Privacy Policy
Version 1.0 · Effective from 1 January 2026
The Polish version of this document is legally binding.
1. Data controller
The controller of your personal data is Damian Walicki, trading as Damian Walicki Consulting, based in Rzeszów (Zbyszewskiego 9 lok. 42, 35-119 Rzeszów), registered in CEIDG (Polish business register), NIP (tax ID) 8133428095, REGON 388123012 (the “Controller”). For matters relating to the protection of personal data, you can contact us at: privacy@qerify.com — for all other matters: support@qerify.com
2. What data we collect
- Account data: email address, password (stored as a hash), user role.
- Freelancer profile data: first name and surname, photo, bio, skills, tools, hourly rates.
- Freelancer identity document (KYC verification): we keep the scan of the document in private file storage only until the administrator makes a decision — once it is approved or rejected, the file is deleted and only the verification result is kept.
- Transaction data: information about contracts, work stages (milestones) and payments (processed through Stripe).
- Communication data: messages exchanged within contracts.
- Technical data: IP address, browser type, session cookies.
- AI data: the content of conversations with the AI Concierge (deleted after 90 days).
3. Purposes and legal basis of processing
| Purpose | Legal basis |
|---|---|
| User account management and authentication | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(f) GDPR (legitimate interests of the controller) |
| Vetting and assessment of freelancers’ skills | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(f) GDPR (legitimate interests of the controller) |
| Identity verification and eligibility for payouts (KYC) | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(c) GDPR (compliance with a legal obligation to which the controller is subject) |
| Project matching and AI advice (AI Concierge, matching) | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(f) GDPR (legitimate interests of the controller); Article 6(1)(a) GDPR (consent of the data subject) |
| Handling of contracts, milestones and escrow deposits | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(f) GDPR (legitimate interests of the controller) |
| Settlements, invoices and tax obligations (KSeF, JPK) | Article 6(1)(c) GDPR (compliance with a legal obligation to which the controller is subject); Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract) |
| Automation Marketplace — orders, subscriptions and featured listings | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(f) GDPR (legitimate interests of the controller) |
| Job Board — job postings and bids | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(f) GDPR (legitimate interests of the controller) |
| Reviews and reputation (Outcome Score) | Article 6(1)(f) GDPR (legitimate interests of the controller); Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract) |
| Disputes and mediation | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(f) GDPR (legitimate interests of the controller) |
| Electronic signatures and document audit trail | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(c) GDPR (compliance with a legal obligation to which the controller is subject) |
| Transactional communications and notifications | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(f) GDPR (legitimate interests of the controller); Article 6(1)(a) GDPR (consent of the data subject) |
| Referral programme and promo codes | Article 6(1)(b) GDPR (performance of a contract or steps taken prior to entering into a contract); Article 6(1)(f) GDPR (legitimate interests of the controller) |
| Cookie-free product analytics | Article 6(1)(f) GDPR (legitimate interests of the controller); Article 6(1)(a) GDPR (consent of the data subject) |
| Content moderation, security and administrative logs | Article 6(1)(f) GDPR (legitimate interests of the controller); Article 6(1)(c) GDPR (compliance with a legal obligation to which the controller is subject) |
| Handling of data subject requests and accountability for consents | Article 6(1)(c) GDPR (compliance with a legal obligation to which the controller is subject) |
4. Data recipients
Your data may be disclosed to the following entities:
- Supabase Inc. — database hosting and authentication service (European Union (EU region)).
- Vercel Inc. — application hosting (United States).
- MXRoute LLC — sending transactional email (United States).
- OpenAI, L.L.C. — natural language processing and generation of vector representations (United States).
- Anthropic, PBC — natural language processing (alternative model provider) (United States).
- Stripe, Inc. / Stripe Payments Europe Ltd. — processing of payments, payouts and identity verification (KYC) (Ireland and the United States).
- Cloudflare, Inc. — protection against automated traffic (bot protection) (United States).
- Hostinger International Ltd. — hosting of the server running the controller’s CRM system (Twenty, self-hosted instance) — handling of sales enquiries left in conversations with the AI Concierge (Germany (according to the RIPE address registry for the server)).
- Polish National Revenue Administration (KSeF, JPK) — recipient of tax records under statutory provisions (Poland).
- The operator’s accounting firm — accounting and tax services (Poland).
- PostHog, Inc. — product analytics (United States).
- Functional Software, Inc. (Sentry) — application error monitoring (United States).
Data is transferred outside the EEA only on the basis of appropriate safeguards (standard contractual clauses approved by the European Commission).
5. Data retention periods
The periods below are enforced automatically by a daily system job. When a period expires, the data is either permanently deleted or irreversibly anonymised — once properly anonymised, a record is no longer personal data and may be kept as statistical or evidential material (e.g. the mere fact and outcome of a dispute, without the parties’ data).
| Data category | Period | After expiry |
|---|---|---|
| Invoices and accounting records — 5 years from the end of the calendar year in which the tax payment deadline fell (in practice about 6 years from issue). We do not delete them even at the data subject’s request (Article 17(3)(b) and (e) GDPR); once the period expires, the parties’ data is anonymised. | 6 years (until the end of the calendar year) | anonymisation |
| Completed and cancelled contracts — 3 years from closure, with the period ending on the last day of the calendar year. The subject matter and amount are kept; the parties’ data is removed. | 3 years (until the end of the calendar year) | anonymisation |
| Milestones of completed contracts — 3 years from settlement. The amount and status are kept; the description, which may contain personal data, is removed. | 3 years (until the end of the calendar year) | anonymisation |
| Resolved disputes — 3 years from resolution. The fact of the dispute, its subject matter, outcome and amount are kept; the parties’ data and the content of the reasoning are removed. | 3 years (until the end of the calendar year) | anonymisation |
| Orders in the Automation Marketplace — 3 years from confirmation, and for orders cancelled or refunded before confirmation — from the last change. The amounts, commission and seller are kept (needed for financial reporting); the buyer’s data and the delivery content are removed. | 3 years (until the end of the calendar year) | anonymisation |
| Product reviews — 3 years. The rating and content are kept (they underpin the catalogue’s credibility); the link to the author is removed. | 3 years (until the end of the calendar year) | anonymisation |
| Project reviews feeding the Outcome Score — 3 years. The rating assigned to the reviewed provider is kept (it still counts towards their Outcome Score); the review’s author and content are removed. | 3 years (until the end of the calendar year) | anonymisation |
| Audit trail of electronic signatures — 6 years, i.e. as long as the document it evidences. The hash chain is kept (breaking it would invalidate the evidence); the signatory’s data is removed. | 6 years (until the end of the calendar year) | anonymisation |
| NDAs — 6 years from conclusion. The fact and date of conclusion are kept; the parties’ data is removed. | 6 years (until the end of the calendar year) | anonymisation |
| Logs of administrative actions — 3 years. The type of action and its date are kept (they demonstrate accountability); the administrator’s identity and the content of the metadata are removed. | 3 years | anonymisation |
| Records of consents given and withdrawn — 3 years from the action. The fact of consent, its version and date are kept; the IP address and user agent, which served only as corroboration, are removed. | 3 years | anonymisation |
| Register of data subject requests (access, erasure) — 3 years. It demonstrates that a request was fulfilled and when; after the period expires, the link to the person is removed. | 3 years | anonymisation |
| Closed and settled job postings — 3 years. The content of the posting is kept; the poster is removed. | 3 years (until the end of the calendar year) | anonymisation |
| Bids submitted in response to job postings — 3 years. The bidder and the content of the bid are removed. | 3 years (until the end of the calendar year) | anonymisation |
| Accounts with no sign-in for 3 years (for an account nobody has ever signed in to — from its creation), with no active contracts, disputes or payouts in progress — anonymised after a prior warning sent by email 30 days before the deadline; signing in during that time cancels the anonymisation. Platform administrator accounts are not subject to this rule. The law does not set a period here, so we have set it ourselves and justify it by its purpose: after this time the account no longer serves the provision of the service. | 3 years | anonymisation |
| Conversations with the AI Concierge, together with messages and matching results — 90 days. This period reflects the commitment made in the Privacy Policy; extending it would require amending the policy and informing users. | 90 days | deletion |
| Contact details left in a conversation with the AI Concierge (email address, optionally a phone number, company name and NIP tax number) — 12 months from when the contact was left. The period is longer than the 90 days for the conversation itself because the transcript and the contact serve different purposes: the conversation is a record of the content of the enquiry, while the contact is the basis for responding to it and for matching a provider. A sales enquiry that has not turned into a contract within a year no longer serves the purpose for which the data was collected. The row is deleted in full because there is no accounting obligation requiring it to be kept longer in anonymised form. | 1 year | deletion |
| Messages in closed contracts — 3 years from sending, and only once the contract is no longer active. Until then they constitute evidence in any dispute. | 3 years (until the end of the calendar year) | deletion |
| In-app notifications — 12 months. They have no evidential or accounting value. | 1 year | deletion |
| Saved searches and alerts — 24 months from last activity. | 2 years | deletion |
| Push notification subscriptions — 12 months of inactivity. | 1 year | deletion |
| Records of system announcements being viewed — 24 months. Purely operational data. | 2 years | deletion |
| History of promo code use — 24 months. | 2 years | deletion |
| Log of scheduled job runs (system health centre) — 3 months. Purely operational data with no evidential value after that time. | 90 days | deletion |
| Resolved technical incidents (system health centre) — 12 months from resolution. The incident resolution date is NULL for open/acknowledged incidents, so they never qualify — we delete only closed cases. | 1 year | deletion |
Raw page-view data in our own analytics is deleted after 90 days; only aggregated statistics that cannot be used to identify you are kept. We do not delete invoices or accounting records even at your request — Article 17(3)(b) and (e) GDPR excludes the right to erasure where the data is necessary for compliance with a legal obligation and for the establishment, exercise or defence of legal claims.
6. Your rights
Under the GDPR, you have the following rights:
- Right of access to your data (Article 15 GDPR)
- Right to rectification of your data (Article 16 GDPR)
- Right to erasure of your data (the “right to be forgotten”, Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to object (Article 21 GDPR)
- Right to lodge a complaint with the UODO, the Polish data protection authority (www.uodo.gov.pl)
7. Cookies
The Platform uses strictly necessary cookies to handle user sessions (Supabase authentication) and one functional cookie that remembers the selected interface language (qerify_locale) — it stores only the language code, with no identifier of any person. We do not use advertising cookies or third-party tracking cookies. In addition, we measure aggregate site traffic with Vercel Web Analytics — a service that does not store cookies or any identifiers that would allow a specific user to be identified, and only collects aggregated visit statistics.
8. Security
We apply appropriate technical and organisational measures: TLS encryption, password hashing (bcrypt), Row-Level Security in the database, least-privilege access and regular audits.
9. Automated decision-making (Article 22 GDPR)
The Platform uses a matching algorithm that automatically selects up to 3 suggested Freelancers, Agencies or Ready Teams for the project you describe.
How the algorithm works:
- Your project description is converted into a mathematical representation (a vector embedding).
- The system compares it with the profiles of registered specialists using cosine similarity.
- It takes into account declared skills, tools used, industry, budget and availability.
- The result is a list of candidates — not a hiring decision. The final choice is yours.
Your rights: You can opt out of automated matching at any time and ask our team to review candidates manually — write to privacy@qerify.com. You also have the right to obtain an explanation of why the algorithm suggested particular candidates.
Privacy questions: privacy@qerify.com