SocialPlate Privacy Policy
Effective date: 1 January 2026
Last updated: 18 April 2026
1. General information
This Privacy Policy sets out the rules for processing and protecting personal data provided by Users in connection with their use of the services available on the SocialPlate platform.
Data controller:
- Name: Bytly spółka z ograniczoną odpowiedzialnością (operator of the SocialPlate platform)
- Registered office: ul. Wolna 11, 42-202 Częstochowa, Poland
- Court of registration: District Court in Częstochowa, 17th Commercial Division of the National Court Register
- KRS: 0001135848
- NIP: 9492272400
- REGON: 540044350
- Share capital: 5,000.00 PLN
- Email: kontakt@socialplate.pl
- Phone: 572 272 538
The controller of your personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation — GDPR) is Bytly sp. z o.o., with its registered office in Częstochowa, operator of the SocialPlate platform.
Data Protection Officer (DPO): The controller has not appointed a Data Protection Officer, as it does not meet the conditions set out in Article 37 GDPR. For all matters relating to the processing of personal data, please contact us at: kontakt@socialplate.pl.
Obligation to provide data: Providing personal data is voluntary, but necessary to enter into and perform the service agreement (registration, subscription, invoice issuance). Failure to provide data will prevent use of the Platform.
2. Legal basis for processing
Your personal data are processed on the basis of:
- Article 6(1)(a) GDPR — consent of the data subject
Applies to: newsletter sign-up, marketing cookies - Article 6(1)(b) GDPR — processing necessary for the performance of a contract
Applies to: provision of SocialPlate services, management of the user account, processing of payments - Article 6(1)(c) GDPR — processing necessary to comply with a legal obligation
Applies to: issuing VAT invoices, retaining accounting records - Article 6(1)(f) GDPR — legitimate interests of the controller
Applies to: pursuit of claims, direct marketing of own products, analytics and statistics
3. What data we collect
3.1 Data provided by the User
When using the platform, we may collect the following data:
A) Registration data (account):
- Full name
- Email address
- Phone number (optional)
- Password (stored in encrypted form)
B) Business / venue data:
- Venue / restaurant name
- Venue address
- NIP (for invoice purposes)
- Billing address (if different from the venue)
C) Payment data:
- Transaction and payment history
- Payment card data (processed by a third-party payment operator — we do not store card numbers)
D) Content uploaded to the platform:
- Photos of dishes and the venue
- Post captions
- Publishing schedules
E) Data from contact forms:
- Full name, email address, message content, phone number (if provided)
3.2 Data collected automatically
A) Technical data: IP address, browser type, operating system, ISP, date of visit, pages visited.
B) Cookies: (see section 7 for details)
3.3 Data from social media integrations
When you connect your SocialPlate account to Facebook or Instagram, we collect: account IDs, access tokens, basic information about the page/profile, and statistics relating to published content.
Note: Access to your social media accounts is limited strictly to publishing content and reading statistics. We do not modify your privacy settings or access private messages.
3.4 Source of data (Article 14 GDPR)
Most data are collected directly from you. In the case of Facebook/Instagram integrations, some data (e.g. reach statistics, page/profile data, data relating to comment authors visible in statistics) are received via Meta Platforms Ireland Ltd. on the basis of the permissions you grant when connecting your accounts. The scope of those data is determined by Meta's platform policy and the consents you give during the OAuth flow.
4. Purposes and retention periods
| Purpose of processing | Legal basis | Retention period |
|---|---|---|
| Provision of services, user account (B2B) | Art. 6(1)(b) | Until account deletion + 3 years (limitation period for business claims, Art. 118 Civil Code) |
| Provision of services, user account (consumer / sole trader acting as consumer) | Art. 6(1)(b) | Until account deletion + 6 years (general limitation period, Art. 118 Civil Code) |
| Issuing and retaining invoices | Art. 6(1)(c) | 5 years from the end of the calendar year in which the tax payment deadline fell (Art. 70 § 1 Tax Ordinance) |
| Accounting records | Art. 6(1)(c) | 5 years (Art. 74 Accounting Act) |
| Handling enquiries and complaints | Art. 6(1)(b / f) | Until the matter is resolved + limitation period (3–6 years depending on status) |
| Defence of claims | Art. 6(1)(f) | Until the limitation period expires + 1 year |
| Marketing (newsletter) | Art. 6(1)(a) | Until consent is withdrawn |
| Analytics and statistics | Art. 6(1)(f) | Anonymised data, indefinitely |
5. Who has access to your data
5.1 Recipients within SocialPlate
Your personal data may be disclosed to:
- Employees and contractors of the controller, solely to the extent necessary for the provision of the Services, under authorisations and confidentiality undertakings.
- Public authorities: tax offices, courts, law-enforcement bodies, on the basis of applicable law, upon their duly justified request.
5.2 Processors (sub-processors)
SaaS application data within the EU. The core infrastructure of the SocialPlate application (database, file storage, application servers, backups) is located within the European Union. Customer data do not leave the European Economic Area (EEA), except for transfers to the services listed below, for which the safeguards set out in section 5.3 apply.
In accordance with Article 28 GDPR, we entrust the processing of data to trusted providers. Current list of sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Cloud provider, SaaS application | Hosting of the application, database, file storage, backups | EU |
| Netlify, Inc. | Hosting of the marketing website and contact forms | USA (SCC + DPF) |
| Simple Analytics B.V. | Traffic analytics (no cookies, no personal data) | Netherlands (EEA) |
| PayPro SA (Przelewy24) | Payment processing and subscription management | Poland |
| Meta Platforms Ireland Ltd. | Integration with Facebook and Instagram (Graph API) | Ireland / USA (SCC + DPF) |
| Google Ireland Ltd. | AI services for generating post captions | Ireland / USA (SCC + DPF) |
| Accounting firm | Bookkeeping and VAT invoicing | Poland |
This list is kept up to date. We notify B2B Customers of any material changes to the list of sub-processors at least 30 days in advance, giving them the opportunity to object.
5.3 Transfers outside the EEA
Some sub-processors are established outside the European Economic Area (primarily in the USA). In such cases, transfers are made on the basis of:
- An adequacy decision of the European Commission (e.g. the EU–U.S. Data Privacy Framework for certified entities), or
- Standard Contractual Clauses (SCCs) adopted by the European Commission under Decision 2021/914.
A copy of the safeguards applicable to a specific transfer is available upon request at kontakt@socialplate.pl.
5.4 Data Processing Agreement for B2B Customers
If, as a business customer (restaurant, venue), you upload to the Platform photographs or other content that may contain personal data of third parties (e.g. employees, guests), you are the controller of those data, and the SocialPlate controller acts as the processor. A template Data Processing Agreement (DPA) is available on request at kontakt@socialplate.pl.
6. How we process photos and content
Process: Upload → AI analysis → Caption generation → Storage.
Security: SSL/TLS encryption, restricted access.
Publication: ONLY on the profiles you specify. We do not share content with third parties.
Generated captions: Editable, contain no personal data.
7. Cookies and analytics
Cookies are small text files that websites store on your device. They are governed by Article 173 of the Telecommunications Act and the GDPR (in so far as they involve personal data).
7.1 Cookies used on the Platform
On the marketing website (socialplate.pl) we use only strictly necessary cookies of a technical nature (session, security, display preferences). These cookies do not require consent under Article 173(3) of the Telecommunications Act.
In the logged-in user panel (the SocialPlate application) we additionally use cookies that are necessary to maintain the login session.
We do not use marketing, advertising or profiling cookies. We do not use Google Analytics, Google Ads, Facebook Pixel or similar tools that require consent.
7.2 Cookie-free analytics (Simple Analytics)
We measure traffic on our website using Simple Analytics (Simple Analytics B.V., Netherlands), a tool designed in compliance with GDPR:
- It does not store cookies or any other identifiers on your device
- It does not collect IP addresses in an identifiable form
- It does not track users across websites
- Data are aggregated and anonymous
For this reason, the use of Simple Analytics does not require consent or a cookie banner.
7.3 Managing cookies
You can manage cookies at any time in your browser settings (Chrome, Firefox, Safari, Edge). Disabling strictly necessary cookies may prevent you from using the logged-in features of the Platform.
7.4 Future changes
If in future we implement tools that require consent (e.g. Google Analytics, Meta Pixel, remarketing), we will deploy a cookie consent panel and update this Policy with at least 14 days' notice.
8. Your rights (GDPR)
8.1 Right of access (Article 15 GDPR)
You have the right to obtain from the controller confirmation as to whether we process your personal data and, if so, to obtain a copy of those data together with information about the purposes, recipients and retention periods.
8.2 Right to rectification (Article 16 GDPR)
You have the right to request the immediate rectification of inaccurate personal data or the completion of incomplete data.
8.3 Right to erasure / "right to be forgotten" (Article 17 GDPR)
You have the right to request erasure of your data where they are no longer necessary for the purposes for which they were collected, you have withdrawn consent, a valid objection has been lodged, or the data were processed unlawfully. Please note that in some cases applicable law (e.g. tax law) requires us to continue to store certain data.
8.4 Right to restriction of processing (Article 18 GDPR)
You may request restriction of processing in the circumstances set out in the GDPR (e.g. when you contest the accuracy of the data or have lodged an objection).
8.5 Data deletion instructions (Meta/Facebook Data Deletion Instructions)
In accordance with Facebook's platform requirements, we provide data deletion instructions for users who use Facebook Login or integrate their pages:
- Deletion within the application: Log in to your SocialPlate account, go to "Settings", and select "Delete account". This will permanently delete your data from our servers.
- Direct contact: Send an email to kontakt@socialplate.pl requesting data deletion.
- Deletion via Facebook:
- Go to Settings & Privacy on your Facebook account.
- Click Settings.
- Navigate to Apps and Websites.
- Find the SocialPlate app.
- Click the Remove button.
- To request confirmation of data deletion, click "View removed apps and websites", select SocialPlate and click "Send request".
8.6 Right to data portability (Article 20 GDPR)
You have the right to receive your data in a structured, commonly used, machine-readable format (e.g. CSV, JSON).
How to exercise this right: Write to kontakt@socialplate.pl with the subject "Data transfer"
Response time: Up to 30 days
8.7 Right to object (Article 21 GDPR)
You have the right to object to the processing of your data:
- Based on legitimate interests (Article 6(1)(f))
- For direct marketing purposes
How to exercise this right: Click "Unsubscribe" in the newsletter OR write to kontakt@socialplate.pl
8.8 Right to withdraw consent (Article 7(3) GDPR)
Where processing is based on consent, you may withdraw it at any time.
Note: Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
8.9 Right to lodge a complaint
If you believe that we are processing your data unlawfully, you may lodge a complaint with:
President of the Personal Data Protection Office (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
9. Data security
Technical measures:
- SSL/TLS encryption
- Password hashing (bcrypt/Argon2)
- Regular backups
- Firewall
Organisational measures:
- Restricted access
- Confidentiality agreements
- Audits
- Training
10. Marketing and newsletter
This section governs marketing communications directed to Users and subscribers. The legal bases are set out in section 2 above.
10.1 Newsletter
Current status: As at the date of the last update of this Policy, the controller does not send a regular newsletter.
If we launch a newsletter in future:
- Sending only on the basis of freely given, separate and prior consent (Article 6(1)(a) GDPR + Article 10(2) of the Act on the Provision of Electronic Services + Article 172 of the Telecommunications Act)
- Consent obtained via a double opt-in mechanism (confirmation via a link in an activation email)
- Withdrawal of consent in 1 click via an "unsubscribe" link in every message and by email to kontakt@socialplate.pl
- Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal
10.2 Direct marketing to existing Customers
The controller may send active Customers information about new features, pricing changes or planned service updates on the basis of legitimate interests (Article 6(1)(f) GDPR). Customers may object at any time by writing to kontakt@socialplate.pl.
10.3 Remarketing and digital advertising
We currently do not carry out remarketing or use advertising pixels (Meta Pixel, Google Ads, etc.). Should we implement such tools in future, they will operate exclusively on the basis of explicit consent given in the cookie consent panel.
11. Automated decision-making and artificial intelligence
11.1 No legally significant automated decisions (Article 22 GDPR)
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
11.2 AI-generated captions
The Platform uses artificial intelligence models (provided by Google Ireland Ltd.) to generate post caption proposals based on photos you upload. We inform you that:
- AI-generated content constitutes proposals that the User reviews and approves before publication
- Generated captions may contain inaccuracies; ultimate responsibility for published content rests with the User
- Photos are sent to the AI provider solely for the purpose of generating a caption and are not used to train models (in accordance with the commercial API terms)
- This disclosure fulfils the transparency obligation under Article 50 of Regulation (EU) 2024/1689 (AI Act)
12. Children's data and security breaches
12.1 Data of persons under 18
The SocialPlate Platform is intended solely for persons who are at least 18 years of age. We do not direct our Services to children and we do not knowingly collect personal data of persons under 18. If we determine that we have received personal data of a minor without an appropriate legal basis, such data will be deleted without delay. If you are a parent or guardian and suspect that your child has provided us with data, please contact us at: kontakt@socialplate.pl.
12.2 Reporting breaches (Articles 33–34 GDPR)
In the event of a personal data breach, we report it to:
- The President of the Personal Data Protection Office, within 72 hours of becoming aware of the breach (Article 33 GDPR), unless it is unlikely to result in a risk to the rights and freedoms of natural persons
- The data subjects, without undue delay, where the breach is likely to result in a high risk (Article 34 GDPR)
If you suspect a breach of the protection of your data on the controller's side, please report it immediately to: kontakt@socialplate.pl.
13. Changes to the Privacy Policy
The controller reserves the right to amend this Privacy Policy, in particular in the event of:
- Changes to applicable law (GDPR, Personal Data Protection Act, Act on the Provision of Electronic Services, AI Act, DSA)
- Changes to the scope of the Services or the addition of new features
- Changes to the list of sub-processors
- The need to clarify provisions
We give at least 14 days' advance notice of material changes via:
- An email to the address provided in the Account, and
- A notice on the socialplate.pl website
Continued use of the Services after changes take effect constitutes acceptance of those changes. If you do not agree to the changes, you may delete your Account at any time.
14. Contact for data protection matters
Data controller:
Bytly sp. z o.o. (operator of the SocialPlate platform)
- Address: ul. Wolna 11, 42-202 Częstochowa
- Email: kontakt@socialplate.pl
- Phone: 572 272 538
How to submit a GDPR request: write to kontakt@socialplate.pl with the subject "GDPR Request". We respond within 30 days (with the possibility of extension by a further 60 days for complex cases, in accordance with Article 12(3) GDPR).
© 2026 Bytly sp. z o.o., operator of the SocialPlate platform. All rights reserved.