Toolando.tech Privacy Policy
This Privacy Policy describes what data is processed on Toolando.tech, for what purposes, on what legal basis, and what rights you have. I process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Polish data protection law.
Last updated: July 23, 2026
§1. Data controller
1.1. The data controller (“Controller”) is Szymon Badyl, owner of Toolando.tech, operating online tools services.
1.2. Privacy contact: badyltech@outlook.com.
1.3. The Controller has not appointed a Data Protection Officer as it is not required for this activity under GDPR.
§2. What data we process
2.1. Depending on how you use the Service, we process the following categories:
- Technical and usage data: IP address, browser type and version, operating system, language, request date/time, pages visited, traffic source, cookie identifiers (after consent).
- Account data: email address, password (hash), user ID, registration date, Premium status, Stripe customer ID (if applicable).
- Payment data: processed by Stripe — the Controller does not store full payment card numbers.
- Correspondence data: email address, message content, contact date — when you write to badyltech@outlook.com or use the contact form.
- User files: processed temporarily only to perform tool operations — not stored after conversion completes.
§3. Purposes and legal bases
3.1. We process data for the following purposes:
- Providing the Service
- File conversion, tool operation, Account management — legal basis: Art. 6(1)(b) GDPR (contract) or (f) (legitimate interest: operating the Service).
- Premium subscription
- Payment and subscription handling — legal basis: Art. 6(1)(b) GDPR; accounting: Art. 6(1)(c) (legal obligation).
- Traffic analytics
- Google Analytics — only after consent to analytics cookies — legal basis: Art. 6(1)(a) GDPR (consent).
- Advertising
- Google AdSense — only after consent to advertising cookies — legal basis: Art. 6(1)(a) GDPR (consent).
- Security
- Abuse prevention, server logs — legal basis: Art. 6(1)(f) GDPR (legitimate interest).
- Contact and complaints
- Responding to messages — legal basis: Art. 6(1)(f) GDPR or (b) (when related to a contract).
§4. Cookies and similar technologies
4.1. The Service uses cookies and similar technologies. On first visit we show a consent banner where you can accept all cookies or limit yourself to essential ones.
4.2. Types of cookies:
- Essential — required for the Service to work (e.g. language, session, cookie preferences). No consent required.
- Analytics — Google Analytics, aggregate visit statistics. Consent required.
- Advertising — Google AdSense, ad personalization. Consent required.
4.3. You can change your cookie choices at any time via the banner or browser settings.
§5. Recipients and processors
5.1. Data may be shared with trusted processors acting on the Controller's behalf:
- Vercel Inc. — hosting and infrastructure (USA, EU standard contractual clauses).
- Stripe, Inc. — Premium payment processing (USA/Ireland, PCI DSS).
- Google LLC — Analytics and AdSense (after consent; partner policy: https://policies.google.com/technologies/partner-sites).
- Resend — transactional emails (e.g. welcome email after registration), if configured.
- AI model providers — processing prompts and files only within Premium AI tools, without storage after completion.
5.2. The Controller does not sell personal data to third parties.
§6. Files uploaded to tools
6.1. Files uploaded to converters and other tools are not stored after the operation completes.
6.2. Files are not used for AI model training, profiling, or marketing.
6.3. Some tools (e.g. the universal file opener) process files entirely locally in the browser — the file never leaves your device.
6.4. Do not upload files containing sensitive data (e.g. health data, national ID numbers) unless absolutely necessary — you do so at your own risk.
§7. Retention periods
7.1. We retain data for the following periods:
- Account data — until Account deletion or a deletion request.
- Server logs — up to 90 days, unless longer retention is required to establish claims.
- Correspondence — up to 3 years from case closure.
- Billing data (Stripe) — as required by tax law (typically 5 years).
- User files — deleted immediately after processing (usually seconds to minutes).
- Cookie preferences — up to 12 months or until consent is withdrawn.
§8. Your rights (GDPR)
8.1. You have the following rights:
- Right of access (Art. 15 GDPR).
- Right to rectification (Art. 16 GDPR).
- Right to erasure — “right to be forgotten” (Art. 17 GDPR).
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR).
- Right to object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).
- Right to withdraw consent at any time — without affecting lawfulness of processing before withdrawal (Art. 7(3) GDPR).
- Right to lodge a complaint with a supervisory authority (in Poland: PUODO, uodo.gov.pl).
8.2. To exercise your rights, write to badyltech@outlook.com. I will respond without undue delay, within 30 days at latest.
§9. Data security
9.1. I apply technical and organizational measures appropriate to the risk, including HTTPS encryption, limited system access, and deletion of files after processing.
9.2. No system is 100% secure. In case of a personal data breach likely to result in high risk to your rights, I will inform you in accordance with Art. 34 GDPR.
§10. Children
10.1. The Service is not directed at children under 16. I do not knowingly process data of children under 16 without a guardian's consent.
10.2. If you believe a child provided data without guardian consent, contact badyltech@outlook.com — the data will be deleted.
§11. Changes to this Policy
11.1. This Policy may be updated to reflect changes in the Service, technologies, or law.
11.2. Material changes will be communicated via a Service notice or email (for users with Accounts).
11.3. The current version is always available at /polityka-prywatnosci.
Privacy questions: badyltech@outlook.com. Terms of Service available at /regulamin.