Privacy policy
1. Data controller (Art. 13(1)(a) GDPR)
SystemGalerii.pl — System Galerii Wojciech Rygielski
Address: Warsaw, Poland
Email: kontakt@systemgalerii.pl
Phone: +48 453 653 831
Effective from: 1 January 2024
2. Data Protection Officer (Art. 37 GDPR)
Data Protection Officer: Michał Grycz
Email: iod@systemgalerii.pl
3. Scope and categories of data collected (Art. 13(1)(c) GDPR)
| Category | Data scope | Source |
|---|---|---|
| Account data | Email address, name, password hash (bcrypt), role, avatar | From user (registration) |
| Gallery data | Titles, descriptions, photos, tags, theme settings | From user (upload) |
| Payment data | Order history, amounts, billing address NOTE: card numbers are NOT stored — processed by Stripe | From user + Stripe |
| Technical data | IP address, browser type, operating system, screen resolution, language | Automatically (HTTP headers) |
| Analytics data | Navigation path, time on page, events (clicks), web vitals | Umami (anonymous) |
| Contact data | Email, message content (support requests) | From user (form) |
4. Purposes and legal basis of processing (Art. 13(1)(c) GDPR)
| Purpose | Legal basis | Data category |
|---|---|---|
| Account registration and maintenance | Art. 6(1)(b) GDPR (contract performance) | Account data |
| Provision of Platform services | Art. 6(1)(b) GDPR (contract performance) | Gallery data, technical data |
| Payment and billing processing | Art. 6(1)(b) GDPR (contract performance) | Payment data |
| Sending notifications (invoices, status changes) | Art. 6(1)(c) GDPR (legal obligation) | Account data |
| Analytics and Platform improvement | Art. 6(1)(a) GDPR (consent) + (f) (legitimate interest) | Analytics data, technical data |
| Marketing and personalisation | Art. 6(1)(a) GDPR (consent) | Account data, cookies |
| Claims enforcement and legal defence | Art. 6(1)(f) GDPR (legitimate interest) | All categories |
5. Data retention periods (Art. 13(2)(a) GDPR)
| Data type | Retention period | Justification |
|---|---|---|
| Account data (active) | For the duration of account use | Contract performance |
| Account data (after deletion) | 30 days (grace period), then permanent deletion | Art. 17 GDPR + reversal option |
| Payment data (invoices) | 5 years from end of tax year | Tax obligation (Tax Ordinance) |
| Activity logs | 365 days (1 year) | Legitimate interest — security |
| Audit logs | 730 days (2 years) | Legal requirement |
| Notifications | 180 days (6 months) | Automatic cleanup |
| Analytics data (raw) | 90 days (3 months) | Anonymisation after analysis |
| Sessions (Redis) | 30 days (automatic Redis TTL) | Session maintenance |
6. Recipients and subprocessors (Art. 13(1)(e) GDPR)
| Entity | Purpose | Location | Safeguards |
|---|---|---|---|
| Stripe, Inc. | Payment processing | USA (Privacy Framework) | Standard Contractual Clauses (SCC) |
| Vercel, Inc. | Application hosting | EU (Frankfurt) + USA | DPA + SCC |
| Neon (PostgreSQL) | Database hosting | EU (Frankfurt) | DPA + encryption |
| Redis Labs | Cache and sessions | EU | DPA |
| Sentry | Error and performance monitoring | USA (SCC) | DPA + SCC |
| Replicate, Inc. | AI — background removal, colorization, photo culling, descriptions, face detection, restoration, upscaling | USA (SCC) | DPA + SCC |
| Backblaze B2 | Media file storage (photos, videos) | USA (SCC) | DPA + Standard Contractual Clauses (SCC) |
| iFirma | VAT invoices (billing data) | Poland (EU) | Processing agreement / DPA |
| SMTP provider | Transactional email (notifications, password reset) | EU / per configuration | TLS + DPA |
| Umami | Analytics (anonymous) | EU (self-hosted) | No personal data |
7. Data security (Art. 32 GDPR)
- Transmission encryption: All data transmitted via SSL/TLS (HTTPS)
- Password encryption: Passwords stored as bcrypt (12 rounds)
- JWT tokens: Short-lived access tokens (15 min) with refresh token rotation
- Data separation: Databases in isolated instances within the EU
- Backups: Encrypted backups with 30-day retention
- Monitoring: 24/7 availability and data integrity monitoring
- Audit: Logging of all administrative actions
- Access: Least privilege principle
8. Your rights (Art. 15–22 GDPR)
Art. 15 — Right of access
You have the right to obtain confirmation as to whether we process your data and to receive a copy. You may use the data export tool in your user panel.
Art. 16 — Right to rectification
You have the right to request immediate rectification of inaccurate personal data. You may edit your data in the user panel or contact us.
Art. 17 — Right to erasure ("right to be forgotten")
You have the right to request erasure of your data when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent and there is no other legal basis
- You object to processing
- The data was processed unlawfully
You may delete your account in the user panel (Settings → Delete account) or send a request to kontakt@systemgalerii.pl.
Art. 18 — Right to restriction of processing
You have the right to request restriction of processing when you contest the accuracy of data, object to erasure, or need the data to establish or defend legal claims.
Art. 20 — Right to data portability
You have the right to receive your data in a structured, commonly used format (JSON) and transmit it to another controller. Use data export in the panel.
Art. 21 — Right to object
You have the right to object to processing based on legitimate interest, including profiling. After objection, we will cease processing unless we demonstrate compelling legitimate grounds.
Art. 22 — Automated decision-making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects users.
9. Right to withdraw consent (Art. 7(3) GDPR)
10. Cookie policy
| Type | Name | Purpose | Period | Required |
|---|---|---|---|---|
| Essential | sg-token, __Host-sg-token, sg-refresh | Authentication and session (JWT) | Session / 7 days (30 with “remember me”) | ✅ |
| Essential | sg-session, sg-csrf | Session marker, CSRF protection | Session / 24 h | ✅ |
| Essential | gallery_invite_*, sg-client-token, __Host-sg-client-token, client-id, client-id-sig | Gallery and client panel access (JWT) | 30 days | ✅ |
| Essential | sg-2fa-pending, __Host-oauth_state | 2FA verification, OAuth login state | 5–10 min | ✅ |
| Consent | __Host-sg-analytics-consent, __Host-sg-marketing-consent, __Host-sg-preferences-consent | Consent choice storage (audit) | 1 year | ✅ |
| Preference | sg-lang | Interface language | 1 year | — |
| Functional | gcal_oauth_uid | Google Calendar integration (optional) | Session | — |
| Analytics | — (no cookies) | Umami — anonymous data sent via POST, cookieless | — | — |
| Payments (third party) | __stripe_sid, __stripe_mid | Stripe payment processing (stripe.com domain) | Session / 1 year | only during payment |
11. Transfers to third countries (Art. 44–49 GDPR)
- European Commission adequacy decisions (Privacy Framework)
- Standard Contractual Clauses (SCC) approved by the European Commission
12. Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
President of the Personal Data Protection Office (UODO)
Address: ul. Stawki 2, 00-193 Warsaw, Poland
Tel.: +48 22 531 03 00
Email: biuro@uodo.gov.pl
Website: www.uodo.gov.pl
We recommend contacting us first — most issues can be resolved quickly and amicably.
13. Changes to this privacy policy
14. Privacy contact
Data Protection Officer (DPO):
Email: iod@systemgalerii.pl
Controller:
Email: kontakt@systemgalerii.pl
Phone: +48 453 653 831