Privacy Policy

Last updated: August 31, 2026

§1. Data Controller

The controller of personal data processed in connection with the use of the Seatify application (hereinafter: the “Application”) is Seatify (hereinafter: the “Controller”). For all matters concerning the protection of personal data, you may contact us at the e-mail address: kontakt@seatify.app.

This Privacy Policy describes what data we collect, for what purpose, on what legal basis, and what rights are available to data subjects. It supplements the Terms of Service.

§2. Scope and Roles — Account Data and Data Entered by the User

We distinguish two categories of data in respect of which we act in different roles:

  • User account data (e.g. e-mail address, login credentials, settings) — with respect to this data, the Controller acts as the controller within the meaning of the GDPR.
  • Data entered by the User into the Application (e.g. guest lists, first and last names, table assignments) — with respect to this data, the User is the controller, and the Controller processes it on behalf of the User as a processor, solely for the purpose of providing the Service.

The User is responsible for having a legal basis to enter the data of third parties and for fulfilling the information obligations toward them.

§3. Purposes and Legal Bases of Processing

  • Creating and maintaining an account and providing the Service — Article 6(1)(b) GDPR (performance of a contract).
  • Ensuring security, handling requests and complaints, and analyzing the operation of the Application — Article 6(1)(f) GDPR (legitimate interest of the Controller).
  • Fulfilling the legal obligations incumbent on the Controller — Article 6(1)(c) GDPR.
  • Marketing contact or sending information about the Application — Article 6(1)(a) GDPR (consent), where such consent has been given; consent may be withdrawn at any time.

§4. Data Retention Period

We retain account data for the period of its activity. In the Beta Version, an account is active for 12 (twelve) months from the date of registration, in accordance with the Terms of Service. After an account is deleted or deactivated, the data is deleted or anonymized, unless longer retention is required by law or necessary to establish, pursue, or defend claims.

We retain data entered by the User for as long as it remains in the Application; it is deleted when the User deletes it or when the account is deleted.

§5. Data Recipients and Processors

In order to provide the Service, we use trusted providers who process data on our behalf under data processing agreements, in particular:

  • infrastructure providers (hosting, database, authentication),
  • e-mail service providers and providers of communication with the User,
  • providers of analytics and monitoring tools for the operation of the Application.

Data may be transferred to countries outside the European Economic Area only with the application of appropriate safeguards referred to in the GDPR (e.g. standard contractual clauses).

§6. Rights of Data Subjects

Every person has the right to:

  • access their data and obtain a copy of it,
  • rectification (correction) of data,
  • erasure of data (“right to be forgotten”),
  • restriction of processing,
  • data portability,
  • object to processing based on legitimate interest,
  • withdraw consent at any time, without affecting the lawfulness of processing prior to the withdrawal.

Data subjects have the right to lodge a complaint with the Polish DPA (PUODO), ul. Stawki 2, 00-193 Warsaw. In matters concerning the data of guests entered into the Application, we recommend contacting first the User, who is their controller.

§7. Cookies and Browser Storage

The Application uses cookies and related technologies (e.g. local storage in the browser) to ensure proper operation, maintain the session of a logged-in User, and remember settings.

We process files necessary for the operation of the Application on the basis of legitimate interest. Others (e.g. analytics) are used only with consent. The scope of cookies can be managed in the browser settings; restricting their use may affect the operation of the Application.

§8. Data Security

We apply reasonable technical and organizational measures to protect data against unauthorized access, loss, or disclosure. The rules of liability relating to data security — including in the Beta Version — are set out in the Terms of Service.

§9. Changes to the Privacy Policy

The Controller may update this Privacy Policy for important reasons, in particular legal or technical changes or changes to the scope of the Service. The current version is published in the Application each time together with the date of the last update.