← Back to Pando Polski English

Pando Privacy Policy

Version: 1.1

Published and effective: on the date of publication in the service

1. Data controller

The controller of the personal data of users of the Pando service is Ignis Kacper Holak, ul. Wiejska 21, 44-180 Toszek, Poland, NIP (tax ID): 5842820373, REGON: 522504647, contact email: pando@holak.me, contact person: Kacper Holak ("we", the "Controller").

For all matters concerning personal data, you can contact the Controller at the email address above.

2. Scope of this Policy

This Privacy Policy explains how we process personal data of users of the Pando website and application available at pando.holak.me, including data collected when you create an account, use app features, contact us, make payments for paid features of the Service (if you use them), receive marketing communications, and use cookies or similar technologies.

Two roles in Pando. Pando is a simple CRM: users may enter data about their own customers and business contacts. With respect to:

  • data of Pando users (your account, billing, support, logs) — we are the controller and this Policy applies;
  • customer data entered by a user into the CRM — the user is the controller, and we process those data solely on the user's behalf as a processor, under the data-processing terms set out in the Terms of Service (§8). Individuals whose data are concerned should address their requests primarily to the user acting as their controller; any requests received by us will be promptly forwarded to the relevant user.

3. Categories of data we process

We may process the following categories of data:

  • identity and contact data (e.g. email address, username),
  • account data (e.g. password in encrypted form, settings, profile data),
  • payment and billing data — only if you use paid features,
  • support and complaint data (contents of requests, correspondence),
  • technical and security data (IP address, session identifiers, device and browser data, event logs),
  • analytics data (cookie identifiers, usage data) — only after the required consent has been obtained,
  • consent and marketing-preference data,
  • customer data entered by the user into the CRM — processed solely on behalf of the user as controller (see section 2).

As a rule, we do not expect you to provide special-category data (e.g. health data, beliefs) and we ask you not to provide such data unless we explicitly require it and identify an appropriate legal basis under Article 9 GDPR.

4. Purposes and legal bases of processing

We process data for the following purposes:

  1. Creating and maintaining your account and providing the app services — Art. 6(1)(b) GDPR (performance of a contract).
  2. Ensuring security, preventing abuse and keeping technical logs — Art. 6(1)(f) GDPR (the Controller's legitimate interest in protecting the service and its users).
  3. Handling support requests, complaints and contact — Art. 6(1)(b) or (f) GDPR, depending on the context of the request.
  4. Complying with tax and accounting obligations (for paid services) — Art. 6(1)(c) GDPR.
  5. Electronic marketing (e.g. a newsletter) — Art. 6(1)(a) GDPR (consent), together with any consents required under electronic-communications law.
  6. Analytics that are not necessary for the operation of the service — based on cookie consent and, where needed, consent under Art. 6(1)(a) GDPR.

5. Whether providing data is mandatory

Data marked as mandatory are necessary to conclude and perform the contract or to comply with a legal obligation — without them we cannot provide the service. Providing other data is voluntary, although it may be necessary for certain features.

6. Sources of data

As a rule, we collect data directly from you. If we obtain data from another source — for example from a payment provider or a person inviting you to the app — we will provide the information required by Art. 14 GDPR, including the source of the data.

7. Recipients of data

Recipients of data may include our technical service providers, in particular:

  • hosting and infrastructure provider: Hostinger,
  • email service provider: currently Hostinger,
  • analytics tools: we currently do not use any analytics tools; if we introduce one, its provider will be listed here before we start using it,
  • payment service provider: payments for paid access are currently settled directly (e.g. by bank transfer against an issued invoice), without an external payment processor; if one is introduced, it will be listed here,

— only to the extent necessary to provide the services or comply with legal obligations. Where a provider acts as a processor, we enter into a data processing agreement compliant with Art. 28 GDPR with that provider.

8. Transfers outside the EEA

If data are transferred outside the European Economic Area, we use a valid transfer mechanism — in particular a European Commission adequacy decision or standard contractual clauses — and we explain the safeguards and how to obtain a copy of them.

Current status: data are stored on servers located within the EEA — the production server is located in Lithuania and backups are stored in France. We do not currently transfer personal data outside the EEA.

9. Retention periods

We retain data for as long as necessary for the relevant purpose and, afterwards, for as long as required by law or necessary to defend legal claims. Detailed periods:

  • account data — for the life of the account and, after deletion, for up to 12 months for security, settlement and claims-defence purposes,
  • security logs — up to 90 days, unless longer storage is needed to investigate an incident,
  • marketing consents — until consent is withdrawn, plus the period needed to demonstrate compliance,
  • accounting records — for the period required by law,
  • support requests and complaints — up to 12 months after the matter is closed.

10. Cookies and similar technologies

We use cookies and similar technologies that are necessary for the service to work (e.g. the login session, remembering your cookie preferences). Only after the required consent has been obtained do we also use analytics or marketing technologies that are not strictly necessary.

You can change your cookie choices at any time in the cookie preference panel available in the service.

11. Marketing communications

We send marketing communications (e.g. a newsletter) only where we have an appropriate legal basis and any required consent. You may withdraw consent at any time — for example by clicking the unsubscribe link in a message — without affecting the lawfulness of processing carried out before withdrawal.

12. Data security

We implement appropriate technical and organisational measures, taking into account the nature, scope, context and purposes of processing and the risk to users' rights and freedoms. These measures include access controls, encrypted connections (TLS/HTTPS), encrypted password storage, backups, event logging and incident-response procedures.

13. Data breaches

In the event of a personal data breach, we act in accordance with the GDPR, including notifying the President of the Personal Data Protection Office (PUODO) and affected data subjects where required.

14. Your rights

You have the right to:

  • access your data,
  • rectify your data,
  • erase your data,
  • restrict processing,
  • data portability,
  • object to processing based on legitimate interests,
  • withdraw consent where processing is based on consent.

Requests may be sent to pando@holak.me. We normally respond within one month of receiving the request.

15. Complaint to the supervisory authority

You also have the right to lodge a complaint with the President of the Personal Data Protection Office in Poland (Prezes UODO).

16. Children

The service is not intended for children under 16, unless we expressly state otherwise and obtain the required authorisation from the holder of parental responsibility. If we discover that a child's data were collected without the required basis, we will take appropriate steps to delete them.

17. Account deletion

You may request deletion of your account in the account settings or by contacting us at pando@holak.me. Deleting your account does not always mean immediate deletion of all data: we may retain some information for the period required by law, for security purposes or to defend legal claims (see section 9).

18. Changes to this Policy and language versions

We publish changes to this Privacy Policy in the service; we will inform you of material changes in advance. The Polish and English versions are maintained in parallel; in the event of inconsistency, the Polish version prevails for users habitually resident in Poland, unless mandatory law requires otherwise.

Terms of Service →