Skip to content
SystemGalerii
GalleryPricingBlogAboutContact
Sign in Sign up
Privacy

Privacy policy

Last updated: August 17, 2026

Table of contents

  1. 1. Data controller (Art. 13(1)(a) GDPR)
  2. 2. Data Protection Officer (Art. 37 GDPR)
  3. 3. Scope and categories of data collected (Art. 13(1)(c) GDPR)
  4. 4. Purposes and legal basis of processing (Art. 13(1)(c) GDPR)
  5. 5. Data retention periods (Art. 13(2)(a) GDPR)
  6. 6. Recipients and subprocessors (Art. 13(1)(e) GDPR)
  7. 7. Data security (Art. 32 GDPR)
  8. 8. Your rights (Art. 15–22 GDPR)
  9. 9. Right to withdraw consent (Art. 7(3) GDPR)
  10. 10. Cookie policy
  11. 11. Transfers to third countries (Art. 44–49 GDPR)
  12. 12. Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
  13. 13. Changes to this privacy policy
  14. 14. Privacy contact

1. Data controller (Art. 13(1)(a) GDPR)

The controller of your personal data is:

SystemGalerii.pl — System Galerii Wojciech Rygielski

Address: Warsaw, Poland

Email: kontakt@systemgalerii.pl

Phone: +48 453 653 831

Effective from: 1 January 2024

2. Data Protection Officer (Art. 37 GDPR)

We have appointed a Data Protection Officer whom you may contact regarding all matters relating to personal data processing and the exercise of data protection rights.

Data Protection Officer: Michał Grycz

Email: iod@systemgalerii.pl

3. Scope and categories of data collected (Art. 13(1)(c) GDPR)

Depending on how you use the Platform, we process the following categories of data:
CategoryData scopeSource
Account dataEmail address, name, password hash (bcrypt), role, avatarFrom user (registration)
Gallery dataTitles, descriptions, photos, tags, theme settingsFrom user (upload)
Payment dataOrder history, amounts, billing address
NOTE: card numbers are NOT stored — processed by Stripe
From user + Stripe
Technical dataIP address, browser type, operating system, screen resolution, languageAutomatically (HTTP headers)
Analytics dataNavigation path, time on page, events (clicks), web vitalsUmami (anonymous)
Contact dataEmail, message content (support requests)From user (form)

4. Purposes and legal basis of processing (Art. 13(1)(c) GDPR)

PurposeLegal basisData category
Account registration and maintenanceArt. 6(1)(b) GDPR (contract performance)Account data
Provision of Platform servicesArt. 6(1)(b) GDPR (contract performance)Gallery data, technical data
Payment and billing processingArt. 6(1)(b) GDPR (contract performance)Payment data
Sending notifications (invoices, status changes)Art. 6(1)(c) GDPR (legal obligation)Account data
Analytics and Platform improvementArt. 6(1)(a) GDPR (consent) + (f) (legitimate interest)Analytics data, technical data
Marketing and personalisationArt. 6(1)(a) GDPR (consent)Account data, cookies
Claims enforcement and legal defenceArt. 6(1)(f) GDPR (legitimate interest)All categories

5. Data retention periods (Art. 13(2)(a) GDPR)

We retain data for the following periods:
Data typeRetention periodJustification
Account data (active)For the duration of account useContract performance
Account data (after deletion)30 days (grace period), then permanent deletionArt. 17 GDPR + reversal option
Payment data (invoices)5 years from end of tax yearTax obligation (Tax Ordinance)
Activity logs365 days (1 year)Legitimate interest — security
Audit logs730 days (2 years)Legal requirement
Notifications180 days (6 months)Automatic cleanup
Analytics data (raw)90 days (3 months)Anonymisation after analysis
Sessions (Redis)30 days (automatic Redis TTL)Session maintenance

6. Recipients and subprocessors (Art. 13(1)(e) GDPR)

We entrust data processing to the following entities:
EntityPurposeLocationSafeguards
Stripe, Inc.Payment processingUSA (Privacy Framework)Standard Contractual Clauses (SCC)
Vercel, Inc.Application hostingEU (Frankfurt) + USADPA + SCC
Neon (PostgreSQL)Database hostingEU (Frankfurt)DPA + encryption
Redis LabsCache and sessionsEUDPA
SentryError and performance monitoringUSA (SCC)DPA + SCC
Replicate, Inc.AI — background removal, colorization, photo culling, descriptions, face detection, restoration, upscalingUSA (SCC)DPA + SCC
Backblaze B2Media file storage (photos, videos)USA (SCC)DPA + Standard Contractual Clauses (SCC)
iFirmaVAT invoices (billing data)Poland (EU)Processing agreement / DPA
SMTP providerTransactional email (notifications, password reset)EU / per configurationTLS + DPA
UmamiAnalytics (anonymous)EU (self-hosted)No personal data

7. Data security (Art. 32 GDPR)

We apply the following technical and organisational measures:
  • Transmission encryption: All data transmitted via SSL/TLS (HTTPS)
  • Password encryption: Passwords stored as bcrypt (12 rounds)
  • JWT tokens: Short-lived access tokens (15 min) with refresh token rotation
  • Data separation: Databases in isolated instances within the EU
  • Backups: Encrypted backups with 30-day retention
  • Monitoring: 24/7 availability and data integrity monitoring
  • Audit: Logging of all administrative actions
  • Access: Least privilege principle

8. Your rights (Art. 15–22 GDPR)

You have the following rights:
Art. 15 — Right of access

You have the right to obtain confirmation as to whether we process your data and to receive a copy. You may use the data export tool in your user panel.

Art. 16 — Right to rectification

You have the right to request immediate rectification of inaccurate personal data. You may edit your data in the user panel or contact us.

Art. 17 — Right to erasure ("right to be forgotten")

You have the right to request erasure of your data when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis
  • You object to processing
  • The data was processed unlawfully

You may delete your account in the user panel (Settings → Delete account) or send a request to kontakt@systemgalerii.pl.

Art. 18 — Right to restriction of processing

You have the right to request restriction of processing when you contest the accuracy of data, object to erasure, or need the data to establish or defend legal claims.

Art. 20 — Right to data portability

You have the right to receive your data in a structured, commonly used format (JSON) and transmit it to another controller. Use data export in the panel.

Art. 21 — Right to object

You have the right to object to processing based on legitimate interest, including profiling. After objection, we will cease processing unless we demonstrate compelling legitimate grounds.

Art. 22 — Automated decision-making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects users.

To exercise the above rights, write to: iod@systemgalerii.pl. We will respond within 30 days (Art. 12 GDPR).

9. Right to withdraw consent (Art. 7(3) GDPR)

Where processing is based on consent (Art. 6(1)(a) GDPR), you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
You can manage cookie consent via the cookie banner displayed on the site or in your browser settings.

10. Cookie policy

Our Platform uses the following types of cookies:
TypeNamePurposePeriodRequired
Essentialsg-token, __Host-sg-token, sg-refreshAuthentication and session (JWT)Session / 7 days (30 with “remember me”)✅
Essentialsg-session, sg-csrfSession marker, CSRF protectionSession / 24 h✅
Essentialgallery_invite_*, sg-client-token, __Host-sg-client-token, client-id, client-id-sigGallery and client panel access (JWT)30 days✅
Essentialsg-2fa-pending, __Host-oauth_state2FA verification, OAuth login state5–10 min✅
Consent__Host-sg-analytics-consent, __Host-sg-marketing-consent, __Host-sg-preferences-consentConsent choice storage (audit)1 year✅
Preferencesg-langInterface language1 year—
Functionalgcal_oauth_uidGoogle Calendar integration (optional)Session—
Analytics— (no cookies)Umami — anonymous data sent via POST, cookieless——
Payments (third party)__stripe_sid, __stripe_midStripe payment processing (stripe.com domain)Session / 1 yearonly during payment
Cookie management: you can change settings at any time via the cookie banner or in your browser settings. Disabling essential cookies may prevent use of the Platform.

11. Transfers to third countries (Art. 44–49 GDPR)

Some of our subprocessors (Stripe, Vercel) are based in the USA. Data transfers are based on:
  • European Commission adequacy decisions (Privacy Framework)
  • Standard Contractual Clauses (SCC) approved by the European Commission
You may request a copy of the safeguards applied by contacting our DPO.

12. Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)

If you believe data processing violates GDPR, you have the right to lodge a complaint with:

President of the Personal Data Protection Office (UODO)

Address: ul. Stawki 2, 00-193 Warsaw, Poland

Tel.: +48 22 531 03 00

Email: biuro@uodo.gov.pl

Website: www.uodo.gov.pl

We recommend contacting us first — most issues can be resolved quickly and amicably.

13. Changes to this privacy policy

We reserve the right to amend this Privacy Policy. We will notify users of any changes by email (to the address provided during registration) and by posting information on the website.
Last updated: 1 June 2026.

14. Privacy contact

For all matters relating to personal data protection:

Data Protection Officer (DPO):

Email: iod@systemgalerii.pl

Controller:

Email: kontakt@systemgalerii.pl

Phone: +48 453 653 831

Related documents

Terms of Service Cookie settings Contact
SystemGalerii

A professional platform for managing and sharing photo galleries for photographers and their clients.

Navigation

  • Gallery
  • Pricing
  • Blog
  • About
  • Contact

Contact

  • kontakt@systemgalerii.pl
  • +48 453 653 831
  • Warsaw, Poland

Newsletter

Stay up to date with news and promotions.

© 2026 SystemGalerii.pl — All rights reserved.

Terms of Service· Privacy Policy· FAQ· Changelog· Roadmap· System Status· API Documentation