This site sets no cookies of its own, does not track its visitors and runs no analytics. The sections below describe what data is processed nevertheless, who is responsible for it and what rights the people it concerns have.
1. Data controller
- Controller
- [FULL NAME]
- Registered business
- [BUSINESS NAME AS REGISTERED IN CEIDG]
- Address
- [STREET AND NUMBER, POSTCODE, CITY], Poland
- NIP (tax ID)
- [NIP]
- REGON
- [REGON]
- kontakt@nightcommit.com
Night Commit is the brand under which the controller makes and publishes mobile apps. Any matter concerning personal data can be sent to kontakt@nightcommit.com or by post to the controller's address.
2. Scope
This policy covers the nightcommit.com website in Polish and English and e-mail correspondence sent to the controller. Night Commit apps have their own privacy policies, published together with them in the app stores.
3. Cookies and analytics
The site itself stores no cookies or other identifiers on visitors' devices, uses no analytics, advertising or social media plugins and loads nothing from third-party servers: fonts and images are hosted together with the site. Visitors are not profiled.
The one possible exception is a technical cookie set by the hosting provider (Cloudflare, for example __cf_bm or cf_clearance) only when its protection against bots or attacks has to verify a browser. It serves only the security of the site, does not track visitors and is strictly necessary to provide the site, so it does not require consent.
4. Hosting and technical data
The site is delivered through the infrastructure of Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA), which serves it to visitors and protects it against attacks. Whenever a page is displayed, Cloudflare processes the technical data needed to deliver it, in particular the IP address, the date and time of the request, the address of the page, information about the browser and operating system, and the referring page.
- Purpose: delivering the site, keeping it secure and protecting it against abuse.
- Legal basis: the controller's legitimate interest in a secure and working website (Article 6(1)(f) GDPR).
- Retention: the controller keeps no server logs of its own and does not combine this data with any other data. Cloudflare keeps it for as long as security requires, in line with its own privacy policy.
Cloudflare processes this data as a processor under a data processing agreement (Data Processing Addendum). The data may be transferred to the United States. Cloudflare participates in the EU-U.S. Data Privacy Framework, covered by the European Commission's adequacy decision (Article 45 GDPR), and applies the standard contractual clauses approved by the Commission (Article 46(2)(c) GDPR). More information is available in Cloudflare's privacy policy.
5. E-mail correspondence
A message sent to kontakt@nightcommit.com reaches the controller, who then processes the data it contains: the sender's e-mail address and the name and any other information the sender chooses to include.
- Purpose: replying to the message and continuing the correspondence.
- Legal basis: the controller's legitimate interest in answering messages (Article 6(1)(f) GDPR) and, where the message concerns entering into or performing a contract, Article 6(1)(b) GDPR.
- Retention: until the correspondence ends, and afterwards no longer than the limitation period for claims that may arise from it.
- Recipients: the e-mail and hosting providers used by the controller, acting as processors. Where they process data outside the European Economic Area, this is based on an adequacy decision of the European Commission or on standard contractual clauses.
Providing data is voluntary, but without an e-mail address a message cannot be answered.
6. Rights of data subjects
Every person whose data is processed has the right to:
- access their data and receive a copy of it,
- have their data rectified,
- have their data erased,
- restrict the processing,
- data portability, to the extent the processing is based on a contract and carried out by automated means,
- object to processing based on the controller's legitimate interest (Article 21 GDPR).
Requests can be sent to kontakt@nightcommit.com. They are answered without undue delay and within one month at the latest.
Everyone also has the right to lodge a complaint with a supervisory authority, in Poland the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or with the authority of their own EU country of residence.
7. Automated decisions
The data is not used for automated decision-making, including profiling.
8. Changes to this policy
The policy may be updated, for example when the way the site works changes. The current version is always available at nightcommit.com/en/privacy, and the date at the top shows when it took effect. The Polish version at nightcommit.com/privacy is the reference text.