Elevate Privacy Policy
Version: 2
Effective date: 17 June 2026
Replaces: version 1 (earlier drafts)
This Privacy Policy describes how personal data is processed in connection with the use of the Elevate platform — a multi-tenant service desk / helpdesk system that includes, among others: ticketing, a knowledge base, SLA tracking, reporting, and an optional AI assistant, available at elevate.dynaminds.pl (with subdomains assigned to individual clients).
This document constitutes the information notice required under Article 13 and Article 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the "GDPR").
1. Identity and contact details of the controller
The controller of personal data, with respect to the scope described in section 3 (Account data and billing data), is:
Dynaminds — a brand operated by B2B.net S.A., established in Poland.
- Address: Aleje Jerozolimskie 180, 02-486 Warsaw, Poland
- NIP (tax ID): 5711707392
- KRS (company register no.): 0000387063
- Email (general matters): [email protected]
- Email (data protection): [email protected]
This company is referred to below as "Dynaminds", "we", or the "Controller".
1a. Data-protection contact (DPO / contact point)
For all matters concerning the processing of personal data and the exercise of rights under the GDPR, you may contact us at: [email protected] or in writing at the Controller's registered address, marked "Data protection".
Dynaminds has not appointed a Data Protection Officer (DPO) within the meaning of Article 37 GDPR, as the conditions for mandatory appointment set out in that provision are not met. The role of the data-protection contact point is served by the address [email protected]. If Dynaminds formally appoints a DPO in the future, their contact details will be set out in this Policy and made available through the same contact channel.
2. Two roles of Dynaminds: controller and processor (KEY DISTINCTION)
Within the Elevate platform, Dynaminds acts in two different roles, depending on the category of data:
| Data category | Role of Dynaminds | Basis of the relationship |
|---|---|---|
| Account data and billing data (email, name, organization membership, invoicing data, technical data) | Controller (independently determines purposes and means) | this Privacy Policy |
| Data entered into the optional AI assistant within the scope of Account data (e.g., a user's administrative queries about their own account) | Controller (to the extent that the AI feature forms part of the service provided by Dynaminds to the Account user) | this Privacy Policy |
| Data contained in the content of tickets — titles, descriptions, comments, attachments, which MAY contain personal data of end users and staff of the client organization — including their processing by the AI feature (e.g., semantic search, knowledge base) | Processor — processes on behalf of and on the documented instructions of the client | Data Processing Agreement (DPA) concluded with the client organization |
For data contained in tickets, the client organization is the controller (the business entity using Elevate), and Dynaminds acts solely as a processor under a separate Data Processing Agreement (DPA), accepted electronically in the platform during onboarding by a person authorized to represent the client (Article 28(9) GDPR).
With respect to ticket data:
- the processing rules (purposes, legal bases, retention, data subject rights) are determined by the client-controller in its own information notice;
- requests from data subjects (e.g., access, erasure) are, as a rule, handled by the client-controller; if such a request is sent directly to Dynaminds, we will forward it to the relevant client-controller and assist them in accordance with the DPA;
- the details (scope of the processing, sub-processors, transfers, security measures, return/erasure of data upon termination) are governed by the DPA — see the cross-reference in section 13.
The remaining sections of this Policy concern primarily situations in which Dynaminds is the controller (Account and billing data), unless expressly stated otherwise.
3. Categories of data processed
As a controller, we process the following categories of data:
a) Account data:
- email address,
- first and last name,
- organization (tenant) membership and role within the organization.
b) Billing data (for paid purchases):
- NIP / tax ID (collected at payment / during checkout),
- VAT invoicing data (name, address of the entity),
- subscription history, balances, and credit transactions,
- payment-related data handled by Stripe (Dynaminds does not store full payment card data).
c) Technical and security data:
- IP address (processed in transit, e.g., for connection security),
- browser information and diagnostic / crash/error reports.
d) Data contained in the content of tickets (processor role — see section 2):
- titles, descriptions, comments, and attachments added to tickets, which may contain personal data of end users or staff of the client organization. In this respect Dynaminds is a processor, and the controller is the client organization.
4. Purposes of processing and legal bases (per purpose)
Below we set out the purposes of processing together with their corresponding legal bases under Article 6 GDPR. This concerns data for which Dynaminds is the controller (Account, billing, and technical data).
| No. | Purpose of processing | Data categories | Legal basis |
|---|---|---|---|
| 1 | Creating and maintaining the Account, providing the Elevate service (platform access, ticketing, knowledge base, SLA, reporting), handling subscriptions and credits | Account data, billing data | Art. 6(1)(b) GDPR — performance of a contract (the Terms) to which the user / organization is a party, and steps prior to entering into a contract |
| 2 | Payment processing, invoicing, tax settlements (including VAT) | billing data, NIP, invoicing data | Art. 6(1)(c) GDPR — compliance with a legal obligation (accounting and tax law, including the Accounting Act, the VAT Act, and the Tax Ordinance) |
| 3 | Ensuring platform security, prevention of abuse and fraud (anti-fraud), ensuring integrity and continuity of operation, establishing or defending legal claims | technical data (IP, diagnostic data), logs, Account data | Art. 6(1)(f) GDPR — the legitimate interest of the Controller in protecting IT systems, preventing abuse, and securing claims |
| 4 | Service communication and handling requests/inquiries addressed to us (including the exercise of GDPR rights) | Account data, contact data | Art. 6(1)(b) GDPR (within the scope of the contract) and Art. 6(1)(c) GDPR (with respect to fulfilling GDPR obligations) |
| 5 | Making the optional AI assistant available as a platform feature — only with respect to Account data (e.g., a user's administrative queries about their own account), if the feature is enabled | Account data entered into the AI feature | Art. 6(1)(b) GDPR — performance of the contract for the Elevate service, of which the AI feature forms a part |
| 6 | Marketing activities and non-essential cookies (if used at all) | Account data, contact data | Art. 6(1)(a) GDPR — consent (voluntary, withdrawable at any time) |
The processing of ticket content by the AI assistant (e.g., semantic search, generating answers from the knowledge base) is not carried out on the basis of Article 6 GDPR by Dynaminds as a controller. In this respect Dynaminds acts as a processor, and the basis for the processing is the documented instruction of the client-controller arising from the Data Processing Agreement (DPA) (Article 28 GDPR). The purposes and legal bases of this processing are determined by the client-controller — see section 2 and section 13.
The platform currently uses only essential cookies and does not engage in tracking-based marketing (see section 11).
5. Recipients of data and processors (sub-processors)
Data may be disclosed to the following categories of recipients:
- providers of IT, hosting, database, email, monitoring, and payment services acting as processors under appropriate data processing agreements (DPAs);
- public authorities entitled under the law, where they submit a request based on a legal ground.
We use the following sub-processors (each acting under its own data processing agreement / DPA). In the table below we indicate the role in which Dynaminds uses each sub-processor:
- Processor — the sub-processor touches ticket content (which may contain personal data of the client's end users and staff); Dynaminds uses it in its processor role on behalf of the client-controller under the DPA;
- Controller — the sub-processor touches only Account / billing / technical data for which Dynaminds is the controller.
| Sub-processor | Function | Role of Dynaminds (data category) | Processing location |
|---|---|---|---|
| Supabase | database (stores Account data and ticket content) | Processor (ticket content) and Controller (Account data) | EU (Frankfurt) |
| Microsoft (Azure / Microsoft 365) | email (sending via Microsoft Graph; notifications may contain ticket content) | Processor (ticket content) and Controller (Account data) | EU (European tenant) |
| Stripe | payments, tax (Stripe Tax) | Controller (billing data) | EU + US |
| Hetzner | hosting / servers (infrastructure for the entire platform) | Processor (ticket content) and Controller (Account data) | EU (Nuremberg) |
| Cloudflare | CDN / WAF (security, content delivery network, technical data in transit) | Processor (traffic containing ticket content) and Controller (technical data) | global edge network |
| Sentry | error monitoring (diagnostic / technical data) | Controller (technical data) | EU (Frankfurt) |
| Anthropic | AI assistant — processes queries sent to the AI, including ticket content (only when the AI feature is enabled) | Processor (ticket content) and Controller (Account data entered into the AI) | US |
| Voyage AI | vector embeddings for semantic search and the knowledge base — processes ticket content (only when the AI feature is enabled) | Processor (ticket content) | US |
The current, versioned list of sub-processors is available at /legal/subprocessors. We notify of material changes to the sub-processor list (e.g., the addition of a new one) in accordance with the DPA.
6. Transfers of data to third countries
Some sub-processors process data outside the European Economic Area (EEA), in particular in the United States (Stripe, and — when the AI feature is enabled — Anthropic and Voyage AI). Cloudflare may process data within a global edge network.
In each such case, the transfer takes place on the basis of appropriate mechanisms provided for in Chapter V of the GDPR. The primary basis — where a given provider holds an active certification — is a European Commission adequacy decision (Art. 45 GDPR) under the EU–U.S. Data Privacy Framework (EU-U.S. DPF):
- Stripe, Microsoft, Cloudflare, Sentry, Anthropic, and Voyage AI are certified under the EU-U.S. DPF; transfers concerning them take place primarily on the basis of an adequacy decision (Art. 45 GDPR) (in accordance with the current List of sub-processors available at
/legal/subprocessors).
As a supplementary mechanism — in particular in the event that a provider's DPF certification is suspended, withdrawn, or does not cover a specific processing operation — we apply:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Art. 46(2)(c) GDPR), together with supplementary technical and organizational measures.
The current transfer basis for each provider is set out in the List of sub-processors (/legal/subprocessors). A copy of, or information about, the safeguards applied may be obtained by contacting [email protected].
7. Data retention periods
We retain data no longer than is necessary to achieve the purposes for which it was collected, taking into account legal obligations and limitation periods for claims:
| Data category | Retention period |
|---|---|
| Account data | for the duration of the Account being active (term of the contract), and after its termination — until the expiry of the limitation periods for claims related to the contract (as a rule up to 3 years for claims related to the conduct of business activity, and where the law provides a longer period for certain claims — correspondingly longer), in accordance with purpose No. 3 (establishing or defending legal claims, Art. 6(1)(f) GDPR); after those periods expire, the data is deleted or anonymized |
| Active tickets | for the duration of the Account being active |
| Closed tickets | archived after 1 year, then anonymized after 3 years |
| Event log / audit (audit log) | 2 years |
| Backups | up to 30 days |
| Events / errors in Sentry | 90 days |
| Billing data and invoices | for the period required by accounting and tax law (as a rule 5 years counted from the end of the year in which the tax obligation arose) |
For ticket data (processor role), the retention period also results from the client-controller's instructions and the DPA; upon termination of the services, the data is returned or deleted in accordance with the DPA.
8. Rights of data subjects
To the extent that Dynaminds is the controller, you have the following rights:
- right of access (Art. 15 GDPR) — to obtain information about the processing and a copy of the data;
- right to rectification (Art. 16 GDPR) — to correct inaccurate data or complete incomplete data;
- right to erasure ("right to be forgotten", Art. 17 GDPR) — subject to exceptions; with respect to tickets, data may be anonymized rather than deleted, in order to preserve the integrity of other persons' data and compliance with legal obligations;
- right to restriction of processing (Art. 18 GDPR);
- right to data portability (Art. 20 GDPR) — to receive data in a structured, commonly used, machine-readable format (e.g., JSON), where the processing is based on consent or a contract and is carried out by automated means;
- right to object (Art. 21 GDPR) — to processing based on legitimate interest (Art. 6(1)(f) GDPR), on grounds relating to your particular situation;
- right to withdraw consent at any time (Art. 7(3) GDPR) — to the extent that processing is based on consent (Art. 6(1)(a) GDPR); withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
Requests concerning the exercise of rights may be submitted to [email protected]. We respond without undue delay, within one month at the latest of receiving the request (with the possibility of an extension by two further months in the case of complex requests — with notification of the reasons).
If a request concerns data contained in tickets (where the client organization is the controller), we will forward it to the relevant client-controller or ask you to address it directly to them.
9. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a supervisory authority, which in Poland is:
President of the Personal Data Protection Office (PUODO)
ul. Stanisława Moniuszki 1A, 00-014 Warsaw
tel. (22) 531 03 00
https://uodo.gov.pl
A complaint may be lodged if you consider that the processing of your personal data infringes the GDPR.
10. Information on whether the provision of data is a requirement
- Providing Account data (email, name) is a contractual requirement — it is necessary to create an Account and use the Elevate platform. Failure to provide this data makes it impossible to provide the service.
- Providing billing data (including NIP and invoicing data) is a statutory and contractual requirement when making paid purchases — it is necessary to issue an invoice and fulfill tax obligations. Failure to provide this data makes it impossible to carry out a paid sale.
- Providing data for marketing / non-essential cookies is entirely voluntary and based on consent.
11. Cookies
The Elevate platform uses only essential cookies, serving to maintain the authentication (login) session. They are necessary for the proper functioning of the service and do not require consent.
We do not use cookies for tracking, analytics, or advertising. Should any non-essential cookies be introduced in the future, their use will be preceded by obtaining separate, voluntary consent (opt-in).
12. Automated decision-making and profiling
Dynaminds does not take, with respect to data subjects, decisions based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect them, within the meaning of Article 22 GDPR.
The optional AI assistant (if enabled) supports the handling of tickets, but is not used to automatically make binding decisions concerning natural persons.
13. Source of data (where data does not originate from the data subject) — Article 14 GDPR
With respect to data contained in tickets, Dynaminds may process personal data of natural persons (e.g., end users or staff of the client organization) that was not provided directly by those persons, but originates from the client organization, which is the controller of that data. In this respect Dynaminds acts as a processor, and the full information obligation toward those persons rests, as a rule, with the client-controller. Nonetheless, in the interest of transparency, in accordance with Article 14 GDPR we provide information on the following elements:
- Identity and contact details of the processor and of the data-protection contact point: as in sections 1 and 1a (Dynaminds / B2B.net S.A., [email protected]). The controller of this data remains the client organization (Art. 14(1)(a) GDPR).
- Source of the data (Art. 14(2)(f) GDPR): the client organization (the controller), which enters the data into the platform as part of creating and handling tickets; the data does not originate from publicly accessible sources.
- Categories of data (Art. 14(1)(d) GDPR): identification and contact data and any information contained in the content of tickets (titles, descriptions, comments, attachments).
- Purposes of processing and legal basis (Art. 14(1)(c) GDPR): the data is processed solely for the purpose of providing the service desk / helpdesk service to the client-controller — i.e., enabling the creation, handling, archiving, and searching of tickets, and, once the AI feature is enabled, also assisting in their handling (e.g., semantic search, knowledge base). The basis for processing by Dynaminds is Article 28 GDPR (processing on the documented instructions of the controller) under the Data Processing Agreement (DPA); the relevant purposes and legal bases vis-à-vis data subjects within the meaning of Article 6 GDPR are determined by the client-controller in its own information notice.
- Recipients or categories of recipients (Art. 14(1)(e) GDPR): the data may be disclosed to the sub-processors listed in section 5 that touch ticket content — in particular Supabase (database), Hetzner (hosting), Microsoft (email), Cloudflare (CDN/WAF), and, once the AI feature is enabled, also Anthropic and Voyage AI — each acting as a sub-processor under its own DPA, as well as to public authorities entitled under the law.
- Transfers to third countries (Art. 14(1)(f) GDPR): with respect to sub-processors outside the EEA (US), the mechanisms described in section 6 apply (EU-U.S. DPF adequacy decision as the primary basis, SCCs as a supplementary mechanism).
- Retention period (Art. 14(2)(a) GDPR): with respect to ticket data we apply the periods set out in section 7 (closed tickets: archived after 1 year, anonymized after 3 years; backups up to 30 days; audit log 2 years), provided that the final retention period and the timing of the return or deletion of data upon termination of the services are determined by the client-controller in its instructions and by the Data Processing Agreement (DPA).
- Rights of data subjects (Art. 14(2)(c) and (e) GDPR): those persons have the rights listed in section 8 and the right to lodge a complaint with a supervisory authority (section 9). Requests are, as a rule, handled by the client-controller; if they are sent directly to Dynaminds, we will forward them to the relevant client-controller and assist them in accordance with the DPA (see section 2).
The details of the entrusted processing (scope, sub-processors, transfers, security measures, return/erasure of data upon termination) are governed by the Data Processing Agreement (DPA) — /dpa.
14. Final provisions and changes to the Policy
This Privacy Policy is effective as of 17 June 2026 (version 2).
Acceptance of the Privacy Policy and the Terms takes place in the platform (click-wrap) during registration (signup); the Data Processing Agreement (DPA) is accepted during onboarding by a person authorized to represent the client organization, in electronic form (Article 28(9) GDPR).
We may update this Policy. We will inform users of material changes and, where necessary, ask for renewed acceptance. Each version is versioned and dated.
Related documents:
- Terms —
/terms - Data Processing Agreement (DPA) —
/dpa - List of sub-processors —
/legal/subprocessors
For questions, please contact: [email protected].
Elevate Privacy Policy
Version: 2
Effective date: 17 June 2026
Replaces: version 1 (earlier drafts)
This Privacy Policy describes how personal data is processed in connection with the use of the Elevate platform — a multi-tenant service desk / helpdesk system that includes, among others: ticketing, a knowledge base, SLA tracking, reporting, and an optional AI assistant, available at
elevate.dynaminds.pl(with subdomains assigned to individual clients).This document constitutes the information notice required under Article 13 and Article 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the "GDPR").
1. Identity and contact details of the controller
The controller of personal data, with respect to the scope described in section 3 (Account data and billing data), is:
Dynaminds — a brand operated by B2B.net S.A., established in Poland.
This company is referred to below as "Dynaminds", "we", or the "Controller".
1a. Data-protection contact (DPO / contact point)
For all matters concerning the processing of personal data and the exercise of rights under the GDPR, you may contact us at: [email protected] or in writing at the Controller's registered address, marked "Data protection".
Dynaminds has not appointed a Data Protection Officer (DPO) within the meaning of Article 37 GDPR, as the conditions for mandatory appointment set out in that provision are not met. The role of the data-protection contact point is served by the address [email protected]. If Dynaminds formally appoints a DPO in the future, their contact details will be set out in this Policy and made available through the same contact channel.
2. Two roles of Dynaminds: controller and processor (KEY DISTINCTION)
Within the Elevate platform, Dynaminds acts in two different roles, depending on the category of data:
| Data category | Role of Dynaminds | Basis of the relationship |
|---|---|---|
| Account data and billing data (email, name, organization membership, invoicing data, technical data) | Controller (independently determines purposes and means) | this Privacy Policy |
| Data entered into the optional AI assistant within the scope of Account data (e.g., a user's administrative queries about their own account) | Controller (to the extent that the AI feature forms part of the service provided by Dynaminds to the Account user) | this Privacy Policy |
| Data contained in the content of tickets — titles, descriptions, comments, attachments, which MAY contain personal data of end users and staff of the client organization — including their processing by the AI feature (e.g., semantic search, knowledge base) | Processor — processes on behalf of and on the documented instructions of the client | Data Processing Agreement (DPA) concluded with the client organization |
For data contained in tickets, the client organization is the controller (the business entity using Elevate), and Dynaminds acts solely as a processor under a separate Data Processing Agreement (DPA), accepted electronically in the platform during onboarding by a person authorized to represent the client (Article 28(9) GDPR).
With respect to ticket data:
The remaining sections of this Policy concern primarily situations in which Dynaminds is the controller (Account and billing data), unless expressly stated otherwise.
3. Categories of data processed
As a controller, we process the following categories of data:
a) Account data:
b) Billing data (for paid purchases):
c) Technical and security data:
d) Data contained in the content of tickets (processor role — see section 2):
4. Purposes of processing and legal bases (per purpose)
Below we set out the purposes of processing together with their corresponding legal bases under Article 6 GDPR. This concerns data for which Dynaminds is the controller (Account, billing, and technical data).
| No. | Purpose of processing | Data categories | Legal basis |
|---|---|---|---|
| 1 | Creating and maintaining the Account, providing the Elevate service (platform access, ticketing, knowledge base, SLA, reporting), handling subscriptions and credits | Account data, billing data | Art. 6(1)(b) GDPR — performance of a contract (the Terms) to which the user / organization is a party, and steps prior to entering into a contract |
| 2 | Payment processing, invoicing, tax settlements (including VAT) | billing data, NIP, invoicing data | Art. 6(1)(c) GDPR — compliance with a legal obligation (accounting and tax law, including the Accounting Act, the VAT Act, and the Tax Ordinance) |
| 3 | Ensuring platform security, prevention of abuse and fraud (anti-fraud), ensuring integrity and continuity of operation, establishing or defending legal claims | technical data (IP, diagnostic data), logs, Account data | Art. 6(1)(f) GDPR — the legitimate interest of the Controller in protecting IT systems, preventing abuse, and securing claims |
| 4 | Service communication and handling requests/inquiries addressed to us (including the exercise of GDPR rights) | Account data, contact data | Art. 6(1)(b) GDPR (within the scope of the contract) and Art. 6(1)(c) GDPR (with respect to fulfilling GDPR obligations) |
| 5 | Making the optional AI assistant available as a platform feature — only with respect to Account data (e.g., a user's administrative queries about their own account), if the feature is enabled | Account data entered into the AI feature | Art. 6(1)(b) GDPR — performance of the contract for the Elevate service, of which the AI feature forms a part |
| 6 | Marketing activities and non-essential cookies (if used at all) | Account data, contact data | Art. 6(1)(a) GDPR — consent (voluntary, withdrawable at any time) |
The processing of ticket content by the AI assistant (e.g., semantic search, generating answers from the knowledge base) is not carried out on the basis of Article 6 GDPR by Dynaminds as a controller. In this respect Dynaminds acts as a processor, and the basis for the processing is the documented instruction of the client-controller arising from the Data Processing Agreement (DPA) (Article 28 GDPR). The purposes and legal bases of this processing are determined by the client-controller — see section 2 and section 13.
The platform currently uses only essential cookies and does not engage in tracking-based marketing (see section 11).
5. Recipients of data and processors (sub-processors)
Data may be disclosed to the following categories of recipients:
We use the following sub-processors (each acting under its own data processing agreement / DPA). In the table below we indicate the role in which Dynaminds uses each sub-processor:
| Sub-processor | Function | Role of Dynaminds (data category) | Processing location |
|---|---|---|---|
| Supabase | database (stores Account data and ticket content) | Processor (ticket content) and Controller (Account data) | EU (Frankfurt) |
| Microsoft (Azure / Microsoft 365) | email (sending via Microsoft Graph; notifications may contain ticket content) | Processor (ticket content) and Controller (Account data) | EU (European tenant) |
| Stripe | payments, tax (Stripe Tax) | Controller (billing data) | EU + US |
| Hetzner | hosting / servers (infrastructure for the entire platform) | Processor (ticket content) and Controller (Account data) | EU (Nuremberg) |
| Cloudflare | CDN / WAF (security, content delivery network, technical data in transit) | Processor (traffic containing ticket content) and Controller (technical data) | global edge network |
| Sentry | error monitoring (diagnostic / technical data) | Controller (technical data) | EU (Frankfurt) |
| Anthropic | AI assistant — processes queries sent to the AI, including ticket content (only when the AI feature is enabled) | Processor (ticket content) and Controller (Account data entered into the AI) | US |
| Voyage AI | vector embeddings for semantic search and the knowledge base — processes ticket content (only when the AI feature is enabled) | Processor (ticket content) | US |
The current, versioned list of sub-processors is available at
/legal/subprocessors. We notify of material changes to the sub-processor list (e.g., the addition of a new one) in accordance with the DPA.6. Transfers of data to third countries
Some sub-processors process data outside the European Economic Area (EEA), in particular in the United States (Stripe, and — when the AI feature is enabled — Anthropic and Voyage AI). Cloudflare may process data within a global edge network.
In each such case, the transfer takes place on the basis of appropriate mechanisms provided for in Chapter V of the GDPR. The primary basis — where a given provider holds an active certification — is a European Commission adequacy decision (Art. 45 GDPR) under the EU–U.S. Data Privacy Framework (EU-U.S. DPF):
/legal/subprocessors).As a supplementary mechanism — in particular in the event that a provider's DPF certification is suspended, withdrawn, or does not cover a specific processing operation — we apply:
The current transfer basis for each provider is set out in the List of sub-processors (
/legal/subprocessors). A copy of, or information about, the safeguards applied may be obtained by contacting [email protected].7. Data retention periods
We retain data no longer than is necessary to achieve the purposes for which it was collected, taking into account legal obligations and limitation periods for claims:
| Data category | Retention period |
|---|---|
| Account data | for the duration of the Account being active (term of the contract), and after its termination — until the expiry of the limitation periods for claims related to the contract (as a rule up to 3 years for claims related to the conduct of business activity, and where the law provides a longer period for certain claims — correspondingly longer), in accordance with purpose No. 3 (establishing or defending legal claims, Art. 6(1)(f) GDPR); after those periods expire, the data is deleted or anonymized |
| Active tickets | for the duration of the Account being active |
| Closed tickets | archived after 1 year, then anonymized after 3 years |
| Event log / audit (audit log) | 2 years |
| Backups | up to 30 days |
| Events / errors in Sentry | 90 days |
| Billing data and invoices | for the period required by accounting and tax law (as a rule 5 years counted from the end of the year in which the tax obligation arose) |
For ticket data (processor role), the retention period also results from the client-controller's instructions and the DPA; upon termination of the services, the data is returned or deleted in accordance with the DPA.
8. Rights of data subjects
To the extent that Dynaminds is the controller, you have the following rights:
Requests concerning the exercise of rights may be submitted to [email protected]. We respond without undue delay, within one month at the latest of receiving the request (with the possibility of an extension by two further months in the case of complex requests — with notification of the reasons).
If a request concerns data contained in tickets (where the client organization is the controller), we will forward it to the relevant client-controller or ask you to address it directly to them.
9. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a supervisory authority, which in Poland is:
President of the Personal Data Protection Office (PUODO)
ul. Stanisława Moniuszki 1A, 00-014 Warsaw
tel. (22) 531 03 00
https://uodo.gov.pl
A complaint may be lodged if you consider that the processing of your personal data infringes the GDPR.
10. Information on whether the provision of data is a requirement
11. Cookies
The Elevate platform uses only essential cookies, serving to maintain the authentication (login) session. They are necessary for the proper functioning of the service and do not require consent.
We do not use cookies for tracking, analytics, or advertising. Should any non-essential cookies be introduced in the future, their use will be preceded by obtaining separate, voluntary consent (opt-in).
12. Automated decision-making and profiling
Dynaminds does not take, with respect to data subjects, decisions based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect them, within the meaning of Article 22 GDPR.
The optional AI assistant (if enabled) supports the handling of tickets, but is not used to automatically make binding decisions concerning natural persons.
13. Source of data (where data does not originate from the data subject) — Article 14 GDPR
With respect to data contained in tickets, Dynaminds may process personal data of natural persons (e.g., end users or staff of the client organization) that was not provided directly by those persons, but originates from the client organization, which is the controller of that data. In this respect Dynaminds acts as a processor, and the full information obligation toward those persons rests, as a rule, with the client-controller. Nonetheless, in the interest of transparency, in accordance with Article 14 GDPR we provide information on the following elements:
The details of the entrusted processing (scope, sub-processors, transfers, security measures, return/erasure of data upon termination) are governed by the Data Processing Agreement (DPA) —
/dpa.14. Final provisions and changes to the Policy
This Privacy Policy is effective as of 17 June 2026 (version 2).
Acceptance of the Privacy Policy and the Terms takes place in the platform (click-wrap) during registration (signup); the Data Processing Agreement (DPA) is accepted during onboarding by a person authorized to represent the client organization, in electronic form (Article 28(9) GDPR).
We may update this Policy. We will inform users of material changes and, where necessary, ask for renewed acceptance. Each version is versioned and dated.
Related documents:
/terms/dpa/legal/subprocessorsFor questions, please contact: [email protected].