Privacy policy
1. Controller
The controller of the data of DoPusk Service Users is Sergey Panphilov, Kąty Grodziskie 19B/39, 03-289 Warszawa, kontakt@dopusk.pl. (For Employee data entered by the User — see point 8: processing entrustment.)
2. What data we process (User data)
Account data: first name, surname, email address, company data (if provided). Technical data: access logs, IP address, device type — to the extent necessary for operation and security.
3. Purposes and legal bases
Providing the service (Art. 6(1)(b) GDPR); security and logs (Art. 6(1)(f) — legitimate interest); legal obligations, e.g. donation accounting (Art. 6(1)(c)).
4. Retention period
Account data — for the duration of using the Service and until any claims become time-barred. Logs — up to 12 months.
5. Recipients
Infrastructure providers (hosting) with which processing agreements are concluded. Data is not sold. The Service uses no profiling or third-party advertising cookies.
6. Cookies
The Service uses only essential files (session, preferences, including language and theme choice). No marketing cookies and no profiling. Visit statistics for the public pages are aggregate and cookie-free (Cloudflare Web Analytics) — no user profile is created. Fonts are hosted locally — no requests to external CDNs.
7. Individual rights
Access, rectification, erasure, restriction, objection, data portability, and a complaint to the President of the UODO. Handled via: kontakt@dopusk.pl.
8. Processing entrustment (Employee data)
Employee data entered by the User is processed by the Operator as a processor on behalf of the User (the controller of that data). The rules are set out in the Data Processing Agreement (DPA) — see the separate document.
9. Transfers outside the EEA
Data is stored in the EEA; there are no transfers to third countries. (Should the infrastructure provider change — appropriate safeguards under Art. 46 GDPR will be ensured.)
10. Security
Field-level encryption of sensitive data, an audit log, document checksums — details on the Security page.
11. Processing entrustment (DPA)
Employee data entered by the User is processed by the Operator as a processor under a Data Processing Agreement (DPA), accepted when the Account is created. Full text: Data Processing Agreement (DPA).
Effective date: 01.08.2026