Version 2026-06-02 · effective from June 2, 2026
Privacy Policy
1. Data Controller
The controller of personal data relating to the Client account (directory owner) and data collected on katalogio.pl is [COMPANY NAME / FULL NAME], with its registered office at [REGISTERED ADDRESS], Tax ID [TAX ID] (“Controller”).
Contact for data protection matters: [DATA PROTECTION EMAIL].
The Controller has not appointed a Data Protection Officer (DPO). The obligation to appoint one is subject to periodic review under Article 37 of the GDPR.
2. Two Roles: Controller and Processor
The Platform operates on a multi-tenant (SaaS) model. Depending on the category of data, we act in different roles:
We act as controller
- for Client (directory owner) account data — e.g. email address, billing data;
- for data collected directly on katalogio.pl (registration form, contact form).
We act as processor
- with respect to data the Client enters into their directory (data of vendors/ specialists, data of people making contact, event sign-ups). In this scope, the Client is the controller, and we process this data solely on their documented instructions, under a data processing agreement (DPA, GDPR Art. 28).
3. Categories of Data and Purposes of Processing
We process the following categories of data depending on the relationship:
Client (directory owner)
- identification and contact data (email, directory name, optionally company details);
- billing data (tax ID, address, payment history — handled via Stripe);
- technical login data (IP address, session identifier, system logs).
Vendor / specialist (added by the Client or self-registered)
- vendor account data (email, hashed password) and profile data published in the directory.
Visitor / person making contact (customer)
- contact details and preferences provided voluntarily (e.g. event sign-up / RSVP, contact form);
- technical data and cookies (see section 9).
Special category data (GDPR Art. 9 — including health data). The Platform is not intended for processing health data or other sensitive data. Clients are prohibited from entering such data into custom fields and forms without conducting their own data protection impact assessment (DPIA) and having an appropriate legal basis. The interface warns when attempting to create fields whose names suggest medical data or a national ID number.
4. Legal Bases (GDPR Art. 6)
- Art. 6(1)(b) — performance of a contract (maintaining the account, providing directory features);
- Art. 6(1)(c) — legal obligations (including issuing and retaining invoices, handling complaints);
- Art. 6(1)(f) — legitimate interest (ensuring security, preventing abuse, pursuing claims, service analytics);
- Art. 6(1)(a) — consent (e.g. analytics/marketing cookies, marketing communications) — may be withdrawn at any time.
5. Data Retention Periods
- account data — for the duration of account activity and up to 3 years after closure (statute of limitations for claims);
- billing data and invoices — 5 years from the end of the tax year (tax obligation);
- system logs — generally up to 90 days;
- consent records (acceptance of the Terms and Privacy Policy) — for the term of the agreement and the statute-of-limitations period (accountability, GDPR Art. 7);
- data entrusted by the Client — for the term of the agreement with the Client; after termination, the Client is given access to export the data, after which it is permanently deleted in accordance with the data processing agreement.
6. Recipients of Data and Processors
We use trusted providers (sub-processors) who process data solely on our behalf under data processing agreements. Current list:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | application hosting, CDN | USA |
| Supabase | database, authentication, file storage | EU |
| Stripe | payments, invoicing (Platform–Client relationship) | USA / EU |
| Tpay | marketplace payments (Client–vendor relationship) | Poland |
| Resend | transactional email delivery | USA / EU |
| Google (Places API) | address search and autocomplete | USA |
| OpenStreetMap / Nominatim | maps and geocoding | EU |
This list may change; the current list of sub-processors is made available to Clients on request and as part of the data processing agreement.
7. Transfers of Data Outside the EEA
Some providers (including Vercel, Stripe, Google) may process data in the USA. Transfers are carried out on the basis of appropriate safeguards referred to in GDPR Art. 46 — standard contractual clauses (SCCs) or the provider’s participation in the Data Privacy Framework (DPF). A copy of the safeguards can be obtained by contacting [DATA PROTECTION EMAIL].
8. Rights of Data Subjects
You have the following rights (GDPR Art. 15–22):
- access to your data and to obtain a copy of it;
- rectification (correction) of data;
- erasure of data (“the right to be forgotten”);
- restriction of processing;
- data portability (in a structured format, e.g. CSV/JSON);
- objection to processing based on legitimate interest;
- withdrawal of consent at any time (without affecting the lawfulness of processing carried out before withdrawal).
We process requests without undue delay, no later than within 30 days (GDPR Art. 12(3)). Where we process data as a processor (data in a Client’s directory), we will forward the request to the relevant controller (the Client). You also have the right to lodge a complaint with the President of the Polish Data Protection Authority (UODO) or your local supervisory authority.
10. Data Security
We apply technical and organizational measures appropriate to the risk, including: encrypted transmission (TLS/HTTPS, HSTS), data isolation between Clients (Row Level Security), role-based access control, password hashing (bcrypt), rate limiting, and security headers (including CSP). A detailed description of the measures is provided in the annex to the data processing agreement (TOMs).
11. Automated Decisions and Profiling
We do not make decisions about users based solely on automated processing that would produce legal effects or similarly significantly affect them (GDPR Art. 22).
12. Changes to this Policy
We may update this Policy. We will notify you of material changes in advance (e.g. by email or a notice on the service). Each version is marked with a date and version number shown at the top of the document; the version currently in force is 2026-06-02.