Legal Document · GDPR Compliant

Mandatory Privacy Policy Disclosures

Effective Date

May 20, 2026

Regulatory Basis

GDPR Art. 13 & 14

Version

1.0

This Privacy Policy ("Policy") is issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR) and sets out the mandatory disclosures that must be provided to data subjects at the time their personal data is collected or, where data is obtained from third parties, within a reasonable period. This Policy applies to all personal data processed by the operator of this platform ("we", "us", "our") acting as Data Controller.

1. Identity and Contact Details of the Controller

The Data Controller is the operator of this platform. For all data-protection enquiries, you may contact us via:

  • The Contact page on this platform.
  • Written correspondence to our registered business address.
  • Email directed to our designated Data Protection Officer (DPO), where one has been appointed.

Where a DPO has been appointed, their contact details are provided separately upon request and displayed in the cookie consent interface.

2. Purposes and Legal Bases for Processing (Art. 13(1)(c) & Art. 13(1)(d))

We process personal data for the following purposes and on the following legal bases:

PurposeLegal Basis (GDPR Art. 6)
Account creation and managementArt. 6(1)(b) — Contract
Order fulfilment and payment processingArt. 6(1)(b) — Contract
Legal and tax complianceArt. 6(1)(c) — Legal obligation
Platform security and fraud preventionArt. 6(1)(f) — Legitimate interests
Analytics and platform improvementArt. 6(1)(a) — Consent
Direct marketing and newslettersArt. 6(1)(a) — Consent
Responding to support enquiriesArt. 6(1)(b) — Contract / Art. 6(1)(f) — Legitimate interests
Business claim processingArt. 6(1)(b) — Contract

3. Categories of Personal Data Collected (Art. 13(1))

Depending on the nature of your interaction with the platform, we may collect:

  • Identity data: full name, username.
  • Contact data: email address, phone number, postal address.
  • Account credentials: encrypted passwords and authentication tokens.
  • Usage and technical data: IP address, browser type and version, device identifiers, pages visited, clickstream data, session duration.
  • Transaction data: order history, billing address, payment method type (full card data is processed exclusively by our payment provider and not stored by us).
  • Business data: company name, NIP/VAT number, business address (for business account holders).
  • Communications data: messages sent through the platform's contact and messaging features.
  • Preference data: language settings, dietary requirements, marketing opt-in status.

4. Recipients and Categories of Recipients (Art. 13(1)(e))

Your personal data may be shared with or accessed by:

  • Payment processors (e.g., Stripe) — for secure handling of transactions.
  • Cloud infrastructure providers — for hosting, storage and delivery of platform services.
  • Email service providers — for transactional and marketing communications.
  • Analytics providers — where consent has been obtained.
  • Legal and regulatory authorities — where required by applicable law.
  • Business owners / location admins — limited data visible to owners of claimed business listings for the purpose of managing their listing.

All third-party processors are engaged under data processing agreements compliant with Art. 28 GDPR. We do not sell personal data to third parties.

5. International Data Transfers (Art. 13(1)(f))

Where personal data is transferred outside the European Economic Area (EEA), such transfers are made only when one of the following safeguards is in place:

  • An adequacy decision by the European Commission (Art. 45 GDPR).
  • Standard Contractual Clauses (SCCs) approved under Art. 46(2)(c) GDPR.
  • Binding Corporate Rules (BCR) where applicable.

Details of applicable safeguards are available upon written request to our DPO contact.

6. Data Retention Periods (Art. 13(2)(a))

We retain personal data only for as long as necessary for the stated purposes:

  • Account data: for the duration of the account plus up to 3 years after closure (for legal claims).
  • Transaction records: 5 years from the date of transaction (tax and accounting obligations under Polish law).
  • Marketing consent records: until consent is withdrawn plus 3 years (for demonstrating compliance).
  • Support communications: 2 years from resolution.
  • Server and access logs: up to 12 months.
  • Cookie and analytics data: in accordance with cookie-specific retention periods disclosed in the Cookie Policy.

Upon expiry of the applicable period, data is securely deleted or irreversibly anonymised.

7. Your Rights (Art. 13(2)(b))

Under GDPR Chapter III, you have the right to:

  • Access (Art. 15) — request a copy of your personal data and information about its processing.
  • Rectification (Art. 16) — have inaccurate data corrected without undue delay.
  • Erasure (Art. 17) — request deletion where data is no longer necessary or consent is withdrawn.
  • Restriction (Art. 18) — request that processing is restricted in certain circumstances.
  • Data portability (Art. 20) — receive your data in a machine-readable format.
  • Object (Art. 21) — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent (Art. 7(3)) — at any time, without affecting the lawfulness of prior processing.
  • Lodge a complaint (Art. 77) — with the supervisory authority (UODO in Poland: uodo.gov.pl).

To exercise any of these rights, please contact us via the details in Section 1. We will respond within 30 calendar days. We may request proof of identity before processing your request.

8. Automated Decision-Making and Profiling (Art. 13(2)(f))

We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. Where any such processing is introduced in the future, you will be informed and your rights under Art. 22 GDPR will apply, including the right to human review.

9. Right to Withdraw Consent (Art. 7(3))

Where processing is based on consent, you have the right to withdraw it at any time. Withdrawal may be effected through:

  • Your account preferences page (marketing, analytics, and cookie consent settings).
  • The "unsubscribe" link in any marketing email.
  • Written request to our data-protection contact point.

Withdrawal does not affect the lawfulness of any processing that took place prior to withdrawal. We will action the withdrawal within 72 hours of receipt.

10. Right to Lodge a Complaint (Art. 13(2)(d))

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with the competent data protection supervisory authority. In Poland, this is:

Urząd Ochrony Danych Osobowych (UODO)

ul. Stawki 2, 00-193 Warszawa

Website: uodo.gov.pl

Phone: +48 22 531 03 00

We nevertheless encourage you to contact us first so that we may resolve any concern directly and promptly.

11. Source of Personal Data (Art. 14 — Indirect Collection)

Where personal data is not collected directly from the data subject, it may be obtained from:

  • Publicly available business directories and mapping data sources (e.g., OpenStreetMap).
  • Business representatives who submit or update listing information on behalf of an organisation.
  • Third-party authentication providers (where social login is used).

In such cases, we will provide the disclosures required by Art. 14 GDPR within a reasonable period and no later than one month after obtaining the data.

12. Cookies and Tracking Technologies

We use cookies and similar tracking technologies. A full description of the types of cookies we use, their purposes, and retention periods is set out in our separate Cookie Policy. A consent banner is presented on first visit allowing you to accept or reject non-essential cookies by category. Your preferences can be updated at any time via the Cookie Settings panel.

13. Security of Personal Data (Art. 32)

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit (TLS/HTTPS) and at rest.
  • Access controls and role-based permissions.
  • Regular security testing and vulnerability assessments.
  • Staff training on data protection and information security.
  • Incident response and breach notification procedures.

14. Changes to This Policy

We may update this Policy periodically. Material changes will be communicated via a platform notification or email at least 14 days before taking effect. The date of the last update is shown at the top of this document. Where required by law, we will re-request your consent.

Legal Disclaimer: This document is a template and does not constitute legal advice. It should be reviewed and customised by a qualified legal professional before use in a live environment to ensure full compliance with applicable laws and the specific circumstances of your organisation.