Legal
Privacy Policy
Last updated: 1 June 2025
Table of contents
This Privacy Policy explains how Bliss Software collects, uses and protects your personal data when you visit bliss.software or engage with our services. We process data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Polish law.
1. Data controller
The controller of your personal data is:
- Bliss Software
- Warsaw, Masovian Voivodeship, Poland
- Email: [email protected]
For all data protection matters you can contact us at the email address above.
2. Data we collect
2.1 Data you provide directly
- Name and surname
- Business email address
- Company name and role
- Phone number (if provided)
- Message content submitted via contact forms or email
2.2 Data collected automatically
- IP address and approximate geolocation
- Browser type, version and operating system
- Pages visited, time spent, referral source
- Device type and screen resolution
- Cookie identifiers (see Section 4)
2.3 Data from third parties
- Publicly available professional information (e.g. LinkedIn profile) when you contact us through those platforms
- Referral information from partners or events
3. Purposes and legal basis
We process your personal data only when we have a valid legal basis to do so under Article 6 GDPR:
Responding to enquiries (Art. 6(1)(b) GDPR)
When you submit a contact form or email us, we process your data to respond to your request and provide the service you asked about. This processing is necessary for the performance of a pre-contractual relationship.
Providing our services (Art. 6(1)(b) GDPR)
If you become a client, we process your data to deliver, manage and invoice the agreed services.
Legitimate interests (Art. 6(1)(f) GDPR)
- Website analytics to improve user experience
- Security monitoring and fraud prevention
- Internal reporting and business development
Consent (Art. 6(1)(a) GDPR)
- Marketing cookies and analytics beyond essential functionality
- Newsletter or promotional communications (if applicable)
You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
Legal obligation (Art. 6(1)(c) GDPR)
We may process data to comply with applicable legal requirements, including tax and accounting obligations.
4. Cookies and tracking
We use cookies and similar technologies on our website. You can manage your preferences via the cookie banner displayed on your first visit.
Essential cookies
Required for the website to function correctly. They cannot be disabled. No consent is required.
- cookie_consent - stores your cookie preference (localStorage, session)
Analytics cookies (consent required)
Help us understand how visitors interact with the site. We use these only with your explicit consent.
- Google Analytics 4 - page views, session duration, traffic sources
How to manage cookies
You can withdraw or change your cookie consent at any time by clicking "Cookie settings" in the page footer, or by clearing cookies in your browser settings. You can also opt out of Google Analytics tracking via the Google Analytics Opt-out Browser Add-on.
5. Data sharing and processors
We do not sell your personal data. We may share it with trusted processors who act on our instructions under data processing agreements (DPA):
- Google LLC - analytics (Google Analytics 4), hosted in the EU/EEA or under Standard Contractual Clauses
- Email service providers - for transactional and support communications
- Cloud infrastructure providers - for hosting and data storage
- Accounting and legal advisors - where required by law
We may also disclose data to public authorities when required by applicable law.
6. Data retention
- Contact form enquiries - up to 3 years from last contact, or for the duration of any resulting business relationship
- Client data - for the duration of the contract plus 5 years (statutory accounting requirements under Polish law)
- Analytics data - up to 14 months (Google Analytics default retention)
- Cookie consent records - up to 1 year
After the applicable retention period, data is securely deleted or anonymised.
7. Your rights (GDPR)
Under the GDPR you have the following rights regarding your personal data:
- Right of access (Art. 15) - obtain a copy of the data we hold about you
- Right to rectification (Art. 16) - correct inaccurate or incomplete data
- Right to erasure (Art. 17) - request deletion of your data ("right to be forgotten")
- Right to restriction (Art. 18) - limit how we process your data in certain circumstances
- Right to data portability (Art. 20) - receive your data in a structured, machine-readable format
- Right to object (Art. 21) - object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent (Art. 7(3)) - withdraw consent at any time where processing is based on consent
To exercise any of the above rights, please contact us at [email protected]. We will respond within 30 days of receiving your request. We may ask you to verify your identity before processing the request.
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the Polish supervisory authority:
- Urząd Ochrony Danych Osobowych (UODO)
- ul. Stawki 2, 00-193 Warsaw, Poland
- uodo.gov.pl
8. International transfers
Some of our service providers are based outside the European Economic Area (EEA). Where data is transferred outside the EEA, we ensure an adequate level of protection through one or more of the following mechanisms:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules where applicable
You may request a copy of the relevant safeguards by contacting us.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction or alteration. These include:
- Encryption of data in transit (TLS) and at rest
- Access controls and role-based permissions
- Regular security assessments
- Staff awareness and confidentiality obligations
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
10. Children's privacy
Our website and services are directed solely at business professionals and are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or via a notice on the website.
We encourage you to review this page periodically. Continued use of our website after changes are posted constitutes your acknowledgement of the updated policy.
12. Contact
For any questions, requests or concerns regarding this Privacy Policy or the processing of your personal data, please contact us:
- Email: [email protected]
- Company: Bliss Software, Warsaw, Poland
We aim to respond to all data protection enquiries within 30 days.