Privacy
policy
How we collect, use and protect your personal data - in line with the GDPR and Polish data protection law.
This is a courtesy translation. In case of any discrepancy, the Polish-language version of this document is legally binding.
DoSwiftly is a SaaS platform for online stores. For the User's account we are the data controller. For store end-customer data we are a processor acting under a DPA. We use trusted providers (including OVH, Cloudflare, Postmark, PayU) and apply encryption, data isolation and access control. You have the right of access, rectification, erasure and others - described in section 9.
§ 1 Data controller
The controller of your personal data when you use DoSwiftly is:
- Entrepreneur: Jakub Gabrychowicz, running a sole proprietorship
- Company: JAKUB GABRYCHOWICZ GameGoods
- Address: ul. Łęczycka 15/1, 99-340 Krośniewice, woj. łódzkie
- NIP (Tax ID): 7752647541
- REGON: 360765637
- Service brand: DoSwiftly
- Email: kontakt@doswiftly.pl
- Phone: +48 666 596 594
The Operator (hereinafter also: DoSwiftly or we) is a micro-enterprise and - pursuant to Art. 37 GDPR - is not required to appoint a Data Protection Officer. In all matters concerning personal data, however, the Operator can be contacted using the details in § 2.
§ 2 How to reach us about data
- Email (preferred): kontakt@doswiftly.pl - put "GDPR" in the subject.
- Post: JAKUB GABRYCHOWICZ GameGoods, ul. Łęczycka 15/1, 99-340 Krośniewice.
- Phone: +48 666 596 594.
We respond within 30 days; in complex cases - up to 90 days, with notice of the extension (Art. 12(3) GDPR).
§ 3 The roles in which we process data
DoSwiftly acts in two roles with respect to different sets of data:
- As a Controller we process the data of Users (persons creating an Account and running a Store), billing data, our own marketing, usage statistics, and traffic on doswiftly.pl.
- As a Processor within the meaning of Art. 28 GDPR we process the data of end Customers of Stores run by Merchants. The controller of this data is the Merchant, and we act solely on their documented instructions, in accordance with the Data Processing Agreement (DPA).
§ 4 Purposes of processing and legal bases
| Purpose | Legal basis (GDPR) | Retention period |
|---|---|---|
| Creating and running the Account, providing the Service, support | Art. 6(1)(b) - performance of the Agreement | Duration of the Agreement + 30 days soft-delete |
| Signing in with a Google or Facebook account (if you choose it) | Art. 6(1)(b) - performance of the Agreement | Until such sign-in is disconnected or the Account is deleted |
| Sending transactional emails (registration confirmations, invoices, system notifications) | Art. 6(1)(b) - performance of the Agreement; (c) - legal obligation (invoices) | Delivery logs (metadata: status, message ID, timestamp): 90 days; message content - per the retention of the source purpose (e.g. invoice: 5 years); aggregate rate/bounce statistics: 7 days |
| SMS notifications about Store events (if you enable the SMS channel) | Art. 6(1)(b) - performance of the Agreement | Until the SMS channel is disabled |
| Issuing invoices, tax settlements | Art. 6(1)(c) - legal obligation (Polish Tax Ordinance, Accounting Act) | 5 years from the end of the tax year |
| DoSwiftly's own marketing (newsletter, offers) | Art. 6(1)(a) - consent (opt-in); art. 398 of the Polish Electronic Communications Law | Until consent is withdrawn |
| Analytics, usage statistics, Platform optimization (without analytics cookies) | Art. 6(1)(f) - legitimate interest (product development) | Up to 24 months |
| Security, audit logs, abuse prevention, protecting the sign-in and registration forms against bots (Google reCAPTCHA) | Art. 6(1)(f) - legitimate interest | Up to 365 days |
| Defense against and pursuit of claims | Art. 6(1)(f) - legitimate interest | Limitation period for claims (as a rule 6 years; for business-related claims - 3 years) |
| Handling data-subject rights (Art. 15-22 GDPR), complaint handling | Art. 6(1)(c) - legal obligation | 3 years from case closure |
Providing data is voluntary but necessary to conclude and perform the Agreement and to issue a VAT invoice. Failure to provide data makes it impossible to create an Account.
§ 5 Categories of data processed
- Identifying: first and last name; in the Team's billing profile - company name and NIP.
- Contact: email, phone, mailing address.
- Account and access: login (email address), password stored only as a cryptographic hash, session tokens; when signing in with Google or Facebook - that account's identifier and the first name, last name, email address and profile photo passed on by the provider.
- Billing: invoice data, payment history, PayU transaction ID. We do not store full card numbers - they are processed by PayU as the tokenizer.
- Technical: IP address, user-agent, browser and device data, application instance ID.
- Behavioral: in-app events (e.g. product creation, order), the event log (audit log).
- Store-related: data entered by the Merchant in the dashboard (products, orders, store customers). For this data the Operator is a processor - see the DPA.
- Communication: email correspondence and messages sent to us on Discord, call recordings (where made and after prior notice).
§ 6 Data recipients and sub-processors
Data may be shared with the following categories of recipients:
6.1. Sub-processors
| Sub-processor | Role | Location |
|---|---|---|
| OVH SAS | Hosting of servers, databases and backups; email for the doswiftly.pl domain | Poland (EEA) |
| PayU S.A. | Payment operator for Plans and top-ups, card tokenization | Poland (EEA) |
| Cloudflare, Inc. | CDN, DNS, protection against DDoS attacks and bots, Workers, R2 storage, Custom Hostnames | USA + EU edge (transfer outside the EEA - see § 7) |
| AC PM, LLC (Postmark) | Sending transactional emails (order confirmations, invoices, system notifications, password reset) | Chicago, Illinois, USA (transfer outside the EEA - see § 7) |
| SMSAPI | Sending SMS notifications (if you enable the SMS channel) | Poland (EEA) |
The current list of sub-processors (with links to their policies) is available at /en/dpa#subprocesorzy. We announce changes with 14 days' notice; the Merchant has the right to object - see the DPA.
6.2. Other recipients
- law firms, accounting offices, tax advisors and auditors - to the extent of the services provided, under a confidentiality agreement;
- DMARC reports: the Operator receives aggregate DMARC reports (XML aggregate reports) from Merchants' mail domains at an internal security-monitoring address - they serve solely to detect sender-spoofing attempts and contain no message content or end-recipient data;
- payment operators and financial institutions - to the extent necessary to carry out transactions;
- Google Ireland Ltd. - when you sign in with a Google account and when the sign-in and registration forms are protected against bots (reCAPTCHA); Google processes this data under its own privacy policy;
- Meta Platforms Ireland Ltd. - when you sign in with a Facebook account;
- Discord Inc. - when you contact us on the DoSwiftly Discord server; Discord processes the messages as a separate controller, under its own privacy policy;
- state authorities (courts, prosecutors, tax authorities, the Polish DPA / PUODO, UOKiK) - solely on the basis of a binding, lawful request.
§ 7 Data transfers outside the EEA
Some sub-processors (Cloudflare, AC PM LLC / Postmark) operate outside the European Economic Area. Data is transferred on the basis of:
- Standard Contractual Clauses (SCC) adopted by the European Commission (Decision 2021/914);
- the EU-US Data Privacy Framework for certified providers;
- where necessary - supplementary measures (encryption, pseudonymization, transfer risk assessment).
Data transferred to AC PM, LLC (Postmark) - the transactional email operator - is processed in the United States (Chicago, Illinois). The basis for the transfer is AC PM, LLC's certification under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795 of 10.07.2023) and - additionally - the European Commission's Standard Contractual Clauses (Module 2, Decision 2021/914) incorporated into the Postmark Terms of Service. AC PM, LLC has contractually committed not to use the entrusted Data for purposes other than providing the email sending service (Postmark DPA, § 3.a). Postmark's sub-processors (Deft, AWS US) operate solely in the USA.
A copy of the safeguards applied can be obtained by contacting us at kontakt@doswiftly.pl.
§ 8 Retention periods
We keep data only for as long as necessary to achieve the purposes for which it was collected - see the table in § 4. After these periods expire, data is deleted or anonymized. We rotate backups at most every 90 days - during this period we may be unable to delete data from backups, but we use them only for disaster recovery.
§ 9 Your rights (Art. 15-22 GDPR)
- Access to your data and receiving a copy of it (Art. 15).
- Rectification of inaccurate or incomplete data (Art. 16).
- Erasure of data - the "right to be forgotten" (Art. 17), subject to archiving obligations (e.g. invoices).
- Restriction of processing (Art. 18).
- Portability of data - export in JSON format on request (Art. 20).
- Objection to processing based on legitimate interest or for direct marketing purposes (Art. 21).
- Not being subject to automated decisions, including profiling, producing legal or similarly significant effects (Art. 22) - see § 12.
- Withdrawal of consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise your rights, write to kontakt@doswiftly.pl with the note "GDPR". You can also download some of your data yourself in the dashboard - including orders and stock levels (CSV export) and the event log.
For end Customer data of Stores, requests should be directed to the controller of that data - the Merchant. The Operator will support the exercise of these rights in accordance with the DPA.
§ 10 Right to lodge a complaint with the supervisory authority
You have the right to lodge a complaint with the supervisory authority - the President of the Personal Data Protection Office:
Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl
Beforehand, however, we kindly ask you to contact us - we will try to resolve the matter amicably.
§ 11 Cookies
Detailed information about cookies (types, purposes, periods, providers) and instructions for managing consent are contained in the DoSwiftly Cookie Policy. You can manage cookie settings in your browser - detailed instructions are in the Cookie Policy.
§ 12 Profiling and automated decisions
Within DoSwiftly we do not profile individual persons and do not make decisions based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them (Art. 22 GDPR). Product recommendations in the Store are based on the Store's aggregate sales data (e.g. products most often bought together), and the order of search results - on how well they match the query.
§ 13 Data of minors
DoSwiftly is not directed at persons under 18 years of age. We do not knowingly collect the data of minors for the purpose of creating an Account. If a Merchant runs a Store addressed to minors, responsibility for consents (Art. 8 GDPR) and for the rules of processing such end Customers' data rests with the Merchant as the controller.
§ 14 Data security
We apply the following technical and organizational measures:
- encryption of data in transit (TLS 1.2+) and encryption of credentials for external services and of backups;
- a separate database and separate access credentials for each Store;
- access control based on roles and permissions; administrative access to the infrastructure limited to the Operator's authorized persons;
- passwords stored only as a cryptographic hash;
- regular, encrypted backups and recovery tests;
- protection against DDoS attacks and bot traffic, request rate limits, security monitoring;
- an incident response policy and the obligation to report breaches within 72 hours (Art. 33 GDPR).
§ 15 Changes to the Privacy Policy
The Operator may update this Policy. We will notify you of material changes 14 days in advance by email and via a banner on the site. The current version is always available at doswiftly.pl/en/privacy, with the version marked and its effective date.
Privacy Policy version: 2.0, in effect from 08.10.2026. The previous version 1.1 was in effect from 21.05.2026.