Splotra

Draft document. The entity name, address, tax ID, retention periods and commercial terms are sample data — they show the document’s complete shape and are not binding until replaced.

Privacy policy

This document describes what personal data we process in connection with the Splotra service, on what legal basis and for how long. It describes how the system actually behaves, not what we intend to build.

1. Data controller

Splotra sp. z o.o. (sample data), ul. Przykładowa 1, 00-001 Warszawa, Poland, tax ID 0000000000 — sample data. Data protection contact: kontakt@splotra.com.

2. What data we process

CategoryScopeSource
Account datae-mail address, username, password hash, second-factor secret provided by you when the account is created
Team datateam name, memberships, invitations (invitee e-mail address) provided by you while using the service
Data you uploadcontents of the files and source URLs you point us at, typically a product catalogueprovided by you, or fetched from the address you supplied
Technical datarequest correlation identifiers, timestamps, status codes, IP address in proxy logsgenerated automatically

We do not write the contents of your source records into logs. Logs carry identifiers and metrics, so that an operation can be traced without duplicating your data in a second place.

3. Legal basis and purpose

4. Retention

Account and team data — for as long as you use the service and 30 days after account closure (sample period). Data you upload — until you delete it or close the account; historical versions are immutable by design, and deletion covers them as well. Technical logs — 12 months (sample period).

5. Processors

We use infrastructure providers that process data solely on our instructions:

Authentication runs on our own infrastructure, without a third-party identity provider. We do not share your data for marketing purposes and we do not sell it.

6. Cookies and tracking

This website sets no cookies and loads no external resources — there is no analytics, no social plugins and no fonts fetched from third-party servers. The signed-in application uses strictly necessary session cookies only; they are marked httpOnly and are not accessible to scripts in the browser.

7. Your rights

You have the right to access your data, rectify it, erase it, restrict processing, port it, and to object to processing based on legitimate interest. You may lodge a complaint with the Polish data protection authority (Prezes Urzędu Ochrony Danych Osobowych). Send requests to the address in section 1.

8. Security

Connections are encrypted with TLS. Irreversible operations — publishing, rolling back, issuing an API token, inviting someone to a team — require a fresh second-factor authentication. One team’s data is isolated from another’s at the level of database queries and object storage keys.

9. Changes

We announce material changes before they take effect. Last updated: 11 September 2026 (sample date).