DBC1
  • Product
  • Solutions
    • For IT
    • For HR
  • Customers
  • Security
  • Company
  • Blog
AccountBook a demo

Cardholder Privacy Notice

DBC1 sp. z o.o. - Public

Version: v1.0 Last updated: 29 August 2026

This notice is for people who have been issued a business card by their employer that was produced by DBC1, and for people who tap or scan one.

It is written to be read without a legal background. If you want the detail, everything here is set out in the agreement between DBC1 and your employer.

In short

Your employer decided to issue you a business card and chose what appears on it. DBC1 is the company that makes the card and runs the page it links to. We do this on your employer's instructions - we do not decide what information is on your card, and we do not use it for our own purposes.

If you want your details changed or removed, ask your employer. They can do it themselves, and they are the right people to ask.

1. Who does what

  • Role
  • Your employer
  • Decides what data is held about you, why, and for how long. In legal terms, the controller.
  • DBC1
  • Stores the data, produces the card, and runs the page it links to, following your employer's instructions. In legal terms, the processor.

This means your employer's own privacy notice applies to you, and your rights are exercised through them.

2. What we hold about you

Only what your employer gives us, or what you add yourself if they have enabled that. Typically:

  • your name, and how it should be written or pronounced;
  • your job title, department and work location;
  • your work e-mail, and a telephone number your employer has given us - we are not told whether it is a work or a personal number, so if you would rather it were not shown, ask your employer to change it;
  • a photograph, if your employer includes one;
  • a short biography and links to professional profiles, if your employer includes them;
  • sign-in details, if you have access to the app;
  • a delivery address, if cards are sent to you directly rather than to an office. This may be your home address if that is what your employer has arranged.

We are told not to hold sensitive information about you - such as health data or anything revealing your beliefs, background or private life - and our service is not built for it.

2a. Things you add yourself

Your employer may switch on optional fields you can fill in yourself - a short biography, and links to your profiles on named platforms such as LinkedIn. Each link field only accepts an address on the platform it is for, so you cannot point it somewhere unrelated.

Three things worth knowing:

It is genuinely optional. Nobody has to fill these in, and there should be no consequence if you do not.

Whatever you add is visible to anyone holding your card's address. Your card page has no login. The address contains a long random identifier, so nobody can find it by guessing or by browsing - but once someone has it, whether from your card, a forwarded link or a screenshot, they can see everything on the page. It is closer to a public profile than to a message sent to one person.

You can remove it yourself. You can edit or delete anything you added, at any time, without asking anyone.

2c. Extra QR codes you can create

Your employer may let you generate additional QR codes that lead to the same card page, each with a label you choose - "Berlin conference", "October webinar", or whatever helps you tell them apart. You can put them on slides, in a footer, on a poster.

What your employer can see: how many times each labelled code was used, and when. Combined with your labels, that shows where you have been publishing your details and which of those places people used.

What is not recorded: who scanned. Not their name, not their identity, and no location more precise than the country.

If you would rather not create labelled codes, you do not have to - a plain card works exactly the same way. And if you have questions about what your employer does with this information, ask them; they decide, not us.

One thing to keep in mind: a code on a conference slide can be photographed, shared and re-posted. It leads to the same page as your card, so treat publishing one as making that page more widely known.

2b. If someone shares your card link

Your employer may switch on link previews. When that is on and someone pastes your card address into a chat or messaging app, the app shows a small preview instead of a plain web address.

Your employer chooses what that preview contains. It can show your photograph, your name and your job title; or your name and job title without the photograph; or nothing about you at all - only your employer's branding; or previews can be switched off entirely.

Two things follow from that, and both are worth knowing.

The app that shows the preview has to fetch your name and photograph from us in order to display it. So the company operating that app receives them. Which company that is depends on where the link was shared, and neither we nor your employer chooses it.

Previews are stored by those apps and we cannot get them back. If a colleague shares your card in a channel today, the preview may still sit in that channel's history long after you have left and your details have been deleted from our systems. We can stop serving your name and photograph - and we do, as soon as you are deactivated - but we cannot reach into someone else's app and remove a copy already made there. Nor can your employer.

This is a real limit on deleting your data, so we would rather say it plainly than leave you to discover it.

This setting belongs to your employer, not to you - it applies to everyone in the organisation and you cannot change it for yourself. If you would rather your photograph, or your details generally, did not appear in previews, that is a conversation to have with them. They can remove the photograph, remove your details altogether, or switch previews off.

The biography is a free text field, so please do not write anything there that reveals something you would rather keep private - your health, your beliefs, your politics, your union membership, or your sex life. Once it is on the page, it can be copied or screenshotted by anyone who sees it.

3. What happens when someone taps or scans your card

They are taken to your card page. We record that it happened, so that your employer can see how often cards are being used.

What is recorded: the time, the general type of device, and the country the scan came from, worked out from the internet address. Nothing more precise than the country - not the city, not the street, not a position on a map.

What is not recorded: who the person is. We do not identify them, we do not place a tracking cookie, and we do not follow them to other websites.

If your card plays how your name is pronounced, your employer has switched that on. The audio is generated by a speech service: your name, and only your name, is sent to that service once to make the file. We keep the file and play it from our own systems, so nothing is sent again when someone opens your page. The service is contractually forbidden from using your name to train anything, and machine-generated audio is labelled as such.

If you would rather not have a pronunciation at all, remove it - it is yours to delete.

If you save your card to a phone wallet, what happens depends on which wallet, and your employer chooses which are available.

With Apple Wallet, the pass comes from us to your phone. Apple does not receive what is on it.

With Google Wallet, the pass is stored on Google's servers and linked to your Google account, so Google does receive your name, job title and contact details. Google also does not allow photographs on its passes, so your photo will not appear there even if it appears elsewhere.

You never have to use either. Our app shows your code directly, without any wallet and without anyone else receiving your details.

If your employer uses our browser extension, it shows your code on screen during video calls. It does not listen to your meetings, does not read what is said or shown, does not see who else is on the call, and does not record the name of the meeting. It notes only that your code was displayed, and when.

If someone chooses to send you their own contact details through your card page, those details go to your employer's account, and may also be passed to a system your employer has chosen, such as their sales system. How that data is handled is your employer's responsibility, and your employer is the one who must tell that person what happens to it.

4. What we use it for

To produce your card, to run your card page, to create your digital wallet pass and e-mail signature if your employer uses those, to deliver the card to you, and to show your employer how often cards are used.

We send you e-mail only when the service requires it - for example a link to add your card to your phone's wallet, or a notice that your cards have been despatched. Those links expire and can be used once.

We only ever e-mail you, at your work address. We will never send you a text message. If you receive an SMS claiming to be from DBC1 with a link in it, it is not from us - please report it to your IT team.

We never add your address to a mailing list of ours. We do not use your data to advertise to you, we do not sell it, and we do not share it with advertising networks.

We do not send your data to artificial intelligence services, and we do not use it to train any machine learning model.

5. Where your data is

On servers in the European Union.

The one exception is delivery: if your card is posted to you, the carrier is given your name, address and, if delivery notifications are switched on, your phone number or e-mail. If you are outside the EU, that information necessarily travels to where the card is going.

6. Who else sees it

Only companies that help us run the service - cloud hosting, card production, support tooling and monitoring - and only as far as they need to. They all operate within the European Economic Area, they are contractually bound, and they cannot use your data for their own purposes.

We publish the categories of company we use at trust.dbc1.com. Your employer has the full list, including names, as part of its agreement with us. If you want to know who specifically is involved, ask them.

Your employer decides who inside their organisation can see your record.

7. How long it is kept

For as long as your employer wants, within the limits they have configured. They choose the periods, not us.

When your employer removes you from their systems - for example because you leave - your record is deleted after the period they have set. Files we generate to print your cards are deleted automatically after 90 days, whatever else is configured.

If you want to know the exact periods that apply to you, ask your employer; they set them and can tell you.

8. Your card after you leave

Your details come down. Your name, photograph, contact details and anything you added yourself are deleted on the schedule your employer has set - typically shortly after you are removed from their systems.

The cards themselves cannot be collected back in. People you handed them to still have them, and may tap one months later. Your employer chooses what happens then:

  • A message with an alternative contact - someone tapping the card sees a short note saying the person is no longer available, with an address or number to use instead. Our standard wording does not include your name and does not say why you left. Your employer can change the wording, and is responsible for what it says.
  • Nothing at all - the card simply stops working.

If you are not comfortable with what the message says, contact your former employer. They decide the wording and they can switch the card off entirely. If you ask us, we will pass the request to them.

The card itself is your employer's property unless they have told you otherwise.

9. Your rights

You have the right to see what is held about you, to have it corrected, to have it deleted in some circumstances, to object to how it is used, and to complain to a data protection authority.

Ask your employer first. They control the data and can usually act immediately. If you contact us directly, we will pass your request to them and let you know we have done so - we are not permitted to change or delete your record without their instruction.

If you are not satisfied, you can complain to the data protection authority in the country where you live or work. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw.

10. Contact

Your employer - for anything about your data, your card, or your details.

DBC1 - for questions about how the service itself works: dpo@dbc1.com, DBC1 sp. z o.o., ul. Św. Mikołaja 8-11, 50-125 Wrocław, Poland.

DBC1

The infrastructure behind every handshake. Business card management for enterprise teams.

Product

  • Overview
  • Status
  • For IT
  • For HR
  • Customers

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms of Use
  • Cardholder Privacy Notice
  • Trust Center

Company

  • Contact
  • Brand & press
© 2026 DBC1 Sp. z o.o.
×

Book a demo

Trouble loading? Open the form in a new tab
×

Contact us

Trouble loading? Open the form in a new tab