Vriendi Privacy Policy

Version dated: 30 September 2026

This is an English translation of the Polish privacy policy for convenience only. In case of any discrepancy, the Polish version is legally binding.

§1. Data controller

  1. The controller of personal data processed in connection with the use of the Vriendi service (vriendi.com) is Chillsoft Tomasz Mańka, a Polish sole proprietorship, NIP (tax ID): 8992843377, registered at: Wspólna 53, 42-713 Kochcice, Poland, hereinafter the "Controller".
  2. The Controller can be contacted regarding personal data protection matters at: hello@vriendi.com.

§2. What data we collect

  1. In connection with booking and paying for event participation, we process: name, email address, age, and the city and date of the chosen event. This data is collected via the payment processor Stripe during the ticket purchase process.
  2. In connection with the contact form available on the site, we process: name, email address, and the content of the message sent.
  3. In connection with signing up for the waitlist, we process the data provided in the Tally form, including your email address.
  4. Automatically, through cookies, similar technologies and cookieless signals, we collect data about how the service is used (including pages visited and events in the booking process) - details in §6.

§3. Purposes and legal basis for processing

  1. Data is processed for the purpose of:
    • entering into and performing an agreement for participation in an event, including handling payment - based on Art. 6(1)(b) GDPR,
    • responding to a message sent via the contact form or a waitlist sign-up - based on Art. 6(1)(b) and (f) GDPR,
    • communicating with participants before and after the event (including reminders and organizational information) - based on Art. 6(1)(f) GDPR (the Controller's legitimate interest),
    • issuing accounting documents and tax settlements - based on Art. 6(1)(c) GDPR (legal obligation),
    • analyzing site traffic and measuring the effectiveness of marketing activities - based on Art. 6(1)(f) GDPR and, for cookies necessary for this purpose, based on consent given in accordance with Art. 399 of the Polish Electronic Communications Law of 12 July 2024.

§4. Recipients of data

  1. Personal data may be shared only with entities that support the operation of the service, to the extent necessary:
    • Stripe - online payment processing,
    • Render - hosting of the booking system and database (servers in Frankfurt, EU),
    • Brevo - sending emails (including confirmations, reminders and replies to messages),
    • Google (Google Analytics) - visit statistics,
    • Meta (Meta Pixel, Conversions API) - measuring ad performance,
    • Tally.so - handling the waitlist and survey forms,
    • Netlify - website hosting.
  2. Some of the above entities may process data outside the European Economic Area (including in the USA). In such cases, the transfer relies on mechanisms ensuring an adequate level of data protection, in particular standard contractual clauses approved by the European Commission.
  3. The Controller does not sell personal data or share it with third parties for purposes other than those described in this Policy.

§5. Data retention period

  1. Data related to a booking and payment is stored for the duration of the service, and afterwards for the period required by tax and accounting law (generally 5 years, counted from the end of the year in which the transaction took place).
  2. Data from the contact form and waitlist is stored for as long as necessary to respond to and handle the inquiry, no longer than 12 months from the last contact, unless an objection or a deletion request is submitted earlier.
  3. Data collected via cookies is stored for the period indicated in §6, in line with each tool's own settings.

§6. Cookies and analytics tools

  1. The service uses cookies and similar technologies to ensure the site works correctly, to track visit statistics, and to measure the effectiveness of marketing activities.
  2. The service uses, in particular: Google Analytics (visit statistics) and Meta Pixel (measuring the performance of ads on Facebook and Instagram).
  3. On their first visit, users can accept or decline analytics and marketing cookies using a banner. The choice is remembered in the browser's storage (localStorage), so the banner is not shown again. Consent can be withdrawn at any time by clearing the vriendi.com site data in the browser settings (the banner will then reappear) or by writing to hello@vriendi.com.
  4. Google Analytics runs in Google Consent Mode (version 2). The Google Analytics script loads on every visit, but until the user gives consent it does not store cookies or any other identifiers on their device and only sends Google cookieless signals about page views and events on the site (e.g. a completed purchase). Google uses them to estimate statistics in aggregated form, without identifying the user. Once consent is given, Google Analytics stores analytics cookies (including _ga).
  5. Meta Pixel is loaded only after consent is given. Without consent, the Meta script is not loaded and stores no cookies.
  6. Regardless of cookie consent, when a payment is started and a purchase is completed, the Controller sends Meta, directly from its server (Meta Conversions API, without cookies), information about the event (including its type and value) together with a one-way encrypted (SHA-256) email address and first name, the IP address and browser information (user agent). The purpose is measuring ad performance, and the legal basis is the Controller's legitimate interest (Art. 6(1)(f) GDPR). Objections to this processing can be sent to hello@vriendi.com.
  7. Users can manage cookies at any time through their web browser's settings, including deleting stored cookies and blocking future ones. Restricting cookies may affect some of the site's functionality.

§7. User rights

  1. The data subject has the right to: access their data, rectify it, erase it, restrict its processing, transfer it, and object to processing based on the Controller's legitimate interest.
  2. Where processing is based on consent (e.g. certain cookies), the data subject has the right to withdraw it at any time, without affecting the lawfulness of processing carried out before its withdrawal.
  3. Requests regarding the above rights should be sent to: hello@vriendi.com.
  4. The data subject has the right to lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland) if they believe that data processing violates GDPR.

§8. Data security

  1. The Controller applies appropriate technical and organizational measures to protect personal data being processed, including against access by unauthorized persons.
  2. The Controller does not store Participants' card details or other sensitive financial data - this data is processed exclusively by the payment processor Stripe.

§9. Changes to this Privacy Policy

  1. The Controller reserves the right to amend this Privacy Policy, in particular in connection with changes to the law or to how the service operates.
  2. The current version of the Privacy Policy is always available at vriendi.com/polityka-prywatnosci (Polish) and vriendi.com/en/privacy-policy (English).

§10. Contact

  1. Any questions regarding this Privacy Policy and personal data processing should be sent to: hello@vriendi.com.