Data controller
- Company
- UMOVI PROSTA SPÓŁKA AKCYJNA
- Address
- ul. Henryka Sienkiewicza 49, 42-600 Tarnowskie Góry, Polska
- Privacy contact
- privacy@umovi.app
- Phone
- +48 500 566 563
§ 1. Scope of this Policy
- This Policy explains how Umovi processes data relating to Clients, visitors to the public website, Business Users, Providers’ employees, persons contacting Umovi and persons using integrations.
- This Policy covers Umovi websites, mobile applications, panels, communications, billing features, API and MCP interfaces, and privacy settings.
- The Provider may be a separate controller of the Client’s data. Its own privacy information is presented on its profile, in the Booking summary or in a notice before data are disclosed.
§ 2. Controller and contact details
- The controller of data processed for the Platform’s own purposes is UMOVI PROSTA SPÓŁKA AKCYJNA, with its registered office in Tarnowskie Góry, at ul. Henryka Sienkiewicza 49, 42-600 Tarnowskie Góry, Polska, entered in the register of entrepreneurs of the National Court Register maintained by Sąd Rejonowy w Gliwicach, X Wydział Gospodarczy Krajowego Rejestru Sądowego under number 0001263973, tax identification number (NIP) 6452601936, statistical identification number (REGON) 545606947, hereinafter “Umovi”.
- For personal data enquiries, please contact privacy@umovi.app or write to the address in paragraph 1. If a data protection officer is appointed, their details will be published in the Legal Information.
- Where Umovi processes data solely on behalf of a Provider, it helps forward the request to the appropriate controller or explains how to contact that controller directly.
§ 3. Division of roles between Umovi and the Provider
- Umovi is a separate controller of data needed for Account creation, authentication, security, provision and development of the Platform, handling Bookings as a platform service, billing the Provider, its own communications, moderation, pursuing claims and fulfilling legal obligations.
- The selected Provider is a separate controller of data disclosed for a Booking, conclusion and performance of its own service, operational contact, payment settlement, complaints and fulfilment of sector-specific and tax obligations.
- Umovi acts as a processor when, on the Provider’s instructions, it makes Provider’s Client Records available, stores their notes and attachments, runs a Provider campaign or performs another function whose purposes and essential means are determined by the Provider.
- Merely recording the Client–Provider relationship resulting from a Booking does not constitute consent to marketing or the creation of optional notes. Roles are assessed for each specific operation, rather than once for the entire Platform.
- If joint determination of the purposes and means of a particular operation results in joint controllership, Umovi and the Provider will enter into the required arrangement and make its essence available to the data subject before that operation begins.
§ 4. Categories of data and sources
| Person or area | Categories of data | Main source |
|---|---|---|
| Website visitor | IP address, request time and route, device and browser type, privacy settings, theme, language, form and attribution data — where consent has been given | the device, browser and User |
| Client | name, email, telephone number, Account and login identifiers, profile photo, language, settings, sessions and 2FA | the Client or login provider after authorisation |
| Booking | Provider, location, service, employee or workstation, time slot, time zone, status, indicative price, messages, events and acknowledgements | the Client, Provider and operation of the Platform |
| Location | coordinates sent for an individual search, a town, city or address entered manually, distance from results | the device or Client |
| Business User | company, registration, tax and billing data, roles, permissions, offering, schedules, staff and activity in the panel | the Business User, public registers and operation of the Platform |
| B2B payments | Plan, amount, currency, invoice, transaction identifier and status, payment method token; Umovi does not hold the full card number | the Provider and payment operator |
| Communications | sender and recipient address, telephone number, device token, content, attachments, delivery and unsubscribe status | the parties to the communication and channel supplier |
| Provider’s Client Records | permitted notes, preferences that do not contain special categories of data, attachments and change history | the Provider as controller |
| Integrations and MCP | application, OAuth scopes, connection tokens and metadata, instructions, results, audit events | the User and authorised application |
| Security and support | IP address, device and session identifiers, logs, Account activity, reports, evidence of consent and acknowledgements, incident data | operation of the Platform, the User and suppliers |
§ 5. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Account creation, login, sessions, 2FA and Account management | identification, contact, authentication and technical data | Article 6(1)(b) GDPR; Article 6(1)(f) for Account protection |
| Searching offerings and handling Bookings | criteria, optional location, Booking data, messages and statuses | Article 6(1)(b) GDPR |
| Disclosure of data to the selected Provider | contact details and Booking data | Article 6(1)(b) GDPR — steps at the Client’s request and performance of the platform service |
| Acknowledgement of information about disclosure | User, Provider, notice version, date, language and application interface | Article 6(1)(f) GDPR — accountability and defence of claims |
| Billing the Provider and tax documents | company details, payments, invoices and checks | Article 6(1)(b) and (c) GDPR |
| Security, auditing, prevention of abuse and claims | logs, sessions, IP addresses, events and reports | Article 6(1)(f) GDPR; Article 6(1)(c) where an obligation arises by law |
| Operational notifications | email, telephone number, push token, content and status | Article 6(1)(b) or (f) GDPR |
| Marketing by Umovi or a Provider | contact details, sender, channel, consent wording and evidence | Article 6(1)(a) GDPR and consent required by the Polish Electronic Communications Law |
| Client recommendations | Booking history, saved places, frequency and timing | Article 6(1)(f) GDPR — more relevant service discovery; right to object |
| Optional campaign measurement and analytics | pseudonymous identifier, campaign source, event and setting | Article 6(1)(a) GDPR and consent to the technology where required |
| Moderation and platform obligations | Content, report, decision and evidence | Article 6(1)(c) and (f) GDPR |
| Handling an instruction through MCP | scopes, instruction and operation data | Article 6(1)(b) GDPR; Article 6(1)(f) for security auditing |
- Providing data necessary for an Account or Booking is voluntary, but the requested feature cannot be performed without them. Optional data are marked as such, and not providing them does not restrict the basic feature.
- Acknowledging information before the first Booking with a Provider is not GDPR consent. Marketing consent is separate, voluntary and may be withdrawn.
§ 6. Special categories of data and minors
- The Platform is not intended for processing health data or other special categories of data. These must not be entered into comments, messages, Provider’s Client Records or attachments.
- This restriction also applies to Providers in medicine, beauty, physiotherapy or other sectors in which such data arise outside the Platform. Umovi is not a medical records system.
- Accounts and Bookings are intended for adults. Umovi does not collect dates of birth or carry out automated age verification; at registration, it records a declaration of adulthood together with the version of the Terms and Conditions.
§ 7. Location, maps and the device
- Device location is used only after system permission has been granted, to show nearby services and calculate distance. The User may refuse and enter a location manually.
- Coordinates are sent for an individual search request. Umovi does not store them as a profile field or movement history. Limited data may temporarily appear in standard security logs.
- A manually selected town or city or location preference may be stored on the device. The User can change or remove it in application settings or browser storage.
- Maps and geocoding may involve a connection to Apple or Google, depending on the device and application interface. The map provider receives the technical data and query needed to display the map under its own rules.
- There is no need to store precise location in login data. Umovi does not plan to do so; any change requires a separate assessment of necessity, minimisation and retention, and an update to the information before implementation.
§ 8. Recipients and suppliers
- Booking data are received by the selected Provider and its authorised staff. The Client sees the recipient’s identity before disclosure.
- Below we identify the full names of entities whose integrations may support Platform features. An entity receives data only when the relevant feature and delivery route are active for the User.
| Entity | Function | Typical data scope and location |
|---|---|---|
| Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg | cloud infrastructure, databases, private files, logs and backups | Platform data depending on the feature; primary data region: European Union, eu-central-1 |
| Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland | Google login, Google Maps and Places on Android, Firebase Cloud Messaging | login identifier and data shared by the User; map query; notification token and data |
| Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland | Apple login, MapKit on the web and iOS, Apple Push Notification service | login identifier and shared data; map query; notification token and data |
| Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, operator of Resend | production email delivery once this route is activated | address, name, message content and technical status; possible transfer to the USA |
| PROMOHUB sp. z o.o., ul. Bagatela 10/39, 00-585 Warszawa, NIP 7011181115, operator of SMS-fly.pl | SMS delivery when this route is selected | number, sender name, content and delivery status |
| Digital Virgo Polska sp. z o.o., rondo Ignacego Daszyńskiego 1, 00-843 Warszawa, KRS 0001068391, NIP 5272317216, operator of JustSend | SMS delivery when this route is selected | number, sender name, content, campaign identifier and status |
| PayU S.A., ul. Grunwaldzka 186, 60-166 Poznań, KRS 0000274399 | Provider payments for the Platform | company details, amount, currency, transaction identifier and status; does not concern Client payments for services |
| Stripe Payments Europe, Limited and Stripe Technology Europe, Limited, 1 Wilton Park, Wilton Place, Dublin 2, D02 FX04, Ireland | Provider payments for the Platform | company details, amount, currency, method, identifier and status; does not concern Client payments for services |
- The VAT number and validation result may be transmitted to the European Commission and the relevant tax administrations through VIES. Data required to issue or process a document may be sent to the Head of Poland’s National Revenue Administration through KSeF.
- An authorised MCP application is a separate recipient only within the scope selected by the User. Its exact name, controller, scope and privacy policy are presented before authorisation.
- Data may be received by law firms, auditors, insurers, an acquirer of the business and public authorities where there is a legal basis or where necessary to establish, exercise or defend legal claims.
- Umovi does not list local or test tools because they are not production recipients of User data. The current list of subprocessors is maintained at https://pro.umovi.app/pl/privacy#legal-section-8.
§ 9. Transfers outside the EEA
- Umovi’s primary infrastructure operates in an AWS region within the European Union. This does not mean that every supporting service operates solely within the EEA.
- Where a recipient processes data outside the EEA, Umovi applies an appropriate mechanism under Chapter V GDPR: an adequacy decision, the EU–US Data Privacy Framework for a certified recipient, or standard contractual clauses together with a transfer assessment and supplementary safeguards.
- Information about the specific mechanism and a copy of the relevant safeguards, with confidential information protected, can be obtained from the privacy contact address.
§ 10. Marketing, consent and acknowledgements
- Marketing consents are recorded separately for the relevant controller or sender and available channel, such as email, SMS, push, voice call or in-app message.
- Evidence of consent may include the person, sender, purpose, channel, version and language of the statement, application interface, dates of consent and withdrawal, and limited data needed to demonstrate compliance.
- Consent can be withdrawn in settings, through a link in a message or by contacting the controller. Withdrawal applies prospectively and does not affect the lawfulness of earlier processing.
- Provider marketing remains disabled until the Client gives the appropriate consent. A subsequent Booking flow should not request marketing consent again if it is already active; where it is disabled, the request may be shown again without preselection and without blocking the Booking.
- Acceptance of the Terms and Conditions, acknowledgement of information about disclosure of data, and marketing consent are separate events with separate versions and effects.
§ 11. Recommendations and automated decisions
- Umovi may recommend Providers based on previous Bookings, their frequency, time since the last Booking and saved places. The basis is a legitimate interest in making it easier to find a suitable service again.
- The User may object to personalisation. After objecting, they can still use search and the standard ordering of results.
- Recommendations and ranking do not produce legal effects or similarly significantly affect the User. Umovi does not make decisions concerning the Client under Article 22 GDPR solely by automated means.
- Security rules may temporarily block suspicious activity, and the availability engine may reject a scheduling conflict. The User may contact Umovi for clarification of a restriction.
§ 12. MCP and external applications
- MCP operates after specific OAuth scopes have been authorised. Umovi stores the connection identifier, scopes, tokens in a protected form and technical history needed for security.
- Data are used solely to carry out the User’s instruction concerning their own Bookings and related messages. Umovi does not disclose them to an AI model for training, advertising, general profiling or purposes unrelated to the instruction.
- The external application may use an AI model under its own rules. Its privacy policy should be read before authorisation. Revoking the connection blocks new operations but does not erase copies that the application previously created in accordance with the access granted.
- For the first Booking with a Provider, the application must display information about disclosure of data and obtain active acknowledgement. An OAuth scope does not itself replace this step.
§ 13. Retention periods
| Category | Period or end event |
|---|---|
| Account | until Account deletion or the end of the contract, followed by erasure, anonymisation or restriction of data needed for legal requirements and claims |
| Access token | usually around 15 minutes |
| Web refresh token | usually around 7 days; the session may be revoked earlier |
| Mobile refresh token | depending on the session, up to 365 days; the session may be revoked earlier |
| Expired or revoked tokens | up to 30 days after expiry or revocation for security |
| Completed, cancelled or no-show Bookings and related messages, revisions and events | 1095 days after completion or cancellation, unless a legal hold or claim justifies a longer period |
| Active and future Bookings | until completion or cancellation, then as above |
| Acknowledgement of information about disclosure of data | for the duration of the relationship with the Provider and the period needed to demonstrate compliance or defend claims, no longer than 3 years after the last event without another basis |
| Marketing consents and evidence | while valid and for up to 3 years after withdrawal or last use, to demonstrate compliance |
| Exports, imports and prepared export documents | up to 7 days |
| Audit logs | up to 365 days |
| Read notifications | up to 180 days |
| Successfully delivered webhooks | up to 90 days |
| Failed webhook deliveries | up to 180 days |
| Billing and tax data | for the period required by accounting and tax law |
| Provider’s Client Records and attachments | according to the Provider’s instructions; by default until deletion of the record or the end of the relationship or contract, with 30 days for export and erasure from active systems within the following 30 days |
| Backups | on a rolling basis for up to 90 days after erasure from the active system; not reused except for disaster recovery |
- A legal hold may temporarily suspend automatic erasure only to the extent needed for an incident, claim or legal obligation. Access to such data is restricted.
- Soft deletion is not final erasure. After the retention period, data are physically erased or irreversibly anonymised unless a further basis exists.
- After restoring a backup, Umovi reapplies recorded erasure requests and queues.
§ 14. Security
- Umovi uses measures appropriate to the risk, including encryption in transit and at rest, role-based and least-privilege access control, tenant isolation, secure password hashing, session management, 2FA, audit logs, secret protection, monitoring, backups and incident procedures.
- Administrative access is restricted to persons who need it and is subject to authentication and logging. Details may be withheld where disclosure would weaken security.
- The User should use a unique password, protect their device, enable 2FA and promptly report suspicious activity.
§ 15. Data subject rights
- To the extent provided by the GDPR, a person may request access to and a copy of their data, rectification, erasure, restriction and portability, and object to processing based on legitimate interests.
- A person has an unconditional right to object to direct marketing and to withdraw consent at any time, without affecting the lawfulness of earlier processing.
- If a solely automated decision covered by Article 22 GDPR were introduced, the person would have the right to information, human intervention and to contest the decision. Umovi does not currently apply such a decision to the Client.
- Requests may be sent to privacy@umovi.app. Umovi may verify identity proportionately. It normally responds within one month; in complex cases, this period may be extended in accordance with the GDPR.
- A person may lodge a complaint with the President of the Polish Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warszawa, using the current channels listed at uodo.gov.pl.
§ 16. Cookies, changes and versions
- The Cookies and Technologies Policy contains information about cookies, local storage, SDKs, device permissions and consent settings.
- The current version and date of this Policy are published on the Platform. Umovi gives advance notice of a material change to a purpose, recipient, profiling or rights through the Account, email or another durable medium.
- If a new purpose requires consent, Umovi will request it before processing begins. Continued use of the Platform does not replace consent.