Atsep.app

PRIVACY POLICY

of the website www.atsep.app and the Atsep Inspection application: www.atsep-inspection.web.app

Effective date: 01.01.2026

1. GENERAL PROVISIONS

1.1. Personal Data Controller

The controller of personal data collected through the Website www.atsep.app and the Application www.atsep-inspection.web.app is:

Radoslaw Pesta

conducting business under the name: Kedar Radoslaw Pesta

registered in the Central Register and Information on Business Activity

Address: ul. Klonowa 18, 09-414 Brudzen Duzy

Tax ID (NIP): 7743145840

REGON: 388417127

E-mail: biuro@atsep.app

hereinafter referred to as the “Controller”, who is also the Service Provider.

1.2. Legal Basis

Users’ personal data are processed in accordance with:

– Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as: “GDPR”;

– Act of 10 May 2018 on the Protection of Personal Data;

– Act of 18 July 2002 on the Provision of Electronic Services.

1.3. Data Processing Principles

The Controller attaches great importance to the privacy of all entities using its services. The Controller ensures the security of the data provided, which is duly protected and secured against access by unauthorized persons, as reflected in this Privacy Policy.

1.4. Nature of the Website and Application

The Website and Application are closed and intended exclusively for registered Users, each of whom has an individual, private Account created by logging in via a Google account.

2. METHODS AND PURPOSES OF PROCESSING PERSONAL DATA

2.1. Contact with Users via Electronic Mail

Scope of data:

– E-mail address

– Other data included in the message content

Purpose of processing:

– Establishing and maintaining contact with the User

– Responding to inquiries

Legal basis:

– Art. 6(1)(a) GDPR – the User’s consent resulting from initiating contact

Processing after the end of contact:

Data will also be processed after the end of contact with the Controller for archival purposes to demonstrate the course of correspondence in the future.

Legal basis for archiving:

– Art. 6(1)(f) GDPR – the Controller’s legitimate interest

Note:

Providing an e-mail address is voluntary, but necessary to contact the Controller via electronic mail.

2.2. Issuing and Sending Invoices

Scope of data:

– First and last name or company name

– Address

– Tax ID (NIP)

– E-mail address

Purpose of processing:

– Performance and settlement of the electronically provided service

– Issuing an invoice

– Fulfillment of tax obligations

Legal basis:

– Art. 6(1)(c) GDPR – obligation arising from tax law

– Art. 6(1)(f) GDPR – the Controller’s legitimate interest

Note:

Providing invoice data is mandatory for the correct issuance of an invoice.

2.3. Account and Application Management

Scope of data:

– Personal data shared in the User Account

– Data from the Google account (e-mail address, first name, last name)

– Company data entered by the User

– Technical data (IP address, device type)

Purpose of processing:

– Performance of the contract for the provision of electronic services

– User Account management

– Providing access to the Application’s functionalities

Legal basis:

– Art. 6(1)(b) GDPR – performance of a contract

Retention period:

Until the User deletes the Account or the contract is terminated.

2.4. Complaint Handling

Scope of data:

– First and last name

– Company name

– E-mail address

– Phone number

– Content of the complaint

Purpose of processing:

– Handling the complaint procedure

– Archiving complaint documentation

Legal basis:

– Art. 6(1)(c) GDPR – legal obligation arising from consumer rights regulations (if applicable)

– Art. 6(1)(f) GDPR – the Controller’s legitimate interest (archiving)

Retention period:

Data will be processed for the time necessary to complete the complaint procedure and additionally for archival purposes for up to 3 years from the date of complaint resolution.

Note:

Providing data is voluntary, but necessary to submit and process a complaint. In the case of data provided in the complaint submission process, some rights (e.g. the right to erasure) may not be available to the User if the data is necessary to demonstrate the course of the complaint process.

2.5. Processing for Archival and Evidentiary Purposes

Purpose of processing:

– Securing information that may serve to demonstrate facts

– Archiving documentation

Legal basis:

– Art. 6(1)(f) GDPR – the Controller’s legitimate interest

2.6. Confirmation of Obligations and Pursuit of Claims

Purpose of processing:

– Confirming the fulfillment of the Controller’s obligations

– Pursuing claims or defending against claims directed at the Controller

– Preventing or detecting fraud

Legal basis:

– Art. 6(1)(f) GDPR – the Controller’s legitimate interest (protection of rights, confirmation of obligations, obtaining due remuneration)

Retention period:

Until the limitation period for claims in accordance with the provisions of the Civil Code.

3. DISCLOSURE OF PERSONAL DATA

Personal data may be transferred to the following entities whose services the Controller uses to operate the Website and provide services:

3.1. Payment Operators

Stripe Payments Europe, Ltd.

The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland

The Controller may also use other payment operators (PayPal, przelewy24, etc.) depending on the User’s choice.

3.2. Accounting Services

The Controller may transfer data necessary for accounting purposes to an accounting office or tax advisor.

3.3. Hosting Service Providers

cyber_Folks S.A.

Address: ul. Wierzbiecice 1B, 61-569 Poznan

KRS: 0000685595

REGON: 367731587

NIP: 7792467259

Google LLC (Firebase, Cloud Storage)

The Controller uses Google Cloud Platform infrastructure for data storage and application hosting.

3.4. Public Authorities

Personal data may be transferred to public authorities on the basis of applicable law, including:

– Tax authorities (Tax Office)

– Law enforcement authorities (Police, Prosecution Service)

– Courts

3.5. Transfer of Data Outside the EEA

Some service providers (Google, Stripe) may process data outside the European Economic Area. In such cases, the Controller ensures appropriate safeguards, including standard contractual clauses approved by the European Commission.

4. RETENTION PERIOD OF PERSONAL DATA

4.1. Data Necessary for Contract Performance and Pursuing Claims

Personal data necessary for:

– Performance of the contract

– Handling complaint claims

– Confirming the fulfillment of the Controller’s obligations

– Pursuing claims or defending against claims

will be stored for the period necessary for the purpose for which they were collected, and then:

– Invoices and accounting documents: 5 years from the end of the tax year (in accordance with tax regulations)

– Complaint documentation: 3 years from the date of complaint resolution

– Correspondence: 3 years for archival purposes

4.2. Other Personal Data

Other personal data will be stored for the period necessary for the purpose for which they were collected, but no longer than 5 years from the date of collection.

4.3. Data in the User Account

Data stored in the User Account will be processed until:

– Deletion of the Account by the User

– Termination of the contract

– Withdrawal of consent to data processing (if applicable)

5. USER RIGHTS IN CONNECTION WITH THE PROCESSING OF PERSONAL DATA

5.1. Catalogue of Rights

In accordance with the GDPR, the User has the following rights in connection with the processing of their personal data:

a) Right to information

The right to information on how personal data are processed (Art. 13-14 GDPR).

b) Right of access to data

The right to obtain confirmation as to whether the Controller processes the User’s personal data, and the right to obtain a copy of such data (Art. 15 GDPR).

c) Right to rectification of data

The right to demand immediate rectification of inaccurate personal data or completion of incomplete data (Art. 16 GDPR).

d) Right to erasure (“right to be forgotten”)

The right to demand the erasure of personal data (Art. 17 GDPR).

Limitations:

The Controller may refuse to erase data for which it has a basis for continued processing, in particular when data are necessary for:

– Fulfillment of a legal obligation (e.g. storage of invoices for 5 years)

– Establishment, exercise or defense of legal claims

e) Right to restriction of processing

The right to demand restriction of the processing of personal data in specific situations (Art. 18 GDPR).

f) Right to object

The right to object to the processing of personal data where the basis for processing is the legitimate interest of the Controller or the performance of tasks in the public interest (Art. 21 GDPR).

g) Right to withdraw consent

The right to withdraw consent at any time if personal data were processed on the basis of the User’s consent (Art. 7(3) GDPR). Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

h) Right to data portability

The right to receive personal data in a structured, commonly used, machine-readable format and the right to transmit those data to another controller (Art. 20 GDPR).

i) Right to lodge a complaint with a supervisory authority

The right to lodge a complaint with the President of the Personal Data Protection Office if the User believes that the processing of their personal data violates the provisions of the GDPR.

Contact details of UODO:

Personal Data Protection Office

ul. Stawki 2, 00-193 Warsaw

Phone: 22 531 03 00

E-mail: kancelaria@uodo.gov.pl

Website: https://uodo.gov.pl

5.2. Exercising Rights

All the above rights can be exercised by contacting the Controller:

– E-mail: biuro@atsep.app

– In writing to the address: ul. Klonowa 18, 09-414 Brudzen Duzy

Response time:

Submitted requests will be fulfilled without undue delay, no later than within 30 days of receipt of the request. Within this period, the Controller will respond or inform of any possible extension of the deadline (by up to another 60 days) and explain the reasons.

Identity verification:

If the Controller has doubts as to whether a specific request was submitted by an authorized person, they may request additional information to confirm the identity of the User.

6. PROTECTION OF CONFIDENTIAL INFORMATION OF USERS

6.1. Definition of Confidential Information

All information, files and data placed in the Website and Application by the User constitute Confidential Information, in particular:

– Voice recordings

– Text descriptions

– Photographs

– Drawings

– Acceptance protocols

– Inspection reports

6.2. Principles of Protection of Confidential Information

Confidential Information:

a) User’s property

Remains the exclusive property of the User and, upon their explicit request, will be permanently deleted from the Controller’s servers.

b) Due diligence

Is stored and protected by the Controller with due diligence, at least with the same diligence with which the Controller protects its own confidential information from disclosure.

c) Prohibition on disclosure to third parties

Will not be disclosed by the Controller to third parties, including other Users or potential clients of the Controller, without the explicit written consent of the User under pain of nullity.

d) Limited purpose of use

Will not be used by the Controller in any way other than in accordance with the Terms and Conditions, and in particular will not be used for:

– Copying

– Creating elaborations or designs

– Production

– Sales

– Marketing

6.3. Exceptions to Confidentiality

The provisions of section 6.2 do not apply to those pieces of information, files and data that:

– Are publicly available (unless disclosure occurred as a result of a violation of the Terms and Conditions, Privacy Policy or generally applicable law)

– Were obtained by the Controller from another, legally permitted source

– Must be disclosed on the basis of mandatory provisions of law or a final court judgment

7. COOKIES

7.1. General Information on Cookies

The Website, like almost all other websites, uses Cookies to provide Users with the best possible experience.

What are cookies?

Cookies are IT data, in particular small text files, saved and stored on devices (e.g. a computer, tablet, smartphone) through which the User uses the Website pages.

Consent to cookies:

During the User’s first visit to the Website, information about the use of cookies is displayed. Failure to change browser settings is equivalent to consent to their use.

7.2. Cookie Security

Cookies used by the Controller are safe for Users’ devices. In particular, it is not possible for viruses or other unwanted or malicious software to reach Users’ devices in this way.

Cookie functions:

– Identification of software used by the User

– Individual adjustment of the Website’s operation

– Remembering User preferences

Cookie content:

Cookies usually contain the name of the domain from which they originate, the time they are stored on the device, and an assigned value.

7.3. Types of Cookies

a) Session cookies

They are stored on the User’s device and remain there until the end of the browser session. The stored information is then permanently deleted from the device’s memory. The session cookie mechanism does not allow any personal data or confidential information to be obtained from the User’s device.

b) Persistent cookies

They are stored on the User’s device and remain there until they are deleted. The end of the browser session or turning off the device does not cause them to be deleted from the User’s device. The persistent cookie mechanism does not allow any personal data or confidential information to be obtained from the User’s device.

c) Analytical cookies

They enable a better understanding of the way the User interacts with the Website content and better organization of its layout. Analytical cookies collect information about:

– The way Users use the Website

– The type of page from which the User was redirected

– The number of visits and the User’s time spent on the Website

Privacy note:

Information collected by analytical cookies does not record specific personal data of the User, but serves exclusively for the preparation of statistics on the use of the Website.

Google Analytics:

Analytical cookies may be used to develop statistics on the Website in the Google Analytics application. More information: https://policies.google.com/privacy

7.4. Cookie Management

The User can restrict or disable Cookies’ access to their device by changing their internet browser settings.

Instructions for popular browsers:

– Google Chrome: Settings → Privacy and security → Cookies

– Mozilla Firefox: Options → Privacy & Security → Cookies and Site Data

– Microsoft Edge: Settings → Cookies and site permissions

– Safari (macOS): Preferences → Privacy

Consequences of disabling cookies:

In the event of using the option to restrict or disable cookies, use of the Website will be possible, except for functions that by their nature require cookies (in particular logging in and Account management).

8. SERVER LOGS

8.1. General Information

Use of the Website and Application involves sending queries to the server on which the Website pages and Application data are stored. Every query directed to the server is saved in the server logs.

8.2. Scope of Data in Logs

Logs include, among others:

– User’s IP address

– Date and time of the query

– Information about the internet browser

– Information about the User’s operating system

– Address of the page from which the redirect occurred

– Server response code

8.3. Purpose of Log Processing

Logs are saved and stored on the server exclusively for the purpose of:

– Administration of the Website and Application

– Ensuring the security of the IT system

– Diagnosing technical problems

– Detecting and preventing abuse

8.4. Principles of Access to Logs

Data saved in server logs:

– Are not associated with specific Users

– Are not used by the Controller for the purpose of identifying Users

– Constitute exclusively auxiliary material for the administration of the Website and Application

– Their content is not disclosed to anyone other than persons authorized to administer the server

8.5. Log Retention Period

Server logs are stored for up to 90 days, after which they are automatically deleted.

9. SECURITY AND PERSONAL DATA PROTECTION AUTHORITY

9.1. Security Measures

The Controller guarantees the confidentiality of all personal data entrusted to it. The Controller ensures the adoption of all security and personal data protection measures required by law, in particular:

Technical measures:

– Data transmission encryption (HTTPS/SSL protocol)

– Protection against unauthorized access

– Regular backups

– Software updates and security patches

– System security monitoring

Organizational measures:

– Personal data are collected with due diligence

– Data are duly protected against access by unauthorized persons

– Limiting access to data exclusively to authorized persons

– Employee training in the field of personal data protection

9.2. Security Incidents

In the event of a personal data breach, the Controller will:

– Report the incident to the President of UODO within 72 hours of becoming aware of the breach (if the breach poses a risk to Users’ rights)

– Directly inform the Users whose data may have been breached (if the breach poses a high risk)

9.3. Right to Lodge a Complaint

If you believe that the Controller is processing personal data unlawfully, you may lodge a complaint with the competent supervisory authority:

President of the Personal Data Protection Office

ul. Stawki 2, 00-193 Warsaw

Phone: 22 531 03 00

E-mail: kancelaria@uodo.gov.pl

Website: https://uodo.gov.pl

10. PROFILING AND AUTOMATED DECISION-MAKING

The Controller does not use profiling or automated decision-making that would produce legal effects on the User or similarly significantly affect them (Art. 22 GDPR).

11. DATA OF THIRD PARTIES

11.1. User’s Responsibility

The User may enter data of third parties (e.g. client data, data contained in acceptance protocols) into the Application. In such case, the User declares that:

– They have an appropriate legal basis for processing such data

– They have informed the third parties about the transfer of their data to the Controller

– They have obtained the necessary consents or fulfilled other legal requirements in accordance with the GDPR

11.2. Controller’s Role

The Controller processes the data of third parties provided by the User exclusively on behalf of the User (as a data processor) to the extent necessary for the provision of services specified in the Terms and Conditions.

The User bears full responsibility for the lawfulness of the processing of third-party data transferred to the Controller.

12. CHANGES TO THE PRIVACY POLICY

12.1. Right to Make Changes

The Controller reserves the right to make changes to the Privacy Policy in the following cases:

– Changes in personal data protection legislation

– Changes in the scope of services provided or functionalities of the Website/Application

– Introduction of new tools or technologies

– Improvement of personal data protection

12.2. Procedure for Making Changes

Users will be informed of every change to the Privacy Policy at least 14 days before the changes take effect by:

– An e-mail message to the address assigned to the Account

– A notice in the Website/Application after logging in

– Publication of the amended Privacy Policy on the www.atsep.app website

12.3. Consequences of Non-Acceptance of Changes

The User has the right not to accept the introduced changes. In such case, the User may:

– Terminate the contract with immediate effect

– Request deletion of the Account and all personal data

Failure to respond by the User within 14 days of notification of changes means acceptance of the new version of the Privacy Policy.

13. CONTACT IN MATTERS OF PERSONAL DATA PROTECTION

For questions regarding the processing of personal data, the exercise of rights, or other privacy-related matters, please contact:

E-mail: biuro@atsep.app

Correspondence address:

Kedar Radoslaw Pesta

ul. Klonowa 18

09-414 Brudzen Duzy

The Controller undertakes to respond within 30 days of receiving the inquiry.

14. FINAL PROVISIONS

1. The Privacy Policy constitutes an integral part of the Terms and Conditions for the provision of electronic services.

2. In matters not regulated in the Privacy Policy, the following regulations apply:

– GDPR Regulation

– Act on the Protection of Personal Data

– Act on the Provision of Electronic Services

– Civil Code

– Other applicable provisions of Polish law

3. This Privacy Policy enters into force on 01.01.2026.

4. The current version of the Privacy Policy is always freely available at www.atsep.app and in the Application www.atsep-inspection.web.app in a form enabling its downloading, saving, and printing.

Date of last update: 01.01.2026

Kedar Radoslaw Pesta

Personal Data Controller