Privacy policy
Fassung vom 16.09.2026. Verbindlich ist die polnische Fassung; andere Sprachfassungen dienen nur der Information. Eine deutsche Übersetzung folgt – bis dahin gilt der englische Text.
1. Controller
The controller of personal data in connection with the use of the Standbook service (standbook.app) is Progrise Szymon Konieczny, VAT ID PL6342611135, ul. Marcina Radockiego 156/1, 40-645 Katowice, Poland, REGON 243479052. Contact for data protection matters: support@standbook.app. The controller has not appointed a data protection officer; all matters can be raised directly at the address above.
2. Who and what this policy covers
- Account users (venue owners, administrators and assistants) and people who contact us – Progrise is the controller of their data.
- Exhibitors and applicants on venue sites (markets, halls, fairs) – the controller of their data is the venue organiser; Progrise processes it on the organiser’s behalf as a processor under the Data Processing Agreement (Annex 1 to the Terms). Requests concerning this data should be addressed to the organiser, whose contact details are in the footer of the venue site; we assist organisers in responding to data subject requests.
- Visitors of standbook.app and of the demo instance.
3. What data we process, why and on what basis
- User account: e-mail address, name, language, terms acceptance timestamp, password hash (if a password was set), session identifiers (stored as hashes), last activity date, browser name. Purpose: concluding and performing the agreement, login, account security. Basis: Article 6(1)(b) GDPR (contract) and (f) (legitimate interest – security).
- Venue and billing data: organiser name and contact details, invoicing data (name, address, VAT ID), payment and invoice history. Card payments are processed by Stripe – we do not receive or store full card numbers. Purpose: settlement of the service and tax/accounting obligations. Basis: Article 6(1)(b) and (c) GDPR.
- Audit log and server logs: who performed which operation in the panel and when, IP address (in server logs and as a shortened identifier attached to requests), login events, rate limits. Purpose: accountability, abuse detection, security. Basis: Article 6(1)(f) GDPR.
- Correspondence and support: e-mail content and sender details. Purpose: handling requests and complaints. Basis: Article 6(1)(b) and (f) GDPR.
- Product information: we may send customers messages about material changes to the service and new features (Article 6(1)(f) GDPR); you can object at any time by replying to the message. We do not send third-party advertising.
- Demo instance (demo.standbook.app): data entered in the demo is publicly visible and deleted daily; please do not enter real personal data there.
Providing account and billing data is voluntary but necessary to use the service. We do not make decisions based solely on automated processing and do not profile users.
4. Exhibitor data processed on behalf of organisers
On behalf of organisers we store request data: company name, contact person, e-mail, phone, assortment, request content, language, date of acceptance of the organiser’s terms and a shortened IP address identifier, as well as stall line-ups, attendance and payment status. This data is used solely to handle bookings and the organiser’s communication with the exhibitor (confirmations, decisions, reminders). The organiser decides how long it is kept; deleting an exhibitor in the panel anonymises their data while keeping the attendance history without identifying details.
5. Recipients of data (sub-processors)
We use providers that process data on our behalf under data processing agreements:
- Railway Corp. (USA) – application and database hosting; data stored in the European Union region (Amsterdam, Netherlands).
- Cloudflare, Inc. (USA) – domain registry, DNS and network traffic protection.
- Stripe Payments Europe Ltd. (Ireland) – payment and invoice processing; Stripe is an independent controller of payment data to the extent described in its privacy policy.
- E-mail provider [to be completed once selected] – sending transactional messages (login links, confirmations, reminders).
- Invoicing provider [to be completed] – issuing invoices in accordance with Polish law (including KSeF).
Data may also be disclosed to public authorities where required by law and to advisers (accounting, legal) to the extent necessary. We do not sell personal data and do not share it for third-party marketing.
6. Transfers outside the European Economic Area
Data is stored on servers in the European Union. Some providers are established in the USA; transfers take place on the basis of the European Commission’s adequacy decision for entities certified under the EU-U.S. Data Privacy Framework or standard contractual clauses approved by the European Commission, with additional safeguards (encryption, access restriction). A copy of the safeguards can be obtained by writing to support@standbook.app.
7. Retention
- Account and venue data – for the term of the agreement, then 30 days for data export (90 days after the end of a trial without choosing a plan), after which it is deleted or anonymised.
- Accounting documents and invoicing data – 5 years from the end of the tax year in which the document was issued (legal obligation).
- Server logs and security events – up to 12 months.
- Venue audit log – for the term of the agreement.
- Correspondence – up to 3 years after the matter is closed (limitation of claims).
- Demo instance data – up to 24 hours.
8. Data subject rights
Everyone has the right of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time (without affecting the lawfulness of processing before withdrawal). Requests can be sent to support@standbook.app; we respond without undue delay and no later than within one month. Requests concerning exhibitor data are forwarded to the venue organiser or handled on its instructions.
You also have the right to lodge a complaint with a supervisory authority: in Poland this is the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl); persons in other EEA countries may contact their national supervisory authority.
9. Data security
We apply technical and organisational measures appropriate to the risk, in line with Article 32 GDPR and – to the extent appropriate to the scale of the service – with the cybersecurity risk-management requirements described in Article 21 of the NIS 2 Directive (Progrise is not an essential or important entity within the meaning of that Directive but applies these principles to support customers who are subject to such requirements):
- Encryption: all traffic is encrypted (TLS, HTTPS enforced with HSTS); database connections are encrypted; backups are stored encrypted by the hosting provider.
- Authentication and access: login via one-time e-mail links or a password stored only as a hash (scrypt); session tokens stored in the database as SHA-256 hashes; roles with least privilege; immediate session invalidation when access is removed; request rate limits.
- Data separation: each venue’s data is logically separated and every database query is automatically restricted to the current venue.
- Accountability: a panel audit log (who, what, when) and security event logs.
- Business continuity: daily backups with 30-day retention, a recovery procedure, infrastructure in an EU data centre with the provider’s independent security certifications.
- Supply-chain security: sub-processors selected with regard to their certifications and data processing agreements; software dependencies kept up to date; security patches deployed without delay.
- Incident handling: risk analysis, an incident response procedure; personal data breaches are reported to the supervisory authority within 72 hours and to organisers whose data has been entrusted to us without undue delay, no later than 48 hours after becoming aware of the breach; data subjects are informed where required by law.
- Minimisation: we collect only necessary data; deleting an exhibitor anonymises their data.
10. Cookies and browser storage
Strictly necessary files (no consent required): the user session cookie (stalls_auth), the venue panel session cookie (stalls_session), the language cookie (locale, 12 months) and the cookie that remembers your cookie decision (sb_consent, 12 months). A venue site stores the identifiers of submitted applications and the contact details typed into the form in the browser (localStorage) to make the next application easier; this data stays on the user's device only.
Analytics and marketing files (only with consent): on standbook.app and in the demo instance we use Google Tag Manager and, through it, Google Analytics 4 (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). These tools start only after consent is given in the banner (Art. 6(1)(a) GDPR and the ePrivacy rules); before that they are not loaded and set no files. Google Analytics sets, among others, the _ga (2 years) and _ga_* (2 years) cookies used to distinguish visitors and sessions; IP addresses are not stored. Consent can be withdrawn or changed at any time in “Cookie settings” in the page footer; withdrawal does not affect the lawfulness of processing before it. We do not embed analytics or marketing tools on customers' venue sites (other than the demo).
11. Changes to this policy
We update the policy when the scope of the service, the law or the list of sub-processors changes. The current version is always available at standbook.app/legal/privacy with the date of the last change; account users are informed of material changes by e-mail.