Privacy Policy

Edition: 2026.07, effective as of 16 July 2026

The protection of privacy and the security of personal data constitute an integral element of the operational architecture of the Psyll platform. This Privacy Policy defines the principles for the collection, processing, storage, and deletion of user data in a manner consistent with the highest standards of digital security, the Privacy by Design and Privacy by Default principles, and applicable legal regulations, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), the Polish Act of 10 May 2018 on the Protection of Personal Data, and other relevant national and EU provisions.

Psyll undertakes to ensure full transparency in the processing of data, to minimise the scope of information collected to what is strictly necessary, and to provide users with genuine, effective control over their personal data. The Policy complies with the requirements of Google Analytics and our other analytics and payment processing partners, as described below. All data transmitted to these entities is anonymised, pseudonymised, or limited to what is strictly necessary for the relevant purpose, and its processing takes place solely on the basis of legitimate interest, contractual necessity, or the user's explicit consent (with the possibility of withdrawing consent at any time).

1. Data controller and general principles

The controller of personal data processed within the Psyll ecosystem is the operational team of the Psyll platform (hereinafter referred to as the “Administrator” or “we”). The Administrator determines the purposes and means of processing. Contact regarding data protection matters is available at dpo@psyll.com or via the contact form.

Data processing is carried out in strict accordance with the principles set out in Article 5 of the GDPR:

  • Lawfulness, fairness, and transparency — personal data is processed lawfully, fairly, and in a transparent manner in relation to the data subject. Users receive clear, plain-language information about the purposes and scope of processing.
  • Purpose limitation — personal data is collected for specified, explicit, and legitimate purposes and is not further processed in a manner incompatible with those purposes.
  • Data minimisation — only personal data that is adequate, relevant, and limited to what is necessary for the stated purposes is collected.
  • Accuracy — personal data is accurate and kept up to date. Reasonable steps are taken to rectify or erase inaccurate data without delay.
  • Storage limitation — personal data is retained in a form permitting identification of data subjects only for as long as necessary for the purposes for which it is processed.
  • Integrity and confidentiality (security) — personal data is processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, by means of appropriate technical and organisational measures.
  • Accountability — the Administrator is responsible for and able to demonstrate compliance with the above principles through documented policies, records of processing activities, regular audits, and data protection impact assessments where required.

2. Scope and purposes of data processing

Psyll processes personal data exclusively for clearly defined, legitimate operational, technical, and legal purposes. Processing is limited to what is necessary to provide, maintain, secure, and improve the platform’s services. The following categories of data and purposes apply:

  • Authentication and account management: email address, password (stored exclusively in hashed form using strong, industry-standard algorithms), and optional profile data (first name, last name, avatar URL, biographical information, and any voluntarily provided location or professional details). Purposes: secure user identification and authentication, password recovery, delivery of essential service communications, and maintenance of account integrity.
  • Social activity and user-generated content (UGC): all content published by the user (posts, analyses, comments, images, and associated metadata such as publication date, time, categories, tags, and engagement statistics). Purposes: public display of content, profile building, community interaction, and retention of records for evidentiary or dispute-resolution purposes. Published content is visible to other users unless specific privacy settings are applied.
  • Platform security and integrity: IP addresses, session metadata (User-Agent, session duration, navigation paths, referrers), system logs, telemetry data (error reports, performance metrics), and device information (browser type, operating system, screen resolution). Purposes: detection and prevention of abuse (including DDoS attacks, brute-force attempts, spam, and unauthorised access), infrastructure monitoring, and maintenance of a secure environment for all users.
  • Analytics and service development: anonymised or aggregated statistical data (number of visits, time spent on pages or sections, click patterns, traffic sources, search rankings, user flows, and feature usage). Purposes: analysis of traffic and user behaviour, optimisation of platform architecture, content, and interface, internal reporting, and evidence-based product development. Processing occurs via Google Analytics and Ahrefs, subject to applicable consent mechanisms.
  • User support and communications: name, email address, subject line, message content, and any files attached to enquiries submitted via contact or support forms. Purposes: responding to user requests, providing technical assistance, handling feedback or complaints, and improving service quality.
  • Subscription and payment data (PSYLLPRO): for users who purchase the PSYLLPRO subscription, subscription status, billing period, transaction identifiers, and limited billing information (e.g., name, email address, billing country, and the last four digits and type of the payment card) as returned to the Administrator by the payment processor. Full payment card numbers, CVV codes, and other sensitive payment credentials are collected and processed exclusively by Stripe, Inc., and are never transmitted to or stored by the Administrator. Purposes: processing subscription payments, managing subscription status and renewals, fraud prevention, invoicing, and compliance with accounting and tax obligations.
  • Advertising (free plan users): for users on the free plan, limited technical and interaction data (such as IP address, device and browser information, and non-precise location data) may be processed by the Administrator's advertising partner, Mediavine (Journey), for the purpose of serving and measuring partner advertisements. This processing is subject to the consent mechanisms described in the Cookie Policy and does not apply to users with an active PSYLLPRO subscription, who are not shown such advertisements.

The Administrator may additionally process personal data where necessary to comply with legal obligations (e.g., accounting, tax, or regulatory record-keeping) or to establish, exercise, or defend legal claims, for the periods mandated by applicable law.

3. Legal bases for processing

Processing is founded on one or more of the following legal grounds under the GDPR:

  • Article 6(1)(b) GDPR — processing necessary for the performance of a contract to which the user is a party or in order to take steps at the user's request prior to entering into a contract (account creation, service provision, UGC publication, core platform functionalities, and processing of the PSYLLPRO subscription, including payment via Stripe).
  • Article 6(1)(f) GDPR — processing necessary for the legitimate interests pursued by the Administrator or a third party, provided such interests are not overridden by the user’s interests or fundamental rights and freedoms. Legitimate interests include platform security, fraud prevention, statistical analysis for service improvement, and protection against legal claims. A balancing test is performed for each processing activity.
  • Article 6(1)(a) GDPR — processing based on the user’s freely given, specific, informed, and unambiguous consent (optional analytics and tracking technologies). Consent may be withdrawn at any time via the consent management interface, browser settings, or direct contact with the Administrator, without prejudice to the lawfulness of prior processing.
  • Article 6(1)(c) GDPR — processing necessary to comply with a legal obligation to which the Administrator is subject (retention of accounting records, tax documentation, or responses to lawful requests from public authorities). Consent logs (IP address, timestamp, browser version, and consent status) are maintained to demonstrate compliance with the accountability principle.

4. Data retention and security

The Administrator applies rigorous, multi-layered technical and organisational measures:

  • Encryption of data in transit (TLS 1.3 or higher) and at rest (AES-256 or equivalent).
  • Regular security audits, vulnerability assessments, and penetration testing.
  • Web Application Firewall (WAF), DDoS mitigation, intrusion detection/prevention systems, and 24/7 security monitoring.
  • Zero-trust architecture, multi-factor authentication for accounts and administrative access, and secure email protocols (SPF, DKIM, DMARC).
  • Data Protection Impact Assessments (DPIA) conducted for high-risk processing activities.
  • Mandatory staff training on data protection and information security.

Retention periods (applied on a data-category basis):

  • Account data and associated UGC: duration of active account status plus 30 days following deletion (buffer period for appeals or recovery).
  • Security logs, IP addresses, and telemetry: maximum 12 months, or shorter once the data is no longer required.
  • Google Analytics data: retained in accordance with Google’s policy (typically up to 26 months for aggregated, anonymised data).
  • Ahrefs analytics data: retained in aggregated form in accordance with Ahrefs’ data retention practices, for as long as necessary for search and traffic analytics purposes.
  • Subscription and billing records (PSYLLPRO): retained for the duration of the active subscription and, thereafter, for the statutory period required for accounting, tax, and legal purposes (generally up to 5 years, in accordance with Polish accounting law). Full payment card data is retained solely by Stripe in accordance with its own retention policy.
  • Support and communication records: up to 3 years to address follow-up enquiries or legal matters.
  • Consent logs: retained for the period necessary to demonstrate compliance, aligned with applicable limitation periods.

Upon account deletion, personal data is permanently erased from production systems and encrypted backups, except where retention is required by law. In the event of a personal data breach likely to result in a high risk to individuals’ rights and freedoms, affected users and, where required, the competent supervisory authority will be notified without undue delay and no later than 72 hours after the breach becomes known.

5. Data sharing and international transfers

Psyll does not sell, rent, lease, or otherwise commercially exploit personal data. Disclosure to third parties occurs only to the minimum extent necessary and under appropriate contractual safeguards (Data Processing Agreements or equivalent):

  • Infrastructure providers: hosting, cloud, and content delivery services located within the EEA or protected by Standard Contractual Clauses and supplementary safeguards.
  • Analytical services: Google Analytics and Ahrefs — data is shared in anonymised or pseudonymised form solely for statistical, traffic, and content-performance analysis purposes. Further details are set out in the separate Cookie Policy. Users may withdraw consent at any time.
  • Payment processing: Stripe, Inc. — limited billing data (name, email address, billing country, transaction and subscription identifiers) is shared with Stripe solely for the purpose of processing PSYLLPRO subscription payments. Full payment card data is collected and held exclusively by Stripe and is never accessible to the Administrator. Further details are set out in the Purchaser Terms.
  • Advertising partner: Mediavine (Journey) — for Users on the free plan only, limited technical and interaction data may be shared with Mediavine and its advertising demand partners for the purpose of serving and measuring partner advertisements, subject to the consent mechanisms described in the Cookie Policy. This does not apply to active PSYLLPRO subscribers.
  • Legal obligations: disclosure to courts, law enforcement, or regulatory authorities only pursuant to a valid legal order or statutory requirement.

Any transfer of personal data outside the EEA is effected exclusively on the basis of European Commission-approved Standard Contractual Clauses, accompanied by a documented transfer impact assessment and, where necessary, additional technical or organisational safeguards.

6. User rights (data sovereignty)

Data subjects enjoy the following rights under the GDPR. Requests are handled free of charge (except where manifestly unfounded or excessive) and responded to within one month (extendable by up to two further months in complex cases). Requests may be submitted via account settings, the website form, or email to dpo@psyll.com. Reasonable identity verification may be required.

  • Right of access (Art. 15) — confirmation of processing and access to personal data together with processing information; portable copy available in structured, machine-readable format.
  • Right to rectification (Art. 16) — correction of inaccurate data and completion of incomplete data.
  • Right to erasure (“right to be forgotten”, Art. 17) — deletion of personal data, subject to statutory exceptions.
  • Right to restriction of processing (Art. 18) — limitation of processing under specified conditions.
  • Right to data portability (Art. 20) — receipt of personal data in a structured, commonly used, machine-readable format and transmission to another controller.
  • Right to object (Art. 21) — objection to processing based on legitimate interests or for direct marketing (including profiling).
  • Right to withdraw consent (Art. 7) — withdrawal at any time with immediate effect on future processing.
  • Right not to be subject to solely automated decision-making (Art. 22) — Psyll does not currently conduct automated decision-making or profiling that produces legal or similarly significant effects.

Data subjects also have the right to lodge a complaint with the competent supervisory authority, in particular the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych – UODO), ul. Stawki 2, 00-193 Warsaw, Poland, or with the supervisory authority in their country of residence or place of work.

7. Additional provisions

  • Changes to the policy: The Administrator reserves the right to amend this Privacy Policy to reflect changes in processing activities, legal requirements, or platform functionality. Material changes will be communicated by email (where an address is registered) or prominent notice on the platform. Continued use after the effective date constitutes acceptance of the revised policy. The current version is always available at https://psyll.com/privacy-policy.
  • Governing law and jurisdiction: This Privacy Policy is governed by Polish law and applicable EU law (including the GDPR). Any disputes shall be subject to the exclusive jurisdiction of the courts of the Republic of Poland.
  • Contact: For all matters relating to this Privacy Policy or personal data processing, please write to contact@psyll.com or use the online form. The Data Protection Officer may be contacted directly at dpo@psyll.com.