Privacy Policy
How we handle personal data when you visit the HeroSwipe Website, contact us, register interest in our services, or send us a privacy or account-deletion request.
This is an information notice, not a request for consent. Reading it, accepting our Terms or submitting an ordinary enquiry does not mean that you consent to marketing or optional tracking.
This Policy applies to the public-facing HeroSwipe landing pages, product-information pages and related legal and contact pages that display or link to it (the “Website”). It covers visitors, prospective business customers, prospective testers, people contacting us on behalf of an organisation, and people using the Website-related request channels described below.
It covers browsing, enquiries, demonstration requests, early-access or launch-interest registrations, waiting lists, optional email updates, and handling privacy, withdrawal and account-deletion correspondence.
The Website is not the whole HeroSwipe platform. Participation in tests, detailed tester profiles, points and rewards, business workspaces, product uploads, Content Generator and marketplace integrations require service-specific privacy information. Except for the account-closure process explained in section 9, this Policy is not a complete notice for those operations. That information must be provided before the relevant data is collected or operational access begins.
A Website waiting-list registration records your interest; it does not itself authorise creating a detailed tester profile or using your data for unrelated product research. Where a separate service notice applies, it explains that service’s purposes, recipients, retention and data-protection roles.
The controller for the processing described in this Policy is:
You can use either email address to exercise data-protection rights. We will route your message appropriately. You do not need an account, a particular subject line or a special form to contact us.
Contact and registration information: your name and email address; your company, role, telephone number, preferred language, country or service of interest where you provide them or the relevant form asks for them; and the content of your enquiry and subsequent correspondence. We collect only the fields used by the particular feature, not every category listed here on every visit.
Choices and request records: your subscription and consent choices, the date and method of giving or withdrawing consent, the wording or notice version presented, and verification and request-status records needed to administer your request.
Deletion and privacy requests: the email or account identifier needed to locate the relevant records, your instructions, necessary ownership-verification information, and the dates of deactivation, cancellation and deletion. We do not ask for your password or authentication codes.
The systems that deliver and protect the Website process technical information such as your IP address, request date and time, requested page, browser and device information, response or error information, and referring-page information where your browser sends it. Cookie identifiers, stored preferences and optional usage measurements are processed only where the relevant technology is used, as explained in section 10 and the information supplied with the relevant consent choice.
We obtain most information directly from you or your browser. Our service providers also supply delivery, security and request-status information needed for the relevant service. If a colleague or employer introduces you as a business contact, we may receive your name, business email, role and the context of the introduction. We use these details to handle that business communication, not to treat the introduction as your marketing consent.
When we obtain personal data about you indirectly, we provide the relevant information, including its source, within the applicable GDPR timeframe: normally by our first communication, before a first disclosure, or within one month, whichever occurs first, unless a specific legal exception applies.
Please do not send sensitive personal data, identity-document copies, payment-card information or unrelated information about other people through an ordinary Website enquiry. Detailed tester questionnaires and product datasets do not belong in these forms.
The General Data Protection Regulation (EU) 2016/679 (“GDPR”) requires a legal basis for each use of personal data. The bases below apply to the identified purpose; they are not interchangeable permissions to use all information for any purpose.
Technical request data and security logs help us serve pages, diagnose faults, prevent abuse and investigate incidents.
Legal basis: Article 6(1)(f), our legitimate interests in a reliable and secure Website and protecting users and systems. Optional audience measurement is separate and is not included in this basis.
We use contact details, the request and related correspondence to answer you and take the steps you ask us to take.
Legal basis: Article 6(1)(b) where necessary for a requested service or pre-contractual steps with you personally. For general correspondence and contact with an organisation’s representative, Article 6(1)(f): our legitimate interest in responding to requests and managing business communications.
We record your request, verify your email where required, and send the invitation or launch notification you specifically requested. We may use the service, country or language you selected to route that request.
Legal basis: Article 6(1)(b) for the free waiting-list service requested by you. Where you act for an organisation, Article 6(1)(f), our legitimate interest in handling its request. A request for one notification is not consent to an ongoing marketing newsletter.
We use your email address, optional name and chosen subscription preferences to send the product news, early-access promotions or offers to which you subscribed.
Legal basis: Article 6(1)(a), your consent, together with the prior communication consent required by Article 398 of the Polish Electronic Communications Law where applicable.
Where optional Website analytics or campaign measurement is offered, we identify the tool, provider, data and purpose before asking for your consent. We use the specified browsing and interaction data for that purpose only after you consent. Advertising, if introduced, has its own clearly described purpose and choice.
Legal basis: Article 6(1)(a), consent, and the applicable consent rules for storing or accessing information on your device. The Website service is not conditional on accepting these optional uses.
We identify the records concerned, verify a request where necessary, act on your instructions, and record the outcome.
Legal basis: Article 6(1)(c) for GDPR obligations, including Articles 12–22. Necessary administration of a requested service or account closure may rely on Article 6(1)(b); preventing impersonation relies on Article 6(1)(f), our legitimate interest in protecting the account holder. Section 9 explains the limited recovery period.
We keep the minimum evidence needed to demonstrate consent and the handling of rights, honour opt-outs, comply with binding legal obligations, and establish, exercise or defend claims.
Legal basis: Article 6(1)(c) for obligations including GDPR accountability and consent requirements under Articles 5(2), 7(1) and 24, and Article 6(1)(f) for necessary claim-related records and preventing unwanted contact. The legitimate interests are demonstrating lawful conduct and resolving disputes, not retaining every record indefinitely.
Where we rely on legitimate interests, we assess whether the processing is necessary and whether your interests, rights or freedoms override those interests. You may object as explained in section 11. We do not silently switch to another basis to continue the same optional marketing or tracking after you withdraw consent.
You may browse the public Website without creating an account. Technical processing needed to deliver the requested page still occurs. Fields marked as required in a form are needed for the stated request; for example, without a working email address we cannot send an email response or launch invitation. Other fields are optional unless their necessity is explained.
Marketing consent is optional and separate from requesting early access, submitting an enquiry and accepting the Website Terms. You may unsubscribe through the link in a marketing email or by contacting us. Unsubscribing does not prevent service messages needed to handle an outstanding request, but we do not use that exception to send unrelated promotions.
Withdrawing consent affects future consent-based processing, not the lawfulness of processing before withdrawal. It does not require deleting your account or waiting through the account-recovery period.
Access is limited to people and organisations who need the information for the identified purpose. Depending on the feature used, the relevant recipients are:
Providers acting as processors handle data under appropriate data-processing agreements and our instructions. A provider acting as an independent controller is responsible for its own specified processing; the information provided for that service identifies its role.
Website enquiries and waiting-list contact details are not supplied to business customers as research results or as marketing-contact lists. A disclosure specifically requested by you, such as introducing you to a named business contact, is handled for that request.
HeroSwipe is established in Poland. A provider’s location, subprocessors or remote support access can involve processing outside the European Economic Area (“EEA”), even when a server is located within the EEA.
Where an international transfer takes place, we use an applicable GDPR Chapter V mechanism: an adequacy decision under Article 45 covering the recipient and transfer, or appropriate safeguards under Article 46, such as applicable European Commission standard contractual clauses, with the required assessment and supplementary measures where necessary. A provider’s foreign location or a contract alone is not a substitute for those checks.
You may ask [email protected] for information about the safeguards used for your data and a copy of the relevant safeguards, subject to proportionate redaction of confidential information. Simply using the Website is not consent to an international transfer.
We keep personal data only for the relevant purpose, then delete it or make it irreversibly anonymous. A separate, documented legal obligation or need to preserve specific evidence may justify retaining limited records for longer, not keeping an entire account active.
| Records | Period or determining criteria |
|---|---|
| Enquiries and demonstration correspondence | While we handle the request and any agreed follow-up, then up to 12 months after closure for continuity if you return to the same enquiry. We remove information sooner where it is no longer needed or a valid erasure request requires it. Necessary dispute evidence is separated as described below. |
| Early-access and waiting-list records | Until you leave the list, we send the requested invitation or notification, or the relevant programme ends, whichever occurs first. We then remove the active list entry without undue delay. If you separately join the service, its notice governs the records needed for that service. |
| Marketing subscription information | Until you withdraw consent or the subscription service ends. Minimal opt-out and compliance records are kept separately; they are not an active marketing subscription. |
| Routine Website access and security logs | Up to 30 days from the event. Only entries relevant to an identified incident, obligation or dispute may be isolated and kept longer for that specific purpose. |
| Account awaiting permanent deletion | 7 days (168 hours) from deactivation, unless you cancel in time or an applicable erasure right requires earlier action. Section 9 explains the process and limited post-deletion records. |
| Consent, opt-out, rights-request and dispute evidence | Only the records needed to demonstrate compliance, enforce an opt-out or address a claim. An opt-out entry is kept while needed to prevent re-import into an active mailing list. Other evidence is limited to the applicable legal retention or claim-limitation period; an active proceeding may require relevant evidence until final resolution and any necessary enforcement. We review continued necessity and do not use these records for marketing. |
| Optional cookies and associated measurement data | The device-storage lifetime and server-side data-retention period specified for the relevant tool in the information provided before your consent choice, as explained in section 10. A cookie’s expiry date is not necessarily the same as the provider’s data-retention period. |
| Backup copies | Deleted data may remain in restricted disaster-recovery copies until overwritten or securely expired, for no more than 90 days after live-system deletion, unless specific evidence must be isolated under a separate lawful retention ground. Backups are not an account-recovery service after permanent deletion. |
Where a backup must be restored, we reapply the relevant deletion and suppression instructions before the restored data is returned to normal use. We require processors handling the relevant data to apply the deletion instructions to their systems and any authorised subprocessors.
Records relating to actual tester rewards, payments, invoices or business-platform transactions have service-specific legal retention requirements. If those records remain after account deletion, they must be limited to what the relevant obligation or outstanding claim requires and explained in the applicable service notice. They are not retained merely because this Website Policy exists.
You may request deletion of an operational HeroSwipe account through the account-deletion option in the app or by emailing [email protected], preferably from the email associated with your account. You do not need to give a reason. If you no longer have access to that email, contact the same address for proportionate verification.
After receiving the request and completing any necessary verification, we deactivate the account and confirm by email the exact permanent-deletion date and time, including the time zone. The recovery period lasts 7 days (168 hours) from deactivation. Normal account use is suspended. During this period, retained account information is used to implement your request and permit its cancellation, not to continue normal testing or profiling activity.
You may cancel the deletion request by emailing the same address before that deadline and clearly asking to keep your account. A valid cancellation received in time stops deletion even if our acknowledgement is sent later. Cancelling deletion does not renew marketing consent that you have separately withdrawn.
If you do not cancel, the account is permanently deleted and cannot be reactivated. Associated personal data is erased or irreversibly anonymised, except for specific records that must or may lawfully be retained, for example for tax or accounting obligations, unresolved payments or rewards, fraud-related evidence or legal claims. Such exceptions must be necessary and proportionate; retained records have restricted access and are not used to rebuild your account. Section 8 explains backups and retention criteria.
Your GDPR rights are separate. The 7-day recovery period does not postpone withdrawal of marketing consent, cancellation of a Website service, or a statutory right to erasure. You may request erasure without waiting for that period to expire. Where the legal conditions are met, we act without undue delay; earlier erasure may make account recovery impossible. Account deletion does not waive an existing payment, refund or reward claim.
Full procedural instructions are available on the Account Deletion page. Uninstalling the app or signing out does not itself delete the account.
Cookies, local or session storage, pixels and similar technologies may store information on your device or access information already stored there. Some uses also involve personal data. Server-side logs are addressed separately above.
Strictly necessary technologies are limited to what is needed to transmit a communication or provide a service you expressly request, such as a genuinely necessary security or preference function. They are not used as a label for optional advertising or analytics. Where personal data is involved, the appropriate basis is the one identified for the relevant service, security or compliance purpose in section 4.
Optional technologies, including consent-based audience measurement, campaign tracking and non-essential third-party embeds, are not activated until the relevant informed consent has been obtained. Before an optional technology is enabled, we provide its identifier, provider, purpose, data categories, device-storage lifetime, server-side retention period and information about relevant recipients and international transfers alongside the consent choice. Closing a banner, scrolling, continuing to browse or accepting the Terms is not consent.
Where optional technologies are offered, the Website’s consent controls allow you to reject them, choose by purpose and later withdraw consent as easily as it was given. Optional choices start off. You can browse and send an ordinary enquiry without accepting them. Withdrawing a cookie choice stops future consent-based use; erasure of previously collected personal data is assessed under the GDPR.
Browser settings can also let you delete or block cookies. This may affect features that genuinely depend on necessary storage. Those settings do not replace our obligation to obtain consent when required. Email open-tracking or individually tracked marketing links, if introduced, must be separately identified and used only with the applicable consent; a newsletter subscription is not blanket permission for hidden tracking.
The relevant Polish rules include Article 399 of the Electronic Communications Law. Providing this notice does not itself set or change a cookie preference.
Subject to the conditions in the GDPR, you may ask us to:
Confirm whether we process your data and provide the data and the required information about its use.
Rectify inaccurate information and complete incomplete information.
Delete data where a legal ground for erasure applies, or restrict processing in the circumstances set out in the GDPR. Erasure is not absolute where a specific legal obligation or other applicable exception requires retention.
Where processing is automated and based on your consent or a contract with you, provide eligible data you supplied in a structured, commonly used, machine-readable format and, where technically feasible, transmit it to another controller.
Stop the relevant consent-based processing without requiring a reason or account deletion. Earlier lawful processing remains lawful.
Right to object. You may object at any time to processing based on legitimate interests for reasons relating to your particular situation. We must stop unless we demonstrate compelling legitimate grounds overriding your interests, rights and freedoms, or the processing is needed for legal claims.
For direct marketing, your objection is unconditional. We stop using your data for that marketing, including related profiling. You do not need to explain your situation.
Email [email protected] or [email protected], or write to our postal address. Describe the request and provide a way to identify the relevant record and respond. If we have reasonable doubts about your identity, we ask only for additional information necessary to resolve those doubts. Do not send passwords, authentication codes or unsolicited identity-document copies.
We respond without undue delay and normally within one month after receiving your request. Where necessary because of complexity or the number of requests, the GDPR permits up to two additional months; we inform you within the first month and explain the reasons. This is not an automatic waiting period for erasure or an extension of the 7-day deletion process.
Requests are normally free. Any refusal or reasonable fee for a manifestly unfounded or excessive request must meet GDPR conditions and be explained. If we cannot grant a request fully, we explain why, what data remains and the relevant basis, and your complaint and judicial-remedy options. Where required, we inform recipients of rectification, erasure or restriction.
Contact us about your data | Account-deletion instructions
An email link opens your email application; you must send the message to submit a request.
You may complain to a competent data-protection supervisory authority, particularly in the EEA country of your habitual residence, workplace or the alleged infringement. You do not have to contact us first, and this Policy does not restrict your right to seek a judicial remedy.
In Poland, the authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland. Contact information and complaint guidance are available on the official UODO website.
For the Website enquiry and waiting-list activities covered here, we do not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you within Article 22 GDPR. Routine technical filtering or routing a request according to your chosen service or language is not intended to make such a decision. You can contact us if a technical measure prevents your request from reaching us.
This statement does not describe the tester application. Study matching, demographic or behavioural profiles, quality checks, reward decisions and aggregate research reports must be explained in its own notice, including any relevant automated-decision safeguards. Data linked to an account or a pseudonymous identifier is not treated as anonymous merely because a business customer cannot see the tester’s name.
This Policy does not authorise repurposing Website enquiries or waiting-list records to train general-purpose AI models. Any proposed new use requires an appropriate legal basis and information before that use begins. Actual Content Generator inputs, outputs, marketplace data, AI-provider access and any training use must be addressed in the relevant product notice before those features collect personal data.
We apply technical and organisational measures appropriate to the risks, including restricting access to authorised personnel, secure handling of requests, HTTPS for Website communications and controlled retention and deletion. We assess service providers and protect retained records and backups. No online system can be guaranteed completely risk-free; that does not remove our GDPR security obligations.
A normal link to an app store, marketplace or social network takes you to a service with its own privacy information. Embedded content can have different effects and is addressed in section 10. A link does not authorise a third party to collect additional information from this Website without the applicable legal conditions, or remove our responsibility for a disclosure we initiate.
Our Website enquiry, demonstration and early-access sign-up features are intended for people aged 18 or over, as stated in the Website Terms. This is a service-eligibility choice, not a statement that the GDPR always sets the age of consent at 18. We do not seek children’s profiles through these features. If you believe a child has provided information, contact us so that we can assess and address it appropriately. Eligibility and safeguards for any separate application must be explained before registration.
We may update this Policy to reflect actual changes in processing or applicable requirements. We show the effective date and version above and provide suitable notice of material changes, including direct notice where appropriate. Before using personal data for a new purpose, we provide the required information and obtain new consent where that is the appropriate legal basis. Continued browsing is not consent to a new purpose.
We initially focus on EU markets. Availability of the Website worldwide does not mean every HeroSwipe service is available in every country. Applicable mandatory local rights are not excluded. Expansion of the applications or their audiences may require additional service-specific or country-specific notices and safeguards; this Website Policy does not claim universal compliance for future services.
HEROSWIPE sp. z o.o. · KRS 0001184316ul. Ignacego Mościckiego 1, 24-110 Puławy, Poland.
Website Terms of Use | Account Deletion | Privacy contact