Privacy Policy and Cookie Policy — Bastody
This Privacy Policy explains how we process personal data in connection with the Bastody Platform and our website, and how we use cookies and similar technologies. Please read it carefully.
1. Who is the controller of personal data?
The controller of your personal data is Bastody Group sp. z o.o. with its registered office at Warsaw, Długa 29, 00-238 Warsaw, Poland, registered in the Register of Entrepreneurs of the National Court Register under KRS No.: 0000978213, NIP: 5252912849, REGON: 522369422 (referred to as "we", "us", or the "Controller"). Wherever we use the terms "Application", "System", "Platform", or "Service", we mean the Bastody Platform available at https://app.bastodygroup.com.
When you use the Application as a Customer (a research firm), you may process the personal data of third parties (potentially including respondents). In that case you are the controller of such data, and we process it only as a processor — on the terms set out in a separate data processing agreement (DPA). As a Customer, you are responsible for fulfilling information obligations towards those persons and for ensuring that the processing complies with the law.
Data on respondents' behaviour in Mockups (Behavioral Metrics).
Data on how respondents behave within Mockups (e.g. interactions, clicks, scrolling) is collected only in anonymised and/or aggregated form, using our own solutions (without any third-party analytics tool for this purpose). We do not process it in a way that allows respondents to be identified. To the extent that a study would involve processing respondents' personal data, the Customer (the research firm) is the controller of that data and we act as a processor under the DPA (see section 1).
Facial Coding
Facial Coding is an optional add-on it can be enabled, on the Customer's instruction, only for Respondents within a Mockup. Where it is enabled, related consent is requested from Respondents within the Mockup served through our Platform and the camera is activated; we present that request and process the resulting facial-expression and attention data (via the provider iMotions) solely as a processor, on the Customer's behalf and on the Customer's instructions, under the DPA. The Customer is the controller and remains responsible for the legal basis — in particular Respondents' explicit consent under Article 9 GDPR — for the validity of that consent, for informing Respondents, and for obligations under the GDPR and the EU AI Act. This is not processing for which we are the controller.
2. Whom can you contact regarding the processing of personal data?
We have decided not to appoint a data protection officer, as this is not mandatory in our situation. On matters relating to data protection and privacy, you can contact us by e-mail at: legal@bastody.com, and via the live chat available in the Application.
3. For what purposes do we process personal data?
We process personal data for the following purposes:
| Purpose | Description of the purpose | Legal basis |
|---|---|---|
| Creating and operating the Account and the Team | Registering an Account requires the data set out in the form; you may provide further data when editing your Account; the system records the IP address used at registration. We process the data to perform the agreement for the Account. After the Account is deleted, the data is archived for the possible establishment, pursuit, or defence of claims. | Art. 6(1)(b) GDPR |
| Providing the Service (creating and configuring Mockups, making Behavioral Metrics available) | We process the data necessary to make the Platform available and operate it, and to deliver the ordered Mockups and Behavioral Metrics. | Art. 6(1)(b) GDPR |
| Billing, payments, and tax/accounting obligations | In connection with performing the contract, we fulfil tax and accounting obligations (issuing and storing invoices). We process, among others, name, company name, address, and tax ID. Providing the data required by tax law is necessary. | Art. 6(1)(c) GDPR in conjunction with tax law |
| Handling requests, live chat, and complaints | When you submit a request or complaint, you provide the data contained in it; the system records the IP address. We process the data to handle the request; once handled, it is archived for possible claims. | Art. 6(1)(b) and (c) GDPR |
| Contact and handling of correspondence | When you contact us (e.g. by e-mail or live chat), you provide the data contained in the correspondence; the system records the IP address. We process it to conduct communication, which is our legitimate interest. | Art. 6(1)(f) GDPR |
| Security, monitoring, and prevention of abuse | We monitor the operation and security of the Platform (including logs and IP address) to ensure security and prevent abuse, which is our legitimate interest. | Art. 6(1)(f) GDPR |
| Analytics and statistics | We carry out analytical and statistical activities; within them we have access only to Anonymous Information (aggregate statistics not attributed to specific individuals), which is our legitimate interest. | Art. 6(1)(f) GDPR |
| Own marketing | We may carry out our own marketing activities (e.g. e-mail communication about our services). We do not use external advertising systems to target ads. | Art. 6(1)(f) GDPR; where consent is required – (a) |
| Creating archives | We may create archives (physical and digital) of the data we have processed, in order to organise our data records, which is our legitimate interest. | Art. 6(1)(f) GDPR |
| Establishing, pursuing, or defending claims | Use of the Application may give rise to claims on our or your side; we process the data necessary to establish, pursue, or defend such claims, which is our legitimate interest. | Art. 6(1)(f) GDPR |
| Fulfilling data-protection obligations | As a controller, we fulfil our obligations under the GDPR (e.g. handling your requests), processing the data necessary to perform them and to demonstrate accountability. | Art. 6(1)(c) GDPR in conjunction with the GDPR, and Art. 6(1)(f) GDPR |
4. What information do we hold about you?
Within each purpose we may process a different scope of data — only what is necessary for that purpose. The data includes in particular:
- name
- e-mail address (including a billing e-mail address)
- login data
- a profile photo or team photo (if you add one)
- team name
- billing details: legal company name, address (street, city, state/province, postal/ZIP code, country), VAT/Tax ID, and a PO number (if you provide one)
- IP address and technical data (device, browser)
- content of correspondence and requests
Card payments are handled by the Payment Service Provider (Stripe). We do not store your full payment card details — they are processed directly by Stripe in accordance with its terms.
5. What is "Anonymous Information"?
We use tools and mechanisms that collect information relating to your use of the Application, in particular:
- information about your operating system and browser
- pages viewed and transitions between them
- time spent in the Application
- clicks and scrolling
- the source from which you came to the Application
We refer to this information as "Anonymous Information". In our view it does not constitute personal data, because it does not allow us to identify you and we do not combine it with personal data. Out of caution — in case it were attributed the character of personal data — we describe it here as well.
We also collect technical and diagnostic data, in particular console logs and fetch/XHR requests, for the purposes of security, error diagnosis and ensuring the proper operation of the Service, on the basis of our legitimate interest. This data may occasionally contain information capable of constituting personal data; where it does, we process it accordingly and minimize it.
6. Where do we get information about you?
In most cases you provide it to us yourself when using the Application — e.g. when creating an Account, making a payment, contacting us, or using the chat. Some information is collected automatically by the tools we use (see the Annex).
7. Is your data safe?
We take care of the security of your personal data. We have analysed the risks associated with our processing activities and implemented appropriate technical and organisational measures (including access controls, encryption in transit, backups, and infrastructure monitoring). We continuously improve our safeguards.
8. How long do we store personal data?
We process data for as long as is justified within a given purpose. Retention periods:
| Purpose | Retention period |
|---|---|
| Account and Team / providing the Service | for the duration of the Account, and thereafter until the expiry of the limitation period for claims |
| Billing, invoices, taxes | 5 years from the end of the year in which the tax obligation arose |
| Requests, chat, complaints | until handled, and thereafter until the expiry of the limitation period for claims |
| Contact and correspondence | until the communication ends, and thereafter until the expiry of the limitation period for claims |
| Security and logs | for as long as necessary for security purposes, and no longer than necessary for that purpose |
| Analytics and statistics | as Anonymous Information (aggregate data not identifying individuals) |
| Marketing | until objection or withdrawal of consent |
| Creating archives | until the archiving purpose ceases, and no longer than the expiry of the limitation period for claims |
| Establishing, pursuing, or defending claims | until the expiry of the limitation period for claims |
| Fulfilling data-protection obligations | for as long as necessary to perform the obligation and to demonstrate accountability |
9. Who are the recipients of personal data?
The external service providers (processors) involved in processing your personal data fall into the following categories:
| Processor | Purpose of the cooperation |
|---|---|
| Hosting / server infrastructure provider | Storing data and making the Application available |
| Cloud services / CDN provider | Content delivery, security, storage |
| Authentication (login) system provider | Handling user authentication and authorisation in the Application |
| Payment system provider | Handling card payments and obtaining transaction data |
| E-mail communication provider | Sending transactional messages and any marketing communication |
| Chat / support tool provider | Handling live chat and user requests |
| Monitoring / error-tracking tool provider | Monitoring errors, performance, and security of the Platform |
| Accounting firm / invoicing-accounting system provider | Accounting and issuing invoices and accounting documents |
A detailed list of the specific tools and their providers is set out in the Annex to this Policy. Data may also be disclosed to entities authorised under applicable law.
10. Do we transfer data to third countries or international organisations?
Yes, some processing operations may involve transfers of data to third countries, in particular the USA, in connection with tools whose providers or infrastructure are located outside the EEA. These providers ensure an adequate level of data protection through the mechanisms provided for in the GDPR, in particular Standard Contractual Clauses (SCCs).
Currently your personal data may be transferred to third countries in connection with the following solutions:
| Type of solution | Provider | Third country |
|---|---|---|
| Sending e-mails | Resend (Plus Five Five, Inc.) | USA (DPF/SCC) |
| CDN, security | Cloudflare, Inc. | USA (DPF/SCC) |
| Payment processing | Stripe (SPEL, Ireland / Stripe, LLC, USA) | IRL → USA (DPF/SCC) |
| Live chat / support | Chatwoot, Inc. | USA |
| Backend, database, authentication | Supabase, Inc., RackNerd LLC | USA |
| Error & performance monitoring | Functional Software, Inc. (Sentry) | USA- EU- US (DPF/SCC) |
In addition, Anonymous Information collected through the tools listed in the Annex may be transferred to third countries, in particular the USA. Details of the individual tools are set out in the Annex to this Policy.
11. Do we use profiling?
We do not take decisions about you based solely on automated processing (including profiling) that would produce legal effects concerning you or similarly significantly affect you.
12. What are your rights?
The GDPR grants you the following rights:
- the right of access to your data and to obtain a copy
- the right to rectification
- the right to erasure
- the right to restriction of processing
- the right to object to processing based on legitimate interest
- the right to data portability
- the right to withdraw consent (where processing is based on consent)
- the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (PUODO)
The rules for exercising these rights are set out in Articles 15–21 GDPR. These rights are not absolute and do not apply to all processing activities.
13. Do we use cookies or similar technologies, and how?
Yes, the Application uses cookies and similar technologies. They collect information used, among other things, to ensure the proper operation of the Application, to maintain your session after logging in, to ensure security, and to analyse the use of the Application.
14. On what basis do we use cookies or similar technologies?
We use cookies on the basis of your consent, except for cookies that are necessary for the proper provision of the service. Non-essential cookies remain blocked until you give your consent. On your first visit we display a banner allowing you to manage your consents.
15. Can you disable cookies or similar technologies?
Yes. You can manage cookie settings via the privacy mechanism in the Application and in your browser settings.
16. For what purposes do we use cookies or similar technologies?
We use cookies to: ensure the proper operation of the Application (including maintaining your session), ensure security, remember your settings (including privacy settings), and for statistical and analytical purposes. Some cookies are associated with the external tools described in the Annex.
17. What external tools do we use?
A list of external tools, together with their description, is set out in the Annex to this Policy.
18. Do we track your activities within the Application?
We may use tools that collect information about your use of the Application (e.g. for security and operational monitoring). These tools are described in the Annex.
19. Do we direct targeted advertising to you?
No. We do not direct behavioural targeted advertising to you and we do not use external advertising tools for that purpose. We may send you our own marketing communications (e.g. by e-mail) on the terms described in section 3.
20. How can you manage your privacy?
You can manage your privacy in particular through:
- the cookie management mechanism in the Application
- your web browser's privacy settings
- browser plug-ins and additional privacy-management software
- your browser's incognito mode
- exercising the rights described in section 12
You can also contact us at any time at the address indicated in section 2.
21. Is there anything else you should know?
If anything is unclear or you would like to know more about how we process your data, please write to us at: legal@bastody.com.
22. May this Privacy Policy be amended?
Yes, we may modify this Policy, in particular due to technological changes or changes in the law. If you have an Account, we will inform you of material changes by e-mail. Archived versions of the Policy will be available at the links below.
Privacy Policy effective as of 01.03.2026.
Annex — List of external tools
| Tool | Provider | Purpose | Country / transfer | Privacy policy |
|---|---|---|---|---|
| Resend | Plus Five Five, Inc. (Resend, resend.com) | sending (transactional) e-mails | USA — EU-US DPF and SCC | resend.com/legal/privacy-policy |
| Sentry | Functional Software, Inc. (Sentry, sentry.io) | error and performance monitoring of the Platform | region: Germany (EU) ; provider USA –EU- US DPF/SCC | sentry.io/privacy |
| Chatwoot | Chatwoot, Inc. (HQ: India; cloud: USA) | live chat / support | USA (cloud) | chatwoot.com/privacy-policy |
| Cloudflare | Cloudflare, Inc. (cloudflare.com) | CDN, security, content delivery | USA — EU-US DPF and SCC | cloudflare.com/privacypolicy |
| Supabase | Supabase, Inc. (USA; EU region available, AWS) | backend, database, authentication | USA | supabase.com/privacy |
| RackNerd | RackNerd LLC (USA) | backend, database, authentication | USA | racknerd.com/privacy-policy |
| Stripe | Stripe Payments Europe, Ltd. (Ireland) / Stripe, LLC (USA) | card payment processing | IRL → USA — EU-US DPF and SCC | stripe.com/privacy |
| Fornex | Fornexcloud Ltd. | hosting/server infrastructure | Cyprus (EU), data hosted in Germany (EEA) | https://fornex.com/privacy/ |
| iMotions | iMotions A/S (Copenhagen, Denmark, EU) | Facial Coding — analysis of Respondents' facial expression and attention (on the Customer's behalf); biometric data | Denmark (EU) | imotions.com/privacy-policy |
