Desk & Park Privacy Policy
This privacy policy explains what personal data is processed in connection with the use of the Desk & Park service available at deskandpark.com, for what purposes and on what legal bases, to whom it is disclosed, and what rights data subjects have. Capitalized terms have the meanings given to them in the Terms of Service.
1. Data Controller
The data controller (subject to Section 4) is Pixel of Software sp. z o.o., with its registered office at: ul. Rydygiera 13, 01-793 Warszawa, KRS: 0000525252, NIP: 5252525252 (the "Operator", "we"). We process data in accordance with Regulation (EU) 2016/679 (the "GDPR"). Contact for all data protection matters: hello@pixelofsoftware.com.
2. What Data We Process
- account and identity data — e-mail address, first and last name (if provided), role within the Organization and technical account identifiers;
- Organization data — name, space configuration (maps of desks, parking spaces and meeting rooms) and settings;
- reservation data entered by the Organization — data of the Organization's Users (e.g. first and last name, e-mail address), reservations of desks, parking spaces and meeting rooms, and any other information the Organization chooses to collect (e.g. vehicle registration numbers);
- billing data — invoice details, payment history and Stripe transaction identifiers; full payment card data is never transmitted to us;
- technical and security logs — IP address, browser and device information, timestamps, sign-in events and audit log entries;
- e-mail verification code (OTP) records— hashed one-time codes, the associated e-mail address, validity period and number of usage attempts.
3. Purposes and Legal Bases of Processing
- entering into and performing the agreement for the Service — including account creation, e-mail code authentication, handling reservations, subscriptions and support — Article 6(1)(b) GDPR;
- compliance with legal obligations to which the Operator is subject, in particular tax and accounting obligations (issuing and retaining billing documents) — Article 6(1)(c) GDPR;
- ensuring the security of the Service, preventing abuse and fraud, diagnostics and monitoring of the Service, and establishing, pursuing and defending legal claims — the Operator's legitimate interest — Article 6(1)(f) GDPR.
4. Our Roles: Controller and Processor
With respect to Customer and Administrator account data, billing data and technical logs, the Operator acts as a data controller — it independently determines the purposes and means of their processing.
With respect to reservation data and User data entered into the Service by an Organization, the data controller is the Organization (the Customer), and the Operator acts solely as a data processor within the meaning of Article 28 GDPR — it processes this data only on the Organization's documented instructions and for the purpose of providing the Service, within that Organization's isolated database.
Persons whose data was entered by an Organization (e.g. the Customer's employees) should address requests concerning their data primarily to their Organization; the Operator assists the Organization in fulfilling such requests.
5. Recipients and Sub-processors
We use the following providers (sub-processors) to deliver the Service:
- Stripe Payments Europe, Ltd. — payment and subscription processing;
- Neon — PostgreSQL database hosting (EU region — Frankfurt);
- Railway — API (backend) hosting;
- Vercel — frontend application hosting;
- Functional Software, Inc. (Sentry) — application error monitoring (EU data region);
- Google Ireland Limited (Firebase Cloud Messaging) — delivery of push notifications to the mobile app (device token);
- e-mail service provider — delivery of verification codes and notifications.
Data may also be disclosed to entities authorized under applicable law (e.g. public authorities) and — to the extent necessary — to the Operator's legal and accounting advisers.
6. Transfers Outside the EEA
Some of our providers may process data outside the European Economic Area, in particular in the United States. In such cases, transfers take place using the safeguards provided for in the GDPR, in particular the standard contractual clauses (SCCs) approved by the European Commission and, for certified providers, on the basis of the adequacy decision concerning the EU–US Data Privacy Framework. Information about the safeguards used can be obtained by contacting us.
7. Data Retention Periods
- account and Organization data — for the duration of the active subscription and for 30 days after termination of the agreement, after which it is permanently and irreversibly deleted;
- billing documents and data required for tax settlements — for 5 years from the end of the year in which the tax obligation arose;
- security and audit logs — for up to 12 months;
- verification code (OTP) records — until the code expires; related security events are retained as security logs.
8. Data Subject Rights
To the extent the Operator is the data controller, every data subject has the right to: access their data, have it rectified or erased, restrict its processing, data portability, and to object to processing based on legitimate interest (Article 6(1)(f) GDPR).
Requests to exercise these rights may be sent to hello@pixelofsoftware.com. Every data subject also has the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland. Where the data controller is the Organization (Section 4), requests should be addressed primarily to that Organization.
9. Cookies and Local Storage
We use only strictly necessary cookies: session and authentication cookies that maintain the signed-in User's secure session. The language preference (PL/EN) is stored locally in the browser (localStorage) and is not shared with third parties.
We do not use advertising cookies, marketing trackers or profiling for advertising purposes.
10. Data Security
In particular, we apply the following technical and organizational measures:
- encryption of data in transit (TLS);
- hashing of one-time codes and secrets (bcrypt / SHA-256);
- tenant isolation — each Organization uses a separate, isolated database;
- role-based access control and the principle of least privilege;
- audit logs of administrative operations;
- backups and security incident response procedures.
11. Changes to This Policy
This privacy policy may be updated, in particular in the event of changes to the Service, changes of providers or changes in the law. We will inform Administrators of material changes by e-mail or by a notice within the Service with reasonable advance notice. The current version of the policy is always available at deskandpark.com.
12. Contact
Questions about this policy and requests concerning personal data should be sent by e-mail to: hello@pixelofsoftware.com or in writing to: Pixel of Software sp. z o.o., ul. Rydygiera 13, 01-793 Warszawa.
Version 1.0 — effective 10 July 2026