Legal document

Privacy Policy

Version: 1.3  ·  Effective date: 4 July 2026  ·  (versions: 1.2 — 2 July 2026, 1.1 — 12 June 2026)
Controller: Agencja LDB Paweł Stefanowicz, ul. Łazienkowska 1b, 58-570 Jelenia Góra, Poland · Tax ID (NIP): 6112516657 · EU VAT: PL6112516657
Contact: [email protected]
This English version is provided for convenience. In case of any discrepancy, the Polish version prevails.

§1. Data Controller

The controller of your personal data is:

Agencja LDB Paweł Stefanowicz
Tax ID (NIP): 6112516657 · EU VAT: PL6112516657
Address: ul. Łazienkowska 1b, 58-570 Jelenia Góra, Poland
E-mail: [email protected]

For any matters concerning personal data, you may contact us at the e-mail address above.

§2. What data we collect

Depending on how you use the XLR.pro service, we process the following data:

  • Registration data: e-mail address, password (stored in encrypted form)
  • Company data (optional): company name, Tax ID (NIP), address — required when activating a paid subscription and issuing invoices
  • Billing data: payment card details — processed exclusively by the payment provider Stripe (Stripe Payments Europe, Ltd.); XLR.pro does not store card data
  • Technical data: IP address, browser type, operating system, time and date of visits — collected automatically by the server and analytics tools
  • Application usage data: activity logs, history of warehouse operations, equipment data entered by the user
  • Cookies: details in §7

§3. Purpose and legal basis for processing

Purpose Legal basis (GDPR)
Provision of the XLR.pro service (account operation, access to the application) Art. 6(1)(b) — performance of a contract
Payment handling and invoicing Art. 6(1)(b) and (c) — contract and legal obligation
Newsletter and marketing communication Art. 6(1)(a) — consent (may be withdrawn at any time)
Website analytics (Google Analytics 4) Art. 6(1)(f) — legitimate interest / consent to cookies
Remarketing (Meta Pixel) Art. 6(1)(a) — consent to marketing cookies
Handling complaints and contact Art. 6(1)(f) — legitimate interest of the controller
Service security and abuse prevention (logging of security events: sign-ins, IP address, request-rate limit hits; detection of unauthorized access and mass data harvesting — scraping) Art. 6(1)(f) — legitimate interest of the controller (ensuring the security of the Service and its users)
Help with using the Service — built-in AI assistant (the content of questions asked to the assistant and the context in which they were asked: app screen, role, plan, language — in order to provide answers and improve the Service and its documentation) Art. 6(1)(f) — legitimate interest of the controller (user support and development of the Service)
Retention of documentation (tax obligations) Art. 6(1)(c) — legal obligation (5 years)

§4. Data recipients — processors

In providing the service we use the following subcontractors (processors):

Entity Purpose Location
Google LLC (Google Analytics 4, Google Tag Manager) Website traffic analytics USA (SCC)
Meta Platforms Ireland Ltd. (Meta Pixel) Remarketing, conversion tracking Ireland / USA (SCC)
Resend Inc. Transactional system e-mails (confirmations, notifications) USA (SCC)
Stripe Payments Europe, Ltd. (and Stripe, Inc.) Payment and subscription billing handling Ireland (EEA) / USA (SCC)
Railway, Inc. Application and database hosting USA (SCC)
Cloudinary Ltd. Image hosting and processing (equipment photos, logos, profile pictures) Israel / USA (SCC, adequacy decision)
Anthropic, PBC (Claude API) AI-assisted generation of quote content and answers of the built-in help assistant (the quote content and questions provided by the User are processed; per the provider's policy, data sent via the API is not used for model training) USA (SCC)

Transfers of data outside the EEA (to the USA) take place on the basis of Standard Contractual Clauses (SCC) approved by the European Commission, which ensures an adequate level of data protection.

§5. Data retention period

  • User account data: for the duration of the account + 30 days after its deletion (backups); billing data is retained for 5 years from the issue of the invoice (tax obligation)
  • Analytics logs (GA4): 14 months by default
  • Marketing data (newsletter): until consent is withdrawn or the subscription is cancelled
  • Security event logs (sign-ins, IP addresses, request-rate limit hits): up to 90 days
  • Help assistant questions (question and answer content with context): up to 12 months; also deleted together with the account
  • Other system logs: up to 12 months

§6. Your rights

Under the GDPR you have the following rights:

  • Access to data — you may request a copy of the data we process
  • Rectification — you may request correction of inaccurate data
  • Erasure — the "right to be forgotten" (subject to legal obligations)
  • Restriction of processing — you may request that processing of your data be suspended
  • Data portability — you may receive your data in CSV/JSON format
  • Objection — to processing based on legitimate interest
  • Withdrawal of consent — at any time, without affecting the lawfulness of processing carried out before the withdrawal

Send requests to: [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO — the Polish supervisory authority), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl.

§7. Cookies

The XLR.pro service uses cookies. We distinguish three categories:

Category Description Consent required?
Essential User session, security, language preferences No — always active
Analytics Google Analytics 4 — measuring traffic and user behaviour Yes — consent required
Marketing Meta Pixel — remarketing and conversion tracking on Facebook/Instagram Yes — consent required

You can change your cookie preferences at any time by clicking the cookie management icon in the footer of the site or in your browser settings.

§8. Data security

We apply appropriate technical and organisational measures to protect personal data:

  • Encryption of communication (HTTPS/TLS)
  • Password hashing (bcrypt, 12 rounds)
  • JWT authorisation with short-lived tokens
  • Regular database backups
  • Access to data restricted to authorised staff

§9. Changes to this Privacy Policy

We will inform you of material changes to this Policy by e-mail 14 days before the changes take effect. The current version is always available at xlr.pro/privacy-policy.

§10. Contact

For matters concerning personal data protection, contact us:

Agencja LDB Paweł Stefanowicz
E-mail: [email protected]
We respond within 5 business days.