Privacy Policy

Last updated: April 4, 2026

1. Data Controller

The data controller is FactoryDeck sp. z o.o. based in Poland. Data Protection Officer contact: dpo@factorydeck.app.

2. Legal Basis for Processing

We process data based on Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest — system security, analytics).

3. Categories of Data

We process: email address, first and last name, company name, hashed IP address, system activity logs.

4. Retention Periods

Account data: duration of agreement + 3 years after closure. Activity logs: 12 months. Analytics data (EventLog): 24 months.

5. Data Subject Rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), portability (Art. 20), and objection (Art. 21 GDPR). To exercise these rights, contact us at dpo@factorydeck.app.

6. Data Processors

Data may be processed by: Railway (hosting EU/US + SCC), Resend (email, US + SCC), GitHub (support tickets).

7. Data Transfers Outside EEA

Data transfers to the US are governed by Standard Contractual Clauses (SCC) under Art. 46 GDPR.

8. Complaints

You have the right to lodge a complaint with the Polish Data Protection Authority (uodo.gov.pl).

Privacy Policy — FactoryDeck