Privacy Policy

Double Digital sp. z o.o.

1. Data Controller

The data controller is Double Digital limited liability company based in Warsaw, ul. Grzybowska 87, 00-844 Warsaw ('Controller', 'Double Digital').

Contact for personal data protection matters:

  • e-mail: kontakt@double-digital.pl
  • mailing address: Double Digital sp. z o.o., ul. Grzybowska 87, 00-844 Warsaw

2. Scope of Application

This Privacy Policy applies to:

  • digital products and platforms offered by Double Digital in a subscription model
  • Double Digital websites and applications
  • user account registration
  • one-time and recurring payments
  • integration with external systems (e.g. Google Ads)
  • communication conducted by Double Digital

This Privacy Policy applies regardless of whether the User uses the Services as an individual or on behalf of a business entity.

3. Legal Basis for Data Processing

Personal data is processed in accordance with:

  • Regulation (EU) 2016/679 of the European Parliament and Council (GDPR)
  • applicable provisions of Polish and EU law

Legal bases for data processing:

  • Art. 6 para. 1 lit. b GDPR – performance of contract or taking steps prior to its conclusion
  • Art. 6 para. 1 lit. c GDPR – legal obligations (accounting
  • taxes)
  • Art. 6 para. 1 lit. f GDPR – legitimate interest of the Controller
  • Art. 6 para. 1 lit. a GDPR – User consent (if required)

4. What Data We Collect

4.1. User Account Data

  • first and last name or company name
  • email address
  • login data (passwords in encrypted form)
  • phone number (if required for account security)

4.2. Billing Data

  • invoice data
  • information about payments and subscriptions
  • billing history

Double Digital does not store payment card data – it is processed solely by certified payment operators.

4.3. Product and Technical Data

  • IP address
  • system logs
  • data on system activity
  • configurations
  • settings
  • events
  • marketing and advertising data processed as part of integrations (e.g. campaigns
  • keywords
  • results)

5. Data from External Integrations

If Double Digital services are connected to external systems (e.g. Google Ads, Meta, analytics tools): data may be temporarily retrieved, processed and synchronized, data is used solely for the purpose of providing Services, after completion of the technical process, source data may be deleted or anonymized

    6. Purposes of Data Processing

    • provision and billing of Services
    • management and security of User accounts
    • processing of payments and subscriptions
    • handling of inquiries and communication
    • improvement of product quality and functionality
    • ensuring system security
    • pursuing or defending claims

    7. Aggregated Data, Anonymization and Technology Development

    Double Digital may process data in permanently anonymized and aggregated form for the purpose of: developing algorithms and AI models, training optimization systems, creating benchmarks, market analysis and statistics, development of new functionalities and products

    • developing algorithms and AI models
    • training optimization systems
    • creating benchmarks
    • market analysis and statistics
    • development of new functionalities and products

    Such data:

    • Such data: do not allow identification of the User or their company
    • do not constitute personal data under GDPR
    • may be stored indefinitely
    • are the property of Double Digital

    8. Marketing and Communication

    • provision of Services
    • transmission of technical and organizational information
    • sending commercial information – only with consent

    The User may withdraw consent for marketing communication at any time.

    9. Data Recipients

    • IT and hosting service providers
    • payment operators
    • accounting firms
    • analytics and mailing tool providers
    • public authorities – if required by law

    Data is not sold to third parties.

    10. Data Transfer Outside the EU

    If data is transferred outside the European Economic Area, the Controller ensures appropriate legal safeguards required by GDPR (e.g. standard contractual clauses).

    11. Data Retention Period

    • account and product data – for the duration of the agreement
    • after the end of subscription – up to 12 months
    • accounting data – in accordance with the law
    • anonymized and aggregated data – indefinitely

    12. User Rights

    • access to data
    • rectification
    • deletion
    • restriction of processing
    • data portability
    • objection
    • withdrawal of consent at any time
    • filing a complaint with the President of the Personal Data Protection Office

    13. Data Security

    Double Digital applies technical and organizational measures ensuring the protection of personal data

    • encryption of transmission (SSL)
    • server security
    • limited access to data

    14. Changes to Privacy Policy

    The Privacy Policy may be updated. The current version is always available on Double Digital services.

    15. Contact

    For matters related to personal data protection, please contact: kontakt@double-digital.pl, Double Digital sp. z o.o., ul. Grzybowska 87, 00-844 Warsaw