← Back to SaasLab

Privacy Policy

Last updated: 2 May 2026 · Effective: 2 May 2026
Data Controller: Radosław Myszka operating as SaasLab, with registered place of business in Poland (EU). Contact: kontakt@saaslab.one · saaslab.one

This policy applies to the SaasLab compliance SaaS suite — including products published at cbam.saaslab.pl, nis2.saaslab.pl, aiact.saaslab.pl, adr.saaslab.pl, bdo.saaslab.pl, kobize.saaslab.pl, haccp.saaslab.pl, agri-api.saaslab.pl, and the marketing website saaslab.one.

1. Who we are

SaasLab is a sole-proprietorship business operated by Radosław Myszka (Poland), publishing software-as-a-service compliance tools for European SMEs. We process personal data of customers, prospective customers, website visitors, and users of our SaaS applications.

For the purposes of GDPR (Regulation (EU) 2016/679), we act as Data Controller for account, billing, and marketing data, and as Data Processor for content data customers upload into our SaaS products (e.g. compliance records, fields and treatments, transport data).

2. What data we collect

CategoryExamplesSource
Account dataFull name, email address, company name, NIP/VAT, billing addressProvided by you at signup
Authentication dataGoogle OAuth profile (name, email, avatar URL); session tokensGoogle OAuth flow
Content dataCompliance records, transport logs, field maps, AI inventory entries, etc.Entered by you in the app
Payment dataCard last-4, payment status, invoice records (full card data is held by Stripe/Paddle, not by us)Stripe / Paddle
Technical dataIP address, browser, OS, screen size, page paths, error logsAutomatic on visit
Marketing dataEmail open/click status (if you opted in), survey responsesYour interaction with our emails

Data we do not collect

We process your personal data under one or more of the following legal bases:

4. Processing purposes

  1. Service delivery — operating the SaaS, syncing your data between web and mobile, generating reports and PDFs
  2. Authentication & account security — Google OAuth login, MFA where applicable, session management, fraud detection
  3. Billing & tax — issuing invoices, processing payments via Stripe/Paddle, complying with Polish VAT/CIT obligations
  4. Customer support — responding to emails sent to kontakt@saaslab.one or product-specific addresses
  5. Service communication — transactional emails (welcome, password reset, billing receipts, deadline reminders, system status)
  6. Product improvement — analysing aggregated, pseudonymised usage data to improve features
  7. Direct marketing — periodic product updates and regulatory news to existing customers (you may unsubscribe at any time)

5. Data storage & location

Your data is stored in the European Union — specifically on Microsoft Azure infrastructure in West Europe (Netherlands) and North Europe (Ireland) regions. Microsoft Ireland Operations Limited is a sub-processor and a Data Processing Agreement is in place under Art. 28 GDPR.

Application databases use SQLite hosted on Azure App Service (per-product isolation: cbamreporter.db, nis2compliance.db, etc.). Mobile applications (Agri Field Journal) additionally store data locally on the user's device in a persistent SQLite database.

6. Retention periods

Data categoryRetention period
Active account dataFor the duration of the customer relationship
Content data after account deletion30 days (then permanent deletion)
Invoices & tax records5 years from the end of the tax year (Polish tax law)
Marketing preferencesUntil you unsubscribe or for 3 years of inactivity
System logs (access logs, error logs)90 days
Backup snapshots30 days rolling

7. Third parties & sub-processors

We share personal data only with the following sub-processors, all of which provide adequate safeguards:

Sub-processorPurposeLocationSafeguard
Microsoft Ireland Operations Ltd. (Azure)Application hosting, databases, file storageEU (West Europe / North Europe)DPA + EU SCCs
Google LLC (OAuth)Sign-in only — no data sent beyond OpenID claimsUSAEU SCCs + Adequacy (TADPF)
Stripe Payments Europe Ltd.Payment processing, billingIreland (EU)DPA + EU SCCs
Paddle.com Market LimitedAlternative payment processing (merchant of record)UK (adequacy decision)DPA + Adequacy decision
Cloudflare Inc. (CDN, Web Analytics)DNS, DDoS protection, anonymous web analyticsUSA / global edgeEU SCCs
Google Analytics 4 (G-X3EXYNC2ZD)Anonymised website usage analytics (anonymize_ip enabled)EU primary, USA backupEU SCCs + IP anonymisation
Meta PixelConversion measurement on marketing pages (opt-out via cookie banner)EU/USAEU SCCs + Adequacy (TADPF)
GitHub Inc. (backups)Source code & daily database backupsUSAEU SCCs + private repository

We do not sell or rent personal data to any third party. We do not engage in cross-context behavioural advertising.

8. International transfers

Where personal data is transferred outside the EU/EEA (specifically to USA-based sub-processors above), we rely on:

9. Your rights under GDPR

You have the following rights regarding your personal data:

  1. Right of access (Art. 15) — request a copy of your data
  2. Right to rectification (Art. 16) — correct inaccurate or incomplete data
  3. Right to erasure / "right to be forgotten" (Art. 17) — request deletion subject to legal-retention exceptions
  4. Right to restriction of processing (Art. 18) — pause processing while a dispute is resolved
  5. Right to data portability (Art. 20) — receive your data in a structured, commonly used format (CSV/JSON)
  6. Right to object (Art. 21) — object to processing based on legitimate interest, including direct marketing
  7. Right to withdraw consent (Art. 7(3)) — for any consent-based processing, at any time
  8. Right not to be subject to automated decision-making (Art. 22) — we do not perform any solely-automated decisions with legal or similarly significant effects
  9. Right to lodge a complaint — with the Polish supervisory authority (UODO, uodo.gov.pl) or your local national DPA

To exercise any of these rights, email kontakt@saaslab.one. We respond within 30 days (extendable by 60 days for complex requests, with notification). There is no fee for reasonable requests.

10. Cookies & tracking

The marketing website (saaslab.one) and our SaaS applications use the following cookie categories:

TypePurposeLifetimeConsent required
Strictly necessarySession, CSRF, language preference, cookie banner stateSession — 1 yearNo
FunctionalUI preferences, tutorial dismissal flagsUp to 1 yearNo (legitimate interest)
Analytics (Google Analytics 4 _ga)Aggregated, IP-anonymised usage statistics13 monthsYes (banner)
Marketing (Meta Pixel _fbp)Conversion measurement on landing pages3 monthsYes (banner)
Cloudflare Web AnalyticsCookieless privacy-respecting traffic analyticsNone (cookieless)No

You can manage cookie preferences via the cookie banner shown on first visit, your browser settings, or by contacting us. Withdrawal of analytics/marketing consent does not affect site functionality.

11. Security measures

12. Children

SaasLab products are designed for business use by adults (compliance professionals, business owners, consultants). We do not knowingly collect personal data of children under 16. If you believe a child has provided us with personal data, contact us immediately and we will delete it.

13. Changes to this policy

We may update this policy to reflect changes in legislation, our services, or sub-processors. Material changes will be notified via in-app banner or email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision. Historical versions are available on request.

14. Contact & complaints

For any questions, requests, or complaints regarding this policy or your personal data:

SaasLab (Radosław Myszka)
Email: kontakt@saaslab.one
Website: saaslab.one
Polish version of this policy: saaslab.one/polityka-prywatnosci

You may also lodge a complaint with the Polish data-protection authority:

Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
Website: uodo.gov.pl

If you are based outside Poland, you may instead lodge a complaint with your national supervisory authority. A list is maintained by the European Data Protection Board at edpb.europa.eu.