CERTICA.EU PRIVACY POLICY

Section 1. General provisions

This Privacy Policy sets out the rules for processing personal data of Users of the certica.eu website (the "Service").

The controller of Users' personal data is MOCKIT PROSTA SPÓŁKA AKCYJNA with its registered office in Płock, address: ul. Swojska 25A, 09-410 Płock, entered in the National Court Register (KRS) under number 0001062495, tax ID (NIP): 7743281916, REGON: 526618046, email: jakub.wujec@certica.eu (the "Controller").

Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the Act on the provision of electronic services.

Section 2. Purposes and legal bases for processing data

Users' personal data is processed for the following purposes:

  • Providing services and Account management (including authentication) - the legal basis is the necessity of processing for the performance of a contract (Article 6(1)(b) GDPR).
  • Processing payments and issuing invoices - the legal basis is compliance with a legal obligation to which the Controller is subject under tax law (Article 6(1)(c) GDPR).
  • Handling complaints and contact with the User - the legal basis is the legitimate interest of the Controller (Article 6(1)(f) GDPR).
  • Pursuing or defending against claims - the legal basis is the legitimate interest of the Controller (Article 6(1)(f) GDPR).
  • Product analytics and IT security (including error monitoring) - to improve service quality and ensure proper operation of the Service, which constitutes a legitimate interest of the Controller (Article 6(1)(f) GDPR).

Section 3. Scope of data collected

Depending on the User's activity, the Controller processes the following data:

  • Registration data: email address (passwords are encrypted and processed by an external authentication provider).
  • Billing data: company name, tax ID (NIP), registered office address.
  • Technical and analytics data: IP address, browser information, server logs, activity history in the Service, data on any application errors.

Section 4. Data recipients (Who do we share data with?)

The Controller maintains the highest standard of data security and confidentiality. All application data is hosted on Google Cloud Platform (GCP) servers located in the Warsaw region (Poland), which ensures that the main databases do not leave the territory of the European Economic Area. In the course of providing services, the Controller uses trusted external entities (processors) to whom personal data may be entrusted:

  • WorkOS - for secure authentication and login processing for Users.
  • Stripe Inc. - for processing card transactions and payments.
  • Fakturownia Sp. z o.o. (fakturownia.pl) - for automatic issuance of VAT invoices via API.
  • Sentry - for application error monitoring (detecting technical problems).
  • PostHog - for product analytics (studying how Users use the application).
  • External accounting office - for the Controller's accounting and tax services.

Note: Where data is transferred to entities established outside the European Economic Area (e.g. to Stripe Inc. or WorkOS infrastructure in the USA), the Controller relies on appropriate legal safeguards, including Standard Contractual Clauses adopted by the European Commission.

Section 5. Data retention period

Data related to maintaining the Account and providing the Service is stored for as long as the User holds an Account.

After Account deletion, billing data necessary for accounting and tax purposes is stored for 5 years, counting from the end of the calendar year in which the tax obligation arose (in accordance with Polish law).

Data processed for the purpose of defending against potential claims may be stored until the claims become time-barred.

Section 6. User rights

Each User has the right to:

  • Access their data and receive a copy.
  • Rectify (correct) their data.
  • Erasure of data (right to be forgotten) - unless other legal provisions require further storage (e.g. accounting legislation).
  • Restriction of processing.
  • Data portability.
  • Object to processing based on legitimate interest (including product analytics).
  • Lodge a complaint with a supervisory authority - the President of the Personal Data Protection Office (PUODO) in Warsaw.

Section 7. Cookies and tracking technologies

The Service uses cookies and browser local storage for proper operation of the website. These are so-called essential cookies, responsible among other things for secure login and session maintenance (handled in part by WorkOS technology). These files do not require User consent.

The Service uses the PostHog analytics tool, which collects anonymous or pseudonymised data on how Users use the platform, for its continuous improvement.

The Service does not use marketing cookies for tracking users for advertising purposes (such as Facebook Pixel or Google Ads).

Users can manage cookies through their web browser settings or block analytics scripts using blocking plugins (e.g. ad blockers), which will not affect the basic functionality of the Service.