We care about your data as much as we care about your projects. Below we explain what personal data veedeck processes, for what purpose, on what legal basis, and what rights you are entitled to.
To be finalised. The controller's details have been filled in. The remaining fields in brackets [ ] (names of service providers) must be completed before publication. Consultation with a lawyer specialising in data protection is recommended.
This Privacy Policy sets out the rules for processing the personal data of Users of the veedeck platform, available at veedeck.com, including the data of people using the contact forms on the site.
The Policy was developed based on:
The rules for using cookie files are described in a separate Cookie Policy.
The controller of personal data is Daniel Rychlik, a sole trader operating under the business name Daniel Rychlik Management, with a permanent place of business at ul. Młynarska 2A/17, 51-116 Wrocław, Poland, NIP: 8943229341, REGON: 527749980, hereinafter referred to as the "Controller". Due to the nature and scale of the business, the Controller has not appointed a Data Protection Officer.
For matters concerning the processing of personal data, including the exercise of rights, you may contact the Controller at the e-mail address contact@veedeck.com.
The Policy applies in particular to:
Payments are handled by Stripe (Stripe Payments Europe, Limited, using Stripe, Inc. infrastructure), including the BLIK and Przelewy24 methods. The Controller does not store full payment-card numbers – these are processed exclusively by the payment operator.
Providing the data is voluntary but necessary to receive a reply. Data from the form is not used for other purposes (e.g. marketing) without separate consent.
Consent can be withdrawn at any time, e.g. via a link in the message content or by contacting the Controller.
The platform uses Google Analytics 4, provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). The tool is loaded only after the User gives consent in the cookie banner (using the Google Consent Mode v2 mechanism). Google processes data including the pages visited, referral source, approximate location (with IP address anonymisation), and device and browser type. Data in Google Analytics is stored for the period set by the Controller (up to 14 months), after which it is automatically deleted or aggregated. For details on cookie files, see the Cookie Policy.
Under all plans (Solo, Studio, Office) the platform provides the Veepick extension - a Chrome browser extension used to retrieve product data (name, price, photos, descriptions) from supplier/store websites indicated by the User, for use in projects and client presentations.
The extension processes data about products, not the personal data of third parties - except where the User themselves enters such data into the project content. In that case, the User is responsible as the controller of that data.
Detailed information on the scope of data read and processed by the Veepick extension (including data stored locally in the browser, the product page URL, and how the image picker works) can be found in the dedicated Veepick Privacy Policy.
Personal data may be shared with the following categories of recipients:
A data-processing agreement (Art. 28 GDPR) is concluded with every entity that processes data on behalf of the Controller.
Due to the use of providers based, or with technical infrastructure, outside the EEA (e.g. Stripe, Inc. - USA, Google LLC - USA as part of the Google Analytics service, hosting/CDN providers), data may be transferred to third countries. Such transfers use the safeguard mechanisms provided for under the GDPR, in particular the Standard Contractual Clauses approved by the European Commission and, in the case of Google LLC, the Data Privacy Framework (EU-US DPF).
| Data category | Retention period |
|---|---|
| Account data and service usage history | for the duration of the contract + the statute-of-limitations period for claims (generally up to 6 years after the end of the relationship) |
| Billing / accounting data | 5 years from the end of the tax year in which the document was issued |
| Contact-form data | until the correspondence is concluded + the statute-of-limitations period for claims |
| Data processed on the basis of marketing consent | until consent is withdrawn |
Everyone whose data we process has the right to:
The Controller applies appropriate technical and organisational measures to ensure data security, including encrypted connections (SSL/TLS), access control to systems, and regular reviews of infrastructure security.
The Controller reserves the right to make changes to the Policy, in particular in connection with changes in the law or in the platform's functionality. The current version is published on veedeck.com along with the date of the last update.
For matters related to the protection of personal data: