LEGAL
Privacy Policy
Last updated: 2026-04-10
1. Data Controller
Roksana Wierzbicka RoxApp, Dębowa 4, 66-330 Szarcz, Poland, NIP 7611531687,
is the data controller under the EU General Data Protection Regulation (GDPR). Contact:
contact@rox-app.com.
2. What data we collect
- Contact form submissions: name, email, subject, message. Used solely to respond to your inquiry.
- Product accounts (where applicable): email, name, and product-specific information required to deliver the service.
- Payment data: processed directly by Stripe. We do not store card details on our servers. Stripe's privacy policy applies in addition to ours.
- Technical logs: IP address, browser user agent, timestamps, for security and abuse prevention. Retained for up to 30 days.
3. Legal basis (Art. 6 GDPR)
- Contract performance — for paid services and custom work.
- Legitimate interest — for security logging and spam prevention.
- Consent — for any optional communications.
- Legal obligation — for tax and accounting records.
4. Data sharing and processors
We use the following third-party processors:
- Vercel — hosting (EU regions).
- Web3Forms — contact form delivery.
- Stripe — payment processing.
- Email providers used for support correspondence.
We do not sell personal data and do not share it with advertisers.
5. International transfers
Where processors operate outside the EEA, transfers rely on Standard Contractual Clauses or equivalent safeguards.
6. Retention
Contact form messages: up to 12 months. Customer account data: for the duration of the contract plus statutory retention periods (typically 5–10 years for invoicing data under Polish law). Technical logs: up to 30 days.
7. Your rights
Under the GDPR you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Request erasure ("right to be forgotten").
- Restrict or object to processing.
- Data portability.
- Lodge a complaint with the Polish supervisory authority (UODO).
To exercise any of these rights, contact us at contact@rox-app.com.
8. Cookies
RoxApp's marketing website uses one essential functional cookie (roxapp-lang) to
remember your language preference. It stores no personal data and does not track you. No
marketing or analytics cookies are set by default.