Katalogio
Create your directory

Version 2026-06-02 · effective from June 2, 2026

Privacy Policy

This Privacy Policy describes how the Katalogio platform (“Platform”, “we”) processes personal data of users of the service available at katalogio.pl, as well as in the subdomains and custom domains of directories operated by our Clients. This document complies with the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council).

1. Data Controller

The controller of personal data relating to the Client account (directory owner) and data collected on katalogio.pl is [COMPANY NAME / FULL NAME], with its registered office at [REGISTERED ADDRESS], Tax ID [TAX ID] (“Controller”).

Contact for data protection matters: [DATA PROTECTION EMAIL].

The Controller has not appointed a Data Protection Officer (DPO). The obligation to appoint one is subject to periodic review under Article 37 of the GDPR.

2. Two Roles: Controller and Processor

The Platform operates on a multi-tenant (SaaS) model. Depending on the category of data, we act in different roles:

We act as controller

  • for Client (directory owner) account data — e.g. email address, billing data;
  • for data collected directly on katalogio.pl (registration form, contact form).

We act as processor

  • with respect to data the Client enters into their directory (data of vendors/ specialists, data of people making contact, event sign-ups). In this scope, the Client is the controller, and we process this data solely on their documented instructions, under a data processing agreement (DPA, GDPR Art. 28).

3. Categories of Data and Purposes of Processing

We process the following categories of data depending on the relationship:

Client (directory owner)

  • identification and contact data (email, directory name, optionally company details);
  • billing data (tax ID, address, payment history — handled via Stripe);
  • technical login data (IP address, session identifier, system logs).

Vendor / specialist (added by the Client or self-registered)

  • vendor account data (email, hashed password) and profile data published in the directory.

Visitor / person making contact (customer)

  • contact details and preferences provided voluntarily (e.g. event sign-up / RSVP, contact form);
  • technical data and cookies (see section 9).

Special category data (GDPR Art. 9 — including health data). The Platform is not intended for processing health data or other sensitive data. Clients are prohibited from entering such data into custom fields and forms without conducting their own data protection impact assessment (DPIA) and having an appropriate legal basis. The interface warns when attempting to create fields whose names suggest medical data or a national ID number.

4. Legal Bases (GDPR Art. 6)

  • Art. 6(1)(b) — performance of a contract (maintaining the account, providing directory features);
  • Art. 6(1)(c) — legal obligations (including issuing and retaining invoices, handling complaints);
  • Art. 6(1)(f) — legitimate interest (ensuring security, preventing abuse, pursuing claims, service analytics);
  • Art. 6(1)(a) — consent (e.g. analytics/marketing cookies, marketing communications) — may be withdrawn at any time.

5. Data Retention Periods

  • account data — for the duration of account activity and up to 3 years after closure (statute of limitations for claims);
  • billing data and invoices — 5 years from the end of the tax year (tax obligation);
  • system logs — generally up to 90 days;
  • consent records (acceptance of the Terms and Privacy Policy) — for the term of the agreement and the statute-of-limitations period (accountability, GDPR Art. 7);
  • data entrusted by the Client — for the term of the agreement with the Client; after termination, the Client is given access to export the data, after which it is permanently deleted in accordance with the data processing agreement.

6. Recipients of Data and Processors

We use trusted providers (sub-processors) who process data solely on our behalf under data processing agreements. Current list:

ProviderPurposeLocation
Vercel Inc.application hosting, CDNUSA
Supabasedatabase, authentication, file storageEU
Stripepayments, invoicing (Platform–Client relationship)USA / EU
Tpaymarketplace payments (Client–vendor relationship)Poland
Resendtransactional email deliveryUSA / EU
Google (Places API)address search and autocompleteUSA
OpenStreetMap / Nominatimmaps and geocodingEU

This list may change; the current list of sub-processors is made available to Clients on request and as part of the data processing agreement.

7. Transfers of Data Outside the EEA

Some providers (including Vercel, Stripe, Google) may process data in the USA. Transfers are carried out on the basis of appropriate safeguards referred to in GDPR Art. 46 — standard contractual clauses (SCCs) or the provider’s participation in the Data Privacy Framework (DPF). A copy of the safeguards can be obtained by contacting [DATA PROTECTION EMAIL].

8. Rights of Data Subjects

You have the following rights (GDPR Art. 15–22):

  • access to your data and to obtain a copy of it;
  • rectification (correction) of data;
  • erasure of data (“the right to be forgotten”);
  • restriction of processing;
  • data portability (in a structured format, e.g. CSV/JSON);
  • objection to processing based on legitimate interest;
  • withdrawal of consent at any time (without affecting the lawfulness of processing carried out before withdrawal).

We process requests without undue delay, no later than within 30 days (GDPR Art. 12(3)). Where we process data as a processor (data in a Client’s directory), we will forward the request to the relevant controller (the Client). You also have the right to lodge a complaint with the President of the Polish Data Protection Authority (UODO) or your local supervisory authority.

9. Cookies

We use cookies and similar technologies. Essential cookies (session, security, storing consent choices) are always active and do not require consent. Analytics and marketing cookies are only activated once you consent via the cookie banner. You can change your choice at any time by reopening the cookie settings. Details on the categories are presented in the consent banner shown on your first visit.

10. Data Security

We apply technical and organizational measures appropriate to the risk, including: encrypted transmission (TLS/HTTPS, HSTS), data isolation between Clients (Row Level Security), role-based access control, password hashing (bcrypt), rate limiting, and security headers (including CSP). A detailed description of the measures is provided in the annex to the data processing agreement (TOMs).

11. Automated Decisions and Profiling

We do not make decisions about users based solely on automated processing that would produce legal effects or similarly significantly affect them (GDPR Art. 22).

12. Changes to this Policy

We may update this Policy. We will notify you of material changes in advance (e.g. by email or a notice on the service). Each version is marked with a date and version number shown at the top of the document; the version currently in force is 2026-06-02.

Katalogio
Terms of ServicePrivacy PolicyDPA
© 2026 Katalogio. All rights reserved.