Privacy Policy
What data we collect, why, and how long we keep it.
This policy explains how we process the personal data of visitors to the Dock website, individuals contacting us, using the client portal, and participating in our partner programme.
1. Data Controller and Contact Details
The data controller is DOCK SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office in Gdańsk, ul. Franciszka Rakoczego 9/73, 80-288 Gdańsk, Poland, entered into the Register of Entrepreneurs under KRS number 0001105135, NIP 9571173402, REGON 528630778, hereinafter referred to as "Dock" or "we".
For matters regarding personal data protection and exercising your rights, you can reach us at contact@dock.eu or by mail to our registered address.
2. Scope of this Policy
This policy covers data processing relating to:
- using the dock.eu website;
- forms, quote requests, and correspondence;
- registration, logging in, and using the portal;
- handling projects, tasks, tickets, and logged time;
- messaging, as well as sharing documents and attachments;
- preparing proposals, concluding contracts, and billing;
- the partner programme, referrals, and the discount wallet;
- security, integrations, and AI-assisted features;
- the use of cookies and similar technologies.
Standalone Dock products and services may have their own privacy policies or additional notices regarding their specific features.
3. What Data We Process
The scope of data depends on how you use our services. Not every individual provides us with all the details listed below.
- Contact and identification details: full name, email address, phone number, organisation name, job title, representative details, and proof of authority.
- Organisation and billing details: registered address, VAT/tax identification number (NIP), registration data, and information necessary to conclude a contract, issue invoices, establish payment terms, and settle accounts.
- Account data: user ID, organisation link, role, permissions, account status, settings, and authentication credentials.
- Collaboration data: content of inquiries, proposals, and contracts; projects, tasks, comments, support tickets, messages, attachments, entry authors, logged working time, and audit logs of key actions.
- Partner programme data: partner and submitter details, referred contact and organisation data, description of requirements, referral status, reward eligibility details, granted discounts, wallet transactions, and programme terms acceptance.
- Technical data: IP address, browser and device details, session identifiers, login timestamps, security events, error logs, and service usage metrics.
- Privacy choices: selected cookie categories and records required to honour consents granted, withdrawals, or objections.
Please do not provide sensitive data, such as health information, nor passwords, access keys, or other credentials, unless strictly necessary and an appropriate, secure channel has been agreed upon.
4. Sources of Data
We collect data directly from you, from the organisation you represent, from the person inviting you to the portal, or from the partner who submitted a referral.
We may also receive details from integrations enabled during our collaboration, such as ticketing systems or identity providers. Business data may be verified against public registers and systems, such as KRS, CEIDG, or VIES. Technical data is generated automatically when you use our service.
If we received your data from a third party, we will provide the required information on processing, including the source and data categories. We do this within the timeframe required by the GDPR — generally within a month at the latest, or at the time of first contact if we reach out earlier. If the data is disclosed to another recipient, we adhere to the deadlines applicable to such disclosure.
5. Purposes and Legal Bases for Processing
Contact and Preparing Collaboration
We process data to respond to inquiries, evaluate needs, and prepare proposals. If you act as a party to a prospective contract, the legal basis is Art. 6(1)(b) GDPR. For organisation representatives, the legal basis is Art. 6(1)(f) GDPR — our legitimate interest in handling correspondence and maintaining business relationships.
Accounts, the Portal, and Service Delivery
We process data to maintain accounts, manage access, deliver projects, handle support tickets, communicate, share files, and document delivered work. The legal basis is performance of a contract pursuant to Art. 6(1)(b) GDPR where you are a party, or Art. 6(1)(f) GDPR when you act on behalf of an organisation. In the latter case, our legitimate interest is the effective management and delivery of the engagement.
Partner Programme
We use data to process referrals, verify eligibility requirements, determine reward entitlements, and manage the discount wallet. The legal basis is Art. 6(1)(b) GDPR for partners who are natural persons, or Art. 6(1)(f) GDPR for organisation representatives and managing referred contacts.
Legal Obligations and Financial Accounting
Data required to maintain accounting records, comply with tax obligations, and meet other statutory requirements is processed pursuant to Art. 6(1)(c) GDPR, in conjunction with relevant legislation.
Security and Legal Defence
We process data to manage access controls, detect misuse, investigate incidents, handle complaints, and establish, pursue, or defend legal claims. The legal basis is Art. 6(1)(b), (c), or (f) GDPR, respectively. Our legitimate interest is the protection of our users, information, systems, and Dock's rights.
Marketing, Analytics, and Personalisation
Where you use optional features based on consent, we process data pursuant to Art. 6(1)(a) GDPR. Marketing of our own services may also be based on our legitimate interest, where permitted by circumstances and applicable law.
Regardless of the legal basis under the GDPR, using email or telephone for commercial communications and placing optional technologies on your device are subject to specific telecommunications and electronic privacy regulations. Accepting terms of service or opening an account does not substitute for this required consent.
6. Data of Referred Contacts
Under our partner programme, we may receive your full name, business email address or phone number, organisation details, and project requirements. We use this information to assess the referral and establish legitimate business contact.
The referral of your details by a partner does not constitute consent to receive newsletters, telemarketing, or unsolicited promotional communication. A partner cannot grant such consent on your behalf simply by submitting your email address or phone number.
The partner receives information necessary to track their referral and review their reward. They do not gain access to the referred organisation's account, correspondence, project documentation, or full billing records.
The lifetime validity of a granted discount does not imply indefinite retention of all personal data belonging to the referred individual. We restrict retained details to what is strictly necessary to verify entitlements, billing records, and the defence of legal claims.
7. Data Access in the Portal and Integrations
Access to organisation data depends on user roles, permissions, and involvement in specific projects, issues, or conversations. Organisation administrators can manage access rights for their users. The portal is a professional collaboration tool.
When logging in via third-party providers or corporate SSO, we receive the details necessary to identify the user, such as an identifier and email address. We never receive passwords stored with your identity provider.
Integrations with third-party systems may synchronise data necessary for operation, such as tickets, comments, author details, and logged hours. The scope depends on the active feature and agreed collaboration workflows.
8. Data Recipients
Where strictly necessary, data may be disclosed to:
- authorised Dock personnel and sub-contractors involved in delivering services;
- providers of hosting, cloud storage, backup solutions, and network infrastructure;
- providers of email delivery and communication services;
- providers of collaboration software, project management tools, authentication, and digital signatures;
- providers of active analytics, marketing tools, and form security solutions;
- AI tool providers, strictly within the scope of features used;
- accounting, billing, and legal advisory partners;
- authorised members of your organisation and participants in a specific case;
- public authorities and other bodies entitled to receive data by law.
Vendors processing personal data on our behalf must act solely within the scope of their assigned processing activities and under appropriate data protection agreements. Certain recipients, such as public authorities or service providers you engage independently, act as independent controllers.
You can request details about the specific recipients processing your data by contacting us.
9. International Data Transfers (Outside the EEA)
Engaging international service providers may involve transferring data outside the European Economic Area (EEA). This also applies to remote access granted to data hosted on servers within Europe.
Any such transfer requires a valid GDPR mechanism, such as an adequacy decision by the European Commission or appropriate safeguards, notably Standard Contractual Clauses (SCCs), accompanied by transfer impact assessments and supplementary protective measures where necessary.
You may request information on whether your data is transferred outside the EEA, the recipients, the legal safeguards relied upon, and how to obtain a copy of relevant documentation.
10. Data Retention Periods
Retention periods are defined individually for each purpose, taking into account data scope, contract duration, statutory duties, and applicable limitation periods.
- Inquiries and correspondence: for the duration of the matter and follow-up discussions, and thereafter only as necessary to comply with legal obligations or protect against specific legal claims.
- Account and permissions: for the lifespan of the account, and following its closure only to the extent necessary for billing, security, and statutory obligations.
- Collaboration documentation: for the duration of the agreement, fulfilling warranty obligations and handling claims, and thereafter throughout the applicable limitation period, taking interruptions or suspensions into account.
- Accounting and tax records: for the duration required by applicable statutory requirements for each respective category of documents.
- Wallet and rewards: as long as necessary to prove entitlements and settle balances, and subsequently to the extent required by law or needed for defending legal claims.
- Consent-based data: until consent is withdrawn or the processing purpose expires. Evidence of consent and its withdrawal may be retained to demonstrate regulatory compliance.
- Objections and opt-outs: the minimal details necessary to respect your opt-out preferences are retained to prevent unwanted contact in the future.
- Logs and security data: for the time needed to detect and investigate incidents; details concerning specific incidents are kept throughout the resolution process and relevant claim periods.
- Backups: for the lifecycle of backup retention and rotation. Prior deletion requests are observed and honoured during any data restoration.
Closing an account does not automatically delete invoices, contracts, or other records we are legally mandated to retain. Nor does it grant us the right to retain full account histories without limit. Once legal grounds expire, data is securely erased or irreversibly anonymised.
11. Cookies and Tracking Technologies
Our service uses essential session mechanisms and security safeguards to ensure the website and portal function properly. We may also deploy optional preference, analytics, and marketing technologies, depending on active features and your consent settings.
- Strictly Necessary: session maintenance, authentication, form security, and storing privacy preferences.
- Preferences: enhanced usability and personalisation settings.
- Analytics: measuring site usage and evaluating performance.
- Marketing: measuring campaign effectiveness and tailoring advertising.
The dock_consent cookie stores your chosen categories and preference version for up to 365 days. This record can be cleared at any time in your browser settings. Updates to our consent configuration may require renewing your choice.
Deploying technologies outside the statutory exemption for strictly necessary functionality requires prior consent. Simply browsing the website, signing up, or accepting terms of service does not constitute consent.
You can manage your choices via the cookie banner, rejecting optional categories or accepting specific ones. Settings can be updated at any time using the cookie management tool available on the site.
You can also delete and block cookies via your browser. Blocking essential cookies may prevent you from logging in or maintaining a session. Deleting cookies does not automatically remove data already saved on the server.
The absence of cookies does not imply no data processing occurs: connecting to a provider's server inherently reveals IP addresses and technical headers. Such operations also require an appropriate legal basis.
12. Automation and Artificial Intelligence
The portal uses automation rules for routine operational tasks, such as triggering notifications, dispatching tasks, and computing reward estimates under partner programme terms.
AI-assisted tools may support drafting proposals, preparing contract and task copy, translating content, and document parsing. When using these features, prompts, inputs, attachments, and the contextual data required to execute the operation may be transmitted to the tool provider. This material may include personal data.
The legal basis for processing matches the purpose for which the material is processed. Utilising AI tools does not establish an independent legal basis or permit open-ended data usage. Where we process data on behalf of a client, we operate strictly under documented instructions and applicable Data Processing Agreements (DPAs).
AI-generated outputs require human review. Generative drafting features do not make automated, legally binding decisions regarding entering into contracts or conferring rights. Regarding reward computations or automated operations, you may request human review and clarification from Dock.
Before submitting confidential information or third-party personal data into AI features, ensure it falls within the agreed scope of our engagement. For information regarding data processing within specific features, please contact us at contact@dock.eu.
13. Data Processed on Behalf of Clients
In the course of delivering services, we may process personal data controlled by our clients, such as users of their websites, online shops, or web applications. In such cases, we act as a data processor, strictly within the boundaries of the agreed Data Processing Agreement.
This policy does not replace the privacy notices that clients must provide to their data subjects. If we receive a data subject request concerning client-controlled data, we will help direct you to the appropriate data controller.
14. Your Rights
Subject to conditions set out in the GDPR, you have the right to:
- access your data and receive a copy;
- rectify inaccurate data and complete incomplete records;
- request erasure ("right to be forgotten") where applicable;
- restrict processing;
- data portability, where statutory criteria are met;
- object to processing based on legitimate interests;
- withdraw consent at any time;
- lodge a complaint with a supervisory authority.
You can object to direct marketing at any time, free of charge and without stating grounds. This includes profiling associated with such marketing. For other purposes based on legitimate interests, an objection must relate to your particular situation.
Withdrawing consent does not affect the lawfulness of processing conducted prior to its withdrawal. Privacy rights are not absolute — for example, mandatory tax retention rules may prevent immediate data erasure. In such cases, we will clarify the legal basis and scope of ongoing retention.
You can exercise your rights by emailing contact@dock.eu. We respond within one month of receipt as a standard. Should legal grounds permit an extension, we will inform you of the delay and state the reasons.
Where reasonable doubts arise, we may request necessary details to confirm your identity, keeping such requests to a strict minimum.
You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO). Guidance is available at uodo.gov.pl. You may also lodge a complaint with another competent supervisory authority within the EU under the GDPR. Prior contact with Dock is not a prerequisite to submitting a complaint.
15. Voluntary Nature of Data Submission
Providing personal data is generally voluntary; however, certain details are required to respond to inquiries, maintain an account, perform contracts, or settle partner programme rewards. Without this information, performing the requested service may not be possible.
Statutorily required details are necessary to fulfil legal duties, such as issuing invoices. Refusing consent for marketing or optional cookies never affects your access to core Dock services.
16. Changes to this Policy
We update this policy in line with evolving services, workflows, tools, and statutory legal requirements. Material updates affecting the processing of client portal user data will be communicated clearly and proportionally to their significance.
Updating this policy does not replace required consent nor permit unrestricted new processing purposes. If an update requires additional notices, consent, or another legal basis, those requirements will be met before any new processing commences.