GETLOCAL PRIVACY AND COOKIES POLICY
Last updated: April xx, 2026
Definitions:
- Service – the website available at www.getlocal.pl and the GetLocal mobile application for Android and iOS.
- Data Controller / Joint Controllers – entities indicated in point 2, jointly determining the purposes and methods of data processing.
- User – any natural person using the Service.
- Personal Data – any information enabling the identification of a natural person, directly or indirectly.
- Processing – operations performed on personal data, such as collection, storage, modification, sharing, or deletion.
- Cookies – small text files saved on the User's device while using the Service.
- GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).
- Venue Profile – a profile created in the Service by a User representing a business entity - a catering/gastronomy venue.
- Paid Services – paid functionalities of the Service, including the publication and promotion of venue profiles.
- Payment Operator – external entities providing electronic payment services (banks and the Tpay payment gateway).
- Billing Data – data necessary for payments: name/company name, address, TAX ID (NIP), e-mail, and transaction details.
1. General Information
This Privacy Policy defines the rules for processing personal data of users of the GetLocal service, available at getlocal.pl and as a mobile application authored by Mijsys.
Providing data is voluntary, but failure to do so may prevent the use of certain functions, such as account creation or paid services.
2. Data Controller
The Joint Controllers of personal data are:
- Mijsys - Patryk Szkudlarek, address: Ks. Augustyna Kordeckiego 17 lok. 2, 85-225 Bydgoszcz, Poland, NIP: 9452092695 - responsible for: IT, service maintenance, account data;
- Fundacja Motywajki based in Bydgoszcz, KRS 0001172399, NIP 9671487264 - responsible for: marketing, content, local community.
The Joint Controllers jointly determine the purposes of processing. Specific arrangements regarding responsibilities are available upon request. Controllers may use processors (e.g., IT providers) to ensure the proper functioning of the service.
3. Types of Data Collected
The Service may collect:
- technical data (e.g., IP address, browser type),
- contact data (name, email, phone number),
- activity data within the service,
- cookies.
For Venue Profiles, we additionally collect: company name, address, TAX ID. For Paid Services, we process email, billing data, and transaction statuses. Payments are handled by external operators under their own privacy policies.
4. Cookies
The Service uses the following types of cookies:
- Essential (technical) – to ensure the Service works correctly,
- Analytical – to analyze traffic,
- Marketing – to tailor advertising content.
Users can manage cookies via their browser settings. Analytical and marketing cookies require User consent.
5. Purpose of Processing
We process data to:
- provide services and create user accounts,
- communicate and improve service quality,
- conduct marketing and activity analysis,
- fulfill legal obligations and process payments/subscriptions.
We may use profiling to tailor content and recommendations. Profiling does not produce legal effects for the User. You have the right to object to profiling at any time.
6. Data Retention Period
We store data for:
- the duration of the contract and until the statute of limitations for claims expires,
- until consent is withdrawn,
- the period required by law (e.g., tax regulations).
7. Data Sharing
Data may be shared with:
- technical, analytical, and marketing service providers and payment operators,
- state authorities upon legal request,
- external contractors (e.g., developers) based on data processing agreements (Art. 28 GDPR).
Data transfer outside the EEA occurs only with appropriate safeguards (e.g., Standard Contractual Clauses).
8. Legal Basis
Processing is based on:
- Consent (Art. 6(1)(a) GDPR),
- Contract performance (Art. 6(1)(b) GDPR),
- Legal obligation (Art. 6(1)(c) GDPR),
- Legitimate interest (Art. 6(1)(f) GDPR) – e.g., communication, marketing, and statistics.
9. Your Rights
You have the right to: access, rectify, erase ("right to be forgotten"), restrict processing, data portability, and object. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO) in Poland.
10. Contact
For personal data protection matters, please contact: privacy@getlocal.pl
Found an error on this page?