Privacy Policy

Last updated: June 26, 2026

1. Data Controller

The controller of your personal data is:

EHUB STUDIO

ul. Idzikowskiego 44/9, 54-129 Wrocław, Poland

NIP (Tax ID): 8943202520

REGON: 524163417

PKD (Business Activity Codes): 62.01.Z, 73.11.Z, 47.91.Z

Email (legal matters and data protection): legal@ehub.studio

Email (technical support): support@ehub.studio

2. Scope of Personal Data Collected

As part of providing the Kiero OMS platform services, we process the following categories of personal data:

  • Identification and registration data: first name, last name, email address, encrypted password (bcrypt), user identifier
  • Business data: organization name, tax ID (NIP), REGON, KRS, registered address, legal form of business
  • Contact data: phone number, correspondence address, contact persons
  • Technical data: IP address, browser and operating system information, User Agent, session timestamps, cookies and local browser storage
  • Transactional and operational data: order history, customer data, products, stock levels, documents (invoices, shipping documents), shipping labels – entered by the User while using the platform
  • Payment data: transaction history, subscription plan, invoice history – payment card data is processed exclusively by PayU S.A. and is not stored by Kiero OMS

3. Purpose and Legal Basis for Processing

We process personal data on the following legal bases and for the following purposes:

Performance of a contract (Art. 6(1)(b) GDPR)

Processing necessary for the performance of the Kiero OMS service agreement – account registration, authorization, access to features, issuing and delivering invoices, payment processing via PayU, providing technical support

Consent of the data subject (Art. 6(1)(a) GDPR)

Marketing communications, newsletters, notifications about new features and offers – solely on the basis of voluntary, revocable consent given by the User. Consent may be withdrawn at any time without affecting the lawfulness of processing based on consent before withdrawal

Legal obligation (Art. 6(1)(c) GDPR)

Issuing and archiving VAT invoices and accounting documentation (Accounting Act – 5 years), reporting to tax and fiscal authorities, fulfilling obligations arising from AML/KYC regulations

Legitimate interests of the controller (Art. 6(1)(f) GDPR)

Ensuring system security and preventing abuse, analyzing security logs and audits, pursuing or defending against legal claims, improving platform functionality based on anonymized analytical data

4. Data Retention Periods

  • Account and user profile data: for the entire duration of the agreement and 30 days after account deletion (retention period allowing possible recovery); then permanently deleted
  • Accounting documents (VAT invoices, corrections): 5 years from the end of the tax year, in accordance with the Accounting Act and Tax Ordinance
  • Marketing data (consents, newsletter subscriptions): until the User withdraws consent or deletes their account
  • System logs, event logs, and security records: 90 days, then automatically deleted
  • Database backups: automatically created every 24 hours, stored for 30 days, then permanently deleted

After account deletion, all operational data (orders, products, customers) is permanently and irreversibly removed from Kiero OMS servers within 30 days, except for data whose retention is required by law.

5. Sharing and Entrusting Personal Data

Personal data may be shared or entrusted only to the following categories of recipients, based on appropriate data processing agreements:

  • Infrastructure and hosting: Supabase Inc. (PostgreSQL database, file storage – servers in EU region), Cloudflare Inc. (CDN, DDoS protection, DNS management) – data processed in accordance with EU Standard Contractual Clauses
  • Payment operator: PayU S.A., headquartered in Poznań, Poland (KRS 0000274399) – exclusively transaction data necessary for payment processing; payment card data is processed directly by PayU in a PCI-DSS certified environment
  • Analytics and monitoring services: tools for monitoring system performance and security (data anonymized or pseudonymized); email service providers for transactional communication
  • Public and judicial authorities: Tax Office, ZUS (Social Insurance), law enforcement – exclusively on the basis of applicable law, upon written request from an authorized body

All processors and sub-processors are bound by data processing agreements to implement appropriate technical and organizational measures to protect data in accordance with GDPR. We do not sell personal data to any third parties for commercial purposes.

6. Transfer of Data Outside the European Economic Area (EEA)

Some of our infrastructure providers (Cloudflare) may process data in countries outside the European Economic Area. In each such case, we apply appropriate safeguards guaranteeing an adequate level of data protection, in particular: Standard Contractual Clauses (SCC) approved by the European Commission (Decision 2021/914/EU), adequacy decisions issued by the European Commission. Supabase – our database provider – processes data in the EU region (Frankfurt, eu-central-1).

7. Your Data Protection Rights

Under GDPR, you have the following rights, which you may exercise by contacting us at legal@ehub.studio:

  • Right of access (Art. 15 GDPR): right to obtain confirmation of whether we process your personal data and to receive a copy of that data along with information about the purposes and legal bases of processing
  • Right to rectification (Art. 16 GDPR): right to request immediate rectification of inaccurate or completion of incomplete personal data
  • Right to erasure / 'right to be forgotten' (Art. 17 GDPR): right to request deletion of personal data in cases specified in GDPR; this does not cover data whose retention is required by law
  • Right to restriction of processing (Art. 18 GDPR): right to request restriction of processing when the accuracy of data is contested, there is no legal basis, or you have objected to processing
  • Right to data portability (Art. 20 GDPR): right to receive your data in a structured, commonly used format (JSON/CSV) and to transmit it to another controller; export is available directly from the account panel
  • Right to object (Art. 21 GDPR): right to object to processing based on legitimate interests of the controller (Art. 6(1)(f) GDPR), in particular to processing for direct marketing purposes
  • Right to withdraw consent: right to withdraw marketing consent at any time without affecting the lawfulness of processing based on consent before withdrawal
  • Right to lodge a complaint: right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) or another competent supervisory authority in an EU member state

To exercise the above rights, please contact us: legal@ehub.studio

8. Data Security – Technical and Organizational Measures

We apply multi-layered security measures in accordance with Art. 32 GDPR and industry standards:

  • Transmission encryption: TLS 1.2/1.3 protocol (HTTPS) for all connections between the browser and server; SSL/TLS certificates renewed automatically
  • Data-at-rest encryption: PostgreSQL database (Supabase) with AES-256 disk-level encryption; sensitive fields (API tokens, integration keys) additionally encrypted at the application level
  • Access control: Row Level Security (RLS) mechanism in the database ensuring data isolation between organizations; Role-Based Access Control (RBAC); two-factor authentication (2FA) available for user accounts
  • Backups and business continuity: automatic database backups every 24 hours; data replication; backup retention for 30 days; disaster recovery plan (Recovery Time Objective < 4 hours)
  • Monitoring and threat detection: security event log recording; monitoring of anomalies and unauthorized access attempts; real-time security alerts; regular security reviews
  • Organizational policies: Principle of Least Privilege for production data access; vulnerability management and update policy; data breach notification procedure (UODO notification within 72 hours of discovery)

9. Cookies and Tracking Technologies

The Kiero OMS platform uses cookies and similar local storage technologies. Strictly necessary cookies (user session, authentication, language and theme preferences) are required for the proper functioning of the service and do not require consent. Analytical cookies (anonymous data about how the platform is used, performance) may only be set after the User's consent. You can manage cookie preferences in the account settings or through your browser settings. Detailed information about the cookies used, their retention periods, and third parties with access to them can be found in the Cookies Policy available in the settings panel.

10. Changes to this Privacy Policy

This Privacy Policy may be updated in connection with changes in legislation, supervisory authority guidelines, or the development of Kiero OMS services. Users will be notified of any significant changes by email to the address associated with their account at least 14 days before the changes take effect. The current version of the Privacy Policy is always available at kiero-oms.pl/en/privacy. The date of the last update can be found at the top of this document.

11. Contact for Data Protection Matters

For matters relating to personal data protection, exercising data subject rights, and any questions regarding this Privacy Policy, please contact us:

Email: legal@ehub.studio

Correspondence Address:

EHUB STUDIO

ul. Idzikowskiego 44/9, 54-129 Wrocław, Poland