Privacy Policy
Version 2.1
Language versions: This privacy policy is provided in English and Polish. Both versions are intended to be identical in content and equally describe the data processing carried out.
1. Controller
The controller responsible for the processing of personal data within the meaning of the General Data Protection Regulation (GDPR) is:
Remigiusz Lysko
unregistered business activity (działalność nierejestrowana)
Rokitno 62
22-678 Rokitno
Poland
Tel.: +48 799 332 033
E-mail: hello@pybient.com
A data protection officer has not been appointed, as there is no statutory obligation to appoint a data protection officer.
2. Scope of Application
This privacy policy applies to:
- visiting the website pybient.com,
- use of the contact form,
- the acquisition and management of Pybient licenses,
- payment processing,
- the creation and dispatch of the license file,
- software activation and license verification,
- the management of permitted device seats,
- voluntary error reports and support requests submitted from within the software,
- checking the availability of software updates.
Personal data are processed only to the extent necessary for the purposes described below or to the extent that another legal basis exists.
3. Hosting at OVHcloud and Server Log Data
The website, the online shop, and the license server run on OVHcloud infrastructure (OVH group of companies, headquarters: 2 rue Kellermann, 59100 Roubaix, France).
OVHcloud processes the data stored on this infrastructure on our behalf. The contractual data protection arrangements required for this purpose have been concluded with OVHcloud, including a data processing agreement pursuant to Art. 28 GDPR.
When the website or the license server is accessed, technically necessary connection data may arise at the level of the server infrastructure used. These may include in particular:
- IP address,
- date and time of access,
- the page or interface accessed,
- the volume of data transferred,
- browser type and version,
- operating system,
- referrer address,
- messages about successful or unsuccessful access attempts.
These data serve the technical provision and the protection of the website and the license server against attacks and misuse.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of our systems.
We ourselves do not create any of our own logs going beyond this and do not carry out any regular analysis of the log data that arise. Insofar as log files arise on the infrastructure, they are automatically overwritten or deleted as part of log rotation, at the latest after 30 days. Only in the event of a specific security incident may the data concerned be analyzed and stored for longer — until the incident has been fully clarified and averted.
4. Technically Necessary Cookies and Session Data
For the ordering process, technically necessary WordPress and WooCommerce session functions are used.
They serve in particular to:
- manage the shopping cart,
- remember the selected product and its quantity,
- store the selected payment method,
- retain order data already entered between the individual ordering steps,
- technically carry out the ordering process.
The processing is necessary to carry out the ordering process desired by the user.
The legal basis is Art. 6(1)(b) GDPR. In addition, the processing is based on Art. 6(1)(f) GDPR insofar as it is necessary for the secure and undisturbed operation of the online shop.
Session data are deleted or automatically expire after the ordering process is completed or aborted, at the latest 48 hours after the last activity.
We ourselves do not use cookies for advertising, analytics, or tracking purposes.
When an external payment service provider is accessed, its own cookies or comparable technologies may be used there in accordance with the data protection provisions of the respective provider.
5. Contact Form and General Contact
The website offers the possibility of contacting us via a contact form.
The following data are processed in this context:
- name,
- e-mail address,
- content of the message,
- time of submission,
- technically necessary data serving protection against spam and misuse, namely the number of seconds between the page being opened and the form being sent, and the content of a hidden form field that is invisible to human visitors and is only filled in by automated programs.
The name, e-mail address, and message are necessary so that the inquiry can be allocated and answered.
The transmitted data are processed for the purpose of handling the inquiry. If the inquiry relates to a planned or existing contract, the legal basis is Art. 6(1)(b) GDPR.
For general inquiries, processing takes place on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in handling incoming inquiries, communicating with customers, and documenting the communication.
The message may be processed via the server and e-mail systems we use and stored in our e-mail mailbox.
Contact inquiries are generally deleted after their handling has been finally completed, at the latest after twelve months. Longer storage takes place only if the message forms part of a contract, a complaint, a legal dispute, or another matter for which statutory retention periods or limitation periods apply.
6. Orders via WooCommerce
The online shop is based on WordPress and WooCommerce. WordPress and WooCommerce are installed on our infrastructure operated at OVHcloud.
When an order is placed, in particular the following data are processed:
- name,
- e-mail address,
- street and house number,
- postal code,
- city,
- country,
- where applicable, company or institution,
- where applicable, the buyer's NIP number, if voluntarily provided when ordering,
- the selected license type,
- the ordered quantity or number of workstations,
- the acquired major version,
- price and currency,
- payment method,
- time of order placement,
- order number,
- payment reference,
- order and payment status,
- the selected language.
The data are processed for the purpose of:
- concluding and performing the purchase contract,
- allocating payments,
- creating the individual license,
- sending the license file,
- informing the customer about the order,
- handling matters relating to technical support, complaints, and statutory liability for conformity with the contract,
- fulfilling statutory accounting and tax obligations.
The legal basis for the performance of the contract is Art. 6(1)(b) GDPR.
Insofar as storage is necessary to fulfill tax, accounting, or other statutory obligations, it takes place on the basis of Art. 6(1)(c) GDPR.
The license plugin used by Pybient does not store the customer's IP address separately as proof of consent in its own order metadata. Independently of this, the IP address may technically appear in server log files.
7. Declarations Concerning the License Agreement and the Right of Withdrawal
During the ordering process, the following declarations are stored:
- acceptance of the license agreement,
- the express request for delivery of the digital service to begin before expiry of the withdrawal period,
- confirmation of the acknowledgment that the right of withdrawal expires upon the commencement of delivery,
- the wording of these declarations as displayed at the time of the order,
- the timestamp transmitted by the end device,
- the timestamp generated on the server side,
- the language selected in the ordering process.
These data are stored as part of the contractual documentation and in order to demonstrate the proper delivery of the digital content.
The legal bases are Art. 6(1)(b) and (c) GDPR. Insofar as the data are needed for the establishment, exercise, or defense of legal claims, the processing is additionally based on Art. 6(1)(f) GDPR.
These declarations do not constitute consent to advertising or to any other use of the customer's data.
8. Payment Processing
In particular, Autopay, Stripe, PayPal, and bank transfer may be offered as payment methods.
Autopay
If an online payment via Autopay (BLIK, payment card, fast bank transfer / pay-by-link) is selected, the data necessary for payment processing are transmitted to the payment service provider:
Autopay S.A.
ul. Powstańców Warszawy 6
81-718 Sopot, Poland
The data processed by Autopay may include in particular:
- name,
- e-mail address,
- order number,
- amount and currency,
- payment status,
- transaction reference,
- bank account or card details entered on the payment page,
- technical connection data such as the IP address.
Autopay processes these data within the scope of its payment services as an independently responsible controller within the meaning of data protection law. Autopay's own data protection provisions apply to any further processing.
The legal basis for the transmission of data in the context of the selected payment is Art. 6(1)(b) GDPR.
PayPal
If PayPal is selected, the data necessary for payment processing are transmitted to PayPal or collected by PayPal.
The provider for customers in the European Economic Area is generally:
PayPal (Europe) S.à r.l. et Cie, S.C.A.
22–24 Boulevard Royal
L-2449 Luxembourg
The data processed by PayPal may include in particular:
- name,
- e-mail address,
- billing address,
- order number,
- amount and currency,
- information about the purchased product,
- payment status,
- transaction reference,
- technical connection data.
PayPal processes data within the scope of its payment services as an independently responsible controller within the meaning of data protection law. PayPal's data protection provisions, available on PayPal's website, apply to any further processing.
The legal basis for the transmission of data in the context of the selected payment is Art. 6(1)(b) GDPR.
Stripe
If payment via Stripe (cards, wallets, and local payment methods) is selected, the data necessary for payment processing are transmitted to the payment service provider or collected by it directly on its payment page:
Stripe Payments Europe, Limited
The One Building, 1 Grand Canal Street Lower
Dublin 2, D02 H210, Ireland
The data processed by Stripe may include in particular:
- name,
- e-mail address,
- billing address,
- order number,
- amount and currency,
- payment status,
- transaction reference,
- card or account details entered on the payment page,
- technical connection data such as the IP address as well as data used for fraud prevention.
Stripe processes these data within the scope of its payment services as an independently responsible controller within the meaning of data protection law. Stripe's own data protection provisions apply to any further processing.
Stripe may transfer data to its parent company Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA, and thus to a third country. As a safeguard, Stripe uses the standard contractual clauses of the European Commission pursuant to Art. 46(2)(c) GDPR.
The legal basis for the transmission of data in the context of the selected payment is Art. 6(1)(b) GDPR.
Bank Transfer
In the case of a bank transfer, the participating banks process in particular:
- the payer's name,
- bank account details,
- the amount,
- the payment date,
- the transfer reference or payment reference.
We receive the information necessary to allocate the payment.
The legal basis is Art. 6(1)(b) GDPR.
9. Creation of the License File
After successful completion of the order, an individual license file is created.
The license file may contain in particular the following data:
- the licensee's name,
- e-mail address,
- license number,
- license type,
- the acquired major version,
- the permitted number of devices,
- the internal order number.
These data are stored in the license file in signed and encrypted form. The encryption serves to protect against unauthorized reading and manipulation of the license data.
The license file is sent as an attachment to the e-mail address provided when ordering.
For the purpose of e-mail dispatch, a copy of the file is temporarily created on the server. This temporary server copy is deleted immediately after dispatch.
Copies held by the recipient and by the participating e-mail providers are subject to the settings and retention rules of the respective mailbox.
The legal basis for creation and dispatch is Art. 6(1)(b) GDPR.
10. License Management
For the management of the license relationship, in particular the following data are stored:
- license number,
- license hash,
- license type,
- the acquired major version,
- the permitted number of devices,
- license status,
- the internal allocation to the order,
- the activation (unlock) value,
- the time of license creation,
- where applicable, internal support and handling notes.
The license hash serves as the technical identifier of the license. In the license management system it is linked to the corresponding order.
These data are processed for the performance of the perpetual license agreement, the technical verification of the license, the handling of technical support matters, and the prevention of unauthorized use.
The legal basis is Art. 6(1)(b) GDPR.
The prevention of license misuse, the safeguarding of the licensing system, and the establishment or defense of claims are additionally based on Art. 6(1)(f) GDPR.
11. License Verification at Every Program Start
Every time the software is started, an online license verification is carried out.
The software checks in particular:
- whether the license is known and active,
- whether the license has been blocked,
- which license type and which major version are unlocked,
- how many device seats are permitted,
- whether the device used is already known,
- whether a free device seat is still available.
In particular, the following data are transmitted to the license server:
- the cryptographic hash of the license,
- the cryptographic hash of the device identifier,
- technically necessary connection data.
The device identifier in plain form is not transmitted to the license server. The customer's name and e-mail address are not part of the activation request transmitted at each program start.
The IP address is not stored as part of the device binding. However, it may technically appear in the short-term server log files of the infrastructure used.
In the activation database, in particular the following are stored:
- the license hash,
- the device hash,
- the time of the first activation,
- the time of the last successful license verification.
The license and device hashes are pseudonymized data. They do not directly contain the user's name or e-mail address, but they can be allocated via the license management system to the license and thus indirectly to the order.
The processing is necessary for the performance of the license agreement and the provision of the full version.
The legal basis is Art. 6(1)(b) GDPR.
The prevention of license misuse and the enforcement of the agreed device limit are additionally based on Art. 6(1)(f) GDPR.
12. Device Seats and Inactive Device Bindings
Each activated device occupies one device seat within the license.
Each time the program is successfully started, the time of the last license verification of the respective device is updated.
If a device has not contacted the license server for at least 90 days, it is no longer counted as an active device in the calculation of currently occupied device seats. The device seat freed in this way may then be used by another device.
The associated device hash and the activation times remain stored in the current licensing system until:
- the respective device binding is manually released,
- all device bindings of the license concerned are deleted,
- the associated license is finally deleted,
- the license server ceases to be operated and there is no longer any further legal basis for storage.
Manual release may take place in particular in the event of a device replacement, a reinstallation, or at the licensee's request.
Device hashes are not used for advertising, analytics, or profiling purposes.
13. Automated Technical License Decision
License verification takes place in a technical and automated manner.
The system may return in particular the following states:
- license active,
- license blocked,
- license unknown,
- permitted number of device seats reached.
Depending on this result, use of the full version may be permitted or restricted.
No profiling and no evaluation of the user's personal characteristics take place. The decision is based solely on the technical license status and the agreed number of device seats.
To the extent that this constitutes an automated individual decision within the meaning of Art. 22(1) GDPR, it is permissible under Art. 22(2)(a) GDPR because it is necessary for the performance of the contract concluded with the user: without automated verification, the agreed number of device seats and the licensed scope of use cannot be maintained. The user has the right to obtain human intervention, to express their point of view, and to contest the decision.
If, in the user's view, the result is incorrect, a review by a human and, if necessary, a correction or the manual release of a device seat can be requested at hello@pybient.com.
14. Checking for Update Availability After Program Start
After the program starts, the software checks whether an update (a newer version) is available.
If an update is available, the user is informed of this solely by means of a popup window in the program. Nothing further happens; in particular, the program does not download or install the update automatically.
To obtain the updated version, the user must actively visit the website themselves and download the updated version from there.
During the update check — as with every connection to the server infrastructure used — technically necessary connection data may arise (see section 3). Beyond that, no further personal data are transmitted or stored as part of the update check.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in informing users about available updates, in particular about bug fixes and security updates.
15. Voluntary Error Reports from the Software
The software contains a voluntary error reporting function.
When the "Report bug" ("Bug melden") function is clicked, the e-mail program configured on the user's device is opened. The software does not send messages on its own and does not access the user's e-mail account or password.
The e-mail program generally uses the e-mail address configured in it by the user as the sender. Before sending, the user can:
- check the sender address used,
- read and change the content of the message,
- check the attached files,
- remove attachments,
- cancel the sending.
The user decides for themselves whether the e-mail is actually sent.
A technical protocol or log file and a screenshot may voluntarily be attached to the error report.
Depending on how the program is used, the screenshot or log file may unintentionally contain personal data or confidential information. These may include, for example:
- names,
- file names,
- file or folder paths,
- project names,
- the contents of open files or windows,
- operating system user names,
- e-mail addresses,
- other information visible on the screen.
Before creation or transmission, the software draws the user's attention to the following:
- check the screenshot and log file,
- black out or remove unnecessary personal data,
- do not transmit confidential content,
- check from which e-mail address the error report is sent.
Upon the actual sending of the e-mail, the user voluntarily transmits:
- the sender e-mail address used,
- the content of the error report,
- where applicable, the log file,
- where applicable, the screenshot,
- other attachments or information added by them.
The data are processed exclusively for the purpose of investigating, reproducing, and correcting the reported error and for communication with the user.
If the report concerns a purchased license or a support service owed, the legal basis is Art. 6(1)(b) GDPR.
Otherwise, processing takes place on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in correcting software errors, improving the stability and security of the software, and responding to voluntarily submitted error reports.
Screenshots and log files are deleted as soon as they are no longer needed to investigate the error. As a rule, they are deleted at the latest twelve months after the handling of the error report has been finally completed.
The associated e-mail correspondence is generally also deleted at the latest twelve months after the handling has been finally completed. Longer storage takes place only where it is necessary for handling a contractual dispute, a dispute concerning conformity with the contract, or another legal dispute.
Technical error information may be stored for longer without personal content in order to permanently document the error and to prevent recurring errors.
The user should not transmit special categories of personal data within the meaning of Art. 9 GDPR, access data, private keys, or other information subject to confidentiality.
15a. External Tools in the Compiler
Certain functions in the compiler call separate third-party programs that are not part of Pybient and are installed separately on the device (hereinafter "external tools"). Such a call takes place only on the express instruction of the user.
When called, an external tool may independently establish internet connections, download components or packages, and thereby transmit data to its provider or to a package source. At least the IP address of the device becomes known to those parties; depending on the tool, further technical details may be added, such as the operating system, the system architecture, or the requested package name.
This processing takes place under the respective provider's own responsibility. We are not involved in it, receive no data from it, and can influence neither the scope nor the purpose of the processing carried out there. The privacy notices of the respective provider apply.
Anyone who wishes to avoid such connections can refrain from using the functions concerned, or obtain the required programs and components in advance by other means and provide them locally. The call can be adjusted or deactivated in the compiler configuration.
16. Recipients and Categories of Recipients
Personal data may, insofar as necessary for the purposes described, be transferred to the following recipients or categories of recipients:
- OVHcloud as hosting and server provider,
- Autopay S.A., if an online payment via Autopay is selected,
- PayPal, if this payment method is selected,
- Stripe Payments Europe, Limited and Stripe, Inc., if payment via Stripe is selected,
- the participating banks in the case of bank transfers,
- e-mail providers and technical e-mail servers,
- IT and maintenance service providers, insofar as they require access to perform their tasks,
- tax advisors or accounting service providers,
- legal advisors, courts, and authorities, insofar as there is a statutory obligation or it is necessary for the establishment or defense of claims.
WordPress and WooCommerce are used as software installed on our infrastructure. The mere use of this software does not automatically result in the transfer of all order data to its manufacturers. Additional external WooCommerce services come into consideration only if they are actually activated and used.
Personal data are not sold or transferred for third-party advertising purposes.
17. Processing Outside the European Union or the European Economic Area
Insofar as personal data are processed outside the European Union or the European Economic Area, this takes place exclusively in compliance with Art. 44–49 GDPR.
A suitable basis may in particular be:
- an adequacy decision of the European Commission,
- standard contractual clauses,
- other legally recognized guarantees.
In the case of external payment or e-mail service providers, depending on the selected provider and its infrastructure, processing in third countries may occur. The data protection provisions of these providers additionally apply to processing carried out by them under their own responsibility.
18. Storage Period
Personal data are stored only for as long as is necessary for the respective purpose or for as long as a statutory retention obligation exists.
In particular, the following periods and criteria apply:
Server Log Data
Log data arising on the server infrastructure are automatically overwritten or deleted as part of log rotation, at the latest after 30 days. We ourselves do not create any of our own logs going beyond this.
In the event of a security incident, the data concerned may be stored until the incident has been fully clarified and averted.
Contact Inquiries
General contact inquiries are deleted at the latest twelve months after their handling has been finally completed.
Error Reports
Personal content from error reports, log files, and screenshots is deleted at the latest twelve months after the handling has been finally completed, unless longer storage is necessary due to a contractual dispute, a dispute concerning conformity with the contract, or another legal dispute.
Order, Payment, and Tax Data
Data concerning orders, payments, accounting, and tax-relevant data are stored in accordance with the statutory retention periods.
In Poland, the basic tax limitation period is generally five years, counted from the end of the calendar year in which the payment deadline for the respective tax expired. The statutory grounds for interruption, suspension, or extension of the period remain unaffected.
Contractual Evidence and Evidence of Declarations
The stored declarations concerning the license agreement, immediate delivery, and the right of withdrawal are retained together with the contractual documentation for as long as they are necessary for statutory evidentiary obligations or for the establishment, exercise, or defense of legal claims.
License Data
The license number, license hash, license type, major version, device limit, license status, and the necessary allocation to the order are stored for the duration of the perpetual license and the operation of online license verification.
Storage may therefore be permanently necessary during the ongoing license relationship.
After the final termination of the license relationship, these data are deleted as soon as they are no longer necessary for the fulfillment of statutory obligations or for the establishment, exercise, or defense of claims.
Device Hashes
Device hashes and activation times are stored according to the criteria listed in section 12.
A device binding that has been inactive for at least 90 days is no longer counted as an occupied device seat, but is not automatically deleted from the database.
The binding is deleted upon manual release, upon deletion of all device bindings, or upon final deletion of the associated license data.
Temporary License File
The license file temporarily created for e-mail dispatch is deleted from the server immediately after sending.
After expiry of the respective periods, the data are deleted or anonymized in such a way that allocation to a specific person is no longer possible.
19. Obligation to Provide Data
The data marked as mandatory fields in the order form are necessary for the conclusion and performance of the purchase contract.
Without these data:
- the order cannot be processed,
- the payment cannot be allocated,
- the individual license file cannot be created,
- the license cannot be delivered.
The transmission of the license hash and the device hash at every program start is necessary for the online verification and use of the full version.
If the license server is temporarily unavailable, the offline mode and tolerance (grace) arrangements provided for in the license agreement and in the software apply.
Use of the contact form and the submission of an error report with a log file or screenshot are voluntary.
20. Rights of Data Subjects
Data subjects are entitled — under the conditions provided for by law — in particular to the following rights:
- the right of access pursuant to Art. 15 GDPR,
- the right to rectification pursuant to Art. 16 GDPR,
- the right to erasure pursuant to Art. 17 GDPR,
- the right to restriction of processing pursuant to Art. 18 GDPR,
- the right to data portability pursuant to Art. 20 GDPR,
- the right to object pursuant to Art. 21 GDPR (see the highlighted section 21 in this regard).
The right to erasure does not apply insofar as further processing is necessary, in particular:
- for the fulfillment of statutory obligations,
- for the performance of a license agreement that is still in force,
- for the establishment, exercise, or defense of legal claims.
Requests concerning the exercise of these rights may be directed to:
To prevent the unauthorized disclosure or deletion of data, appropriate confirmation of identity may be required.
21. Right to Object Pursuant to Art. 21 GDPR
You have the right to object at any time — on grounds relating to your particular situation — to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(f) GDPR.
If you lodge an objection, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
The objection may be lodged without any particular form at: hello@pybient.com
Processing for direct marketing purposes does not take place.
22. Right to Lodge a Complaint
Data subjects have the right to lodge a complaint with a data protection supervisory authority.
This applies in particular to the supervisory authority competent for:
- the habitual place of residence,
- the place of work,
- the place of the alleged data protection infringement.
The Polish data protection supervisory authority competent for the controller is:
Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office)
Urząd Ochrony Danych Osobowych
ul. Stanisława Moniuszki 1A
00-014 Warszawa
Poland
E-mail: kancelaria@uodo.gov.pl
23. Data Security
We apply appropriate technical and organizational measures to protect personal data.
These include in particular:
- encrypted data transmission,
- access restrictions,
- pseudonymized license and device identifiers,
- cryptographically signed license files,
- encrypted license file content,
- signed license server responses,
- server-side input validation,
- protection against automated form submissions,
- regular updating and backing up of the systems used.
Complete protection during the transmission of data over the internet or by e-mail cannot be guaranteed despite appropriate protective measures.
In particular, unencrypted e-mails may be processed in transit by the participating e-mail providers.
24. Changes to This Privacy Policy
This privacy policy is adapted when the following change:
- the services used,
- the data processing,
- the software functions,
- the legal requirements.
The current version published on the website applies in each case.