DashStack sp. z o.o.

Wersja polska

Privacy and Personal Data Protection Policy

How DashStack sp. z o.o. collects, uses, secures, retains and deletes personal data — as a controller for its own business activities and as a processor acting on documented instructions from its customers.

Document version
1.0
Effective date
15 February 2026
Document owner
Management Board / Privacy Responsible Person
Classification
Internal / Controlled Document
Review frequency
At least annually, or following significant legal, regulatory, organizational, security or technological changes

1. Purpose

The purpose of this Privacy and Personal Data Protection Policy is to establish the principles, responsibilities, and minimum requirements applied by DashStack sp. z o.o. when collecting, accessing, using, storing, disclosing, transferring, updating, exporting, retaining, or deleting personal data.

DashStack is committed to processing personal data lawfully, fairly, transparently, securely, and only for defined business purposes. This Policy is intended to support compliance with Regulation (EU) 2016/679 (GDPR), the Polish Act on the Protection of Personal Data, applicable contractual obligations, and customer or platform privacy requirements.

This Policy shall be read together with DashStack sp. z o.o. Information Security Policy v1.0 and any applicable data processing agreements, customer contracts, privacy notices, retention rules, and security procedures.

2. Scope

This Policy applies to personal data processed by DashStack in connection with its business activities, including personal data processed as a controller and personal data processed on behalf of customers or business partners as a processor or sub-processor.

  • all employees, contractors, subcontractors, temporary personnel, and consultants of DashStack;
  • all systems, applications, databases, servers, endpoints, cloud services, and communication tools used to process personal data;
  • customer, seller, consumer, employee, candidate, contractor, supplier, and business-contact data;
  • personal data processed in connection with e-commerce platforms, integrations, APIs, support services, and software developed or maintained by DashStack;
  • personal data received from or processed for customers, sellers, marketplaces, and platforms, including TikTok Shop where applicable.

3. Definitions and Privacy Roles

Personal data means any information relating to an identified or identifiable natural person. Processing includes any operation performed on personal data, whether automated or manual.

DashStack may act in different roles depending on the processing activity:

  • Controller — where DashStack determines the purposes and means of processing personal data for its own business activities;
  • Processor or sub-processor — where DashStack processes personal data on documented instructions from a customer, seller, platform, or other controller.

The Management Board is responsible for approving this Policy and ensuring that appropriate privacy governance is maintained. A person designated by management as the Privacy Responsible Person coordinates privacy compliance activities, supports data subject requests, assists with incident handling, maintains relevant documentation, and escalates material privacy risks to management.

All personnel processing personal data are responsible for complying with this Policy, confidentiality obligations, access restrictions, and documented processing instructions.

4. Data Protection Principles

DashStack shall process personal data in accordance with the following principles:

  • Lawfulness, fairness and transparency — processing shall have an appropriate legal basis and shall not be misleading or unfair;
  • Purpose limitation — personal data shall be collected for specified, explicit, and legitimate purposes and shall not be used incompatibly with those purposes;
  • Data minimization — only personal data reasonably necessary for the relevant purpose shall be processed;
  • Accuracy — reasonable steps shall be taken to keep personal data accurate and, where necessary, up to date;
  • Storage limitation — personal data shall not be retained for longer than necessary for the relevant purpose or legal obligation;
  • Integrity and confidentiality — personal data shall be protected using appropriate technical and organizational measures;
  • Accountability — DashStack shall be able to demonstrate compliance through documented policies, contracts, records, and security controls.

5. Lawful Basis and Processing Instructions

Where DashStack acts as a controller, personal data shall be processed only where an appropriate legal basis exists, such as performance of a contract, compliance with a legal obligation, legitimate interests, consent, or another basis permitted by applicable law.

Where DashStack acts as a processor or sub-processor, personal data shall be processed only on documented instructions from the relevant controller, except where processing is required by applicable law. If DashStack believes an instruction conflicts with applicable data protection law, the matter shall be escalated to the Privacy Responsible Person and the customer or controller shall be informed where appropriate.

Personal data received from a customer, marketplace, seller, or platform shall not be used for unrelated purposes, sold, or disclosed to unauthorized third parties unless separately authorized and permitted by applicable law.

6. Categories of Personal Data

Depending on the service and customer instructions, DashStack systems may process categories of personal data such as:

  • identification and contact data, including name, email address, telephone number, and delivery or billing details;
  • account, seller, customer, and user identifiers;
  • order, transaction, fulfillment, support, and customer-service information;
  • IP addresses, device identifiers, authentication and security logs, and other online identifiers;
  • employee, contractor, candidate, and business-contact information;
  • other personal data required to provide contracted software, integration, support, or operational services.

Special categories of personal data and criminal-conviction data shall not be intentionally processed unless required for an approved business purpose and supported by an appropriate legal basis, safeguards, and authorization.

7. Data Collection, Minimization and Accuracy

Systems and business processes shall be designed to avoid collecting personal data that is not reasonably necessary. Mandatory fields, API payloads, logs, exports, and reports should be limited to information needed for the stated purpose.

Where DashStack is able to correct personal data, reasonable mechanisms shall be maintained to update inaccurate or outdated information. Where data is controlled by a customer or platform, correction requests shall be forwarded or implemented according to documented instructions.

8. Transparency and Privacy Notices

Where DashStack acts as a controller and applicable law requires it, individuals shall be provided with a privacy notice describing the relevant processing in clear and accessible language.

Privacy notices should explain, as applicable, the identity of the controller, processing purposes, legal bases, categories of recipients, international transfers, retention periods or criteria, data subject rights, complaint rights, and relevant contact details.

Privacy notices and internal privacy documentation shall be reviewed when processing activities materially change and at least periodically as part of the annual Policy review.

9. Data Subject Rights

DashStack shall support the exercise of applicable data subject rights, including where relevant:

  • access to personal data;
  • rectification of inaccurate or incomplete personal data;
  • erasure of personal data;
  • restriction of processing;
  • data portability;
  • objection to processing;
  • withdrawal of consent where processing is based on consent;
  • rights relating to automated decision-making where applicable.

Requests received directly by DashStack shall be verified and handled according to the role DashStack performs for the relevant processing activity. Identity verification shall be proportionate and shall not require unnecessary additional personal data.

10. Assistance to Customers, Sellers and TikTok Shop

Where DashStack processes personal data on behalf of TikTok Shop, a seller, customer, or other controller, DashStack shall reasonably assist the controller in responding to data subject requests relating to personal data processed through DashStack systems.

This assistance may include locating, exporting, correcting, updating, restricting, or deleting personal data in accordance with documented and authorized instructions. DashStack shall not independently alter or disclose controller-owned personal data in response to a request unless authorized by the controller or required by law.

Requests received from a data subject that relate to data controlled by a customer, seller, or TikTok Shop shall be promptly routed to the relevant controller or handled under the controller’s documented instructions.

11. Access Control and Confidentiality

Access to personal data shall be restricted according to the principles of least privilege and need-to-know. Access shall be granted only to personnel who require it for legitimate business responsibilities.

  • individual user accounts shall be used where appropriate;
  • privileged and administrative access shall be restricted;
  • access to production systems and sensitive personal data shall receive enhanced protection;
  • access rights shall be reviewed periodically and adjusted when responsibilities change;
  • access shall be revoked promptly when employment, cooperation, or the business need ends;
  • personnel with access to confidential information shall be subject to appropriate confidentiality obligations.

12. Security of Personal Data

DashStack shall apply appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, misuse, or other forms of unlawful processing.

Security controls are described in greater detail in the DashStack Information Security Policy and may include endpoint protection, anti-malware controls, firewalls, network segregation, secure authentication, multi-factor authentication, access logging, monitoring, backup controls, patch management, and vulnerability remediation.

13. Encryption

Confidential, Restricted, and other sensitive personal data shall be protected using industry-standard encryption mechanisms where appropriate to the risk and processing context.

Personal data transmitted over public or untrusted networks shall use secure encrypted protocols such as TLS/HTTPS, SSH, or VPN. Sensitive data stored on company endpoints, servers, databases, backups, and approved cloud storage shall be protected using appropriate disk-level, storage-level, database-level, device-level, or platform-provided encryption where supported and appropriate.

Encryption keys, credentials, and secrets shall be accessible only to authorized personnel and shall not be stored in publicly accessible source code repositories.

14. Data Retention and Deletion

Personal data shall be retained only for as long as necessary to fulfill the relevant processing purpose, customer instruction, contractual requirement, or applicable legal obligation.

Where DashStack acts as a processor or sub-processor, retention and deletion shall follow the applicable contract, data processing agreement, platform requirements, and documented controller instructions. At the end of the service, personal data shall be returned or deleted as required, subject to legally required retention and backup-management constraints.

Deletion processes shall consider active systems, databases, exports, temporary files, logs, and backups. Backup copies may be retained for a limited recovery period and shall remain protected from unauthorized use until overwritten or securely deleted under the applicable backup lifecycle.

15. Data Location and International Transfers

DashStack seeks to use European Economic Area (EEA) infrastructure for personal data where reasonably practicable and where DashStack controls region selection. Current primary production and hosting locations used for relevant services include Poland and Germany, including infrastructure hosted in Frankfurt, Germany.

Personal data shall not be transferred outside the EEA unless the transfer is permitted by applicable data protection law and appropriate safeguards are in place. Depending on the circumstances, safeguards may include an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism.

Where third-party providers may process personal data outside the EEA, DashStack shall assess the provider, contractual terms, transfer mechanism, and relevant security measures before approval for processing covered by this Policy.

16. Third Parties and Sub-processors

Third parties that process personal data for DashStack or on behalf of DashStack customers shall be selected with appropriate consideration of privacy and security risks.

Where required, processing shall be governed by contractual terms addressing confidentiality, security, data protection obligations, incident notification, assistance with data subject rights, deletion or return of data, and use of further sub-processors.

Where DashStack acts as a processor and intends to appoint a sub-processor, customer authorization or notification shall be handled in accordance with the applicable data processing agreement.

17. Privacy by Design and by Default

Privacy considerations shall be incorporated into the design and material modification of systems and processing activities involving personal data. Appropriate measures may include data minimization, pseudonymization, restricted defaults, access controls, retention limits, encryption, separation of environments, and reduced use of production personal data in development and testing.

Production customer personal data shall not be used in development or testing unless necessary, authorized, and appropriately protected, such as through anonymization or pseudonymization.

18. Data Protection Impact and Risk Assessment

New or materially changed processing activities shall be assessed for privacy risk where appropriate. Where processing is likely to result in a high risk to the rights and freedoms of individuals, DashStack shall support or conduct a Data Protection Impact Assessment (DPIA) as required by applicable law and according to DashStack’s role in the processing.

Privacy risks identified through assessments, customer reviews, incidents, audits, or technical changes shall be documented and addressed proportionately.

19. Personal Data Breaches and Incident Response

Suspected personal data breaches shall be reported immediately to the Privacy Responsible Person and handled together with the Security Incident Management process defined in the DashStack Information Security Policy.

Incident handling shall include appropriate detection, assessment, containment, investigation, remediation, recovery, documentation, and corrective actions. The assessment shall consider the categories and volume of personal data involved, affected individuals, likely consequences, and existing protective measures.

Where DashStack acts as a processor or sub-processor, the relevant controller shall be informed without undue delay after DashStack becomes aware of a personal data breach affecting data processed on the controller’s behalf. DashStack shall provide reasonable information and assistance required for the controller to assess notification obligations.

Where DashStack acts as a controller, notification to the competent supervisory authority and affected individuals shall be made where required by GDPR or other applicable law, including the applicable 72-hour supervisory-authority timeframe under GDPR where notification is required.

20. Records, Documentation and Accountability

DashStack shall maintain privacy documentation appropriate to its role, scale, and processing activities. Such documentation may include records of processing activities, data processing agreements, approved sub-processor information, security and privacy policies, incident records, data subject request records, retention rules, and relevant risk assessments.

Privacy-related records shall be made available to authorized personnel and, where contractually or legally required, to customers or competent authorities.

21. Employee and Contractor Personal Data

Personal data relating to employees, contractors, and candidates shall be processed only for legitimate employment, cooperation, recruitment, security, legal, payroll, administrative, or operational purposes and shall be restricted to authorized personnel.

Where company systems are monitored for security, operational, or compliance purposes, monitoring shall be proportionate, conducted in accordance with applicable law, and communicated to personnel where required.

22. Use of AI Tools and External Online Services

Personnel shall not enter customer personal data, confidential personal data, credentials, Restricted information, or non-public source code into external AI tools or online services unless the service has been approved for the relevant data category and appropriate contractual and data protection arrangements are in place.

Any use of AI or external services involving personal data shall follow data minimization, access-control, security, retention, and international-transfer requirements under this Policy.

23. Privacy Complaints and Regulatory Correspondence

Privacy complaints, objections, notices, or correspondence received from individuals, customers, former customers, supervisory authorities, or other regulators shall be promptly forwarded to the Privacy Responsible Person.

Such matters shall be documented, assessed, and responded to within applicable legal or contractual deadlines. Material complaints or regulatory matters shall be escalated to the Management Board.

24. Training and Awareness

Personnel with access to personal data shall be informed of relevant privacy and security responsibilities. Training or awareness activities shall be proportionate to role and risk and may cover confidentiality, phishing, secure handling of personal data, data subject requests, incident reporting, use of external services, and restrictions on sharing personal data.

25. Audit, Review and Continuous Improvement

DashStack may review or audit privacy controls, access permissions, data flows, processor arrangements, retention practices, and security measures to verify compliance with this Policy and applicable contractual requirements.

Identified deficiencies shall be documented and corrected within a timeframe proportionate to the associated risk.

26. Exceptions

Material exceptions to this Policy shall be documented, justified by a legitimate business or legal requirement, approved by an authorized person, and supported by appropriate compensating measures where possible. Exceptions should be time-limited and periodically reviewed.

27. Policy Violations

Violation of this Policy may result in restriction or revocation of access to personal data or company systems and may lead to appropriate organizational, contractual, disciplinary, or legal measures in accordance with applicable law and contractual arrangements.

28. Policy Review and Updates

This Policy shall be reviewed at least once every 12 months and shall also be reviewed following significant changes to applicable law, regulatory guidance, processing activities, customer or platform requirements, IT infrastructure, organizational structure, third-party processing arrangements, or following a material privacy or security incident.

Material updates shall be approved by the Management Board or an authorized representative of DashStack sp. z o.o. The current approved version shall be made available to relevant personnel and, where appropriate, to customers or business partners as evidence of DashStack’s privacy governance.

29. Related Documents

  • DashStack sp. z o.o. Information Security Policy v1.0;
  • applicable Data Processing Agreements (DPAs);
  • customer and platform contractual requirements;
  • incident response, backup, access-control, and security procedures maintained under the Information Security Policy.

30. Approval

This Privacy and Personal Data Protection Policy is approved for use within DashStack sp. z o.o. upon signature or formal approval by the Management Board or an authorized representative.

Company: DashStack sp. z o.o. Approved by: Management Board / Authorized Representative.

DashStack sp. z o.o. — Privacy and Personal Data Protection Policy v1.0

Back to top