This Privacy Policy defines the principles governing the processing of personal data of users of the APAToDo mobile application and describes the measures implemented to ensure the security of processed personal data.
The Operator makes every effort to ensure that personal data is processed in accordance with:
Using the Application constitutes acceptance of this Privacy Policy.
Personal data is processed solely to the extent necessary for providing the services available within the Application.
The Controller applies appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, or disclosure.
The Controller of personal data is:
APAMA
Kamyk, Plac Witosa 1A
E-mail:
it@apama.pl
Tax ID (NIP): 9491572040
The Controller is responsible for processing personal data in accordance with applicable laws and ensuring that data subjects can exercise their rights.
For any matters related to personal data protection, users may contact the Controller via the email address provided above.
Depending on how the Application is used, we may process the following categories of personal data:
Personal data may be processed for the following purposes:
Personal data is processed on one or more of the following legal bases:
Personal data is retained only for as long as necessary to achieve the purposes for which it was collected or for the period required by applicable law.
After the applicable retention period expires, personal data is permanently deleted or anonymized unless further retention is required by law.
Under the GDPR, every user has the right to:
Users also have the right to lodge a complaint with the competent supervisory authority responsible for personal data protection.
The Controller implements appropriate technical and organizational measures to ensure a level of security appropriate to the risks associated with personal data processing.
These measures include, in particular:
Access to personal data is granted only to authorized persons or trusted service providers acting on behalf of the Controller under appropriate agreements.
The Controller continuously takes steps to minimize the risk of accidental loss, destruction, unauthorized disclosure, or unauthorized access to personal data.
To provide the Application, the Controller may use trusted third-party service providers responsible for selected technical services.
These entities may process personal data only to the extent necessary to perform services on behalf of the Controller and under applicable data protection laws.
The Controller carefully selects service providers and requires them to maintain appropriate security standards.
Some services used by the Controller may involve processing personal data outside the European Economic Area (EEA).
In particular, the Application uses Google services, including Firebase Authentication and Cloud Firestore, which may involve international transfers of personal data.
Whenever personal data is transferred outside the EEA, appropriate safeguards are applied in accordance with the GDPR, including Standard Contractual Clauses approved by the European Commission or other legally recognized transfer mechanisms.
The Controller makes every reasonable effort to ensure that all third-party providers maintain an adequate level of protection for personal data.
Due to the use of services provided by entities located outside the European Economic Area (EEA), Users' personal data may be transferred to third countries.
In particular, the Controller uses services provided by Google LLC, including Firebase Authentication and Cloud Firestore.
Such transfers are carried out in accordance with the GDPR and are based on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission or other legally recognized transfer mechanisms.
The Controller exercises due diligence to ensure that all processors maintain an adequate level of personal data protection.
The Controller reserves the right to amend this Privacy Policy in the event of:
Users will be informed of any significant changes through the Application, by email, or by any other effective means.
The latest version of this Privacy Policy is always available within the Application and on the Controller's website.
Continued use of the Application after changes become effective constitutes acceptance of the updated Privacy Policy.
If you have any questions regarding the processing of your personal data or wish to exercise your rights under the GDPR, you may contact the Controller using the following details:
APAMA
Kamyk, Plac Witosa 1A
E-mail:
it@apama.pl
The Controller will respond to requests concerning personal data without undue delay and within the time limits required by applicable law.
Where required by law, the Controller may request additional information necessary to verify the identity of the requesting person.
To ensure proper operation of the Application, the Controller may process technical information related to the User's device.
Such information may include:
This information is processed solely for:
The Controller does not use this information for profiling or marketing purposes.
The Application may send notifications regarding:
These notifications are an integral part of the Application and are intended to ensure proper task management.
Users may disable push notifications in their device settings. However, disabling them may limit certain Application functionality.
The Controller does not make decisions concerning Users based solely on automated processing as referred to in Article 22 of the GDPR.
The Controller does not perform profiling of Users within the meaning of the GDPR.
The Application is not intended for individuals under the age of 16 unless its use complies with applicable law and, where required, is authorized by a legal guardian.
The Controller does not knowingly collect personal data from children in violation of applicable law.
If the Controller becomes aware of unauthorized processing of a minor's personal data, appropriate measures will be taken to delete or restrict such data.
The Terms of Service and this Privacy Policy are separate documents governing the use of the Application and the processing of personal data.
In the event of any inconsistency regarding personal data processing, this Privacy Policy shall prevail.
These documents are available free of charge within the Application and may also be published on the Controller's website.
Last updated: July 2026