Desk & Park Privacy Policy

This privacy policy explains what personal data is processed in connection with the use of the Desk & Park service available at deskandpark.com, for what purposes and on what legal bases, to whom it is disclosed, and what rights data subjects have. Capitalized terms have the meanings given to them in the Terms of Service.

1. Data Controller

The data controller (subject to Section 4) is Pixel of Software sp. z o.o., with its registered office at: ul. Adama Mickiewicza 37/58, 01-625 Warszawa, KRS: 0001261874, NIP: 5253103170 (the "Operator", "we"). We process data in accordance with Regulation (EU) 2016/679 (the "GDPR"). Contact for all data protection matters: hello@pixelofsoftware.com.

2. What Data We Process

  • account and identity data — e-mail address, first and last name (if provided), role within the Organization and technical account identifiers;
  • Organization data — name, space configuration (maps of desks, parking spaces and meeting rooms) and settings;
  • reservation data entered by the Organization — data of the Organization's Users (e.g. first and last name, e-mail address), reservations of desks, parking spaces and meeting rooms, and any other information the Organization chooses to collect (e.g. vehicle registration numbers);
  • billing data — invoice details, payment history and Stripe transaction identifiers; full payment card data is never transmitted to us;
  • technical and security logs — IP address, browser and device information, timestamps, sign-in events and audit log entries;
  • sales enquiries — the e-mail address, company name and IP address submitted through the contact form on the Service’s public pages;
  • e-mail verification code (OTP) records— hashed one-time codes, the associated e-mail address, validity period and number of usage attempts.

3. Purposes and Legal Bases of Processing

  • entering into and performing the agreement for the Service — including account creation, e-mail code authentication, handling reservations, subscriptions and support — Article 6(1)(b) GDPR;
  • compliance with legal obligations to which the Operator is subject, in particular tax and accounting obligations (issuing and retaining billing documents) — Article 6(1)(c) GDPR;
  • ensuring the security of the Service, preventing abuse and fraud, diagnostics and monitoring of the Service, and establishing, pursuing and defending legal claims — the Operator's legitimate interest — Article 6(1)(f) GDPR.

4. Our Roles: Controller and Processor

With respect to Customer and Administrator account data, billing data and technical logs, the Operator acts as a data controller — it independently determines the purposes and means of their processing.

With respect to reservation data and User data entered into the Service by an Organization, the data controller is the Organization (the Customer), and the Operator acts solely as a data processor within the meaning of Article 28 GDPR — it processes this data only on the Organization's documented instructions and for the purpose of providing the Service, within that Organization's isolated database.

Persons whose data was entered by an Organization (e.g. the Customer's employees) should address requests concerning their data primarily to their Organization; the Operator assists the Organization in fulfilling such requests.

5. Recipients and Sub-processors

We use the following providers (sub-processors) to deliver the Service:

  • Stripe Payments Europe, Ltd. — payment and subscription processing;
  • Neon — PostgreSQL database hosting (EU region — Frankfurt);
  • Railway — API (backend) hosting;
  • Vercel — frontend application hosting;
  • Functional Software, Inc. (Sentry) — application error monitoring (EU data region);
  • Google Ireland Limited (Firebase Cloud Messaging) — delivery of push notifications to the mobile app (device token);
  • e-mail service provider — delivery of verification codes and notifications;
  • Chatlio, Inc. (USA) and Slack Technologies, LLC (USA) — support chat on the public pages of the Service (chat widget and conversation handling). The chat script is loaded only after you press the "Chat with us" button; the conversation and any data you provide in it reach our Slack channel.

Data may also be disclosed to entities authorized under applicable law (e.g. public authorities) and — to the extent necessary — to the Operator's legal and accounting advisers.

6. Transfers Outside the EEA

Some of our providers may process data outside the European Economic Area, in particular in the United States. In such cases, transfers take place using the safeguards provided for in the GDPR, in particular the standard contractual clauses (SCCs) approved by the European Commission and, for certified providers, on the basis of the adequacy decision concerning the EU–US Data Privacy Framework. Information about the safeguards used can be obtained by contacting us.

7. Data Retention Periods

  • account and Organization data — for the duration of the active subscription and for 30 days after termination of the agreement, after which it is permanently and irreversibly deleted;
  • billing documents and data required for tax settlements — for 5 years from the end of the year in which the tax obligation arose;
  • security and audit logs — for up to 12 months;
  • support tickets together with any attached screenshots — 12 months from the day the ticket is closed; open tickets are kept until they are closed;
  • sales enquiries from the contact form — 12 months from the closing of the enquiry; unresolved enquiries are kept until they are closed;
  • verification code (OTP) records — until the code expires; related security events are retained as security logs.

8. Data Subject Rights

To the extent the Operator is the data controller, every data subject has the right to: access their data, have it rectified or erased, restrict its processing, data portability, and to object to processing based on legitimate interest (Article 6(1)(f) GDPR).

Requests to exercise these rights may be sent to hello@pixelofsoftware.com. Every data subject also has the right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland. Where the data controller is the Organization (Section 4), requests should be addressed primarily to that Organization.

9. Cookies and Local Storage

We use only strictly necessary cookies: session and authentication cookies that maintain the signed-in User's secure session. The language preference (PL/EN) is stored locally in the browser (localStorage) and is not shared with third parties.

The support chat widget (Chatlio) stores a conversation identifier in your browser only after you open the chat yourself; until then no chat script is loaded.

We do not use advertising cookies, marketing trackers or profiling for advertising purposes.

10. Data Security

In particular, we apply the following technical and organizational measures:

  • encryption of data in transit (TLS);
  • hashing of one-time codes and secrets (bcrypt / SHA-256);
  • tenant isolation — each Organization uses a separate, isolated database;
  • role-based access control and the principle of least privilege;
  • audit logs of administrative operations;
  • backups and security incident response procedures.

11. Changes to This Policy

This privacy policy may be updated, in particular in the event of changes to the Service, changes of providers or changes in the law. We will inform Administrators of material changes by e-mail or by a notice within the Service with reasonable advance notice. The current version of the policy is always available at deskandpark.com.

12. Contact

Questions about this policy and requests concerning personal data should be sent by e-mail to: hello@pixelofsoftware.com or in writing to: Pixel of Software sp. z o.o., ul. Adama Mickiewicza 37/58, 01-625 Warszawa.

Version 1.2 — effective 22 September 2026