masar. ← Back to masar.ceo
Privacy

Privacy Policy — masar.

A brand of Nexia Global Sp. z o.o.

Last updated: [DATE] · Version 1.1


1. Who we are

masar. is a brand of Nexia Global Sp. z o.o., a company registered in Poland. Nexia Global Sp. z o.o. is the controller (administrator danych osobowych) of the personal data described in this policy — it is the entity that contracts with you and issues invoices.

ControllerNexia Global Sp. z o.o.
Registered seatul. Technologiczna 2, 45-839 Opole, Poland
NIP7543363294 (EU VAT: PL7543363294)
REGON526545471
KRS0001061540, Sąd Rejonowy w Opolu, VIII Wydział Gospodarczy Krajowego Rejestru Sądowego
Share capital10 000 PLN
Emailahmed@masar.ceo
Phone+48 452 071 804

This policy covers masar.ceo and the pages linked from it — the fit check, the Founder-CEO Dependency Scorecard, the report it produces, and the booking flow for the founder call.

For anything to do with your personal data — a question, a request, or a complaint — write to ahmed@masar.ceo. It reaches the person who decides, not a queue.

2. What we collect, and why

a) The fit check (3 questions)

Team size, approximate annual revenue, and which seat you hold. These are answered before you identify yourself and are used only to route you. They travel with you into the scorecard as part of your firm profile.

b) The scorecard (20 statements)

Your answer to each of the twenty statements, the five domain scores calculated from them, your total Independence Score, and the band it places you in.

c) The gate (to unlock your report)

First name, last name, work email, company. A phone number, only if you choose to give one — it is optional, and leaving it blank does not change your report.

d) Automatically

Your IP address, browser and device type, the pages you visit and when, and similar diagnostic data generated by visiting the site. Cookies and similar technologies — see section 8.

We do not collect special-category data

No health, biometric, political, religious or similar data. Please do not put any into the free-text fields; if you do, we will delete it.

Purpose Legal basis Notes
Producing your scorecard and showing you your reportart. 6(1)(b) RODO — steps taken at your request before a contractYou get the report whether or not you consent to anything else.
Emailing you a copy of your reportart. 6(1)(b)Only if you asked for it to be sent.
Sending you commercial information about masar. programmes by emailart. 6(1)(a) RODO — your consent, and art. 398 Prawo komunikacji elektronicznejSeparate, unticked opt-in. Withdraw any time.
Calling or texting you about your scorecardart. 6(1)(a) + art. 398 PKESeparate, unticked opt-in, and only if you gave a number.
Booking and running the founder callart. 6(1)(b)
Analytics cookies, and what we learn from themart. 6(1)(a) RODO — your consent, and art. 399 PKE for the storage itselfIts own switch in the cookie bar. Refusing changes nothing about the report you get.
Advertising measurement: the Meta Pixel, and the matching Lead event we send Meta from our serverart. 6(1)(a) RODO — your consent, and art. 399 PKE for the storage itselfA separate switch from analytics. See section 5 on why Meta is a joint controller here rather than a processor.
Keeping a record that you did or did not consentart. 6(1)(c) — our legal obligation under art. 7(1) RODOWe must be able to prove consent.
Security, abuse prevention, and defending legal claimsart. 6(1)(f) — our legitimate interest
Invoicing and accounting, if you become a clientart. 6(1)(c) — Polish tax and accounting law

Consent is never bundled. Under art. 18 ust. 4 ustawy o świadczeniu usług drogą elektroniczną and art. 7 ust. 4 RODO, we may not make the service conditional on marketing consent — and we don't. Each channel has its own unticked checkbox, and withdrawing is as easy as giving (art. 7 ust. 3 RODO).

4. Profiling — what the scorecard actually does

We want to be explicit about this because it is the heart of the service.

Your twenty answers are scored automatically. The score produces five domain figures, a total Independence Score out of 100, and a band. The band informs how we follow up — for example, the highest-scoring bands are not sold to at all; they get an invitation to a fireside conversation instead. This is profiling within the meaning of art. 4(4) RODO, and we disclose it under art. 13 ust. 2 lit. f RODO.

It is not an automated decision with legal or similarly significant effect under art. 22 RODO: nothing is decided about you by the machine alone. A person reads your result, and any conversation that follows is with a person. You can ask us how your score was produced, and we will tell you.

5. Who else sees your data

We do not sell your personal data. We never have and we have no plans to.

Most of the companies we share it with act as our processor: they handle it on our instructions and for no purpose of their own, under a written agreement required by art. 28 RODO. Those are in the table immediately below. Meta is the exception, and it gets its own subsection after the table because calling it a processor would be inaccurate.

Processors

Provider What it does Where your data sits
Make.com — operated by Make Technologies s.r.o., a wholly owned subsidiary of Celonis SE (Munich, Germany)Moves your submission from the website to the tools belowEU zone (eu2.make.com) — Dublin, Ireland, on AWS eu-west-1
MailerLite (UAB "MailerLite")Email delivery and list managementLithuania (EU)
Brevo (Sendinblue SAS)Booking and scheduling the founder callFrance (EU)
Google Cloud Poland Sp. z o.o.Google Sheets, as our record of submissionsGoogle Cloud region europe-central2 (Warsaw, Poland)
NamecheapHosting this websiteNamecheap European datacentre, Amsterdam (Netherlands)
Google Analytics 4 (Google Ireland Ltd)Counting visits and telling a bounce apart from a completed scorecard — only if you accept the analytics purposeEU, with onward transfer to the US under the safeguards in section 6

Our automation provider sits under EU jurisdiction end to end: Make.com belongs to Celonis SE, a German enterprise-software company, and our workspace runs in the EU zone, so your submission does not leave the Union on its way between our website and the tools above.

Meta: a joint controller, not a processor

Only if you accept the advertising purpose, we use the Meta Pixel and Meta's Conversions API. Meta Platforms Ireland Limited (Merrion Road, Dublin 4, Ireland) is the counterparty.

Meta is not our processor. It uses what it receives for its own purposes as well as ours, which is exactly what an art. 28 agreement forbids, so the honest label is the one the Court of Justice arrived at in C-40/17 (Fashion ID): for the collection of your data and its transmission to Meta, we and Meta are joint controllers under art. 26 RODO. Once the data is with Meta, its subsequent processing is Meta's own responsibility as an independent controller, and our arrangement with it does not and cannot govern that part. The allocation of responsibilities is set out in Meta's Controller Addendum, which forms part of its business terms, and we will send you our copy on request.

What reaches Meta, and only after you have said yes to advertising:

Leg What is sent Form
From your browser (the Pixel)Page views and four scorecard events (FitCheckComplete, ScorecardStart, Lead, Schedule), the page URL, your IP address, your user agent, and the _fbp / _fbc identifiersAs collected. An IP address is unavoidable in any HTTP request.
From our server (Conversions API, via Make)The same single Lead event, plus your email, phone number, first name and last nameHashed with SHA-256 before they leave our systems. Meta never receives the plain values from us.

Both legs carry the same event identifier so that Meta counts one conversion rather than two. The Lead event also carries your Independence Score band as the conversion's category, which is how we tell which advertising brings founders who actually complete the instrument.

Our automation only forwards the server leg when your recorded advertising consent is true. If you decline advertising, or accept analytics only, no Pixel loads, no Conversions API call is made, and Meta learns nothing about your visit at all — not a hashed identifier, not an IP address.

If you want the practical consequence in one sentence: allowing this lets Meta connect your visit to the profile it already holds on you, if you have an account with it. That is why it is a separate switch, and why declining it costs you nothing on this site.

Everyone else

We also disclose data where the law requires it — to a court, a public authority or a regulator acting within its powers — and, if Nexia Global is ever party to a merger or sale of assets, to the acquiring party, with notice to you first.

Webfonts and the PDF library are served from our own servers, not from a third-party CDN, so simply loading a masar. page does not send your IP address to Google, jsDelivr or anyone else.

6. Transfers outside the EEA

If you decline advertising, your data is processed inside the European Union. Every processor in the table above stores it in an EU or EEA datacentre, in Warsaw, Dublin, Amsterdam, Vilnius or Paris, and our automation workspace is pinned to the EU zone.

Some of those providers belong to groups with a parent or affiliates outside the EEA, and support or administrative access from a third country cannot be ruled out entirely. Where that happens, the transfer is covered by the European Commission's standard contractual clauses (art. 46 ust. 2 lit. c RODO) and, where the provider is certified under it, the EU–US Data Privacy Framework adequacy decision of 10 July 2023.

Advertising is the one purpose that leaves the Union by design. Your counterparty is Meta Platforms Ireland Limited, in Dublin, but Meta operates as a global group and routes data to Meta Platforms, Inc. in the United States. That transfer rests on the EU–US Data Privacy Framework adequacy decision of 10 July 2023, under which Meta Platforms, Inc. is certified, backed by standard contractual clauses for anything the Framework does not reach. We are telling you this under art. 13 ust. 1 lit. f RODO rather than leaving you to infer it: allowing the advertising purpose means allowing a transfer to the United States, and declining it means no such transfer takes place, because nothing is sent to Meta at all.

You can ask us for a copy of the safeguards in place, and we will send them.

We do not rely on your consent as the basis for transfers. Consent is a derogation under art. 49 RODO, not a safeguard, and it is the wrong instrument for routine processing.

7. How long we keep it

Data Kept for
Scorecard answers, scores and band3 years from your last contact with us, or until you object
Contact details, where you gave marketing consentUntil you withdraw consent, or 3 years from your last contact with us — whichever comes first
Contact details, where you gave no marketing consent12 months, then deleted
Proof that you did or did not consentFor as long as we could need it to defend a claim — normally 3 years after the processing ends (art. 118 k.c.)
Booking and call recordsDuration of the relationship, then 3 years
Invoices and accounting records, if you become a client5 years from the end of the tax year (Ordynacja podatkowa, ustawa o rachunkowości)
Cookie consent, per purpose12 months, then we ask again. Adding or removing a purpose invalidates the record early and we ask again then
Meta's _fbp and _fbc cookies, if you allowed advertising90 days from being set, and expired immediately if you withdraw that consent
What Meta itself keeps from the Pixel and Conversions APISet by Meta as an independent controller, not by us. See Meta's own Privacy Policy
Server logs[…] months

8. Cookies

Storing or reading anything on your device that is not strictly necessary requires your prior consent under art. 399 Prawo komunikacji elektronicznej. Nothing non-essential loads before you choose. Declining is as easy as accepting, on the same bar, with the same size button and no pre-ticked boxes, and you can change your mind at any time from Cookie settings in the footer.

There are two optional purposes and you decide on each one separately. Accept allows both, Decline allows neither, and Choose gives you a switch per purpose. Bundling them into a single yes would not meet the specificity that art. 4 pkt 11 RODO requires of consent, so we do not.

Two strictly necessary entries do not need consent and cannot be switched off: the one that remembers your cookie choice, and the one that holds your in-progress scorecard answers so a refresh does not lose them. Neither leaves your browser.

Analytics only runs if you accept it. We use Google Analytics 4 to count visits and to tell a visitor who read one page from one who completed the twenty statements. If you decline, the Google tag is never loaded, no request reaches Google, and your IP address is not disclosed to them. When you do accept, we send page views and three events (scorecard_start, scorecard_complete with your score and band, and call_booked). Your name, email, company and phone number are never sent to Google.

Advertising measurement only runs if you accept it, separately. We use the Meta Pixel, and a matching server-side Lead event through Meta's Conversions API, to tell whether an ad that brought you here led anywhere. If you decline, connect.facebook.net is never contacted and no server event is forwarded, so Meta learns nothing about your visit. If you accept, the hashed-identifier detail, the joint-controller position and the US transfer are set out in sections 5 and 6 above, which is where the substance of this one lives.

The full detail is in our Cookie Policy.

9. Your rights

Under RODO you have the right to:

To exercise any of these, email ahmed@masar.ceo. Every marketing email also carries a one-click unsubscribe link. We answer within one month, and will tell you if a complex request needs longer (art. 12 ust. 3 RODO).

You can complain to the supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (UODO) ul. Stawki 2, 00-193 Warszawa, Poland uodo.gov.pl

10. Security

We use appropriate technical and organisational measures to protect your data: encryption in transit (HTTPS across the site), access limited to the people who need it, and providers chosen for their own security posture. No method of transmission or storage over the internet is completely secure, and we will not pretend otherwise — but if a breach ever put your rights at risk, we would notify UODO within 72 hours and tell you directly where the law requires it (art. 33–34 RODO).

11. Children

masar. is a service for founders and executives. It is not directed at children and we do not knowingly collect data from anyone under 16 — the age set by art. 8 RODO as applied in Poland. If you believe a child has given us data, write to ahmed@masar.ceo and we will delete it.

Our pages link to services we don't run, including our scheduling provider. Once you're there, their privacy policy governs, not ours. We'd encourage you to read it.

13. Changes to this policy

We may update this policy. The version and date at the top always tell you which one you're reading. If a change materially affects how we use your data, we'll say so prominently on the site before it takes effect, and email you where we have a basis to.

14. Contact

Emailahmed@masar.ceo
PostNexia Global Sp. z o.o., ul. Technologiczna 2, 45-839 Opole, Poland
Phone+48 452 071 804