Privacy Policy of the Portal
In force from 02.09.2026
This Privacy Policy (hereinafter: the “Privacy Policy”) sets out the principles for the processing of personal data obtained through the website: https://www.fledit.com (hereinafter: the “Portal”) and is addressed to users of the Portal (hereinafter: the “Users” or “User”).
The owner of the Portal and, at the same time, the data controller is Ekipa Management Sp. z o.o., with its registered office at: ul. Pod Sikornikiem 27A, 30-216 Kraków, KRS 0000873292 (hereinafter: the “Controller”). The Controller may be contacted by post or by email at: support@fledit.com
Personal data collected by the Controller through the Portal are processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: “GDPR”), as well as on the basis of other provisions concerning the protection of personal data, in particular the Act of 10 May 2018 on the Protection of Personal Data. The purpose of this Privacy Policy is to fulfil the information obligation arising from Article 13 GDPR.
The Controller attaches significant importance to protecting the privacy of Portal Users and to the security of the processing of their personal data.
I. PURPOSES, LEGAL BASES FOR PROCESSING, CATEGORIES OF PERSONAL DATA
1. CONSENT
The Controller processes Users’ data on the basis of consent where explicit consent is given in a form made available on the Portal.
The Controller uses tools that enable the display of personalised advertisements, such as advertisements in the Google search engine, remarketing, advertisements displayed on YouTube and on social-media platforms. Dedicated advertisements will be displayed if the phrase entered by the User in the search engine corresponds to the list of phrases set by the Controller in the campaign; and also if the Google algorithm matches the User on the basis of so-called targeting based on the websites visited by the User, videos watched by the User on YouTube, etc. The User may withdraw consent for the Controller to use the above tools, including Google Marketing Platform cookies. The User may do so on the Google Marketing Platform opt-out page or the Network Advertising Initiative opt-out page.
In connection with the provision of licences for the FLEDIT plug-in, the Controller processes the following data: the licence key and device identifiers (so-called HWIDs) assigned to the given key. These data are processed to verify the validity of the licence, ensure compliance with the device-number limit, and handle licence deactivation. Licence data do not include the User’s first and last name, email address or other direct identifiers.
The FREE version of the FLEDIT plug-in is made available in exchange for subscribing to the newsletter. Providing an email address and consenting to receive the newsletter is voluntary but necessary to obtain access to the FREE version. Subscription to the newsletter, including subscription connected with obtaining the FREE version, takes place on the basis of the User’s consent, which constitutes an independent legal basis for data processing, separate from other marketing activities based on the Controller’s legitimate interest. The User may withdraw consent to receive the newsletter at any time, which does not affect the validity of a licence previously granted for the FREE version. The newsletter is operated in two language versions (Polish and English), with separate subscriber databases. The User selects the version appropriate to the language version of the product page through which they subscribe.
When using the free and paid versions of the FLEDIT plug-in, the User may be shown messages in the plug-in interface retrieved from the Controller’s server. In particular, the messages may concern paid versions of FLEDIT, including information on their features, offers and purchasing options, as well as available plug-in updates.
2. CONCLUSION AND PERFORMANCE OF A CONTRACT
The Controller processes Users’ personal data in order to take steps at their request prior to entering into a contract with the Controller, or where this is necessary for the performance of a contract already concluded (Article 6(1)(b) GDPR).
3. LEGAL OBLIGATION
The Controller processes Users’ personal data in order to fulfil a legal obligation incumbent on the Controller (Article 6(1)(c) GDPR).
In practice, this means the need to process Users’ personal data in connection with compliance with obligations arising from legal provisions, in particular obligations arising from tax laws, the Act of 29 September 1994 on Accounting, the Act of 18 July 2002 on the Provision of Electronic Services, the Act of 23 April 1964 - Civil Code, and the Act of 30 May 2014 on Consumer Rights.
4. LEGITIMATE INTEREST OF THE CONTROLLER OR A THIRD PARTY
The Controller may process Users’ personal data where this is necessary for purposes arising from legitimate interests pursued by the Controller or by a third party (Article 6(1)(f) GDPR).
In practice, this involves the processing of data in the following cases:
- •Profiling: Based on information held about Users collected in the course of using the Portal, the Controller displays to Users on the Portal information about events, competitions and other activities organised by the Controller.
- •Marketing of products and services offered by the Controller:
The Controller sends Users marketing information concerning goods and services offered by the Controller.
The Controller does not transfer any personal data, in particular email addresses or telephone numbers, to third parties in order to enable them to undertake direct-marketing activities concerning goods and services offered by those entities.
- •Assertion of claims by the Controller and defence against claims made against the Controller:
Where a User fails to perform or improperly performs a contract concluded with the Controller, the Controller may, within the limits of applicable law, assert claims.
Where a User makes claims against the Controller, the Controller processes that User’s personal data in order to defend against such claims.
- •Organisation of competitions:
The Controller organises competitions announced on the Platform or on the Controller’s fan pages on social-media platforms. If the User takes part in a competition, the Controller may process data in order to carry it out and enable that User to participate in it.
- •Contacting the Controller: The User may contact the Controller using the contact details available on the Platform. In such case, the Controller may process the User’s personal data in order to conduct communication and consider the matter initiated by the User.
- •Retention of data to ensure accountability, i.e. to demonstrate compliance with provisions on the processing of personal data.
- •Operation of the website: The Controller uses necessary cookies for the proper operation of the Portal. The use of necessary cookies may involve the processing of the User’s personal data, based on the Controller’s legitimate interest in operating the website.
- •Affiliate programme: The Controller may process the personal data of persons participating in the FLEDIT affiliate programme (in particular, the email address connected with a Gumroad account and data necessary to settle commissions) in order to manage the affiliate programme, calculate and pay due remuneration, and prevent abuse. The legal basis for processing is the Controller’s legitimate interest in operating and developing marketing activities through a network of affiliates.
II. RECIPIENTS OF PERSONAL DATA
In connection with the processing of the User’s personal data for the purposes referred to in Part I of the Privacy Policy, the Controller may disclose the User’s data to the following recipients or categories of recipients:
- •entities providing transport services (couriers, external transport companies),
- •entities providing postal services,
- •business information bureaus,
- •entities providing services consisting in making business reports on entrepreneurs available,
- •banks with which the Controller holds a bank account, in connection with the transfer through such account of amounts to the User’s account in the event of returns of goods, complaints or overpayments,
- •entities providing the Controller with logistics, agency or distribution services, document-archiving services, financial-statement audit services, tax, financial, business and legal advisory services, IT services and marketing services,
- •entities providing payment services, entities entrusted by the Controller with debt-collection activities, and litigation attorneys representing the Controller or the above-mentioned entities,
- •entities responsible for providing cookies - detailed information on this subject can be found in the Cookie Policy,
- •entities providing IT services and operating loyalty programmes.
For the sale of the FLEDIT product, the Gumroad platform is used. Gumroad is an independent controller of purchasers’ personal data in the scope of payment processing, tax settlements, issuing receipts/invoices and providing post-sale support. Personal data processed by Gumroad are processed in accordance with its own privacy policy. The Controller does not have access to the User’s full payment data, but only to information necessary to handle licences (e.g. licence keys, number of activations).
III. PLANNED DATA RETENTION PERIOD
Personal data are retained for the period necessary to achieve the purposes indicated in Part I of this Privacy Policy.
- •In the case of data processed on the basis of consent (concerning cookies), until consent is withdrawn or the retention periods of individual cookies indicated in the Cookie Policy expire, if this occurs before consent is withdrawn.
- •In the case of data processed for the conclusion and performance of a contract, the Controller processes personal data until the expiry of the limitation period for civil-law claims arising therefrom.
- •In the case of data processed for compliance with a legal obligation, the processing period follows from legal provisions.
- •In the case of data processed to pursue the legitimate interest of the Controller or a third party, the retention period of personal data varies depending on the specific purpose of processing:
- •Where data are processed for customer relationship management, data are processed until the User lodges an objection under Article 21(1) GDPR due to the User’s particular situation, but no longer than while the User uses the Controller’s services or remains in a commercial relationship with the Controller;
- •Where data are processed for profiling, data are processed until the User lodges an objection under Article 21(2) GDPR, but no longer than while the User uses the Controller’s services or remains in a commercial relationship with the Controller.
- •Where personal data are processed for marketing products and services offered by the Controller, including sending the newsletter and making the FREE version available, the Controller processes personal data on the basis of the User’s freely given consent until it is withdrawn, in particular by withdrawing consent to receive commercial information by email or SMS, or by objecting to the processing of personal data; other marketing activities may be carried out on the basis of the Controller’s legitimate interest.
- •Where personal data are processed in order for the Controller to assert claims or defend against claims made against the Controller, the Controller processes personal data for this purpose until the asserted claim is enforced or claims become time-barred, whichever occurs first.
- •Where personal data are processed for organising competitions, the Controller processes personal data for this purpose until claims relating to the organisation of such a competition become time-barred.
- •Where personal data are processed for accountability purposes, the Controller processes personal data for as long as necessary to document fulfilment of legal requirements and enable competent public authorities to verify such fulfilment.
IV. RIGHTS OF THE DATA SUBJECT
1. RIGHT OF ACCESS TO DATA
The User has the right to access their data, including the right to obtain a copy of the data, also by electronic means.
2. RIGHT TO RECTIFICATION OF DATA
The User has the right to request the rectification of inaccurate personal data. The User has the right to request completion of incomplete personal data.
3. RIGHT TO ERASURE OF DATA
The User has the right to request that the Controller erase their personal data where:
- •the data are no longer necessary for the purposes for which they were collected or otherwise processed;
- •the User objects, on grounds relating to their particular situation, to the processing by the Controller of personal data based on the Controller’s or a third party’s legitimate interest, and there are no overriding legitimate grounds for processing;
- •the User objects to the processing of their data for direct marketing purposes;
- •the personal data have been processed unlawfully;
- •the personal data must be erased in order to comply with a legal obligation under EU or Polish law to which the Controller is subject.
However, the Controller notes that this right is subject to significant limitations.
The Controller will not be able to comply with the User’s request if further processing is necessary for:
- a)compliance by the Controller with a legal obligation requiring processing under EU or national law (e.g. where the limitation period for tax liabilities connected with the contract concluded between the Controller and the User has not yet expired, or the retention period for accounting documents issued in connection with the contract concluded between the Controller and the User has not yet expired);
- b)the establishment, exercise or defence of claims.
4. RIGHT TO RESTRICTION OF PROCESSING
The User has the right to request restriction of processing where:
- •the User contests the accuracy of personal data - for a period enabling the Controller to verify the accuracy of such data;
- •the processing is unlawful and the User opposes erasure of personal data, requesting restriction of their use instead;
- •the Controller no longer needs the personal data for processing purposes, but the User needs them for the establishment, exercise or defence of claims;
- •the User has objected, on grounds relating to their particular situation, to the processing by the Controller of personal data based on the Controller’s or a third party’s legitimate interest - pending verification whether the Controller’s legitimate grounds override the grounds of objection raised by the User.
5. RIGHT TO DATA PORTABILITY
The User has the right to receive, in a commonly used computer-readable file format, data provided by them which the Controller processes by automated means on the basis of a contract concluded with the User or on the basis of the User’s consent. The User also has the right to request that the above file be transmitted to another controller where technically feasible.
6. RIGHT TO OBJECT
The User has the right to object at any time - on grounds relating to their particular situation - to processing of personal data concerning the User based on the Controller’s or a third party’s legitimate interest, including profiling.
The Controller has the right to refuse to cease processing the User’s data if it demonstrates:
- •compelling legitimate grounds for processing that override the User’s interests, rights and freedoms;
- •grounds for the establishment, exercise or defence of claims.
The User has the right to object at any time where the Controller processes the User’s data for direct marketing purposes, including profiling.
V. COMPLAINT TO THE SUPERVISORY AUTHORITY
The User has the right to lodge a complaint with the supervisory authority, i.e. the President of the Personal Data Protection Office.
VI. VOLUNTARY PROVISION OF DATA
Providing data in forms available on the Platform is voluntary; however, refusal to provide them makes it impossible to use certain functionalities and to subscribe to the newsletter, which - including to the extent connected with making the FREE version available - is provided on the basis of prior consent, separate from other marketing activities based on the Controller’s legitimate interest. Failure to give consent makes it impossible to receive the newsletter and to use the FREE-version functionalities connected with the newsletter.
VII. SOURCES FROM WHICH DATA ARE OBTAINED
The Controller obtains the User’s personal data directly from the User.
All data entered by the User within the FLEDIT plug-in (such as notes, work-time and settlement tracker, their client data, macros and settings), as well as the audio analysed by the transcription, automatic censoring and silence removal functions (Transcribe, Auto Censor, Cut Silence), including the voices of persons recorded in it, and the captions created from it, are processed and stored solely locally on the User’s computer. The Controller has no access to such data; they are not transmitted to the Controller or Gumroad, and the plug-in contains no telemetry or User-behaviour tracking mechanisms.
VIII. COOKIES AND OTHER TRACKING TECHNOLOGIES
Detailed information on the Controller’s use of cookies can be found in the Cookie Policy.
IX. PERSONAL DATA SECURITY, FINAL PROVISIONS
- 1.The Controller applies technical and organisational measures to protect personal data against disclosure to unauthorised persons, loss or damage, appropriate to the identified risk associated with processing.
- 2.This Privacy Policy is effective as of 02.09.2026