Privacy Policy

Last updated: 2026-08-23

This document describes how SoftwareCat ("SoftwareCat", "we", "us") processes the personal data of users who visit softwarecat.io and who book a meeting through our calendar or contact us by email.

SoftwareCat operates on the principles of data sovereignty and privacy by default - we collect only what is necessary, and booking data is stored within the European Union.

1. Data Controller

The controller of your personal data is SoftwareCat, based in Poznań, Poland, operated by Bartosz Walczak. Tax ID (NIP): 7812086596. Contact: [email protected].

2. What Data We Collect

Booking a meeting: full name, email address, any information you optionally provide in the note/message field, and meeting metadata (date, time, time zone).

Email contact: any data you choose to share with us in your message.

Technical data: to ensure security and the proper functioning of the server, limited technical data may be processed, such as your IP address and basic device/browser information (server logs).

Website analytics: We use a self-hosted, cookieless analytics tool to understand how visitors use our website. It does not collect personal data - it records only aggregated, anonymised statistics such as page views, referral sources, and country-level geographic data. No individual visitor is tracked or identified. Because we self-host this tool on our own EU infrastructure, no data is sent to any external servers.

Providing your data is voluntary, but without an email address we have no way to confirm your booking or respond to your enquiry. We do not knowingly collect special categories of data (e.g. health, beliefs), and we ask that you do not submit such data in the booking form.

3. Purposes and Legal Basis

  • Arranging and holding your booked meeting - Art. 6(1)(b) GDPR (steps taken at your request prior to entering into an agreement).
  • Contacting you regarding your booking or enquiry - Art. 6(1)(f) GDPR (legitimate interest in providing a response).
  • Ensuring the security and proper functioning of the Site - Art. 6(1)(f) GDPR (legitimate interest).
  • Understanding how visitors use our website in aggregate - Art. 6(1)(f) GDPR (legitimate interest in improving the Site). No personal data is processed for this purpose.

We do not make decisions about you based solely on automated processing that would produce legal effects. We do not carry out profiling for marketing purposes.

4. Booking Tool

To handle bookings, we use booking software that we self-host on our own infrastructure (within the EEA). This means that the data you provide when booking is processed and stored on our servers within the European Union, and not in the external cloud service of the software provider.

5. Data Recipients

We work with trusted providers:

  • Hosting provider (data centre within the EEA) - hosting of the application, server, and our self-hosted instances of the booking tool and analytics tool.
  • Google (Google Calendar) - synchronisation of booked meetings with our calendar. After a booking is made, the meeting data (your full name, email address, and meeting details) is saved to Google Calendar so that we can manage appointments.

We do not sell data to third parties.

6. Transfers Outside the EEA

Booking data and Site data are stored on servers within the European Economic Area.

The exception is synchronisation with Google Calendar: Google LLC is based in the United States, so we treat the transfer of data to this service as a transfer outside the EEA. The basis for this transfer is the European Commission's adequacy decision (EU-US Data Privacy Framework) together with Standard Contractual Clauses.

7. Retention Period

We retain booking data and correspondence for a maximum of 24 months from the last contact, unless a longer retention period is required to perform an agreement or to meet accounting obligations. Data that you ask us to delete is erased, unless we are legally obliged to retain it.

8. Your Rights

  • Access to your data and to receive a copy of it.
  • Rectification, erasure, or restriction of processing.
  • Portability of your data to another controller in a commonly used format - Art. 20 GDPR.
  • Objection to processing based on legitimate interest.
  • Withdrawal of consent at any time - this does not affect the lawfulness of processing carried out before the withdrawal (applies to processing based on consent).
  • Lodging a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, Warsaw, Poland).

To exercise these rights, write to [email protected].

9. Cookies

The embedded booking widget uses cookies and browser storage necessary for the booking function to work properly. Because the software is self-hosted on our own domain, these are first-party cookies (not third-party). They are functional and security cookies, including:

  • session cookies enabling the booking process and time-slot selection,
  • security tokens (CSRF) protecting against abuse.

These cookies are strictly necessary to provide the booking service - without them the booking form will not work - and they are not used for tracking or marketing purposes.

Our website analytics are powered by a self-hosted analytics tool that is fully cookieless and does not use any browser storage. No consent banner is required for analytics, and no personal data is collected or transmitted to third parties.

You can change your cookie preferences at any time in your browser settings.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest version. We will communicate any material changes in an appropriate manner.

11. Contact

For any matters concerning this policy or the processing of your data, write to:

SoftwareCat
Email: [email protected]