Cookie settings

Decide per category. You can come back here at any time from the footer.

NecessaryAlways on

Signing in, your language and theme, and remembering this very choice. The site does not work without them, so there is nothing to switch off.

Google Analytics, to see which pages get used and where people give up. Off until you turn it on, and the data is never passed on to Google Ads.

Aderlo Cloud
Sign inGet started

Privacy Policy — Aderlo Cloud

Effective from 1 August 2026

In force from 1 Aug 2026.

§ 1. Data Controller

  1. The controller of Clients' personal data is: ADERLO PROSTA SPÓŁKA AKCYJNA (simple joint-stock company) ul. Nowogrodzka 50/54 lok. 515, 00-695 Warsaw, Poland KRS: 0000955282, NIP: 5492466214, REGON: 521268860 (hereinafter: the "Controller" or "Aderlo").

  2. Contact for data protection matters: support@aderlo.cloud Correspondence address: Aderlo PSA, ul. Żwirki i Wigury 25, 32-600 Oświęcim, Poland

  3. In the event of any discrepancy between language versions of this Privacy Policy, the Polish version shall prevail.


§ 2. Aderlo's Two Roles in Data Processing

  1. Aderlo as Data Controller — with respect to personal data of Aderlo Cloud platform Clients (registration data, billing data, panel logs, correspondence).

  2. Aderlo as Data Processor — with respect to personal data that Clients store in their hosting services (e.g. WooCommerce store databases, newsletter subscriber lists, customer order data). In this role, Aderlo processes data solely on the Client's instructions and on the basis of a Data Processing Agreement (DPA), which forms an annex to the Terms of Service.

  3. Clients operating online stores or other services collecting personal data on Aderlo Cloud infrastructure are required to enter into a DPA with Aderlo — this document is an integral part of the Terms and takes effect upon conclusion of the hosting service agreement.


§ 3. Purposes, Legal Bases and Retention Periods

3.1. Performance of the Hosting Service Agreement

  • Purpose: account registration, service activation, service management, technical support, communication.
  • Legal basis: Article 6(1)(b) GDPR (performance of a contract).
  • Retention: duration of the agreement + limitation period (generally 6 years).

3.2. Legal Obligations (Accounting, Tax)

  • Purpose: issuing invoices, maintaining accounting records, KSeF transmission.
  • Legal basis: Article 6(1)(c) GDPR (legal obligation).
  • Retention: 5 tax years from the end of the calendar year in which the tax payment deadline fell.

3.3. Security and Audit Logs

  • Purpose: platform security, abuse detection, audit logs (IP addresses, operations performed).
  • Legal basis: Article 6(1)(f) GDPR (legitimate interest — infrastructure security).
  • Retention: audit logs — 24 months; server logs — 12 months.

3.4. Direct Marketing and Newsletter

  • Purpose: sending commercial information, news about services and promotions.
  • Legal basis: Article 6(1)(a) GDPR (consent).
  • Retention: until consent is withdrawn.

3.5. Correspondence and Support

  • Purpose: handling enquiries, complaints and support requests.
  • Legal basis: Article 6(1)(f) GDPR (legitimate interest).
  • Retention: duration of correspondence + limitation period.

3.6. Establishment and Defence of Legal Claims

  • Purpose: establishing, pursuing or defending legal claims.
  • Legal basis: Article 6(1)(f) GDPR (legitimate interest).
  • Retention: until expiry of the limitation period (generally 6 years; 3 years for periodic claims).

3.7. Email Delivery and Engagement Measurement

  • Purpose: establishing whether a message we sent (a pro forma invoice, a service notification, support correspondence) was delivered, rejected by the recipient's server or reported as spam, and — for messages addressed to Clients — whether it was opened and whether its links were used.
  • Legal basis: Article 6(1)(b) GDPR for the delivery record itself (evidence that the Client was informed) and Article 6(1)(f) GDPR for open and click measurement (legitimate interest: sender reputation, ceasing delivery to non-existent addresses, assessing how well our communication works).
  • Data: recipient email address, event time and type (processed, delivered, bounced, dropped, deferred, spam report, unsubscribe), the recipient server's response, and — for opens and clicks — the IP address, the mail client or browser identifier (user agent) and the clicked link.
  • How it is measured: opens through a transparent image (pixel) embedded in the HTML body; clicks through a redirect on the Controller's own tracking domain. Disabling automatic image loading in your mail client prevents open measurement.
  • Retention: 90 days from sending; the events are then deleted together with the record of the message.
  • Objection: available at any time (Article 21 GDPR) — a request to support@aderlo.cloud disables open and click measurement for that address. It does not cover the delivery record itself, which is necessary to perform the agreement.
  • Exclusions: messages addressed solely to the Aderlo team (technical alerts) are not measured.

§ 4. Categories of Personal Data Processed

  1. Depending on the processing purpose, the Controller may process:

    • Identification data: first name, last name, company name,
    • Contact data: e-mail address, phone number,
    • Address data: residential / business address,
    • Billing data: tax ID, invoice data (bill_to snapshot), payment history (no card numbers — stored exclusively by Stripe),
    • Service data: DA Account names, domains, selected applications,
    • Preference data: currency, interface language,
    • Technical data: IP address, session ID, browser information (user agent),
    • Audit log data: IP addresses, timestamps, description of operations performed.
  2. Provision of personal data is voluntary but necessary for account registration and contract conclusion.


§ 5. Data Recipients (Sub-processors)

EntityRoleData Location
Hetzner Online GmbHWeb server (hosting), backup serverFalkenstein, Germany (EU)
Supabase Inc.Client panel databaseeu-west-1, Ireland (EU)
Vercel Inc.Client panel / website hostingUSA/edge — transfer outside EEA under SCC and/or DPF
Stripe Payments Europe, Ltd.Card payment processingUSA — SCC and/or DPF
MSERWIS Sp. z o.o. (domeny.tv)Domain registrationPoland (EU)

The Controller does not sell personal data to third parties.


§ 6. Transfers Outside the EEA

  1. Personal data may be transferred to the United States (Vercel, Stripe) on the basis of: a) an adequacy decision by the European Commission (Article 45 GDPR), including EU-US Data Privacy Framework, or b) Standard Contractual Clauses (SCC) adopted by the European Commission (Article 46(2)(c) GDPR).

  2. The Client has the right to obtain a copy of the safeguards applied by contacting the Controller.


§ 7. Data Retention

Data CategoryRetention Period
Invoices and accounting documents5 tax years
Audit logs (audit_log)24 months
Server logs (access/error)12 months
Account data after service termination30 days
Client correspondenceLimitation period (up to 6 years)
Marketing data (newsletter)Until consent is withdrawn
Email delivery events (including opens and clicks)90 days

§ 8. Cookies and Tracking Technologies

  1. The Client Panel (aderlo.cloud) uses session cookies (Supabase Auth), strictly necessary for maintaining the logged-in user session. These cookies do not require consent and do not serve marketing or analytical purposes.

  2. The informational site aderlo.cloud may use Google Analytics 4 (GA4) for traffic analysis. In this case, analytical cookies are set only after user consent via a cookie banner. IP anonymisation is applied.

  3. Users may manage cookies through browser settings or the consent management tool on the site.

  4. Emails addressed to Clients carry a tracking pixel measuring opens and links redirected through the Controller's own tracking domain. These are not cookies and are not subject to banner consent, because they operate outside the browser — the legal basis is legitimate interest and objection is available as described in § 3.7. Disabling automatic image loading in your mail client prevents open measurement.


§ 9. Data Subject Rights

  1. Under the GDPR, the Client has the following rights: a) Right of access (Article 15), b) Right to rectification (Article 16), c) Right to erasure (Article 17), d) Right to restriction of processing (Article 18), e) Right to data portability (Article 20), f) Right to object (Article 21), g) Right to withdraw consent (Article 7(3)), h) Right to lodge a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl.

  2. Requests should be sent to: support@aderlo.cloud. The Controller will respond within one month (extendable by two months for complex requests).


§ 10. Data Security

  1. The Controller applies appropriate technical and organisational measures, including: SSL/TLS encryption, CloudLinux CageFS account isolation, Imunify360 malware protection, ECC RAM, NVMe drives with PLP in RAID1, daily backups on a separate EU server, role-based access control, 24/7 security monitoring.

  2. Servers are located in the Hetzner Online GmbH data centre in Falkenstein, Germany (EU).


§ 11. Data Protection Officer

  1. The Controller has not appointed a Data Protection Officer, as the conditions requiring mandatory appointment under Article 37 GDPR are not met.

  2. For data protection matters, contact the Controller at: support@aderlo.cloud.


§ 12. Changes to the Privacy Policy

  1. The Controller reserves the right to amend this Privacy Policy, in particular in the event of changes to applicable law or services offered.

  2. Clients with active accounts will be notified of material changes by e-mail.

  3. This Privacy Policy is effective from 1 August 2026.


ADERLO PROSTA SPÓŁKA AKCYJNA ul. Nowogrodzka 50/54 lok. 515, 00-695 Warsaw, Poland KRS: 0000955282 · NIP: 5492466214 · REGON: 521268860