Version: 1.0
Effective date: 13 July 2026
1. Scope of this document
This Privacy Policy explains how personal data is processed in connection with the use of the MOCADO service and platform — Multi Content Delivery Platform — available under the following domains:
mocado.pl,
mocado.com.pl,
mocado.eu,
and their publicly available subdomains, in particular app and api.
This document covers the website, contact forms, user accounts, SaaS platform operation, communication, billing and activities related to service security.
The use of cookies and similar technologies is described in a separate Cookie Policy.
2. Data Controller
The controller of personal data processed for the purposes of operating the service, managing accounts, entering into and performing contracts and communicating with users is:
Krzysztof Polak, an entrepreneur conducting business activity under the business name Krzysztof Polak, Polish Tax Identification Number (NIP): 6572286992.
Contact regarding privacy and personal data matters: kontakt@polak.net.pl.
The Controller has not appointed a Data Protection Officer. All matters concerning the processing of personal data may be addressed directly to the e-mail address indicated above.
3. MOCADO’s roles in data processing
Depending on the type of data, MOCADO may act in two different roles:
Data Controller — with respect to the personal data of website visitors, account users, customers, prospective customers, communication recipients and persons contacting MOCADO.
Data Processor — with respect to personal data entered into the platform by customers or transmitted through the platform for their own purposes, in particular data contained in published content and recipient databases.
In the latter case, the MOCADO customer remains the Data Controller. Detailed rules governing the processing of personal data on behalf of a customer are set out in a Data Processing Agreement concluded with the customer.
4. What data may be processed
Depending on how MOCADO is used, the following categories of personal data may be processed:
identification data, such as first name, surname, company name and job title;
contact details, such as e-mail address and telephone number;
account data, such as user identifier, role, organisation and permissions information;
authentication data in an appropriately secured form; passwords are not stored in plain text;
data relating to contracts, service plans, orders, payments, invoices and settlements;
the content of correspondence, support requests and contacts with technical support;
data concerning the use of the website and platform, such as visited pages, performed operations and application events;
technical and operational data, such as IP address, connection date and time, device type, operating system, browser and system logs;
consent settings and communication preferences;
data provided by a customer while using the platform’s functions.
Providing personal data is voluntary, but it may be necessary to create an account, enter into and perform a contract, receive a response or use certain functions.
MOCADO is not intended for the deliberate processing of special categories of personal data referred to in Article 9 of the GDPR. Customers should not enter such data into the platform unless this has been agreed in advance and there is an appropriate legal basis and adequate safeguards.
5. Purposes and legal bases for processing
Responding to enquiries and handling contact forms
Article 6(1)(f) GDPR — legitimate interest consisting in conducting communication; Article 6(1)(b) GDPR where the contact is aimed at entering into a contract.
Creating and maintaining an account and providing SaaS services
Article 6(1)(b) GDPR — entering into and performing a contract.
Customer support, support requests and technical assistance
Article 6(1)(b) and (f) GDPR — performance of a contract and ensuring efficient customer support.
Billing, invoicing and compliance with tax or accounting obligations
Article 6(1)(c) GDPR — compliance with a legal obligation.
Establishing, pursuing or defending legal claims
Article 6(1)(f) GDPR — protection of the Controller’s rights.
Ensuring security, preventing abuse, diagnosing errors and maintaining logs
Article 6(1)(f) GDPR — security and reliability of services.
Statistical measurements and analytics concerning the use of the public website
Article 6(1)(a) GDPR — consent, where optional cookies or similar technologies are used.
Newsletter and electronic marketing
Article 6(1)(a) GDPR — consent; where appropriate, also Article 6(1)(f) GDPR, subject to the requirements applicable to electronic communications.
Sending SMS messages related to the service
Article 6(1)(b) GDPR where the message is necessary for the performance of a contract; in the case of marketing — consent pursuant to Article 6(1)(a) GDPR.
Quality assessment, feature development and platform improvement
Article 6(1)(f) GDPR — development and optimisation of services.
Where processing is based on consent, consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
6. Sources of personal data
Personal data is obtained primarily directly from the data subject, for example when completing a form, creating an account, entering into a contract or contacting technical support.
Personal data may also be obtained:
from an employer, colleague or organisation that created a user account;
from a MOCADO customer, where the customer has provided the data in connection with the use of the platform;
from a payment service provider, with respect to transaction status and identifiers;
automatically from the device and software used to access the service.
7. Recipients of personal data
Personal data may be disclosed to entities supporting the operation of MOCADO, solely to the extent necessary to achieve a specific purpose. Such entities may include in particular:
providers of IT infrastructure, hosting, backup and security tools;
providers of e-mail and message delivery services, including Amazon Web Services in connection with Amazon Simple Email Service (SES);
analytics service providers, including Google Analytics, after obtaining the required consent;
providers of customer service and communication systems;
newsletter, payment and SMS service providers, after these functions are launched;
accounting firms, legal advisers, auditors and insurers;
public authorities where disclosure of personal data is required by law.
Service providers receive only the data necessary to perform the tasks entrusted to them and are required to ensure appropriate security. An up-to-date list of key processors may be made available upon a justified request.
8. Transfers of personal data outside the European Economic Area
Some technology providers may process personal data outside the European Economic Area, in particular in the United States.
In such cases, the transfer of personal data is carried out using a mechanism permitted under the GDPR, in particular:
an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework where the recipient participates in that framework;
Standard Contractual Clauses approved by the European Commission;
another legal basis provided for in Chapter V of the GDPR.
Where appropriate, the Controller assesses the risks associated with the transfer and applies additional technical or organisational safeguards.
9. Data retention period
Personal data is retained no longer than necessary for the purpose for which it was collected:
account data and data related to the service — for the duration of the contract and thereafter until the expiry of the applicable limitation period for claims;
billing data and accounting documentation — for the period required by tax and accounting laws;
correspondence and support requests — for the period necessary to handle the matter and thereafter until the expiry of any applicable limitation period for claims;
technical and security logs — for the period necessary to ensure security, analyse events and perform diagnostics, and for a longer period only where they relate to an incident or where required by law;
analytics data — in accordance with the retention period configured in the analytics tool, no longer than 14 months unless the data has been effectively anonymised;
data processed on the basis of consent — until consent is withdrawn or until the purpose of processing ceases to exist;
data used to establish, pursue or defend claims — until the conclusion of proceedings or the expiry of the applicable limitation periods.
After the applicable retention period expires, personal data is deleted, anonymised or remains blocked only to the extent required by law.
10. Rights of data subjects
Subject to the conditions set out in the GDPR, data subjects have the right to:
access their personal data and obtain a copy;
rectify their personal data;
erase their personal data;
restrict processing;
data portability;
object to processing based on legitimate interests;
withdraw consent at any time;
lodge a complaint with the President of the Personal Data Protection Office in Poland.
Requests relating to the exercise of rights may be sent to kontakt@polak.net.pl. Before fulfilling a request, the Controller may ask for information necessary to verify the identity of the person making the request.
A complaint may be lodged with the President of the Personal Data Protection Office. Current contact details of the supervisory authority are available at uodo.gov.pl.
Where MOCADO processes personal data solely on behalf of a customer as a Data Processor, a request concerning such data should primarily be addressed to the relevant customer acting as the Data Controller. MOCADO supports the customer in handling such requests in accordance with the Data Processing Agreement.
11. Automated decision-making and profiling
Personal data is currently not used to make decisions concerning individuals based solely on automated processing that would produce legal effects or similarly significantly affect them.
If such functionality is introduced, this document will be updated before such processing begins, and data subjects will receive the information required by law regarding the rules, significance and anticipated consequences of such processing.
12. Data security
The Controller applies technical and organisational measures appropriate to the level of risk, including in particular access and permission controls, encryption of data in transit, backups, event logging, software updates and incident response procedures.
No method of transmitting or storing data can guarantee complete security. In the event of a personal data breach, the Controller takes the actions required under the GDPR, including, where required, notifying the competent supervisory authority and the affected data subjects.
13. Children’s data
MOCADO is a service intended for businesses, organisations and persons acting in a professional capacity. The service is not intended for children, and the Controller does not knowingly collect children’s personal data in connection with their independent use of the platform.
Where a customer uses MOCADO to process children’s personal data, the customer is responsible for ensuring an appropriate legal basis, fulfilling information obligations and entering into any required Data Processing Agreement.
14. Planned services
Newsletter, payment and SMS communication functions may be launched in the future. Personal data will be processed for these purposes only after the relevant functions have been implemented, the required information has been provided and, where necessary, consent has been obtained.
Once specific service providers have been selected, this Privacy Policy will be supplemented before their services are used.
15. Changes to this Privacy Policy
This Privacy Policy may be updated if MOCADO’s functions, data processing methods, service providers or applicable laws change.
The current version is published on the MOCADO website together with its effective date. Users with an account may be informed of material changes through the application or by e-mail.