Publication date: June 1, 2026 .
This Privacy Policy sets out the principles for the processing of personal data by Printbox Sp. z o.o., including the methods of its collection, use, and disclosure. The document also contains information about your rights in connection with the processing of your personal data. We encourage you to read this Policy carefully, as it is an essential source of information that will allow you to make informed decisions about sharing your data and exercising your rights under the applicable data protection regulations. If you have any questions or concerns regarding the processing of your personal data or the protection of your privacy, please contact us:
Data Protection Officer (DPO): We have appointed a Data Protection Officer whom you can contact in all matters regarding the processing of your personal data and the exercise of your rights under data protection regulations. You can contact our DPO:
The controller of your personal data is Printbox Sp. z o.o. (hereinafter: Printbox), a limited liability company with its registered office in Kraków at ul. Fabryczna 20A, 31-553 Kraków, Poland, entered into the Register of Entrepreneurs of the National Court Register under KRS number: 0000484669, NIP (Tax Identification Number): 6762470210, with a share capital of PLN 108,500.00. Printbox acts as a data controller within the meaning of the GDPR in situations where it independently determines the purposes and means of processing personal data, in particular in connection with:
List of Printbox websites:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
Purposes of processing:
Legal basis:
Storage period:
We only collect personal data that is necessary for the purposes indicated. We obtain this data directly from you (e.g., when you provide it in a form or contact us), automatically (e.g., through cookies), and occasionally from third parties (e.g., social media, if you interact with us through them). Below are the categories of personal data we may process:
Identification and contact data: e.g., name and surname, email address, phone number, company name, job title, country of residence/registered office. Providing this data is voluntary, but necessary for us to respond to your inquiry, provide a service, or enter into a contract with you (e.g., a service agreement or a license agreement).
Data regarding the use of our website and services (technical data): information collected automatically about your visit to our websites, such as IP address and approximate device location (e.g., country or city determined based on the IP), browser and device type, operating system, unique online identifiers (e.g., cookie ID), pages visited, time spent on the site, entry source (e.g., the site from which you were redirected to our website), as well as information about your interaction with our content (e.g., clicks on links, opening our emails, etc.). This data is collected using cookies and similar technologies and is used by us to analyze website traffic, improve our services, and ensure security.
Transactional and commercial data: information related to interest in our services, history of contacts with us, inquiries, and in the case of customers—data about concluded contracts, purchased services/licenses, payments, etc. (to the extent it concerns a natural person, e.g., the owner of a sole proprietorship or a contact person at a business client).
Recruitment data: if you apply for a job at Printbox, we process the data contained in your application (CV, cover letter, etc.), such as information about professional experience, education, qualifications, skills, as well as contact details for recruitment purposes.
Other information you voluntarily provide to us: any other personal data you decide to disclose to us, e.g., in the content of a message sent to us, in contact form fields, or during a phone/video call. We will process such data only for the purpose for which you provided it.
As a rule, we obtain data directly from you when you use our services or contact us. This data may come from channels such as: forms on the website, chats, newsletter subscriptions, email correspondence, phone calls, in-person or online meetings, and messages sent via social media, etc.
We automatically collect technical data necessary for the operation and optimization of the service, including:
We less frequently obtain data from third parties, solely to supplement information or for verification:
We assure you that we do not purchase databases from data brokers or obtain information in a manner contrary to the law.
The General Data Protection Regulation (GDPR) grants you several rights related to the processing of your personal data. As the controller of your data, we respect these rights and ensure you can exercise them.
Below is a list of your rights:
You have the right to obtain confirmation from us as to whether or not we are processing your personal data. If we are, you have the right to access it and receive information, including about the purposes of the processing, categories of data, recipients, the planned storage period, and your rights. You can also request a copy of the data.
If you notice that your personal data we hold is incorrect or incomplete, you have the right to request its immediate rectification or completion.
You have the right to request the erasure of your personal data if:
Please remember that this right is not absolute and there are exceptions (e.g., when processing is necessary for the establishment, exercise, or defense of legal claims, or to comply with a legal obligation).
You have the right to request the restriction of the processing of your data in certain situations, e.g., when:
If the processing is based on your consent or for the performance of a contract and is carried out by automated means, you have the right to receive the data you have provided to us in a structured, commonly used, and machine-readable format. You also have the right to transmit this data to another controller without hindrance from us, and to have the data transmitted directly from us to another controller, where technically feasible.
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on our legitimate interest (Article 6(1)(f) of the GDPR), including profiling. In such a case, we will cease to process your data for these purposes, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
Particularly important: If your personal data is processed for direct marketing purposes (including profiling to the extent that it is related to such direct marketing), you have the right to object at any time to such processing. This objection does not require justification. Upon receipt of an objection, we will immediately cease processing your data for this purpose.
If the processing of your data is based on consent, you have the right to withdraw that consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. You can withdraw your consent as easily as it was given (e.g., by clicking the link in a newsletter or by contacting us).
If you believe that the processing of your personal data violates the provisions of the GDPR or other data protection laws, you have the right to complain with a supervisory authority responsible for data protection. In Poland, this authority is the President of the Personal Data Protection Office (PUODO). You can find the contact details for PUODO on the website: https://uodo.gov.pl/en/p/contact
You can submit any requests related to the exercise of the above rights in the following ways:
The controller will endeavor to respond to your request promptly, no later than within one month, or to inform you of the need to extend this deadline (by a maximum of two additional months), along with an explanation of the reasons for the delay. In certain situations, the controller may ask for additional information to confirm your identity in order to verify your right to make the request. This is part of the adequate security measures aimed at ensuring that personal data is not disclosed to an unauthorized person.
Your personal data may be shared by us with other entities only by applicable law. We never sell personal data to third parties. The categories of entities to whom we may disclose your data are:
We are part of a structure in which we work closely with other entities to provide and develop our services. Your data may be shared with:
Within our group and between affiliated entities, uniform, high standards of data protection apply, and transfers are based on joint controllership agreements and/or data processing agreements (DPAs).
In our daily operations, we use the help of trusted subcontractors who may process your data on our behalf and at our direction. Such processors include, among others:
Hosting and IT infrastructure providers – we store data on the servers of external providers (e.g., cloud service providers). We enter into agreements with them that guarantee data confidentiality and security.
Analytical and marketing tool providers – e.g., Google (Google Analytics, Google Ads), Meta (Facebook Pixel), Hotjar, which support us in analysis and promotion. Where possible, we have concluded processing agreements with them (e.g., in the case of Google) or ensured that they operate under services that comply with the law. Please note that some of these entities may also act as independent controllers in a limited scope.
We utilize CRM, email, and relationship management system providers to manage our customer and contact database (CRM) and send mailings. This means your contact details may be stored on the servers of such a provider and processed to handle communication. We always choose providers who guarantee compliance with privacy protection requirements.
Communication and customer service tool providers: Entities providing systems for managing email, contact forms, and support ticket systems (helpdesk).
Payment processing partners – if you make a payment as part of our services, the payment-related data (e.g., card number, bank account details) is directly handled by our external payment provider. In such cases, they act as independent controllers of this financial data.
Accounting, legal, and audit firms – if necessary, we may share some of your data with our advisors (e.g., lawyers in the event of a legal dispute, auditors examining our compliance with regulations, an accounting office that processes our invoices with your data, etc.). Such sharing occurs only to the necessary extent and under appropriate agreements.
Other subcontractors as needed – e.g., a courier company (it will receive your address if we need to send you a contract or materials), SMS service providers (if we confirm something by SMS), document archiving companies, external developers, consultants (when implementing projects or providing services). In each case, the amount of data transferred is limited to the necessary minimum.
There are situations where the law requires or permits the disclosure of your data to other data controllers. Such recipients include:
Public authorities and law enforcement agencies: If authorized bodies (e.g., police, prosecutor's office, court, supervisory authority) request us to disclose data based on relevant legal provisions, we are obliged to provide it. In each case, we carefully verify the legal basis of the request and the scope of the information provided, ensuring security and proportionality.
Entities involved in corporate transactions: If in the future Printbox were to consider restructuring, merger, or sale of all or part of the company, your data could be transferred to a potential buyer/investor as part of a due diligence review, and then to the new owner of the company. In such a situation, the new entity will assume the obligations of the data controller and will be able to use the data for service continuity, but still by this Policy.
In certain cases, you may ask us to transfer your data to a specific entity or give your consent for it. For example, if you ask us for a reference and agree for us to disclose your data to another client, we will do so. Or if, by using an integration of our services with another company's service, you authorize the flow of your data (e.g., logging in with a Google account), then the data is transferred with your consent and according to your intention.
We impose data protection requirements on all our data processors acting on our behalf—they must guarantee appropriate security measures, process data only for the purposes we specify and at our direction, and delete or return the data after the service is completed. We also ensure that we do not share any data in an unauthorized manner. We do not sell databases with email addresses, we do not share customer lists with marketing partners without a legal basis, and we do not disclose user information to other customers. Each recipient receives only the data that is necessary to achieve a specific purpose (minimization). If you have doubts about a particular recipient, you can always request information from us about whether and to whom we have transferred your data.
Our websites use cookies and similar technologies (such as pixels, local storage, and monitoring scripts) to ensure their proper functioning, analyze traffic, and support marketing activities. Cookies are small text files saved on your device (computer, smartphone) when you visit a website. On subsequent visits, they allow the website to recognize your browser and, for example, remember your preferences.
These are cookies necessary for the proper functioning of our website and services. They enable basic functions such as navigation or remembering your privacy settings (e.g., whether you have consented to cookies). Without these cookies, the website cannot function correctly.
These allow us to collect aggregated information about how users use our websites—which subpages they visit, how much time they spend on them, and what features they click. Thanks to them, we can improve the structure and content of our services, as well as solve technical problems. We use, among others:
Google Analytics (Google LLC) - a popular analytical tool for analyzing website traffic statistics. The data we receive from Google Analytics is in the form of collective reports and statistics. It does not allow us to link information to a specific user directly. Typical information we analyze includes, for example: general data about users' operating systems and web browsers, the popularity of individual subpages of our service, the average time spent on the site and its subpages, user navigation paths on the site, general information about traffic sources to the site (e.g., search engines, other sites), approximate geographical location (e.g., at the country or city level), etc. The processing of data in connection with the use of Google Analytics cookies is based on your voluntary consent (Article 6(1)(a) of the GDPR), which you express through our cookie consent management mechanism (cookie banner). We emphasize that we have implemented privacy protection measures when using Google Analytics—e.g., the IP address anonymization function, so that the user's IP address is shortened before being saved (this limits the possibility of identification). Remember that you have control over cookies. You can withdraw your consent to the use of Google Analytics cookies at any time by changing the settings in our cookie consent management mechanism. Additionally, most web browsers offer configuration options that allow you to manage cookies, including blocking or deleting them. Google also provides information on the possibility of opting out of data collection by Google Analytics (e.g., through special browser add-ons). We recommend that you familiarize yourself with Google's official resources on this matter. More information on how Google uses data when you use its partners' sites and apps, as well as on privacy protection in Google services, can be found in the company's publicly available information materials (e.g., in its privacy policy).
Hotjar (Hotjar Ltd) - an analytical and feedback tool that helps us understand how users navigate our site. Hotjar can anonymously record mouse clicks, cursor movements, page scrolling, and interactions with selected interface elements. This helps identify usability problems with the service and optimize the content layout. Hotjar also collects information about the user's device (device type, browser, approximate geographical location at the country level). Hotjar does not save any content typed into forms and does not record the screen in a way that would allow your personal data to be known. There is a mechanism for automatically skipping text fields (entered characters are masked). Data from Hotjar is stored on servers in the European Union (AWS region eu-west-1, Ireland). You can also object to tracking by Hotjar in a simple way—this tool honors the "Do Not Track" signal in your browser. You can also opt out of being tracked by Hotjar on all sites that use it by visiting the Hotjar opt-out page: https://www.hotjar.com/policies/do-not-track/ . For more information on how Hotjar processes data, please visit their privacy page: https://www.hotjar.com/legal/policies/privacy/
We set these cookies or our advertising partners (third parties) to track user activity and display personalized ads for our products on other websites (so-called behavioral advertising, retargeting). In other words, if you have visited our site and shown interest in specific content or a product, thanks to these cookies, you may later see our advertisement—e.g., on Facebook, Instagram, in Google search results, or on Google Display Network partner sites—tailored to your interests. We use, among others:
Based on data from the Pixel, we can target our ads to you on Facebook/Instagram (so-called retargeting) and create anonymous statistics on the effectiveness of these ads (e.g., we learn how many people, after clicking on an ad, came to our site and performed a specific action). We do not receive any of your personal data from your profile from Meta—we only receive aggregated reports. However, the Pixel itself transmits certain information about your device and behavior (the address of the visited page, cookie ID, IP address, browser information, etc.) to Meta, which Meta can link to data from your Facebook/Instagram account and also use for its purposes. As a result, Meta also acts here to a certain extent as a separate data controller that uses the data for its purposes. More information can be found in Facebook's privacy policy. In EU countries, we use the Pixel only with your express consent (consent for marketing cookies). This consent is voluntary—you can withdraw it at any time. After withdrawing consent, the Pixel will be deactivated in your browser, and we will no longer track your activities or target personalized ads to you. More information on data processing by Meta can be found in the Meta Privacy Policy and the Meta Cookie Policy.
Google Ads – our sites may use Google Ads remarketing code, which saves cookies that allow us to display our ads to you on the Google Display Network (e.g., on YouTube, in the Google search engine, or on Google AdSense partner sites) based on your activity on our sites. For example, if you visited a specific product page on our site, the remarketing cookie may cause you to see an ad for that product while browsing another website. This mechanism, like the Pixel, is activated in the EU only with your consent for marketing cookies.
LinkedIn Insight Tag – on our websites, we may use the LinkedIn Insight Tag—a piece of JavaScript code provided by LinkedIn that enables conversion tracking, audience creation, and analysis of the effectiveness of advertising campaigns conducted on the LinkedIn platform. The Insight Tag saves cookies in the user's browser that allow us to identify visitors to our site as LinkedIn users (if they have an account there) and monitor their interactions with our site. The data collected includes, among other things: pages visited, URL, browser type, IP address, device information, and a timestamp. This data is then sent to LinkedIn and can be used to create personalized advertising campaigns and analyze the effectiveness of our marketing activities. The Insight Tag is activated only after obtaining your express consent for marketing cookies. You can withdraw this consent at any time through our cookie consent management mechanism. For more information on cookies related to LinkedIn, please see their Policy: https://www.linkedin.com/legal/cookie-policy .
Mailchimp – on our websites, we may use tracking features offered by the Mailchimp platform, used for managing newsletters, analyzing the effectiveness of email dispatches, and monitoring further user interactions with our site after clicking on a link from a message. Mailchimp may save cookies in the user's browser and use so-called "web beacons" (tracking pixels) embedded in the content of emails. Thanks to these technologies, it is possible to track information such as: the fact that a message was opened, a link was clicked, the date and time of the interaction, IP address, browser type, device data, and the path of movement on the site after coming from the newsletter. The collected data is sent to Mailchimp and used for analytical purposes—e.g., to report on campaign effectiveness, create recipient segments, and automate marketing. We do not receive any data from Mailchimp that would allow user identification if they have not previously consented to subscribe to the newsletter. Mailchimp may process user data on servers located in the United States—the data transfer is based on standard contractual clauses and certification under the EU–U.S. Data Privacy Framework. Mailchimp technologies are activated only after obtaining your express consent for marketing cookies. You can withdraw this consent at any time through our cookie consent management mechanism. Additionally, you can unsubscribe from the newsletter by clicking the "Unsubscribe" link available in every message. More information on data and cookie processing by Mailchimp can be found in their privacy policy: Global Privacy Statement | Intuit
Other advertising tools – depending on our marketing campaigns, we may periodically use other advertising platforms (such as LinkedIn Ads, Twitter Ads, etc.) that operate on a similar principle—by placing a relevant advertising script/pixel and associated cookies on our site. If new external advertising tools are implemented, we will update our privacy/cookie policy and inform users about the appearance of new cookies.
These are cookies set directly by our websites. They are primarily used for the proper functioning of the site and for collecting basic information about how users use the site. Thanks to these cookies, it is possible, for example, to remember preferences, maintain a logged-in user's session, and analyze basic statistics about visits and traffic on the site. Unlike third-party cookies, first-party cookies are not used to track the user outside our site.
In addition to traditional cookies, our websites may also use other tracking technologies that allow for the analysis of how the site is used, the optimization of its operation, and the conduct of marketing activities. These technologies do not always rely on saving information in the browser in the form of cookies—they may operate based on mechanisms such as localStorage, pixel tags (tracking pixels), browser fingerprinting, or the analysis of IP addresses for approximate user geolocation. Some of these solutions allow for the identification of visitors even when they do not provide their contact details or express clear preferences for browsing the site. In this regard, we use, among others:
Cookies can be session-based (deleted automatically when you close your browser) or persistent (they remain on your device for a specified period or until you manually delete them). On our site, we use both session and persistent cookies. Essential and preference cookies are usually session or short-term, while analytical and marketing cookies may remain active for longer. For example, standard Google Analytics cookies (_ga) can stay on your device for up to 2 years, and user data in statistics can be stored for up to 14 months (according to the default data retention settings in GA). In turn, some Google advertising cookies (e.g., Google Ads remarketing cookies) can remain valid for up to 540 days if not deleted by the user earlier. Detailed information about the lifespan of individual cookies can be checked in the settings of the cookie management banner available on our sites or in your browser settings.
You have control over the cookies used by our websites. Below are ways to manage cookies and tracking preferences:
On your first visit to our site, we display a cookie banner where you can accept or reject individual categories of cookies (except for essential ones, which are always active). You can change your choices at any time—click on the link to the cookie settings (e.g., "Privacy Preferences" or a shield icon) available on our site and adjust your consents there.
You can also manage cookies at the level of your web browser. Most browsers allow you to delete already saved cookies, block the saving of new cookies, and set preferences for selected websites. However, please remember that by blocking all cookies (including essential ones), you may lose access to some features of our site or cause it to function incorrectly. You can find instructions for managing cookies in the documentation or help section of the browser you use. For convenience, here are a few examples:
Our site honors "Do Not Track" signals sent by the browser. If you have enabled this option in your browser, our service will recognize this signal and will not track you for analytical or marketing purposes. The "Do Not Track" setting works globally, meaning external analytical/advertising tools (such as the Hotjar above) should also stop tracking your activity. You can check or enable this setting in your browser's options (usually in the Privacy section).
Regardless of the above methods, you can also use the opt-out options offered directly by some of our external partners. For example:
Please remember that changing cookie settings or withdrawing consents does not automatically delete existing cookies from your device. You can always delete cookies yourself through your browser's options. If you have any questions or problems related to cookies on our site, please contact us—we will be happy to help.
Printbox operates internationally, so your personal data may be transferred to countries outside the European Economic Area (EEA). This applies in particular to:
EU law requires that such a data transfer ensures a level of data protection adequate to that in Europe. Therefore:
If the European Commission has recognized a given country as providing an adequate level of data protection (has an adequacy decision), then we base the transfer on this decision. For example, Israel or Japan has such a decision.
In the case of the USA: As of July 2023, there is an adequacy decision for the EU-US Data Privacy Framework (a framework for data transfer to the USA). Some of our providers may be certified under this program, which means that a transfer to them is permissible as if it were within the EEA. We check the status of our providers on an ongoing basis.
If a country does not have an adequacy decision (which applies, among others, to the USA for non-certified entities, as well as other countries like India, Brazil, etc.), we use appropriate contractual safeguards, primarily the Standard Contractual Clauses (SCCs) approved by the European Commission (by Article 46 of the GDPR). SCCs oblige the data recipient outside the EEA to protect data by EU standards. In addition, where necessary, we implement additional protective measures, e.g., data encryption, limiting the scope of data transferred, and strict access policies.
In the case of transfers within the Printbox group (Poland <-> USA), we also use appropriate mechanisms (e.g., we have signed a data processing agreement with Standard Contractual Clauses between Printbox Sp. z o.o. and Printbox LLC). Thanks to this, even data transferred to the USA remains protected by this agreement.
In special situations, we may base the transfer on an exception provided for in Article 49 of the GDPR (e.g., when the transfer is necessary for the performance of a contract with you or for the establishment or defense of legal claims) – however, we primarily try to rely on the safeguards mentioned above.
Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict that person's preferences, interests, behavior, location, etc. At Printbox, certain activities may be considered profiling. Still, we do not make decisions about you that produce legal effects or similarly significantly affect you based solely on automated processing (by Article 22 of the GDPR). This means that we do not entrust algorithms with decisions that would affect your rights or opportunities (e.g., we do not use automatic refusal to conclude a contract without human intervention).
Mainly for marketing and analytical purposes, as described in the previous sections. Examples:
We analyze your behavior on the website (e.g., which subpages you visit, which materials you download) to infer which products or topics may be of interest to you. Based on this, we can customize the content of the newsletter or offer sent to you (e.g., if you frequently read about photobooks, we may provide you with a case study of a client from the photobook industry).
If you have consented to advertising cookies, tools such as the Facebook Pixel or Google Ads will profile you within their platforms – e.g., they will assign you to a group of people interested in e-commerce software – which will result in you being shown relevant ads.
We use customer segmentation in our CRM – e.g., we distinguish between active and inactive customers, potential (leads), and contracted ones – to tailor our commercial communication to them accordingly.
You have the right to object at any time to the processing of your data for direct marketing purposes, including profiling to the extent that it is related to such marketing (Article 21(2) of the GDPR). If you object, we will stop such profiling and/or sending you marketing. Furthermore, suppose you believe that profiling based on our legitimate interest violates your legitimate rights or interests. In that case, you can also object for these reasons (Article 21(1) of the GDPR) – we will consider your objection unless we can demonstrate compelling legitimate grounds that override your interests.
As mentioned, as part of our marketing activities, we use ads targeted to users' interests. This is done through partners such as Google or Meta, who use cookies and online identifiers to match advertising content to your internet user profile. We ensure that these ads relate exclusively to our services and products (we do not share your data with other companies to advertise unrelated products to you). You can opt out of behavioral advertising from us at any time – instructions can be found in Section 8.
We make every effort to ensure the security of your personal data and protect it from accidental or unlawful destruction, loss, modification, unauthorized disclosure, or access. Printbox has implemented appropriate technical, physical, and organizational measures by applicable laws and industry standards to protect the data we process. We use, among other things, modern IT infrastructure security solutions (firewalls, intrusion detection systems), encryption of data transmission (HTTPS/SSL protocol for connections to our website), regular software updates, and system monitoring for vulnerabilities. We store personal data on secure servers, in professional data centers that meet high protection standards.
Access to your personal data is granted only to authorized persons for whom it is necessary to perform their duties – our employees or trusted subcontractors. All of them are obliged to maintain confidentiality and comply with Printbox's internal security policies. We regularly train our staff on data protection and apply the principle of access minimization (each person sees only the data needed for their role). Furthermore, we have procedures in place for security incidents (including potential data breaches) – in the event of such an incident, we will take immediate steps to resolve it and minimize its effects, and if required, we will notify the relevant authorities and data subjects (by Articles 33–34 of the GDPR). Despite the measures taken, please remember that no system guarantees 100% security. The Internet as a communication environment carries some risk – e.g., when sending information via email or online forms, you should be cautious (especially when using a public Wi-Fi network). Printbox continuously improves its security measures to meet emerging threats, but cannot entirely rule out, for example, the effects of highly sophisticated attacks. However, we assure you that within our capabilities, we apply industry best practices to keep your data safe with us. If you have additional questions about the security of your data, we encourage you to contact us: gdpr@getprintbox.com .
System logs are automatically created records of events on our servers that note basic information about how users use our websites. When you visit any Printbox website, our IT system may automatically save data in the logs such as: the IP address of your device, the date and time of the visit, the URL of the requested page (the specific HTTP request), information about your browser and operating system (the so-called User-Agent header sent by your browser), and possibly other technical data, e.g., the referring page address (referrer), application errors, etc. This information is collected automatically by the server in the background – this happens for all users visiting the site, regardless of whether they are logged in or not.
System logs are used mainly for administrative and security purposes. Thanks to them, we can, for example, monitor the correct operation of the site, diagnose technical problems (by analyzing error entries), and also protect our IT systems – logs allow us to detect abuse (e.g., hacking attempts, DDoS attacks) and analyze any incidents. The legal basis for processing data in the logs is our legitimate interest (Article 6(1)(f) of the GDPR) in ensuring the security and proper functioning of the service. We do not use data from server logs to identify specific individuals or for marketing purposes. These records are primarily for IT administrators, and access to them is strictly limited.
How long do we store logs? We store the data contained in server logs for a limited time, by the principle of minimization. We usually delete or anonymize logs after a maximum of 36 months from their registration. More extended storage of logs may occur exceptionally – e.g., if log entries are needed for evidentiary purposes in connection with an ongoing investigation or defense against claims (in such a case, we may retain selected logs until the matter is clarified or the proceedings are legally concluded). After the storage period expires, the logs are securely deleted or anonymized. Information from the logs, as technical data, is not disclosed to unauthorized entities. It may only be transferred to authorized bodies (e.g., police, prosecutor's office) based on legal provisions or used by us to protect our rights (by applicable law) legally.
The law and the scope of our business may change, so from time to time we update this Privacy Policy to keep it up to date with current regulations and our practices. At the top of the document, you will find the publication/last update date.
In the event of significant changes (e.g., changes in processing purposes, introduction of new services that significantly affect how data is processed, or changes regarding your rights), we will take additional steps to notify you. This may include sending an email notification (if we have your email address in our database) or displaying a clear notice on our website during your next visit.
We encourage you to periodically review the Privacy Policy to be aware of how we protect your data. Your continued use of our sites and services after the updates are implemented will mean acceptance of the new content of the Policy (unless the law requires separate consent in a specific case). To ensure complete transparency, all archived versions of the privacy policy are available below.