well as ours, which is exactly what an art. 28 agreement forbids, so the honest label is the one the Court of Justice arrived at in C-40/17 (Fashion ID): for the collection of your data and its transmission to Meta, we and Meta are joint controllers under art. 26 RODO. Once the data is with Meta, its subsequent processing is Meta's own responsibility as an independent controller, and our arrangement with it does not and cannot govern that part. The allocation of responsibilities is set out in Meta's Controller Addendum, which forms part of its business terms, and we will send you our copy on request.
What reaches Meta, and only after you have said yes to advertising:
| Leg | What is sent | Form |
|---|---|---|
| From your browser (the Pixel) | Page views and four scorecard events (FitCheckComplete, ScorecardStart, Lead, Schedule), the page URL, your IP address, your user agent, and the _fbp / _fbc identifiers | As collected. An IP address is unavoidable in any HTTP request. |
| From our server (Conversions API, via Make) | The same single Lead event, plus your email, phone number, first name and last name | Hashed with SHA-256 before they leave our systems. Meta never receives the plain values from us. |
Both legs carry the same event identifier so that Meta counts one conversion rather than two. The Lead event also carries your Independence Score band as the conversion's category, which is how we tell which advertising brings founders who actually complete the instrument.
Our automation only forwards the server leg when your recorded advertising consent is true. If you decline advertising, or accept analytics only, no Pixel loads, no Conversions API call is made, and Meta learns nothing about your visit at all — not a hashed identifier, not an IP address.
If you want the practical consequence in one sentence: allowing this lets Meta connect your visit to the profile it already holds on you, if you have an account with it. That is why it is a separate switch, and why declining it costs you nothing on this site.
Everyone else
We also disclose data where the law requires it — to a court, a public authority or a regulator acting within its powers — and, if Nexia Global is ever party to a merger or sale of assets, to the acquiring party, with notice to you first.
Webfonts and the PDF library are served from our own servers, not from a third-party CDN, so simply loading a masar. page does not send your IP address to Google, jsDelivr or anyone else.
6. Transfers outside the EEA
If you decline advertising, your data is processed inside the European Union. Every processor in the table above stores it in an EU or EEA datacentre, in Warsaw, Dublin, Amsterdam, Vilnius or Paris, and our automation workspace is pinned to the EU zone.
Some of those providers belong to groups with a parent or affiliates outside the EEA, and support or administrative access from a third country cannot be ruled out entirely. Where that happens, the transfer is covered by the European Commission's standard contractual clauses (art. 46 ust. 2 lit. c RODO) and, where the provider is certified under it, the EU–US Data Privacy Framework adequacy decision of 10 July 2023.
Advertising is the one purpose that leaves the Union by design. Your counterparty is Meta Platforms Ireland Limited, in Dublin, but Meta operates as a global group and routes data to Meta Platforms, Inc. in the United States. That transfer rests on the EU–US Data Privacy Framework adequacy decision of 10 July 2023, under which Meta Platforms, Inc. is certified, backed by standard contractual clauses for anything the Framework does not reach. We are telling you this under art. 13 ust. 1 lit. f RODO rather than leaving you to infer it: allowing the advertising purpose means allowing a transfer to the United States, and declining it means no such transfer takes place, because nothing is sent to Meta at all.
You can ask us for a copy of the safeguards in place, and we will send them.
We do not rely on your consent as the basis for transfers. Consent is a derogation under art. 49 RODO, not a safeguard, and it is the wrong instrument for routine processing.
7. How long we keep it
| Data | Kept for |
|---|---|
| Scorecard answers, scores and band | 3 years from your last contact with us, or until you object |
| Contact details, where you gave marketing consent | Until you withdraw consent, or 3 years from your last contact with us — whichever comes first |
| Contact details, where you gave no marketing consent | 12 months, then deleted |
| Proof that you did or did not consent | For as long as we could need it to defend a claim — normally 3 years after the processing ends (art. 118 k.c.) |
| Booking and call records | Duration of the relationship, then 3 years |
| Invoices and accounting records, if you become a client | 5 years from the end of the tax year (Ordynacja podatkowa, ustawa o rachunkowości) |
| Cookie consent, per purpose | 12 months, then we ask again. Adding or removing a purpose invalidates the record early and we ask again then |
Meta's _fbp and _fbc cookies, if you allowed advertising | 90 days from being set, and expired immediately if you withdraw that consent |
| What Meta itself keeps from the Pixel and Conversions API | Set by Meta as an independent controller, not by us. See Meta's own Privacy Policy |
| Server logs | […] months |
8. Cookies
Storing or reading anything on your device that is not strictly necessary requires your prior consent under art. 399 Prawo komunikacji elektronicznej. Nothing non-essential loads before you choose. Declining is as easy as accepting, on the same bar, with the same size button and no pre-ticked boxes, and you can change your mind at any time from Cookie settings in the footer.
There are two optional purposes and you decide on each one separately. Accept allows both, Decline allows neither, and Choose gives you a switch per purpose. Bundling them into a single yes would not meet the specificity that art. 4 pkt 11 RODO requires of consent, so we do not.
Two strictly necessary entries do not need consent and cannot be switched off: the one that remembers your cookie choice, and the one that holds your in-progress scorecard answers so a refresh does not lose them. Neither leaves your browser.
Analytics only runs if you accept it. We use Google Analytics 4 to count visits and to tell a visitor who read one page from one who completed the twenty statements. If you decline, the Google tag is never loaded, no request reaches Google, and your IP address is not disclosed to them. When you do accept, we send page views and three events (scorecard_start, scorecard_complete with your score and band, and call_booked). Your name, email, company and phone number are never sent to Google.
Advertising measurement only runs if you accept it, separately. We use the Meta Pixel, and a matching server-side Lead event through Meta's Conversions API, to tell whether an ad that brought you here led anywhere. If you decline, connect.facebook.net is never contacted and no server event is forwarded, so Meta learns nothing about your visit. If you accept, the hashed-identifier detail, the joint-controller position and the US transfer are set out in sections 5 and 6 above, which is where the substance of this one lives.
The full detail is in our Cookie Policy.
9. Your rights
Under RODO you have the right to:
- Access your data and get a copy (art. 15)
- Correct anything inaccurate or incomplete (art. 16)
- Erase it (art. 17)
- Restrict how we use it (art. 18)
- Portability — receive it in a machine-readable format, or have it sent to another controller (art. 20)
- Object to processing based on our legitimate interest (art. 21 ust. 1)
- Object to direct marketing at any time (art. 21 ust. 2) — this one is absolute. Say stop and we stop, no reasons needed, no questions asked.
- Withdraw consent at any time (art. 7 ust. 3), without affecting anything done lawfully beforehand
To exercise any of these, email ahmed@masar.ceo. Every marketing email also carries a one-click unsubscribe link. We answer within one month, and will tell you if a complex request needs longer (art. 12 ust. 3 RODO).
You can complain to the supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych (UODO) ul. Stawki 2, 00-193 Warszawa, Poland uodo.gov.pl
10. Security
We use appropriate technical and organisational measures to protect your data: encryption in transit (HTTPS across the site), access limited to the people who need it, and providers chosen for their own security posture. No method of transmission or storage over the internet is completely secure, and we will not pretend otherwise — but if a breach ever put your rights at risk, we would notify UODO within 72 hours and tell you directly where the law requires it (art. 33–34 RODO).
11. Children
masar. is a service for founders and executives. It is not directed at children and we do not knowingly collect data from anyone under 16 — the age set by art. 8 RODO as applied in Poland. If you believe a child has given us data, write to ahmed@masar.ceo and we will delete it.
12. Links to other sites
Our pages link to services we don't run, including our scheduling provider. Once you're there, their privacy policy governs, not ours. We'd encourage you to read it.
13. Changes to this policy
We may update this policy. The version and date at the top always tell you which one you're reading. If a change materially affects how we use your data, we'll say so prominently on the site before it takes effect, and email you where we have a basis to.
14. Contact
| ahmed@masar.ceo | |
| Post | Nexia Global Sp. z o.o., ul. Technologiczna 2, 45-839 Opole, Poland |
| Phone | +48 452 071 804 |