← Back

Privacy Policy

Version 2 · effective 2026-06-17

Elevate Privacy Policy

Version: 2
Effective date: 17 June 2026
Replaces: version 1 (earlier drafts)

This Privacy Policy describes how personal data is processed in connection with the use of the Elevate platform — a multi-tenant service desk / helpdesk system that includes, among others: ticketing, a knowledge base, SLA tracking, reporting, and an optional AI assistant, available at elevate.dynaminds.pl (with subdomains assigned to individual clients).

This document constitutes the information notice required under Article 13 and Article 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the "GDPR").


1. Identity and contact details of the controller

The controller of personal data, with respect to the scope described in section 3 (Account data and billing data), is:

Dynaminds — a brand operated by B2B.net S.A., established in Poland.

This company is referred to below as "Dynaminds", "we", or the "Controller".

1a. Data-protection contact (DPO / contact point)

For all matters concerning the processing of personal data and the exercise of rights under the GDPR, you may contact us at: [email protected] or in writing at the Controller's registered address, marked "Data protection".

Dynaminds has not appointed a Data Protection Officer (DPO) within the meaning of Article 37 GDPR, as the conditions for mandatory appointment set out in that provision are not met. The role of the data-protection contact point is served by the address [email protected]. If Dynaminds formally appoints a DPO in the future, their contact details will be set out in this Policy and made available through the same contact channel.


2. Two roles of Dynaminds: controller and processor (KEY DISTINCTION)

Within the Elevate platform, Dynaminds acts in two different roles, depending on the category of data:

| Data category | Role of Dynaminds | Basis of the relationship |
|---|---|---|
| Account data and billing data (email, name, organization membership, invoicing data, technical data) | Controller (independently determines purposes and means) | this Privacy Policy |
| Data entered into the optional AI assistant within the scope of Account data (e.g., a user's administrative queries about their own account) | Controller (to the extent that the AI feature forms part of the service provided by Dynaminds to the Account user) | this Privacy Policy |
| Data contained in the content of tickets — titles, descriptions, comments, attachments, which MAY contain personal data of end users and staff of the client organization — including their processing by the AI feature (e.g., semantic search, knowledge base) | Processor — processes on behalf of and on the documented instructions of the client | Data Processing Agreement (DPA) concluded with the client organization |

For data contained in tickets, the client organization is the controller (the business entity using Elevate), and Dynaminds acts solely as a processor under a separate Data Processing Agreement (DPA), accepted electronically in the platform during onboarding by a person authorized to represent the client (Article 28(9) GDPR).

With respect to ticket data:

The remaining sections of this Policy concern primarily situations in which Dynaminds is the controller (Account and billing data), unless expressly stated otherwise.


3. Categories of data processed

As a controller, we process the following categories of data:

a) Account data:

b) Billing data (for paid purchases):

c) Technical and security data:

d) Data contained in the content of tickets (processor role — see section 2):


4. Purposes of processing and legal bases (per purpose)

Below we set out the purposes of processing together with their corresponding legal bases under Article 6 GDPR. This concerns data for which Dynaminds is the controller (Account, billing, and technical data).

| No. | Purpose of processing | Data categories | Legal basis |
|---|---|---|---|
| 1 | Creating and maintaining the Account, providing the Elevate service (platform access, ticketing, knowledge base, SLA, reporting), handling subscriptions and credits | Account data, billing data | Art. 6(1)(b) GDPR — performance of a contract (the Terms) to which the user / organization is a party, and steps prior to entering into a contract |
| 2 | Payment processing, invoicing, tax settlements (including VAT) | billing data, NIP, invoicing data | Art. 6(1)(c) GDPR — compliance with a legal obligation (accounting and tax law, including the Accounting Act, the VAT Act, and the Tax Ordinance) |
| 3 | Ensuring platform security, prevention of abuse and fraud (anti-fraud), ensuring integrity and continuity of operation, establishing or defending legal claims | technical data (IP, diagnostic data), logs, Account data | Art. 6(1)(f) GDPR — the legitimate interest of the Controller in protecting IT systems, preventing abuse, and securing claims |
| 4 | Service communication and handling requests/inquiries addressed to us (including the exercise of GDPR rights) | Account data, contact data | Art. 6(1)(b) GDPR (within the scope of the contract) and Art. 6(1)(c) GDPR (with respect to fulfilling GDPR obligations) |
| 5 | Making the optional AI assistant available as a platform feature — only with respect to Account data (e.g., a user's administrative queries about their own account), if the feature is enabled | Account data entered into the AI feature | Art. 6(1)(b) GDPR — performance of the contract for the Elevate service, of which the AI feature forms a part |
| 6 | Marketing activities and non-essential cookies (if used at all) | Account data, contact data | Art. 6(1)(a) GDPR — consent (voluntary, withdrawable at any time) |

The processing of ticket content by the AI assistant (e.g., semantic search, generating answers from the knowledge base) is not carried out on the basis of Article 6 GDPR by Dynaminds as a controller. In this respect Dynaminds acts as a processor, and the basis for the processing is the documented instruction of the client-controller arising from the Data Processing Agreement (DPA) (Article 28 GDPR). The purposes and legal bases of this processing are determined by the client-controller — see section 2 and section 13.

The platform currently uses only essential cookies and does not engage in tracking-based marketing (see section 11).


5. Recipients of data and processors (sub-processors)

Data may be disclosed to the following categories of recipients:

We use the following sub-processors (each acting under its own data processing agreement / DPA). In the table below we indicate the role in which Dynaminds uses each sub-processor:

| Sub-processor | Function | Role of Dynaminds (data category) | Processing location |
|---|---|---|---|
| Supabase | database (stores Account data and ticket content) | Processor (ticket content) and Controller (Account data) | EU (Frankfurt) |
| Microsoft (Azure / Microsoft 365) | email (sending via Microsoft Graph; notifications may contain ticket content) | Processor (ticket content) and Controller (Account data) | EU (European tenant) |
| Stripe | payments, tax (Stripe Tax) | Controller (billing data) | EU + US |
| Hetzner | hosting / servers (infrastructure for the entire platform) | Processor (ticket content) and Controller (Account data) | EU (Nuremberg) |
| Cloudflare | CDN / WAF (security, content delivery network, technical data in transit) | Processor (traffic containing ticket content) and Controller (technical data) | global edge network |
| Sentry | error monitoring (diagnostic / technical data) | Controller (technical data) | EU (Frankfurt) |
| Anthropic | AI assistant — processes queries sent to the AI, including ticket content (only when the AI feature is enabled) | Processor (ticket content) and Controller (Account data entered into the AI) | US |
| Voyage AI | vector embeddings for semantic search and the knowledge base — processes ticket content (only when the AI feature is enabled) | Processor (ticket content) | US |

The current, versioned list of sub-processors is available at /legal/subprocessors. We notify of material changes to the sub-processor list (e.g., the addition of a new one) in accordance with the DPA.


6. Transfers of data to third countries

Some sub-processors process data outside the European Economic Area (EEA), in particular in the United States (Stripe, and — when the AI feature is enabled — Anthropic and Voyage AI). Cloudflare may process data within a global edge network.

In each such case, the transfer takes place on the basis of appropriate mechanisms provided for in Chapter V of the GDPR. The primary basis — where a given provider holds an active certification — is a European Commission adequacy decision (Art. 45 GDPR) under the EU–U.S. Data Privacy Framework (EU-U.S. DPF):

As a supplementary mechanism — in particular in the event that a provider's DPF certification is suspended, withdrawn, or does not cover a specific processing operation — we apply:

The current transfer basis for each provider is set out in the List of sub-processors (/legal/subprocessors). A copy of, or information about, the safeguards applied may be obtained by contacting [email protected].


7. Data retention periods

We retain data no longer than is necessary to achieve the purposes for which it was collected, taking into account legal obligations and limitation periods for claims:

| Data category | Retention period |
|---|---|
| Account data | for the duration of the Account being active (term of the contract), and after its termination — until the expiry of the limitation periods for claims related to the contract (as a rule up to 3 years for claims related to the conduct of business activity, and where the law provides a longer period for certain claims — correspondingly longer), in accordance with purpose No. 3 (establishing or defending legal claims, Art. 6(1)(f) GDPR); after those periods expire, the data is deleted or anonymized |
| Active tickets | for the duration of the Account being active |
| Closed tickets | archived after 1 year, then anonymized after 3 years |
| Event log / audit (audit log) | 2 years |
| Backups | up to 30 days |
| Events / errors in Sentry | 90 days |
| Billing data and invoices | for the period required by accounting and tax law (as a rule 5 years counted from the end of the year in which the tax obligation arose) |

For ticket data (processor role), the retention period also results from the client-controller's instructions and the DPA; upon termination of the services, the data is returned or deleted in accordance with the DPA.


8. Rights of data subjects

To the extent that Dynaminds is the controller, you have the following rights:

Requests concerning the exercise of rights may be submitted to [email protected]. We respond without undue delay, within one month at the latest of receiving the request (with the possibility of an extension by two further months in the case of complex requests — with notification of the reasons).

If a request concerns data contained in tickets (where the client organization is the controller), we will forward it to the relevant client-controller or ask you to address it directly to them.


9. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a supervisory authority, which in Poland is:

President of the Personal Data Protection Office (PUODO)
ul. Stanisława Moniuszki 1A, 00-014 Warsaw
tel. (22) 531 03 00
https://uodo.gov.pl

A complaint may be lodged if you consider that the processing of your personal data infringes the GDPR.


10. Information on whether the provision of data is a requirement


11. Cookies

The Elevate platform uses only essential cookies, serving to maintain the authentication (login) session. They are necessary for the proper functioning of the service and do not require consent.

We do not use cookies for tracking, analytics, or advertising. Should any non-essential cookies be introduced in the future, their use will be preceded by obtaining separate, voluntary consent (opt-in).


12. Automated decision-making and profiling

Dynaminds does not take, with respect to data subjects, decisions based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect them, within the meaning of Article 22 GDPR.

The optional AI assistant (if enabled) supports the handling of tickets, but is not used to automatically make binding decisions concerning natural persons.


13. Source of data (where data does not originate from the data subject) — Article 14 GDPR

With respect to data contained in tickets, Dynaminds may process personal data of natural persons (e.g., end users or staff of the client organization) that was not provided directly by those persons, but originates from the client organization, which is the controller of that data. In this respect Dynaminds acts as a processor, and the full information obligation toward those persons rests, as a rule, with the client-controller. Nonetheless, in the interest of transparency, in accordance with Article 14 GDPR we provide information on the following elements:

The details of the entrusted processing (scope, sub-processors, transfers, security measures, return/erasure of data upon termination) are governed by the Data Processing Agreement (DPA)/dpa.


14. Final provisions and changes to the Policy

This Privacy Policy is effective as of 17 June 2026 (version 2).

Acceptance of the Privacy Policy and the Terms takes place in the platform (click-wrap) during registration (signup); the Data Processing Agreement (DPA) is accepted during onboarding by a person authorized to represent the client organization, in electronic form (Article 28(9) GDPR).

We may update this Policy. We will inform users of material changes and, where necessary, ask for renewed acceptance. Each version is versioned and dated.

Related documents:

For questions, please contact: [email protected].