English · Français · Deutsch · Español · Polski
Daidala Privacy Policy
Last updated: 12 September 2026
1. Controller and contact
The controller described in this policy is Alt-Tab Konrad Makowski, Snopków 20, 21-002 Jastków, Poland, Polish tax identification number NIP 713-274-23-92, operating Daidala at https://daidala.tech.
Privacy contact: support@daidala.tech. No Data Protection Officer has been appointed.
2. Two roles
This policy applies to data for which Alt-Tab Konrad Makowski determines the purposes and means of processing. It covers visitors, account holders, purchasers and people who contact us.
For personal data placed by a customer in that customer's Daidala instance, the customer is the controller and Alt-Tab Konrad Makowski is the processor. That processing is governed by the data processing agreement in section 10 of the Daidala Terms of Service. A person whose data is held in a customer instance should contact that customer. A request received by us will be forwarded to the customer.
3. Data, purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, browser and device data, requested pages and timestamps | operation, security and abuse detection | Article 6(1)(f) GDPR - legitimate interest in security and stability |
| necessary cookies and similar information | session, sign-in, security, remembering the analytics choice and the language choice | Article 6(1)(b) or (f) GDPR; storing and reading information on the device without consent, as this is strictly necessary for the service (Article 399(3) of the Polish Electronic Communications Law (PKE) and corresponding laws of other countries, see section 9) |
| data sent to Google Analytics 4 after you allow analytics in the “Analytics” card: IP address, the page you are on, the referring page, browser and device data, and Google cookies that recognise a returning visit | website measurement | Article 6(1)(a) GDPR and consent to storing and reading information on the device (Article 399(1) PKE and corresponding laws of other countries, see section 9) |
| name, email, password hash, business name, address, VAT number and account data | account creation, management and contract performance | Article 6(1)(b) GDPR |
| order, subscription, payment and refund data | entering into and performing the contract | Article 6(1)(b) GDPR |
| invoice, settlement, country and tax-status data | accounting and tax duties | Article 6(1)(c) GDPR |
| data needed for sanctions screening | compliance with EU law | Article 6(1)(c) GDPR |
| service messages about payment, activation, suspension, termination, retrieval and deletion | contract performance and legal duties | Article 6(1)(b) and (c) GDPR |
| support correspondence | handling the request and legal claims | Article 6(1)(b) and (f) GDPR |
| contract and billing data after termination | establishing, pursuing or defending claims | Article 6(1)(f) GDPR |
Required account and purchase data are provided voluntarily, but the contract cannot be concluded or performed without them.
4. Recipients
Data may be received by:
- Google Ireland Limited for Google Analytics 4, only after you allow analytics;
- Stripe Payments Europe, Limited and Stripe entities involved in a payment; card data are sent directly to Stripe;
- cloud infrastructure providers whose servers run customer instances, in data centres in the European Union, for data processed on customer instructions;
- an accounting or invoicing provider, if used for a particular settlement;
- public authorities where required by law.
The storefront, transactional email, promotional files and post-termination data packages use the controller's own infrastructure in Poland. Cloudflare, Inc. operates DNS for the daidala.tech domain, Śląsk Data Center operates DNS for the snopkow.eu domain used for transactional email, and Let's Encrypt issues TLS certificates. The DNS providers do not carry traffic to the website and do not receive account or order data.
The recipient list will be updated before a new provider is enabled.
5. Transfers outside the EEA
The storefront and its database operate in Poland. Customer instances and their data are hosted in the European Union.
Google and Stripe may also process data outside the EEA. Where this occurs, they use a transfer basis required by Chapter V GDPR, including an adequacy decision or Standard Contractual Clauses. Information about the applicable safeguard is available from support@daidala.tech.
6. Retention
| Data | Period |
|---|---|
| nginx access logs containing IP addresses | 90 days |
| application logs | no fixed period; removed when the pod is replaced during deployment |
| account data | contract term and 30-day retrieval period; afterwards only where needed for legal duties or claims |
| post-termination data package | until the end of the 30-day retrieval period |
| storefront database backups | 14 days |
| customer instance data | no separate backups |
| invoices and tax records | for the period required by tax and accounting law |
| claims data | until the applicable limitation period expires |
| support correspondence | 12 months after closure, longer only where needed for claims |
| analytics choice | 12 months |
| sanctions screening data | 5 years, unless the law or proof of screening requires another period |
| Google Analytics | Google keeps the analytics data sent from this website for 2 months from collection (the retention period set in our Google Analytics account) and then deletes it automatically. Aggregated report data that can no longer be linked to an individual visitor may be kept longer. |
7. Rights
Subject to GDPR conditions, a person may request access, correction, deletion, restriction and portability. A person may object to processing based on legitimate interests. Consent may be withdrawn at any time without affecting earlier lawful processing.
Requests should be sent to support@daidala.tech. We normally respond within one month. A complaint may be lodged with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, which is the supervisory authority competent for the controller. It may also be lodged with the supervisory authority of the EU or EEA country where the person lives or works, or where the alleged infringement took place (Article 77 GDPR). The European Data Protection Board publishes the list of supervisory authorities.
8. Automated decisions
We do not make decisions based solely on automated processing that produce legal or similarly significant effects. A human reviews a sanctions-screening result before a sale is refused.
9. Cookies and analytics
| Name | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
_storefront_session | Daidala | maintain the session | session | necessary |
analytics_consent | Daidala | remember analytics choice | 12 months | necessary |
storefront_language | Daidala | remember the chosen site language | 12 months | necessary |
_ga | distinguish users in GA4 | up to 12 months | analytics | |
_ga_P0DEB3C6XG | maintain GA4 session state | up to 12 months | analytics |
gtag.js only loads once you allow analytics in the “Analytics” card. Before you answer, and after you decline, the page does not connect to Google: nothing is sent to Google and no Google cookie or identifier is created. Once you allow it, Google receives your IP address, the page you are on, the referring page, and browser and device data, and the Google cookies in the table above are stored in your browser. Withdrawing consent deletes those cookies and stops the measurement. Consent can be refused without losing access and changed through the “Analytics” footer link. Closing the choice window without selecting an option is not consent.
Storing and reading information on your device is governed by the law of the country where you use the website: in Poland Article 399 of the Electronic Communications Law (PKE), in France Article 82 of Law No. 78-17 (Informatique et Libertés), in Germany Section 25 TDDDG, in Spain Article 22(2) of Law 34/2002 (LSSI), and in other EU countries the laws implementing Article 5(3) of Directive 2002/58/EC.
10. Security and changes
We use technical and organisational measures appropriate to risk. This policy may change when services, providers or law change. The current version and date are published on the website. Active customers will be informed by email of a material change where required by law or the nature of the change.