Privacy Policy
Version: 2026-08-12
Effective date: August 12, 2026
Last updated: August 12, 2026
This Privacy Policy explains how Natallia Vasilyeva, trading as NATALLIA VASILYEVA – Poland Documents, processes personal data in connection with the Registry Intelligence website, public official-source research, communications, purchases, and the CPSC eFiling CSV Checker & Builder, a distinct product of Registry Intelligence. It also contains supplemental disclosures for residents of the United States, including a California Notice at Collection where applicable.
Application release condition. Live uploads and public paid sales remain disabled for every country and purchaser type until the effective Subprocessor List identifies and authorizes every production provider and location, the required transfer arrangements are complete, the applicable country/subdivision and purchaser-type route is expressly enabled, and the privacy, security, payment, recovery, evidence, retention, deletion, and end-to-end controls described in this Policy have passed release testing.
At a glance:
- Poland Documents is the controller for website, research, contact, transaction, security, and contract-evidence data, but acts only under an accepted DPA for Customer Personal Data.
- The Application supports global B2B and B2C purchasers through three required purchaser routes; each country/subdivision and purchaser-type route is disabled by default until approved and enabled.
- No general Application account is required. The purchaser verifies the Job email before any document upload; protected access then uses the current browser session, a 30-minute one-time magic link, or the Job ID plus Recovery Code as applicable.
- Application files and results are temporary, are not added to public Registry Intelligence products, are not used for advertising, and are not used to train AI models.
- The personal-use Consumer route accepts the Consumer’s own personal data and non-personal information; third-party personal data requires the applicable controller or processor route.
- General public pages may use consent- and opt-out-controlled technologies described in the Cookie Policy; protected Application pages follow stricter isolation.
- Privacy requests require no account and may be sent to inbox@polandoc.com.
1. Controller identity, contact details, and scope
For the independent-controller activities described in this Policy, the controller is Natallia Vasilyeva, trading as NATALLIA VASILYEVA – Poland Documents, a sole proprietorship (jednoosobowa działalność gospodarcza) registered in the Republic of Poland.
Public brand and client-facing platform: Registry Intelligence
Product: CPSC eFiling CSV Checker & Builder
NIP: 9512533744
REGON: 521062093
Business and legal correspondence address: ul. Ogrodowa 58, lok. 29, 00-876 Warszawa, Poland
Telephone: +48 501 335 073
Privacy contact: inbox@polandoc.com
Registry Intelligence is a U.S.-focused commercial intelligence platform and editorial publication operated by Natallia Vasilyeva, trading as NATALLIA VASILYEVA – Poland Documents. The CPSC eFiling CSV Checker & Builder is a distinct product of Registry Intelligence. NATALLIA VASILYEVA – Poland Documents is the Application’s legal operator, seller, service provider, and contracting party. The Application is technically isolated from Registry Intelligence city modules and unrelated application runtimes; that isolation does not restrict its use of the Registry Intelligence brand.
This Policy applies to personal data processed through polandoc.com, Registry Intelligence research and publications, contact and support channels controlled by Poland Documents, purchases, and the CPSC eFiling CSV Checker & Builder (the “Application”). A third-party website, payment page, messaging service, government portal, or marketplace is governed by its own privacy notice when it determines its own processing purposes and means.
Capitalized Application terms not defined in this Policy have the meanings stated in the CPSC eFiling CSV Checker & Builder Application Terms and License.
2. Controller, processor, service-provider, and contractor roles
Poland Documents acts as an independent controller for personal data processed for website operation, official-source research, inquiries, purchaser and representative identification, verified-email and no-account recovery administration, contracting, checkout, billing, tax, payment administration, fraud prevention, security, direct support, contract and acceptance evidence, Delivery and Full Performance evidence, withdrawals, refunds, deletion evidence, legal compliance, and the establishment, exercise, or defence of legal claims. Under an applicable U.S. state privacy law, Poland Documents may be described as a business or controller for the same activities.
Where a business, professional, sole trader, or other organization acts as a controller or processor and submits personal data for processing on its documented instructions, Poland Documents acts as its processor, service provider, contractor, or further processor only to the extent stated in the accepted Data Processing Addendum (the “DPA”) and, where applicable, the accepted U.S. State Privacy Law Addendum. “Customer Personal Data” means personal data contained in or derived from Customer Data that Poland Documents processes on documented instructions, including personal data in source files, extracted text, mappings, corrections, validation results, intermediate files, Output Packages, and support materials. The person or organization identified in that acceptance record is the “Customer”.
Consumer-contract status and data-protection role are separate questions. A sole trader may complete a business data-processing route while retaining any consumer-contract protection that mandatory law extends to that person. An individual purchasing solely for personal, family, or household purposes is not required to accept a business DPA merely because the individual uses the Application. Acknowledgement of this Privacy Policy records that the notice was reviewed; it is not blanket consent, acceptance of a DPA, or a substitute for consent separately required by law.
Before the first upload made in a controller or processor capacity, the authorized representative must select the relevant role and separately accept the effective DPA, the exact effective Subprocessor List, and, where applicable, the effective U.S. State Privacy Law Addendum. Because inspecting a file to decide whether it contains personal data is itself processing, the Application may require this route for every such upload unless a technically enforced no-personal-data route prevents personal data from reaching Poland Documents before acceptance.
Where Poland Documents acts only on a Customer’s instructions, that Customer remains responsible for determining the lawful basis and permitted purpose, providing required notices, respecting individual rights, and having authority to appoint Poland Documents and the authorized Subprocessors. This Policy supplements, but does not replace, the Customer’s own privacy notice.
3. Sources and categories of personal data
3.1 Data provided directly by a user, purchaser, or representative
- name, verified email address, telephone number, country, U.S. state or territory where relevant, language, and contact preferences;
- organization name, business address, professional role, authority, controller or processor role, upstream-controller information, and tax or registration details where required for a business, DPA, invoice, or tax route;
- the mandatory purchaser choice — an individual for personal, family or household use; an individual or sole proprietor for business, trade or professional use; or an organization or other legal entity — together with the purchaser country or territory and any subdivision required by the active route;
- contact, privacy-rights, withdrawal, complaint, support, security, and refund communications;
- mappings, corrections, confirmations, selected records, instructions, and feedback; and
- information reasonably necessary to verify identity, authority, a payment, or a request.
No general Registry Intelligence account or reusable password is required for an Application Job.
No purchaser option is preselected. The purchaser choice is recorded before email verification, Job creation, or upload and is used only to display the correct notices and contract documents; it does not determine or waive rights that apply by law. Business email, VAT ID, payment method, IP-derived location, or the intended U.S. use of the output does not silently change the selected purchaser type. Buyer geography is global, but a country/subdivision and purchaser-type route remains unavailable until its versioned tax, consumer, invoice or receipt, payment, privacy, contract, language, and dispute controls are approved and enabled.
3.2 Application files, certificate data, and generated results
Where the relevant format or function is expressly enabled in the live workflow, the Application may process:
- supported CSV, XLSX, PDF, and ZIP files;
- text extracted from a PDF and OCR-derived values only where the PDF or OCR workflow has passed the required production privacy, security, provider, location, retention, and transfer review;
- product-certificate fields, importer, manufacturer, laboratory, certifier, point-of-contact, Product ID, Version ID, date, location, citation, testing, and related trade-party information contained in those files;
- column mappings, validation findings, corrections, confirmations, Selected Ready Records, and user instructions;
- the free prepayment review: the Readiness Report, errors and warnings, missing confirmations, Ready Record count, selected records, mappings and corrections, and the exact final price;
- the paid Output Package: one or more CPSC-formatted CSV files labelled “CPSC CSV,” a Validation Summary, a Correction Ledger, a Ruleset & Provenance Receipt, and a README;
- the protected controls “Download CPSC CSV” and “Download Complete Output Package (ZIP)”; the direct CPSC CSV control supplies the single CPSC CSV or a CSV-only set when batching creates multiple sequentially numbered CPSC CSV files;
- temporary Job identifiers, file names where operationally necessary, file type and size, row and column counts, batch information, validation status, ruleset version, processing state, payment state, access state, and deletion state; and
- substantive Job content voluntarily reproduced in or attached to a support request.
“Protected” describes the access channel and does not mean that the ZIP itself is encrypted unless the live checkout expressly states that it is. The prepayment Readiness Report is separate from the paid Output Package. The standard promised paid result contains only the five canonical components listed above, with multiple sequentially numbered CPSC CSV files where batching is required.
3.3 Transaction, verification, recovery, and evidence data
- order, amount, currency, tax, payment, invoice, refund, chargeback, and payment-provider references;
- for a separate Registry Intelligence client portal or subscription service, any account identifier, access entitlement, subscription status, profile setting, and login or security event required for that separate service; no such general account is required for an Application Job;
- verified-email events and references, transactional-message identifiers, delivery or bounce status, magic-link and Recovery Code events, restricted-session events, credential issuance, use, expiry, and revocation;
- the exact purchaser choice, purchaser country or territory and subdivision, Job ID, verified-email reference, fixed Order Confirmation, immutable checkout snapshot, and evidence-snapshot identifier;
- each control’s exact rendered text and language, stable control identifier, initial unchecked state, affirmative event, UTC timestamp, and applicable withdrawal event;
- interface, document, pricing, schema, and ruleset versions, URLs and integrity hashes; pricing inputs, Selected Ready Record count, band calculation, subtotal, tax, total, currency, package, and output-component integrity records; and
- payment reference, contract acceptance, Delivery, Full Performance, recovery, withdrawal, refund, complaint, support-hold, access-expiry, and deletion events.
Clear magic links, recovery codes, download secrets, and complete access tokens are not placed in analytics, ordinary logs, email subjects, or long-term contract evidence. A download-start or download-completion event may be retained as limited operational telemetry, but it does not by itself define Delivery or Full Performance.
Full Performance is determined by completion of the promised paid processing and genuine availability of every paid deliverable in usable form through the promised functional method; it does not require the Purchaser actually to download or open a file. This legal state and any separate download telemetry are recorded distinctly.
3.4 Technical, device, cookie, and security data
- IP address, approximate location derived from an IP address, browser, user-agent, device type, operating system, date and time of access, and referring page;
- pages and functions used, cookie or privacy choices, Privacy Policy acknowledgement, contractual acceptance events, and any separate marketing consent;
- session, access-control, rate-limit, bot-detection, authentication, payment-webhook, security, error, and incident-response events; and
- minimized Job, generation, email-verification, order-confirmation, recovery, withdrawal, refund, and deletion status information.
IP address, user-agent, and device data are not required elements of the six-year contract-evidence record. They are retained under the shorter security-log period unless a documented fraud, security, legal-claim, or binding preservation reason requires restricted retention.
3.5 Data received from other sources
Personal data may also be received from a Customer or authorized representative; a payment provider, bank, card network, accounting provider, or tax system; a transactional-email or security provider; a person making an authorized request; and official public sources described in Section 4. We do not purchase private consumer dossiers or use private-contact enrichment services.
4. Official-source commercial intelligence and public records
Sections 1, 3–5, 11–16, and 18 of this Policy, together with the applicable module-specific Data Sourcing & Compliance notice, provide the general Article 14 information. Publication of those notices does not replace individual notice where Article 14(3) requires it. No identifiable-person record may be first publicly displayed or otherwise disclosed until the applicable direct notice has been provided or a documented Article 14(5) exception and its safeguards have been approved for that module.
Registry Intelligence publishes commercial research based on lawfully accessible official government, municipal, county, state, federal, regulatory, public-institutional, and government-authorized sources. These may include registries, public portals, downloadable datasets, official APIs, GIS services, permit and licensing systems, procurement platforms, inspection and enforcement records, property and land systems, and agency publications.
Official records may contain a person’s name, professional or public role, business affiliation, occupational or facility licence, filing contact, business or mailing address, ownership information, public identifier, permit or inspection history, procurement activity, and other information connected with commercial or regulated activity. The source, category, and commercial context are described more fully in the Data Sourcing & Compliance notice.
Each affected module or displayed record identifies, directly or through a clear source trail, the originating authority or database and the relevant source, retrieval, or review date. Poland Documents does not assume that information is exempt from GDPR merely because it is publicly accessible.
Unless a separate lawful basis, applicable Article 9 or Article 10 condition, necessity assessment, and required data-protection impact assessment have been documented, Registry Intelligence does not republish special-category data, criminal-conviction or offence data, children’s data, government-identification numbers, private personal contact details, or an individual’s separate residential or mailing address. A property address may be displayed as a property attribute only; an owner’s separate residential or mailing address is suppressed unless strictly necessary and proportionate to an approved module purpose.
Where GDPR applies and Poland Documents acts as controller for this research, processing ordinarily relies on the legitimate interests in source-transparent commercial research, public-record accessibility, regulatory and market transparency, provenance, and accurate business context under Article 6(1)(f) GDPR. Before a module is released or materially expanded, Poland Documents documents the interest pursued, strict necessity, less intrusive alternatives, source context, reasonable expectations, impact on individuals, and safeguards. Public availability alone does not make every personal field necessary or establish that the balancing test is satisfied. Fields that are private, sensitive, disproportionate, irrelevant, or unsuitable for the stated commercial purpose are excluded, limited, suppressed, or not republished.
Before release or material expansion of each module, Poland Documents records an Article 35 GDPR threshold assessment. Where the processing is likely to result in a high risk to individuals, the module does not launch until a data-protection impact assessment has been completed and any required Article 36 consultation has been resolved.
Where personal data was not obtained directly from the individual and individual notice is required, Poland Documents provides the information identified in this Policy and the applicable module-specific notice no later than one month after obtaining the data, at the first communication with the individual, or before the first disclosure to another recipient, whichever applicable deadline occurs first.
Each direct Article 14 notice and any first communication concerning processing based on Article 6(1)(f) explicitly brings the Article 21 right to object to the individual’s attention, clearly and separately from other information.
Poland Documents does not rely on a blanket assumption that scale, cost, or public availability makes individual notice impossible or disproportionate. Before relying on Article 14(5)(b), it documents the assessment for the specific module and affected category, including the number of people, age and source of the data, available contact channels, whether obtaining contact details would require additional collection, cost, risk, and safeguards. Where that exception lawfully applies, safeguards include this public notice, a prominent module-specific source notice, source transparency, data minimization, purpose limitation, source-linked correction, and an accessible objection, correction, or suppression channel. If contact details later become available or Poland Documents communicates with the individual, direct notice is provided unless another documented exception applies.
Public-record information may be shown to authorized users or visitors of the identified Registry Intelligence module or report. A recipient determines its own lawful basis and responsibilities for any later independent use. A publicly available email address or telephone number is not treated as consent to electronic marketing.
Registry Intelligence does not use these records to create private consumer profiles and is not offered for consumer credit, employment, tenant, insurance, background-screening, or other eligibility decisions. It does not use leaked databases, hacked data, stolen credentials, private financial or medical data, private consumer contact lists, or synthetic personal-contact enrichment.
5. Purposes and legal bases under GDPR
Where GDPR applies, Poland Documents processes personal data for the following purposes and legal bases:
- Website access and communications. To operate the website, respond to a person’s request, and provide requested information under Article 6(1)(b) where the person requests pre-contract steps, or Article 6(1)(f) for ordinary business communications and the legitimate interests in responsive administration and service operation.
- Contracting and Application delivery. To record the purchaser choice and location, verify the Job email before any document upload, establish the appropriate enabled route, freeze an order, validate and process the contracting person’s data, provide the Readiness Report, take payment, generate and deliver the Output Package, provide protected access, and handle withdrawal, correction, redelivery, or refund under Article 6(1)(b).
- Organizational contacts. To communicate with an employee, representative, or business contact about an organization’s Job under Article 6(1)(f), based on the legitimate interests in performing and administering the requested business service.
- Customer Personal Data. Where Poland Documents acts for a Customer, it processes Customer Personal Data only on documented instructions under the DPA. The Customer determines and documents its lawful basis. Article 6(1)(b) does not automatically apply to a third party merely because that person’s data appears in an uploaded file.
- Payments, accounting, and tax. To process a transaction and refund under Article 6(1)(b), comply with accounting, tax, invoice, and lawful-authority duties under Article 6(1)(c), and reconcile or defend a transaction under Article 6(1)(f).
- Security, fraud prevention, and service integrity. To verify access, prevent malicious uploads, fraud, misuse, unauthorized disclosure, and circumvention; maintain minimized operational logs; investigate incidents; and protect users, Poland Documents, and third parties under Article 6(1)(f), and Article 6(1)(c) where a legal duty applies.
- Evidence and legal claims. To maintain minimized evidence of notices, acceptance, price, performance, Delivery, Full Performance, withdrawal, refund, deletion, and complaints, and to establish, exercise, or defend legal claims under Article 6(1)(f), or Article 6(1)(c) where required by law.
- Official-source research. For the purposes and legitimate interests described in Section 4 under Article 6(1)(f).
- Privacy requests and regulatory compliance. To verify and answer a request, cooperate with a competent authority, and demonstrate compliance under Article 6(1)(c) and, where appropriate, Article 6(1)(f).
- Non-essential cookies, analytics, social media, or marketing technologies. Under Article 6(1)(a) and applicable electronic-communications law where prior consent is required. Necessary storage or access is used only where the law permits it without consent.
Consent may be withdrawn at any time through the available consent control or by contacting Poland Documents, without affecting processing lawfully carried out before withdrawal. Refusing or withdrawing non-essential consent does not increase the price or prevent use of functions that do not require the relevant technology.
The verified Job email is used for transactional, security, support, legal, order-confirmation, delivery, and Job communications only. Poland Documents does not use contact details contained in Customer Personal Data to contact Data Subjects or for marketing, except on the Customer’s documented instruction or where law requires it. The verified email is not added to an electronic-marketing list unless the individual separately and optionally consents to that distinct purpose.
Poland Documents does not send electronic direct marketing to a checkout, support, official-source, or other email address or telephone number unless the subscriber or end user has separately given prior valid consent for that channel and sender under Articles 398 and 400 of the Polish Electronic Communications Law and Article 6(1)(a) GDPR. A publicly listed business contact is not treated as marketing consent.
Poland Documents does not use uploaded Customer Personal Data or Output Packages as an independent source for product development. Application improvement uses synthetic or test data and genuinely anonymous aggregate statistics. Personal Controller Data is not used for product improvement unless the specific data category, purpose, lawful basis, retention period, and, where applicable, legitimate-interest assessment have first been documented and disclosed.
6. Application processing boundaries and lifecycle
Before any document upload, the Application records the required purchaser choice and location, confirms that the applicable country/subdivision and purchaser-type route is enabled, verifies the Job email, and presents the required notices and separate upload controls. An applicable controller or processor route also remains technically blocked until the verified representative, controller or processor role selection, DPA and Subprocessor authorization, and fixed acceptance-snapshot requirements in Sections 2 and 8 have been completed.
Before payment, the Application provides the free review: the Readiness Report, errors and warnings, missing confirmations, Ready Record count, selected records, mappings and corrections, and the exact final price for the frozen paid scope. The free stage does not provide a paid CPSC CSV or the Complete Output Package and does not require a purchase.
After payment and successful generation, the paid Output Package contains only the components listed in Section 3.2. It is supplied as one ZIP through the protected Job page, with a separate protected direct-download control for the CPSC CSV file or files. The Application does not submit data or files to CPSC, CBP, ACE, the CPSC Product Registry, Amazon, a marketplace, a laboratory, a customs broker, or another authority.
Uploaded Customer Data, extracted text, Readiness Reports, mappings, corrections, intermediate files, validation results, and Output Packages:
- are not added to Registry Intelligence city modules, public-source datasets, lead products, editorial content, or unrelated customer products;
- are not sold or licensed as data products;
- are not used for cross-context behavioural advertising or targeted advertising;
- are not used to train, fine-tune, test, benchmark, or evaluate a general-purpose or third-party artificial-intelligence model; and
- are processed only to provide and secure the Job, provide user- or Customer-requested support, comply with a legally binding requirement, preserve only the minimum data permitted by the DPA, and return or delete the data under this Policy and the DPA.
The Application does not autonomously choose or infer a certificate type, legal citation, testing exclusion, laboratory, manufacturer, certifier, point of contact, Product ID, Version ID, or another substantive compliance value. PDF text extraction or OCR may operate only if expressly enabled after the verified production data flow, provider or local-processing arrangement, locations, retention settings, safeguards, transfer mechanism, and effective Subprocessor List have been disclosed and the user has affirmatively selected the OCR-enabled workflow. Each OCR-derived value is identified as machine-generated and must be confirmed or corrected before paid generation. If OCR is not enabled, a scanned PDF is rejected rather than silently omitted.
Non-essential social-media, marketing, advertising, remarketing, and cross-site analytics technologies are disabled on upload, protected Job, checkout, recovery, and download pages. Privacy-restricted first-party or service-provider analytics may operate on such a page only after a documented production test proves that the technology does not constitute sale, sharing, or targeted advertising and cannot receive uploaded content, a filename, record value, complete Job identifier, access or recovery secret, checkout snapshot, record-level result, or Output Package. If that separation cannot be verified, the technology remains disabled.
7. Required information, third-party data, and prohibited data
Fields identified as required by a form, upload flow, DPA route, checkout, or rights-request process are necessary for the stated function. If required information is not provided, Poland Documents may be unable to answer, verify authority, accept a file, provide the Job, take payment, deliver a result, provide recovery, or answer the request. A field not identified as required is generally optional.
The Consumer route accepts only the Consumer’s own personal data and non-personal information. It does not accept personal data relating to another individual. If an input contains or is reasonably expected to contain third-party personal data, transfer of file content remains blocked unless the user completes the applicable controller or processor route and accepts the effective DPA. If no lawful route applies, the file is rejected before content transfer. Consumer-contract status remains separate and is preserved where mandatory law applies.
Do not upload or send: Social Security numbers; personal government-identification numbers; payment-card or bank-account data; passwords, login credentials, API keys, or authentication secrets; health, genetic, or biometric data; precise location data; personal data about children; criminal-offence, credit-report, background-check, or employment-screening data; or other sensitive personal data that the Application does not expressly request.
Complete payment-card numbers and security codes must be entered only in the payment provider’s environment. If prohibited data is detected or reported, Poland Documents may isolate the Job, restrict access, reject further processing, notify the user or Customer where appropriate, and securely delete the affected content unless law requires limited preservation. Prohibited data must not be resent through ordinary email or support.
8. Verified email, no-account recovery, and evidence
No general Registry Intelligence account or reusable password is required. The purchaser first records the mandatory purchaser choice and location, then provides an email address and verifies it before any document upload. The verified email is bound to the Job. For an applicable controller or processor flow, the representative’s business email, authority, role, and required DPA and Subprocessor acceptances are also completed before file content is accepted.
The current browser continues through a protected Secure, HttpOnly session while that session remains valid. From a new device, protected Job access uses either: (a) a fresh, one-time magic link sent only to the verified email after the Job ID is supplied, which expires 30 minutes after issue and becomes invalid after successful use; or (b) the Job ID together with the independently issued Recovery Code. A new magic link may be requested until automatic Job deletion. All issue, resend, and validation attempts are rate-limited and use neutral responses.
The Recovery Code contains at least 128 bits of cryptographic entropy, is displayed once when the Job is created, is stored only as a keyed hash, remains valid until automatic Job deletion, and is never sent in the same message as the email magic link. A Job ID alone, Stripe payment reference, billing detail, purchaser fact, business fact, or identity document is not an authentication factor. The 30-minute magic-link period is separate from the seven-calendar-day paid-output entitlement measured from Delivery Time; no credential extends that entitlement or restores expired or deleted content.
If the purchaser loses access to both the verified email account and the Recovery Code and has no still-valid authorized browser session, Job access and paid-output access cannot be recovered. Support must not reset either factor, change the verified email, disclose Job data, issue a replacement credential, or restore downloads. Support may handle a complaint, billing issue, or refund without granting Job access.
Poland Documents keeps an immutable or equivalently tamper-evident server-side evidence snapshot containing the exact purchaser choice, country or territory and subdivision, Job ID, verified-email reference, exact order snapshot, each control’s exact rendered text and initial unchecked state, affirmative event and any withdrawal event, UTC timestamp, interface and document versions and hashes, pricing inputs, Selected Ready Record count, band calculation, subtotal, tax, total, currency, ruleset, package, payment reference, fixed Order Confirmation, transactional-message and bounce evidence, output-integrity evidence, and the relevant Delivery, Full Performance, access, complaint, withdrawal, refund, hold, and deletion events. Browser local storage alone is not sufficient evidence.
Where an enabled route requires a separate express request or consent, including a Consumer’s request for immediate paid performance, that control is separate from the Terms, Privacy Policy, Refund & Delivery Policy, marketing choices, and payment control and is unchecked by default. Privacy Policy acknowledgement is recorded as notice acknowledgement, not consent. A DPA or U.S. State Privacy Law Addendum acceptance is a business processing arrangement, not Consumer privacy consent. Full uploaded files, Output Packages, clear tokens, Recovery Codes, and complete payment-card data are excluded from the six-year evidence store.
9. Payments, invoices, and tax
Payment is made through the provider identified on the checkout page, currently designed to use Stripe Checkout. When a user opens or enters information in Stripe Checkout, the applicable Stripe entity may collect contact and billing details, transaction and payment-method information, IP address, browser and device identifiers, cookies, approximate location, and fraud signals, including information entered before an attempted checkout is completed. Depending on the function and purpose, Stripe may act as Poland Documents’ processor or service provider and/or as an independent controller for payment processing, authentication, fraud prevention, legal compliance, service analytics, and an optional Stripe service the user separately chooses, such as Link. Stripe’s independent processing is described in the Stripe Privacy Policy.
Poland Documents receives only the transaction information needed to verify payment, accept the order, authorize generation and delivery, reconcile the charge, issue an invoice, administer a refund or dispute, prevent fraud, and keep required records. Source files, substantive certificate records, Output Packages, clear access tokens, recovery codes, and complete Job identifiers are not included in payment-provider metadata or otherwise sent to the payment provider.
Billing, invoice, and tax data may be provided to Poland Documents’ accounting provider and, where applicable, Poland’s National e-Invoice System (KSeF), tax authorities, or other legally authorized recipients. The exact payment provider and required pre-payment disclosures are presented before data is submitted or a charge is made.
After the signed payment event, amount, currency, Job ID, and frozen order snapshot are verified, a fixed Order Confirmation and the applicable Refund & Delivery Policy are made available through the protected Job page and sent to the verified order email. The evidence record preserves the fixed confirmation, its integrity hash, the transactional-message identifier, and delivery or bounce status without placing source files, Output Packages, complete Job identifiers, or access secrets in payment-provider metadata or email subjects.
10. Cookies, analytics, social media, and browser signals
The website uses technologies necessary for security, consent management, language and interface preferences, session handling, checkout, verified-email and protected access, and proper technical functioning. Necessary technologies operate without consent only where permitted by applicable law.
Under Article 399 of the Polish Electronic Communications Law, Poland Documents stores information on, or accesses information from, a user’s terminal device without consent only where it is strictly necessary to transmit an electronic communication or provide a service or function expressly requested by that user. Other cookies, local-storage objects, pixels, analytics tags, embedded-media trackers, and similar technologies remain disabled until the user gives prior, informed, specific, and affirmative consent where that rule applies.
Privacy Policy acknowledgement, acceptance of Application terms, payment, or use of a necessary function is not consent to non-essential tracking. Non-essential choices are unchecked by default, may be made by category, and may be rejected as easily as accepted. The current provider categories, purposes, cookie names, and lifetimes are described in the Cookie Policy.
Depending on the page, configuration, and consent choice, analytics, anti-bot, embedded-media, font, or social-media providers may receive an IP address, browser and device data, page URL, referring page, time, and interaction data. Some social-media or marketing providers may collect online activity over time and across websites under their own notices. They are not permitted to receive Application uploads, Customer Personal Data, Output Packages, complete Job identifiers, or access and recovery secrets.
If Google Analytics 4 is enabled after the applicable statistics choice, Google may collect limited device, browser, page, and usage data over time and across its services as described in its privacy materials. Google Analytics advertising features, Google Signals, advertising identifiers, and Application User-ID or full Job-ID transmission remain disabled unless a later, conspicuous notice and every required consent or U.S. opt-out control are implemented first. Advertising pixels, remarketing tags, and social-media tracking pixels are not used on Application upload, protected Job, checkout-return, recovery, or download pages.
Users may accept, reject, or change non-essential choices through the “Manage Consent” control. Withdrawal prevents future loading governed by that choice; existing third-party cookies may also need to be deleted through the browser.
The website recognizes and honors Global Privacy Control (GPC) as a request to opt out of sale, sharing, and targeted advertising for the browser or device from which the signal is received. The signal is applied before affected third-party technology loads and is not subjected to identity verification or account creation. Because no general Application account is used, an unauthenticated GPC signal applies to the browser or device and online activity reasonably associated with it; it does not by itself identify unrelated offline records. The legacy “Do Not Track” signal is not treated as a general privacy-rights request because it has no uniform technical or legal standard. A user may always exercise a listed right directly under Sections 16–18.
11. Recipients, service providers, and Subprocessors
Personal data is disclosed only where reasonably necessary for the purposes in this Policy and subject to the applicable role, contract, confidentiality, security, and data-protection requirements. Recipient categories may include:
- website hosting, content-delivery, security, anti-bot, consent-management, and technical-maintenance providers;
- transactional-email and communication providers used for email verification, fixed confirmations, delivery notices, support, and legally required notices;
- payment providers, banks, card networks, fraud-prevention providers, accounting providers, KSeF, and tax authorities;
- analytics, embedded-media, font, and social-media providers only as described in Section 10 and the Cookie Policy;
- the exact Application Subprocessors identified in the accepted effective Subprocessor List;
- professional legal, accounting, security, and technical advisers under duties of confidentiality; and
- courts, regulators, supervisory authorities, law-enforcement bodies, or other competent recipients where disclosure is required by law or necessary to establish, exercise, or defend legal rights.
The exact effective CPSC eFiling CSV Checker & Builder Subprocessor List identifies every production provider that may process Customer Personal Data on behalf of a Customer, including its legal entity, address, function, data categories, processing and remote-access countries, onward chain, transfer mechanism, and effective date. A generic provider category in this Policy does not replace that list or the authorization required by the DPA. While the published Subprocessor List remains pre-production and states that no production Subprocessor is authorized, the Application does not accept live files or Customer Personal Data and does not enable public paid sales.
A payment provider, bank, card network, public authority, or analytics provider is not an Application Subprocessor merely because it processes separate Controller Data for its own or Poland Documents’ purposes. If a provider begins receiving Customer Personal Data on a Customer’s behalf, it must first be classified, disclosed, contractually bound, and authorized under the DPA.
Poland Documents does not sell uploaded Customer Personal Data or Output Packages for monetary or other valuable consideration, does not share them for cross-context behavioural advertising, and does not disclose them for targeted advertising. General-website tracking disclosures are stated separately in Sections 10 and 17.
12. International data transfers and processing locations
Poland Documents is established in Poland. Controller Data may be processed in Poland, elsewhere in the European Economic Area, in the user’s location, and in the locations used by the verified recipients described in this Policy. Customer Personal Data may be stored, processed, or remotely accessed only in the locations identified in the accepted effective Subprocessor List and in the Customer’s identified country for an authorized return or delivery under the DPA.
Where GDPR or another applicable law requires a transfer safeguard, Poland Documents uses the mechanism applicable to the verified legal entity, data, location, and transfer. This may include an adequacy decision, a recipient’s active and scope-appropriate participation in an approved data-privacy framework, completed Standard Contractual Clauses approved by the European Commission with the correct module and annexes, a documented transfer assessment and supplementary safeguards, or another lawful mechanism. A provider’s general claim of certification is not relied upon unless the exact legal entity, covered service, data, and current certification are verified.
Where Poland Documents acts as an EEA processor and makes Customer Personal Data or record-level results available to a non-EEA Customer, the applicable DPA transfer workflow, including any required completed clauses and transfer information, must be in place before the first display, download, support disclosure, API response, or other return. No live Customer Personal Data is sent to an unlisted production provider, location, or onward recipient.
Information about an applicable safeguard and a copy of relevant transfer documentation, subject to necessary redactions, may be requested at inbox@polandoc.com.
13. Retention, expiry, and deletion
The following exact rules reproduce the current Pricing, Limits & Retention Schedule for the Application and state the applicable criteria for other processing. An exception is permitted only for a documented delivery or refund case, fraud or chargeback matter, security incident, legal claim, mandatory duty, or binding legal process, and only the necessary data is isolated and restricted. A later policy or interface change does not silently extend retention of existing Job content. Application timestamps and expiries are recorded in Coordinated Universal Time (UTC).
| Data or state | Retention or deletion rule |
|---|---|
| Upload that does not successfully create a Job | Every active copy is deleted within 24 hours. |
| Active free or unpaid Job content | Expires after 7 consecutive days of inactivity and in every case no later than 30 calendar days after Job creation. Active-system deletion completes within the following 24 hours unless a documented hold applies. |
| Paid Job awaiting Delivery | Retained until Delivery, cancellation, or refund resolution. If Delivery has not occurred within 14 calendar days after verified payment, Poland Documents must deliver, obtain a documented written extension, or initiate a full refund. After cancellation or refund resolution, active-system deletion completes within 24 hours unless a documented lawful hold applies. For Customer Personal Data subject to the DPA, the Customer’s timely return-or-deletion choice applies. |
| Delivered paid Job | The protected Output Package ZIP, direct CPSC CSV access, source files, mappings, confirmations, corrections, intermediate data, and generated files expire exactly 7 calendar days after Delivery Time. Paid-output access then ends, and active-system deletion completes within the following 24 hours. A still-valid magic link, Recovery Code, or authorized browser session may authenticate only lawfully retained Job-status information until automatic Job deletion and cannot restore expired content. |
| Timely acknowledged withdrawal, support, delivery, or refund request requiring Job content | Only the content reasonably necessary is retained for 30 calendar days. Any extension requires a documented reason, a necessity review, and an additional fixed 30-day period; the hold does not automatically extend general download access. |
| Ordinary Application, access, rate-limit, and security logs | Retained exactly 90 calendar days from creation unless a documented binding preservation requirement applies. Raw source rows, full files, complete tokens, and Output Package content are not written to these logs. |
| Fraud, chargeback, or security-incident evidence | Retained for 12 months after the case closes, unless an unresolved claim, binding process, or mandatory legal duty requires longer restricted preservation. |
| Encrypted backup remnants of deleted active Job content | Deleted or overwritten no later than 30 calendar days after active-system deletion, except for a documented legal-preservation copy. Backups are not used for ordinary customer recovery, and deletion markers are reapplied after a disaster-recovery restoration. |
| Contract, document-acknowledgement, acceptance, pricing, Delivery, Full Performance, withdrawal, refund, and deletion evidence without complete uploaded files | Retained for 6 years after the later of payment, Delivery, cancellation, or refund; longer only for an identified longer limitation period, unresolved claim, mandatory duty, suspension, interruption, or binding process. |
| Separate client-portal account and access data, where that different service is used | Retained while the account or access arrangement remains active and deleted or anonymized within 30 days after closure, except for transaction, security, contract, or legal records retained under another applicable row. |
| Invoices, accounting, tax, payment, and refund records | Retained for the applicable Polish statutory tax period. A structured invoice in KSeF is retained there for 10 years from the end of the calendar year in which it was issued. |
| Ordinary support and privacy correspondence without complete Job content | Retained for 3 years after the matter closes, unless linked to an unresolved transaction, claim, security matter, or mandatory recordkeeping duty. |
| Cookies, consent choices, and general-site analytics | Retained for the cookie lifetime or provider period disclosed in the Cookie Policy, only while necessary for the stated purpose and subject to withdrawal or opt-out where applicable. The consent-preference cookie is retained for up to 365 days. Any separate minimized evidence of consent or withdrawal is retained only for the period necessary to demonstrate compliance under the applicable legal basis and is not treated as permission to continue tracking after withdrawal. |
| Official-source research containing personal data | Retained while the source remains lawfully available and authoritative enough, and the field remains relevant, proportionate, and necessary for the stated commercial-research purpose. Each module has a documented revalidation interval not exceeding 12 months. If personal fields are not revalidated by that deadline, they are suppressed from current-facing results pending review. Longer historical retention requires documented continuing necessity and clear source and record-date context. Data is corrected, suppressed, or removed sooner where appropriate. |
“Delivery Time” uses the strict definition in the Application Terms: it is recorded only after all purchased processing is complete, the complete and conforming Output Package has passed the required integrity checks, both protected download controls are genuinely functional and accessible, the exact seven-day access expiry and scheduled deletion time are recorded and displayed, and the ready-for-download notice has been accepted by the verified transactional-email provider without a known hard failure. A payment receipt, queue entry, file-creation event, inaccessible link, or failed notice is not Delivery.
Expiry or deletion of temporary Job content does not waive or shorten a withdrawal, conformity, complaint, refund, chargeback, or privacy right. Poland Documents is not required to recreate data lawfully deleted before a timely preservation request, but it will use retained evidence and provide any remedy required by contract or law.
14. Security and confidentiality
Poland Documents applies technical and organizational measures proportionate to the nature, scope, context, purpose, and risk of processing. Before the Application accepts live file content, the production measures and evidence required by the DPA, Data Security notice, and implementation standard must be implemented and tested.
Before live processing or a material change involving scale, OCR, a new data category, automated extraction, aggregation, or another risk factor, Poland Documents documents a GDPR Article 35 threshold assessment. Processing likely to result in high risk does not begin until the required data-protection impact assessment is complete and any required prior consultation has been resolved.
Required Application measures include encrypted transport, appropriate encryption of active storage and backups, least-privilege access, multifactor authentication for privileged access capable of reaching Customer Personal Data, environment and product separation, verified email, protected access and recovery verifiers, restricted support access, parser and archive safety controls, file-type and size enforcement, malware or content screening appropriate to enabled formats, payment-webhook verification, secrets management, dependency and release controls, minimized logging, tested backup and deletion controls, incident response, and provider-change gates.
A protected download channel does not mean that the downloaded ZIP is itself encrypted unless checkout says so. No transmission or security control eliminates every risk. Users must protect their devices, verified email, Job link, recovery code, restricted session, and downloaded files, and should promptly report suspected unauthorized access to inbox@polandoc.com.
If a personal-data breach occurs, Poland Documents investigates, mitigates, documents, and notifies the competent authority, affected individual, or Customer where and within the time required by applicable law and the DPA. More information is provided on the Data Security page.
15. Automated processing, validation statuses, and OCR
The Application may automatically parse a supported file, map fields, apply implemented structural and consistency checks, identify validation statuses, calculate counts and price, enforce security and checkout eligibility, batch output, and control generation or protected access according to the accepted ruleset.
These functions do not make a legal, product-safety, certification, customs, government-filing, credit, employment, housing, insurance, healthcare, or other decision producing legal or similarly significant effects about an individual. A Readiness status is an Application result, not CPSC approval. An OCR-derived value cannot become a Selected Ready Record until the user confirms or corrects it. The user remains responsible for reviewing every input, mapping, correction, and output and deciding whether and how to use it.
Poland Documents does not currently use Application data for profiling that produces legal or similarly significant effects. If that changes, the required pre-use assessment, notice, explanation, human-review, consent, and opt-out rights will be implemented before the affected processing begins.
16. Rights under GDPR and related European law
Where GDPR applies and Poland Documents acts as controller, an individual has the following rights, subject to the conditions and exceptions in applicable law:
- receive transparent information about processing;
- obtain confirmation and access to personal data;
- correct inaccurate or incomplete personal data;
- request erasure or restriction;
- object, on grounds relating to the individual’s situation, to processing based on legitimate interests;
- object at any time to direct marketing;
- receive data in a portable format where the legal conditions apply;
- withdraw consent at any time where processing is based on consent;
- not be subject to a qualifying solely automated decision and to obtain the safeguards required by law; and
- lodge a complaint with a competent supervisory authority and seek a judicial remedy.
In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych – UODO), https://uodo.gov.pl/. An individual may also complain to the authority available under applicable law, including in the EEA country of habitual residence, place of work, or alleged infringement.
Poland Documents responds without undue delay and ordinarily within one month after receipt. Where GDPR permits an extension because of complexity or the number of requests, the period may be extended by up to two further months; the individual is informed of the extension and reasons within the first month. Requests are ordinarily free of charge. A reasonable fee or refusal is used only where GDPR permits it for a manifestly unfounded or excessive request. Where Article 19 GDPR applies, Poland Documents communicates a rectification, erasure, or restriction to relevant recipients unless this is impossible or involves disproportionate effort, and identifies those recipients to the individual on request.
Where Poland Documents processes Customer Personal Data solely for a Customer under the DPA or U.S. State Privacy Law Addendum, Poland Documents ordinarily refers the request to and assists that Customer as the relevant controller or business. Where Poland Documents acts as controller for the requester’s data, the request is handled directly under this Policy. Consumer-contract status and data-protection role are determined separately.
17. U.S. State Privacy Notice and California Notice at Collection
This section supplements the remainder of the Policy for a resident of a U.S. state with an applicable privacy law. It also serves as Poland Documents’ online California Notice at Collection to the extent the California Consumer Privacy Act (CCPA) applies. A concise, conspicuous notice entitled “California Notice at Collection” appears at or before each relevant collection point, including the website or Application landing page, verified-email field, contact or support form, first upload control, recovery form, and checkout redirect. It links directly to this Section 17, not merely to the top of this Policy, and links directly to the “Your Privacy Choices” or “Do Not Sell or Share My Personal Information” control where sale or sharing applies.
The point-of-collection text is: “NOTICE AT COLLECTION. On affected public pages, we collect online identifiers and internet or other electronic-network activity and classify disclosures of those categories to enabled social-media, marketing, or analytics providers as a sale and sharing for cross-context behavioural advertising. Other categories, purposes, recipients, and retention periods are stated in the U.S. State Privacy Notice. Application files, Customer Personal Data, and generated Job data are not sold or shared for cross-context behavioural advertising. Use Your Privacy Choices to opt out and see the Privacy Policy.” “U.S. State Privacy Notice” links directly to this Section 17, and “Your Privacy Choices” links directly to the opt-out control.
17.1 Categories collected in the preceding 12 months
The following table is both a preceding-12-month disclosure and a prospective notice for an activated Application. The “preceding 12 months” column distinguishes existing website or research processing from Application file processing that remains disabled under the release condition at the top of this Policy and Section 11.
| Statutory category and examples | Sources and purposes | Recipient categories | Retention | Preceding-12-month and prospective status |
|---|---|---|---|---|
| Identifiers and contact data: name, postal or business address, email, telephone number, IP address, public-record or organization identifier, Job ID, payment reference, and protected access verifier. | From the individual, representative, device, Customer, payment provider, or official source; for contact, routing, verification, service, security, recovery, public-record research, and legal compliance. | Hosting, security, email, payment, accounting, professional advisers, authorities, authorized module users solely for official-source fields, and authorized Application Subprocessors as applicable. Module users do not receive private contact, Job, payment, or protected-access identifiers. | Section 13 according to context: exactly 90 days from creation for ordinary technical logs, 3 years after closure for ordinary correspondence, 6 years for minimized contract evidence, applicable statutory tax periods, or the public-record criteria. | Collected: Yes. Sold for monetary or other valuable consideration: Yes, only for online identifiers disclosed through the general-site tracking described in Section 17.2; No for names, contact, public-record, Job, or payment identifiers. Shared for cross-context behavioural advertising: Yes, only for those online identifiers. Disclosed for a business purpose: Yes — to the recipient categories in this row for hosting, security, communication, payment, accounting, research delivery, and legal compliance. Prospectively, Application identifiers remain excluded from advertising disclosures. |
| Customer-record and transaction information: contact and billing information, business or tax details where required, acceptance evidence, order, amount, currency, tax, payment, refund, support, and complaint information. Complete card numbers and security codes are not intentionally received. | From the purchaser, representative, Stripe or another identified payment provider, accounting provider, bank, or authority; for contracting, payment, invoice, tax, refund, fraud, dispute, and evidence purposes. | Payment providers, banks, card networks, accounting and tax systems, email providers, advisers, authorities, and courts as applicable. | Six years for minimized contract evidence; the applicable statutory tax period and the stated KSeF period for invoice and tax data; 12 months after closure for fraud, chargeback, or security-incident evidence; 3 years after closure for ordinary correspondence. | Collected: Yes. Sold: No. Shared for cross-context behavioural advertising: No. Disclosed for a business purpose: Yes — to payment, banking, accounting, email, fraud-prevention, adviser, court, and authority categories for transaction, tax, support, dispute, and compliance purposes. Prospective status is unchanged. |
| Commercial information: service considered or purchased, Job status, Selected Ready Record count, price, ruleset, delivery, recovery, refund, and chargeback status. | From the purchaser, Application state, and payment provider; to provide, price, secure, evidence, support, and remedy the transaction. | Payment, email, accounting, security, support, professional-adviser, and authority categories as necessary. | Temporary Job periods or the 6-year minimized contract-evidence period in Section 13; fraud, chargeback, or security-incident evidence for 12 months after the case closes, subject only to a documented mandatory exception. | Collected: Yes. Sold: No. Shared for cross-context behavioural advertising: No. Disclosed for a business purpose: Yes — to payment, accounting, email, security, support, adviser, and authority categories for service administration, evidence, fraud prevention, and compliance. Prospective status is unchanged. |
| Internet or other electronic-network activity and geolocation data: browser, device, cookie, page, interaction, referring URL, session, consent choice, rate-limit, access, error, security data, and country, state, or approximate area derived from IP. Precise geolocation is not requested. | From the browser, device, consent tool, security service, and enabled website technology; for website operation, language and route selection, consent, analytics where allowed, security, fraud prevention, and legal compliance. | Hosting, security, consent, analytics, embedded-content, social-media, and payment providers depending on the page and choices. | Ordinary technical, access, rate-limit, and security logs exactly 90 days from creation; consent choice ordinarily up to 365 days; provider or cookie period identified in the Cookie Policy. | Collected: Yes. Sold for monetary or other valuable consideration: Yes, for general-site online identifiers and activity disclosed to enabled social-media and marketing or analytics providers. Shared for cross-context behavioural advertising: Yes, for the same categories. Disclosed for a business purpose: Yes — to hosting, security, consent, analytics, payment, and technical providers for operation, measurement, consent, fraud prevention, and security. Prospectively, affected public-page tracking is opt-out controlled and remains prohibited on Application protected pages. |
| Professional, employment-related, communication, and public-record information: organization, role, authority, licence, registration, filing contact, professional message, and commercial official-source fields. | From the individual, Customer, representative, support communication, or identified official source; for organizational administration, authorized support, source-transparent research, correction, and legal compliance. | Communication and support providers, advisers, authorities, authorized module users, and Application Subprocessors where applicable. | Ordinary correspondence for 3 years after closure; public-record criteria in Section 13; Application content under the temporary Job periods. | Collected: Yes. Sold: No for non-public personal information. Shared for cross-context behavioural advertising: No. Disclosed for a business purpose: Yes — to communication and support providers, advisers, authorities, and module users for communication, support, legal compliance, and source-linked research delivery. Official public information may be made available as described in Section 17.2. Prospective Application-file collection remains disabled under the release condition. |
| Application content mapped to statutory categories: authorized certificate records, mappings, corrections, Readiness Report, validation results, CPSC CSV files, Validation Summary, Correction Ledger, Ruleset & Provenance Receipt, README, ZIP, and direct CSV copies. Depending on the field, this content may fall within identifiers, California Civil Code §1798.80 customer-record information, commercial information, professional or employment-related information, internet or other electronic-network activity, or sensitive personal information. | Prospectively from the user or Customer and generated solely to provide, secure, support, return, and delete the requested Job. | Only the user or Customer, authorized Application Subprocessors in the effective list, and a legally compelled recipient where applicable. | Failed upload deleted within 24 hours; free or unpaid Job deleted after 7 days of inactivity and no later than 30 days from creation; paid Job retained until Delivery, cancellation, or refund resolution and, if not delivered within 14 days after verified payment, delivered, placed under a documented written extension, or fully refunded; source and output content retained 7 days from Delivery Time; active-system deletion completed within 24 hours after expiry; backup remnants deleted or overwritten within 30 days after active-system deletion. | Collected: No in the preceding 12 months through a live production Application. Sold: No. Shared for cross-context behavioural advertising: No. Disclosed for a business purpose: No through the pre-production Application. Prospectively after activation, disclosure is limited to the user or Customer, authorized Subprocessors for service delivery, and legally compelled recipients. These data are never used for advertising or AI-model training. |
| Limited inferences and statuses: fraud or security risk signals, route eligibility, file readiness, validation, and support status. These concern transaction or Job operation, not a consumer profile. | Generated from transaction, device, file, and service events; for security, fraud prevention, pricing, technical eligibility, validation, and support. | Security and payment providers; authorized Application Subprocessors; advisers or authorities where necessary. | Ordinary technical and security logs exactly 90 days from creation; fraud, chargeback, or security-incident evidence for 12 months after the case closes; minimized contract evidence for 6 years where applicable. | Collected: Yes for limited website or transaction security statuses; No for production Application readiness statuses. Sold: No. Shared for cross-context behavioural advertising: No. Disclosed for a business purpose: Yes — to security and payment providers, advisers, or authorities for fraud, security, dispute, and compliance purposes. Prospective readiness statuses remain outside legally significant consumer decisions. |
| Sensitive personal information actually authorized: protected Job or recovery authentication information used solely for access and security, and a tax identifier only where legally required. Prohibited sensitive content is not an authorized collection category. | Prospectively from system issuance or directly from the person where tax law requires it; solely for verification, security, recovery, tax, and legal compliance. Not used to infer characteristics. | Only security, payment, tax, or authorized Application providers necessary for the stated function. | Live credentials expire with the Job and are not long-term evidence; raw security logs exactly 90 days from creation; legally required tax data for the applicable statutory period. | Collected: Yes only for a legally required transaction tax identifier; No for production Application recovery credentials. Sold: No. Shared for cross-context behavioural advertising: No. Disclosed for a business purpose: Yes — only to payment, accounting, tax, security, or authority recipients for authentication, fraud prevention, tax, and legal compliance. Prospectively, protected Application credentials are used only for service access and security. |
Information lawfully made available from government records may be excluded from “personal information” under an applicable state law, but Poland Documents still applies the source and use boundaries in this Policy. Poland Documents does not collect an additional category or use it for an incompatible purpose without providing the notice and choice required by applicable law.
17.2 Sale, sharing, targeted advertising, and disclosure
Application data: Poland Documents has not sold Customer Personal Data, uploaded files, Readiness Reports, record-level validation data, or Output Packages for monetary or other valuable consideration and has not shared them for cross-context behavioural advertising in the preceding 12 months. It does not use them for targeted advertising.
General website activity: During the preceding 12 months, Poland Documents disclosed identifiers, including IP address and cookie, browser, or device identifiers, and internet or other electronic-network activity, including page, referrer, and interaction data, to enabled social-media and marketing or analytics providers for measurement and cross-site advertising or tracking purposes described in the Cookie Policy. Poland Documents classifies those disclosures as both a sale for other valuable consideration and sharing for cross-context behavioural advertising under applicable U.S. state definitions. No other category was sold or shared for that purpose. As of this Policy’s effective date, the prospective status is consent- and opt-out-controlled on affected public pages and disabled on Application protected pages. Poland Documents does not sell or share Application uploads, Customer Personal Data, Readiness Reports, record-level validation data, or Output Packages.
To the extent an applicable law grants an opt-out, the visitor may use “Manage Consent,” the conspicuous “Your Privacy Choices” or “Do Not Sell or Share My Personal Information” control displayed where required, a valid Global Privacy Control signal, or a request under Section 18. Opting out disables the affected non-essential technology for that browser or device. Application upload, Job, recovery, checkout, and download pages remain subject to the stricter separation in Section 6.
The preceding-12-month business-purpose disclosure matrix is the table in Section 17.1: each statutory category states whether it was disclosed, the recipient categories, the operational purpose, and the retention rule. The separate sale-and-sharing status for each category appears in the same row. Poland Documents does not have actual knowledge that it sells or shares the personal information of consumers under 16 years of age.
Poland Documents does not disclose contact, purchase, Customer, or Job data to a third party for that third party’s own direct-marketing purpose. Poland Documents uses and discloses sensitive personal information only for authentication, security, fraud prevention, tax or legal compliance, and service-delivery purposes permitted by applicable law, and not to infer characteristics. It does not use or disclose sensitive personal information for a purpose that gives rise to a right to limit under the CCPA.
Official-source research: Registry Intelligence makes available only information verified as lawfully available from official government records or otherwise processed under the lawful framework in Section 4, together with source context. It does not sell or share non-public personal information or derived consumer inferences. If a field or distribution model does not satisfy an applicable public-information exclusion, Poland Documents will classify and disclose the activity, implement any required opt-out, and complete any applicable data-broker registration before that processing begins.
17.3 U.S. privacy rights
Where the relevant law applies, a U.S. resident may have the right to confirm processing; know and access categories, sources, purposes, recipients, and specific information; correct inaccuracies; delete information; obtain a portable copy; opt out of legally defined sale, sharing, targeted advertising, or qualifying profiling; limit certain use or disclosure of sensitive personal information; withdraw consent to sensitive-data processing; obtain a list of specific third parties where required; and appeal a refusal to act. Poland Documents will not unlawfully discriminate or retaliate because a person exercised a privacy right.
The right not to be discriminated or retaliated against includes protection in a person’s capacity as a consumer and, where the applicable law so provides, as an applicant to an educational program, job applicant, student, employee, or independent contractor.
Poland Documents does not offer a financial incentive, loyalty program, or price or service difference in exchange for personal information. No generally applicable privacy right is conditioned on waiving another non-waivable right.
17.4 California online privacy disclosures
California residents may review and request correction of personal information through the process in Section 18. Material changes are communicated as described in Section 20, and the effective date appears at the top of this Policy.
The website’s exact response to Global Privacy Control and legacy “Do Not Track” signals is stated in Section 10. Other parties may collect online activity over time and across websites only through the general-site technologies described there and in the Cookie Policy; Poland Documents does not authorize that collection in the Application file-processing workflow.
18. How to exercise a privacy right
No account is required to submit a privacy request. A request may be submitted:
- by email to inbox@polandoc.com; or
- through the online contact form at https://polandoc.com/contacts/, identifying the message as a “Privacy Request”; or
- by post to Natallia Vasilyeva, NATALLIA VASILYEVA – Poland Documents, ul. Ogrodowa 58, lok. 29, 00-876 Warszawa, Poland.
For an access, correction, deletion, portability, specific-information, or appeal request, state the right requested and provide the name, email, jurisdiction, and information reasonably needed to locate the relevant record, such as a Job ID or payment reference. An opt-out request is governed instead by the no-verification rule below. Do not send complete card details, passwords, magic links, recovery codes, authentication secrets, or unrelated sensitive data.
For an access, correction, deletion, portability, or specific-information request, Poland Documents verifies identity and authority in a manner proportionate to the requested data and risk and does not require creation of an account. An authorized agent may submit a request where law permits; Poland Documents may require proof of the agent’s authority and may directly verify the request with the individual where permitted. A request is answered without charge and within the period required by applicable law, subject to any lawful extension or exception. If a request is denied in whole or part, Poland Documents explains the reason and any available appeal or complaint route.
A request to opt out of sale, sharing, or targeted advertising does not require identity verification or creation of an account. Poland Documents requests only the information reasonably necessary to apply the preference. A valid GPC signal is processed for the browser or device without requiring a name, email address, Job ID, or payment reference.
A U.S. resident may appeal a refusal by replying to the decision or emailing inbox@polandoc.com with the subject “Privacy Appeal.” The appeal will be reviewed by a person not responsible for the initial decision where reasonably practicable, and the response will include any regulator complaint route required by applicable law.
A direct request cannot require Poland Documents to reconstruct complete Job content that was lawfully deleted before the request or to disclose another person’s data, security secrets, or privileged material. This does not remove a contractual or statutory remedy and does not affect assistance owed to a Customer under the DPA.
19. Eligibility, age, and children
Registry Intelligence services and the Application may be used by eligible Business Users, Consumers, and Protected Sole Traders who are at least 18 years old and legally capable of entering the transaction. They are not directed to, and may not be used by, anyone under 18.
Personal data about children is outside the Application’s permitted upload scope. A certificate concerning a children’s product is not, by that fact alone, personal data about a child. If child personal data is detected or reported, it is isolated, access is restricted, and it is securely deleted or otherwise handled as mandatory law requires.
20. Changes to this Policy
The current version, effective date, and last-updated date appear at the top of this page. Poland Documents may amend this Policy prospectively to reflect verified legal, regulatory, provider, security, product, or operational changes.
A material change is communicated through a conspicuous website or Application notice and, where appropriate or required, direct notice to the verified contact before the changed processing begins. A new incompatible purpose, material provider or location, or processing that requires consent or contractual authorization is not introduced merely by posting a revised Policy.
The Policy version acknowledged for an Application Job and its integrity hash are preserved in the evidence snapshot. A later Policy does not silently extend retention of existing uploaded content, shorten promised access, alter an accepted Job, or remove an accrued right or remedy. Archived versions may be requested at inbox@polandoc.com.
21. Privacy contact
Questions, requests, corrections, objections, suppression requests concerning official-source research, and security reports may be sent to:
Natallia Vasilyeva
NATALLIA VASILYEVA – Poland Documents
Registry Intelligence
ul. Ogrodowa 58, lok. 29
00-876 Warszawa, Poland
Telephone: +48 501 335 073
Email: inbox@polandoc.com
Do not include complete payment-card details, passwords, magic links, recovery codes, authentication secrets, source files, Output Packages, or unnecessary sensitive information in the initial request.