Privacy Policy

Last updated: August 10, 2026

Privacy Policy

1. General Information

This Privacy Policy describes the rules governing the processing of personal data in connection with the use of the TheCloudHero.co website, hereinafter referred to as the “Website”.

The controller of personal data is:

OSS Solutions Krzysztof Nowacki
Tax Identification Number (NIP): 7162667933
Email address: contact@thecloudhero.co

hereinafter referred to as the “Controller”.

For matters concerning privacy, personal data protection and the exercise of rights under the GDPR, you may contact the Controller at: contact@thecloudhero.co.

2. Purpose and Nature of the Website

TheCloudHero.co is an educational website dedicated to Salesforce technology, professional skills development and the job market related to the Salesforce ecosystem.

The Website is intended in particular to:

  • promote knowledge about Salesforce;
  • publish educational materials, articles and information related to Salesforce;
  • support the professional development of people interested in working with Salesforce technology;
  • provide information about skills, professions and career development opportunities within the Salesforce ecosystem;
  • increase awareness of the Salesforce job market;
  • make it easier for users to find Salesforce-related job opportunities.

In pursuing these objectives, the Website presents basic information about Salesforce-related job opportunities. This information is obtained from publicly available sources, in particular job boards, employers’ websites and career pages.

The publication of job information is for informational purposes and is intended, among other things, to present employment opportunities, demand for specific skills and the situation on the Salesforce job market. The full job description and the option to apply are available on the source website.

The Website does not allow users to create accounts, does not accept or store CVs/resumes, does not allow users to submit applications, does not forward applications to employers, does not conduct recruitment processes and does not operate a newsletter.

3. Data That May Be Processed

3.1. Technical Data and Logs

When using the Website, data necessary to establish a connection, display the Website, maintain its operation and ensure security may be processed automatically, including:

  • IP address;
  • date and time of connection;
  • address of the requested resource;
  • browser type and version;
  • operating system and device type;
  • error information;
  • information regarding connection security;
  • data contained in server logs, hosting service logs and network infrastructure logs.

3.2. Analytics Data

After the required consent has been provided, data concerning the way the Website is used may be processed, including:

  • internet, session or device identifiers;
  • information about the device, operating system and browser;
  • approximate location determined based on the IP address;
  • date and time of the visit;
  • source from which the user entered the Website;
  • pages visited and time spent on them;
  • clicks and other interactions with the Website;
  • clicks on links leading to job offers;
  • information about errors and Website performance.

The scope of the data depends on the configuration of the analytics tool and the user’s decision regarding consent.

3.3. Data Provided in Correspondence

If the Controller is contacted by email, the following data may be processed: the sender’s email address, first and last name, company name, message content, data contained in attachments and other information voluntarily provided by the sender.

Users should not send CVs/resumes, health data, other special categories of personal data or information that is not necessary to handle the matter via the contact email address.

4. Purposes and Legal Bases for Processing

4.1. Provision and Proper Operation of the Website

Technical data may be processed in order to make the Website available, handle requests sent to the server, ensure performance and diagnose errors.

The legal basis for such processing is the Controller’s legitimate interest in operating and maintaining the Website — Article 6(1)(f) of the GDPR.

4.2. Website Security

Technical data and logs may be processed in order to protect against attacks and abuse, detect unauthorised access, filter malicious traffic and investigate security incidents.

The legal basis for such processing is the Controller’s legitimate interest in ensuring the security, integrity and availability of the Website — Article 6(1)(f) of the GDPR.

4.3. Analytics

After consent has been granted, data may be processed in order to measure the number of visits, analyse the popularity of content and job offers, examine how the Website is used, measure clicks on links, identify usability issues and develop Website functionality.

The legal basis for such processing is the user’s consent — Article 6(1)(a) of the GDPR.

Consent is voluntary and may be withdrawn at any time using the privacy settings or consent management panel. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. Refusal to give consent does not prevent the use of the basic functions of the Website.

4.4. Handling Correspondence and Requests

Data provided in an email may be processed in order to respond, conduct correspondence, handle a request concerning a job offer, process a request to correct or remove information, handle a report of an infringement or a complaint concerning the operation of the Website.

The legal basis is the Controller’s legitimate interest in handling correspondence — Article 6(1)(f) of the GDPR. If the correspondence is aimed at entering into or performing a contract, Article 6(1)(b) of the GDPR may also apply.

4.5. Claims and Legal Obligations

Data may be processed for the establishment, exercise or defence of legal claims pursuant to Article 6(1)(f) of the GDPR, as well as for compliance with a legal obligation to which the Controller is subject pursuant to Article 6(1)(c) of the GDPR.

5. PostHog Cloud EU

The Website uses PostHog Cloud EU to analyse how the Website is used.

Depending on the configuration, PostHog may process information concerning the device, operating system, browser, pages visited, source of the visit, user session, interactions with the Website, link clicks and technical errors.

Analytics data is sent to the European environment of the PostHog Cloud EU service.

To the extent specified in the agreement and service configuration, PostHog acts as a processor processing personal data on the Controller’s behalf. OSS Solutions Krzysztof Nowacki remains the controller of personal data for the analytics purposes of TheCloudHero.co.

Analytics requiring consent is activated only after such consent has been obtained.

The rules governing the use of cookies and similar technologies are described in a separate Cookie Policy and in the consent management panel.

6. Cloudflare

The Website uses Cloudflare services, among other things, to secure connections, protect against attacks and abuse, filter malicious traffic, deliver content and improve the stability and speed of the Website.

In this context, Cloudflare may process technical data such as the IP address, device and browser information, date and time of connection, address of the requested resource and security-related data.

The legal basis for such processing is the Controller’s legitimate interest in ensuring the security and availability of the Website — Article 6(1)(f) of the GDPR.

7. Hosting, Domain, Email and Google Services

The Website uses Google services or infrastructure related to hosting, domain maintenance, DNS, data storage, backups, email services or technical security.

As a result, IP addresses, logs, connection data, technical data and data contained in correspondence may be processed.

The scope of processing depends on the services actually used and their configuration.

8. Recipients of Personal Data

Personal data may be disclosed to entities supporting the Controller in operating the Website, in particular:

  • the provider of PostHog Cloud EU;
  • Cloudflare;
  • hosting, cloud infrastructure, domain and DNS providers;
  • email and backup service providers;
  • IT and security service providers;
  • entities providing legal, accounting or advisory services;
  • public authorities where disclosure of data is required by law.

The Controller does not sell users’ personal data.

9. Transfers of Personal Data Outside the European Economic Area

PostHog is used in the PostHog Cloud EU version.

However, some other service providers may be established outside the European Economic Area, use subcontractors located outside the EEA or allow access to data from third countries.

Where personal data is transferred outside the EEA, the transfer is carried out on the basis of mechanisms provided for under the GDPR, in particular an adequacy decision issued by the European Commission, Standard Contractual Clauses or other appropriate safeguards.

10. Data Retention Periods

10.1. Analytics Data

Analytics data processed using PostHog Cloud EU is stored for no longer than 12 months from the date of collection and is subsequently deleted or permanently anonymised.

10.2. Technical and Security Logs

Technical logs and security-related data may be stored for no longer than 12 months.

Data may be retained for a longer period where necessary to investigate a specific incident, detect abuse, fix an error, comply with a legal obligation or establish, exercise or defend legal claims.

10.3. Consent Data

Information concerning the granting, refusal or withdrawal of consent may be stored for the period necessary to demonstrate the Controller’s compliance with the law, but no longer than until the expiry of the applicable limitation period for claims.

10.4. Correspondence

Correspondence is stored for the period necessary to handle the matter and, after the matter has been concluded, may be retained for the period necessary to document the response, comply with a legal obligation or establish, exercise or defend legal claims.

11. Rights of Data Subjects

In the cases provided for under the GDPR, data subjects have the right to:

  • access their personal data and obtain a copy of it;
  • rectify or complete their personal data;
  • have their personal data erased;
  • restrict the processing of their personal data;
  • data portability;
  • object to processing based on legitimate interests;
  • withdraw consent at any time;
  • lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).

Requests may be sent to: contact@thecloudhero.co.

The Controller may request information necessary to verify the identity of the person submitting the request where this is necessary to protect personal data against unauthorised disclosure.

12. Right to Object

Where personal data is processed on the basis of the Controller’s legitimate interests, the user may object to such processing on grounds relating to their particular situation.

The Controller will cease processing the data for the relevant purpose unless the Controller demonstrates compelling legitimate grounds for the continued processing which override the interests, rights and freedoms of the user, or where the data is required for the establishment, exercise or defence of legal claims.

13. Voluntary Provision of Data

Providing personal data in correspondence is voluntary, but failure to provide information necessary to handle the matter may make it impossible to provide a response.

Consent to analytics is voluntary, and refusal to provide such consent does not prevent the use of the Website’s basic functions.

14. Automated Decision-Making and Profiling

Users’ personal data is not used to make decisions concerning them based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them.

The Website does not profile candidates and does not make recruitment decisions.

15. Information Contained in Job Offers

The Website presents a limited scope of publicly available information about job offers, such as:

  • job title;
  • employer name;
  • location;
  • working arrangement;
  • basic information about the job offer;
  • link to the source website.

The Controller does not intend to publish private contact details of specific individuals responsible for recruitment.

A person whose personal data appears on the Website may request that the information be corrected, its publication restricted or the information removed by contacting contact@thecloudhero.co and identifying the relevant page or job offer.

16. External Websites

The Website contains links to external recruitment websites, employer career pages and other websites.

After clicking such a link, the user leaves TheCloudHero.co and becomes subject to the rules applicable on the external website.

The Controller does not determine how personal data is processed by those websites.

Before submitting an application, CV/resume or other personal data, the user should review the privacy policy and terms and conditions of the source website.

17. Data Security

The Controller applies appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, loss, destruction, alteration or other unlawful processing.

Such measures are selected taking into account the nature of the data, the scope of processing and the associated risks.

18. Changes to the Privacy Policy

This Privacy Policy may be updated in particular in the event of changes to the Website’s functionality, tools used, service providers, methods of processing personal data, applicable laws or guidelines issued by supervisory authorities.

The current version of the Privacy Policy is published on the Website together with the date of the most recent update.