Privacy
Policy
Information on the processing of personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
1. Data Controller
The controller of your personal data is Remarkable Solutions Sp. z o.o., with its registered office in Warsaw, address: al. Jana Pawła II 43A lok. 37B, 01-001 Warsaw, Poland, Tax Identification Number (NIP): 5272967931 (hereinafter: the Controller).
For matters related to data protection, you can contact us at: kontakt@remarkablesolutions.pl.
2. Data We Collect
Depending on how you use our website and the Remarkable Presence mobile application, we may collect the following data:
Contact Form
- first and last name
- email address
- company name
- phone number (optional)
- type of services of interest
- message content (optional)
- NDA signing preference
Newsletter
- email address
Automatically Collected Data
- IP address
- browser type and version
- operating system
- screen resolution
- date and time of visit
- pages visited
- referral source (referrer)
Cookies and localStorage
- cookie consent preferences (stored in localStorage under the cookieConsent key and in the remarkableConsent cookie)
Remarkable Presence Mobile Application
The data processed in the Remarkable Presence mobile application is described in detail in section 3.
3. Remarkable Presence Mobile Application
Remarkable Presence (package name com.remarkable.presence) is an Android application distributed through Google Play. It is used to manage a business's online presence: its Google business profile, social media accounts, publications and statistics. Remarkable Solutions Sp. z o.o. is the controller of the data processed in the application. For the client company's data (for example content published on the company's profiles) we may also act as a processor on the client's behalf, under the agreement with the client.
Account and sign-in
- email address, name and user identifier in the sign-in service (Logto, running on our servers)
- when signing in with a Google account (Google Sign-In): email address, name and Google account identifier
- roles, permissions and assignment to the client company
- session tokens, stored on the device in encrypted storage
Connections to third-party platforms
The application connects to third-party platforms only after the user authorises it (OAuth sign-in on the platform's own site). We store the access tokens for these platforms on our servers in encrypted form. A connection belongs to the client company, not to the account of the person who created it.
- Google Business Profile, scope business.manage: Google tokens, the email address of the Google account used to connect, business profile data (including name, address, categories and opening hours), customer reviews and review replies, and profile statistics. We read this data and, on the user's instruction, write changes to the profile, for example a review reply or a change of opening hours.
- Google Search Console: Google tokens, the email address of the Google account used to connect, and search performance data for the company's website (queries, impressions, clicks, positions).
- Meta (Facebook and Instagram): access tokens, which user created the connection, data about the company's Facebook pages and Instagram accounts, posts, comments, private messages sent to the company, and insights. On the user's instruction we publish posts and reply to comments or messages.
- LinkedIn: access tokens, the name, email address and profile picture of the LinkedIn member who created the connection, and data about the company pages they administer. On the user's instruction we publish content to the member's profile or to the company page.
Content and processing by artificial intelligence
The application can prepare suggested posts, replies to reviews and messages, and provides an assistant. For this purpose we send the data needed for the task to our language model provider (OpenAI): information about the business, the user's request, the text of the review or message being answered, and earlier messages in the conversation with the assistant. We store conversations with the assistant and the information it remembers, linked to your account. AI-generated content is never published automatically: the user decides what is published. Photos the user selects from the device gallery are uploaded to our servers so they can be attached to posts.
Push notifications
We send push notifications through Firebase Cloud Messaging (Google). We store the device token issued by Firebase, the platform type, your notification settings and the content of notifications addressed to you. You can turn notifications off in the application settings or in Android settings.
Subscriptions and payments
Paid plans in the application are purchased through Google Play Billing. Payment is handled by Google; we do not receive card or other payment details. To verify purchases and determine plan entitlements we use RevenueCat (RevenueCat, Inc.), to which we pass the user's identifier in our platform and the Google Play transaction data. We store purchase events (for example purchase, renewal, cancellation, expiry) and the subscription status of the client company. A subscription belongs to the client company.
Public business card
A company can publish a public business card at remarkablesolutions.pl/wizytowka/. The card contains only the data the company chooses to publish (for example name, contact details, address, links). It is available to anyone who knows its address until the company turns it off.
Technical data
- device network connectivity status (to support offline use)
- application version and feature configuration (feature flags retrieved from the Flagsmith server)
- images and data stored locally in the device cache to improve performance
- server logs and a security audit log for the account
Transfers outside the European Economic Area
Google, Meta, LinkedIn, OpenAI and RevenueCat may process data in the United States or other countries outside the EEA. Such transfers are based on a European Commission adequacy decision (EU-US Data Privacy Framework) or on standard contractual clauses approved by the European Commission.
Account deletion
You can delete your account in the application (Więcej → Usuń konto, that is More → Delete account) or by sending a request by email. Details, including the list of data that is deleted and data that stays with the company, are on the Account deletion page.
4. Purposes and Legal Bases for Processing
We process your personal data based on the following legal bases:
| Purpose of Processing | Legal Basis |
|---|---|
| Responding to inquiries submitted through the contact form | Art. 6(1)(f) GDPR (legitimate interest of the Controller) |
| Establishing and performing cooperation | Art. 6(1)(b) GDPR (necessity for the performance of a contract or pre-contractual steps) |
| Website traffic analysis and functionality improvement | Art. 6(1)(f) GDPR (legitimate interest of the Controller) |
| Marketing activities | Art. 6(1)(a) GDPR (consent) or Art. 6(1)(f) GDPR (legitimate interest) |
| Website security (spam protection, CAPTCHA) | Art. 6(1)(f) GDPR (legitimate interest of the Controller) |
| User authentication in the mobile application (Google Sign-In) | Art. 6(1)(b) GDPR (necessity for the performance of a contract) |
| Providing services through the mobile application | Art. 6(1)(b) GDPR (necessity for the performance of a contract) |
| Managing feature availability in the application (feature flags) | Art. 6(1)(f) GDPR (legitimate interest of the Controller) |
| Operating connections to Google Business Profile, Google Search Console, Meta and LinkedIn and carrying out operations requested by the user | Art. 6(1)(b) GDPR (necessity for the performance of a contract) |
| Preparing suggested content and operating the assistant using artificial intelligence | Art. 6(1)(b) GDPR (necessity for the performance of a contract) |
| Sending push notifications | Art. 6(1)(b) GDPR (necessity for the performance of a contract); notifications can be turned off in settings |
| Handling subscriptions purchased through Google Play | Art. 6(1)(b) GDPR (necessity for the performance of a contract) |
| Keeping a security audit log for accounts | Art. 6(1)(f) GDPR (legitimate interest of the Controller) |
5. Cookies
Our website uses cookies and the localStorage mechanism to ensure the proper functioning of the website, analyse traffic, and personalise content. On your first visit, we display a cookie consent banner where you can manage your preferences.
Cookie Categories
| Category | Description | Can Be Disabled |
|---|---|---|
| Necessary | Cookies essential for the proper functioning of the website. These include remembering consent preferences (remarkableConsent cookie, cookieConsent localStorage). | No |
| Analytics | Allow analysis of how the website is used, measuring traffic and identifying areas for improvement. | Yes |
| Marketing | Used to display personalised advertising content and measure the effectiveness of marketing campaigns. | Yes |
| Functional | Enable remembering selected settings, such as the website language, and improve the user experience. | Yes |
Cookie preferences are stored in JSON format in the browser's localStorage (cookieConsent key) and in the remarkableConsent cookie with a validity period of 365 days. You can change your preferences at any time using the cookie banner displayed on the website.
Regardless of the settings on our website, you can also manage cookies directly in your browser settings. Disabling cookies may affect the functionality of certain elements of the website.
6. Third-Party Services
To ensure the proper functioning of the website, we use the following third-party services:
Google Fonts
The website uses fonts loaded from Google servers (fonts.googleapis.com, fonts.gstatic.com). When loading fonts, the user's browser connects to Google servers, which results in the user's IP address being transmitted to Google LLC. Data processing is carried out in accordance with Google's privacy policy: https://policies.google.com/privacy.
Cloudflare Turnstile
In our contact forms, we use the Cloudflare Turnstile service, which provides protection against spam and automated form submissions (CAPTCHA). This service may process data about the user's device and browser. Details about Cloudflare's data processing can be found in their privacy policy: https://www.cloudflare.com/privacypolicy/.
Google Sign-In (Mobile Application)
The mobile application uses Google Sign-In for user authentication. During login, Google provides us with basic profile data (name, email address). Data processing is carried out in accordance with Google's privacy policy: https://policies.google.com/privacy.
Flagsmith (Mobile Application)
The mobile application uses Flagsmith (self-hosted on our servers) for feature flag management. This service does not process personal user data; it only provides application feature configuration.
Logto (Mobile Application)
Sign-in to the application is handled by Logto running on our servers. Account data in this service is not transferred to an external provider.
Google Business Profile, Google Search Console and Firebase Cloud Messaging (Mobile Application)
Services of Google LLC and Google Ireland Limited used for the business profile, search data and push notifications. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google's privacy policy: https://policies.google.com/privacy.
Google Play (Mobile Application)
The application is distributed through Google Play, and paid plans are billed through Google Play Billing. Google processes installation and payment data as a separate controller, in accordance with Google's privacy policy: https://policies.google.com/privacy.
RevenueCat (Mobile Application)
RevenueCat, Inc. verifies purchases made in Google Play and reports the subscription status to us. RevenueCat's privacy policy: https://www.revenuecat.com/privacy/.
Meta Platforms (Mobile Application)
Connections to Facebook pages and Instagram accounts use the APIs of Meta Platforms Ireland Limited. Meta's privacy policy: https://www.facebook.com/privacy/policy/.
LinkedIn (Mobile Application)
Connections to a member profile or company page use the APIs of LinkedIn Ireland Unlimited Company. LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy.
OpenAI (Mobile Application)
We use the OpenAI API to prepare suggested content and to operate the assistant. Under OpenAI's terms, data sent through the API is not used to train models by default. OpenAI's privacy policy: https://openai.com/policies/privacy-policy/.
jsDelivr CDN
We use the jsDelivr content delivery network to load the Devicon icon library. When loading resources from the CDN, the user's browser connects to jsDelivr servers, which may result in the transmission of the IP address. jsDelivr's privacy policy is available at: https://www.jsdelivr.com/terms/privacy-policy-jsdelivr-net.
7. Data Retention Period
Your personal data will be stored for the following periods:
- Contact form data - until the purpose for which it was collected has been fulfilled (e.g., responding to the inquiry, completion of cooperation) or until a successful objection to processing is raised.
- Cookies and localStorage data - up to 365 days from the time of consent or until manually deleted by the user.
- Server logs - for the period necessary to ensure security and diagnostics, no longer than 12 months.
- Mobile application account - until the account is deleted. When the account is deleted, account data is promptly deleted or anonymised and the account in the sign-in service is removed.
- Session tokens on the device - until logout or account deletion.
- Push notification device tokens and notification settings - until you sign out on the device, Firebase invalidates the token, or the account is deleted.
- Assistant conversations - until the account is deleted.
- Purchase events linked to the user - until the account is deleted. The record of the purchase stays with the client company without a link to the deleted account.
- Connections to Google, Meta and LinkedIn and their tokens - until the company disconnects the integration, access is revoked on the platform, or cooperation with the client ends.
- Client company data (businesses, posts, statistics, subscription status) - for the duration of cooperation with the client, and then until deleted at the client's request or as set out in the agreement.
- Security audit log - entries are kept after account deletion, but the personal data in them is anonymised.
- Mobile application cache - stored locally on the device until logout, account deletion, clearing the application data or uninstalling the application.
- Backups - deleted data may remain in backups until they are overwritten as part of the backup rotation cycle.
8. Your Rights
Under the GDPR, you have the following rights regarding the processing of your personal data:
- Right of access - you have the right to obtain confirmation from the Controller as to whether your personal data is being processed, and to access that data.
- Right to rectification - you have the right to request the immediate rectification of inaccurate data or the completion of incomplete data.
- Right to erasure - you have the right to request the deletion of your personal data (right to be forgotten) when there are no grounds for continued processing.
- Right to restriction of processing - you have the right to request the restriction of processing in cases specified in Art. 18 GDPR.
- Right to data portability - you have the right to receive your personal data in a structured, commonly used, machine-readable format.
- Right to object - you have the right to object at any time to the processing of data based on the Controller's legitimate interest.
- Right to withdraw consent - if processing is based on consent, you have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, contact us at: kontakt@remarkablesolutions.pl. You can also delete your Remarkable Presence account yourself, as described on the Account deletion page.
You also have the right to lodge a complaint with a supervisory authority. The competent authority in Poland is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), address: ul. Stawki 2, 00-193 Warsaw, website: https://uodo.gov.pl.
9. Data Security
The Controller implements appropriate technical and organisational measures to ensure the protection of processed personal data, including:
- data transmission encryption using the SSL/TLS protocol
- access controls for personal data, based on the principle of least privilege
- regular reviews and updates of IT infrastructure security
- personnel training in data protection
- backup procedures
- encrypted storage of access tokens in the mobile application (Flutter Secure Storage)
- encrypted storage on our servers of access tokens for Google, Meta and LinkedIn
10. Changes to This Privacy Policy
The Controller reserves the right to make changes to this Privacy Policy. Changes may result from changes in legislation, changes in website functionality, or changes in the scope of data processed.
The current version of the Privacy Policy is always available on this page. In the event of significant changes, we will inform you through the website.
11. Contact for Data Protection Inquiries
If you have any questions regarding this Privacy Policy or the processing of your personal data, please contact us:
- Email: kontakt@remarkablesolutions.pl
- +48 780 257 520
- Postal address: Remarkable Solutions Sp. z o.o., al. Jana Pawła II 43A lok. 37B, 01-001 Warsaw, Poland
- Phone: +48 780 257 520