Version 1.0, effective 6 July 2026.
Section 1. Data controller
1. The controller of the personal data of users of the QuickPSD website available at https://quickpsd.app (the Service) is [TO BE COMPLETED: full name], correspondence address: [TO BE COMPLETED: address], e-mail: [TO BE COMPLETED: contact e-mail address] (the Controller).
2. The Controller has not appointed a data protection officer. All matters concerning personal data can be addressed to the Controller at the e-mail address indicated in point 1.
3. Personal data is processed in accordance with Regulation (EU) 2016/679 (GDPR) and Polish data protection law.
Section 2. Local file processing principle
1. Graphic files opened and edited in the Service's editor are processed exclusively locally, in the browser on the user's device. The contents of these files, including layers, text and graphics, are not transmitted to the Controller's servers or to any third parties.
2. The Service's server records only the fact that an export was performed (without the content of the exported file) in order to count daily limits.
Section 3. Categories of processed data
- User account: e-mail address, password stored as a cryptographic hash (the Controller does not know or store the plain-text password), display name, optional avatar, account settings (theme, language, e-mail notification preference), registration and e-mail verification dates.
- Sessions and tokens: login session identifiers and single-use tokens for e-mail verification, password recovery and e-mail address change, together with their expiry dates.
- Licenses: license key value, the e-mail address the key is bound to, activation and expiry dates, key status.
- Technical data used for export limits: a random identifier stored in a cookie (anon_id), a truncated cryptographic hash (HMAC) of the IP address and - where available - a truncated hash of the browser fingerprint. The raw IP address is not stored in the counters; the counters are kept in a cache (Redis) and expire automatically at the end of each day (UTC).
- Export security data: single-use request identifiers (nonces) and rate-limiting data based on the IP address hash.
- Server logs: standard infrastructure logs (reverse proxy and application) which may contain the IP address, request URL, timestamp and browser identifier (user agent). Log retention period: [TO BE COMPLETED: server log retention period].
- Correspondence: the content of messages sent to the Controller (complaints, inquiries) together with the sender's e-mail address.
- Customer register: in the Service's administration panel, the Controller keeps a register of key buyers and business partners containing the name, e-mail address, optionally company name and phone number, and notes related to license handling.
Section 4. Purposes and legal bases of processing
- Creating and maintaining an account, providing the editor services, activating and handling license keys, sending transactional messages (e-mail verification, password recovery, e-mail change) - Article 6(1)(b) GDPR (performance of a contract or steps prior to entering into one).
- Handling complaints and withdrawal statements - Article 6(1)(b) and (c) GDPR (performance of a contract and legal obligations under consumer law).
- Counting daily export limits, preventing abuse and circumvention of limits, securing the export mechanism, ensuring the security and stability of the Service (including server logs) - Article 6(1)(f) GDPR (the Controller's legitimate interest in protecting its infrastructure and enforcing the rules of the Service).
- Keeping sales records and settlements required by tax law, including the sales register for unregistered business activity - Article 6(1)(c) GDPR (legal obligation).
- Establishing, pursuing or defending legal claims - Article 6(1)(f) GDPR (the Controller's legitimate interest).
- Traffic analytics or marketing using cookies other than necessary ones - only if implemented in the future and only on the basis of the user's prior consent (Article 6(1)(a) GDPR); see Section 8 point 4.
Section 5. Data retention periods
- Account data - until the account is deleted, and after deletion for the limitation period of potential claims provided by law.
- Login sessions and single-use tokens - until they expire or are used; expired records are deleted.
- License data - for the duration of the license, and after its expiry for the limitation period of claims and the period required by tax law.
- Export limit counters - until the end of the given day (UTC), after which they expire automatically.
- The anon_id cookie identifier - up to 12 months from when it was last set.
- Server logs - for the period indicated in Section 3.
- Correspondence and complaint documentation - for the limitation period of claims.
- Customer register data - for the duration of the cooperation, the period required by tax law and the limitation period of claims.
Section 6. Recipients and processors
1. Contabo GmbH (Aschauer Straße 32a, 81549 Munich, Germany) - the provider of the VPS server on which the Service, its database and cache operate. Contabo acts as a processor within the meaning of Article 28 GDPR under a Data Processing Agreement concluded with the Controller. The server is located in the European Union region.
2. Outgoing e-mail (SMTP) provider - [TO BE COMPLETED: name and registered office of the SMTP provider] - to the extent necessary to send transactional messages (recipient's e-mail address and message content), as a processor.
3. G2G (operator of the g2g.com platform) - the platform through which keys are purchased. G2G processes data related to the order and payment (including payment data) as a separate, independent controller, in accordance with its own privacy policy available at g2g.com. The Controller has no access to buyers' payment data; it receives order information from G2G to the extent made available to sellers by the platform.
4. The domain registrar (Spaceship) provides only domain registration and maintenance and does not process the personal data of the Service's users.
5. Data may also be disclosed to entities authorized under the law (e.g. courts, law enforcement) and to the Controller's legal and accounting advisors to the extent necessary to support its activity.
6. The database, cache (Redis) and limit mechanisms run on the infrastructure described in point 1; the Controller does not use external cloud services to store user data.
Section 7. Transfers outside the European Economic Area
1. User data is stored on a server located in the European Union and, as a rule, is not transferred outside the European Economic Area.
2. If the SMTP provider referred to in Section 6 point 2 processes data outside the EEA, the transfer takes place on the basis of appropriate safeguards provided for in Chapter V GDPR, in particular standard contractual clauses.
3. Key purchases take place on the G2G platform, whose operator may process order data outside the EEA as a separate controller, in accordance with its own privacy policy.
Section 8. Cookies
1. The Service uses only cookies necessary for its operation and functional cookies storing user preferences:
- qp_session - maintaining the logged-in user's session; until logout or session expiry.
- anon_id - counting the daily export limit for non-logged-in users (signed random identifier); 12 months.
- cookie_consent - remembering acknowledgement of the cookie notice; 12 months.
- NEXT_LOCALE - remembering the selected language; 12 months.
- interface theme - remembering the selected theme (light/dark); 12 months.
2. Necessary and functional cookies are not used to track users across other websites or for advertising purposes.
3. Users may delete or block cookies in their browser settings; blocking necessary cookies may prevent logging in and the correct operation of limits.
4. The Service does not currently use third-party analytics or marketing tools. If such tools are implemented in the future, their launch will be preceded by: an update of this policy (naming the tools, the scope of data and the recipients), an adjustment of the cookie consent mechanism so that non-necessary cookies are set only after the user's voluntary consent, and the ability to withdraw consent at any time.
Section 9. Rights of data subjects
1. Every person whose data is processed by the Controller has the right to: access their data and obtain a copy of it (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), portability of data processed on the basis of a contract or consent (Article 20 GDPR), objection to processing based on legitimate interest (Article 21 GDPR), and withdrawal of consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
2. These rights can be exercised by contacting the Controller at the e-mail address indicated in Section 1 point 1. Some operations (changing profile data, removing the avatar, changing the e-mail address, deleting the account) are available directly in the account panel.
3. The Controller responds to requests without undue delay, no later than within one month; this period may be extended by two further months for complex or numerous requests, of which the requesting person will be informed.
Section 10. Right to lodge a complaint
Data subjects have the right to lodge a complaint with the supervisory authority - the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, https://uodo.gov.pl. Persons residing in other EEA countries may lodge a complaint with the supervisory authority competent for their place of residence.
Section 11. Voluntariness of providing data and automated decisions
1. Providing data is voluntary but necessary to use the relevant features: an e-mail address and password - to create an account; the e-mail address bound to a key - to use the PRO plan.
2. Using the editor without registration does not require providing identifying data; only the technical data described in Section 3 is then processed.
3. The Controller does not make decisions concerning users based solely on automated processing, including profiling, that would produce legal effects or similarly significantly affect them. Automatic enforcement of daily export limits is part of the agreed service and does not constitute such a decision.
Section 12. Changes to the privacy policy
1. The Controller may update this policy in the event of changes to the Service, changes in the law or the implementation of new tools.
2. Users holding an account will be informed of material changes by e-mail or by a notice in the Service before the changes take effect. The current version of the policy is always available at https://quickpsd.app/privacy.
This document was generated with the assistance of AI based on the information provided - review by a lawyer is recommended before publication (consumer law, GDPR, sale through an intermediary).