Privacy Policy

Privacy Policy – Vlčí Lístek

HQ Market sp. z o.o. · PB Vision iT
1. Data Controller

HQ Market sp. z o.o.
ul. Frezerów 3, 20-209 Lublin, Poland
Polish Tax Identification Number / NIP: 9462684492

The "Vlčí Lístek" Service is part of a project developed by PB Vision iT.

Contact regarding personal data matters:

2. Scope of Processed Data
2.1 User data:
  • first and last name,
  • phone number,
  • e-mail address.
2.2 Company data:
  • company name,
  • registration number (IČO) or other tax identifier,
  • authorized representative details.
2.3 Technical data:
  • IP address,
  • login information,
  • activity within the Service,
  • data related to use of Service functionalities.
2.4 Data of persons and entities covered by a record

The Service may process data of persons, companies or other entities that are the subject of a record submitted by a user. This may include in particular: first and last name, company name, company identification data, contact details, location, record category, description of experience, relationship between the parties, and other information provided by the user.

2.5 Data on the use of the Service:
  • content and status of draft entries,
  • the selected entry topic,
  • search queries and search history,
  • information on the use of search functions,
  • monitoring settings and criteria,
  • data needed to send notifications,
  • status and type of active access,
  • information on publication attempts and completion of publication after payment.

The user who submits a record is responsible for ensuring that the data included in the record is accurate, proportionate and relevant to the purpose of the Service.

3. Purposes and Legal Bases of Processing

Personal data is processed for the following purposes and on the following legal bases:

  • user registration and account management – Art. 6(1)(b) GDPR,
  • payment processing and invoicing – Art. 6(1)(b) and (c) GDPR,
  • publication, search and comparison of records – Art. 6(1)(f) GDPR,
  • handling reports, content moderation and user communication – Art. 6(1)(f) GDPR,
  • ensuring Service security and preventing misuse – Art. 6(1)(f) GDPR,
  • creating, storing and editing draft entries – Art. 6(1)(b) GDPR,
  • performing and securing searches across all areas of the database – Art. 6(1)(b) and (f) GDPR,
  • keeping search history to prevent misuse – Art. 6(1)(f) GDPR,
  • providing record monitoring and comparing the set criteria with published records – Art. 6(1)(b) and (f) GDPR,
  • sending notifications to users as part of monitoring – Art. 6(1)(b) GDPR,
  • managing permissions to view results and publish records, including completing publication after a successful payment – Art. 6(1)(b) GDPR.

The legitimate interests of the Controller include in particular: operating a system for sharing experiences, fraud prevention, protecting users from dishonest conduct, ensuring Service security, content moderation and defence against legal claims.

4. Content Moderation

The Controller may review, moderate, temporarily hide or remove records where there is reasonable suspicion that they are false, offensive, unlawful, contain excessive personal data or violate the rules of the Service.

5. International Nature of Data Processing

The Service operates as part of an international system available in different countries and language versions.

Data may be processed within this system for the purposes of:

  • comparing information,
  • identifying potential connections between reports,
  • ensuring the functionality of the Service.

Such processing does not result in automated decision-making producing legal effects concerning users.

6. Data Recipients

Personal data may be transferred to cooperating entities, including:

  • hosting and IT infrastructure providers,
  • payment operators (e.g. Stripe),
  • technical and analytical service providers.

Data may also be disclosed to public authorities where required by law.

7. Data Transfers Outside the EEA

Should the operation of the Service involve transfers of personal data outside the European Economic Area, such transfers will take place only on the basis of appropriate legal mechanisms under the GDPR, in particular adequacy decisions or standard contractual clauses.

8. Anonymity

The Service allows users to publish content anonymously or publicly. The Administrator does not disclose user data to other users unless the user decides otherwise.

9. Data Retention Period

Personal data is retained:

  • account data – for the duration of the Free or paid account,
  • draft entries – for the duration of the account, until the user deletes or publishes them,
  • search queries, search history and security logs – for the period necessary to prevent misuse and ensure the security of the Service, typically up to 12 months,
  • monitoring settings and data – for as long as the user keeps monitoring active, no longer than the duration of the account,
  • published entries – for the period they remain published in the database, or until they are removed in accordance with the Terms,
  • data related to invoicing and accounting – for the period required by tax and accounting regulations (typically 5 years),
  • data necessary to defend against potential claims – for a period corresponding to the applicable limitation periods (typically up to 3 years).
10. User Rights

Users have the right to:

  • access their data,
  • rectify their data,
  • erase their data,
  • restrict processing,
  • data portability.

Where data is processed on the basis of legitimate interests, the data subject has the right to object to such processing at any time.

Users also have the right to lodge a complaint with a supervisory authority, in particular the Office for Personal Data Protection in the Czech Republic or the supervisory authority in their country of residence.

Requests should be sent to:

11. Voluntary Provision of Data

Providing personal data is voluntary but necessary to use the Service.

12. Security Measures

The Administrator applies appropriate technical and organizational measures to protect personal data.

13. Changes to the Privacy Policy

The Administrator reserves the right to amend this Privacy Policy. Users will be informed electronically about any changes.