English · Français · Deutsch · Español · Polski

Daidala Privacy Policy

Last updated: 12 September 2026

1. Controller and contact

The controller described in this policy is Alt-Tab Konrad Makowski, Snopków 20, 21-002 Jastków, Poland, Polish tax identification number NIP 713-274-23-92, operating Daidala at https://daidala.tech.

Privacy contact: support@daidala.tech. No Data Protection Officer has been appointed.

2. Two roles

This policy applies to data for which Alt-Tab Konrad Makowski determines the purposes and means of processing. It covers visitors, account holders, purchasers and people who contact us.

For personal data placed by a customer in that customer's Daidala instance, the customer is the controller and Alt-Tab Konrad Makowski is the processor. That processing is governed by the data processing agreement in section 10 of the Daidala Terms of Service. A person whose data is held in a customer instance should contact that customer. A request received by us will be forwarded to the customer.

3. Data, purposes and legal bases

DataPurposeLegal basis
IP address, browser and device data, requested pages and timestampsoperation, security and abuse detectionArticle 6(1)(f) GDPR - legitimate interest in security and stability
necessary cookies and similar informationsession, sign-in, security, remembering the analytics choice and the language choiceArticle 6(1)(b) or (f) GDPR; storing and reading information on the device without consent, as this is strictly necessary for the service (Article 399(3) of the Polish Electronic Communications Law (PKE) and corresponding laws of other countries, see section 9)
data sent to Google Analytics 4 after you allow analytics in the “Analytics” card: IP address, the page you are on, the referring page, browser and device data, and Google cookies that recognise a returning visitwebsite measurementArticle 6(1)(a) GDPR and consent to storing and reading information on the device (Article 399(1) PKE and corresponding laws of other countries, see section 9)
name, email, password hash, business name, address, VAT number and account dataaccount creation, management and contract performanceArticle 6(1)(b) GDPR
order, subscription, payment and refund dataentering into and performing the contractArticle 6(1)(b) GDPR
invoice, settlement, country and tax-status dataaccounting and tax dutiesArticle 6(1)(c) GDPR
data needed for sanctions screeningcompliance with EU lawArticle 6(1)(c) GDPR
service messages about payment, activation, suspension, termination, retrieval and deletioncontract performance and legal dutiesArticle 6(1)(b) and (c) GDPR
support correspondencehandling the request and legal claimsArticle 6(1)(b) and (f) GDPR
contract and billing data after terminationestablishing, pursuing or defending claimsArticle 6(1)(f) GDPR

Required account and purchase data are provided voluntarily, but the contract cannot be concluded or performed without them.

4. Recipients

Data may be received by:

The storefront, transactional email, promotional files and post-termination data packages use the controller's own infrastructure in Poland. Cloudflare, Inc. operates DNS for the daidala.tech domain, Śląsk Data Center operates DNS for the snopkow.eu domain used for transactional email, and Let's Encrypt issues TLS certificates. The DNS providers do not carry traffic to the website and do not receive account or order data.

The recipient list will be updated before a new provider is enabled.

5. Transfers outside the EEA

The storefront and its database operate in Poland. Customer instances and their data are hosted in the European Union.

Google and Stripe may also process data outside the EEA. Where this occurs, they use a transfer basis required by Chapter V GDPR, including an adequacy decision or Standard Contractual Clauses. Information about the applicable safeguard is available from support@daidala.tech.

6. Retention

DataPeriod
nginx access logs containing IP addresses90 days
application logsno fixed period; removed when the pod is replaced during deployment
account datacontract term and 30-day retrieval period; afterwards only where needed for legal duties or claims
post-termination data packageuntil the end of the 30-day retrieval period
storefront database backups14 days
customer instance datano separate backups
invoices and tax recordsfor the period required by tax and accounting law
claims datauntil the applicable limitation period expires
support correspondence12 months after closure, longer only where needed for claims
analytics choice12 months
sanctions screening data5 years, unless the law or proof of screening requires another period
Google AnalyticsGoogle keeps the analytics data sent from this website for 2 months from collection (the retention period set in our Google Analytics account) and then deletes it automatically. Aggregated report data that can no longer be linked to an individual visitor may be kept longer.

7. Rights

Subject to GDPR conditions, a person may request access, correction, deletion, restriction and portability. A person may object to processing based on legitimate interests. Consent may be withdrawn at any time without affecting earlier lawful processing.

Requests should be sent to support@daidala.tech. We normally respond within one month. A complaint may be lodged with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, which is the supervisory authority competent for the controller. It may also be lodged with the supervisory authority of the EU or EEA country where the person lives or works, or where the alleged infringement took place (Article 77 GDPR). The European Data Protection Board publishes the list of supervisory authorities.

8. Automated decisions

We do not make decisions based solely on automated processing that produce legal or similarly significant effects. A human reviews a sanctions-screening result before a sale is refused.

9. Cookies and analytics

NameProviderPurposeDurationCategory
_storefront_sessionDaidalamaintain the sessionsessionnecessary
analytics_consentDaidalaremember analytics choice12 monthsnecessary
storefront_languageDaidalaremember the chosen site language12 monthsnecessary
_gaGoogledistinguish users in GA4up to 12 monthsanalytics
_ga_P0DEB3C6XGGooglemaintain GA4 session stateup to 12 monthsanalytics

gtag.js only loads once you allow analytics in the “Analytics” card. Before you answer, and after you decline, the page does not connect to Google: nothing is sent to Google and no Google cookie or identifier is created. Once you allow it, Google receives your IP address, the page you are on, the referring page, and browser and device data, and the Google cookies in the table above are stored in your browser. Withdrawing consent deletes those cookies and stops the measurement. Consent can be refused without losing access and changed through the “Analytics” footer link. Closing the choice window without selecting an option is not consent.

Storing and reading information on your device is governed by the law of the country where you use the website: in Poland Article 399 of the Electronic Communications Law (PKE), in France Article 82 of Law No. 78-17 (Informatique et Libertés), in Germany Section 25 TDDDG, in Spain Article 22(2) of Law 34/2002 (LSSI), and in other EU countries the laws implementing Article 5(3) of Directive 2002/58/EC.

10. Security and changes

We use technical and organisational measures appropriate to risk. This policy may change when services, providers or law change. The current version and date are published on the website. Active customers will be informed by email of a material change where required by law or the nature of the change.