[Controller legal name, address and contact — and a DPO/contact e‑mail — to be inserted by the owner.] For personal data our business customers upload about their own contacts and employees, Butterpie acts as a processor on the customer’s instructions under a data‑processing addendum.
To provide and secure the Service (performance of a contract), to comply with legal obligations (e.g. tax/accounting record‑keeping), and for limited legitimate interests (security, fraud prevention). [Bases to be confirmed per processing activity by counsel.]
We retain personal data only as long as needed for the purposes above or as required by law. Statutory accounting records are retained for the periods Polish law requires. Data tied to a closed account is deleted or anonymized after a defined window, subject to legal holds.
We share data with sub‑processors (hosting, payment processing, e‑mail delivery) under contract, only as needed to run the Service. [A current sub‑processor list to be maintained by the owner.] We do not sell personal data.
Hosting is within the EU/EEA. Where any transfer outside the EEA occurs, it is protected by appropriate safeguards (e.g. Standard Contractual Clauses).
Subject to law you may request access, rectification, erasure, restriction, portability and objection, and may lodge a complaint with the Polish supervisory authority (UODO). The Service provides self‑serve data export and erasure request flows. Contact privacy@butterpie.io.
We apply per‑tenant isolation, encryption in transit, multi‑factor authentication, audited access and data‑minimization by design. No system is perfectly secure; we work to reduce and respond to risk.
We will post updates here and, for material changes, notify account holders.