PL

Privacy policy

Last updated: 2026-10-09

1. Data controller

The controller of the personal data of VeriSec users is kompea.pl sp. z o.o., ul. Stanisława Przybyszewskiego 38/2, 01-824 Warszawa, NIP 5272986466, KRS 0000947907 ("we"). For questions about personal data, contact us at helpdesk@kompea.pl.

2. What this notice covers

It covers the data of people who have a VeriSec account: account data, sign-in data and the audit log. The content an organisation (Client) enters into registers and documents in VeriSec is processed on behalf of that Client, under a data processing agreement. The Client is its controller and informs people about its processing.

3. What data, why, and on what legal basis

Account Email address, name, job title, profile picture, language, role and permissions, organisation, password (stored only as a hash), Google account identifier (when signing in with Google). Purpose: creating the account and providing the service. Basis: art. 6(1)(b) GDPR (contract), and where a Client creates the account for its employee, art. 6(1)(f) GDPR (the legitimate interest of the Client and ours in giving access to the service).
Sign-in Authenticator app secret, one-time codes sent by email, time of last sign-in. Purpose: two-factor authentication and account protection. Basis: art. 6(1)(f) GDPR (security of the service).
Audit log Who made which change and when, IP address, browser information (user agent). Purpose: security, accountability for changes, detecting abuse, establishing, pursuing or defending legal claims. Basis: art. 6(1)(f) GDPR.
Emails Email address. Purpose: account activation, password reset, sign-in codes, notifications about tasks in the service. Basis: art. 6(1)(b) and (f) GDPR.

Providing the data is voluntary, but the service cannot be used without it. We make no automated decisions and do no profiling.

4. Who receives the data

  • Administrators of the organisation (Client) the account belongs to, for that organisation’s accounts.
  • Server provider: OVH Sp. z o.o. (OVHcloud), ul. Swobodna 1, 50-088 Wrocław; server in Warsaw, Poland.
  • Google, only if the user chooses to sign in with Google.

Providers process the data on our behalf, under data processing agreements. The data is not transferred outside the European Economic Area.

5. How long we keep the data

  • Account data: until the account is deleted or the contract with the Client ends, then for the limitation period for claims.
  • Audit log: kept permanently, as the log is tamper-evident; on a justified erasure request, personal data is removed from its entries.
  • Backups: daily copies made by the server provider, overwritten in rotation after at most 7 days.
  • One-time sign-in codes: until used or expired.

6. Your rights

You have the right to access your data, to have it corrected or erased, to restrict its processing, to data portability, and to object to processing based on legitimate interest. Write to us at helpdesk@kompea.pl. You can also lodge a complaint with the President of the Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warszawa).

7. Cookies and browser storage

The service stores on your device only what it needs to work or to remember settings you choose yourself. We use no analytics, advertising or tracking tools, and load nothing from other companies’ servers. Such storage needs no consent, which is why the service shows no cookie banner.

NameTypePurposeKept for
PHPSESSIDcookieSign-in session, form protection (CSRF), chosen languageUntil the browser is closed or you sign out
themelocalStorageLight or dark themeUntil cleared in the browser
sidebarCollapsedlocalStorageCollapsed or expanded menuUntil cleared in the browser
sessionFingerprintlocalStorageNoticing that another tab shows a different accountUntil cleared in the browser

You can delete this data or block it in your browser settings. Without the session cookie you cannot sign in.

8. Changes

We will announce significant changes to this notice in the service. The current version is always on this page.