1. General Information
This Privacy Policy explains how personal data of users of rubicon-group.pl and the related software service is collected, used, processed, and protected.
The data controller is:
Rubicon Group Vladyslav Riadov
NIP: 6972395549
REGON: 526790012
Address: ul. Jana Ostroroga 1a/28, 64-100 Leszno, Poland
For privacy-related inquiries please contact:
Personal data is processed in accordance with:
- Regulation (EU) 2016/679 (GDPR)
- applicable laws of the Republic of Poland.
2. Data We Collect
When using the website and the Service, the following categories of data may be processed.
Account Data
- Telegram user ID
- Telegram username
- user-defined name or client name.
Service Operation Data
- Telegram account phone numbers
- account names within the Service
- account group names
- account group composition
- account session authorization files
- activity logs
- service statistics (subscriptions, unsubscriptions, messages, search queries)
- technical information about proxies used
- device parameters used by accounts
- message texts or message templates uploaded by users for automated sending through the Service
- other technical information necessary for the stable operation, analysis, and improvement of the Service.
Website Data
The website operates on WordPress using the WooCommerce plugin.
These systems may automatically collect:
- IP address
- email address
- username
- authentication data
- technical cookies.
3. Payment Information
Payments are processed through the third-party payment service:
Stripe
Stripe may collect:
- name and surname
- billing address
- payment information
- transaction data.
The Service operator does not have access to full credit card information.
Transaction information may be transferred to the accounting service:
inFakt
This system may be accessed by the accountant responsible for the business.
4. Purpose of Data Processing
Personal data may be processed for the following purposes:
- providing access to the Service
- maintaining the technical operation of the Service
- processing payments
- accounting and tax compliance
- customer support
- ensuring system security
- fraud prevention
- analyzing and improving the Service.
5. Legal Basis for Processing
Personal data is processed based on:
- performance of a contract (GDPR Art. 6(1)(b))
- compliance with legal obligations (Art. 6(1)(c))
- legitimate interests of the controller (Art. 6(1)(f)).
6. Processing by Third-Party Services
Certain personal data may be processed by third-party services when necessary for the operation of the Service, including:
- payment processors used to process payments
- accounting service providers
- hosting providers where the Service infrastructure is located.
The Service operator does not sell personal data to third parties for marketing purposes.
Service servers are physically located within the European Union (Germany).
7. User Content and Responsibility
Users may upload information required for the operation of the Service, including message templates or text messages intended for automated sending.
The Service operator:
- does not review such content
- does not moderate such content
- is not responsible for its legality or accuracy.
Users are solely responsible for the information they upload, store, or distribute through the Service.
8. Security Logs
To ensure stable operation and prevent abuse, the Service may maintain technical logs that may include:
- technical usage parameters
- system events
- information related to the use of Service features.
Such data is used solely for security and system stability purposes.
9. Data Retention
Personal data is retained for as long as necessary to:
- provide the Service
- comply with legal and tax obligations
- maintain accounting records
- protect the legitimate interests of the controller.
10. User Rights
Users have the right to:
- access their personal data
- request correction of data
- request deletion of data
- restrict processing
- receive a copy of their data
- file a complaint with a data protection authority.
In Poland, the supervisory authority is Urząd Ochrony Danych Osobowych (UODO).
11. Data Security
The controller implements appropriate technical and organizational measures to protect personal data against:
- unauthorized access
- loss
- destruction
- unauthorized modification.
12. Age Requirement
The Service is intended for users 18 years of age or older.
Individuals under 18 should not use the Service without the consent of a legal guardian.
13. Policy Changes
The operator reserves the right to update this Privacy Policy.
The current version will always be available on the website.
14. Language Priority
This Privacy Policy is available in Ukrainian and English.
In case of discrepancies between language versions, the Ukrainian version shall prevail.