Privacy Policy
Last updated: 2026-08-03
1. Introduction
WeldStack ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform for managing welding qualifications and documentation. The data controller is: Michał Rymut WeldStack, ul. Rzeszowska 163B, 39-200 Dębica, Poland, NIP: 8722294647, email: [email protected].
2. Our Roles: Data Controller and Data Processor
This policy applies to data for which WeldStack is the data controller: user account data, billing data, and data related to communication (including support request handling) and marketing.
Data about welders, personnel, and qualification certificates entered into the platform by our customers (employers or contracting parties) is processed by us solely as a data processor, on behalf of and on the documented instructions of the customer, who remains its controller — on the basis of a data processing agreement (Art. 28 GDPR). If you are a welder or an employee whose data has been entered into the platform, please direct requests concerning that data (access, rectification, erasure, etc.) to your employer — we will provide them with the necessary technical support.
3. Information We Collect
We collect information you provide directly to us, such as when you create an account, use our services, or contact us for support. This may include: name, email address, company information, and usage data. Data about welders and qualification certificates entered into the platform by our customers is processed by us as a data processor — see Section 2 ("Our Roles").
Providing data is voluntary, but the data marked as required at registration (email address, organization name) is necessary to conclude and perform the contract — without it we cannot create an account or provide the service.
If you sign in with Google, we receive from Google your email address, first and last name, and Google account identifier — to the extent you consent to on the Google sign-in screen.
4. How We Use Your Information
We use data for the following purposes and on the following legal bases (Art. 6(1) GDPR): providing and maintaining the service, account administration, processing transactions, responding to your requests, and service-related notifications (including about expiring certificates) — point (b) (performance of a contract); billing, taxes, and accounting — point (c) (legal obligation); improving the platform, ensuring security, and preventing abuse — point (f) (the controller’s legitimate interest); analytics on marketing pages and marketing communication — point (a) (your consent).
5. Data Storage and Security
Your account and service data are stored in secure data centers within the European Union. Selected document and recording processing features rely on external services: text recognition on certificates and transcript correction are performed by Google Cloud (Vertex AI / Gemini), whereby processing may take place in Google data centers outside the EEA, and conversion of voice recordings to text is performed by ElevenLabs, Inc., established in the USA. These transfers take place on the basis of a European Commission adequacy decision (EU-U.S. Data Privacy Framework) or Standard Contractual Clauses (SCCs). This content is not used by these providers to train their models. We apply appropriate technical and organizational measures (Art. 32 GDPR), including encryption of data in transit and at rest, regular backups, and access controls. Some supporting tools (analytics — only with your consent, error monitoring, transactional email delivery, payment processing) may involve transferring limited data outside the EEA — see Sections 6 and 8. Such transfers rely on European Commission adequacy decisions or Standard Contractual Clauses (SCCs).
6. Data Sharing
We do not sell your personal data. We may share information with: service providers who assist in operating our platform, competent public authorities where required by law, and other parties with your explicit consent. In particular, we use the services of: Google Cloud (hosting, EU), Google Cloud Vertex AI and ElevenLabs (document and speech processing), Resend, Inc. (USA — transactional email delivery; EU-U.S. Data Privacy Framework / SCCs), and Functional Software, Inc. dba Sentry (USA — error monitoring; EU-U.S. Data Privacy Framework) — as data processors, and Paddle (payments) as a separate data controller. Payment processing, taxes, and invoicing are handled by Paddle.com Market Limited ("Paddle") as our Merchant of Record and a separate data controller. Paddle processes your payment data (card details, billing address) in accordance with its own privacy policy. We do not store or have access to your full payment card details.
7. Your Rights (GDPR)
Under GDPR, you have the right to: access your personal data, rectify inaccurate data, request deletion of your data, restrict processing, data portability, and object to processing. Where processing is based on consent, you can withdraw it at any time — withdrawal does not affect the lawfulness of processing carried out before it. You also have the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warszawa, Poland, uodo.gov.pl. We do not make decisions based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you. To exercise these rights, contact us at [email protected].
8. Cookies and Similar Technologies
The storage of information on your terminal device, or access to information stored there (cookies and similar technologies), takes place on the basis of Article 399 of the Polish Electronic Communications Law of 12 July 2024 and, as regards personal data, on the bases described in this policy. We ask for your consent before using any optional technologies. You can change your choice at any time — withdrawing consent is as easy as giving it — via the "Cookie settings" link in the page footer or in Settings → Data & Privacy.
Strictly necessary (no consent required): the sign-in cookie "__Host-refresh_token" — HttpOnly, Secure; a session cookie removed when you close the browser, while the associated sign-in token remains valid for up to 7 days; with "remember me", the cookie and token remain valid for up to 90 days; the "cc_cookie" cookie storing your consent choice (182 days); and browser storage (localStorage) holding preferences you set yourself: language, theme, interface density and view settings.
Google sign-in: the Google Identity Services script is loaded only in connection with your action of signing in with Google (never automatically when a page loads); your browser may then store the "g_state" cookie (Google One Tap).
Analytics — only with your consent and only on our public marketing pages: Google Analytics 4, provided by Google Ireland Ltd. / Google LLC, using cookies "_ga" and "_ga_*" (up to 2 years) to measure how the site is used (pseudonymous identifier, device and approximate location information, page activity, the domain of the referring website — never the page address on it — and campaign tags ("utm_*") contained in the link you followed; data may be processed outside the EEA). Analytics never runs inside the application or on certificate verification pages (/verify).
Error monitoring: we use Sentry to receive error reports so we can keep the service reliable and secure (legitimate interest, GDPR Art. 6(1)(f)). It stores no persistent identifiers on your device, and before sending we apply filtering mechanisms that remove or mask the specified categories of data (headers, cookies, email addresses, URL parameters, among others). You may object at any time: [email protected].
Payments: the Paddle checkout component loads only when you start a payment and processes data under Paddle's own privacy policy (see Section 6).
We use no advertising or social-media trackers.
9. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Audit logs are retained for 12 months. We retain evidence of consents given and withdrawn for 72 months in order to demonstrate compliance (Art. 5(2) and Art. 7(1) GDPR). We retain billing data and payment-related documents for 5 years from the end of the tax year in which the tax obligation arose, in accordance with tax and accounting regulations. You may request deletion of your data at any time; we will fulfill the request to the extent that further retention is not required by law (e.g., tax law) or necessary for the establishment, exercise, or defense of legal claims (Art. 17(3) GDPR).
When a free trial ends without a subscription, or after a subscription is cancelled, we keep the organization’s data for a further 90 days (during which you can return to the service or export your data) and then delete it from production systems; backups containing this data are overwritten as part of the standard backup rotation cycle and are not used to restore deleted data. If previously deleted data is restored as part of disaster recovery, we will delete it again without undue delay once the recovery is complete.
Free-trial abuse prevention: after account data is deleted, we retain for up to 24 months a minimal record consisting solely of the account owner’s email address, the Google account identifier (if Google sign-in was used) and the trial start date. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR): preventing repeated use of the free trial. This record is not used for any other purpose, is not subject to profiling, and is deleted automatically when the period expires. You have the right to object to this processing: [email protected].
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
11. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at: [email protected]