Legal documents

Privacy Policy

How APPVENTIS PROSTA SPÓŁKA AKCYJNA processes personal data within the STORYLANDIA service and application.

1.

Definitions

1.1. Controller – APPVENTIS PROSTA SPÓŁKA AKCYJNA (a simplified joint-stock company) with its registered office in Radom, Poland (Kazimierza Pułaskiego 6/10, 26-600 Radom), entered into the Register of Entrepreneurs maintained by the District Court of Lublin Wschód in Lublin with its seat in Świdnik, 6th Commercial Division of the National Court Register, under KRS number: 0001145581, Tax ID (NIP): 7963033729, with a share capital of PLN 100.00.

1.2. STORYLANDIA Application or Application – the mobile application owned by the Controller, enabling Users to generate personalized stories for children.

1.3. Personal Data – any information relating to an identified or identifiable natural person, in particular by reference to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity, including image, voice recordings, contact details, location data, information contained in correspondence, and information collected through recording devices or similar technologies.

1.4. Account – an individual section of the Application assigned to a specific User, identified by a single email address or mobile phone number, enabling the User to perform certain actions within the Application.

1.5. Data Subject – a natural person whose Personal Data are processed by the Controller, including but not limited to Users and other individuals who contact the Controller (e.g. by email).

1.6. Policy – this Privacy Policy.

1.7. Terms of Service – the Terms and Conditions of the STORYLANDIA Application.

1.8. GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.

1.9. STORYLANDIA Website or Website – the online service named STORYLANDIA, operated by the Controller in Polish, available at https://storylandia.pl, which also includes the STORYLANDIA Application.

1.10. Services – services provided electronically to Users by the Controller within the Application.

1.11. User – a natural person aged 18 or older with full legal capacity, or a person over 13 years of age using the Service under the supervision and consent of a legal guardian, who, after reading and accepting the Terms of Service, has completed the registration process, resulting in the creation of an active Account.

2.

Processing of personal data

2.1. In connection with its business operations, in particular through the Website and Application, the Controller collects and processes Personal Data in accordance with applicable laws, especially the GDPR, and adheres to the principles of data processing laid down therein.

2.2. The Controller:

  • 2.2.1. ensures transparency in the processing of Personal Data;
  • 2.2.2. provides information about data processing at the time of collection, in particular about the purposes and legal basis, unless exempted by law;
  • 2.2.3. collects and processes only the data necessary for the stated purpose and for no longer than required.

2.3. When processing Personal Data, the Controller ensures their confidentiality and security and provides Data Subjects with access to information about how their data are processed. If, despite implemented safeguards, a personal data breach occurs (e.g. data leakage or loss) that could pose a high risk to individuals' rights or freedoms, the Controller shall inform the affected Data Subjects in compliance with legal requirements.

3.

General data security principles

3.1. The confidentiality and security of Personal Data are a top priority for the Controller.

3.2. The Controller may use non-personal data collected through the Website and Application only when anonymized, i.e. when it cannot be linked to a specific User, for purposes such as producing anonymous reports and aggregate statistics. This provision does not apply to the processing of pseudonymous data (including the device advertising identifier and installation identifiers assigned by the software libraries (SDKs) used) for analytics and advertising purposes — such data do not constitute anonymized data, and their processing takes place on the terms and legal bases described in §4.3, §4.9–§4.10 and §7.6–§7.9.

3.3. To ensure data integrity and confidentiality, access to Personal Data is restricted to authorized individuals and only to the extent necessary for the performance of their duties.

3.4. The Controller uses organizational and technical measures to ensure that all data operations are logged and performed only by authorized persons.

3.5. The Controller also ensures that any contractors or third parties acting on its behalf guarantee the application of appropriate security measures whenever they process Personal Data.

3.6. The Controller continuously conducts risk assessments and monitors the adequacy of safeguards, implementing additional measures where necessary to improve data protection.

4.

Purposes and legal bases of processing

4.1. Account creation

  • 4.1.1. To create a User Account, it is necessary to provide certain data such as an email address. By accepting the Terms of Service, the User enters into an electronic services agreement with the Controller.
  • 4.1.2. Legal basis: necessity for the performance of a contract or to take steps at the request of the User prior to entering into a contract (Article 6(1)(b) GDPR).

4.2. Use of the Application

  • 4.2.1. To provide the Application's Services, the Controller processes other Personal Data necessary for the performance of specific functions.
  • 4.2.2. Legal basis: Article 6(1)(b) GDPR – contract performance or pre-contractual steps.

4.3. Analytical, statistical and research purposes

  • 4.3.1. The Controller may process Personal Data for analytical, statistical, and research purposes, such as analyzing Users' activity and preferences to improve the functionality of the Website and Application.
  • 4.3.2. The Controller may also prepare aggregated reports, analyses, and studies for third parties or for research purposes. Such documents will never include Personal Data identifying individual Users.
  • 4.3.3. Uploaded graphic files (e.g. photos or drawings) may be processed to generate personalized stories. These files are used exclusively to create story content and related visuals. They will not be published or used for other purposes and may be deleted or anonymized after the service is completed. The legal basis for the processing of these files is the necessity for the performance of a contract or to take steps at the request of the User prior to entering into a contract (Article 6(1)(b) GDPR).
  • 4.3.4. The legal basis for the processing referred to in §4.3.1 and §4.3.2 is the Controller's legitimate interest in analysing how the Website and the Application are used and in improving their functionality (Article 6(1)(f) GDPR).

4.4. Email and postal correspondence

  • 4.4.1. Personal Data contained in correspondence received by email or post are processed solely for communication and issue resolution.
  • 4.4.2. Legal basis: legitimate interest of the Controller (Article 6(1)(f) GDPR) – handling correspondence related to business operations.

4.5. Telephone contact

  • 4.5.1. When contacting the Controller by phone on matters unrelated to an existing contract or services, the Controller may request limited Personal Data necessary to handle the issue.
  • 4.5.2. Legal basis: legitimate interest of the Controller (Article 6(1)(f) GDPR) – resolving matters related to its business activity.

4.6. Pursuing claims

  • 4.6.1. The Controller may process certain Personal Data to establish, exercise, or defend legal claims arising from Users' use of the Website or Application.
  • 4.6.2. Legal basis: legitimate interest of the Controller (Article 6(1)(f) GDPR).

4.7. Exercising data subject rights

  • 4.7.1. To facilitate the exercise of rights under the GDPR (e.g. filing complaints or requests), the Controller may process relevant Personal Data.
  • 4.7.2. Legal basis: legitimate interest of the Controller (Article 6(1)(f) GDPR).

4.8. Marketing of Controller's services

  • 4.8.1. Commercial communications

    • 4.8.1.1. With the Data Subject's consent, the Controller may send commercial messages by email.
    • 4.8.1.2. Legal basis: consent (Article 6(1)(a) GDPR) and, where applicable, Article 10(2) of the Polish Act on Electronic Services (18 July 2002) or Article 398 of the Electronic Communications Law (12 July 2024).
  • 4.8.2. Newsletter

    • 4.8.2.1. Based on the Data Subject's consent, the Controller may send newsletters to the provided email address.
    • 4.8.2.2. Legal basis: consent (Article 6(1)(a) GDPR).

4.9. Advertising measurement and personalization (Google, Meta)

  • 4.9.1. With the Data Subject's consent, the Controller processes data about the use of the Website and the Application (including screens opened and actions taken, events such as registration or purchase, device and operating system type, and approximate location at country or city level) together with the device advertising identifier and other pseudonymous identifiers, in order to measure the effectiveness of advertising campaigns (including conversion measurement), build audiences, and display personalized advertising and remarketing within Google and Meta services.
  • 4.9.2. Legal basis: consent of the Data Subject (Article 6(1)(a) GDPR). Consent is voluntary and collected separately — through a consent banner displayed in the Application and on the Website.
  • 4.9.3. Consent may be withdrawn at any time in the consent settings available in the Application and on the Website. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
  • 4.9.4. Giving consent is voluntary and is not a condition for using the Website or the Application. Withholding consent only means that advertising will not be personalized and its effectiveness will not be measured in a way linked to the device identifier.
  • 4.9.5. The recipients of these data and the scope of the sharing are described in §7.6–§7.9 of this Policy.

4.10. Storing and reading information on the user's device

  • 4.10.1. Using the Website and the Application involves storing information on the Data Subject's terminal device and accessing information already stored on it. This applies both to the Controller and to the providers of analytics and advertising tools listed in §7. In particular, this includes: cookies and similar technologies on the Website, the device advertising identifier (Advertising ID on Android and Identifier for Advertisers on iOS), installation identifiers assigned by the software libraries (SDKs) used, and data written to the device's local storage.
  • 4.10.2. Storing and reading information strictly necessary to provide the Services requested by the Data Subject (e.g. maintaining a session and login state, remembering settings, ensuring security) takes place without consent, pursuant to Article 399(3) of the Polish Act of 12 July 2024 – Electronic Communications Law.
  • 4.10.3. Storing and reading information for the purposes referred to in §4.9 (advertising measurement and personalization) requires the Data Subject's consent, pursuant to Article 399(1)(2) of the Electronic Communications Law. That consent is collected together with the consent referred to in §4.9 and may be withdrawn at any time.
  • 4.10.4. Regardless of the consents given on the Website and in the Application, the Data Subject can manage the advertising identifier at the operating system level — reset it or turn off ad personalization (Android: Settings → Privacy → Ads; iOS: Settings → Privacy & Security → Tracking). In a web browser, the Data Subject can manage and delete cookies.
5.

Provision of personal data

5.1. Account creation. Providing Personal Data is voluntary but required to create an Account and use the Services.

5.2. Newsletter. Providing an email address is voluntary but necessary to receive newsletters.

6.

Social media profiles

6.1. The Controller operates public profiles on Facebook and LinkedIn. It processes Personal Data of visitors to these profiles (e.g. comments, likes, social media IDs) for purposes including:

  • 6.1.1. effective profile management and communication;
  • 6.1.2. promotion of services, events, and activities;
  • 6.1.3. statistical and analytical purposes;
  • 6.1.4. potential establishment or defense of legal claims.

6.2. Legal basis: legitimate interest of the Controller (Article 6(1)(f) GDPR) – brand promotion, service improvement, and claim management.

6.3. Note: This Policy does not cover processing performed by the operators of Facebook or LinkedIn. Details are available in those platforms' respective privacy policies.

6.4. Users may delete their comments, stop following the Controller, or delete their social media accounts at any time.

7.

Data recipients

7.1. In connection with its operations, Personal Data may be disclosed to third parties such as IT service providers, postal operators, couriers, accounting firms, legal or consulting service providers, and marketing agencies.

7.2. Data of Users using online payments are shared with payment service providers under the Polish Payment Services Act (19 August 2011).

7.3. Aggregated and anonymized data (i.e. data that do not allow identification of individual Data Subjects) may be shared with external providers for statistical purposes and to better assess the attractiveness of the services offered by the Controller. Sharing of data for advertising measurement and personalization is governed by §7.6–§7.9 — such data include pseudonymous identifiers (including the device advertising identifier), do not constitute anonymized data, and are shared only with the Data Subject's consent.

7.4. The Controller reserves the right to disclose selected information to competent authorities or third parties who lawfully request such information.

7.5. For sending email messages (marketing, transactional, and service emails) the Controller uses the services of Mailjet SAS, with its registered office at 4 rue Jules Lefebvre, 75009 Paris, France, part of the Sinch AB group. Mailjet SAS acts as a processor under a data processing agreement concluded with the Controller in accordance with Article 28 GDPR. The current list of Sinch sub-processors is available at: https://sinch.com/legal/data-protection-agreement-sub-processors/.

7.6. For analytics and advertising the Controller uses the services of Google — Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC. Only with the Data Subject's consent (§4.9), through Google Analytics for Firebase and Google Ads, the Controller shares with Google data about the use of the Website and the Application together with pseudonymous identifiers, including the device advertising identifier, for the purposes of measuring advertising effectiveness and conversions, building audiences, and remarketing. Google's data practices are described at: https://business.safety.google/privacy/ and https://policies.google.com/technologies/partner-sites.

7.7. For advertising and the measurement of its effectiveness the Controller also uses the services of Meta — Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland. Only with the Data Subject's consent (§4.9), through Meta App Events (an SDK in the Application) and the Meta Pixel (on the Website), the Controller shares with Meta information about events relating to the use of the Website and the Application (e.g. registration, purchase) together with pseudonymous identifiers, including the device advertising identifier. Meta's data practices are described in its Privacy Policy, available at: https://www.facebook.com/privacy/policy/.

7.8. The role of Google and Meta in relation to the tools referred to in §7.6 and §7.7 differs depending on the provider and the phase of processing:

  • 7.8.1. Google acts as a processor on behalf of the Controller with respect to measurement (Google Analytics for Firebase), and as a separate controller with respect to advertising features (Google Ads, including conversion measurement, audience building, and remarketing) — in accordance with the Google Ads Data Processing Terms and the Google Ads Controller-Controller Data Protection Terms.
  • 7.8.2. Meta acts as a joint controller together with the Controller for the phase of collecting and transmitting event data through the Meta App Events and Meta Pixel tools, and — once the data have been transmitted — as a separate controller with respect to further processing for its own purposes — in accordance with the Meta Business Tools Terms and the Meta Controller Addendum. The joint-controllership arrangements are described in §7.9.
  • 7.8.3. Any transfer of data outside the EEA in connection with these services takes place on the basis described in §8. If the consent referred to in §4.9 is not given or is withdrawn, no data are shared with Google or Meta for advertising purposes.

7.9. Joint controllership of data with Meta (Article 26 GDPR)

  • 7.9.1. Joint controllership covers only the phase of collecting and transmitting event data through the Meta App Events and Meta Pixel tools. Once the data have been transmitted, Meta Platforms Ireland Limited processes them as a separate controller, for its own purposes and on its own responsibility.
  • 7.9.2. The allocation of responsibilities between the Controller and Meta follows from the joint-controllership arrangement (the Meta Controller Addendum), available at: https://www.facebook.com/legal/controller_addendum. With respect to data processed after transmission, Meta is responsible for giving effect to the rights of Data Subjects under Articles 15–20 GDPR. Requests concerning jointly processed data that are addressed to the Controller are forwarded to Meta without undue delay, and no later than within seven calendar days. The information obligations towards Data Subjects — including informing them that Meta is a joint controller and about how Meta processes data — are fulfilled by the Controller; detailed information from Meta is available at the address indicated in §7.7.
  • 7.9.3. Irrespective of the terms of the arrangement, pursuant to Article 26(3) GDPR the Data Subject may exercise their rights in respect of and against each of the joint controllers — both the Controller and Meta.
8.

Data transfer outside the EEA

8.1. The Controller generally processes Personal Data within the European Economic Area (EEA).

8.2. Where the Controller uses the services of entities with offices or infrastructure outside the EEA — both processors (in particular sub-processors of email marketing, hosting, or analytics providers) and recipients acting as separate controllers or joint controllers (Google and Meta, §7.6–§7.9) — transfers of Personal Data take place only on the basis of:

  • 8.2.1. a European Commission adequacy decision (Article 45 GDPR), including for certified recipients in the United States — on the basis of the EU–US Data Privacy Framework (Commission Decision 2023/1795); or
  • 8.2.2. Standard Contractual Clauses approved by Commission Decision 2021/914 (Article 46(2)(c) GDPR) — incorporated into agreements with processors (module two) and with recipients acting as separate controllers or joint controllers (module one).

8.3. A current list of processors, including those whose sub-processors may be located outside the EEA, is available on request to the address provided in §12 and is referenced in §7 of this Policy.

9.

Automated decision-making and profiling

9.1. The Controller uses profiling within the meaning of Article 4(4) GDPR to tailor marketing communications to the preferences and behaviour of Users of the Application, and — only with the Data Subject's consent (§4.9) — also to build audiences and personalize advertising within Google and Meta services.

9.2. Profiling consists of assigning Users to segments (e.g. by Application activity, subscription status, favourite story categories, language of communication) based on data collected through their use of the Application.

9.3. Profiling performed by the Controller does not produce legal effects concerning the Data Subject or similarly significantly affect them within the meaning of Article 22(1) GDPR — it serves solely to adjust the content and frequency of marketing communications and of the advertising referred to in §9.1.

9.4. The legal basis for profiling for marketing purposes is the consent of the Data Subject (Article 6(1)(a) GDPR), expressed separately and in a manner allowing it to be withdrawn at any time.

9.5. The Controller does not make decisions about Data Subjects based solely on automated processing that would produce legal effects concerning them or similarly significantly affect them.

10.

Data retention period

10.1. Personal Data are retained for as long as the User maintains an Account and for three (3) years after its deletion or closure.

10.2. This period may be extended if necessary for legal claims or defense, or as required by law.

10.3. When data are processed based on legitimate interest, they are retained until an effective objection is raised.

10.4. When processed based on consent, data are retained until consent is withdrawn. Withdrawal does not affect the lawfulness of prior processing.

11.

Data subject rights

Data Subjects have the following rights:

  • 11.1. Right to information – to obtain details about the processing of their Personal Data.
  • 11.2. Right of access – to receive a copy of their data.
  • 11.3. Right to rectification – to correct inaccurate or incomplete data.
  • 11.4. Right to erasure ("right to be forgotten") – to request deletion of data no longer necessary.
  • 11.5. Right to restriction of processing – to request suspension of processing under certain conditions.
  • 11.6. Right to data portability – to receive their data in a structured, machine-readable format or have it transmitted to another controller.
  • 11.7. Right to object – to object to processing for marketing or other legitimate interest purposes.
  • 11.8. Right to withdraw consent – where processing is based on consent, it may be withdrawn at any time.
  • 11.9. Right to lodge a complaint – with a supervisory authority, in Poland: the President of the Personal Data Protection Office (UODO).
12.

Exercising your rights

12.1. Requests regarding Data Subject rights may be submitted:

  • 12.1.1. in writing: APPVENTIS PROSTA SPÓŁKA AKCYJNA, ul. Kazimierza Pułaskiego 6/10, 26-600 Radom, Poland;
  • 12.1.2. by email: [email protected].

12.2. If identification is not possible, the Controller may request additional information. Responses are provided within one month. In justified cases, this period may be extended with prior notice.

12.3. Requests submitted electronically will generally receive electronic replies unless otherwise requested.

12.4. The Controller keeps records of requests and responses to demonstrate compliance and to establish or defend legal claims.

13.

Data protection officer

13.1. The Controller has not appointed a Data Protection Officer.

14.

Updates to this Privacy Policy

14.1. This Privacy Policy may be amended due to changes in applicable law or in the Controller's operations.

14.2. The Controller will inform Users about updates via the Website or Application, indicating the effective date of changes, allowing Users to exercise their GDPR rights, including withdrawal of consent or objection.

14.3. This Privacy Policy is effective as of 13 August 2026.

14.4. Archived versions of the Privacy Policy are available upon request to the address provided in §12.