Privacy Policy
Version: 11 October 2026. Scope: the public information-only website takeora.pl and correspondence with support@takeora.pl. App-account, payment and optional diagnostic terms will be updated before those production services launch.
1. Data controller
The controller for this website and support correspondence is Przemysław Smyk, address: ul. Relaksowa 16/22, 20-819 Lublin, Poland. Privacy requests: support@takeora.pl. Data protection officer contact details will be supplied if a DPO is appointed; no appointment is currently represented.
2. Website data
Hosting systems may process your IP address, request time, requested URL, browser information and technical errors. If you contact us, we process your email address, any contact details you choose to provide and your message. The current informational website has no user account form, checkout, marketing analytics or tracking pixels. Do not send passwords, tokens, private photographs or your entire Takeout library to support.
3. Purposes and legal bases
Maintaining and securing the site: our legitimate interests (GDPR Article 6(1)(f), site security and operation). Answering requests: pre-contractual steps requested by you where relevant (Article 6(1)(b)), or our legitimate interest in handling enquiries (Article 6(1)(f)). Where a specific legal obligation applies, Article 6(1)(c). Contacting support does not subscribe you to marketing.
4. Recipients and hosting
Website hosting and email services are supplied by OVHcloud. According to the customer dashboard, TakeORA’s Free 100M hosting runs in the eu-west-gra region in France; we use the support@takeora.pl mailbox through Zimbra Starter. OVHcloud processes data to provide, maintain and secure the services and may use subprocessors under the relevant service terms and data-processing agreement. Hosting the primary website in France does not mean that all auxiliary processing necessarily takes place in France. Any transfer outside the European Economic Area requires a lawful basis and safeguards under Chapter V GDPR; you can request information about applicable arrangements from the controller. The informational website has no live checkout, so visitor data is not currently sent to a payment operator.
5. Retention
Technical, access and error logs are processed as needed to operate the site, diagnose problems, prevent abuse, ensure security and comply with legal obligations. Their retention depends on the type of log and the terms of the relevant OVHcloud service; we do not claim a single unverified retention period for every log. According to OVHcloud, its Web Statistics reports use anonymised and aggregated data. We retain correspondence sent to support@takeora.pl while handling the enquiry and afterwards only for as long as reasonably necessary to document our actions, deal with complaints, comply with legal duties or establish, exercise or defend legal claims. The period depends on the nature of the matter and applicable statutory time limits. Once these purposes and grounds cease, the data is deleted; technical backups held by the provider are subject to the applicable service rules. We do not claim that emails are automatically deleted after a fixed number of months.
6. Cookies and local storage
TakeORA website code does not run ads, our own marketing analytics or tracking pixels; our scripts do not set cookies or localStorage. However, OVHcloud states that its shared hosting uses a technical “SERVER ID” cookie for load balancing and keeping a session on the appropriate server; the provider describes it as anonymous, strictly necessary for the service and valid for less than 24 hours. Shared hosting also includes OVHcloud Web Statistics, which the provider says is enabled by default and uses anonymised, aggregated traffic data rather than marketing scripts deployed by TakeORA. If we later activate our own analytics or other technologies requiring consent, we will first update the notice and obtain consent wherever required by law.
7. Photos, videos and the future application
The planned application is designed to process Takeout media locally and leave source files read-only. This policy does not confirm that the production account backend or app is live or fully approved. Before accounts, device identification, GB billing, optional diagnostics or Paddle go live, we will publish details of the actual data, legal bases, retention and recipients. Paddle, if activated as Merchant of Record, acts in its own distinct capacity and is not automatically solely our processor.
8. Rights and complaints
Subject to applicable GDPR conditions, you may request access, rectification, erasure, restriction, portability (where applicable), object to processing based on legitimate interests, or withdraw consent where relevant. Contact support@takeora.pl. You may complain to the Polish Data Protection Authority (UODO) or another competent supervisory authority.
9. Updates
This notice may change, particularly before accounts and checkout launch. We will display the version and effective date. New wording does not retrospectively legitimise processing without a proper legal basis.