Privacy Policy and Cookie Policy — Bastody

Privacy Policy and Cookie Policy — Bastody

This Privacy Policy explains how we process personal data in connection with the Bastody Platform and our website, and how we use cookies and similar technologies. Please read it carefully.

1. Who is the controller of personal data?

The controller of your personal data is Bastody Group sp. z o.o. with its registered office at Warsaw, Długa 29, 00-238 Warsaw, Poland, registered in the Register of Entrepreneurs of the National Court Register under KRS No.: 0000978213, NIP: 5252912849, REGON: 522369422 (referred to as "we", "us", or the "Controller"). Wherever we use the terms "Application", "System", "Platform", or "Service", we mean the Bastody Platform available at https://app.bastodygroup.com.

When you use the Application as a Customer (a research firm), you may process the personal data of third parties (potentially including respondents). In that case you are the controller of such data, and we process it only as a processor — on the terms set out in a separate data processing agreement (DPA). As a Customer, you are responsible for fulfilling information obligations towards those persons and for ensuring that the processing complies with the law.

Data on respondents' behaviour in Mockups (Behavioral Metrics).

Data on how respondents behave within Mockups (e.g. interactions, clicks, scrolling) is collected only in anonymised and/or aggregated form, using our own solutions (without any third-party analytics tool for this purpose). We do not process it in a way that allows respondents to be identified. To the extent that a study would involve processing respondents' personal data, the Customer (the research firm) is the controller of that data and we act as a processor under the DPA (see section 1).

Facial Coding

Facial Coding is an optional add-on it can be enabled, on the Customer's instruction, only for Respondents within a Mockup. Where it is enabled, related consent is requested from Respondents within the Mockup served through our Platform and the camera is activated; we present that request and process the resulting facial-expression and attention data (via the provider iMotions) solely as a processor, on the Customer's behalf and on the Customer's instructions, under the DPA. The Customer is the controller and remains responsible for the legal basis — in particular Respondents' explicit consent under Article 9 GDPR — for the validity of that consent, for informing Respondents, and for obligations under the GDPR and the EU AI Act. This is not processing for which we are the controller.

2. Whom can you contact regarding the processing of personal data?

We have decided not to appoint a data protection officer, as this is not mandatory in our situation. On matters relating to data protection and privacy, you can contact us by e-mail at: legal@bastody.com, and via the live chat available in the Application.

3. For what purposes do we process personal data?

We process personal data for the following purposes:

PurposeDescription of the purposeLegal basis
Creating and operating the Account and the TeamRegistering an Account requires the data set out in the form; you may provide further data when editing your Account; the system records the IP address used at registration. We process the data to perform the agreement for the Account. After the Account is deleted, the data is archived for the possible establishment, pursuit, or defence of claims.Art. 6(1)(b) GDPR
Providing the Service (creating and configuring Mockups, making Behavioral Metrics available)We process the data necessary to make the Platform available and operate it, and to deliver the ordered Mockups and Behavioral Metrics.Art. 6(1)(b) GDPR
Billing, payments, and tax/accounting obligationsIn connection with performing the contract, we fulfil tax and accounting obligations (issuing and storing invoices). We process, among others, name, company name, address, and tax ID. Providing the data required by tax law is necessary.Art. 6(1)(c) GDPR in conjunction with tax law
Handling requests, live chat, and complaintsWhen you submit a request or complaint, you provide the data contained in it; the system records the IP address. We process the data to handle the request; once handled, it is archived for possible claims.Art. 6(1)(b) and (c) GDPR
Contact and handling of correspondenceWhen you contact us (e.g. by e-mail or live chat), you provide the data contained in the correspondence; the system records the IP address. We process it to conduct communication, which is our legitimate interest.Art. 6(1)(f) GDPR
Security, monitoring, and prevention of abuseWe monitor the operation and security of the Platform (including logs and IP address) to ensure security and prevent abuse, which is our legitimate interest.Art. 6(1)(f) GDPR
Analytics and statisticsWe carry out analytical and statistical activities; within them we have access only to Anonymous Information (aggregate statistics not attributed to specific individuals), which is our legitimate interest.Art. 6(1)(f) GDPR
Own marketingWe may carry out our own marketing activities (e.g. e-mail communication about our services). We do not use external advertising systems to target ads.Art. 6(1)(f) GDPR; where consent is required – (a)
Creating archivesWe may create archives (physical and digital) of the data we have processed, in order to organise our data records, which is our legitimate interest.Art. 6(1)(f) GDPR
Establishing, pursuing, or defending claimsUse of the Application may give rise to claims on our or your side; we process the data necessary to establish, pursue, or defend such claims, which is our legitimate interest.Art. 6(1)(f) GDPR
Fulfilling data-protection obligationsAs a controller, we fulfil our obligations under the GDPR (e.g. handling your requests), processing the data necessary to perform them and to demonstrate accountability.Art. 6(1)(c) GDPR in conjunction with the GDPR, and Art. 6(1)(f) GDPR

4. What information do we hold about you?

Within each purpose we may process a different scope of data — only what is necessary for that purpose. The data includes in particular:

  • name
  • e-mail address (including a billing e-mail address)
  • login data
  • a profile photo or team photo (if you add one)
  • team name
  • billing details: legal company name, address (street, city, state/province, postal/ZIP code, country), VAT/Tax ID, and a PO number (if you provide one)
  • IP address and technical data (device, browser)
  • content of correspondence and requests

Card payments are handled by the Payment Service Provider (Stripe). We do not store your full payment card details — they are processed directly by Stripe in accordance with its terms.

5. What is "Anonymous Information"?

We use tools and mechanisms that collect information relating to your use of the Application, in particular:

  • information about your operating system and browser
  • pages viewed and transitions between them
  • time spent in the Application
  • clicks and scrolling
  • the source from which you came to the Application

We refer to this information as "Anonymous Information". In our view it does not constitute personal data, because it does not allow us to identify you and we do not combine it with personal data. Out of caution — in case it were attributed the character of personal data — we describe it here as well.

We also collect technical and diagnostic data, in particular console logs and fetch/XHR requests, for the purposes of security, error diagnosis and ensuring the proper operation of the Service, on the basis of our legitimate interest. This data may occasionally contain information capable of constituting personal data; where it does, we process it accordingly and minimize it.

6. Where do we get information about you?

In most cases you provide it to us yourself when using the Application — e.g. when creating an Account, making a payment, contacting us, or using the chat. Some information is collected automatically by the tools we use (see the Annex).

7. Is your data safe?

We take care of the security of your personal data. We have analysed the risks associated with our processing activities and implemented appropriate technical and organisational measures (including access controls, encryption in transit, backups, and infrastructure monitoring). We continuously improve our safeguards.

8. How long do we store personal data?

We process data for as long as is justified within a given purpose. Retention periods:

PurposeRetention period
Account and Team / providing the Servicefor the duration of the Account, and thereafter until the expiry of the limitation period for claims
Billing, invoices, taxes5 years from the end of the year in which the tax obligation arose
Requests, chat, complaintsuntil handled, and thereafter until the expiry of the limitation period for claims
Contact and correspondenceuntil the communication ends, and thereafter until the expiry of the limitation period for claims
Security and logsfor as long as necessary for security purposes, and no longer than necessary for that purpose
Analytics and statisticsas Anonymous Information (aggregate data not identifying individuals)
Marketinguntil objection or withdrawal of consent
Creating archivesuntil the archiving purpose ceases, and no longer than the expiry of the limitation period for claims
Establishing, pursuing, or defending claimsuntil the expiry of the limitation period for claims
Fulfilling data-protection obligationsfor as long as necessary to perform the obligation and to demonstrate accountability

9. Who are the recipients of personal data?

The external service providers (processors) involved in processing your personal data fall into the following categories:

ProcessorPurpose of the cooperation
Hosting / server infrastructure providerStoring data and making the Application available
Cloud services / CDN providerContent delivery, security, storage
Authentication (login) system providerHandling user authentication and authorisation in the Application
Payment system providerHandling card payments and obtaining transaction data
E-mail communication providerSending transactional messages and any marketing communication
Chat / support tool providerHandling live chat and user requests
Monitoring / error-tracking tool providerMonitoring errors, performance, and security of the Platform
Accounting firm / invoicing-accounting system providerAccounting and issuing invoices and accounting documents

A detailed list of the specific tools and their providers is set out in the Annex to this Policy. Data may also be disclosed to entities authorised under applicable law.

10. Do we transfer data to third countries or international organisations?

Yes, some processing operations may involve transfers of data to third countries, in particular the USA, in connection with tools whose providers or infrastructure are located outside the EEA. These providers ensure an adequate level of data protection through the mechanisms provided for in the GDPR, in particular Standard Contractual Clauses (SCCs).

Currently your personal data may be transferred to third countries in connection with the following solutions:

Type of solutionProviderThird country
Sending e-mailsResend (Plus Five Five, Inc.)USA (DPF/SCC)
CDN, securityCloudflare, Inc.USA (DPF/SCC)
Payment processingStripe (SPEL, Ireland / Stripe, LLC, USA)IRL → USA (DPF/SCC)
Live chat / supportChatwoot, Inc.USA
Backend, database, authenticationSupabase, Inc., RackNerd LLCUSA
Error & performance monitoringFunctional Software, Inc. (Sentry)USA- EU- US (DPF/SCC)

In addition, Anonymous Information collected through the tools listed in the Annex may be transferred to third countries, in particular the USA. Details of the individual tools are set out in the Annex to this Policy.

11. Do we use profiling?

We do not take decisions about you based solely on automated processing (including profiling) that would produce legal effects concerning you or similarly significantly affect you.

12. What are your rights?

The GDPR grants you the following rights:

  • the right of access to your data and to obtain a copy
  • the right to rectification
  • the right to erasure
  • the right to restriction of processing
  • the right to object to processing based on legitimate interest
  • the right to data portability
  • the right to withdraw consent (where processing is based on consent)
  • the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (PUODO)

The rules for exercising these rights are set out in Articles 15–21 GDPR. These rights are not absolute and do not apply to all processing activities.

13. Do we use cookies or similar technologies, and how?

Yes, the Application uses cookies and similar technologies. They collect information used, among other things, to ensure the proper operation of the Application, to maintain your session after logging in, to ensure security, and to analyse the use of the Application.

14. On what basis do we use cookies or similar technologies?

We use cookies on the basis of your consent, except for cookies that are necessary for the proper provision of the service. Non-essential cookies remain blocked until you give your consent. On your first visit we display a banner allowing you to manage your consents.

15. Can you disable cookies or similar technologies?

Yes. You can manage cookie settings via the privacy mechanism in the Application and in your browser settings.

16. For what purposes do we use cookies or similar technologies?

We use cookies to: ensure the proper operation of the Application (including maintaining your session), ensure security, remember your settings (including privacy settings), and for statistical and analytical purposes. Some cookies are associated with the external tools described in the Annex.

17. What external tools do we use?

A list of external tools, together with their description, is set out in the Annex to this Policy.

18. Do we track your activities within the Application?

We may use tools that collect information about your use of the Application (e.g. for security and operational monitoring). These tools are described in the Annex.

19. Do we direct targeted advertising to you?

No. We do not direct behavioural targeted advertising to you and we do not use external advertising tools for that purpose. We may send you our own marketing communications (e.g. by e-mail) on the terms described in section 3.

20. How can you manage your privacy?

You can manage your privacy in particular through:

  • the cookie management mechanism in the Application
  • your web browser's privacy settings
  • browser plug-ins and additional privacy-management software
  • your browser's incognito mode
  • exercising the rights described in section 12

You can also contact us at any time at the address indicated in section 2.

21. Is there anything else you should know?

If anything is unclear or you would like to know more about how we process your data, please write to us at: legal@bastody.com.

22. May this Privacy Policy be amended?

Yes, we may modify this Policy, in particular due to technological changes or changes in the law. If you have an Account, we will inform you of material changes by e-mail. Archived versions of the Policy will be available at the links below.

Privacy Policy effective as of 01.03.2026.

Annex — List of external tools

ToolProviderPurposeCountry / transferPrivacy policy
ResendPlus Five Five, Inc. (Resend, resend.com)sending (transactional) e-mailsUSA — EU-US DPF and SCCresend.com/legal/privacy-policy
SentryFunctional Software, Inc. (Sentry, sentry.io)error and performance monitoring of the Platformregion: Germany (EU) ; provider USA –EU- US DPF/SCCsentry.io/privacy
ChatwootChatwoot, Inc. (HQ: India; cloud: USA)live chat / supportUSA (cloud)chatwoot.com/privacy-policy
CloudflareCloudflare, Inc. (cloudflare.com)CDN, security, content deliveryUSA — EU-US DPF and SCCcloudflare.com/privacypolicy
SupabaseSupabase, Inc. (USA; EU region available, AWS)backend, database, authenticationUSAsupabase.com/privacy
RackNerdRackNerd LLC (USA)backend, database, authenticationUSAracknerd.com/privacy-policy
StripeStripe Payments Europe, Ltd. (Ireland) / Stripe, LLC (USA)card payment processingIRL → USA — EU-US DPF and SCCstripe.com/privacy
FornexFornexcloud Ltd.hosting/server infrastructureCyprus (EU), data hosted in Germany (EEA)https://fornex.com/privacy/
iMotionsiMotions A/S (Copenhagen, Denmark, EU)Facial Coding — analysis of Respondents' facial expression and attention (on the Customer's behalf); biometric dataDenmark (EU)imotions.com/privacy-policy
contact form

Reach out — we’re always here

Got a question or looking for more details?Feel free to reach out by filling out the form below — we’re here to help.

By clicking the button, you consent to the processing of your personal data and agree to the Privacy Policy