Legal document

Privacy Policy

Last updated: 26 July 2026

Language notice. This English text is a courtesy translation. The Polish version (Polityka prywatności) is the legally binding one; in case of any discrepancy, the Polish wording prevails.
TODO (owner): This document is a technical draft. The description of what data the system actually collects, where it is stored and how it is protected was filled in from the application code and reflects reality. The sections marked TODO are legal and organisational decisions (controller identity, retention periods, choice of legal bases, data processing agreements) — they need the owner's decision or a lawyer's input before this policy is published as binding.

This Policy explains how we process personal data in connection with the use of diagnostix.com.pl (the "Service") and the delivery of remote diagnostic services. It fulfils the information obligation under Articles 13 and 14 of the GDPR (Regulation (EU) 2016/679).

1. Controller and contact

The controller of personal data is: TODO (owner): full company name or sole trader's name, registered address / address for correspondence, tax identification number (NIP) and business register number (REGON). Without these, the Article 13 information obligation is not met — this field must be completed before publication.

Contact for data protection matters: [email protected].

TODO (owner): Confirm whether the address above is the right contact point for data protection matters, and decide whether a Data Protection Officer is appointed. At the current scale a DPO is usually not mandatory, but that assessment is yours and your lawyer's — once settled, state either the DPO's details or that no DPO has been appointed.

2. What data we process

The list below matches the actual data structure of the system.

2.1. Client (workshop) contact details

First and last name of the contact person, workshop name, phone number, e-mail address, city, optionally a tax identification number (for invoicing), the preferred language of correspondence and — if the Client uses the Client panel — a password hash (the password itself is never stored in plain text).

2.2. Submission and vehicle data

Make, model, production year, mileage, engine, gearbox and — optionally — the VIN; problem description, symptom description, tests performed, parts replaced and fault codes read; plus a record of the consents given (GDPR consent, acceptance of the terms) with their timestamp. We treat the VIN carefully: on its own it identifies a vehicle, but combined with other information it may allow the vehicle owner to be identified, so it is covered by the same rules as all other data.

2.3. Attachments

Photos, recordings, printouts and diagnostic files sent by the Client. Such files may incidentally contain personal data (e.g. a visible licence plate, a document with the vehicle owner's details) — see also section 12.

2.4. Correspondence and notes

The content of messages exchanged in the Service between the Client and the operator, with their sent and read timestamps, and the operator's internal notes on a case. Internal notes and materials flagged as internal are never shown to the Client in the Client panel, but they are still data processed by the controller.

2.5. Payment data

Amount, currency, payment status, payment provider, transaction identifier and line-item description. We do not store payment card data — it is handled solely by the payment provider (Stripe) on its own page.

2.6. Invoicing data

The system provides for storing buyer details (name, tax number, address) for invoicing purposes. This feature is not currently in use — invoices are issued outside the Service, in an external accounting system.

2.7. Audit log

A record of events in the system: who changed a case status, confirmed a payment, added a message or logged in, and when. IP addresses are recorded for login events. The log serves security and accountability.

2.8. Knowledge base (anonymised data)

When a case is closed, only a technical summary is added to the internal knowledge base: make, model, engine, gearbox, symptoms, fault codes, the identified root cause, the repair and keywords. The entry contains no name, workshop name, contact details or VIN.

2.9. Technical document library

An internal collection of technical documentation (wiring diagrams, service bulletins, manuals) keyed by vehicle make and model — it contains no personal data and is never shared with Clients.

3. Purposes and legal bases

TODO (owner): The table below lists candidate legal bases derived from what the system actually does. The final choice and wording of the legal bases — in particular the scope of legitimate interest (Art. 6(1)(f)) and the relationship between consent and contract performance — must be confirmed with a lawyer before publication.
PurposeCandidate legal basis
Accepting a submission, free initial review (triage), delivering the diagnostic service, case correspondenceArt. 6(1)(b) GDPR — necessary to perform a contract or take steps prior to entering into it
Operating the Client panel account (login, access to your own cases)Art. 6(1)(b) GDPR
Settling payments and accounting, issuing invoices, keeping tax recordsArt. 6(1)(c) GDPR — legal obligation (tax and accounting law)
Security of the Service: audit log, protection against abuse and spam, rate limiting per IP addressArt. 6(1)(f) GDPR — legitimate interest of the controller
Handling complaints and establishing, exercising or defending legal claimsArt. 6(1)(f) GDPR — legitimate interest of the controller
Recording the consents given at submission time (accountability)Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR

We do not run marketing based on the data we collect: there is no newsletter, no SMS campaigns and no sharing of data with third parties for marketing purposes. Every e-mail the Service sends is transactional (submission confirmation, case status change, payment link, password link).

4. Is providing data mandatory

Providing the data marked as required in the submission form is a condition of accepting the submission and concluding the contract — without it we cannot contact the Client or carry out the analysis. Providing optional data (tax number, VIN, attachments) is voluntary, although omitting it may slow the diagnosis down or make invoicing impossible.

5. Recipients of the data

Data is never sold or shared for marketing purposes. We use the following service providers, which may process data on our behalf to the extent necessary:

  • Stripe — online payment processing (you are redirected to a Stripe payment page). Receives the data needed to settle the transaction.
  • Resend — sending transactional e-mail (recipient address and message content).
  • Cloudflare — the network layer of the Service (connection encryption, protection against attacks and bots, the tunnel to the server). Network traffic, including the user's IP address, passes through this layer.
  • External accounting office / system — for issuing invoices and keeping accounting records. Invoices are currently issued outside the Service.

The Service is not hosted with an external cloud provider: the application and the database run on a server (NAS) owned by the controller and physically located in Poland. There is therefore no separate processor responsible for hosting.

TODO (owner): Verify and record which of the providers above you have a data processing agreement (DPA) with — Stripe, Resend and Cloudflare offer standard DPAs accepted from their dashboards, an accounting office needs a separate agreement. Also fill in the name of the accounting provider actually used and any other recipients (e.g. domain registrar, legal counsel).

6. Transfers outside the European Economic Area

The data stored in the Service (database and files) sits on the controller's server in Poland, i.e. within the EEA. We do not ourselves transfer data outside the EEA.

The providers listed in section 5 operate internationally and may, within their own infrastructure, process data outside the EEA as well, relying on the transfer mechanisms of Chapter V of the GDPR (standard contractual clauses or an adequacy decision).

TODO (owner): Confirm the current transfer status of each provider (Stripe, Resend, Cloudflare, accounting provider) against their current DPA documents and state the specific transfer mechanism here. Do not claim that "data never leaves the EEA" — for third parties that is not true.

7. Retention periods

Data categoryRetention
Cases, submissions, correspondence, attachmentsTODO (owner): set a concrete period (e.g. "X years after the case is closed") or the rule "until an erasure request is received". The system currently deletes nothing automatically — data stays until the operator removes it manually.
Window for reopening a closed case30 days from closure (after that a new submission is required; the case record itself does not disappear automatically)
Payment records and invoicesTODO (owner): typically 5 years under tax law — confirm with your accountant and state clearly when the period starts. Note: invoicing inside the Service is not yet live.
Audit logTODO (owner): set a retention period for the audit log. It is currently not purged automatically.
Client panel accountuntil deletion is requested (the Service does not delete accounts automatically)
Knowledge base entriesindefinitely — entries are anonymised (section 2.8) and do not allow the Client to be identified

8. Your rights

You have the right to:

  • access your data and receive a copy of it (Art. 15 GDPR),
  • have inaccurate or incomplete data corrected (Art. 16 GDPR),
  • erasure of your data (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • object to processing based on the controller's legitimate interest (Art. 21 GDPR),
  • withdraw consent at any time where processing is based on it — without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3) GDPR).

Send your request to [email protected], including details that let us identify the account or case (the e-mail address used for the submission, the workshop name or the case number).

Exercising the right to erasure means deleting the case and client records from the database together with the folder holding the uploaded files. Some data may still have to be retained where the law requires it (e.g. accounting records) or where it is necessary to establish, exercise or defend legal claims — in that case we tell you what is retained and on what basis. Knowledge base entries (section 2.8) are anonymised and are not deleted, because they do not allow anyone to be identified.

You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. If you are in another EEA country, you may lodge a complaint with the supervisory authority of your habitual residence, place of work or the place of the alleged infringement.

9. Automated decision-making

We do not take decisions based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect data subjects. The initial review (triage) and the whole diagnostic analysis are done by a human.

10. Cookies

The Service uses only cookies that are strictly necessary for it to work. We use no analytics, marketing or advertising cookies — there is no Google Analytics, no advertising pixel and no other user-tracking mechanism anywhere in the Service.

CookiePurpose
diag_sessionAdmin panel login session. Technical cookie: httpOnly (not readable by scripts), Secure over HTTPS, SameSite=Lax, valid for 7 days and refreshed on activity.
diag_client_sessionClient panel login session. Same technical parameters as above. Without this cookie logging into the Client panel is impossible.
Cloudflare TurnstileBot protection for the submission form. It is loaded only when configured and may set its own cookie for the verification challenge. Turnstile is not used to track users across websites.

Because all of the above cookies are strictly necessary (authentication and security), they do not require prior consent — informing you, which is what this section does, is sufficient. That is why the Service shows no cookie consent banner. You can block cookies in your browser settings, but logging into the Client panel will then stop working.

TODO (owner): Classifying the Cloudflare Turnstile cookie as "strictly necessary" (security / abuse prevention) is widely accepted, but it is a legal assessment. If you prefer a more conservative stance, ask your lawyer to confirm it — the alternative would be to load Turnstile only after consent. Note: Turnstile keys have not been created yet, so the mechanism is currently inactive.

Online payments happen after a redirect to the Stripe payment page. Cookies set on that page belong to Stripe and are governed by Stripe's own privacy and cookie policies — they are not set by our Service.

11. Security of the data

We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR). In particular:

  • encrypted connections (HTTPS/TLS) for all traffic to the Service,
  • passwords stored only as cryptographic hashes (bcrypt), never in plain text,
  • login sessions in signed httpOnly cookies that are not readable by browser scripts,
  • rate limiting of login attempts and of submissions per IP address,
  • attachment downloads only for logged-in users; files stored under random names with extension and size checks,
  • a server with no inbound open ports — access only through an encrypted tunnel; the database is unreachable from the internet,
  • signature verification of payment provider notifications,
  • an audit log making it possible to establish who changed what and when,
  • nightly backups of the database and files, kept for 14 days and replicated off the primary server,
  • separation of internal materials from what the Client sees — internal notes and internal documentation never reach the Client panel.

12. Third-party data supplied by the Client

When submitting a case, the Client (the workshop) may supply data that is not about itself — for example a vehicle VIN, a photo showing a licence plate, or a document containing the vehicle owner's details. We obtain such data indirectly, from the Client, and process it solely to deliver the diagnostic service to the Client, under the rules described in this Policy (data categories: section 2, retention: section 7, rights: section 8).

TODO (owner): Settle with a lawyer how the Article 14 information obligation towards the vehicle owner is met — through a clause in the Terms obliging the workshop to inform the vehicle owner, or otherwise. Also consider whether the relationship with the workshop here amounts to joint controllership or to separate controllers.

13. Changes to this Policy

The current version of this Policy is always available at diagnostix.com.pl/en/privacy, and the date of the last update is shown at the top of the document. The Polish version is the binding one; this English translation is provided for information only.

TODO (owner): Add how material changes to the Policy are communicated (e.g. e-mail to active Clients or a notice in the Client panel) and the date the first binding version enters into force.