LT
LeanTools
← Back

Privacy Policy

Effective from 1 January 2026 · © 2026 LeanTools

Privacy Policy opisuje, jak platforma LeanTools zbiera, przechowuje, przetwarza i chroni dane osobowe użytkowników. This policy complies with Regulation (EU) 2016/679 (GDPR) and applicable data protection legislation.

§ 1

Data Controller

The controller of personal data processed within the LeanTools platform is:

  • Name: Piotr Mieczkowski
  • Role: Owner, Platform Operator
  • Email: contact@leantools.pl
  • Location: Gdańsk, Poland
  • Website: https://www.leantools.pl
Right of access: You may contact the Controller at any time to exercise your rights regarding your personal data (right of access, rectification, erasure, restriction of processing, data portability).
§ 2

What Data We Collect

2.1 Data Collected During Registration

When creating a LeanTools account we collect the following data:

  • Contact data: email address, phone number (optional)
  • Company data: organisation / company name, user's job title
  • Access data: password (encrypted, invisible to the Controller)
  • Location data: country, region (optional, for analytics purposes)
2.2 Data Collected During Use of the Service

We process the following data while you use the platform:

  • Operational data: information entered into SQDP, Kamishibai and Kaizen boards (KPIs, audits, improvement suggestions)
  • Access log data: login date/time, IP address, browser type, operating system
  • Activity data: actions performed in the platform (editing, deletion, data export)
  • Analytics data: time spent in the app, most-used features, browser errors
2.3 Indirectly Collected Data

Some data is collected automatically without direct user action:

  • Cookies: preference, session and settings information (details in the Cookie Policy)
  • IP address: for location identification and attack prevention
  • User-Agent: browser and device information
  • Analytics data: e.g. from Google Analytics (anonymised)
§ 3

Purposes of Data Processing

We process your personal data solely for the following purposes:

Purpose of Processing Data Category Legal Basis
Service provision — login, access to features Email, hasło (hash), IP Art. 6(1)(b) RODO — wykonanie umowy
Account management — password reset, data changes Email, dane kontaktowe Art. 6(1)(b) RODO — wykonanie umowy
Billing and invoicing — subscription fee collection Email, payment data (via payment gateway) Art. 6(1)(b) RODO — wykonanie umowy
Communication — change notifications, support Email, chat messages Art. 6(1)(a) GDPR — consent; Art. 6(1)(b) — contract performance
Security — protection against attacks and fraud IP, access and activity logs Art. 6(1)(f) GDPR — legitimate interest
Analytics and service improvement — usage statistics Anonymised data, aggregate KPIs Art. 6(1)(f) GDPR — legitimate interest
Legal compliance — legal and judicial obligations All available data Art. 6(1)(c) GDPR — legal obligation

We do not process your data for marketing purposes without your explicit consent. Every marketing or newsletter email includes an unsubscribe link.

§ 4

Legal Basis for Processing

Processing of personal data is justified by one or more of the following legal bases listed in Art. 6 GDPR:

  • Art. 6(1)(a) — Consent (e.g. newsletter, analytics cookies) — you may withdraw consent at any time
  • Art. 6(1)(b) — Contract performance (service provision, registration, payments)
  • Art. 6(1)(c) — Legal obligation (taxes, audits, court orders)
  • Art. 6(1)(f) — Legitimate interest (security, analytics, fraud prevention)
Your consent: During registration you explicitly consent to data processing. You may withdraw it at any time by contacting us at contact@leantools.pl
§ 5

Who We Share Data With

5.1 Internal Recipients

Data may be accessible to:

  • Owner / System Administrator — Piotr Mieczkowski (full access)
  • Współpracownicy — osoby zaproszące do zespołu w ramach konta (dostęp ograniczony do danych wprowadzonych w aplikacji, nie do danych osobistych)
5.2 External Providers (Third Parties)

Data may be transferred to selected service providers acting as Data Processors:

  • Supabase (cloud database) — data storage on EU/US servers
    • Headquarters: USA (Supabase)
    • Data: all user data (covered by Standard Contractual Clauses)
    • Privacy Policy Supabase
  • Vercel (app hosting) — web application delivery
  • Google Analytics — usage analytics (anonymised)
  • Payment gateway (e.g. Stripe) — payment processing
  • Email (SMTP server) — sending confirmation and password reset emails
    • Data: email address, message content
5.3 Disclosure on Legal Request

We may disclose data upon request from law enforcement agencies, courts or tax authorities in accordance with Polish and EU law. We will always endeavour to notify you of such a request unless prohibited by law.

5.4 Security of Data Transfers

Transfers outside the EU: Some providers (Supabase, Vercel, Google) are based in the USA. Transfers are protected by Standard Contractual Clauses (SCC) or other GDPR-compliant mechanisms.

§ 6

How Long We Retain Data

Personal data is retained only for as long as necessary to fulfil the purposes of processing. Details below:

Data Category Retention Period Justification
Account data (email, name, phone) For the duration of the account + 30 days after cancellation Service provision, possibility of reinstatement
Password (hash) For the duration of the account Account security
Operational data (SQDP, Kamishibai, Kaizen) For the duration of the account + 30 days after cancellation User ownership, possibility of export
Access logs (IP, login time) 90 dni Security, anomaly detection
Analytics data (anonymised) 13 miesięcy Trend analysis, service improvement
Payment history / invoices 5 years (tax law requirement) Legal obligation, accounting
Session cookies Until browser is closed Session functionality
Persistent cookies Up to 12 months / until consent is withdrawn User preferences

After the retention period: Data is automatically deleted or anonymised. Upon request we can accelerate deletion.

§ 7

Your Rights (Art. 12-22 GDPR)

As a data subject you have the following rights:

7.1 Right of Access (Art. 15 GDPR)

You may request access to all personal data we hold about you. We will respond within 30 days. Data will be provided in JSON, CSV or PDF format.

7.2 Right to Rectification (Art. 16 GDPR)

If your data is inaccurate or incomplete you may request its rectification. In most cases you can do this yourself in your account settings.

7.3 Right to Erasure (Art. 17 GDPR)

You may request deletion of your data ("right to be forgotten"). Exceptions apply when:

  • Data is still required for service provision (if the account is active)
  • Legal requirement (e.g. fiscal data for 5 years)
  • Our legitimate interests (security, fraud prevention)

7.4 Right to Restriction of Processing (Art. 18 GDPR)

You may request restriction of processing (e.g. suspension while a complaint is resolved) instead of deletion.

7.5 Right to Data Portability (Art. 20 GDPR)

You may request a copy of your data in a structured, commonly used format (JSON, CSV) for transfer to another service. We will provide the data within 30 days.

7.6 Right to Object (Art. 21 GDPR)

You may object to processing of your data based on our legitimate interests (e.g. analytics, marketing). Following an objection we will assess whether our interests override yours.

7.7 Right to Withdraw Consent (Art. 7(3) GDPR)

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

How to exercise your rights: Send all requests to contact@leantools.pl with the subject "GDPR Rights Request" or "Data Subject Request". We require identity verification (email, account screenshot, or other evidence). We respond within 30 days of identity confirmation.
§ 8

Data Security

8.1 Technical Measures

We protect your data through:

  • Transport encryption (TLS/SSL) — all HTTPS connections are encrypted (256-bit AES)
  • Password hashing — passwords are hashed with bcrypt (irreversible, even for us)
  • Database access — restricted to authorised systems (not humans)
  • Backups — regular backups (daily), stored separately
  • Monitoring — alerts for unusual activity and failed login attempts
8.2 Organisational Measures

Data is protected through:

  • Access restriction — only authorised persons may view data (principle of least privilege)
  • Confidentiality agreements — all providers are bound by confidentiality obligations
  • Password policy — we require strong passwords (min. 8 characters)
  • Security audits — we regularly check for vulnerabilities
8.3 Security Incidents

In the event of a data security breach:

  • We will notify you within 72 hours (where required by law)
  • We will describe the cause, scope and remedial steps
  • We will notify the relevant Data Protection Authority if required

Disclaimer: No security method is 100% reliable. We apply industry standards but cannot guarantee absolute protection.
§ 9

Cookie Policy

The LeanTools platform uses cookies to improve user experience. Details can be found in the Cookie Policy.

Cookie types:

  • Strictly necessary cookies — required for operation (session, security) — always active
  • Analytics cookies — usage data collection (Google Analytics) — requires consent
  • Functional cookies — remembering preferences (language, theme) — requires consent

You can manage cookies in your browser settings or via the cookie banner on our website.

§ 10

Protection of Minors' Data

LeanTools is intended for users aged 18 and over. We do not knowingly collect data from minors.

If you are a parent or guardian and learn that your child has provided us with their data, please contact us immediately at contact@leantools.pl. We will delete the child's data within 48 hours.

§ 11

Links to Third-Party Services

LeanTools contains links to external websites (e.g. Supabase, Vercel, Google). This policy does not apply to those sites — each has its own privacy policy. We encourage you to read them.

We are not responsible for the privacy practices of third parties.

§ 12

Changes to the Privacy Policy

We may update this policy to reflect changes in our practices or legal requirements. We will notify you of material changes via:

  • An email to the address associated with your account
  • An in-app notification (banner, popup)
  • Publication of a new version on this page (with effective date)

Continued use of the platform after changes constitutes acceptance of the new policy.

§ 13

Contact and Complaints

13.1 Contact Us

For questions about data privacy or GDPR requests:

  • Email: contact@leantools.pl
  • Subject: "Privacy Question" or "Data Subject Request"
  • Response time: 30 days from identity confirmation
13.2 Complaint to the Data Protection Authority

If you believe we have violated your rights, you may lodge a complaint with the relevant supervisory authority. In Poland:

  • Personal Data Protection Office (UODO)
  • ul. Stawki 2, 00-193 Warszawa
  • Tel: +48 22 531 03 00
  • https://uodo.gov.pl

You may also lodge a complaint with the data protection authority in your country of residence.

© 2026 LeanTools. All rights reserved.

Privacy Policy obowiązuje od dnia publikacji na stronie LeanTools. Ostatnia aktualizacja: 1 stycznia 2026 r.