Privacy policy

Last updated: 2026-06-01

1. Controllers and contact points

For personal data related to user accounts, authentication, subscriptions, billing, platform security, and day-to-day use of decksity, the controller is Jarosław Milasiewicz SOFTWARE SOLUTIONS.

Contact for those matters: Pruszków, rodo@decksity.app.

For customer data processed within a specific DJ-client offer, contract, annex, or related communication flow, the DJ identified in the offer, contract, or communication remains the controller. decksity acts in that scope as a processor on behalf of the DJ.

If a request concerns both platform data and contract-flow data, you may contact the platform operator first. We will coordinate the request with the relevant DJ when needed.

2. Categories of personal data

  • account and profile data, including name, email address, phone number, login metadata, and settings preferences
  • trial eligibility and anti-abuse signals, including pseudonymized hashes of email, phone, tax number, bank account, Stripe customer, and payment-method identifiers where available
  • contract, event, and communication data entered by the DJ or the client, including identification, contact, event, and document details
  • evidence and technical data, including IP address, user agent, timestamps, cookie identifiers, delivery statuses, and security logs

3. Purposes and legal bases

  • service delivery, account management, and performance of a contract under Article 6(1)(b) GDPR
  • compliance with legal obligations, including accounting and tax obligations, under Article 6(1)(c) GDPR
  • trial eligibility control, prevention of repeated free trials, payment abuse prevention, platform security, and defence of claims under Article 6(1)(f) GDPR
  • security, abuse prevention, platform stability, evidence preservation, and defence of claims under Article 6(1)(f) GDPR

4. Recipients and international transfers

Data may be shared with hosting, database, authentication, transactional email, and monitoring providers only to the extent necessary to operate the platform.

If a provider processes data outside the EEA, the transfer is based on an appropriate legal mechanism, such as Standard Contractual Clauses, together with a documented risk assessment where required.

5. Retention

  • account and billing data is kept for the lifetime of the account and later for the period required by law or limitation periods
  • pseudonymized trial eligibility records are kept during the trial process and for up to 24 months after the latest of trial end, trial denial, paid-plan conversion, or account deletion, unless a legal hold or claim requires longer retention
  • contract and evidence data is kept for the time necessary to perform the contract, prove the course of the process, and defend against claims
  • technical logs, session records, and cookie-backed access artifacts are kept for the time required by security, fraud prevention, and platform maintenance policies

6. Data subject rights

You have the right to access, rectify, erase, restrict processing, port data, object, and lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).

For platform data, please contact rodo@decksity.app. For contract-flow data controlled by a DJ, please use the contact details shown in the offer, contract, or related communication received from that DJ.

7. Security

We apply technical and organisational measures appropriate to the risk, including access control, least-privilege permissions, logging, secure transmission, and session protection mechanisms.

8. Updates to this notice

This notice may be updated when the product, legal requirements, or processors change. The current version is published at https://decksity.app.