Privacy Policy
Last updated: 2026-09-29 · Version 1.13
This Privacy Policy explains how BEO TECHNOLOGY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ processes personal data in connection with the SGTM.space website and customer accounts. References to GDPR mean Regulation (EU) 2016/679.
1. Overview and scope
This policy covers personal data we process as a controller, that is, data about account holders, organization members and the people invited to them, partners in our affiliate programme, and visitors to the SGTM.space website and users of its public scanner. Personal data of your website visitors that flows through your server-side tagging Containers is processed by us as a processor on your behalf and is governed by our Data Processing Agreement, not by this policy.
SGTM.space is a service for businesses (B2B): account holders use it for their business or on behalf of their company or organization. This policy is available in Polish and English; if they differ, the Polish version prevails. In the website's other languages we show the English version.
2. Who we are
The controller of the personal data described in this policy is:
- BEO TECHNOLOGY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
- Prezydenta Gabriela Narutowicza 40 / 1, 90-135 Łódź, Poland
- KRS 0001103255 · NIP (Polish tax ID) 7252343252 · EU VAT PL7252343252 · REGON 528493956
- Contact for privacy matters: [email protected]
3. Controller and processor roles
We act as a controller for the personal data of our account holders and website visitors (for example your e-mail address, billing details and login security data). We act as a processor for the personal data of your Visitors that passes through your Containers (for example their IP address and user agent), including what a Live debug session captures from the browsers of the testers who join it; in that relationship you are the controller and the DPA applies.
4. What data we collect
We collect the following categories of personal data, grouped by activity, with the legal basis for each. In this policy, "analytics consent" means consent in the Analytics category, and "advertising cookies consent" means consent in the Advertisement category, given in the consent banner or in Cookie settings. "Marketing e-mail consent" is the separate consent to our newsletter, which you give at registration or in the notification settings.
| Activity | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account registration | E-mail address, hashed password, e-mail verification status and the hashed one-time e-mail verification code (valid for 60 minutes, with an attempt counter) | 6(1)(b) performance of a contract |
| Sign-in with Google or GitHub | When you choose to sign in with Google or GitHub: your account ID at that provider, e-mail address, name and profile picture address, as the provider passes them to us; until you finish registering, we keep them in your session for at most 30 minutes | 6(1)(b) contract |
| Profile | Optional display name | 6(1)(b) contract and 6(1)(f) legitimate interest in addressing you by name |
| Acceptance of our documents | The versions of the Terms, Privacy Policy, Cookie Notice and Data Processing Agreement you accepted, when and how you accepted them (the registration form or sign-in with Google or GitHub), IP address and user agent | 6(1)(f) legitimate interest in showing when and which versions of our documents were accepted and in defending legal claims |
| Organizations and invitations | Organization name, its members and their roles; in an invitation, the invitee's e-mail address (also if they have no account yet), who invited them, the role, the invitation token and its expiry (14 days) | 6(1)(b) contract with the organization and its members; for an invitee, 6(1)(f) the legitimate interest of the organization and ours in adding colleagues to it |
| Company & billing profile | Company name, EU VAT number, address, city, postal code, country | 6(1)(b) contract and 6(1)(c) legal (accounting) obligation |
| Plans & payments | A container's plan, billing period, status, overage and automatic plan change settings, discount codes used, payment-provider customer, subscription and plan identifiers, and the payment events the provider reports to us (card data is handled by the payment provider, not stored by us) | 6(1)(b) contract and 6(1)(c) legal obligation |
| Authentication | Sessions (IP address, user agent, last activity), the "Remember me" token, passkeys (WebAuthn credential data, name, last used), password-reset tokens (valid for 60 minutes) | 6(1)(b) contract and 6(1)(f) legitimate interest in account security |
| Support | Support chat conversations and form tickets: subject, the text of each message, who wrote it and when, read receipts, channel, status and the language you write in | 6(1)(b) contract and 6(1)(f) legitimate interest in helping you and in defending legal claims |
| Website audit and public scanner | The address of the page checked and the audit results (tags, protections and services detected); for an audit in the app, also who ran it and for which container. In the public scanner without signing in we store nothing about the person running it; their IP address is used for at most a day for the scan rate limit and for the Cloudflare Turnstile check. A scanner result has a public link | 6(1)(b) contract, and for the public scanner 6(1)(f) legitimate interest in offering a free tool and protecting it from abuse |
| Cloudflare connection (where available to your organization) | Who connected the Cloudflare account, the encrypted access and refresh tokens, the scopes granted, the list of Cloudflare accounts, and a log of every change we made in your Cloudflare account: zone, resource, action, state before and after, result and the member who requested it | 6(1)(b) contract and 6(1)(f) legitimate interest in documenting the changes made in your Cloudflare account |
| Live debug sessions | Which member of your organization started a Live debug session and when, the container, the duration, the page address entered, when it was stopped, and the confirmation that the testers know their requests are shown, with its version. What the session captures from the testers' browsers is processed on your behalf under the DPA | 6(1)(b) contract and 6(1)(f) documenting who started a session and the confirmation given |
| Account preferences and activity | Preferred language (the one you last used in the app) and the date of your last visit to the app | 6(1)(b) contract and 6(1)(f) writing to you in your language and keeping service e-mails relevant |
| Service e-mail | E-mail address, name, preferred language and delivery metadata. These are e-mails about your account and the Service: verification, a welcome e-mail with setup tips after registration, password reset, new login, invitations, usage limits, billing and plan notices, support replies, and messages about your setup (for example that your container is ready or that a payment failed) | 6(1)(b) contract and 6(1)(f) informing you about your account |
| Newsletter: product news, promotions and discount codes (marketing e-mail) | E-mail address, name, preferred language, whether and when you gave marketing e-mail consent, and the account facts that decide whether a given e-mail is relevant to you: whether your address is confirmed, whether you have created a container or have a paid plan, when you last used the app, and, for an e-mail about a particular container or subscription, whether its domain is verified, whether its tagging server is connected and whether its payment is overdue | 6(1)(a) consent, which Art. 10 of the Polish Act on Providing Services by Electronic Means and Art. 398 of the Polish Electronic Communications Law also require for commercial information sent by e-mail |
| E-mail delivery history | Which automated e-mail was scheduled or sent to which address and when, and whether it was sent, skipped (with the reason) or failed | 6(1)(f) sending each e-mail once and only when its conditions and your consent still hold, and 6(1)(c) and 7(1) for demonstrating consent |
| Security & anti-abuse logs | Application server logs, Cloudflare Turnstile data on registration and in the public scanner (including your IP address, passed to Cloudflare for the check), webhook logs (IP, user agent, payloads from payment and content providers), the country Cloudflare derives from your IP address | 6(1)(f) legitimate interest in securing the Service, preventing fraud and abuse, and applying the consent rules of your region |
| Logs of our tagging server | Browser requests from the pages of our website (with a Referer header pointing to sgtm.space) to our tagging server ssl.sgtm.space and loader load-ssl.sgtm.space, including the cookieless pings sent before a consent choice and after a refusal: IP address, user agent, referring page, host and request address, method, time, response status and size, whether a bot sent the request, and a hash computed from values including the IP address; a Cloudflare Worker writes them to Google BigQuery. Separately, Google Cloud Logging keeps the request logs of our tagging server with the full request address including its parameters, the IP address and the user agent | 6(1)(f) legitimate interest in operating, counting and securing our tagging server, including bot detection |
| Consent management | CookieTip consent ID, complete category choices, source and observation time; CookieTip also processes IP address, user agent and anti-bot interaction signals, including mouse movement samples, also collected before you choose | 6(1)(c) and 7(1), our duty to demonstrate consent, and 6(1)(f) legitimate interest in enforcing your choices and protecting the banner from bots |
| Cookieless Google measurement and consent pings (Advanced Consent Mode) | Before you choose and after you refuse: page address (which may include campaign parameters such as gclid or utm_*), page title, consent state, basic browser and device information (screen size, language, user agent) and IP address as seen by Google, sent by the Google tag to Google Analytics through ssl.sgtm.space and to Google Ads directly and through our Google tag gateway on sgtm.space; no cookie or identifier is stored on your device, and Google uses the pings for aggregated and modelled measurement; without advertising cookies consent Google may also pass ad-click identifiers (such as gclid) from page to page in the page address instead of storing them in cookies; the same pings also reach the other Google accounts of BEO Technology sp. z o.o. described in section 6 | 6(1)(f) legitimate interest in aggregated measurement of our website and ads |
| Consented web and server analytics | Page and product events, event time, GA client/session ID or pseudonymous client ID, account ID and limited container, plan, region, DNS and transaction context | 6(1)(a) analytics consent |
| Consented website performance analytics | Page address, referring page, IP address, user agent and page load timings, collected by Cloudflare Web Analytics without cookies | 6(1)(a) analytics consent |
| Consented advertising measurement | Page views sent by the Google tag to Google Ads, which Google Ads may also use for remarketing; conversion event, Google click ID and SHA-256 hash of the normalized account e-mail; raw e-mail is not placed in the analytics payload | 6(1)(a) advertising cookies consent |
| Consented OpenAI Ads measurement | Pages viewed and the sign-up, container creation, DNS verification and purchase (plan and amount) events, each with an event ID; OpenAI click and browser identifiers (the __oppref and __obref cookies), IP address and user agent; once you are signed in, a SHA-256 hash of your account e-mail and a pseudonymous advertising ID derived from your account ID; through the pixel's automatic advanced matching, SHA-256 hashes of customer information you enter in forms and other recognizable places on our website, such as e-mail address, phone number, name and address, computed in your browser (the raw values are not sent); sent to OpenAI from your browser and from our server; the OpenAI click identifier stored with your account, so a later conversion is credited to the same ad | 6(1)(a) advertising cookies consent |
| Consented affiliate attribution | Affiliate referral and click identifiers (the affonso_referral and affonso_data cookies), IP address and user agent of the visit; on registration your e-mail address and account ID, sent to Affonso from your browser and from our server; the referral identifier, stored with your account | 6(1)(a) advertising cookies consent |
| Crediting the partner who referred an account | The referral identifier stored with an account, either from a consented visit or assigned by us at the request of a partner who manages the account or owns it, in which case we also send the account's e-mail address and account ID to Affonso as that partner's lead, whatever the account's advertising cookies consent; on every later purchase made by that account, and on every purchase in an organization that account created, whichever member pays, the referral identifier together with the payment the provider reports, so Affonso can credit the partner and calculate the commission. This continues after advertising cookies consent is withdrawn | 6(1)(f) legitimate interest in paying partners the commission agreed with them; for a partner's own account assigned at its request, 6(1)(b) contract |
| Matching payments to referrals | Dodo Payments passes Affonso every payment, subscription and refund event of all our customers, including those no partner referred: among other things the customer's e-mail address and name, amount, currency, status, payment and subscription identifiers and the metadata described in section 6. Affonso uses them only to recognise the payments that carry a stored referral identifier, renewals and refunds included | 6(1)(f) legitimate interest in calculating partners' commissions correctly and completely, including correcting them on refunds |
| Affiliate programme (partners) | When you join the programme: the date you joined and your e-mail address and name, which we pass to Affonso to show your partner dashboard in the app (embedded from affonso.io) and in the partner.sgtm.space portal Affonso runs; if your own account was referred, we e-mail our team your address and account ID and the details of the partner who referred you, so that you can be assigned in Affonso as a second-tier partner. You give your payout and tax details (for example your PayPal, Wise or bank account details, tax forms and invoices) directly to Affonso | 6(1)(b) contract (the affiliate programme rules) and 6(1)(f) legitimate interest in assigning the second-tier partner correctly |
With your analytics consent we measure how the SGTM.space website is used and which campaigns lead to sign-ups and purchases: browser analytics travels through our first-party loader and server-side Google Tag Manager to Google Analytics 4. Sign-up, container creation, DNS verification and the first start of a container's tagging server are sent directly by our application rather than through the browser data layer, and once the payment provider confirms a purchase, it is reported to Google from our server with the plan and amount, together with your customer identifier (analytics consent) and a SHA-256 hash of your e-mail address (advertising cookies consent). On the same analytics consent, Cloudflare Web Analytics measures visits and page load performance without cookies; once loaded, it reports the pages you open within the site until the next full page load, even after a withdrawal. With advertising cookies consent, page views, sign-ups, container creation, DNS verification and purchases are also reported to OpenAI Ads, from the OpenAI pixel in your browser and from our server, so we can measure our ads in ChatGPT; in your browser the pixel also detects customer information you enter in our forms, such as your e-mail address, and sends only its SHA-256 hashes (automatic advanced matching). Every path follows your consent choices, described in section 11: made in the banner in the EEA, the UK and Switzerland and whenever we cannot tell where you are, and enabled by default elsewhere until you change them in Cookie settings; if you refuse both optional categories, nothing is reported beyond the cookieless Google pings in the table above, and a withdrawal also stops any report that has not been sent yet, other than those pings and the Cloudflare Web Analytics page reports described above. The only exception is affiliate crediting: when a partner referral is stored with your account, or with the account that created your organization, purchases keep being credited to that partner, and an account we assign to a partner at the partner's request is reported to Affonso as that partner's lead, as the table describes. The logs of our tagging server do not depend on consent, because they record the requests from our website's pages that reach it, whatever the consent choice.
Where the data comes from. You give us most of the data yourself, or it arises as you use the Service. We receive the rest from: Google or GitHub, when you sign in with them (ID, e-mail, name, profile picture); the organization member who invites you (your e-mail address and role); Dodo Payments (payment and subscription status and the billing details you enter at checkout); Affonso (whether an account was referred and by which partner, including the partner's name and e-mail); a partner who asks us to assign an account they manage to them (which account it is); Cloudflare (the country derived from your IP address and, with a Cloudflare connection, the list of accounts and zones); CookieTip (your consent state).
Whether you must provide data. Giving an e-mail address and password, or signing in with Google or GitHub, is required to create an account and enter into the contract; without it we cannot provide the Service. To buy a paid plan you give Dodo Payments the payment details it requires; without them the purchase is not possible. The company profile (company name, EU VAT number, address) is optional, but without it we do not pass your company's details to Dodo for the invoice. A display name, analytics consent, advertising cookies consent, marketing e-mail consent and joining the affiliate programme are optional; not giving them does not limit your use of the Service.
5. How and why we use data
We use personal data to operate and provide the Service, manage billing, secure accounts and prevent fraud, provide support, send service-related communications, and comply with our legal obligations. Only if you give marketing e-mail consent, which you can give when you register or later in the app's notification settings, we also send our newsletter: product news, promotions and discount codes. We do not sell personal data.
Where we rely on legitimate interests (GDPR Art. 6(1)(f)), they are, as the table in section 4 shows: securing accounts and the Service and preventing fraud and abuse; showing that our documents were accepted and confirmations given, and defending legal claims; helping you; writing to you in your language and sending only relevant e-mails; enforcing your consent choices; aggregated measurement of our website and ads without cookies; operating, counting and securing our tagging server; documenting changes in your Cloudflare account; adding members to organizations; and calculating and paying partners' commissions correctly. You can object to such processing (section 9).
6. Who we share data with
We share personal data with service providers who process it on our behalf under data processing agreements and, where the table says so, with partners who use it as independent controllers. Each row gives the entity, its country, its role, the transfer basis and a link to its privacy policy:
| Recipient | Purpose and data | Role | Location and transfer safeguard |
|---|---|---|---|
| Laravel VPS and Laravel Forge: Laravel Holdings Inc., United States (privacy policy) | Hosting of the SGTM.space application and its MySQL database on a Laravel VPS server, and management of that server and its deployments through Laravel Forge; the server runs on infrastructure DigitalOcean, LLC (United States) provides to Laravel in its Frankfurt data centre, as Laravel's sub-processor; this server holds the section 4 data we store ourselves (accounts, organizations, billing, support, application logs) | Processor | Server in Frankfurt (Germany, EEA); access by Laravel Holdings Inc. from the United States under the EU-US Data Privacy Framework, in which Laravel is certified |
| Google Cloud: Google Cloud Poland sp. z o.o., Poland, with Google LLC, United States (Google Cloud privacy notice) | Cloud Run: the containers' tagging servers, including our own tagging server ssl.sgtm.space, with their request logs in Cloud Logging; BigQuery: the request logs the Cloudflare Worker writes (section 4) | Processor (Cloud Data Processing Addendum) | Cloud Run in the region chosen for the container, by default in the EU (europe-west1); BigQuery in the EU (multi-region); Cloud Logging logs kept 30 days; processing by Google LLC in the United States under the EU-US Data Privacy Framework and otherwise Standard Contractual Clauses (SCCs) |
| Google: Google Ireland Limited, Ireland, with Google LLC, United States (Google privacy policy, how Google uses information from partner sites) | Google Tag Manager, Google Analytics 4 and Google Ads: consent-aware product analytics, conversion measurement, including the server-side purchase confirmation, and aggregate modelling through our first-party server container; Google Ads also receives page views and cookieless pings from the Google tag. The Google tag we use is shared with other websites and services of BEO Technology sp. z o.o., so the same Google measurement and advertising data, under the same consent rules and including the cookieless pings, is also made available to the other Google Analytics and Google Ads accounts of BEO Technology sp. z o.o., which we use to measure our wider marketing. Sign-in with Google: when you choose it, Google passes us the data described in section 4 | Google Analytics 4 and Tag Manager: processor; Google Ads: independent controller; for sign-in with Google: independent controller of your Google account | Transfers to the United States under the EU-US Data Privacy Framework and SCCs |
| Cloudflare: Cloudflare, Inc., United States (privacy policy) | Reverse proxy, CDN and WAF firewall that every request to the website and app passes through (IP address, user agent, page address, headers); the country derived from the IP address, on which we base the regional consent rules (section 11); DNS and custom hostnames; Workers, including the request Worker, which writes the logs of our tagging server; KV configuration, R2 storage; Browser Rendering to load the pages checked by the audit and the public scanner; Turnstile anti-abuse on registration and in the public scanner (it receives your IP address) and, only with analytics consent, Web Analytics (cookieless measurement of visits and page performance) | Processor | Global edge network, so a request is served by the data centre nearest to you; transfers to the United States under the EU-US Data Privacy Framework, with the SCCs in Cloudflare's data processing addendum as a fallback |
| Dodo Payments: the Dodo Payments group companies, including Dodo Payments, Inc. (privacy policy) | Merchant of record: sells the subscription, takes the payment, issues invoices and handles taxes. It receives your e-mail and name, company name, EU VAT number and billing address, the card or other payment method details you give Dodo directly, and the metadata we send: account ID, organization ID, container ID and identifier (slug), plan ID, on a plan change the previous plan and the direction of the change (automatic plan changes included), the discount code used (code, its ID, kind and percentage), the analytics purchase-attempt identifier and the Affonso referral identifier. On our instruction it passes every payment event to Affonso (see Affonso) | Independent controller | Processing also outside the EEA; Dodo bases transfers from the EEA on Standard Contractual Clauses |
| Affonso: ZASolution, c/o Block Services, Stuttgarter Str. 106, 70736 Fellbach, Germany (privacy policy, terms) | Affiliate programme: tracks referrals (pixel and cookies, only with advertising cookies consent, except an account we assign to a partner at the partner's request), takes leads (e-mail and account ID) and credits payments to partners, calculating their commission. It receives from Dodo Payments every payment, subscription and refund event of all our customers, including those no partner referred, and matches them to stored referrals (section 4). It runs the partner dashboard embedded in the app and the partner.sgtm.space portal (the partner's e-mail and name) and the payouts and settlements with partners: monthly by PayPal, Wise or bank transfer, with payout and tax details and self-billing invoices | Processor (GDPR Art. 28) for tracking, leads and payment matching; independent controller, as merchant of record, for payouts and settlements with partners | Germany (EEA), servers in Frankfurt; no transfer outside the EEA |
| OpenAI (OpenAI Ireland Ltd), Ireland (privacy policy) | OpenAI Ads conversion measurement: receives the events described in section 4 from the OpenAI pixel and from our server, including the hashed form data from automatic advanced matching, and uses them to measure and report on our ads in ChatGPT and to improve its advertising services. Only with advertising cookies consent | Independent controller | Processing in the United States; OpenAI relies on Standard Contractual Clauses (with the UK Addendum for UK data) |
| Resend: Plus Five Five, Inc., United States (privacy policy) | Delivery of our e-mail: service e-mail, including invitations sent to the invitee's address, and, with your consent, marketing e-mail; receives the recipient's e-mail address, name and the content of the message | Processor | Processing in the United States under the EU-US Data Privacy Framework and the SCCs in Resend's data processing addendum |
| GitHub: GitHub, Inc., United States (privacy statement) | Sign-in with GitHub: when you choose it, GitHub passes us the data described in section 4 | Independent controller of your GitHub account | United States; GitHub relies on the EU-US Data Privacy Framework and SCCs |
| CookieTip: our own consent platform, run by BEO Technology sp. z o.o. (CookieTip privacy policy) | Consent banner and Cookie settings, storage of category decisions and proof of consent, anti-bot signals including mouse movement samples, and a scan of the scripts and cookies the website uses | The same controller, not a separate recipient | Primarily in the EEA; CookieTip's infrastructure providers outside the EEA under the EU-US Data Privacy Framework or SCCs, as the CookieTip privacy policy describes |
| Rewriter.io: our own content tool, run by BEO Technology sp. z o.o. (Rewriter.io privacy policy) | Blog and article content management; it receives no account-holder or visitor personal data. Its webhooks are recorded in our webhook logs | The same controller, not a separate recipient | Google Cloud and Cloudflare infrastructure; SCCs outside the EEA, as the Rewriter.io privacy policy describes |
We may also disclose data where required by law or to defend legal claims, and in connection with a merger, acquisition or sale of assets, subject to confidentiality.
7. International transfers
The application and its database run on a server in Frankfurt. Cloudflare's edge serves each request in the data centre nearest to the person sending it, also outside the EEA. Where a recipient in section 6 processes data outside the European Economic Area, we rely on the safeguard named in its row: the European Commission's adequacy decision for entities certified under the EU-US Data Privacy Framework, or the European Commission's Standard Contractual Clauses (SCCs). When you, as a controller, choose a non-EU Container region for your Visitor data, that transfer is part of our processing on your behalf and is governed by the DPA. OpenAI receives advertising measurement data as an independent controller: OpenAI Ireland Ltd is responsible for data from the EEA and Switzerland and processes it on servers in the United States, relying on the Standard Contractual Clauses for that transfer; see OpenAI's privacy policy. You can obtain a copy of the safeguards we rely on by writing to the address in section 2.
8. Data retention
| Data | Retention |
|---|---|
| Account and profile data, including Google and GitHub IDs | For the life of the account. We close an account when you ask us by e-mail, within 30 days: you can no longer sign in, and we delete the consent history, the e-mail delivery history, the password-reset token and the ad click and partner referral identifiers stored with the account straight away. We keep the e-mail address, name and Google and GitHub IDs with the closed account only for as long as the billing data and proof of acceptance listed in this table need them |
| Billing data and accounting records | 5 years, as accounting and tax law requires |
| Proof of acceptance of our documents (versions, time, IP address, user agent) | For the life of the account and 3 years after it is closed |
| Sessions | Until you sign out or the session expires after the idle period shown in the Cookie Notice |
| The "Remember me" token | The cookie until you sign out, at most 400 days. The value stored with the account is replaced with a new one each time you sign out, so an earlier cookie stops working; we keep it for the life of the account |
| Password-reset tokens and e-mail verification codes | Valid for 60 minutes; the code is deleted after verification, and expired password-reset tokens are deleted regularly |
| Passkeys | Until you remove them; after the account is closed they stop working, and we keep them as long as the closed account's e-mail address |
| Organizations and memberships | For the life of the organization; a membership until you leave or are removed from the organization |
| Organization invitations | Until the invitation is accepted or revoked; unaccepted invitations are deleted 30 days after they expire |
| Preferred language and date of last visit | For the life of the account |
| Consent to marketing e-mail (whether it is given and since when) | Until you withdraw it or your account is closed |
| E-mail delivery history | For the life of the account; removed with the account |
| Support conversations and tickets | 3 years after the ticket is closed |
| Website audits in the app | 90 days |
| Public scanner results | 30 days, after which the public link stops working |
| Cloudflare connection and change log | Tokens and the account list until Cloudflare is disconnected; the change log for the life of the organization |
| Request logs (including IP address and user agent), including the logs of our tagging server | 90 days. After that we keep only aggregate daily counts per container, with no IP address, user agent or any other identifier. These totals are what your usage figures and invoices are based on, so we keep them for as long as the invoices they support. The request logs of our tagging server in Google Cloud Logging are kept 30 days |
| Application server logs | 90 days, with daily file rotation |
| Provisioning logs | 90 days, except where an entry documents an unresolved technical problem on your account, which we keep until it is resolved |
| Webhook and security logs | 90 days |
| Live debug session records (who started a session, when, on which container and page) | 90 days after the session's scheduled end. What a session captures is deleted when it ends, as the DPA describes |
| Account consent history (each choice made at a consent banner or in Cookie settings, and the default set outside the EEA, the UK and Switzerland, with its date), where measurement was ever enabled for your account | For the life of the account; removed with the account |
| Direct analytics delivery data, from any period in which measurement was enabled | Queued details are encrypted and erased on terminal delivery or skip; remaining delivery metadata is erased after 90 days |
| OpenAI ad click identifier stored with your account (only with advertising cookies consent) | For the life of the account; removed with the account |
| Affiliate referral identifier stored with your account | For the life of the account; removed with the account. Affonso keeps its own copy of the affiliate programme data under its privacy policy |
| Checkout attribution identifiers (analytics client and session identifiers, advertising click and browser identifiers, IP address and user agent), from any period in which measurement was enabled | Encrypted at rest and erased once the purchase is reported or skipped; at the latest after 90 days, on the same window as every other log |
The 90-day window is the same for every log we keep ourselves; the one shorter period is the 30 days for which Google Cloud Logging keeps our tagging server's request logs. When the 90 days elapse we do not simply archive the data. The records containing identifiers are deleted, and for request logs the only thing that survives is a count of how many requests each container served on each day. Recipients that are independent controllers (section 6) apply their own retention periods.
9. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time without affecting prior processing. To exercise these rights, or to ask for an export of your account data or for your account to be closed, contact [email protected]; we answer without undue delay and within one month at the latest, and close an account within 30 days. You also have the right to lodge a complaint with the supervisory authority, in Poland the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw.
For optional measurement, use the Cookie settings control available throughout the website and app. Withdrawal stops later browser measurement and queued server events in the withdrawn category, except that an already-loaded Cloudflare Web Analytics script keeps reporting the pages you open within the site until the next full page load, and the Google tag goes back to the cookieless pings (section 4). A partner referral already stored with your account, or with the account that created your organization, keeps crediting that partner on later purchases (section 4); you can object to that. Withdrawal does not affect prior lawful processing, and cookies already stored may remain in your browser until they expire, as the Cookie Notice explains.
To stop marketing e-mail, use the unsubscribe link at the bottom of each such e-mail and confirm on the page it opens, use the unsubscribe button your mail app shows for it (one click, no confirmation needed), or switch it off in the app's notification settings. E-mails scheduled but not yet sent are then not sent. Service e-mails about your account continue, because we need them to provide the Service; the optional usage and login notices among them can be switched off in the same settings.
10. Security
We use technical and organizational measures appropriate to the risk, including encryption in transit (TLS), hashed passwords and verification codes, encrypted Cloudflare connection tokens, passkey (WebAuthn) authentication, access controls, anti-abuse checks and data minimization. We select providers that offer appropriate security guarantees.
11. Cookies
In the European Economic Area, the United Kingdom and Switzerland, and whenever we cannot tell where you are, CookieTip keeps optional categories denied until you choose otherwise. We tell where you are only from the country Cloudflare assigns to your IP address. Elsewhere the optional categories start enabled without a banner, and you can switch any of them off in Cookie settings; if your browser sends a Global Privacy Control signal on your first visit, when we set that default, the Advertisement category starts off. Either way the decision reaches Google through Advanced Consent Mode, and the OpenAI pixel does not load until the advertising category is granted. Before you choose and after you refuse, the Google tag still sends the cookieless measurement and consent pings described in section 4 to Google Analytics and Google Ads; no Google cookie is set until you consent, and Laravel sends no direct analytics event without the relevant stored category. For cookie names, durations and the withdrawal control, see our Cookie Notice.
12. Children
The Service is meant for businesses and is not directed to children; we do not knowingly collect personal data from children.
13. Automated decision-making
We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you (GDPR Art. 22). Only a container's contractual thresholds act automatically: when the container reaches its Request limit, the system blocks further Requests, charges overage if the container's plan has it on, or, if your organization has turned on automatic plan changes, moves the container to a higher plan and charges the difference. These follow from the Request count and the settings the organization chose, not from an assessment of you, and are not profiling. Whether you receive a given automated e-mail follows simple rules about your account, for example no container three days after sign-up or no visit for a number of days; this decides only which message you get, with no legal or similarly significant effect.
14. Changes to this policy
We may update this policy from time to time and will indicate the current version and effective date. We announce material changes, such as a new purpose, a new recipient or a new legal basis, with a banner in the app and one e-mail; for existing users they take effect 14 days after that notice, and for new users on registration. Where a change would need your consent, we will ask for it separately.
Since version 1.11, crediting the partner who referred an account rests on our legitimate interest (GDPR Art. 6(1)(f)) rather than on consent. This also applies to accounts created earlier, which we explain in the joint notice of changes to our documents; you can object to it (section 9).
15. Contact
For privacy questions, contact BEO Technology sp. z o.o. at [email protected], Prezydenta Gabriela Narutowicza 40 / 1, 90-135 Łódź, Poland.