1. Data controller
The data controller is RFC INTERNET Sp. z o.o. Sp. z o.o., with its registered office at ul. Kujawska 2, 85-031 Bydgoszcz, Polska, NIP: 9532640377, REGON: 341482466, KRS: 0000477042. Data-protection contact: internet@rfc.pl. General contact: internet@rfc.pl.
Polish Office of Electronic Communications (UKE) telecom-operator register entry: 11113.
3. Purposes and legal bases of processing
We process your personal data for the following purposes and on the following legal bases:
- providing the service (creating and maintaining your account, sign-in flows) — art. 6(1)(b) GDPR (performance of a contract);
- ensuring the security of the service, preventing abuse, throttling sign-in attempts — art. 6(1)(f) GDPR (legitimate interest of the Controller);
- monitoring application errors to keep the service running (Sentry) — art. 6(1)(f) GDPR (legitimate interest of the Controller); form values are masked before transmission;
- analysing service usage and session recordings with masked content (PostHog) — art. 6(1)(a) GDPR (consent); analytics starts only after you give consent in the banner;
- measuring advertising effectiveness and remarketing (Google Ads) — art. 6(1)(a) GDPR (consent);
- compliance with legal obligations of the Controller, in particular tax and accounting obligations — art. 6(1)(c) GDPR.
4. Data recipients — processors
Your data may be entrusted to the following processors, acting on our documented instructions:
- the frontend hosting provider (Polska) and the backend hosting provider (Polska);
- Sentry — error monitoring service; processing location: Polska;
- PostHog Cloud EU — product analytics and session recordings with masked content; data is processed on servers within the European Union (Unia Europejska); only after you give consent;
- Google Ireland Limited — advertising effectiveness and remarketing; only after you give consent.
5. Transfers outside the European Economic Area
As a rule your data is processed within the European Economic Area. Where a provider's infrastructure requires a transfer outside the EEA, it takes place exclusively under Standard Contractual Clauses approved by the European Commission (art. 46(2)(c) GDPR) or other appropriate safeguards.
6. Data retention
- account data — kept for up to 3 years after account closure or until the limitation period for claims expires;
- transactional and accounting data — 5 years from the end of the financial year (Polish accounting law);
- analytics data (PostHog) — up to 12 months;
- error reports (Sentry) — up to 90 days;
- session and activity logs — until sign-out and 30 days afterwards for security purposes.
7. Your rights
- right of access to your data (art. 15 GDPR);
- right to rectification (art. 16 GDPR);
- right to erasure — “right to be forgotten” (art. 17 GDPR);
- right to restriction of processing (art. 18 GDPR);
- right to data portability (art. 20 GDPR);
- right to object to processing based on legitimate interest (art. 21 GDPR);
- right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (art. 7(3) GDPR); cookie consents can be withdrawn via the “Manage cookies” link in the footer;
- right to lodge a complaint with the President of the Personal Data Protection Office — ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl.
8. Children's data
The service is not directed at persons under 16 years of age and we do not knowingly collect their data. If we become aware that data of a person under 16 has been collected without parental consent, we will delete it without undue delay.
9. Automated decision-making
We do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject (art. 22 GDPR).
10. Changes to this policy
This policy may be updated. The date of the last update is shown at the top of the document. We will notify you of material changes separately — for example via a banner or e-mail.
11. Contact
For all data-protection matters please contact: internet@rfc.pl.