Privacy Policy of FoundIt Service
Version: 1.1
Last updated: 12.07.2026
Effective date: 12.07.2026
§ 1 General Information
1. This Privacy Policy defines the rules for the processing of personal data and the use of technologies related to the operation of the FoundIt service, available at foundit.cc, hereinafter referred to as the "Service".
2. The Policy applies in particular to:
- a) the public website of FoundIt;
- b) User Accounts;
- c) the user dashboard;
- d) pages assigned to Tags;
- e) forms enabling sending messages to the Tag owner;
- f) the contact form;
- g) PWA (Progressive Web Application);
- h) login using OTP codes and Passkeys;
- i) Web Push notifications;
- j) technical data processed in connection with the security and proper functioning of the Service.
3. The Administrator develops the Service taking into account the principles of:
- a) lawfulness of processing;
- b) transparency;
- c) data minimization;
- d) purpose limitation;
- e) storage limitation;
- f) integrity and confidentiality;
- g) accountability.
4. The Administrator's goal is to limit the scope of processed data to the information actually needed for the operation of the Service, ensuring its security, and performing the functions selected by the user.
5. This Privacy Policy does not regulate the rules of using the Service. These rules are specified in a separate Terms of Service.
§ 2 Personal Data Controller
1. The controller of personal data processed in connection with the operation of the Service is:
hereinafter referred to as the "Administrator".
2. The Administrator is a natural person running the FoundIt Service.
3. In all matters related to:
- a) the processing of personal data;
- b) the exercise of rights resulting from data protection regulations;
- c) data security;
- d) questions regarding this Policy
you can contact the Administrator at: contact@foundit.cc.
4. The Administrator has not appointed a data protection officer, unless the obligation to appoint one results from applicable provisions of law.
§ 3 Definitions
For the purposes of this Policy, the following meanings of terms are adopted:
- 1. Administrator – the person indicated in § 2 of the Policy.
- 2. Service – the FoundIt website along with associated functionalities, user dashboard, Tag pages, forms, PWA, and notification mechanisms.
- 3. User – a person using the Service, in particular a person holding an Account.
- 4. Finder – a person visiting the Tag page and using the function enabling the transmission of a message to the Tag owner, without the need to hold an Account.
- 5. Account – a user's individual account in the Service.
- 6. Tag – a unique identifier assigned in the Service to a specific item or another application permitted by the Service's functionality.
- 7. Tag Owner – a user to whose Account a specific Tag is assigned.
- 8. Message – content transmitted via the form available on the Tag page.
- 9. Passkey – an authentication method based on the WebAuthn standard and a cryptographic credential managed using the user's device or a related service.
- 10. OTP – a one-time authentication code sent by email.
- 11. Push Notification – a functional notification delivered using the Web Push standard after the user has previously enabled this function.
- 12. Policy – this Privacy Policy.
- 13. Conversation – a time-limited exchange of encrypted Messages between the Finder and the Tag Owner, relayed by FoundIt.
- 14. Private Link – a link containing a high-entropy secret which can be used to establish access to one specific Conversation without creating an Account.
§ 4 How FoundIt works from a data flow perspective
- 1. FoundIt allows the user to create an Account and assign Tags to it.
- 2. A person who opens a Tag page can – if the Tag owner has not disabled the relevant function – send a first Message. This Message is forwarded regardless of whether the Finder provides or confirms an email address.
- 3. The Message starts a Conversation, is forwarded to the Tag Owner by email, and is stored in encrypted form for a limited time in the Service.
-
4. The Finder may additionally, voluntarily:
- a) attach a photo;
- b) share their location to generate a map link;
- c) provide an email address if they want to allow the Tag Owner to reply through FoundIt.
- 5. If an email address is provided, FoundIt sends a one-time verification link. Only a confirmed address enables the Tag Owner to reply.
- 6. FoundIt relays further Messages. Neither party is shown the other party's email address, and the Finder does not need an Account.
- 7. A reply notification sent to the Finder contains the latest reply and a Private Link to the full Conversation. A person who obtains that link may gain access to the Conversation.
- 8. The Administrator is not a party to the arrangements between the owner of the item and the Finder and does not participate in the physical receipt, storage, or handover of items.
§ 5 Categories of individuals whose data may be processed
The Administrator may process data regarding:
- 1. persons holding an Account;
- 2. persons creating an Account or logging into it;
- 3. Finders using the form on the Tag page;
- 4. persons sending a message through the contact form;
- 5. persons reporting abuse or violations;
- 6. persons using Push Notifications;
- 7. persons whose data has been voluntarily placed in the content of a Message or correspondence directed to the Administrator;
- 8. persons using the Service whose technical data is processed in connection with security, session management, and the proper operation of the system.
§ 6 What data we process
1. Account and authentication
In connection with the creation and maintenance of the Account, the Administrator may process:
- a) email address;
- b) internal Account identifier;
- c) blind index of the email address used to search for the Account;
- d) preferred language of the Service;
- e) date of creation and update of the Account;
- f) information about the acceptance of the applicable Terms of Service;
- g) technical information related to the session;
- h) data necessary for OTP login;
- i) cryptographic credential data of the Passkey, if the user uses this login method.
2. Passkeys
In the case of using Passkeys, the Administrator processes the technical data of the credential necessary to verify the login. The Administrator does not receive or store:
- a) fingerprint;
- b) face scan;
- c) device PIN code;
- d) other biometric data used locally by the user's device to approve the operation.
3. Tags
In connection with the use of Tags, the Administrator may process:
- a) Tag identifier;
- b) Tag code;
- c) association of the Tag with the Account;
- d) name given to the Tag;
- e) type or series of the Tag;
- f) Tag status;
- g) public message of the owner;
- h) redirection configuration;
- i) setting to enable or disable the contact form;
- j) scan counter;
- k) visual layout and design configuration of the Tag.
4. Finders' Conversations and Messages
In connection with Conversations and the transmission of Messages, the Administrator may process:
- a) content of the Message;
- b) identifier of the Tag to which the Message relates;
- c) sender type and the dates on which Messages were created and read;
- d) Conversation status, last activity date, and deletion dates;
- e) the Finder's optional email address, stored in encrypted form, and its verification status;
- f) HMAC values of verification and access tokens; plain tokens are not stored;
- g) optional photo – only temporarily;
- h) optional location – exclusively in the process of preparing a map link.
5. Contact form
In connection with the contact form, the Administrator processes:
- a) sender's email address;
- b) content of the message;
- c) technical data necessary to protect the form against automated abuse;
- d) information related to further correspondence.
6. Web Push Notifications
In the case of enabling Push Notifications, the Administrator may process:
- a) subscription endpoint;
- b) public technical key of the subscription;
- c) subscription authentication token;
- d) association of the subscription with the Account.
7. Technical data and security
In connection with the use of the Service, the following may be processed in particular:
- a) IP address;
- b) time of request;
- c) type of request;
- d) error information;
- e) data necessary for session operation;
- f) technical information of the browser and device sent as standard during internet communication;
- g) data used by mechanisms limiting the frequency of requests (rate limiting);
- h) data needed to detect errors, abuse, and unauthorized access attempts.
These data are not used by the Administrator to create marketing profiles of users.
§ 7 What data FoundIt does not require
-
1. To set up a basic Account, FoundIt does not require providing:
- a) first name;
- b) surname;
- c) phone number;
- d) residential address;
- e) PESEL number;
- f) identity document number;
- g) date of birth;
- h) gender;
- i) profile picture;
- j) classic password for the Account.
- 2. FoundIt does not run a user movement history tracking system.
- 3. FoundIt does not create an archive of photos sent by Finders.
- 4. FoundIt does not use the content of Messages or photos for advertising purposes.
- 5. FoundIt does not conduct advertising profiling of users.
- 6. FoundIt does not use personal data to make decisions based solely on automated processing that would produce legal effects concerning users or similarly significantly affect them.
§ 8 Purposes and legal bases for processing
1. Creation and maintenance of the Account
Data are processed for the purpose of:
- a) creating the Account;
- b) providing access to the dashboard;
- c) managing Tags;
- d) providing Service functions requiring authentication.
Legal basis: the necessity of processing for the performance of a contract for the provision of services by electronic means or to take steps at the request of the data subject prior to entering into a contract.
2. OTP Login
The email address and data related to the OTP code are processed in order to authenticate the user and protect access to the Account.
Legal basis: performance of a contract for the provision of services and the legally justified interest of the Administrator consisting in ensuring the security of Accounts and the Service.
3. Passkey Login
Cryptographic credential data are processed to enable the user to use the selected authentication method.
Legal basis: performance of a contract for the provision of services.
4. Handling Conversations and Messages
The content of Messages, the Finder's optional encrypted email address, and data related to the Conversation are processed for the purpose of:
- a) forwarding the first Message to the Tag Owner;
- b) verifying the Finder's email address at their request;
- c) enabling the Tag Owner and the Finder to exchange further Messages through FoundIt without disclosing their email addresses;
- d) displaying the encrypted Conversation to authorized parties;
- e) notifying the parties about new Messages and enforcing retention and security rules.
Legal basis (Owner): performance of a contract for the provision of services.
Legal basis (Finder): action taken at their express request and the legally justified interest of the Administrator and the Tag owner consisting in enabling voluntary contact in connection with a found item or another permitted way of using the Tag.
5. Photo
The photo is processed only when the Finder voluntarily decides to send it, for the purpose of its technical preparation and forwarding to the Tag owner. The photo is not used for unrelated purposes.
6. Location
Location coordinates are processed only in the case of voluntary use of this function, for the purpose of generating a link to the map and forwarding it to the Tag owner.
7. Contact form
Data transmitted via the contact form are processed for the purpose of receiving the message, providing a reply, conducting further correspondence, and establishing, pursuing, or defending claims if necessary.
Legal basis: legally justified interest of the Administrator consisting in conducting communication, handling reports, and protecting the Administrator's rights. If the correspondence serves to conclude or perform a contract, the basis may also be the necessity of processing to take steps at the request of the data subject or to perform a contract.
8. Security and abuse prevention
Technical data, including IP address, may be processed for the purpose of protecting Accounts, protecting forms, preventing spam and automated abuse, limiting attempts of multiple execution of specific operations, diagnosing errors, ensuring the integrity and availability of the Service, and establishing, pursuing, or defending claims.
Legal basis: legally justified interest of the Administrator consisting in ensuring the security of the Service and its users.
9. Web Push Notifications
Subscription data are processed in order to deliver Push Notifications after the user has voluntarily enabled this function. The user may disable Push Notifications and remove the permission in the settings of their browser or device.
10. Legal obligations
Data may be processed to perform a legal obligation incumbent on the Administrator, if such an obligation results from applicable regulations.
§ 9 Is providing data mandatory?
- 1. Providing an email address is necessary to create and use an Account in the authentication model used by the Service.
- 2. Providing the content of the Message is necessary to use the contact form on the Tag page.
- 3. Providing an email address by the Finder is voluntary. The first Message is forwarded without it, but the Tag Owner cannot reply through FoundIt until the address has been provided and confirmed.
- 4. Adding a photo is voluntary.
- 5. Sharing the location is voluntary.
- 6. Enabling Passkey is voluntary.
- 7. Enabling Push Notifications is voluntary.
- 8. Providing data in the general contact form is voluntary, however, the lack of an email address may prevent providing an answer.
§ 10 Message lifecycle
-
1. A first Message sent by the Finder is:
- a) accepted by the Service;
- b) saved in the database;
- c) stored in encrypted form;
- d) forwarded to the Tag owner by email;
- e) made available to the Tag owner in their dashboard;
- f) associated with a time-limited Conversation;
- g) automatically deleted from the active database after the retention period.
- 2. If the Finder provides an email address, it is stored in encrypted form and a one-time verification link is sent. The first Message is not held back while verification is pending.
- 3. After verification, the parties may exchange further encrypted Messages. Each Finder access grant is established through a Private Link and is limited to one specific Conversation. A session may hold up to five independently obtained grants.
- 4. A Conversation expires after 30 days without activity and no later than 60 days after it was created. A closed Conversation is scheduled for deletion after 7 days.
- 5. Deleting a Conversation removes its Messages, the Finder's encrypted email address, token HMAC values, and related metadata from the active database.
- 6. Limited copies of data may for an additional time remain in technical backups if they are created by the infrastructure provider. Such copies serve to ensure business continuity and disaster recovery of the system after a failure, and not for the day-to-day use of deleted data.
§ 11 Photos
- 1. Adding a photo to the Message is voluntary.
- 2. The photo is processed exclusively to prepare and forward it to the Tag owner.
-
3. In the course of the process, the photo is technically processed, in particular, it may be:
- a) verified for acceptable format and size;
- b) reduced in size;
- c) re-encoded;
- d) stripped of metadata, including EXIF data.
- 4. After preparation, the photo is attached to the email sent to the Tag owner.
- 5. The Service does not save the photo as a permanent element of the Message record.
- 6. The temporary file is deleted after the completion of the sending process. The application also performs a deletion of the temporary file in the event of a handled sending process error.
- 7. The Administrator does not run an archive of photos sent by Finders.
-
8. The Administrator does not use transmitted photos for:
- a) marketing;
- b) advertising;
- c) profiling;
- d) creating public galleries;
- e) training artificial intelligence models.
- 9. It should be remembered that after successfully transferring the photo as an attachment, it may be located in the email system of the Administrator, the email provider, and the recipient of the message in accordance with the rules of operation of those systems.
§ 12 Location
- 1. Sharing the location by the Finder is voluntary.
- 2. In the case of using this function, the coordinates serve to generate a link leading to the OpenStreetMap map.
- 3. The link is forwarded to the Tag owner in the email message.
- 4. In the current flow of Message handling, the coordinates are not saved as an element of the Message record in the database of the Service.
-
5. The Administrator does not use the location for:
- a) creating a location history;
- b) constant tracking of users;
- c) building behavior profiles;
- d) advertising profiling.
- 6. A link containing coordinates may be retained in the email message received by the Tag owner and in the email systems participating in the delivery of the message.
- 7. Opening a link to OpenStreetMap occurs at the recipient's decision and leads to an external service that applies its own data processing rules.
§ 13 IP Address and Technical Data
- 1. FoundIt does not require the Finder to provide first name or surname. The Finder may voluntarily provide an email address solely to enable mediated replies.
- 2. The Finder's email address is encrypted, is not disclosed to the Tag Owner, and is deleted together with the Conversation.
- 3. This does not mean a complete absence of technical processing of the IP address.
-
4. The IP address may be processed temporarily and technically for the purpose of:
- a) limiting abuse;
- b) applying rate limiting;
- c) ensuring security;
- d) diagnosing errors;
- e) operation of network and server infrastructure;
- f) protecting forms.
- 5. The IP address is not forwarded to the Tag Owner as part of the Message content from the Finder.
- 6. The Administrator does not use IP addresses for behavioral advertising or marketing profiling.
§ 14 Data Retention Periods
The Administrator applies the following retention principles:
1. Account
Account data are stored for the period of its existence. After deleting the Account, the data are deleted, subject to:
- a) legal obligations;
- b) the necessity to establish, pursue, or defend claims;
- c) temporary presence in rotating backups.
2. Email Address
The encrypted email address and the corresponding blind index are stored for the period of the Account's existence, subject to situations provided for by law.
3. Passkey Data
Passkey data are stored until:
- a) deletion of the given Passkey;
- b) deletion of the Account;
- c) another event causing the necessity of deleting the given credential.
4. Conversations and Messages
Conversations and Messages are stored for up to 30 days from the last activity, but no longer than 60 days from creation. Closed Conversations are deleted after 7 days. The Finder's encrypted email address and token HMAC values are removed with the Conversation.
5. Photos
Photos are stored exclusively temporarily for the time needed to process and forward them by email.
6. Location
Coordinates are not permanently stored in the active Message record in the current flow of this function.
7. Web Push
Web Push subscription data are stored until:
- a) user unsubscribe;
- b) deletion of subscription;
- c) detection of its expiration;
- d) deletion of the Account.
8. Contact Form
Correspondence is stored for the time needed to:
- a) handle the case;
- b) conduct necessary correspondence;
- c) establish, pursue, or defend claims.
Unhelpful messages, spam, or unnecessary content may be deleted earlier.
9. Logs
Technical and security logs are stored for the period resulting from the security purpose, Service configuration, and hosting infrastructure. The Administrator strives to limit their retention to the period necessary for diagnostics, security, and defense against abuse.
10. Backups
Deleted data may remain in rotating backups for a limited period, if their immediate selective deletion is technically unfeasible or disproportionate. Data from backups are not used for the day-to-day operation of the Service and may be restored exclusively in connection with a failure, incident, or the need to restore system operation.
§ 15 Data Security
- 1. The Administrator applies technical and organizational measures appropriate to the nature of the processed data, the scope of processing, and identified risks.
-
2. In particular, the Service uses or provides for mechanisms including:
- a) encryption of email addresses
The user's email address is stored in the database in encrypted form. - b) blind index of the email address
The Service uses a separate index determined using a cryptographic function, enabling finding the Account without storing the email address as a plain text search field. - c) encryption of Messages
The content of Messages is stored in the database in encrypted form. - d) OTP
The Service enables authentication with a one-time code sent to the user's email address. - e) Passkeys
The user can use cryptographic credentials compatible with WebAuthn. - f) limiting the number of requests
Selected operations are protected by mechanisms limiting the frequency of attempts and queries. - g) anti-bot protection
Selected forms are protected by Cloudflare Turnstile. - h) automatic retention of Messages
Messages are marked with an expiration date and covered by a regular deletion mechanism. - i) minimization of photos
Photos are stored only temporarily and are not saved as a permanent element of the Message. - j) removal of image metadata
The process of reprocessing the photo removes metadata, including EXIF. - k) data limitation in logs
The application applies mechanisms for masking selected categories of data in the context of application logs. - l) security headers
The Service applies browser security mechanisms, including content security policy and other headers limiting selected classes of threats. - m) HMAC protection of Conversation tokens
Verification and access tokens are generated with at least 256 bits of entropy, and only context-separated HMAC values based on a dedicated secret are stored. - n) session-limited Finder access
After a valid Private Link is used, the session identifier is regenerated and a grant limited to that specific Conversation is stored without the plain token. Up to five independently obtained grants may coexist. - o) protection of sensitive pages
Conversation and token pages are not indexed or cached, use a no-referrer policy, and do not load third-party resources.
- a) encryption of email addresses
- 3. No IT system guarantees absolute security. However, the Administrator takes actions adequate to the risk and updates protection measures as the Service develops and threats change.
§ 16 Security on the user side
- 1. Account security also depends on the user's actions.
-
2. In particular, the Administrator recommends:
- a) not sharing OTP codes with other persons;
- b) ignoring requests to share the login code;
- c) securing the device with a PIN code, password, or another available method;
- d) deleting unused Passkeys;
- e) logging out of public or shared devices;
- f) updating the operating system and browser;
- g) not enabling Push Notifications on devices to which unauthorized persons have access;
- h) not forwarding or publishing a Private Link to a Conversation.
- 3. The Administrator should never ask the user to send an OTP code in reply to an email message or via a form.
§ 17 Hosting and Mail Provider
-
1. The Administrator uses the services of:
SEOHOST Sp. z o.o.in the scope of hosting infrastructure and email services.
-
2. In connection with the provision of these services, SEOHOST may process data to the extent necessary for:
- a) maintenance of the Service infrastructure;
- b) database operation;
- c) storage of system files;
- d) performing and maintaining technical backups;
- e) handling email;
- f) ensuring the security and diagnostics of the infrastructure.
- 3. The Administrator uses hosting services on the basis of a contractual relationship and should ensure the proper regulation of data processing entrustment if required by regulations and the scope of services.
§ 18 Cloudflare Turnstile
- 1. The Service uses Cloudflare Turnstile to protect selected forms from automated submissions, spam, and abuse.
- 2. As part of this service, the solution provider may process technical data necessary for risk assessment and request verification.
- 3. The basis for using Turnstile on the part of the Administrator is a legally justified interest consisting in protecting forms, users, and the Service infrastructure.
- 4. Turnstile is not used by the Administrator for marketing profiling of users.
§ 19 OpenStreetMap
- 1. The Service may generate a link to OpenStreetMap based on voluntarily shared coordinates.
- 2. The mere creation of the link does not require sending a query to OpenStreetMap by the FoundIt backend.
- 3. Data may be transferred to the operator of the external service after opening the link by the recipient, in accordance with the rules of operation of the external site.
- 4. The Administrator is not responsible for the privacy policy or processing operations carried out independently by the operator of the external service.
§ 20 Web Push Notifications
- 1. Web Push notifications are functional in nature.
-
2. They may relate in particular to:
- a) scanning a Tag;
- b) receiving a new Message;
- c) other events related to the operation of the Service functions.
- 3. To deliver notifications, it is necessary to process technical subscription data, including the endpoint and keys required by the Web Push standard.
- 4. Delivery of the notification may involve the push infrastructure operator appropriate for the user's browser, operating system, or device.
-
5. The user may disable Push Notifications:
- a) in the Service, if such an option is available;
- b) in the browser settings;
- c) in the operating system settings.
- 6. The Administrator does not use Web Push data for advertising profiling.
§ 21 Cookies and browser technologies
-
1. The Service uses technical solutions required for:
- a) session support;
- b) authentication;
- c) security;
- d) operation of selected PWA functions;
- e) operation of the Service Worker;
- f) handling Push Notifications;
- g) protection against abuse.
- 2. The Service uses a technical session mechanism and the associated cookie.
-
3. The session cookie is used, among other things, to:
- a) maintain the session state;
- b) recognize the logged-in user;
- c) protect the integrity of executed operations;
- d) support functions requiring state remembering between subsequent requests.
-
4. The Service does not use its own cookies for:
- a) behavioral advertising;
- b) tracking the user between independent websites;
- c) creating a marketing profile.
- 5. Service Worker, PWA, and Web Push functions may cause technical data to be saved in the browser in accordance with the standards of these technologies.
- 6. Disabling cookies or other technically necessary mechanisms may cause incorrect operation of login or parts of the Service.
- 7. In the case of introducing in the future analytics, advertising, or other technologies not required for the provision of the service, the Administrator will update this Policy accordingly and apply the consent mechanisms required by law.
§ 22 Recipients of data
Personal data may be transferred or available to the following categories of recipients:
- 1. hosting and server infrastructure providers;
- 2. email providers;
- 3. anti-bot protection service providers;
- 4. Web Push infrastructure providers, if the user enables this function;
- 5. technical service providers supporting the maintenance of the Service, if their participation is necessary;
- 6. legal, accounting, or other professional advisors – exclusively to the extent necessary to protect the Administrator's rights or perform legal obligations;
- 7. public authorities and other authorized entities – if the disclosure of data results from a legal obligation or a properly issued, binding request.
The Administrator does not sell user personal data.
§ 23 Transfer of data outside the European Economic Area
- 1. The Administrator strives to limit data transfers outside the European Economic Area.
-
2. Some infrastructure services, in particular:
- a) anti-bot protection;
- b) Web Push infrastructure;
- c) services of global technology providers
-
3. If a given transfer is subject to the provisions of Chapter V of the GDPR, the Administrator uses an appropriate mechanism legalizing the transfer, such as:
- a) a decision of the European Commission stating an adequate level of protection;
- b) standard contractual clauses;
- c) another mechanism permitted by the GDPR.
- 4. Detailed information regarding a specific transfer may be made available upon request, to the extent required by provisions of law.
§ 24 Rights of the data subject
-
1. Depending on the legal basis and circumstances of processing, the data subject may be entitled to:
- a) the right to access data;
- b) the right to obtain a copy of data;
- c) the right of rectification of data;
- d) the right to supplement data;
- e) the right to delete data;
- f) the right to restrict processing;
- g) the right to data portability;
- h) the right to object;
- i) the right to withdraw consent, when the processing takes place on the basis of consent;
- j) the right to lodge a complaint with the competent supervisory authority.
- 2. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
- 3. The right to data portability applies exclusively in cases provided for by the GDPR.
- 4. The right to object applies in particular to processing based on a legally justified interest, in accordance with the conditions specified in the GDPR.
- 5. In order to exercise the rights, you should contact the Administrator: contact@foundit.cc.
- 6. The Administrator may request information necessary to confirm the identity of the person submitting the request, if this is necessary to protect the data against disclosure to an unauthorized person.
§ 25 Functional possibilities of data management
Regardless of the rights resulting from the GDPR, the user may, within the scope made available by the Service:
- 1. delete the Account;
- 2. delete the saved Passkey;
- 3. disable Push Notifications;
- 4. delete Messages available in their dashboard;
- 5. change selected Account settings;
- 6. manage Tag settings.
The availability of a specific function may depend on the current version of the Service.
§ 26 Account Deletion
- 1. The user may delete the Account using the function made available in the Service.
- 2. Deleting the Account results in the termination of services related to the Account and the loss of access to data and functions associated with it.
- 3. Data associated with the Account are deleted in accordance with the retention rules described in this Policy.
-
4. The Administrator may retain a limited scope of information after deleting the Account if:
- a) required by law;
- b) necessary to establish, pursue, or defend claims;
- c) the data temporarily remains in rotating backups.
- 5. Data located exclusively in backups are not used for the day-to-day operation of the Service.
§ 27 Data of other persons in the Message content
- 1. The User and the Finder should transmit only data actually needed for contact in a specific case.
-
2. You should not place in the Message:
- a) excessive personal data;
- b) identity document numbers;
- c) PESEL numbers;
- d) payment card data;
- e) passwords;
- f) OTP codes;
- g) data of third parties, if providing them is not necessary or compliant with law.
- 3. The Administrator does not encourage the transmission of special categories of personal data.
- 4. If the user voluntarily places such information in the free text of the Message, the Administrator will process it exclusively to the extent resulting from the technical operation of the communication function and legal obligations.
§ 28 Children's data
- 1. The Service is not designed as a service addressed in particular to children.
- 2. The Administrator does not conduct conscious systematic collection of children's data for advertising or profiling purposes.
- 3. If the Administrator obtains reliable information that data have been transmitted in violation of provisions on children's protection, they may take appropriate actions, including restricting processing or deleting the data.
§ 29 Automated decision-making and profiling
- 1. The Administrator does not make decisions concerning users based solely on automated processing, which would produce legal effects concerning them or similarly significantly affect them.
- 2. The Administrator does not conduct advertising profiling within the scope of the Service functions described in this Policy.
- 3. Automated security mechanisms, such as rate limiting or anti-bot assessment, serve to protect the Service and may temporarily limit the execution of a specific technical operation.
§ 30 Complaint to the supervisory authority
- 1. If a person believes that their data is processed in violation of the law, they have the right to lodge a complaint with the competent supervisory authority.
-
2. In Poland, the supervisory authority is:
President of the Personal Data Protection Office
- 3. Using the right to lodge a complaint does not deprive the person of the possibility of contacting the Administrator beforehand to clarify the matter.
- 4. The Administrator encourages direct contact in matters concerning privacy, as it enables quick investigation and clarification of the problem.
§ 31 Data breaches
- 1. The Administrator applies procedures allowing to respond to security incidents.
-
2. In the case of detecting a data breach, the Administrator:
- a) assesses the nature and scale of the event;
- b) takes actions limiting its consequences;
- c) documents the event to the extent required by law;
- d) makes a report to the supervisory authority, if the conditions specified in the applicable regulations are met;
- e) notifies the data subjects, if required by regulations.
§ 32 Changes to the Privacy Policy
-
1. The Administrator may update the Policy, in particular in the case of:
- a) changes in provisions of law;
- b) changes in the Service functions;
- c) changes in the scope or method of data processing;
- d) changes of service providers;
- e) implementation of new technologies;
- f) changes in the Service operating model.
- 2. The current version of the Policy is published in the Service.
-
3. If the change has a significant impact on the way data of users holding an Account are processed, the Administrator may inform them:
- a) by email;
- b) by a message in the Service;
- c) by another appropriate channel.
- 4. A change to the Privacy Policy does not legalize retroactively processing that at the time of its execution did not have a proper legal basis.
§ 33 Contact
In all matters related to privacy, data processing, and the exercise of rights, you can contact the Administrator:
Administrator: [NAME AND SURNAME]
Correspondence address: [CORRESPONDENCE ADDRESS]
E-mail: contact@foundit.cc
§ 34 Final provisions
- 1. The Policy should be read together with the Service Terms of Service, with each of these documents regulating a separate scope of matters.
- 2. In the case of a change in the Service operation, the Administrator assesses whether the change requires updating this Policy.
- 3. The Policy is effective from the date indicated in its header.
- 4. In matters concerning the protection of personal data, the provisions of the GDPR and other relevant provisions of European Union law and Polish law apply.
- 5. The Administrator encourages users to periodically read the current version of the Policy, especially after the implementation of new Service functions.