Documents

Privacy Policy

What we collect, why, how long we keep it and who we entrust it to. No generalities — every point matches what the system actually does.

Last updated: August 17, 2026

01

Data controller

The controller of your personal data is Wojciech Olszewski, a sole trader registered in the Polish Central Registration and Information on Business (CEIDG), ul. Macieja Palacza 41/42, 60-242 Poznań, Polska, VAT ID 7792464798, REGON 367373107.

For anything concerning your data, write to app@rounds.page, or by post to our address for service: ul. Saperska 32B/40, 61-493 Poznań, Polska.

We have not appointed a data protection officer; the scale of our processing does not require one.

02

What we collect

From someone creating an account:

  • email address — used to sign in and to send notifications,
  • password — stored only as a bcrypt hash, which cannot be reversed,
  • a name, if you choose to give one,
  • interface language, so emails arrive in the same language as the service,
  • your Stripe customer and subscription identifiers, if you are on a paid plan.

From someone commenting on a document without an account:

  • the name they enter on arrival, which their comments are signed with,
  • an email address, only if they choose to give one, to receive notifications,
  • the content of their comments and replies, and which comments they have read.

We do not collect surnames, phone numbers, postal addresses or card details. We never see card details — Stripe handles them.

03

The files you upload

An uploaded PDF may contain personal data — someone's name on a business card design, photographs, addresses. We do not process such data for our own purposes: as regards the content of uploaded files you are the controller and we are a processor acting on your instructions.

If you need a data processing agreement, write to us and we will provide one.

We do not open uploaded files in order to read them. The system splits them into pages automatically and no one on our side has any reason to look inside; technical access to the server is restricted and used only to keep the service running.

One technical note, for clarity: identical pages are stored once, recognised by a hash of their rendering. This does not change access rules — a page is only ever shown to someone with access to a document that references it.

04

IP addresses

We do not store IP addresses in our database and do not link them to accounts.

We use them transiently, in server memory, to rate-limit account creation and password resets. The counter expires after an hour and leaves no trace.

Separately, IP addresses appear in web server logs, as they do on every website. Logs are rotated daily and kept for fourteen days, then deleted. The basis is our legitimate interest in detecting abuse and diagnosing faults.

05

Cookies and funnel measurement

Rounds uses two cookies. Both are strictly necessary for the service to work, both are encrypted and inaccessible to scripts in the browser, and neither belongs to a third party.

  • pdfreview_owner — keeps you signed in to the panel, valid for thirty days,
  • pdfreview_guest — remembers the name you comment under and which documents your link gives you access to, valid for one year.

We use no advertising cookies, embed no social network pixels and profile no one. That is why you will not see a cookie consent banner here — there is nothing to consent to.

We do measure where people drop out of the flow — with no analytics cookie, no IP address and no third party. We store only the name of the step (for example “round published”), a timestamp, and — from the moment you register — an account identifier, so we can count how many PEOPLE got further rather than how many times someone clicked. Steps before registration are countable but cannot be linked to an individual. The basis is our legitimate interest in improving the service (Article 6(1)(f) GDPR).

06

Purposes and legal bases

  • Running your account and providing the service — Article 6(1)(b) GDPR, performance of a contract.
  • Sending notifications about comments and about upcoming deletion — Article 6(1)(b) GDPR; you can turn notifications off in account settings.
  • Settling payments and keeping accounting records — Article 6(1)(c) GDPR, legal obligation.
  • Security, abuse prevention and pursuing claims — Article 6(1)(f) GDPR, our legitimate interest.

We make no automated decisions about you and do not profile you.

07

How long we keep it

  • Documents and files — until you delete them, or until the inactivity period for your plan elapses; the period is stated in the pricing section, and you receive an email warning fourteen days before deletion.
  • Account data — until you delete the account; deletion is immediate and permanent.
  • Billing records — for the period required by accounting law.
  • Web server logs — fourteen days.
  • Funnel events (step name and timestamp) — twelve months.
  • Data needed to defend against claims — until the limitation period expires.

08

Who we entrust data to

We do not sell data and do not share it for marketing. We rely on three providers, without which the service could not run:

  • DigitalOcean — server and database. Everything runs in a data centre in Frankfurt, within the European Union.
  • Resend — sending email.
  • Stripe — payment processing. Stripe acts as the seller of record and processes payment data as an independent controller under its own privacy policy.

We may also disclose data to public authorities where required by law.

Some providers are US entities. Transfers outside the European Economic Area take place under standard contractual clauses approved by the European Commission.

09

Your rights

You have the right to:

  • access your data and receive a copy of it,
  • have inaccurate data corrected,
  • have your data erased,
  • restrict processing,
  • port your data to another controller,
  • object to processing based on legitimate interest.

To exercise any of these, write to app@rounds.page. We respond within one month at the latest.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, or with the supervisory authority in your own country.

10

Security

Connections to the service are encrypted. Passwords are stored only as bcrypt hashes. Cookie contents are encrypted and signed, so they cannot be tampered with in the browser. Access to a document requires a link, which you can revoke at any time.

No system is impregnable. If a personal data breach occurs that is likely to risk your rights, we will notify you and the supervisory authority within the time limits the GDPR requires.

11

Changes to this policy

We may update this policy as the service develops. The date of the last change appears at the top, and we will email you about significant changes.