Privacy Policy
Last updated: 1 April 2024 · Version 1.0 · Compliant with EU GDPR (2016/679) and Polish UODO Act
1. Data Controller
The controller of your personal data is Teckologs sp. z o.o., registered in Poland. Data Protection Officer (DPO): dpo@teckologs.com.
The supervisory authority in Poland is the Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw. Website: uodo.gov.pl.
2. Data We Collect
Name, email address, phone number, date of birth, country, profile picture. Legal basis: GDPR Art. 6(1)(b) — performance of contract.
Government-issued ID, selfie with ID. Legal basis: GDPR Art. 6(1)(c) — legal obligation (Polish AML Act, EU AML Directive).
Booking history, payment records, Stripe customer ID (no raw card data stored). Legal basis: GDPR Art. 6(1)(b) — contract performance; Art. 6(1)(c) — accounting law.
Swipe activity, browsing history within the app, device type. Legal basis: GDPR Art. 6(1)(f) — legitimate interest (platform improvement), or consent where required.
Messages sent through our platform, support tickets. Legal basis: GDPR Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest.
3. How We Use Your Data
- Providing, maintaining and improving Teckologs services
- Identity verification and fraud prevention
- Processing bookings and payments
- Matching users with relevant service providers
- Sending transactional communications (booking confirmations, etc.)
- Marketing communications (with your explicit consent only)
- Complying with legal obligations (AML, tax law, court orders)
4. Data Sharing
We do not sell your personal data. We share data only with:
- Stripe, Inc. — payment processing (DPA in place; SCCs applied for US transfers)
- Supabase, Inc. — database and storage infrastructure (GDPR-compliant; EU data residency)
- Vercel, Inc. — application hosting (DPA in place)
- Service providers you book with — necessary booking details only
- Law enforcement / authorities — when legally required
5. International Transfers
Some of our processors (Stripe, Vercel) are based in the United States. Transfers are covered by Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Art. 46(2)(c). A Transfer Impact Assessment (TIA) has been completed for each transfer.
6. Retention Periods
7. Your Rights
Under GDPR and Polish UODO Act, you have the right to:
- Access your data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erasure ("right to be forgotten") (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
- Not be subject to automated decision-making (Art. 22)
- Withdraw consent at any time without affecting prior processing
- Lodge a complaint with UODO (uodo.gov.pl)
Exercise your rights via: My Data Center or email privacy@teckologs.com. We respond within 30 days (GDPR Art. 12(3)).
8. Cookies
We use essential cookies (required for functionality) and optional analytics/marketing cookies. You can manage your cookie preferences at any time via our Cookie Center. See our Cookie Policy for full details.
9. Security
We implement appropriate technical and organizational measures per GDPR Art. 25 and 32, including: encryption at rest and in transit (TLS 1.3), row-level database security, principle of least privilege, regular security audits, and incident response procedures. In the event of a data breach, we will notify affected users and UODO within 72 hours as required by GDPR Art. 33-34.
10. Contact
Privacy inquiries: privacy@teckologs.com
DPO: dpo@teckologs.com
Postal: Teckologs sp. z o.o., Warsaw, Poland