Wersja polska

Privacy policy

Effective from 7 October 2026

SpaDesk is a web application for spa, massage and wellness businesses (the “Companies”), available at app.spadesk.pl, together with the website spadesk.pl. This policy explains what personal data we process, why, who we share it with and what rights you have. The Polish version is the binding one.

1. Data controller

Alex Maher Netskyes

ul. Telefoniczna 23D, 91-728 Łódź, Poland

NIP (tax ID) 7272820962

Email: kontakt@spadesk.pl

We are the controller of the data described in section 3. For anything about personal data, write to kontakt@spadesk.pl.

2. Two roles: controller and processor

We process the data of the people who use SpaDesk (Company owners and staff) and the Companies' own data as a controller — section 3. We process the data of a salon's clients and employees, which the Company enters into the app, on behalf of that Company, which is its controller — section 4.

3. Data we process as controller

What data

Purposes and legal bases

Providing data is voluntary, but an account can't be created without an email address and a password.

4. Data Companies entrust to us

A Company using SpaDesk enters data about:

The Company is the controller of this data. We process it only on the Company's behalf and instructions, to provide the service, and never for our own purposes. If you are a client or an employee of a salon and want to exercise your rights, please contact the salon. If your request reaches us, we will pass it on to the right Company.

5. Who we share data with

We use service providers that process data on our behalf:

Some providers are based outside the European Economic Area, including in the United States. Data is transferred to them on the basis of a European Commission adequacy decision (the EU-U.S. Data Privacy Framework) or standard contractual clauses. Public authorities may also receive data where the law requires it. We don't sell personal data.

6. How long we keep data

7. Your rights

You have the right to:

Write to kontakt@spadesk.pl — we reply within one month. A Company's owner can also download all of the Company's data themselves: Settings → Company → Export all data. How to delete data is described on the Data deletion page.

You also have the right to complain to the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or to the authority where you live.

8. Cookies and browser storage

9. Security

Connections to the app are encrypted (HTTPS). Passwords are stored only as hashes. Each Company's data is kept apart in the database itself. Access tokens for ad platforms and employees' national ID and bank account numbers are encrypted in the database. Access depends on a person's role and locations, and changes are recorded in an audit log.

10. Data from Facebook, Instagram and Google

When someone at a Company connects SpaDesk to their Facebook or Google account, with their permission we receive an access token and the information needed to run the Company's ads: the name on the Facebook profile or the Google account's email address, the list of ad accounts, Facebook Pages and Instagram accounts they manage, and campaign data — budgets, ad copy, targeting area and results.

We use it only to create and change the Company's ads and to show their results in SpaDesk. We don't sell it or share it with anyone else. The connection can be removed at any time — see Data deletion.

11. Changes to this policy

We may change this policy, for example when we add a feature or a provider. The current version is always at this address; we will tell you about important changes in the app or by email.