Last updated: 17 July 2026
1. Who We Are
The personal data controller is:
KROPKA SOFT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, trading under the ERPixel brand
Registered address: ul. Chmielna 2/31, 00-020 Warszawa, Poland
NIP/VAT ID: PL5253062100
Website: https://erpixel.com
Email: sales@erpixel.com
Alexander Koltsov, Member of the Management Board, coordinates personal data protection and information security matters within the Company.
Questions or requests concerning personal data may be sent to sales@erpixel.com or to the registered address stated above.
2. Scope of This Privacy Policy
This Privacy Policy explains how we collect, use, store, disclose and protect personal data relating to:
- website visitors;
- prospective clients;
- clients and former clients;
- employees, representatives and contact persons of our clients and prospective clients;
- users submitting enquiries, support requests or other communications;
- business partners, suppliers and contractors.
The GDPR protects information relating to natural persons. Information relating exclusively to a legal entity may not constitute personal data, although the names, business email addresses, telephone numbers and positions of its employees or representatives are personal data.
Where we process personal data solely on behalf of one of our clients while providing implementation, hosting, integration, maintenance or support services, the client normally acts as the data controller and Kropka Soft acts as a data processor. Such processing is governed by the relevant service agreement and data processing agreement.
3. Personal Data We Collect
Depending on the nature of our relationship, we may process the following categories of personal data:
- name and surname;
- business email address and telephone number;
- company name, position, department and professional role;
- country, business address and preferred language;
- information submitted through website forms, advertising forms, email, telephone calls, meetings, messaging services or other communication channels;
- information concerning enquiries, business requirements, projects and requested services;
- quotations, proposals, discounts, negotiations and contractual information;
- support requests, tickets, service history and communication records;
- project tasks, work records, time records and information about services performed;
- invoices, payments, payment status and accounting information;
- feedback, complaints and customer satisfaction information;
- marketing preferences and records of consent or objection;
- IP address, browser information, device information, logs and website activity;
- information obtained from public registers, company websites, professional platforms, publicly available business sources, referrals or business partners;
- other information voluntarily provided to us.
We do not intentionally request special categories of personal data, such as information concerning health, religion, political opinions, biometric data or sexual orientation. Such information should not be submitted unless it is strictly necessary and an appropriate legal basis has been established.
4. Sources of Personal Data
We may obtain personal data:
- directly from the person concerned;
- from the company or organisation represented by that person;
- through website contact forms, event registrations, advertising forms and meeting-booking tools;
- during telephone calls, online meetings, correspondence or support communication;
- from referrals and business partners;
- from public registers, company websites, professional networking platforms and other publicly available business sources;
- through integrations between our business systems.
Where personal data is not obtained directly from the person concerned, we will provide the required privacy information within the period required by law and, where applicable, no later than the first communication with that person.
5. Purposes and Legal Bases of Processing
We process personal data only where there is a defined purpose and an appropriate legal basis.
Enquiries, client registration and initial contact
We process personal data to:
- register prospective clients and their representatives;
- respond to enquiries;
- establish contact;
- identify business requirements;
- arrange meetings and demonstrations;
- prepare quotations, estimates, proposals and discounts;
- negotiate potential contracts.
The legal basis is taking steps at the request of a person before entering into a contract and our legitimate interest in developing business relationships and responding to enquiries.
Provision of services and contract management
We process personal data to:
- enter into and perform contracts;
- deliver implementation, development, consulting, hosting, migration, training and support services;
- manage projects and project communications;
- record tasks, work performed and time spent;
- manage client accounts and service history;
- communicate with clients and their representatives.
The legal basis is the performance of a contract. Where the contract is concluded with a company or another legal entity, we process the personal data of its representatives on the basis of our legitimate interest in performing and managing the business relationship.
Customer support and service records
We process personal data to:
- register and resolve support requests;
- maintain records of client enquiries and reported issues;
- document technical and functional work;
- communicate about incidents, changes and service delivery;
- analyse service quality and prevent repeated issues.
The legal basis is the performance of a contract and our legitimate interest in providing effective, secure and properly documented support services.
Invoicing, payments and accounting
We process personal data to:
- issue and receive invoices;
- register and reconcile payments;
- maintain accounting and tax records;
- comply with statutory reporting requirements;
- prevent fraud and payment errors.
The legal basis is compliance with legal obligations and, where applicable, the performance of a contract.
Communication, feedback and relationship management
We process personal data to:
- maintain records of correspondence and meetings;
- collect feedback;
- measure customer satisfaction;
- improve our services;
- manage complaints;
- establish, exercise or defend legal claims.
The legal basis is our legitimate interest in managing customer relationships, improving our services and protecting our legal rights.
Marketing and commercial communications
We may process contact details and information about business interests to send information about our services, events, offers, discounts or relevant updates.
Where prior consent is required for communication by email, telephone, SMS or another electronic communication channel, we will send such communication only after obtaining the required consent.
Consent may be withdrawn at any time. A person may also object at any time to the use of their personal data for direct marketing. After an objection or withdrawal of consent, we will stop using the data for that purpose.
Responding to an enquiry or requesting a quotation does not automatically constitute consent to receive unrelated marketing communications.
Website operation, security and fraud prevention
We process technical data such as IP addresses, device information, browser information and server logs to:
- operate and secure the website;
- diagnose technical problems;
- prevent abuse, spam, attacks and unauthorised access;
- maintain system logs;
- investigate security incidents.
The legal basis is our legitimate interest in maintaining the availability and security of our website, systems and services.
Analytics and non-essential cookies
Where we use analytics, advertising, tracking or other non-essential cookies, the legal basis is the visitor’s consent.
Such cookies should not be activated before consent is given. Consent may be withdrawn or changed through the website’s cookie settings.
6. Odoo, n8n, Automation and Artificial Intelligence
We use Odoo-based systems, n8n automation workflows and artificial intelligence tools to process and manage information relating to enquiries, clients, projects, support requests, communications, invoices and payments.
These systems may be used to:
- register and update client records;
- transfer information between authorised systems;
- route enquiries and support requests;
- prepare internal summaries and reports;
- classify or structure communications;
- assist with the preparation of responses, quotations or project documentation;
- verify the completeness and consistency of data;
- automate administrative and technical tasks.
We apply the principle of data minimisation and provide automation and AI services only with the personal data reasonably necessary for the specified purpose.
AI systems are used as supporting tools for activities such as structuring information, preparing summaries, assisting with communications and automating administrative tasks. Where an AI-generated output may materially affect an individual, a client relationship, contractual obligations or service delivery, it is subject to appropriate human review.
We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.
Where third-party automation or AI providers process personal data, we apply appropriate contractual, organisational and technical safeguards in accordance with applicable data protection law. The role and responsibilities of each provider depend on the relevant service and processing arrangement.
7. Recipients and Service Providers
Personal data may be accessed by authorised employees and contractors only where access is necessary for their duties.
We may also disclose personal data to categories of service providers such as:
- Odoo and Odoo hosting or infrastructure providers;
- n8n and automation infrastructure providers;
- AI service providers;
- website and server hosting providers;
- email and communication service providers;
- backup, cybersecurity and IT maintenance providers;
- accounting, invoicing and payment service providers;
- banks and payment institutions;
- analytics and cookie management providers;
- meeting scheduling, video conferencing and messaging providers;
- legal advisers, accountants, auditors and insurers;
- public authorities where disclosure is required by law.
Service providers acting as data processors are required to process personal data only on our documented instructions and to apply appropriate security and confidentiality measures.
We do not sell personal data.
8. International Data Transfers
We seek to process personal data within the European Economic Area wherever reasonably possible.
Some service providers, including certain cloud, automation, communication or AI providers, may process data outside the European Economic Area or allow support personnel outside the EEA to access the data.
Where personal data is transferred outside the EEA, we use an appropriate transfer mechanism, such as:
- a European Commission adequacy decision;
- Standard Contractual Clauses approved by the European Commission;
- supplementary contractual, organisational or technical safeguards where required.
Information about the safeguards applicable to a particular transfer may be requested using the contact details stated in this Privacy Policy.
9. Data Retention
We retain personal data only for as long as it is necessary for the purpose for which it was collected.
As a general rule:
- enquiries and quotations that do not result in a contract may be retained for up to 24 months after the last meaningful contact;
- client, project, service, support and correspondence records are retained for the duration of the business relationship and thereafter until the relevant limitation periods for legal claims have expired;
- invoices, payment records and accounting documentation are retained for the period required by applicable tax and accounting laws;
- direct marketing data is retained until consent is withdrawn, an objection is submitted or the data is no longer required for the marketing purpose;
- technical and security logs are retained for the period necessary to maintain security and investigate incidents;
- data stored in backups is deleted or overwritten according to the applicable backup rotation schedule;
- records necessary to demonstrate consent, an objection or a request for deletion may be retained to demonstrate compliance with legal obligations.
Personal data may be retained for a longer period where this is required by law, necessary for an audit or investigation, or necessary to establish, exercise or defend legal claims.
10. Data Security
We apply organisational and technical measures appropriate to the nature of the data and the risks connected with processing.
These measures include, where applicable:
- role-based and need-to-know access;
- individual user accounts and access permissions;
- restrictions on data export and bulk access;
- authentication and password controls;
- logging and monitoring of system activity;
- regular software updates and security maintenance;
- backups and recovery procedures;
- encrypted communications and storage where appropriate;
- confidentiality obligations for employees and contractors;
- procedures for granting, reviewing and removing access;
- minimisation of the data provided to third-party systems;
- internal security and data protection instructions.
Employees and contractors are not given access to personal data unless such access is necessary for their duties.
No online service or information system can guarantee absolute security. We nevertheless take reasonable steps to prevent unauthorised access, loss, alteration, disclosure or destruction of personal data.
11. Cookies
The website may use:
- strictly necessary cookies required for security and essential website functions;
- preference cookies;
- analytics cookies;
- marketing or advertising cookies;
- cookies set by embedded or third-party services.
Strictly necessary cookies may be used without consent where permitted by law. Analytics, advertising and other non-essential cookies will be used only after the visitor has provided consent.
Visitors should be able to accept, reject or configure non-essential cookie categories and withdraw their consent at any time through the cookie settings.
The cookie settings should provide information about the cookie provider, purpose and duration.
12. Contact Forms
When a person submits a contact form, we process the information entered in the form to respond to the request, register the enquiry, prepare an offer or take steps towards entering into a contract.
Providing the data is voluntary, but failure to provide the information marked as required may prevent us from responding to the enquiry.
Contact form data will not be used for unrelated marketing communication unless the person has separately provided the required consent.
13. Comments and Uploaded Media
Where commenting functionality is available, we may collect the information submitted in the comment form, together with the visitor’s IP address and browser information, for moderation, security and spam prevention.
If the Gravatar service is enabled, a hashed version of the email address may be provided to Automattic to check whether the visitor uses Gravatar.
Users uploading images should remove embedded location information, such as EXIF GPS data, if they do not wish this information to be accessible to website visitors.
14. Embedded Content and External Services
The website may contain links to or content from external services, including video platforms, scheduling systems, social networks, WhatsApp, Calendly and other communication or content providers.
Opening an external link or interacting with embedded content may allow the external provider to collect information, use cookies or monitor interaction according to its own privacy policy.
Where non-essential embedded content involves tracking technologies, it should not be activated until the visitor has provided the required consent.
15. Rights of Individuals
Subject to the conditions and limitations established by applicable law, individuals have the right to:
- obtain confirmation as to whether their personal data is being processed;
- access their personal data and receive a copy;
- correct inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to processing for direct marketing;
- withdraw consent at any time;
- receive personal data in a structured, commonly used and machine-readable format where the right to data portability applies;
- lodge a complaint with a competent supervisory authority.
Requests may be submitted to sales@erpixel.com.
We may ask for information necessary to verify the identity of the person submitting the request. We will respond within the period required by applicable law.
Withdrawing consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
16. Deletion Requests
A person may request deletion of their personal data from our active systems.
We will comply with such a request where required by law. However, some information may need to be retained where it is necessary to:
- comply with tax, accounting or other legal obligations;
- establish, exercise or defend legal claims;
- protect systems and investigate security incidents;
- demonstrate that a privacy request, withdrawal of consent or marketing objection was respected;
- complete normal backup deletion and rotation processes.
Where full deletion is not legally possible, processing will be restricted to the permitted purpose.
17. Supervisory Authority
Individuals have the right to lodge a complaint with the Polish supervisory authority:
President of the Personal Data Protection Office
Urząd Ochrony Danych Osobowych
ul. Stanisława Moniuszki 1A
00-014 Warszawa
Poland
18. Children
Our website and services are intended for businesses and adult professionals. We do not knowingly collect personal data from children for commercial purposes.
19. Changes to This Privacy Policy
We may update this Privacy Policy when our services, systems, providers or legal obligations change.
The current version will be published on this page together with the date of the latest update.
20. Contact
Privacy and personal data requests may be sent to:
KROPKA SOFT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
ul. Chmielna 2/31
00-020 Warszawa
Poland
Email: sales@erpixel.com
Website: https://erpixel.com