Privacy Policy
Last updated: 22 June 2026
This policy explains what personal data we process in connection with your use of the Viamoo website (viamoo.pl) and the event apps hosted at addresses on the viamoo.pl domain — for what purpose and on what basis, who we may share it with, and what rights you have under the GDPR (EU Regulation 2016/679).
1. Data controller
The data controller is [TO COMPLETE: full company name / sole trader details, address, tax ID]. For any matter concerning your personal data you can reach us at kontakt@viamoo.pl.
2. What data we process
People ordering an event (the customer):
- first and last name
- email address
- event name and type, and the chosen subdomain (app address)
- chosen plan and order amount
Guests using the event app:
- the first name or nickname entered when joining the app
- photos and videos added to the gallery and the photo-bingo game
- the content of comments and the name shown under a comment
- guest names at tables (if entered by the organiser in the seating plan)
Technical data:
- a pseudonymous guest device identifier stored in the browser (localStorage) — used to recognise who added a given piece of content; it contains no login credentials
- a one-time admin login token (magic link)
- standard server logs (e.g. IP address, browser information) necessary to keep the service secure and running
3. Purposes and legal bases for processing
- Fulfilling the order and providing the service (creating and running the event app) — Article 6(1)(b) GDPR (performance of a contract).
- Billing and accounting/tax obligations — Article 6(1)(c) GDPR (legal obligation).
- Keeping the service secure, preventing abuse and maintaining the infrastructure — Article 6(1)(f) GDPR (legitimate interest).
- Content added by guests (photos, videos, comments) — Article 6(1)(a) GDPR (consent given by adding the content) and the legitimate interest of the event organiser.
4. Who we share data with (processors)
We rely on trusted service providers who process data on our behalf only to the extent needed to run the service:
- Railway — app hosting and the PostgreSQL database (order data, event configuration, guest content).
- Cloudflare — DNS, content delivery network (CDN) and R2 file storage, where photos and videos are kept (stored in the EU jurisdiction).
- Vercel — hosting for the marketing website.
- Resend — email delivery provider (purchase confirmation, dashboard link).
- Payment provider — [TO COMPLETE once live: Stripe / Przelewy24] — handling payment for the order.
5. Transfers outside the EEA
Some providers (including Railway, Cloudflare, Vercel and Resend) are based or run infrastructure outside the European Economic Area (e.g. in the USA). In such cases, data is transferred on the basis of the appropriate safeguards provided for by the GDPR — in particular Standard Contractual Clauses or the Data Privacy Framework. [TO COMPLETE: confirm the basis for each provider]
6. Retention period
- Event data and guest content — for the duration of the plan and a reasonable period after it expires, after which it is deleted. [TO COMPLETE: exact period, e.g. 30 days after the event]
- Order data and billing documents — for the period required by law (including tax law).
- Admin account — until the event is deleted or a deletion request is made.
7. Your rights
In connection with the processing of your data, you have the right to:
- access your data and obtain a copy of it
- rectify (correct) your data
- erase your data
- restrict processing
- data portability
- object to processing based on legitimate interest
- withdraw consent at any time (without affecting the lawfulness of processing carried out before the withdrawal)
To exercise these rights, write to kontakt@viamoo.pl. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO).
8. Cookies and browser storage
The site uses no marketing or tracking cookies. Inside the event app we use only technical browser storage (localStorage) needed for it to work — for example, to remember a guest's name and recognise their device.
9. Changes to this policy
We may update this policy as the service evolves. The current version is always available on this page, and the date of the last change is shown at the top of the document.