Privacy

Privacy Policy

This Policy explains how Biuro Rachunkowe Zamek sp. z o.o. processes personal data of users of the Zamek website and community forum available at https://buforum.eu. Last updated: 20.07.2026.

01

Data controller

The controller of personal data is Biuro Rachunkowe Zamek sp. z o.o., with its registered office at [FULL REGISTERED OFFICE ADDRESS], Poland, NIP: [NIP], REGON: [REGON], KRS: [KRS]. Privacy enquiries and requests may be sent to hello@finalign.pl, made by telephone at +48 22 123 45 67, submitted through the contact form or sent by post to the controller.

02

Categories and sources of data

Depending on how the Service is used, we may process the account identifier, email address, full name or display name, phone number and company name voluntarily entered in the profile, a profile-image URL supplied by the authentication provider, the account role and status, authentication provider and profile creation or update dates. Forum data include topic titles and content, comments, quotations, tags, publication language, activity dates, reports and moderation history. The contact form stores full name, phone number, email address, message, language, form source, processing status and confirmation that the privacy policy was accepted. Technical data may include an IP address or its cryptographic hash, an email hash used for rate limiting, session identifiers and information about the browser, device, request time, errors and security events.

03

Account, registration and Google login

An account may be created with an email address and password or accessed through Google. Authentication is handled by Supabase Auth. During Google login, the Service may receive the Google account identifier, email address, profile name and profile-image URL if Google provides them. The Service does not receive the Google password. Users cannot upload their own avatar file, but an image supplied by Google may be displayed in the profile. Registration and login are required to create topics, add comments, quote content and submit forum reports.

04

Public forum and user responsibility

The forum may be read without registration. Topic titles and content, comments, quotations, tags, the author's display name and role, and publication dates may be public. Users should publish only information they intend to disclose publicly. Passwords, document numbers, national identification numbers, bank details, exact home addresses, medical data, confidential business information and personal data of other people without a lawful basis must not be posted. Users are responsible for the content they publish, without prejudice to the controller's obligations under applicable law.

05

Moderation, filters and reports

The forum is moderated by administrators and moderators. The Service uses a prohibited-word filter, a blocked-domain list, request limits and account blocking or suspension. Content may be blocked before publication, sent for review, hidden, closed or removed. A user may report a topic, comment or account that appears to violate the law or forum rules. Automated mechanisms protect the Service and are not intended to make decisions producing legal or similarly significant effects without human involvement.

06

Purposes and legal bases

Account, login and forum-activity data are processed to provide electronic services under Article 6(1)(b) GDPR. Contact-form data are processed to answer an enquiry and take steps before entering into a contract under Article 6(1)(b) GDPR, or otherwise on the controller's legitimate interests under Article 6(1)(f) GDPR. Moderation, report handling, prevention of spam and abuse, rate limiting, security and the establishment, exercise or defence of legal claims rely on Article 6(1)(f) GDPR. Data required by law are processed under Article 6(1)(c) GDPR. The Service presents paid accounting services, but no contract or payment is completed directly on the website.

07

Recipients and transfers outside the EEA

Data may be processed by Supabase as provider of database, authentication and infrastructure, by Vercel as application-hosting provider and by Google in connection with OAuth login and the embedded Google Maps content. Data may also be disclosed to IT, legal or accounting service providers and to public authorities where required by law. Some providers may process data outside the European Economic Area. In such cases, transfers are made using a mechanism permitted by the GDPR, in particular an adequacy decision or Standard Contractual Clauses, together with additional safeguards where required.

08

Retention and deletion

Active-account data are retained while the account exists. A deletion request may be sent to the controller; identifying account data are removed after the request is verified, generally within 30 days, unless continued retention is required by law or necessary for legal claims. Published topics and comments may remain to preserve the continuity of discussions. Under the current database structure, deleting the account removes the author_id link to the profile, while the author name copied into a forum entry requires separate anonymisation when the request is handled. Published forum content is retained while the forum operates or until removed under the law or moderation rules. Pending, hidden, deleted or closed content may be removed after 90 days unless needed for a report or legal claim. Open and reviewing reports are retained until the case is completed; resolved or rejected reports and related moderation history are generally retained for 12 months. Contact submissions are retained until handled and then generally for 12 months, unless they led to cooperation, must be kept by law or are needed for claims. Rate-limit records older than 24 hours are automatically deleted during later limit checks. Ordinary technical and security logs may be retained for up to 90 days, account-block data for the duration of the block and up to 12 months afterwards, and deleted data may remain in provider backups for approximately 7–30 days depending on the service and plan.

09

Cookies, sessions and Google Maps

The Service uses necessary cookies and similar Supabase mechanisms to maintain login sessions and provide security. The finalign-locale cookie remembers the selected language for up to one year. No first-party analytics or marketing tools were found in the reviewed code, so the Service does not currently display a consent banner for such cookies. Blocking necessary cookies may prevent login or proper operation. The office section loads an embedded Google Maps iframe as an external resource. Loading the map may send Google the user's IP address and browser or device information. If optional analytics, marketing or other technologies requiring consent are added, they will be activated only after the required consent has been obtained.

10

User rights

Data subjects may request access to and a copy of their data, rectification, erasure, restriction of processing, data portability, object to processing based on legitimate interests and withdraw consent where processing is based on consent. Requests may be sent to hello@finalign.pl. The controller may ask for information needed to verify the requester's identity. A complaint may also be lodged with the President of the Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland.

11

Security, minors and changes

The controller applies technical and organisational measures including HTTPS, access controls, Supabase Row Level Security, restricted privileges, rate limiting, content filters and software updates. Providing data is voluntary, but required data are necessary to create an account, log in, publish on the forum, submit a report or send a contact form. The Service is not directed at children. A person aged 16 or over may create an account independently; a younger person may use the Service only where permitted by law and with any required parental or guardian consent. This Policy may be updated when the law, Service features, providers or processing methods change. The current version is published with its update date. Last updated: 20.07.2026.