Skip to content

Privacy policy

What data we process, why, on what legal basis and for how long – and what rights you have.

Version
1.3
Effective from
Updated

Content: Privacy policy

Draft – requires legal review before publication. Items marked “to be completed” will be filled in once confirmed by the Seller.

This English version is provided for customers using the English version of the website. [to be completed: whether contracts are concluded in English and which language version prevails – any clause giving priority to the Polish version requires legal review with regard to consumers.]

This policy explains what personal data we process on the AutomaizeIT website, for what purposes and on what legal basis, and what rights you have (Article 13 GDPR – Regulation (EU) 2016/679).

1. Controller

The controller is [to be completed: full legal business name], [to be completed: registered address], tax ID (NIP) [to be completed: tax ID (NIP)], REGON [to be completed: REGON number], EU VAT number [to be completed: EU VAT number], registered in: [to be completed: business register (CEIDG or KRS)] (the Controller).

Contact on data protection matters: e-mail kontakt@automaizeit.com, phone +48 501 343 343, or in writing to the Controller's address. The Controller has not appointed a data protection officer [to be confirmed].

2. Purposes, legal bases and retention periods

Purpose Data Legal basis (GDPR) Retention
Replying to a contact form message or e-mail name, e-mail, phone, company, subject, message Art. 6(1)(f) (legitimate interest: replying to enquiries); Art. 6(1)(b) where the enquiry concerns entering into a contract for the duration of the correspondence, then [to be completed, e.g. 12 months] or until claims become time-barred if the correspondence concerns them
Concluding and performing the contract (Order, supply of the Application, Subscription, renewal e-mails) customer type, country, name or company name, tax ID or EU VAT number, address, e-mail, Order details, accepted version of the terms and statements made, payment ID and status Art. 6(1)(b) for the duration of the contract, then until claims become time-barred
Running the Customer Account (registration, sign-in, account management) e-mail address, password hash (we store passwords only in transformed form), address confirmation status, language, dates of creation, change and last sign-in, Account event history Art. 6(1)(b) (contract for the Account) for as long as the Account exists; once it is deleted we remove the profile and keep only the data described in point 4 below
Account sessions (keeping you signed in and Account security) session token hash (we do not store the token from the cookie), time of creation and of last activity, hashed IP address, a short description of the browser (e.g. “Firefox · Windows”) Art. 6(1)(b) and Art. 6(1)(f) (legitimate interest: Account security, detecting unauthorised sign-ins) until sign-out, a password change or session expiry – 30 days after the last activity at the latest
Confirming the e-mail address, resetting the password, changing the e-mail address e-mail address, hashes of one-time tokens and their validity (address confirmation and address change – 24 hours, password reset – 1 hour) Art. 6(1)(b) and Art. 6(1)(f) (Account security) until the token is used or expires; a record of the event remains in the Account history
Requests and complaints submitted via the Account or by e-mail (comment, bug, suggestion, complaint) category, subject and content of the request, the Order or licence concerned, correspondence, status and history of the request Art. 6(1)(b) and (c) (obligations under the Consumer Rights Act) until claims become time-barred
Issuing and administering licences (Licence key, download links) licence identifier, Order details, e-mail address, licence status, number and time of downloads, licence event history Art. 6(1)(b) for the duration of the licence, then until claims become time-barred
Verifying the Application licence (activation and periodic checks, every 60 seconds) licence identifier, hash of the operating system identifier, hashes of network card (MAC) addresses, shortened IP address, Application and operating system version, time and result of the verification (we do not store this hardware data in plain form, only cryptographic hashes of it) Art. 6(1)(b) (making the licensed functions available) and Art. 6(1)(f) (legitimate interest: preventing licence abuse) for the duration of the licence and 12 months after it ends; aggregated data on the availability of the verification service (licence server logs) is kept for the licence period plus 12 months as evidence in complaint procedures and when accounting for licence-server interruptions (§ 9(11) of the Terms of sale), and in the event of a dispute, until claims become time-barred
Evidence of the statements made when ordering (request to begin performance, acknowledgement of the loss of the right of withdrawal, acceptance of technical limitations) wording of the statements, date and time, version of the terms, hashed IP address, time the confirmation was sent and the Licence key released Art. 6(1)(c) and Art. 6(1)(f) (demonstrating compliance with the Consumer Rights Act, defending claims) until claims under the contract become time-barred
Verifying the EU VAT number in VIES and determining the VAT treatment EU VAT number, country, verification result and date Art. 6(1)(c) in conjunction with the Polish VAT Act; Art. 6(1)(f) (demonstrating due diligence) as for tax records
Tax and accounting obligations (invoices, records, including OSS records) invoice details, Order details, data evidencing the Customer's country Art. 6(1)(c) 5 years from the end of the calendar year in which the tax payment deadline expired; OSS records – 10 years from the end of the year of the transaction
Handling withdrawals and complaints data from the withdrawal or complaint form, Order details, correspondence Art. 6(1)(b) and (c) (obligations under the Consumer Rights Act) until claims become time-barred
Establishing, exercising or defending legal claims Order details and correspondence Art. 6(1)(f) until claims become time-barred
Accountability for cookie consents (consent log) decision ID, cookie policy version, selected categories, type of decision, time, hashed IP address Art. 6(1)(c) in conjunction with Art. 7(1) GDPR, and Art. 6(1)(f) [to be completed, e.g. for the validity of the consent and the limitation period]
Interface diagnostic log (only with consent) interface events (clicks – label of the element, load times, JavaScript errors, page path), random tab session ID, hashed IP address Art. 6(1)(a) (consent) until the technical log is rotated [period to be confirmed] or consent is withdrawn
Bot protection for forms (CAPTCHA – Cloudflare Turnstile) IP address, browser and device data and signals about how the browser window is used, collected by the verification script; a one-time verification token Art. 6(1)(f) (legitimate interest: protecting forms against spam and automated abuse) on our side: only the verification result with a hashed IP address in the technical logs (log file rotation); at the service provider – in line with its own privacy policy [period to be confirmed]
Website security and diagnostics (server logs) technical data of HTTP requests (time, page path, result, processing time), hashed IP address Art. 6(1)(f) (legitimate interest: security and continuity of service) log file rotation (approx. 10 files of 10 MB) [period to be confirmed]

The hashed IP address is a cryptographic hash created with a secret key – it lets us recognise repeated requests (e.g. form abuse), but full IP addresses are not stored in the logs (pseudonymisation). We treat the device identifier used in licence verification in the same way: we compare hashes rather than hardware data, we do not build a user profile from them, and we do not combine them with form data beyond linking them to the licence they concern.

Visitor statistics (without cookies)

We keep visitor statistics without cookies and without storing IP addresses. From your IP address and browser details we create a one-time hash that lets us count unique visitors for a single day; the hash key is generated daily and never stored, so after 24 hours it cannot be linked to a person. We store only aggregated daily data (pages visited, referring domain, language, device type, campaign parameters) on our own server, based on our legitimate interest (Art. 6(1)(f) GDPR).

3. Recipients

Data may be shared only with parties that help us run the Website and perform contracts:

  • OVH – server and e-mail hosting [to be completed: OVH entity according to the agreement], as a processor;
  • PayPro S.A. (Przelewy24) – payment processing; for payment data the operator acts as a separate controller [to be confirmed according to the agreement];
  • the European Commission / EU tax administrations (VIES) – for the EU VAT number being verified;
  • Cloudflare, Inc. – bot protection for forms (the Turnstile service), as a processor; it processes the IP address and browser data of the person filling in the form, solely to tell a human from an automated script (no profiling, no advertising cookies);
  • accounting office [to be completed] – for accounting documents;
  • public authorities – only where required by law.

Licence verification data is processed on our own server and is not shared with third parties. We do not sell data or share it for marketing purposes. The Website does not use advertising cookies or third-party analytics tools; fonts are hosted on our own server. The only script loaded from an external server is the CAPTCHA widget (Cloudflare Turnstile) – loaded only on pages with a protected form and only while the protection is switched on.

4. Customer Account: deleting the account and keeping documents

You can delete your Account at any time, without giving a reason and at no cost, from within the Account.

We delete: the profile and contact details, the password, sessions and sign-in history, and the Account event history; we anonymise contact form messages and unpaid Orders.

We keep, for as long as the law requires: invoices and other accounting records and the data of paid Orders (5 years from the end of the calendar year in which the tax payment deadline expired – under the Polish Tax Ordinance and the Accounting Act; OSS records – 10 years), as well as evidence of the statements made when the contract was concluded and data needed to defend against claims – until claims become time-barred. The legal basis is Article 17(3)(b) GDPR (legal obligation) and Article 17(3)(e) GDPR (establishment, exercise or defence of legal claims). This data is moved to an archive with restricted access and is not used for any other purpose.

Please note: deleting the Account does not invalidate the licence or the Licence key, but it removes access to the Account where the key and the documents are shown. Save a copy of your Licence key and sales documents before deleting the Account.

5. Transfers outside the EEA

Apart from the data described below, we do not transfer data to countries outside the European Economic Area [to be confirmed after reviewing the agreements with OVH and the payment operator]. The server is located in the EU [location to be confirmed].

The exception is bot protection for forms: we use Cloudflare Turnstile, and Cloudflare, Inc. is established in the United States and processes data across a global network of servers. The transfer is based on the standard contractual clauses approved by the European Commission (Art. 46(2)(c) GDPR) and, to the extent the provider participates in the Data Privacy Framework, on the European Commission's adequacy decision (Art. 45 GDPR) [the basis and the participation status are to be confirmed in the agreement with the provider before publication]. We provide a copy of the safeguards on request – write to kontakt@automaizeit.com.

6. Your rights

You have the right to:

  • access your data and receive a copy (Art. 15 GDPR),
  • rectification (Art. 16),
  • erasure (Art. 17) – subject to the exceptions described in point 4,
  • restriction of processing (Art. 18),
  • portability of data processed on the basis of a contract or consent (Art. 20),
  • object to processing based on legitimate interest (Art. 21) – including the processing of licence verification data for the purpose of preventing abuse,
  • withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (you can change your consent to the diagnostic log via the “Cookie settings” link in the footer),
  • lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) or with the supervisory authority in the EU Member State where you live or work.

To exercise your rights, write to kontakt@automaizeit.com or submit a request in your Account. We provide the copy of your data in a commonly used, machine-readable format.

7. Whether providing data is required

Providing data is voluntary. However, data marked as required in the forms is necessary to reply, to open an Account, to conclude and perform the contract, or to issue an invoice (a statutory requirement). Without it we cannot handle the enquiry, the Account or the Order. The data sent during licence verification is necessary to make the licensed functions available – without it the Application cannot confirm that you are entitled to use it.

8. Automated decisions and profiling

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. The VAT rate in the order Summary is calculated automatically based on tax law, your country and the VIES result; if in doubt, you can contact us before paying [requires legal review]. The automated licence check (comparing the hash of the device identifier and the number of concurrent sessions) serves solely to make the licensed functions available; you can ask for any refusal to run the Application to be reviewed by a person – in your Account or by writing to kontakt@automaizeit.com.

9. Source of data

Data comes directly from you or from the Application installed on your device (licence verification). The EU VAT number verification result comes from VIES.

10. Changes to this policy

The current version and effective date are shown on this page. We notify material changes affecting concluded contracts by e-mail.

Version 1.3 of 21 September 2026. Version 1.3 describes bot protection for forms (the Cloudflare Turnstile service): the purpose and legal basis (legitimate interest), the scope of data (IP address, browser data), Cloudflare, Inc. as a processor, and transfers outside the EEA based on the standard contractual clauses. Earlier versions: 1.2 completed the licence-verification row – the verification interval (every 60 seconds), the full scope of data sent (hash of the system identifier, hashes of MAC addresses, shortened IP address, Application and OS versions) and the retention period (for the duration of the licence plus 12 months after it ends); 1.1 added descriptions of the processing of Customer Account and session data, requests and complaints, licence verification data and evidence of the statements made when ordering, together with the rules on deleting an Account where documents must still be kept for accounting purposes; 1.0 – the original version.