PRIVACY POLICY OF THE FLABER SERVICE
Version: 18 September 2026. Date of publication: 18 September 2026.
English translation. This is a translation of the Polish original for information. The Polish version is the binding one; in the event of any discrepancy, the Polish version prevails.
This Policy explains what personal data we process in connection with the Flaber Service, for what purpose, for how long and what you can do about it. Every statement it contains corresponds to the actual state of the Service as at the date indicated above.
The Policy has its own version marking, independent of the Terms: it informs, it does not create a contractual obligation, so a change to it does not trigger the procedure under §17 of the Terms.
This section summarises the document. The binding text is the text of the paragraphs below — the summary neither limits nor extends anything.
The controller of the personal data processed in connection with the Flaber Service is:
Piotr Nowak, a natural person address for service: ul. Cystersów 8/47, 31-553 Kraków, Poland
The Service is provided free of charge, and the Controller does not conduct business activity in its scope and is not entered in the register of entrepreneurs. These details are identical to §1 of the Terms; a change to them is a change to the Terms and takes place under the procedure in its §17.
Hereinafter: "Flaber", "we" or "the Controller".
In all matters concerning personal data, privacy, data security and the exercise of GDPR rights you write to:
kontakt@profilon.pl
We conduct contact by electronic mail. We do not run a telephone helpline.
We have not appointed a data protection officer. None of the conditions of Article 37(1) GDPR applies: we are not a public authority, our activity does not consist in monitoring people on a large scale or in large-scale processing of special categories of data. Should we appoint one, the contact details will appear in this place.
Words written with a capital letter — Service, Account, Workshop, Book, Team, Company, Package, Team Lead, Seat, Trial period — have the meaning given to them in §2 of the Terms.
This is the key to the whole document. In one part of the Service we decide about your data, in the other we carry out only someone else's instructions — and who you write to and who is responsible depends on this.
| Data | Who decides on the purpose | Our role |
|---|---|---|
| Account: e-mail address, password, first name, job title | we | controller |
| Register of administrative acts | we | controller |
| Application error log | we | controller |
| Requests addressed to us by e-mail | we | controller |
| Collaboration dimensions saved with your Account | we | controller |
| The Book: person cards, conversations, arrangements, goals, reports | the client | processor |
| Personal data in work documents | the client | processor |
If you want access to Account data, deletion of the Account or a copy of an error record — you write to us and we answer. If the matter concerns records kept about you in someone else's Book, the controller is the person or company that keeps them, and we may only assist them. The rules of that assistance are set out in Annex 1 to the Terms (the data processing agreement).
The same person and the same e-mail address may appear in both roles at once.
An example: the address you log in with is processed by us as controller — because we decided that an Account requires an address. The same address entered by your superior on your card in the Book is processed by us as processor — because it was they who decided that they want you there.
That is why who you address your request to, and who will take the decision, depends not on whose data it is, but on the context in which it is processed.
Separately on the collaboration dimensions. They arise in a sister service, the person fills them in themselves, shares them themselves and copies the result into the form on their own Account themselves — the Team Lead has view access only, with no right to write, which the database enforces. Within the boundaries of Flaber we are their controller on the basis of the contract for the provision of the Service.
When you create an Account, complete it, use the Service, write to us or report a problem.
If someone invited you to a Team or entered you into their Book, your first name, job title and e-mail address come from them.
We do not check whether they had grounds to do so — and we have no technical means of making such a check. They are responsible for it (§10(4) of the Terms). The obligation to inform you about the processing also rests on them, not on us (§10(6) of the Terms).
The date of last login — one date, overwritten. Entries in the register of acts. The error record. We describe them in §4.5 and §4.6.
We do not buy lists, we do not enrich profiles, we do not download data from social networks. We do not obtain data from any external sources.
What: e-mail address (which is also the login), password in the form of an irreversible hash, first name, optionally job title. In addition, the date of last login — one date, overwritten — and a record of which version of the Terms you accepted and when.
What for: provision of the Service, authentication, contact in Account matters and, in the case of the version of the Terms, the ability to demonstrate what was in force.
Basis: Article 6(1)(b) GDPR (performance of a contract). For the record of acceptance of the Terms also Article 6(1)(c) and (f) — demonstrating compliance and defence against a claim.
Do you have to provide it: e-mail address — yes, without it the Account will not be created. Job title is optional.
What: the content of notes, day lists, procedures, templates, the Scratchpad and uploaded files.
We do not read them. Access on our side takes place solely to the extent necessary to remove a malfunction, carry out your request or perform a legal obligation (§10(2) of the Terms, §4 of Annex 1).
Artificial intelligence: no. Content is not passed to language models, is not analysed by them and does not serve to train them. There is not a single such dependency in the Service. Were a function of this kind ever to arise, it would require a separate description and an update of this Policy — it does not fit within the present wording.
If your documents contain data of other people, in that scope we are a processor, and the rules are set out in Annex 1.
What: the first name and job title of the person, the content of notes, the course of conversations, arrangements, goals, summaries and reports.
In this scope we are a processor, and the basis of processing is indicated by the controller, that is the client (§10(4)–(5) of the Terms).
Special categories of data must not be entered into the Service (§9(5) of the Terms). This concerns data about health — including sick notes, pregnancy and disability certificates — political and religious views, trade union membership, racial and ethnic origin, sex life and sexual orientation, biometric and genetic data as well as criminal convictions and offences. The Service does not ask for such data, has no field for it and is not intended for storing it.
What: four dimensions describing the style of collaboration, from which a type is calculated.
The source is you yourself. They arise in a sister service in which you fill them in for yourself, and they reach Flaber because you share them. You copy the result into the form yourself, on your own Account — there is no automatic transfer today.
The Team Lead does not assess the dimensions and does not complete them on the basis of their own observations. They have view access only, and the absence of the right to write is enforced by the database, not by a setting in the interface.
The dimensions are saved with your Account, not in someone else's Book. They remain after you are removed from the Book — the Team Lead has no right to delete them. They cease when you delete them yourself or delete the Account. They do not enter the Team Lead's export file, even though they are visible on screen.
Basis: Article 6(1)(b) — a function of the Service that you activate by your own act of sharing.
We record the fact of an act, never of a read. The following are recorded: granting, withdrawal and rejection of sharing; creation, acceptance, revocation and expiry of an invitation; granting, release and restoration of a Seat; creation and dissolution of a Team; change of Team Lead; change of Package; deletion of a document, including a private one; billing acts; suspension and unsuspension of an Account.
What an entry contains: the identifier of the person performing the act, the identifier of the person the act concerned, and the e-mail addresses of both parties recorded at the moment of the act — so that the register says who did what, also after an Account has been deleted. The address disappears immediately upon deletion of the Account, leaving the identifier alone (§13(4) of the Terms).
What for: resolving disputes about access and demonstrating who granted or withdrew a permission from whom. Basis: Article 6(1)(f) — our and your legitimate interest in the existence of evidence.
Suspending and unsuspending an Account requires a reason to be given, and the reason is a free statement by a human being about someone else's Account, recorded verbatim. It is written by the Provider, in an act performed solely for a breach of §9 of the Terms. We point out three circumstances:
Basis: Article 6(1)(f) — demonstrating that the act was justified and defence against a claim in respect of the cutting off of access.
If an application error occurs, we record: the moment of occurrence, the Account it concerned, the part of the Service in which it arose, and the content of the error — the message and the stack trace. Only we have access to the log.
Three circumstances require explicit statement:
You have no view of your own error records in the application. You receive a case number and an indication of the route of contact. This solution is deliberate: a raw database message could itself disclose data. We issue a copy of the record on request (§9).
Basis: Article 6(1)(f) — maintaining the Service and removing its defects.
Adding a person to the Book always requires their e-mail address, but whether anything goes out to them depends on the Package (§11(3) of the Terms):
The controller of this data is the client, not us; we carry out the sending. For the mere storage of the address in an invitation that never led to an Account, the basis on our side is Article 6(1)(f) — consistency of the record of permissions granted and withdrawn.
The request form opens from Settings and from two emergency screens: after an application error and from the withdrawn-access screen. The message carries the subject, free text, the Account address, the Account identifier, the language and the case number.
We do not save it in our database. Until it is deleted it remains solely on the side of the e-mail provider (§7(5)). This has an important consequence: requests concerning data are handled by the same route — the content of the request therefore passes through a subcontractor and remains there.
A copy confirming dispatch reaches you automatically and does not contain the content of the request. It confirms delivery, it does not replace our answer; the deadlines under §9 run independently of it.
Basis: Article 6(1)(b) and (c) — servicing the contract and performing obligations under the GDPR.
Inside the Service there is a notification inbox. It informs you that someone shared a document with you or withdrew the sharing, submitted or withdrew a proposed change, accepted or rejected your proposal, handed a document over to you or took over yours.
The inbox concerns Workshop documents only — notes, checklists and their completions. Events concerning the Book, invitations and Seats do not create any entry in it; about those we inform you differently or not at all (§4.7).
What an entry contains: the identifier of the person who performed the act, the identifier of the recipient, the type of event and a snapshot of the document's title from the moment of the event — the title remains as it was then, even if the document was later renamed or deleted. The inbox does not contain the content of documents or records from the Book.
We store entries for 90 days, after which an automated job deletes them (§7). They enter the export file on the terms set out in §9(3) — like the rest of the Account administration, that is not in every type of Account.
Basis: Article 6(1)(b) — without a notification you would not know that someone had granted you access, and Article 6(1)(f) to the extent that the entry constitutes a trace of an event.
https://profilon.pl/flaber/podprocesorzy. It is a separate document so that a change of provider does not require a change of the contract with you. We notify you by electronic mail of an intention to add or change a subprocessor at least 14 days in advance (§6 of Annex 1).The distinction matters: automatic deletion after the lapse of time operates for four categories. The rest of the data lives until someone deletes it by a deliberate act.
| Data | Period | What enforces it |
|---|---|---|
| Register of administrative acts | 12 months | automated job, daily |
| Revoked and unfinished invitations | 12 months | automated job, daily |
| Event inbox (notifications) | 90 days | automated job, daily |
| Application error log | 90 days | automated job, daily |
| Account and Account data | until revoked | your act or request — §9 |
| Workshop and work documents | until revoked | your act |
| A person in the Book together with their history | until revoked | act of the client; no automated job |
| A person archived in the Book | indefinitely | archiving is reversible; deletion is a separate act |
| Database backups | 7 days, with rotation | policy of the infrastructure provider |
| Hosting request logs | 1 day | policy of the hosting provider |
| Message content at the e-mail provider | 30 days | policy of the e-mail provider |
| Register of requests made and answers | 3 years from closure of the case | manual review, not an automated job |
To the extent that we are the controller of your data (§2), you have the right to:
To kontakt@profilon.pl. We may ask for additional information if it is needed to confirm your identity. The purpose is to avoid releasing your data to an unauthorised person.
We state them separately, because when combined in a single paragraph they are sometimes read as a single deadline.
| Clock | Deadline |
|---|---|
| Confirmation of receipt of a request | within 72 hours on working days |
| Carrying out the request | without undue delay, no later than within one month |
The deadline for carrying out the request may be extended on the terms set out in Article 12(3) GDPR if the matter is particularly complex — we will inform you of this together with the reason.
We do not declare a deadline shorter than the law requires. At the same time we point out a limitation: administrative access to the infrastructure is held today by one person on our side. The declared deadline determines the waiting time; it does not mean that someone else will handle the request.
You download a file with your data yourself from Settings.
The file includes — subject to the paragraph on structure below — Workshop documents of which you are the author (notes, checklists, procedures, templates), the Scratchpad, private labels, your own collaboration dimensions result and the Account metadata sheet.
The file never includes, regardless of the type of Account: the Book, documents shared with you by other people (only those of which you are the author go out) and the error log.
The rest depends on the structure in which you operate:
After each omitted category the file carries an explicit marker in that place, and the metadata sheet contains a description of the scope written out in words — from the file itself you learn what is not in it and why.
The narrowing concerns the content of the file, not the right of access. A full request we handle by the route in paragraph 1, within the deadlines in paragraph 2. The narrowing of self-service is defensible solely because that route exists.
The narrowing does not hide data within the application itself. The anchor of access to a document remains its author, and the Company or Team marker carries billing, not visibility — your own notes from the period of working in a Company you open and edit unchanged, until the Account is deleted.
Uploaded files and images do not enter the export — download them separately before deleting the Account. We warn you about this on the deletion screen.
It does not cover person cards, conversations, goals or reports — including approved ones — or the collaboration dimensions of other people. There is one reason: a Team Lead leaving an organisation must not take with them the data of the people they led.
On their own, from Settings, an Account is deleted by a User without a Team and by a Team Lead running their own Team outside a Company structure. The deletion is immediate and irreversible.
By request, by the route in paragraph 1, an Account is deleted by: a member of someone else's Team, a User of an Account belonging to a Company and a Company administrator. The model is the same as with work tools: access is granted and withdrawn by the person running the Team or by the Company. This is the only place in which the carrying out of your request depends on our reaction and not on your click — which is why we describe the channel and the deadline here, instead of referring you to a button that does not exist.
Deletion of an Account covers Account data, the Workshop and the Book. It does not cover documents handed over to other people or to the Team, or entries in the register of acts.
After the Trial period lapses, the Book passes into a read state and you will not correct an existing record (§6(8) of the Terms). In this state rectification is carried out by us, at the controller's request, within the deadlines in paragraph 2 — in accordance with §8(6) of Annex 1.
Suspension does not take your rights away from you. A suspended Account does not log in, so you will not download the data yourself — we prepare it on request, within the deadlines in paragraph 2.
How to reach the contact address: entering the correct password on the login screen will display the message about the suspension together with the address. If you do not remember your password, use recovery — the message will go out and the link will lead you to the same message. With an incorrect password you will see the ordinary message about a failed login and we do this deliberately: otherwise the screen would confirm to an outsider that a given Account exists and has been suspended.
You also have the right to learn the reason for the suspension; we provide it with information about other people redacted (§12(4)–(5) of the Terms).
This paragraph concerns people who do not necessarily have an Account with us, but whose data was entered into the Service by a client — an employer, a company, a superior or a co-worker.
Not us. You address a request for access, rectification, erasure and restriction to them. The obligation to inform you about the processing also rests on them. We, as processor, assist them in performing these obligations to the extent arising from Annex 1 to the Terms.
There is no account, role or screen through which a person kept in the Book would obtain access to it — such insight is not provided for in the construction of the Service. This does not mean that you do not have the right of access. It means that it is exercised by the controller, outside the application (§10(7) of the Terms, §8(5) of Annex 1).
We will not answer it on the merits — we will inform you of our role and of who it should be addressed to. What happens next depends on one circumstance:
The reason. There is no query that would return the content of the Book, and our operator console does not release the first names of people from Teams. This is exactly the same property thanks to which your employer or a Company administrator cannot read the Book. We point out this limitation instead of declaring a transfer that we would not be able to carry out.
No system rules out risk entirely. If a personal data breach is established, we act in accordance with the provisions of law and with the contracts with clients — including within the deadlines set out in §10 of Annex 1.
A client acting as controller receives the full list of technical and organisational measures as Annex B to Annex 1, together with the limitations named.
The Service is intended for adults (§4(2) of the Terms). By creating an Account, you declare that you are 18 years of age or older.
We do not direct the Service at children and we do not knowingly collect their data. Nor do we base the creation of an Account on a child's consent within the meaning of Article 8 GDPR — the basis is a contract concluded by an adult. If we learn that the data of a person below that age has reached the Service contrary to this rule, we will take appropriate action, including deletion of the data.
No marketing or analytics cookie operates here, and the only one we use is necessary for the provision of the Service — without it, logging in will not work. Such cookies do not require consent (Article 173(3) of the Polish Telecommunications Act (Prawo telekomunikacyjne)).
The application does not load any analytics tool. It does not measure behaviour, does not create an identifier between sessions, does not embed third-party scripts for advertising purposes. We serve fonts from our own domain — the browser does not connect to external servers for that purpose.
Below we indicate what your browser connects to beyond our address. There are two such connections and both lead to our subprocessors, not to advertisers:
Neither of them embeds an advertising script or a cross-site identifier. Both providers are on the list of subprocessors referred to in §5(3).
| Name | Who sets it | What for | How long |
|---|---|---|---|
sb-<identifier>-auth-token (split into parts where the token is longer) | the authentication provider; we save it without changing its parameters | maintaining a logged-in session | 7 days from last activity, at most 30 days |
This is the only cookie in the application. We do not set any of our own.
How session time is counted. The login credential is renewed automatically every hour for as long as you use the Service. The session expires if you do not enter the application for 7 days, and irrespective of activity it ends after 30 days. You can end it earlier by logging out.
Apart from the cookie, we save view settings on your device, so that when you open the application again it keeps the layout you set. This data is not sent to us and is not read by us — it lies solely in your browser.
| Key | What it holds | When it disappears |
|---|---|---|
pcg:lastView:<person card identifier> | the tab last opened on a person card | until browser data is cleared |
pcg:ckTab | the tab last opened on Checklists | as above |
sb-collapsed | whether the side panel is collapsed | as above |
dock-w | the width of the side panel | as above |
notes-filter, checklists-filter:<variant> | the selected view filter | on closing the browser tab |
One item requires an explicit sentence: the key pcg:lastView carries in its name the identifier of the person card that you opened. It does not contain their first name or any content, but it is a record connected with a specific person and it stays on the device until browser data is cleared. You can delete it at any moment in your browser settings — the application will recreate it on the next use and you lose nothing by doing so.
We treat these records as necessary for the provision of the Service that you yourself requested (Article 173(3) of the Polish Telecommunications Act), and that is why we do not ask for consent: they are not sent to us, they do not create a cross-site identifier, they do not serve measurement or advertising and content cannot be reconstructed from them.
Every system message embeds our logotype as a remote image. Opening the message causes a request to the server, so your IP address, browser and the moment of opening reach the hosting logs. The resource is our own, it does not belong to a third party and it does not serve tracking, but the effect is the same as with a tracking pixel. The logs are stored for 1 day (§7). This also concerns people who will never create an Account — because they received only an invitation.
If you do not want this effect, disable automatic downloading of images in your e-mail programme.
We do not record IP addresses in our database. There is no table, log or call in the application code that would record them; before sending an error report we remove from it the headers carrying the IP address as well as cookies and authentication data. The authentication event log does not store them either — the column in which they could arise remains empty.
The IP address does, however, reach the request logs at the hosting provider, where it is stored for one day, and is visible in the connection to the error log provider — which does not store it, because recording is disabled on their side. The report is sent directly from your browser, so the address is visible at the transport level and no code of ours will change that. We write "is not stored", not "does not reach the provider" — these are not the same thing.
Ours requires a logged-in session, theirs does not — it therefore also covers errors on invitation screens, in the case of people who will never create an Account. We point this out separately, because it is the only situation in which the browser of a person who is not our User connects to a third party.
Flaber's sales website sits in a separate project, uses its own tools and has no access to Service data. A separate cookie notice applies to it — §15.
| Document | Address |
|---|---|
| Terms of Service of the Flaber Service | https://profilon.pl/flaber/regulamin |
| Annex 1 to the Terms — the data processing agreement | https://profilon.pl/flaber/powierzenie |
| Flaber Subprocessors (dated, updated independently) | https://profilon.pl/flaber/podprocesorzy |
| Cookie notice for the sales website | https://profilon.pl/cookies |
Controller: Piotr Nowak E-mail address: kontakt@profilon.pl Postal address: ul. Cystersów 8/47, 31-553 Kraków, Poland
| Date | Change |
|---|---|
| 18 September 2026 | First publication. |