Privacy Policy
Version 2.0 · Published: 7 August 2026 · Effective: 21 August 2026
This version supersedes version 1.0. For Users holding an Account on the publication date, the changes take effect 14 days after publication, in accordance with point 13.
1. Data controller
The controller of your personal data is Aleksander Ambros, conducting unregistered business activity within the meaning of Art. 5 of the Act of 6 March 2018 – Entrepreneurs' Law, address: 41-902 Bytom, 19/3 Łukasza Wallisa St., Poland, e-mail: [email protected].
The Controller has not appointed a Data Protection Officer. For all matters concerning the protection of personal data, please contact the Controller directly at the e-mail address indicated above.
2. Scope of the document and services
This Privacy Policy applies to the use of:
- the public website https://entiway.com,
- the user panel https://app.entiway.com,
- the API interface https://api.entiway.com.
Entiway is a service directed exclusively at entrepreneurs. The Controller applies the principle of data minimisation and processes only the data necessary for providing the service, security, settlements and communication.
The rules for using cookies and similar technologies are described in a separate Cookie Policy.
This document covers two distinct categories of persons:
- Users – persons using the Account, the Panel and the API (points 3–11),
- persons to whom Registry Data relates – sourced from public state registers (point 12).
3. Categories of data and purposes of processing – Users
3.1. Data provided on registration and while maintaining the Account
The Controller processes the data necessary to create and operate the Account, in particular:
- e-mail address,
- password in the form of a cryptographic hash,
- profile name,
- time zone,
- technical identifiers necessary to operate the Account,
- configuration data relating to the API, Monitoring, the Wallet and Account settings.
| Purpose of processing | Legal basis |
|---|---|
| Registration, activation and maintenance of the Account | Art. 6(1)(b) GDPR – necessity for the performance of a contract |
| Provision of the services available in the Panel and the API | Art. 6(1)(b) GDPR – necessity for the performance of a contract |
| Account security and prevention of abuse | Art. 6(1)(f) GDPR – legitimate interest of the Controller |
3.2. Login, session and security data
In connection with logging in to the Panel and using Entiway, the Controller may process technical data such as:
- session identifiers,
- IP address,
- date and time of login or event,
- technical information necessary to secure the login process and detect abuse,
- data on unsuccessful login attempts and temporary access blocks.
| Purpose of processing | Legal basis |
|---|---|
| Authentication of the User and maintenance of the session | Art. 6(1)(b) GDPR – necessity for the performance of a contract |
| Ensuring the security of the service, detecting abuse and protecting the Infrastructure | Art. 6(1)(f) GDPR – legitimate interest of the Controller |
3.3. Technical logs of the API and the Panel
The Controller processes technical logs relating to the operation of Entiway, in three separate layers:
- web server logs – the HTTP server (Nginx) automatically records requests directed to the services, including the IP address, date and time, the resource requested, the HTTP response code, the referring page address and browser information,
- application logs – diagnostic events recorded by the application itself in connection with its operation and error handling,
- API request logs – metadata of authorised requests directed to the API, including the IP address, timestamp, endpoint, request method, response code and processing time, made available to the User in the Panel as part of the service. For requests that end in an error, the content of the request parameters submitted is additionally recorded, excluding passwords and API Tokens.
The retention periods for each layer are indicated in point 8.
| Purpose of processing | Legal basis |
|---|---|
| Technical monitoring, maintaining continuity of operation and diagnosing errors | Art. 6(1)(f) GDPR – legitimate interest of the Controller |
| Ensuring the security of the service | Art. 6(1)(f) GDPR – legitimate interest of the Controller |
3.4. Data relating to settlements
In order to link payments to the Account, the Controller may process data received from the Payment Operator, in particular:
- transaction_id,
- event_id,
- technical payload data relating to the handling of payments and subscriptions,
- information on the crediting of the Wallet and the Wallet operation history.
| Purpose of processing | Legal basis |
|---|---|
| Performance of the Agreement and handling of settlements within Entiway | Art. 6(1)(b) GDPR – necessity for the performance of a contract |
| Maintaining documentation and settlements required by law | Art. 6(1)(c) GDPR – legal obligation |
| Defence against claims and ensuring accountability | Art. 6(1)(f) GDPR – legitimate interest of the Controller |
The Controller does not process payment card data or full payment details of Users; transactions are handled by Paddle as Merchant of Record.
3.5. Data from the contact form
Where the contact form on entiway.com is used, the Controller processes the data provided by the sender of the message: first name or name, e-mail address, company name and the content of the message, as well as automatically attached technical data: the public IP address of the sender, the selected language version of the website, the timestamp of the consent given and the timestamps of the creation and modification of the enquiry. The enquiry is saved in the database of the Controller and sent to the Controller's mailbox; the delivery status of the message is also recorded.
| Purpose of processing | Legal basis |
|---|---|
| Handling the enquiry, correspondence and reply contact | Art. 6(1)(f) GDPR or Art. 6(1)(b) GDPR, where the message concerns the conclusion or performance of the Agreement |
| Pursuit of or defence against claims | Art. 6(1)(f) GDPR – legitimate interest of the Controller |
| Processing of data submitted through the form on the basis of the consent given when sending it | Art. 6(1)(a) GDPR – consent of the data subject |
Consent is given by ticking a checkbox in the form, and the moment it is given is recorded. Consent may be withdrawn at any time by sending a request to [email protected]. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
3.6. Data relating to Monitoring and use of the service
The Controller processes configuration and operational data relating to the use of Entiway, such as the list of monitored entities, the history of monitoring events, API usage, the Wallet balance, the Wallet operation history and Account settings.
| Purpose of processing | Legal basis |
|---|---|
| Provision of the services available in Entiway | Art. 6(1)(b) GDPR – necessity for the performance of a contract |
| Maintaining the security and integrity of the service | Art. 6(1)(f) GDPR – legitimate interest of the Controller |
3.7. Monitoring Alerts
If the User independently enables and configures Alerts in the Panel, the Controller processes their e-mail address and notification preferences in order to deliver them.
Alerts are disabled by default and are sent exclusively in accordance with the individual preferences set by the User. Alerts are a functional element of the service and do not constitute marketing communication.
| Purpose of processing | Legal basis |
|---|---|
| Delivery of notifications of Monitoring events as an element of performance of the Agreement | Art. 6(1)(b) GDPR – necessity for the performance of a contract |
4. Voluntary nature of providing data
Providing data is voluntary, however:
- providing an e-mail address and setting a password is necessary to create an Account and conclude the Agreement – without them the service cannot be provided,
- in the API registration path a business e-mail address is required; addresses from free public mail services and temporary mailboxes are not accepted in this path,
- providing data in the contact form is voluntary, and failure to provide it only prevents a reply to the enquiry,
- providing an e-mail address for the purposes of Alerts is voluntary, and opting out results only in the absence of notifications, without affecting the other functions of the service.
5. What the Controller does not process as a rule
- The Controller does not process full payment card data of Users.
- The Controller does not carry out marketing profiling of Entiway users.
- The Controller does not use User data to sell databases or for independent advertising purposes.
- The Controller does not take decisions in respect of Users based solely on automated processing that produce legal effects or similarly significantly affect them.
6. Recipients of data
Data may be disclosed to the following categories of recipients:
| Recipient | Role and scope |
|---|---|
| Hetzner Online GmbH (Germany, EEA) | Provider of server infrastructure and hosting, acting as a processor. The Controller does not use external SaaS mail service providers – the mail infrastructure is managed independently on servers hosted by Hetzner. |
| Cloudflare, Inc. (USA / global) | Provider of a content delivery network, DNS service, DDoS protection and a reverse proxy, acting as a processor. All HTTP and HTTPS traffic directed to entiway.com, app.entiway.com and api.entiway.com passes through the Cloudflare infrastructure, which processes visitors' IP addresses for security purposes and to optimise content delivery. Separately, in the Panel and in the API documentation, presentation libraries are loaded from the public cdnjs.cloudflare.com network, as a result of which the browser of the User establishes a connection with it and that network may receive technical connection data, including IP address and browser information. |
| Paddle.com Market Limited (United Kingdom) | Independent payment operator and Merchant of Record, responsible for payments, invoicing, refunds and subscription handling, acting as a separate controller in respect of the transactions it carries out. |
| Google LLC (USA) | In respect of connections made by the browser of the User to Google Fonts servers. Fonts are loaded from the fonts.googleapis.com and fonts.gstatic.com domains both on the public website and in the Panel; the provider may receive technical connection data, including IP address and browser information. |
| Entities providing technical, legal or accounting services | Where necessary for conducting the business and operating Entiway. |
| Public authorities | Solely in the cases and to the extent arising from applicable law. |
7. Transfers of data outside the EEA
The core infrastructure of Entiway is maintained on servers located in the European Economic Area.
In connection with the use of third-party services, in particular Cloudflare, Paddle and Google, certain technical data may be processed outside the EEA. Transfers take place on the basis of the mechanisms provided for in Chapter V of the GDPR – European Commission decisions confirming an adequate level of protection, or standard contractual clauses applied by those providers.
8. Data retention periods
The Controller stores data for no longer than is necessary to achieve the purpose of processing, in particular:
| Category of data | Retention period |
|---|---|
| Account data | Duration of the Agreement and 180 days from deactivation of the Account |
| Configuration data, Monitoring, Alert preferences, usage history | Duration of the Agreement and up to 180 days from deactivation of the Account |
| Wallet operation history and data related to settlements | Duration of the Agreement and the period arising from accounting and tax regulations |
| Web server logs | Subject to automatic rotation and permanently deleted after approximately 10 days (rotate 10) |
| Application logs | Subject to automatic rotation and permanently deleted after 14 days |
| API request logs visible in the Panel | Duration of the Agreement and up to 180 days from deactivation of the Account, together with the remaining Account data |
| Data from the contact form | For the duration of handling the matter, and thereafter for the period necessary to archive correspondence or defend against claims, no longer than 12 months, unless longer retention is justified by a specific matter |
| Data required by law | The period arising from those regulations |
After 180 days from deactivation, the Account and the associated data are permanently deleted, except for data that must be retained longer under the law or for the defence against claims.
9. Rights of data subjects
Data subjects have the following rights:
- access to data (Art. 15 GDPR),
- rectification of data (Art. 16 GDPR),
- erasure of data (Art. 17 GDPR) – a request submitted during the term of the Agreement results in its termination,
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on the legitimate interest of the Controller (Art. 21 GDPR),
- lodging a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland.
To exercise your rights, please contact the Controller at: [email protected]. The Controller responds without undue delay, no later than within one month of receiving the request.
10. Security
The Controller applies appropriate technical and organisational measures to protect data, in particular:
- encryption of connections using TLS,
- access control to resources, including restricting database access to authorised addresses,
- mechanisms securing login and sessions,
- storing passwords in the form of cryptographic hashes,
- storing API Tokens in hashed form – if a Token is lost, a new one must be generated,
- limiting the scope of processed data to the minimum necessary for the operation of the service.
11. Analytics on the public website
On the public website entiway.com the Controller uses its own, self-hosted instance of Matomo Analytics, installed on a private server of the Controller, configured in cookieless mode (disableCookies) and with IP address anonymisation enabled, solely for the purpose of producing aggregated traffic statistics and improving the operation of the website. The statistical data is aggregated only and is not linked to identified natural persons. Analytics data is processed on the infrastructure of the Controller and is not transferred to third parties.
Legal basis: Art. 6(1)(f) GDPR – legitimate interest consisting in maintaining aggregated audience statistics and improving the website.
Analytics is not used in the Panel app.entiway.com or in api.entiway.com.
Technical details are described in the Cookie Policy.
12. Persons to whom Registry Data relates
12.1. Source and scope of the data
Entiway makes available data of business entities sourced exclusively from publicly available state registers. The Controller does not obtain this data directly from the persons concerned, nor from any non-public sources.
To the extent that this data relates to natural persons conducting business activity, it constitutes personal data. This data is public by operation of the provisions governing the functioning of the relevant registers, because in the case of this form of business activity the natural person is at the same time the business entity.
Data of natural persons acting as representatives of entities with separate legal personality is made available by the source registers in anonymised or masked form and is obtained and stored by the Controller in that form. The Controller does not reconstruct, supplement or enrich this data from other sources.
12.2. Purposes and legal basis
Purposes of processing:
- making Registry Data available to Users via the Panel and the API,
- detecting and presenting changes in Registry Data within the Monitoring functionality,
- maintaining the currency and integrity of the data resource.
Legal basis: Art. 6(1)(f) GDPR – the legitimate interest of the Controller and of the recipients of the data, consisting in making available and using information that is public in state registers in the course of business, in particular for the purpose of verifying counterparties and preventing abuse.
12.3. Scope of the information obligation
The data is not collected from the persons concerned but from public state registers. This section constitutes the fulfilment of the information obligation referred to in Art. 14 GDPR, to the extent that providing individual information would involve a disproportionate effort within the meaning of Art. 14(5)(b) GDPR – given the scale of the resource and the public nature of the source.
12.4. Role of the User
Upon obtaining Registry Data through Entiway, the User becomes a separate controller of that data. The Controller does not then act as a processor on behalf of the User and is not responsible for the further use of the data in the systems of the User.
The User is independently responsible in particular for having their own legal basis for processing, fulfilling the information obligation towards the data subjects, handling requests from those persons and securing the data in their own infrastructure. Detailed rules are set out in §7 of the Terms of Service.
12.5. Rights and retention period
Persons to whom Registry Data relates have the rights indicated in point 9, including the right to object to processing based on legitimate interest. Requests should be sent to [email protected].
At the same time, because the data originates from public registers and is public in them, rectification of the content of an entry is possible only with the authority maintaining the relevant register. The Controller reflects the state of the source register and takes its changes into account in subsequent processing cycles.
The data is stored for as long as it remains public in the source state register and for as long as the purpose indicated in point 12.2 continues.
13. Changes to the Privacy Policy
The Controller may update this Privacy Policy in the event of changes to the law, technologies, the manner in which Entiway operates, or the scope of data processing.
A new version is published on the relevant website together with a version number and effective date. In the case of material changes, Users are additionally informed electronically or by a notice within the service, at least 14 days in advance.