1. Data controller
The controller of personal data is Do More Soft Hubert Ptaszek, ul. Olszewskiego 6, 25-663 Kielce, Poland, VAT ID 7681848372 (the "Controller"). Contact on data protection matters: rodo@dailyhair.pl.
The Controller has not appointed a data protection officer (DPO); for all matters concerning data processing you may contact us directly at the address above.
Regarding participation in an event, a separate data controller may be the event organizer — as the entity responsible for its organization and entry control. The organizer's identity is shown on the event page.
2. What data we process
Depending on how you use the platform, we process:
- purchase and contact data: participant's name, e-mail address, optionally phone number;
- order and ticket data: order number, ticket type and quantity, ticket code, payment status;
- billing data: invoice details (when requested), amounts and payment history (without payment instrument data — that is processed by the payment provider);
- account data: user identifier, authentication data, marketing consents;
- technical data: IP address, device and browser information, server logs.
3. Sources of data
We obtain data directly from the person it concerns — when creating an Account, placing an order, getting in touch or subscribing to the newsletter.
Some data may come from a Buyer who purchases a Ticket for another participant (e.g. the participant's name). In that case the Buyer must have a basis for sharing that data and inform the participant of this Policy. Technical data is collected automatically while you use the platform.
4. Purposes and legal bases of processing
- Order fulfilment and ticket delivery
- Art. 6(1)(b) GDPR — performance of a contract to which the data subject is party.
- Payment handling
- Art. 6(1)(b) and (f) GDPR — performance of a contract and the legitimate interest of preventing fraud.
- Issuing invoices and tax obligations
- Art. 6(1)(c) GDPR — compliance with a legal obligation of the Controller (tax and accounting law).
- Complaints handling and contact
- Art. 6(1)(b) and (f) GDPR — performance of a contract and the legitimate interest of responding to enquiries.
- Own marketing (newsletter)
- Art. 6(1)(a) GDPR — consent, which can be withdrawn at any time. We record consents with a timestamp (Art. 7 GDPR).
- Security and technical logs
- Art. 6(1)(f) GDPR — the legitimate interest of ensuring the security and continuity of the platform.
- Establishing and defending claims
- Art. 6(1)(f) GDPR — the legitimate interest of the Controller.
5. Data recipients
We entrust data to trusted processors, only to the extent necessary to provide the service and under data processing agreements:
- Supabase (database hosting and authentication) — data stored in the European Union region (Frankfurt, Germany);
- Stripe Payments — online payment handling (BLIK, payment card, Przelewy24);
- Resend — sending transactional messages (purchase confirmation, e-ticket);
- Cloudflare — application hosting, content delivery network and abuse protection;
- the event organizer — to the extent necessary to carry out participation and entry control;
- an accounting office and invoicing system provider — for settlements and tax obligations.
Some providers may process data outside the European Economic Area. In such cases, the transfer is based on standard contractual clauses approved by the European Commission or another mechanism provided for in Chapter V of the GDPR.
6. Sharing data with the organizer
To the extent necessary to carry out participation in the Event and entry control, we share the participant's data with the organizer: name and Ticket status. The organizer processes it as a separate controller for the purpose of running the Event.
We do not share payment instrument data or full payment history with the organizer. The organizer's own privacy policy governs how it processes data after it has been shared.
7. Data retention period
- order and ticket data — for the time needed to provide the service and for the limitation period of claims;
- billing data and invoices — for the period required by tax law (as a rule 5 years counted from the end of the year in which the tax obligation arose);
- data processed on the basis of consent (marketing) — until consent is withdrawn;
- technical logs — for the time needed for security, usually up to 12 months.
8. Your rights
You have the right to access your data, rectify, erase or restrict its processing, the right to data portability and the right to object to processing based on legitimate interest. Where processing is based on consent, you may withdraw it at any time — without affecting the lawfulness of processing carried out before withdrawal.
To exercise your rights, write to rodo@dailyhair.pl. We respond without undue delay and no later than within one month of receiving the request. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).
9. Voluntary provision of data
Providing the data needed to buy a ticket and issue an invoice is voluntary but necessary to conclude and perform the contract — without it we cannot fulfil the order. Providing data for marketing purposes is entirely voluntary.
10. Cookies and analytics
The platform uses cookies and similar technologies necessary for the service to work (including session maintenance and security) and — with consent — for analytics. Cookie settings can be changed in your browser; restricting necessary cookies may affect how the platform works.
Necessary cookies do not require consent and are not used for tracking. Analytics cookies help us understand how you use the platform in a way that limits identifying an individual user; we install them only after consent and only until it is withdrawn.
11. Automated decision-making
We do not make decisions about you based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect you.
12. Policy changes
We may update the Policy in connection with the development of the platform or changes in law. The current version is always available on this page together with its effective date. The rules for buying tickets are described in the Ticket Sales Terms.
13. Data and account deletion
You have the right to request erasure of your personal data and your Account (Art. 17 GDPR). To do so:
- Write to rodo@dailyhair.pl from the e-mail address linked to your Account, with “Data deletion” in the subject.
- We will confirm receipt and erase your Account data and marketing data without undue delay, no later than within 30 days.
- Data we are required to keep by law (including invoices and accounting data — as a rule 5 years, see the “Data retention period” section) is erased once the required retention period ends.
If you sign in with Facebook or Google, you can additionally revoke the app’s access in that provider’s settings — this disconnects the login, but to delete your data from DailyHair please request it by e-mail above.