Privacy Policy
Version: 2.0 · Effective from: 2026-07-25
The Polish version is the legally binding version. This English translation is provided for convenience only.
This Privacy Policy describes how Mazura sp. z o.o. — the owner of the WebDisk brand — processes the personal data of visitors to webdisk.pl and webdisk.io and of Customers using WebDisk services.
1. Data controller
The controller of personal data is Mazura sp. z o.o., with its registered office in Ząbki, ul. Baśniowa 1C/2, 05-091 Ząbki, Poland, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under number KRS 0000971559, NIP (tax ID) 1251732787.
Contact for personal data protection matters: iod@webdisk.io General contact: office@webdisk.io, tel. +48 574 311 332 Correspondence address: ul. Baśniowa 1C/2, 05-091 Ząbki, Poland
2. Scope of this Policy
This Policy covers data for which Mazura sp. z o.o. is the controller, namely:
- data of visitors to the webdisk.pl and webdisk.io websites,
- data of persons contacting us (forms, email, telephone),
- data of Customers of WebDisk services — account data, billing data and technical operational data.
This Policy does not cover data that a Customer places within a purchased service — files, end-user accounts or content processed on the Customer's servers. For that data the Customer is the controller, and Mazura sp. z o.o. acts either as a processor or solely as a provider of a technical resource. Those rules are set out in the documents applicable to each service:
- WebDisk Next — Privacy Policy and Data Processing Agreement,
- WebDisk VM — Privacy Policy and Personal Data Processing Rules,
- other services — documents made available in the panel of the given service.
3. What data we process
3.1. Data of website visitors: IP address, device and browser information, date and time of the visit, pages visited, referral source — collected via cookies and similar technologies (section 8).
3.2. Data provided in contact: first name and surname, email address, telephone number, company name and the content of the message — to the extent provided in the form or correspondence.
3.2a. Technical data of a form submission: when a contact form is sent we also record the IP address it was sent from, information about the browser (the user-agent header) and the result of the automated abuse assessment of the submission. This data does not come from cookies and is recorded regardless of the consents given, solely in order to protect the form against automated mass submissions (chapter 4, legitimate interest). It is not used for profiling or marketing.
3.3. Data of service Customers: the email address serving as the login, first name and surname or entity name, authentication data stored in a form that makes it impossible to read the password, invoicing data together with the tax identification number, the history of payments and documents issued, and technical operational data of the service (connection IP addresses, the log of operations performed in the panel, service status and parameters).
We do not store payment card data — it is processed solely by the payment operator.
4. Purposes and legal bases of processing
| Purpose of processing | Legal basis |
|---|---|
| Providing services, managing the account and handling the contract | Article 6(1)(b) GDPR — necessity for the performance of a contract |
| Responding to enquiries and conducting correspondence | Article 6(1)(b) and (f) GDPR |
| Billing, issuing and retaining accounting documents | Article 6(1)(c) GDPR — legal obligation under accounting and tax regulations |
| Ensuring the security of services and infrastructure, counteracting abuse | Article 6(1)(f) GDPR — legitimate interest |
| Website analytics and statistics | Article 6(1)(a) GDPR — consent given via the consent management mechanism |
| Direct marketing of our own services | Article 6(1)(f) GDPR and, for electronic communications, consent |
| Establishment, exercise or defence of claims | Article 6(1)(f) GDPR |
Providing data is voluntary but necessary in order to conclude and perform the contract, to answer an enquiry and to issue accounting documents.
5. Data recipients
Data may be made available to:
- processors acting on our instruction — infrastructure suppliers, the payment operator, the email operator, analytics tool providers and entities supplying accounting, legal and technical support services,
- public authorities, where such an obligation arises from the provisions of law.
Every processor acts under a data processing agreement concluded with us and solely to the extent necessary to perform the entrusted task.
6. Transfers of data outside the European Economic Area
The infrastructure on which we provide our services is located in the territory of the Republic of Poland.
A transfer of data outside the European Economic Area may occur in connection with the use of tools from suppliers established outside the EEA — in particular analytics tools and the payment operator. Such transfers take place on the basis of standard contractual clauses approved by the European Commission or a Commission adequacy decision, constituting safeguards within the meaning of Article 46 GDPR.
7. Data retention periods
| Category of data | Retention period |
|---|---|
| Account and service data | for the duration of the contract and the grace period specified in the service documents |
| Accounting documentation | for the period required by accounting and tax regulations — as a rule 5 years from the end of the financial year |
| Correspondence and enquiries | for the time necessary to provide a response and thereafter until the limitation period for any claims expires |
| Operations logs and security logs | as a rule 12 months |
| Technical data of form submissions (IP address, browser, assessment result) | 90 days, after which it is deleted; the content of the submission itself is retained |
| Data processed on the basis of consent | until consent is withdrawn |
| Data processed for the establishment, exercise or defence of claims | until the limitation period for claims expires |
8. Cookies and analytics
The webdisk.pl and webdisk.io websites use cookies and similar technologies.
- Necessary cookies — required for the correct operation of the website, including session maintenance and security. Their use does not require consent.
- Analytics and marketing cookies — used solely after consent has been given via the consent management mechanism available on the website. Consent may be withdrawn or its scope changed at any time in the settings of that mechanism; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Detailed information about the cookies used, their providers and retention periods is contained in the Cookie Policy.
9. Rights of data subjects
You have the right to:
- access your data and obtain a copy of it (Article 15 GDPR),
- rectification of inaccurate data or completion of incomplete data (Article 16 GDPR),
- erasure of data (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- object to processing based on a legitimate interest, including to direct marketing (Article 21 GDPR),
- withdraw consent at any time where processing is based on consent.
Please address requests to iod@webdisk.io or in writing to our registered office. We respond without undue delay and no later than within one month of receiving the request.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland.
Requests concerning data placed by a Customer within a purchased service should be addressed directly to that Customer as the controller of such data (section 2).
10. Data security
We apply technical and organisational measures appropriate to the risk, referred to in Article 32 GDPR, in particular:
- encryption of connections using the TLS protocol,
- access control to the infrastructure, including administrative access solely through a dedicated jump host with cryptographic key authentication,
- separation of the production, test and development environments,
- logging of administrative operations and security monitoring of the infrastructure,
- regular security updates and periodic security testing,
- an obligation of confidentiality imposed on persons authorised to process data.
The scope of measures protecting data placed by a Customer within a purchased service — including the availability of encryption at rest — is set out in the documents applicable to that service.
11. Automated decision-making
Data is not used for automated decision-making producing legal effects or similarly significantly affecting the data subject, including profiling.
12. Amendments to this Privacy Policy
This Policy may be updated, in particular where the law, the scope of the services provided or the tools used change. The version and effective date are indicated at the beginning of the document. We announce material amendments on the website and notify Customers by email.
In the event of any discrepancy between the Polish and English versions of this Policy, the Polish version prevails.
Mazura sp. z o.o. · Privacy Policy · version 2.0 · effective from 2026-07-25