Version: v1.0 Last updated: 29 August 2026
DBC1 sp. z o.o., with its registered office at ul. Św. Mikołaja 8-11, 50-125 Wrocław, Poland, entered in the register of entrepreneurs under KRS number 0001261583, NIP PL8971977641 ("DBC1", "we", "us"), is the controller of the personal data described in this Policy.
You can contact us about data protection at dpo@dbc1.com or by post at the address above.
We have appointed an external Data Protection Officer, who can be reached at dpo@dbc1.com or by post at the address above.
This Policy explains how we handle personal data where we decide why and how it is processed. That means:
What this Policy does not cover. Where an organisation uses our platform to issue business cards to its own people, that organisation decides what data is held about them and why. We process that data on its instructions, and it is responsible for informing those individuals. If you have received a business card from your employer that was produced by us, see our Cardholder Privacy Notice instead.
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, browser and device information, pages viewed, referring page | Operating and securing the website; understanding how it is used | Legitimate interests (Art. 6(1)(f) GDPR) - running and improving our site |
| Cookie and similar identifiers, including analytics and advertising identifiers on our marketing website | As described in our Cookie Policy | Consent (Art. 6(1)(a)), except for strictly necessary cookies |
Our marketing website uses Google Analytics, which processes data in the United States under the EU-US Data Privacy Framework, and the LinkedIn Insight Tag, which LinkedIn also uses as an independent controller for its own advertising purposes. Both are set only with your consent, and neither is present on our platform, our card pages, our forms domain or our trust centre.
| Data | Purpose | Legal basis |
|---|---|---|
| Name, business e-mail, telephone, employer, job title, message content | Responding to enquiries, arranging demonstrations, sending a Material Sampler | Steps prior to entering a contract (Art. 6(1)(b)); legitimate interests where you contact us on behalf of an organisation (Art. 6(1)(f)) |
| Delivery address for a Material Sampler | Shipping the sampler | Art. 6(1)(b) / (f) |
| Meeting scheduling data | Arranging calls | Art. 6(1)(b) / (f) |
| Recording and transcript of a call to our demonstration line, where you are told at the start of the call | Handling your enquiry and improving how we answer questions | Consent (Art. 6(1)(a)), which you may withdraw by ending the call or contacting us |
| Data | Purpose | Legal basis |
|---|---|---|
| Name, business e-mail, organisation, job title, stated purpose | Deciding whether to release restricted documents, and recording what was released to whom | Legitimate interests (Art. 6(1)(f)) - protecting confidential material and knowing who is evaluating us |
| IP address, timestamp, the version of the terms you accepted, and which documents you received | Keeping an audit trail of the confidentiality obligation you accepted | Legitimate interests (Art. 6(1)(f)) |
| E-mail address and chosen categories, if you subscribe to updates | Telling you when published documents change | Legitimate interests (Art. 6(1)(f)) - you asked to be told, and every message carries an unsubscribe link |
Documents released this way are watermarked at the point of download with your e-mail address, your IP address and the time, so that each copy is traceable to a single download. We keep request and release records for 24 months from your last release; subscriber addresses until you unsubscribe. Subscribing does not put you on any marketing list.
Status page notifications work the same way. If you subscribe to incident and maintenance notices at status.dbc1.com, we hold your e-mail address for that purpose only, through the provider that hosts the page, and you can unsubscribe from any message.
| Data | Purpose | Legal basis |
|---|---|---|
| Name, job title, business contact details, employer, publicly available professional information | Business-to-business marketing and relationship management | Legitimate interests (Art. 6(1)(f)) - promoting our services to relevant organisations |
| Electronic marketing preferences | Sending, and not sending, marketing communications | Consent where required by the Polish Telecommunications Law and Act on the Provision of Electronic Services |
You can object to marketing at any time by using the unsubscribe link in any message or by contacting us. We will stop.
| Data | Purpose | Legal basis |
|---|---|---|
| Name, business e-mail, role, authentication identifiers, session and device data | Providing access to the platform; authentication; account administration | Performance of our contract with your organisation (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Security and audit logs, including access events and administrative actions | Securing the platform, investigating incidents, meeting our accountability obligations | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
| Support requests and correspondence | Providing support | Art. 6(1)(b) / (f) |
| Product usage in aggregated or pseudonymised form | Improving the service | Legitimate interests (Art. 6(1)(f)) |
| Business e-mail address, for service notices - maintenance, incidents, security advisories, changes to the service, billing | Operating the service you administer | Performance of our contract with your organisation (Art. 6(1)(b)); legal obligation for security notices (Art. 6(1)(c)) |
| Business e-mail address, for product communications - new functionality, release notes, guidance | Keeping the people who administer our product informed about it | Legitimate interests (Art. 6(1)(f)) - you can decline these at any time using the link in any such message, and service notices will continue |
Service notices cannot be declined while you hold an administrator role, because they are necessary to operate the service. Product communications can. Where a message promotes a paid upgrade or a separate offering, we treat it as marketing and send it only with your consent.
| Data | Purpose | Legal basis |
|---|---|---|
| Contact details of individuals at the organisation, contract and order records | Managing the relationship and performing contracts | Art. 6(1)(b) / (f) |
| Billing records, invoices, payment data | Invoicing, accounting and tax | Legal obligation (Art. 6(1)(c)) |
| Sanctions and compliance screening results | Meeting sanctions and anti-money-laundering obligations | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| Data | Purpose | Legal basis |
|---|---|---|
| Application, CV, correspondence, interview notes | Assessing your application | Steps prior to a contract (Art. 6(1)(b)); consent for retention beyond the process (Art. 6(1)(a)) |
We ask you not to send us more information than is needed to assess your application.
Directly from you; from your employer, where it is our customer or a prospective customer; from your colleagues; from public sources such as company websites and professional networks; and automatically, when you use our website or platform.
We share personal data with:
Our customer relationship management system runs on our own infrastructure in the European Union. It is not a third-party service, and no external provider holds the business contact details we keep in it. - Professional advisers - lawyers, accountants and auditors, where necessary. - Carriers, where we ship something to you. - Public authorities, where we are required by law to disclose. - A purchaser or successor, in the event of a merger, reorganisation or sale of our business.
We do not sell personal data, and we do not share it with advertising networks for cross-site targeting.
We do not transmit personal data to third-party artificial intelligence services, and we do not use personal data to train machine learning models.
Our platform and its primary infrastructure operate in the European Union, and that is where the data we process for our customers is stored.
Some of the services we use process data elsewhere. Rather than imply otherwise, here is where that happens:
| What | Where | Safeguard |
|---|---|---|
| Transactional e-mail - messages we send you about the service | United States | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Website analytics, if you consent to analytics cookies | United States | EU-US Data Privacy Framework |
| Authentication, if you hold an account with us | United States | EU-US Data Privacy Framework and Standard Contractual Clauses |
| International delivery of a package to you | Wherever the package is going | Necessary to perform the contract - Art. 49(1)(b) GDPR |
Our customer relationship management system runs on our own infrastructure in the European Union and is not a third-party service.
We maintain an assessment of each transfer outside the EEA, covering the law of the destination country and the safeguards applied, and we review it annually. You can ask us for it, and for details of the safeguards in place, at dpo@dbc1.com.
If you are a business contact of ours and you would prefer your details not to sit in our records, tell us and we will remove them.
We keep each category of data for a defined period, apply it automatically wherever the system allows, and then delete or anonymise it.
The periods that most people ask about:
| Data | Retention |
|---|---|
| Enquiries that do not lead to a relationship | 24 months from last contact |
| Demonstration call recordings | 90 days |
| Marketing contact records | Until you object, then a minimal suppression record kept indefinitely so we do not contact you again |
| Contracts and order records | 6 years from the end of the contract |
| Invoices and accounting records | 5 years from the end of the tax year |
| Unsuccessful job applications | 6 months, or longer with your consent |
Our full retention schedule covers every category, including the data we process on behalf of our customers, and is available on request at dpo@dbc1.com. Where a legal obligation requires us to keep something longer than the period stated, the legal obligation applies and we record the reason.
Under the GDPR you have the right to:
To exercise any of these, contact dpo@dbc1.com. We will respond within one month. We may ask for information to confirm your identity.
Complaints. You may lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, or with the supervisory authority in the EU country where you live or work. We would appreciate the chance to address your concern first.
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you.
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, multi-factor authentication for administrative access, role-based access control, audit logging, and regular review of our security posture. A summary is published at trust.dbc1.com.
No system is completely secure. If a breach affects your personal data and is likely to result in a high risk to your rights, we will inform you.
Our use of cookies and similar technologies is described in our Cookie Policy.
Our services are intended for use by organisations and their personnel. They are not directed at children, and we do not knowingly collect personal data from children.
We may update this Policy. The current version and its date are shown at the top. Where a change materially affects how we use your data, we will bring it to your attention, for example by notice on our website or by e-mail.
Previous versions are available on request.
ul. Św. Mikołaja 8-11, 50-125 Wrocław dpo@dbc1.com