LAPIDAR

Privacy Policy

Legal

Privacy Policy

Effective 11 October 2026

1. Who is responsible

Alan Balcerowiak, operating LAPIDAR as an unregistered business activity (działalność nierejestrowana), ul. Bajeczna 49/2, 32-020 Wieliczka, Poland ("we"). Contact: contact@getlapidar.com.

This policy covers personal data we handle as controller: website visitors, people on our waitlist, and the people who use LAPIDAR accounts. Policyholder data inside files that agencies upload is handled on the agency's behalf, as processor, under our Data Processing Addendum.

2. What we collect and why

We do not sell personal data, do not use advertising trackers, and do not run AI or language models on your data or uploaded files. Uploaded files are parsed by deterministic software on our own server. We do not make decisions about you based solely on automated processing.

You do not have to give us any personal data. Without an email address we cannot add you to the waitlist, and without account details we cannot provide the service.

3. Payments: Link and Stripe as merchant of record

Subscriptions are sold through Stripe's Managed Payments service: Link, a Stripe company, is the reseller and merchant of record. Link and Stripe collect your payment details, billing address and tax details at checkout, issue receipts and invoices, calculate and remit sales tax and VAT, and handle fraud screening, refunds and disputes. For that data they act as independent controllers under their own privacy policies, shown at checkout. Stripe also runs the customer portal ("Manage billing") on our behalf.

3a. Signing in with Google

Signing in with Google. Sign in with Google is optional; you can always use your email and a password. If you use it, you sign in on Google’s page and Google tells us your verified email address and account identifier. Google acts as an independent controller for your Google account under its own privacy policy (policies.google.com/privacy). We use only the openid and email permissions and get no access to your Gmail, Drive or other Google data.

4. Cookies

Cloudflare Web Analytics does not use cookies. When you log in to the app we set strictly necessary cookies for the session (kept up to 14 days, or until you sign out) and for CSRF protection. Cloudflare, which protects the site, may set strictly necessary security cookies (such as __cf_bm) to tell people from automated traffic. We do not use marketing cookies. If you use Sign in with Google, we set one strictly necessary cookie for up to 10 minutes to link Google’s answer to your sign-in attempt. On the sign-up page we may use Cloudflare Turnstile to tell people from automated sign-ups. It runs a short check in your browser and does not use cookies for advertising; Cloudflare processes it as our service provider.

5. Service providers

6. International transfers

Our server is in the United Kingdom, which is covered by an adequacy decision of the European Commission. Cloudflare, Google and Stripe are US companies and may process data in the US. Such transfers rely on the EU–US Data Privacy Framework where the provider is certified under it, or on Standard Contractual Clauses. If you are a customer in the US, your data travels from the US to the United Kingdom for storage and processing.

7. How long we keep data

  • Waitlist: until you unsubscribe or ask us to delete it, and at most 24 months after our last contact with you.
  • Account data: while the account is active. When a subscription ends, account data is kept for 30 days so you can sign in and export it, then deleted, unless you delete the account sooner or ask us for an export within that period. Deleting your account removes its data from the service straight away; copies in backups are overwritten within 15 days, and billing records are kept as described below. An account that never starts a subscription is deleted 30 days after it was created or last signed in, whichever is later. Unconfirmed sign-ups are deleted on the same schedule.
  • Our sales and billing records (amounts and dates of payments, and the email address, agency name and Stripe identifiers they relate to): as long as Polish tax law requires, generally five years from the end of the relevant tax year. They are kept when an account is deleted. Receipts and invoices for your purchase are kept by Link under its own policy.
  • Server logs: web server access logs are deleted after 14 days; application logs are overwritten automatically once they reach a size limit.
  • Email to contact@getlapidar.com: as long as needed to deal with your message. Please do not email files with policyholder data; if you do, we ask you to upload them in the app and delete the email and its attachments within 7 days.
  • Backups: we make a daily backup on the same server, readable only by its administrator, and keep each backup for up to 15 days. Backups are not yet stored off-site.

8. Your rights

Under the GDPR you can ask for access, correction, deletion, restriction, portability, and object to processing based on legitimate interest; where we rely on consent you can withdraw it at any time. Email contact@getlapidar.com. We answer within one month. You can also complain to the Polish supervisory authority, Prezes Urzędu Ochrony Danych Osobowych (uodo.gov.pl), or your local authority.

If you are in the US, you may have rights under state privacy laws. We honor access and deletion requests from anyone, regardless of location.

9. Security

Traffic is encrypted with HTTPS/TLS, passwords are stored as argon2 hashes, each account's files are stored separately, and only Alan Balcerowiak has administrative access to the server. No system is perfectly secure; we will tell you without undue delay if a breach affects your data.

10. Children

LAPIDAR is a business service and is not directed to children.

11. Changes

We will post changes here and update the date above; for material changes we will email account holders.

Questions: contact@getlapidar.com