Privacy Policy
Last updated: April 4, 2026
1. Data Controller
The data controller is FactoryDeck sp. z o.o. based in Poland. Data Protection Officer contact: dpo@factorydeck.app.
2. Legal Basis for Processing
We process data based on Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest — system security, analytics).
3. Categories of Data
We process: email address, first and last name, company name, hashed IP address, system activity logs.
4. Retention Periods
Account data: duration of agreement + 3 years after closure. Activity logs: 12 months. Analytics data (EventLog): 24 months.
5. Data Subject Rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), portability (Art. 20), and objection (Art. 21 GDPR). To exercise these rights, contact us at dpo@factorydeck.app.
6. Data Processors
Data may be processed by: Railway (hosting EU/US + SCC), Resend (email, US + SCC), GitHub (support tickets).
7. Data Transfers Outside EEA
Data transfers to the US are governed by Standard Contractual Clauses (SCC) under Art. 46 GDPR.
8. Complaints
You have the right to lodge a complaint with the Polish Data Protection Authority (uodo.gov.pl).