Necessary cookies keep you signed in and remember your settings. We would also like to measure how the site is used — but only if you agree. More in the privacy policy.

Cookie settings

Decide per category. You can come back here at any time from the footer.

NecessaryAlways on

Signing in, your language and theme, and remembering this very choice. The site does not work without them, so there is nothing to switch off.

Google Analytics, to see which pages get used and where people give up. Off until you turn it on, and the data is never passed on to Google Ads.

Aderlo Cloud
Sign inGet started

Privacy Policy — Aderlo Cloud

Effective from 1 August 2026

In force from 1 Aug 2026.

§ 1. Data Controller

  1. The controller of Clients' personal data is: ADERLO PROSTA SPÓŁKA AKCYJNA (simple joint-stock company) ul. Nowogrodzka 50/54 lok. 515, 00-695 Warsaw, Poland KRS: 0000955282, NIP: 5492466214, REGON: 521268860 (hereinafter: the "Controller" or "Aderlo").

  2. Contact for data protection matters: contact@aderlo.com Correspondence address: Aderlo PSA, ul. Żwirki i Wigury 25, 32-600 Oświęcim, Poland

  3. In the event of any discrepancy between language versions of this Privacy Policy, the Polish version shall prevail.


§ 2. Aderlo's Two Roles in Data Processing

  1. Aderlo as Data Controller — with respect to personal data of Aderlo Cloud platform Clients (registration data, billing data, panel logs, correspondence).

  2. Aderlo as Data Processor — with respect to personal data that Clients store in their hosting services (e.g. WooCommerce store databases, newsletter subscriber lists, customer order data). In this role, Aderlo processes data solely on the Client's instructions and on the basis of a Data Processing Agreement (DPA), which forms an annex to the Terms of Service.

  3. Clients operating online stores or other services collecting personal data on Aderlo Cloud infrastructure are required to enter into a DPA with Aderlo — this document is an integral part of the Terms and takes effect upon conclusion of the hosting service agreement.


§ 3. Purposes, Legal Bases and Retention Periods

3.1. Performance of the Hosting Service Agreement

  • Purpose: account registration, service activation, service management, technical support, communication.
  • Legal basis: Article 6(1)(b) GDPR (performance of a contract).
  • Retention: duration of the agreement + limitation period (generally 6 years).

3.2. Legal Obligations (Accounting, Tax)

  • Purpose: issuing invoices, maintaining accounting records, KSeF transmission.
  • Legal basis: Article 6(1)(c) GDPR (legal obligation).
  • Retention: 5 tax years from the end of the calendar year in which the tax payment deadline fell.

3.3. Security and Audit Logs

  • Purpose: platform security, abuse detection, audit logs (IP addresses, operations performed).
  • Legal basis: Article 6(1)(f) GDPR (legitimate interest — infrastructure security).
  • Retention: audit logs — 24 months; server logs — 12 months.

3.4. Direct Marketing and Newsletter

  • Purpose: sending commercial information, news about services and promotions.
  • Legal basis: Article 6(1)(a) GDPR (consent).
  • Retention: until consent is withdrawn.

3.5. Correspondence and Support

  • Purpose: handling enquiries, complaints and support requests.
  • Legal basis: Article 6(1)(f) GDPR (legitimate interest).
  • Retention: duration of correspondence + limitation period.

3.6. Establishment and Defence of Legal Claims

  • Purpose: establishing, pursuing or defending legal claims.
  • Legal basis: Article 6(1)(f) GDPR (legitimate interest).
  • Retention: until expiry of the limitation period (generally 6 years; 3 years for periodic claims).

§ 4. Categories of Personal Data Processed

  1. Depending on the processing purpose, the Controller may process:

    • Identification data: first name, last name, company name,
    • Contact data: e-mail address, phone number,
    • Address data: residential / business address,
    • Billing data: tax ID, invoice data (bill_to snapshot), payment history (no card numbers — stored exclusively by Stripe),
    • Service data: DA Account names, domains, selected applications,
    • Preference data: currency, interface language,
    • Technical data: IP address, session ID, browser information (user agent),
    • Audit log data: IP addresses, timestamps, description of operations performed.
  2. Provision of personal data is voluntary but necessary for account registration and contract conclusion.


§ 5. Data Recipients (Sub-processors)

EntityRoleData Location
Hetzner Online GmbHWeb server (hosting), backup serverFalkenstein, Germany (EU)
Supabase Inc.Client panel databaseeu-west-1, Ireland (EU)
Vercel Inc.Client panel / website hostingUSA/edge — transfer outside EEA under SCC and/or DPF
Stripe Payments Europe, Ltd.Card payment processingUSA — SCC and/or DPF
MSERWIS Sp. z o.o. (domeny.tv)Domain registrationPoland (EU)

The Controller does not sell personal data to third parties.


§ 6. Transfers Outside the EEA

  1. Personal data may be transferred to the United States (Vercel, Stripe) on the basis of: a) an adequacy decision by the European Commission (Article 45 GDPR), including EU-US Data Privacy Framework, or b) Standard Contractual Clauses (SCC) adopted by the European Commission (Article 46(2)(c) GDPR).

  2. The Client has the right to obtain a copy of the safeguards applied by contacting the Controller.


§ 7. Data Retention

Data CategoryRetention Period
Invoices and accounting documents5 tax years
Audit logs (audit_log)24 months
Server logs (access/error)12 months
Account data after service termination30 days
Client correspondenceLimitation period (up to 6 years)
Marketing data (newsletter)Until consent is withdrawn

§ 8. Cookies and Tracking Technologies

  1. The Client Panel (aderlo.cloud) uses session cookies (Supabase Auth), strictly necessary for maintaining the logged-in user session. These cookies do not require consent and do not serve marketing or analytical purposes.

  2. The informational site aderlo.cloud may use Google Analytics 4 (GA4) for traffic analysis. In this case, analytical cookies are set only after user consent via a cookie banner. IP anonymisation is applied.

  3. Users may manage cookies through browser settings or the consent management tool on the site.


§ 9. Data Subject Rights

  1. Under the GDPR, the Client has the following rights: a) Right of access (Article 15), b) Right to rectification (Article 16), c) Right to erasure (Article 17), d) Right to restriction of processing (Article 18), e) Right to data portability (Article 20), f) Right to object (Article 21), g) Right to withdraw consent (Article 7(3)), h) Right to lodge a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl.

  2. Requests should be sent to: contact@aderlo.com. The Controller will respond within one month (extendable by two months for complex requests).


§ 10. Data Security

  1. The Controller applies appropriate technical and organisational measures, including: SSL/TLS encryption, CloudLinux CageFS account isolation, Imunify360 malware protection, ECC RAM, NVMe drives with PLP in RAID1, daily backups on a separate EU server, role-based access control, 24/7 security monitoring.

  2. Servers are located in the Hetzner Online GmbH data centre in Falkenstein, Germany (EU).


§ 11. Data Protection Officer

  1. The Controller has not appointed a Data Protection Officer, as the conditions requiring mandatory appointment under Article 37 GDPR are not met.

  2. For data protection matters, contact the Controller at: contact@aderlo.com.


§ 12. Changes to the Privacy Policy

  1. The Controller reserves the right to amend this Privacy Policy, in particular in the event of changes to applicable law or services offered.

  2. Clients with active accounts will be notified of material changes by e-mail.

  3. This Privacy Policy is effective from 1 August 2026.


ADERLO PROSTA SPÓŁKA AKCYJNA ul. Nowogrodzka 50/54 lok. 515, 00-695 Warsaw, Poland KRS: 0000955282 · NIP: 5492466214 · REGON: 521268860