Privacy Policy opisuje, jak platforma LeanTools zbiera, przechowuje, przetwarza i chroni dane osobowe użytkowników. This policy complies with Regulation (EU) 2016/679 (GDPR) and applicable data protection legislation.
The controller of personal data processed within the LeanTools platform is:
When creating a LeanTools account we collect the following data:
We process the following data while you use the platform:
Some data is collected automatically without direct user action:
We process your personal data solely for the following purposes:
| Purpose of Processing | Data Category | Legal Basis |
|---|---|---|
| Service provision — login, access to features | Email, hasło (hash), IP | Art. 6(1)(b) RODO — wykonanie umowy |
| Account management — password reset, data changes | Email, dane kontaktowe | Art. 6(1)(b) RODO — wykonanie umowy |
| Billing and invoicing — subscription fee collection | Email, payment data (via payment gateway) | Art. 6(1)(b) RODO — wykonanie umowy |
| Communication — change notifications, support | Email, chat messages | Art. 6(1)(a) GDPR — consent; Art. 6(1)(b) — contract performance |
| Security — protection against attacks and fraud | IP, access and activity logs | Art. 6(1)(f) GDPR — legitimate interest |
| Analytics and service improvement — usage statistics | Anonymised data, aggregate KPIs | Art. 6(1)(f) GDPR — legitimate interest |
| Legal compliance — legal and judicial obligations | All available data | Art. 6(1)(c) GDPR — legal obligation |
We do not process your data for marketing purposes without your explicit consent. Every marketing or newsletter email includes an unsubscribe link.
Processing of personal data is justified by one or more of the following legal bases listed in Art. 6 GDPR:
Data may be accessible to:
Data may be transferred to selected service providers acting as Data Processors:
We may disclose data upon request from law enforcement agencies, courts or tax authorities in accordance with Polish and EU law. We will always endeavour to notify you of such a request unless prohibited by law.
Transfers outside the EU: Some providers (Supabase, Vercel, Google) are based in the USA. Transfers are protected by Standard Contractual Clauses (SCC) or other GDPR-compliant mechanisms.
Personal data is retained only for as long as necessary to fulfil the purposes of processing. Details below:
| Data Category | Retention Period | Justification |
|---|---|---|
| Account data (email, name, phone) | For the duration of the account + 30 days after cancellation | Service provision, possibility of reinstatement |
| Password (hash) | For the duration of the account | Account security |
| Operational data (SQDP, Kamishibai, Kaizen) | For the duration of the account + 30 days after cancellation | User ownership, possibility of export |
| Access logs (IP, login time) | 90 dni | Security, anomaly detection |
| Analytics data (anonymised) | 13 miesięcy | Trend analysis, service improvement |
| Payment history / invoices | 5 years (tax law requirement) | Legal obligation, accounting |
| Session cookies | Until browser is closed | Session functionality |
| Persistent cookies | Up to 12 months / until consent is withdrawn | User preferences |
After the retention period: Data is automatically deleted or anonymised. Upon request we can accelerate deletion.
As a data subject you have the following rights:
You may request access to all personal data we hold about you. We will respond within 30 days. Data will be provided in JSON, CSV or PDF format.
If your data is inaccurate or incomplete you may request its rectification. In most cases you can do this yourself in your account settings.
You may request deletion of your data ("right to be forgotten"). Exceptions apply when:
You may request restriction of processing (e.g. suspension while a complaint is resolved) instead of deletion.
You may request a copy of your data in a structured, commonly used format (JSON, CSV) for transfer to another service. We will provide the data within 30 days.
You may object to processing of your data based on our legitimate interests (e.g. analytics, marketing). Following an objection we will assess whether our interests override yours.
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
We protect your data through:
Data is protected through:
In the event of a data security breach:
The LeanTools platform uses cookies to improve user experience. Details can be found in the Cookie Policy.
Cookie types:
You can manage cookies in your browser settings or via the cookie banner on our website.
LeanTools is intended for users aged 18 and over. We do not knowingly collect data from minors.
If you are a parent or guardian and learn that your child has provided us with their data, please contact us immediately at contact@leantools.pl. We will delete the child's data within 48 hours.
LeanTools contains links to external websites (e.g. Supabase, Vercel, Google). This policy does not apply to those sites — each has its own privacy policy. We encourage you to read them.
We are not responsible for the privacy practices of third parties.
We may update this policy to reflect changes in our practices or legal requirements. We will notify you of material changes via:
Continued use of the platform after changes constitutes acceptance of the new policy.
For questions about data privacy or GDPR requests:
If you believe we have violated your rights, you may lodge a complaint with the relevant supervisory authority. In Poland:
You may also lodge a complaint with the data protection authority in your country of residence.
© 2026 LeanTools. All rights reserved.
Privacy Policy obowiązuje od dnia publikacji na stronie LeanTools. Ostatnia aktualizacja: 1 stycznia 2026 r.