Privacy Policy

PRIVACY POLICY OF THE FLABER SERVICE

Version: 18 September 2026. Date of publication: 18 September 2026.

English translation. This is a translation of the Polish original for information. The Polish version is the binding one; in the event of any discrepancy, the Polish version prevails.

This Policy explains what personal data we process in connection with the Flaber Service, for what purpose, for how long and what you can do about it. Every statement it contains corresponds to the actual state of the Service as at the date indicated above.

The Policy has its own version marking, independent of the Terms: it informs, it does not create a contractual obligation, so a change to it does not trigger the procedure under §17 of the Terms.

In brief

This section summarises the document. The binding text is the text of the paragraphs below — the summary neither limits nor extends anything.

  • We are the controller of your Account data. E-mail address, password in the form of an irreversible hash, first name, optionally job title, date of last login.
  • Records about other people — the Book — belong to the client who keeps them. We only store them. Who you address your request to depends on this.
  • We do not measure your work. We do not record what you read or for how long. There is no dashboard for a superior or for HR, there are no rankings. We do not profile you and we do not take decisions automatically.
  • We do not subject your content to artificial-intelligence analysis. No note is passed to a language model — there is not a single such dependency in the Service.
  • We do not sell data and we do not share it for marketing purposes.
  • We use four providers. The database, the files and the application run in Ireland. The e-mail provider stores data in the United States, irrespective of the sending region.
  • Retention periods: register of acts 12 months, notifications 90 days, error log 90 days, backups 7 days, message content at the e-mail provider 30 days. Your content — until you delete it yourself.
  • You exercise your rights by writing to kontakt@profilon.pl. We confirm receipt within 72 hours on working days and we act no later than within one month.
  • Three limitations that we state explicitly. Deleted data remains for a further 7 days in backups. An error message may quote the value that triggered it — a surname, for example. We do not use end-to-end encryption; content is stored in the database in plain form.
  • If someone keeps records about you and you do not have an Account with us — you address your request to them. If it reaches us, we will not find them ourselves: there is no query that would return the content of the Book. This is the same property thanks to which your employer cannot read it.

§1. Data controller and contact

1. Who is responsible for the data

The controller of the personal data processed in connection with the Flaber Service is:

Piotr Nowak, a natural person address for service: ul. Cystersów 8/47, 31-553 Kraków, Poland

The Service is provided free of charge, and the Controller does not conduct business activity in its scope and is not entered in the register of entrepreneurs. These details are identical to §1 of the Terms; a change to them is a change to the Terms and takes place under the procedure in its §17.

Hereinafter: "Flaber", "we" or "the Controller".

2. Contact

In all matters concerning personal data, privacy, data security and the exercise of GDPR rights you write to:

kontakt@profilon.pl

We conduct contact by electronic mail. We do not run a telephone helpline.

3. Data Protection Officer

We have not appointed a data protection officer. None of the conditions of Article 37(1) GDPR applies: we are not a public authority, our activity does not consist in monitoring people on a large scale or in large-scale processing of special categories of data. Should we appoint one, the contact details will appear in this place.

4. Defined terms

Words written with a capital letter — Service, Account, Workshop, Book, Team, Company, Package, Team Lead, Seat, Trial period — have the meaning given to them in §2 of the Terms.

§2. When we are a controller and when we are a processor

This is the key to the whole document. In one part of the Service we decide about your data, in the other we carry out only someone else's instructions — and who you write to and who is responsible depends on this.

1. The division

DataWho decides on the purposeOur role
Account: e-mail address, password, first name, job titlewecontroller
Register of administrative actswecontroller
Application error logwecontroller
Requests addressed to us by e-mailwecontroller
Collaboration dimensions saved with your Accountwecontroller
The Book: person cards, conversations, arrangements, goals, reportsthe clientprocessor
Personal data in work documentsthe clientprocessor

2. What follows from this

If you want access to Account data, deletion of the Account or a copy of an error record — you write to us and we answer. If the matter concerns records kept about you in someone else's Book, the controller is the person or company that keeps them, and we may only assist them. The rules of that assistance are set out in Annex 1 to the Terms (the data processing agreement).

3. Why this distinction matters

The same person and the same e-mail address may appear in both roles at once.

An example: the address you log in with is processed by us as controller — because we decided that an Account requires an address. The same address entered by your superior on your card in the Book is processed by us as processor — because it was they who decided that they want you there.

That is why who you address your request to, and who will take the decision, depends not on whose data it is, but on the context in which it is processed.

Separately on the collaboration dimensions. They arise in a sister service, the person fills them in themselves, shares them themselves and copies the result into the form on their own Account themselves — the Team Lead has view access only, with no right to write, which the database enforces. Within the boundaries of Flaber we are their controller on the basis of the contract for the provision of the Service.

§3. Where we get your data from

1. Directly from you

When you create an Account, complete it, use the Service, write to us or report a problem.

2. From the client who added you

If someone invited you to a Team or entered you into their Book, your first name, job title and e-mail address come from them.

We do not check whether they had grounds to do so — and we have no technical means of making such a check. They are responsible for it (§10(4) of the Terms). The obligation to inform you about the processing also rests on them, not on us (§10(6) of the Terms).

3. From the operation of the system

The date of last login — one date, overwritten. Entries in the register of acts. The error record. We describe them in §4.5 and §4.6.

4. Where we do not take data from

We do not buy lists, we do not enrich profiles, we do not download data from social networks. We do not obtain data from any external sources.

§4. What data we process, for what purpose and on what basis

4.1 Account data

What: e-mail address (which is also the login), password in the form of an irreversible hash, first name, optionally job title. In addition, the date of last login — one date, overwritten — and a record of which version of the Terms you accepted and when.

What for: provision of the Service, authentication, contact in Account matters and, in the case of the version of the Terms, the ability to demonstrate what was in force.

Basis: Article 6(1)(b) GDPR (performance of a contract). For the record of acceptance of the Terms also Article 6(1)(c) and (f) — demonstrating compliance and defence against a claim.

Do you have to provide it: e-mail address — yes, without it the Account will not be created. Job title is optional.

4.2 The Workshop and work documents

What: the content of notes, day lists, procedures, templates, the Scratchpad and uploaded files.

We do not read them. Access on our side takes place solely to the extent necessary to remove a malfunction, carry out your request or perform a legal obligation (§10(2) of the Terms, §4 of Annex 1).

Artificial intelligence: no. Content is not passed to language models, is not analysed by them and does not serve to train them. There is not a single such dependency in the Service. Were a function of this kind ever to arise, it would require a separate description and an update of this Policy — it does not fit within the present wording.

If your documents contain data of other people, in that scope we are a processor, and the rules are set out in Annex 1.

4.3 The Book

What: the first name and job title of the person, the content of notes, the course of conversations, arrangements, goals, summaries and reports.

In this scope we are a processor, and the basis of processing is indicated by the controller, that is the client (§10(4)–(5) of the Terms).

Special categories of data must not be entered into the Service (§9(5) of the Terms). This concerns data about health — including sick notes, pregnancy and disability certificates — political and religious views, trade union membership, racial and ethnic origin, sex life and sexual orientation, biometric and genetic data as well as criminal convictions and offences. The Service does not ask for such data, has no field for it and is not intended for storing it.

4.4 Collaboration dimensions

What: four dimensions describing the style of collaboration, from which a type is calculated.

The source is you yourself. They arise in a sister service in which you fill them in for yourself, and they reach Flaber because you share them. You copy the result into the form yourself, on your own Account — there is no automatic transfer today.

The Team Lead does not assess the dimensions and does not complete them on the basis of their own observations. They have view access only, and the absence of the right to write is enforced by the database, not by a setting in the interface.

The dimensions are saved with your Account, not in someone else's Book. They remain after you are removed from the Book — the Team Lead has no right to delete them. They cease when you delete them yourself or delete the Account. They do not enter the Team Lead's export file, even though they are visible on screen.

Basis: Article 6(1)(b) — a function of the Service that you activate by your own act of sharing.

4.5 Register of administrative acts

We record the fact of an act, never of a read. The following are recorded: granting, withdrawal and rejection of sharing; creation, acceptance, revocation and expiry of an invitation; granting, release and restoration of a Seat; creation and dissolution of a Team; change of Team Lead; change of Package; deletion of a document, including a private one; billing acts; suspension and unsuspension of an Account.

What an entry contains: the identifier of the person performing the act, the identifier of the person the act concerned, and the e-mail addresses of both parties recorded at the moment of the act — so that the register says who did what, also after an Account has been deleted. The address disappears immediately upon deletion of the Account, leaving the identifier alone (§13(4) of the Terms).

What for: resolving disputes about access and demonstrating who granted or withdrew a permission from whom. Basis: Article 6(1)(f) — our and your legitimate interest in the existence of evidence.

The reason for an Account suspension — the only free text about a person

Suspending and unsuspending an Account requires a reason to be given, and the reason is a free statement by a human being about someone else's Account, recorded verbatim. It is written by the Provider, in an act performed solely for a breach of §9 of the Terms. We point out three circumstances:

  • it is also visible to the administrator of the Company to which the Account belongs (§12(8) of the Terms);
  • you do not see it in the application, because a suspended Account will not log in — but you have the right to learn it and we provide it at your request, with information about other people redacted (§12(4) of the Terms);
  • it is stored for 12 months, like the rest of the register.

Basis: Article 6(1)(f) — demonstrating that the act was justified and defence against a claim in respect of the cutting off of access.

4.6 Application error log

If an application error occurs, we record: the moment of occurrence, the Account it concerned, the part of the Service in which it arose, and the content of the error — the message and the stack trace. Only we have access to the log.

Three circumstances require explicit statement:

  • The page address is masked before it is recorded. We record a pattern, not a specific address — neither the identifier of a person card nor the one-time key from an invitation link reaches the log.
  • The stack trace carries the names of functions and files, never values entered by a human being.
  • An error message may contain a fragment of your data. A database message about a duplicate may quote the value that triggered it — a surname, for example. This circumstance cannot be ruled out.

You have no view of your own error records in the application. You receive a case number and an indication of the route of contact. This solution is deliberate: a raw database message could itself disclose data. We issue a copy of the record on request (§9).

Basis: Article 6(1)(f) — maintaining the Service and removing its defects.

4.7 The address of a person who does not have an Account

Adding a person to the Book always requires their e-mail address, but whether anything goes out to them depends on the Package (§11(3) of the Terms):

  • The Team Package — an invitation is created and goes out by e-mail together with the first name of the inviting person and the name of the Team. The person learns about everything at the moment of being added.
  • The Leader Package — no message goes out, neither then nor later. The person card is created immediately, the address is saved on a held entry, and the invitation link remains inactive.

The controller of this data is the client, not us; we carry out the sending. For the mere storage of the address in an invitation that never led to an Account, the basis on our side is Article 6(1)(f) — consistency of the record of permissions granted and withdrawn.

4.8 Contact and requests

The request form opens from Settings and from two emergency screens: after an application error and from the withdrawn-access screen. The message carries the subject, free text, the Account address, the Account identifier, the language and the case number.

We do not save it in our database. Until it is deleted it remains solely on the side of the e-mail provider (§7(5)). This has an important consequence: requests concerning data are handled by the same route — the content of the request therefore passes through a subcontractor and remains there.

A copy confirming dispatch reaches you automatically and does not contain the content of the request. It confirms delivery, it does not replace our answer; the deadlines under §9 run independently of it.

Basis: Article 6(1)(b) and (c) — servicing the contract and performing obligations under the GDPR.

4.9 Event inbox

Inside the Service there is a notification inbox. It informs you that someone shared a document with you or withdrew the sharing, submitted or withdrew a proposed change, accepted or rejected your proposal, handed a document over to you or took over yours.

The inbox concerns Workshop documents only — notes, checklists and their completions. Events concerning the Book, invitations and Seats do not create any entry in it; about those we inform you differently or not at all (§4.7).

What an entry contains: the identifier of the person who performed the act, the identifier of the recipient, the type of event and a snapshot of the document's title from the moment of the event — the title remains as it was then, even if the document was later renamed or deleted. The inbox does not contain the content of documents or records from the Book.

We store entries for 90 days, after which an automated job deletes them (§7). They enter the export file on the terms set out in §9(3) — like the rest of the Account administration, that is not in every type of Account.

Basis: Article 6(1)(b) — without a notification you would not know that someone had granted you access, and Article 6(1)(f) to the extent that the entry constitutes a trace of an event.

4.10 What we do not do

  • We do not profile you and we do not take decisions in relation to you by automated means within the meaning of Article 22 GDPR.
  • We do not measure your work. We do not record what you read or for how long. There is no dashboard for a superior or for HR, there are no indicators, assessments or rankings.
  • We do not sell data and we do not share it for marketing purposes with any entity.
  • We do not keep visit statistics in the application. The application does not load any analytics tool. Statistics concern only the sales website, which sits in a separate project and has no access to Service data.

§5. Who we pass data to

  • 1. We use entities that process data in our name and on our instructions. We have a data processing agreement with each of them, and we are liable for their actions as for our own.
  • 2. Today there are four entities: the provider of the database, authentication and files; the hosting provider; the system e-mail provider; the error log provider.
  • 3. The current list — with the role of each entity, the place of processing and the basis for transfer outside the EEA — constitutes a separate, dated page: https://profilon.pl/flaber/podprocesorzy. It is a separate document so that a change of provider does not require a change of the contract with you. We notify you by electronic mail of an intention to add or change a subprocessor at least 14 days in advance (§6 of Annex 1).
  • 4. We do not use a payment provider today. There is no place in the Service where card details can be entered (§7 of the Terms). A payment provider will reach the list under paragraph 3 on the day on which it processes the first payment — not earlier.
  • 5. We may pass data to public authorities if the obligation arises from a provision binding on us. We will inform you before the transfer, unless the law prohibits it.

§6. Transfer of data outside the European Economic Area

  • 1. The database, files, authentication and execution of the application run in Ireland. The error log is kept in a European region, in Germany.
  • 2. One exception concerns the handling of outgoing e-mail. The provider sends messages from Ireland, but stores its account data, message metadata, journals and logs in the United States, irrespective of the sending region selected. This concerns the content of invitations, which contain the e-mail address of the invited person, the first name of the inviting person and the name of the Team — also where that person never creates an Account. Your requests to us travel by the same route.
  • 3. Providers operating in the EEA may obtain access to data from outside the EEA to the extent necessary to maintain the infrastructure.
  • 4. We indicate the basis of transfer separately for each entity on the page referred to in §5(3), because not all of them rely on the same one. They are the standard contractual clauses adopted by European Commission Decision 2021/914 and, with some providers, certification under the EU–U.S. Data Privacy Framework. One of the providers does not participate in that programme and with it we rely solely on the clauses.
  • 5. We do not claim that no transfer outside the EEA takes place. Such a claim would be untrue.

§7. How long we store data

The distinction matters: automatic deletion after the lapse of time operates for four categories. The rest of the data lives until someone deletes it by a deliberate act.

DataPeriodWhat enforces it
Register of administrative acts12 monthsautomated job, daily
Revoked and unfinished invitations12 monthsautomated job, daily
Event inbox (notifications)90 daysautomated job, daily
Application error log90 daysautomated job, daily
Account and Account datauntil revokedyour act or request — §9
Workshop and work documentsuntil revokedyour act
A person in the Book together with their historyuntil revokedact of the client; no automated job
A person archived in the Bookindefinitelyarchiving is reversible; deletion is a separate act
Database backups7 days, with rotationpolicy of the infrastructure provider
Hosting request logs1 daypolicy of the hosting provider
Message content at the e-mail provider30 dayspolicy of the e-mail provider
Register of requests made and answers3 years from closure of the casemanual review, not an automated job
  • 1. Why 12 months. The register of acts serves to resolve disputes about access, and those arise within a horizon of weeks. A year covers a full cycle of a team's work with a margin.
  • 2. Why 3 years for the register of requests. We must be able to demonstrate that a request was dealt with (Article 5(2) GDPR), and claims connected with the conduct of business activity are time-barred after three years (Article 118 of the Polish Civil Code (Kodeks cywilny)). This period is not enforced by an automated job — we delete these records manually, as part of a review.
  • 3. A person's address: two different cases. An address to which an invitation went out and which never led to an Account we delete automatically after 12 months. An address entered on a person card in the Leader Package we store for as long as that card exists — automatic deletion does not cover it, because it would delete data that the client uses. It is deleted by the client, by deleting the card or their Account.
  • 4. Deleted data remains in backups for 7 days and is overwritten as they rotate. We have no means of deleting it from the backups earlier, so we do not issue a confirmation of deletion before that period elapses, because it would be untrue. The phrase "we delete immediately" would be inaccurate in this place.
  • 5. Message content at the e-mail provider: 30 days. This concerns both system messages that go out from us and requests that you address to us — including requests concerning data. The period covers the content of the message and its metadata, the delivery status and the provider's journals. Independently of this, the provider deletes all data within 90 days of the closure of our account with them.
  • 6. Before every change to the database structure a manual production dump is created. It is a file with the full content, outside the infrastructure provider's access mechanisms; it is created solely for the purposes of the migration, is stored on the Provider's device and is deleted manually after the correctness of the change has been verified. It is the least protected copy of data in the whole process and we indicate it in this list.
  • 7. Unused Accounts we delete after prior notification by electronic mail, as part of a periodic review (§13(7) of the Terms). We do not state a number of months here, because that period is not enforced by an automated job, and a deadline that nothing enforces would be a promise without cover.
  • 8. Data required by law — billing and accounting documentation — is stored for the period indicated by the applicable provisions.

§8. Your rights

To the extent that we are the controller of your data (§2), you have the right to:

  • 1. Access — information on whether we process your data, and access to it and to information about its processing.
  • 2. Rectification — correction of inaccurate data and completion of incomplete data. You will correct Account data yourself in Settings; that is the fastest route.
  • 3. Erasure — on the terms set out in the GDPR. It does not always mean the immediate disappearance of all copies: data remains in backups until the end of their rotation (§7(4)), and entries in the register of acts are stored for 12 months — save that we delete the e-mail address from them immediately, leaving the identifier alone.
  • 4. Restriction of processing — in the cases provided for by the GDPR.
  • 5. Data portability — receiving the data you provided to us in a machine-readable format. In practice this is carried out by the export described in §9(4).
  • 6. Objection — to processing based on legitimate interest (§4.5, §4.6, §4.7). We will consider it and will either cease the processing or demonstrate the existence of compelling legitimate grounds which override your interests.
  • 7. Withdrawal of consent — if a specific processing operation is based on consent. Withdrawal does not affect the lawfulness of what we did earlier.
  • 8. A complaint to the supervisory authority — the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warszawa. You do not have to write to us first — but if you do write, we will answer within the deadlines set out in §9.

§9. How to exercise your rights

1. Where to write

To kontakt@profilon.pl. We may ask for additional information if it is needed to confirm your identity. The purpose is to avoid releasing your data to an unauthorised person.

2. Deadlines for handling

We state them separately, because when combined in a single paragraph they are sometimes read as a single deadline.

ClockDeadline
Confirmation of receipt of a requestwithin 72 hours on working days
Carrying out the requestwithout undue delay, no later than within one month

The deadline for carrying out the request may be extended on the terms set out in Article 12(3) GDPR if the matter is particularly complex — we will inform you of this together with the reason.

We do not declare a deadline shorter than the law requires. At the same time we point out a limitation: administrative access to the infrastructure is held today by one person on our side. The declared deadline determines the waiting time; it does not mean that someone else will handle the request.

3. Access to data without writing to us: export from the application

You download a file with your data yourself from Settings.

The file includes — subject to the paragraph on structure below — Workshop documents of which you are the author (notes, checklists, procedures, templates), the Scratchpad, private labels, your own collaboration dimensions result and the Account metadata sheet.

The file never includes, regardless of the type of Account: the Book, documents shared with you by other people (only those of which you are the author go out) and the error log.

The rest depends on the structure in which you operate:

  • An independent Account — working alone or your own Team outside a Company structure — the file additionally contains the administration of your Account: the composition of the Team, Seats, invitations, sharings, proposed changes, the event inbox and the register of acts.
  • A member of someone else's Team and an Account within a Company structure — the file does not contain the administration, including the event inbox, or documents created within the Company or the Team. Documents from before joining and the remaining items listed above do go out.

After each omitted category the file carries an explicit marker in that place, and the metadata sheet contains a description of the scope written out in words — from the file itself you learn what is not in it and why.

The narrowing concerns the content of the file, not the right of access. A full request we handle by the route in paragraph 1, within the deadlines in paragraph 2. The narrowing of self-service is defensible solely because that route exists.

The narrowing does not hide data within the application itself. The anchor of access to a document remains its author, and the Company or Team marker carries billing, not visibility — your own notes from the period of working in a Company you open and edit unchanged, until the Account is deleted.

Uploaded files and images do not enter the export — download them separately before deleting the Account. We warn you about this on the deletion screen.

4. The export file never contains the Book

It does not cover person cards, conversations, goals or reports — including approved ones — or the collaboration dimensions of other people. There is one reason: a Team Lead leaving an organisation must not take with them the data of the people they led.

5. Deletion of an Account — three groups of Users make a request

On their own, from Settings, an Account is deleted by a User without a Team and by a Team Lead running their own Team outside a Company structure. The deletion is immediate and irreversible.

By request, by the route in paragraph 1, an Account is deleted by: a member of someone else's Team, a User of an Account belonging to a Company and a Company administrator. The model is the same as with work tools: access is granted and withdrawn by the person running the Team or by the Company. This is the only place in which the carrying out of your request depends on our reaction and not on your click — which is why we describe the channel and the deadline here, instead of referring you to a button that does not exist.

Deletion of an Account covers Account data, the Workshop and the Book. It does not cover documents handed over to other people or to the Team, or entries in the register of acts.

6. Rectification of a record in the Book after expiry of the Trial period

After the Trial period lapses, the Book passes into a read state and you will not correct an existing record (§6(8) of the Terms). In this state rectification is carried out by us, at the controller's request, within the deadlines in paragraph 2 — in accordance with §8(6) of Annex 1.

7. If your Account is suspended

Suspension does not take your rights away from you. A suspended Account does not log in, so you will not download the data yourself — we prepare it on request, within the deadlines in paragraph 2.

How to reach the contact address: entering the correct password on the login screen will display the message about the suspension together with the address. If you do not remember your password, use recovery — the message will go out and the link will lead you to the same message. With an incorrect password you will see the ordinary message about a failed login and we do this deliberately: otherwise the screen would confirm to an outsider that a given Account exists and has been suspended.

You also have the right to learn the reason for the suspension; we provide it with information about other people redacted (§12(4)–(5) of the Terms).

§10. If someone else keeps records about you in Flaber

This paragraph concerns people who do not necessarily have an Account with us, but whose data was entered into the Service by a client — an employer, a company, a superior or a co-worker.

1. The controller is the one who entered the data

Not us. You address a request for access, rectification, erasure and restriction to them. The obligation to inform you about the processing also rests on them. We, as processor, assist them in performing these obligations to the extent arising from Annex 1 to the Terms.

2. There is no screen in the Service through which you will see someone else's Book

There is no account, role or screen through which a person kept in the Book would obtain access to it — such insight is not provided for in the construction of the Service. This does not mean that you do not have the right of access. It means that it is exercised by the controller, outside the application (§10(7) of the Terms, §8(5) of Annex 1).

3. If a request reaches us

We will not answer it on the merits — we will inform you of our role and of who it should be addressed to. What happens next depends on one circumstance:

  • if you have an Account with us and a Seat in a Team — we will establish the controller and pass the request on to them;
  • if you do not have an Account with us — we will not find them ourselves and we will ask you to indicate them.

The reason. There is no query that would return the content of the Book, and our operator console does not release the first names of people from Teams. This is exactly the same property thanks to which your employer or a Company administrator cannot read the Book. We point out this limitation instead of declaring a transfer that we would not be able to carry out.

§11. Data security

1. Safeguards applied

  • Access rules enforced by the database engine on all tables, independently of the correctness of the application. Every query narrowed to the identity of the owner; the enforcement covers the table owner as well. Covered by more than a thousand automated assertions, including negative tests — "does the other person really not see this" — run before every change to the database structure.
  • The tables of the relations layer have no Company or Team column. There is no query with which a Company administrator would read someone else's Book. This is not a setting that can be switched.
  • Disk encryption on the infrastructure provider's side, encrypted transmission on all connections, passwords in the form of an irreversible hash, protection against passwords from known breaches.
  • Backups, logging of administrative acts, a procedure for handling breaches.

2. Limitations of the safeguards

  • We do not use end-to-end encryption or server-side encryption. Content is stored in the database in plain form, so the infrastructure provider and we can technically read it. That is how most tools of this class work. Your employer has no such possibility — not because of a contractual prohibition, but because of the absence of a route in the database structure.
  • There is no two-factor login for Users (there is one on the infrastructure owner's accounts).
  • There is no Account lockout after many failed password attempts — there is a general rate limit on attempts on the authentication provider's side.
  • Administrative access to the database exists, as in every system of this class, and today it is held by one person on our side. The console we use when servicing the Service does not release the content of the Book or the first names of people from a Team — the function that feeds it is not capable of releasing content, and extending it would require a change to the database structure.
  • We do not declare conformity with any certification standard — neither ISO 27001 nor SOC 2, including in the form of "in accordance with standards" or "on certified infrastructure". The certificates of our subprocessors are their certificates and we indicate them solely with them.

3. A limitation that cannot be removed

No system rules out risk entirely. If a personal data breach is established, we act in accordance with the provisions of law and with the contracts with clients — including within the deadlines set out in §10 of Annex 1.

A client acting as controller receives the full list of technical and organisational measures as Annex B to Annex 1, together with the limitations named.

§12. Children's data

The Service is intended for adults (§4(2) of the Terms). By creating an Account, you declare that you are 18 years of age or older.

We do not direct the Service at children and we do not knowingly collect their data. Nor do we base the creation of an Account on a child's consent within the meaning of Article 8 GDPR — the basis is a contract concluded by an adult. If we learn that the data of a person below that age has reached the Service contrary to this rule, we will take appropriate action, including deletion of the data.

§13. Cookies and browser storage

1. No consent banner

No marketing or analytics cookie operates here, and the only one we use is necessary for the provision of the Service — without it, logging in will not work. Such cookies do not require consent (Article 173(3) of the Polish Telecommunications Act (Prawo telekomunikacyjne)).

The application does not load any analytics tool. It does not measure behaviour, does not create an identifier between sessions, does not embed third-party scripts for advertising purposes. We serve fonts from our own domain — the browser does not connect to external servers for that purpose.

Below we indicate what your browser connects to beyond our address. There are two such connections and both lead to our subprocessors, not to advertisers:

  • the provider of the database, authentication and files — logging in, reading and writing data as well as uploading and displaying files go straight from your browser to them. This is the core of how the Service works, not tracking;
  • the error log provider — solely at the moment of an error (paragraph 6).

Neither of them embeds an advertising script or a cross-site identifier. Both providers are on the list of subprocessors referred to in §5(3).

2. Cookies

NameWho sets itWhat forHow long
sb-<identifier>-auth-token (split into parts where the token is longer)the authentication provider; we save it without changing its parametersmaintaining a logged-in session7 days from last activity, at most 30 days

This is the only cookie in the application. We do not set any of our own.

How session time is counted. The login credential is renewed automatically every hour for as long as you use the Service. The session expires if you do not enter the application for 7 days, and irrespective of activity it ends after 30 days. You can end it earlier by logging out.

3. Browser storage

Apart from the cookie, we save view settings on your device, so that when you open the application again it keeps the layout you set. This data is not sent to us and is not read by us — it lies solely in your browser.

KeyWhat it holdsWhen it disappears
pcg:lastView:<person card identifier>the tab last opened on a person carduntil browser data is cleared
pcg:ckTabthe tab last opened on Checklistsas above
sb-collapsedwhether the side panel is collapsedas above
dock-wthe width of the side panelas above
notes-filter, checklists-filter:<variant>the selected view filteron closing the browser tab

One item requires an explicit sentence: the key pcg:lastView carries in its name the identifier of the person card that you opened. It does not contain their first name or any content, but it is a record connected with a specific person and it stays on the device until browser data is cleared. You can delete it at any moment in your browser settings — the application will recreate it on the next use and you lose nothing by doing so.

We treat these records as necessary for the provision of the Service that you yourself requested (Article 173(3) of the Polish Telecommunications Act), and that is why we do not ask for consent: they are not sent to us, they do not create a cross-site identifier, they do not serve measurement or advertising and content cannot be reconstructed from them.

4. The pixel effect in system messages

Every system message embeds our logotype as a remote image. Opening the message causes a request to the server, so your IP address, browser and the moment of opening reach the hosting logs. The resource is our own, it does not belong to a third party and it does not serve tracking, but the effect is the same as with a tracking pixel. The logs are stored for 1 day (§7). This also concerns people who will never create an Account — because they received only an invitation.

If you do not want this effect, disable automatic downloading of images in your e-mail programme.

5. IP addresses

We do not record IP addresses in our database. There is no table, log or call in the application code that would record them; before sending an error report we remove from it the headers carrying the IP address as well as cookies and authentication data. The authentication event log does not store them either — the column in which they could arise remains empty.

The IP address does, however, reach the request logs at the hosting provider, where it is stored for one day, and is visible in the connection to the error log provider — which does not store it, because recording is disabled on their side. The report is sent directly from your browser, so the address is visible at the transport level and no code of ours will change that. We write "is not stored", not "does not reach the provider" — these are not the same thing.

6. The error log provider sees a wider circle of people than our own log

Ours requires a logged-in session, theirs does not — it therefore also covers errors on invitation screens, in the case of people who will never create an Account. We point this out separately, because it is the only situation in which the browser of a person who is not our User connects to a third party.

7. The sales website is a separate matter

Flaber's sales website sits in a separate project, uses its own tools and has no access to Service data. A separate cookie notice applies to it — §15.

§14. Changes to the Policy

  • 1. We may change the Policy where the manner of processing data, the scope of the Service, the list of subprocessors or the provisions of law change.
  • 2. A new version applies from the date of publication. We state the version date at the top of the document, and the list of changes at the end.
  • 3. We notify you by electronic mail of a change that materially affects your rights.
  • 4. A change to this Policy does not replace the procedure for changing the Terms or Annex 1 — those take place under a separate procedure set out in §17 of the Terms. The Policy neither triggers it nor circumvents it.

§15. Related documents

DocumentAddress
Terms of Service of the Flaber Servicehttps://profilon.pl/flaber/regulamin
Annex 1 to the Terms — the data processing agreementhttps://profilon.pl/flaber/powierzenie
Flaber Subprocessors (dated, updated independently)https://profilon.pl/flaber/podprocesorzy
Cookie notice for the sales websitehttps://profilon.pl/cookies

Contact

Controller: Piotr Nowak E-mail address: kontakt@profilon.pl Postal address: ul. Cystersów 8/47, 31-553 Kraków, Poland

Change history

DateChange
18 September 2026First publication.