Roman & Masza | Legal Documents
Privacy Policy
This Privacy Policy explains how RM Sp. z o.o. processes personal data of users of romanmasza.com and of the RomanMasza Social KPI application connected with Facebook, Instagram and other authorised Meta services.
We process personal data lawfully, fairly, transparently and only to the extent necessary for the stated purposes. This Policy applies to data obtained through the website, contact forms, email, technical logs, authorised APIs and interactions with the Company’s public business accounts.
1. Data Controller
RM Sp. z o.o.ul. Rakowicka 10B/4, 31-511 Kraków, Poland
NIP (Tax ID): 6751824957
Email: masza.pro123@gmail.com
Telephone: +48 883 042 151
Coordinator for data subject and deletion requests: Roman Protsenko
RM Sp. z o.o. is the Data Controller. Roman Protsenko is the internal coordinator for data subject requests, including deletion requests. This designation does not amount to his appointment as a Data Protection Officer under the GDPR.
2. Scope and sources of data
- directly from the user through forms, email, telephone, messaging services or other communication channels;
- automatically from the user’s device and browser when visiting the website;
- from Facebook, Instagram and other Meta services after access has been granted or in connection with interactions with public business accounts of RM Sp. z o.o.;
- from providers of technical, analytics and communication services within their functions;
- from publicly accessible sources where lawful and necessary for a specific purpose.
Where personal data is not obtained directly from the person, this Policy also constitutes information under Article 14 GDPR. A link is made available on the website, in related business profiles and in the application interface. Where reasonable and technically feasible, it may be repeated in a short notice at the first direct contact. Any reliance on an exception from individual notice is based on a documented assessment and accompanied by transparency and data-minimisation safeguards.
3. Categories of personal data
3.1. Enquiries and communications
- name and surname, telephone number and email address;
- property, connection or other address provided by the user;
- the content of the message, enquiry and subsequent correspondence;
- preferred method and time of contact;
- other information voluntarily provided in the enquiry.
3.2. Website technical and analytics data
- IP address, date and time, language, browser and device type;
- page views, link clicks and interactions with buttons and forms;
- cookies, consent identifiers and security logs;
- diagnostic information about errors and website operation.
3.3. Application and social-platform data
- platform, account name, username and user, page, profile or business-account identifier;
- post, media, comment, reply and thread identifiers;
- comment and reply text, author name or username, date and time;
- links to posts and available technical metadata;
- aggregated interaction, follower and activity statistics where available under granted permissions;
- access tokens and technical data needed for authentication and connection maintenance;
- synchronisation logs, processing status, errors and service identifiers;
- work cases, reply status, response time, preliminary classification and quality review.
We do not request users’ passwords for Facebook, Instagram or other third-party platforms.
4. Purposes, legal bases and retention
| Purpose | Data categories | Legal basis | Main retention period |
|---|---|---|---|
| Responding to enquiries and pre-contract communication | Contact details, enquiry content and correspondence | Article 6(1)(b) GDPR; in some cases Article 6(1)(f) | Up to 14 months after closure or the last meaningful contact |
| Contract performance and customer service | Contact, contractual and service data | Articles 6(1)(b) and 6(1)(c) GDPR | Contract term plus statutory or claims-related periods |
| Facebook/Instagram integration | Account identifiers, tokens, posts, comments and sync status | Articles 6(1)(b), 6(1)(f); consent where required | Records up to 14 months; tokens until revoked, expired or no longer needed |
| Reply management, KPI and quality control | Comments, replies, author, time, status and work case | Article 6(1)(f) after a documented balancing test | Comments up to 14 months per record; case up to 14 months after closure |
| Preliminary AI classification and prioritisation | Text, context, classification and technical indicators | Article 6(1)(f), with human oversight and right to object | Up to 14 months or earlier following deletion/anonymisation of source data |
| Website analytics | Cookies, online identifiers and events | Article 6(1)(a) and applicable cookie rules | Up to 14 months; earlier after withdrawal or cookie deletion |
| Security and diagnostics | IP address, logs, errors and security events | Articles 6(1)(f) and, where relevant, 6(1)(c) | Up to 14 months; longer only for incident investigation or claims |
| Legal compliance and claims | Necessary evidence, accounting and legal data | Articles 6(1)(c) and 6(1)(f) | Statutory period or period necessary for claims |
5. Information for Facebook and Instagram comment authors
When a user posts a comment or reply under content published by a public business account of RM Sp. z o.o., the relevant record may be received through an authorised Meta interface and imported into RomanMasza Social KPI.
Processing may include Comment ID, Media ID, username, text, publication time, thread relationship, our reply, reply status, response time, preliminary AI classification and quality review. The purposes are timely reply management, statistics, quality control and improvement of work processes. The data is not used for targeted advertising without a separate legal basis and any consent required.
6. Special categories of personal data
RM Sp. z o.o. does not seek to collect health information, political opinions, religious beliefs, biometric data, data concerning sex life or other special-category data through comments or forms. If a user voluntarily or accidentally includes such information, it is not used for additional purposes and is minimised, access-restricted, deleted or irreversibly anonymised unless an appropriate legal basis applies.
7. Automated processing and AI
Some data may be automatically sorted, aggregated or preliminarily classified for statistics, work prioritisation and quality control. The outcome may be reviewed by a person. The processing is not used for solely automated decisions producing legal effects or similarly significant effects for a user.
8. Recipients
- hosting, cloud-infrastructure, backup and technical-support providers;
- developers, IT contractors and administrators acting on behalf of RM Sp. z o.o.;
- email, communications and collaboration providers;
- Google in connection with Google Analytics 4, Google Tag Manager and other services actually used;
- Meta Platforms and related services to the extent necessary for the integration;
- AI providers only where actually used and included in the provider and processing-agreement register;
- accounting, legal and other professional advisers;
- public authorities and courts where disclosure is required by law.
Providers processing data on behalf of RM Sp. z o.o. must be bound by contractual and statutory confidentiality, security and data-processing requirements.
9. International transfers
Some providers may process data outside the European Economic Area. Where this occurs, lawful safeguards are used, such as an adequacy decision, Standard Contractual Clauses and, where required, supplementary measures and a transfer assessment.
10. Detailed retention and deletion rules
- enquiries and correspondence: up to 14 months after closure or the last meaningful contact;
- comments, replies and related identifiers: up to 14 months from receipt of each record;
- work cases and quality reviews: up to 14 months after case closure;
- identifiable quality-base examples: up to 14 months, followed by removal of identifiers or irreversible anonymisation;
- analytics identifiers and GA4 user/event data: up to 14 months;
- technical logs: up to 14 months from creation;
- access tokens and connection data: until revocation, expiry, termination or earlier loss of necessity;
- backups: deletion or overwrite under the backup cycle, normally no later than 90 days after deletion from the active system.
Data may be retained longer only where required by law or necessary to investigate a security incident or establish, exercise or defend legal claims. Processing is then restricted to that purpose.
11. Your rights
- to receive information and access personal data;
- to rectify inaccurate or incomplete data;
- to request erasure;
- to request restriction of processing;
- to object to processing based on legitimate interests;
- to receive data in a portable format where the right applies;
- to withdraw consent at any time without affecting prior lawful processing;
- to lodge a complaint with the competent supervisory authority.
12. How to submit a request
Requests may be sent to masza.pro123@gmail.com with the subject “Personal data request”. To help locate data, provide your name, contact email, platform used, username or connected-account identifier if known. Do not send passwords, access tokens, 2FA codes or other secrets.
We may request reasonable verification of identity or authority. We respond without undue delay and normally within one month. Where permitted by the GDPR, the period may be extended by up to a further two months, with notice and reasons provided within the first month.
13. Cookies and analytics
Optional analytics and marketing technologies are activated only after prior consent. The declared configuration uses Basic Consent Mode: optional Google tags are blocked before the user’s choice. GA4 user and event data retention is set to 14 months and reset upon new activity is disabled. Further details are provided in the Cookie Policy.
14. Security
We use proportionate technical and organisational measures, including access control, permission management, multi-factor authentication, logging, system updates, backups, contractual confidentiality obligations and incident-response procedures. No transmission or storage method can guarantee absolute security, so measures are reviewed in light of risk.
15. Third-party websites and platforms
The website and application may contain links to third-party services. Those services independently determine the rules applicable to their own processing. Users should review the relevant policies before using them.
16. Changes to this Policy
This Policy may be updated when the Service, providers, processing methods or legislation change. The current version is published with the update date. Material changes may also be communicated by other available means.
17. Complaint to the supervisory authority
A user may lodge a complaint with the President of the Personal Data Protection Office in Poland (Prezes Urzędu Ochrony Danych Osobowych, UODO) if they believe their data is processed unlawfully.
UODO contact address: ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland.
18. Contact
RM Sp. z o.o.ul. Rakowicka 10B/4, 31-511 Kraków, Poland
NIP (Tax ID): 6751824957
Email: masza.pro123@gmail.com
Telephone: +48 883 042 151
Coordinator for data subject and deletion requests: Roman Protsenko