Draft document. The entity name, address, tax ID, retention periods and commercial terms are sample data — they show the document’s complete shape and are not binding until replaced.
This document describes what personal data we process in connection with the Splotra service, on what legal basis and for how long. It describes how the system actually behaves, not what we intend to build.
Splotra sp. z o.o. (sample data), ul. Przykładowa 1, 00-001 Warszawa, Poland, tax ID 0000000000 — sample data. Data protection contact: kontakt@splotra.com.
| Category | Scope | Source |
|---|---|---|
| Account data | e-mail address, username, password hash, second-factor secret | provided by you when the account is created |
| Team data | team name, memberships, invitations (invitee e-mail address) | provided by you while using the service |
| Data you upload | contents of the files and source URLs you point us at, typically a product catalogue | provided by you, or fetched from the address you supplied |
| Technical data | request correlation identifiers, timestamps, status codes, IP address in proxy logs | generated automatically |
We do not write the contents of your source records into logs. Logs carry identifiers and metrics, so that an operation can be traced without duplicating your data in a second place.
Account and team data — for as long as you use the service and 30 days after account closure (sample period). Data you upload — until you delete it or close the account; historical versions are immutable by design, and deletion covers them as well. Technical logs — 12 months (sample period).
We use infrastructure providers that process data solely on our instructions:
Authentication runs on our own infrastructure, without a third-party identity provider. We do not share your data for marketing purposes and we do not sell it.
This website sets no cookies and loads no external resources — there is no
analytics, no social plugins and no fonts fetched from third-party servers. The signed-in
application uses strictly necessary session cookies only; they are marked httpOnly
and are not accessible to scripts in the browser.
You have the right to access your data, rectify it, erase it, restrict processing, port it, and to object to processing based on legitimate interest. You may lodge a complaint with the Polish data protection authority (Prezes Urzędu Ochrony Danych Osobowych). Send requests to the address in section 1.
Connections are encrypted with TLS. Irreversible operations — publishing, rolling back, issuing an API token, inviting someone to a team — require a fresh second-factor authentication. One team’s data is isolated from another’s at the level of database queries and object storage keys.
We announce material changes before they take effect. Last updated: 11 September 2026 (sample date).