Appaya Privacy and Cookie Policy

Effective date: 27 August 2026

§ 1. General provisions

  1. This Privacy and Cookie Policy sets out the rules for the processing of personal data and the use of cookies and similar technologies in connection with use of the Appaya website available at: https://appaya.net/
  2. This Policy has been prepared in particular on the basis of:
    • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the ‘GDPR (RODO)’);
    • the Act of 10 May 2018 on the protection of personal data;
    • the Act of 18 July 2002 on the provision of services by electronic means;
    • the Act of 12 July 2024 – Electronic Communications Law;
    • other applicable provisions of law.
  3. This Policy applies to data processed in connection with use of the Website, including data submitted through the Submission Form.

§ 2. Data controller

  1. The controller of personal data is:
    • Appaya Sp. z o.o.
    • Aleje Jerozolimskie 109 / 70
    • 02-011 Warszawa
    • Polska
    • NIP: 7011288190
    • KRS: 0001207992
    • REGON: 543353962
  2. For matters concerning personal data, the Controller may be contacted at: studio@appaya.net
  3. The Controller has not appointed a Data Protection Officer unless the obligation to make such an appointment arises under applicable law.

§ 3. Data we process

Depending on how the Website is used, the Controller may process:

  1. the email address provided in the Form;
  2. information concerning the submitted application, in particular:
    • the application title;
    • a description of the application;
    • information concerning the preferred model;
  3. Materials uploaded by the User, in particular:
    • screenshots;
    • demo recordings;
    • other files provided as part of the Submission;
  4. technical data associated with use of the Website, which may include, in particular, the IP address, connection date and time, information concerning the browser and device, and requests sent to the server;
  5. data contained in correspondence sent to Appaya.

§ 4. Purposes and legal bases of processing

1. Handling the Submission

Data provided through the Form is processed for the purpose of:

  1. receiving the Submission;
  2. reviewing the presented application;
  3. conducting a preliminary assessment of the Submission;
  4. contacting the User regarding the Submission;
  5. providing a response;
  6. obtaining additional information concerning the Submission, where necessary.

The legal basis is Article 6(1)(b) GDPR – taking steps at the request of the data subject prior to the potential conclusion of a contract and performance of the service provided by electronic means consisting in handling the Form.

2. Security and proper operation of the Website

Technical data, including server connection data, may be processed for the purpose of:

  1. ensuring the security of the Website;
  2. detecting abuse and attempted unauthorised access;
  3. preventing attacks;
  4. ensuring the proper operation of the infrastructure;
  5. diagnosing errors.

The legal basis is Article 6(1)(f) GDPR – the Controller’s legitimate interest in ensuring the security and proper operation of the Website.

3. Traffic and activity analysis

  1. The Controller uses its own server-side tools for basic analysis of traffic and activity on the Website.
  2. This analysis is used solely for purposes related to the operation, security and improvement of the Website.
  3. These tools do not store cookies or other identifiers used to track the User’s activity on the User’s device.
  4. The legal basis for processing is Article 6(1)(f) GDPR – the Controller’s legitimate interest in maintaining, securing and improving the Website.

4. Contact and correspondence

  1. Data contained in messages sent to Appaya is processed for the purpose of handling correspondence and providing a response.
  2. The legal basis is Article 6(1)(f) GDPR and, depending on the nature of the contact, also Article 6(1)(b) GDPR.

5. Establishment, exercise or defence of legal claims

  1. Data may be processed for the purpose of establishing, exercising or defending legal claims.
  2. The legal basis is Article 6(1)(f) GDPR.

6. Legal obligations

Where the processing of data is necessary for compliance with a legal obligation to which the Controller is subject, the legal basis is Article 6(1)(c) GDPR.

§ 5. Submissions, screenshots and recordings

  1. The Submission, together with the screenshots, recordings and other Materials provided, is stored in Appaya’s IT system as a single Submission.
  2. The data and Materials are stored on the infrastructure used by Appaya to operate the Website.
  3. Submission data and Materials are not automatically transferred to external submission management platforms.
  4. Before uploading Materials, the User should remove from them any personal data, login details, passwords, access keys and other information that does not need to be provided in order to present the application.
  5. In particular, the User should avoid uploading special categories of personal data within the meaning of Article 9 GDPR unless this is necessary to present the application.
  6. If the User voluntarily includes third-party personal data in the Materials, the User should have a legal basis permitting its disclosure to the Controller.

§ 6. Provision of data

  1. Providing the data marked as required in the Form is necessary for the Submission to be properly sent and handled.
  2. Failure to provide the required data may prevent the Submission from being sent.
  3. The provision of additional information and Materials is voluntary; however, failure to provide them may limit the ability to assess the presented application.
  4. No data need be provided merely to browse the Website.

§ 7. Data retention period

  1. Data and Materials associated with a Submission are retained for the period necessary to handle and assess it.
  2. If no further cooperation is established after handling of the Submission has ended, the data and Materials are generally retained for 12 months from the last contact concerning the Submission and are then erased or anonymised, unless continued retention is justified by a legal obligation or the need to establish, exercise or defend legal claims.
  3. Data may be retained for longer where necessary to establish, exercise or defend legal claims – for a period corresponding to the limitation period applicable to the relevant claim.
  4. Technical data associated with the security and operation of the Website is retained for the period necessary to fulfil those purposes.
  5. Data contained in correspondence is retained for the period necessary to handle the matter and thereafter for a period justified by the need to preserve information about the course of the contact or to defend legal claims.
  6. System backups may contain data subject to erasure under the rules above. Data contained in backups is erased as part of the applicable backup overwrite cycle, unless its earlier erasure is required by law.

§ 8. Recipients of data

  1. Personal data may be disclosed to entities processing data on Appaya’s behalf, solely to the extent necessary for the proper operation of the Website and handling of Submissions.
  2. Such entities include, in particular:
    • Hetzner – the provider of server infrastructure used by Appaya to operate the Website and store data;
    • Google Workspace / Google – the provider of email services used by Appaya to conduct correspondence, including via studio@appaya.net.
  3. The Controller may also use the services of other entities where necessary for the proper operation of the Website or compliance with legal obligations. In such a case, those entities receive only the data necessary to provide the specific service.
  4. Data may be disclosed to public authorities or other authorised entities where such an obligation arises under applicable law.
  5. The Controller does not sell Users’ personal data.

§ 9. Transfers of data outside the European Economic Area

  1. The use of certain technology providers may involve the transfer of personal data outside the European Economic Area.
  2. In the event of such a transfer, the Controller ensures that an appropriate mechanism provided for in the GDPR is applied, in particular an adequacy decision or appropriate safeguards provided for in Chapter V GDPR.
  3. The Controller does not transfer Submissions or Materials to external analytics or marketing platforms.

§ 10. User rights

To the extent provided for in the GDPR, the data subject has the right to:

  1. access personal data;
  2. receive a copy of the data;
  3. rectify the data;
  4. complete incomplete data;
  5. erase the data;
  6. restrict processing;
  7. data portability – in the cases provided for in the GDPR;
  8. object to processing based on Article 6(1)(e) or (f) GDPR;
  9. lodge a complaint with a supervisory authority.
  1. To exercise their rights, Users may contact the Controller at: studio@appaya.net
  2. The Controller responds to requests concerning data subject rights within the time limits specified in the GDPR.

§ 11. Right to lodge a complaint

  1. A data subject has the right to lodge a complaint with the competent supervisory authority if they consider that the processing of their personal data infringes the GDPR.
  2. The supervisory authority competent in Poland is the President of the Personal Data Protection Office.

§ 12. Automated decision-making and profiling

  1. Appaya does not use data from the Form to make decisions concerning the User that produce legal effects or similarly significantly affect the User based solely on automated processing.
  2. The submitted application may be assessed by persons acting on behalf of Appaya.

§ 13. Cookies and similar technologies

  1. The Website does not use cookies or similar technologies to profile Users or track their activity for behavioural advertising purposes.
  2. Appaya’s own analytics tools operate server-side and do not store cookies or other identifiers used to track the User on the User’s device.
  3. The Website may use technical mechanisms necessary for its proper operation, which may relate to request handling, security or the proper operation of a particular feature.
  4. If technologies requiring the User’s consent to store information on their device or access information already stored on it are implemented on the Website in the future, the method of obtaining and withdrawing consent will be adapted to the law applicable at that time.

§ 14. Data security

  1. Appaya implements appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration or disclosure.
  2. Submission data is stored in Appaya’s secure IT system.
  3. Access to data is restricted to persons and entities for whom access is necessary to perform their assigned tasks.
  4. The User should exercise particular caution when preparing Materials and should not submit passwords, login details, API keys or other data enabling access to systems through the Form unless this is necessary.

§ 15. Third-party data

  1. The Form is intended primarily for providing information concerning the User’s own application.
  2. The User should not provide third-party personal data unless this is necessary.
  3. If the User provides third-party personal data, the User should have an appropriate legal basis for doing so.
  4. Where the Controller obtains the data of a third party provided by the User, the Controller may be required to comply with the obligations arising under Article 14 GDPR, subject to the exceptions provided for in that Article.

§ 16. Amendments to the Policy

The Controller may amend this Policy, in particular in the event of:

  1. changes in the law;
  2. changes in how the Website operates;
  3. changes in how data is processed;
  4. changes of service providers;
  5. the introduction of new features.
  1. The current version of the Policy is published on the Website.
  2. Each version of the Policy states its effective date.

§ 17. Contact

For matters concerning the protection of personal data, Appaya may be contacted:

Appaya Sp. z o.o.Aleje Jerozolimskie 109 / 7002-011 WarszawaPolskae-mail: studio@appaya.net

§ 18. Final provisions

  1. This Policy is effective from 27 August 2026.
  2. The Policy is made available on the Website in a manner that enables it to be saved and reproduced.
  3. Matters not governed by this Policy are subject to the GDPR and other applicable provisions of Polish law.