Privacy Policy - RegisterBench (DORA RoI Builder)
Version 1.0, in force from 2026-09-28
1. Controller
The controller of personal data is NORMFORT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ (in short: Normfort sp. z o.o.), registered office at ul. Dywizjonu 303 139/55, 01-470 Warszawa, Poland, entered in the register of entrepreneurs of the National Court Register (registry court: Sąd Rejonowy dla m.st. Warszawy, XII Wydział Gospodarczy KRS) under KRS number 0001256018, NIP 5223379795, REGON 545337418, share capital PLN 5,000.00.
Contact for all data protection matters: support@registerbench.com.
2. Scope
This policy covers the marketing website and the application. It describes two different situations: data for which we are the controller (accounts, support, billing status) and data of your Register of Information, which we process on your instructions.
3. Data we process as controller
Account data. E-mail address, password hash, interface language, two-factor authentication flag, creation date, organisation membership and role. Invitations to an organisation are sent to the e-mail address given by the inviting user and carry a token valid for 7 days.
Sign-in and audit data. Authentication uses bearer access and refresh tokens; the application does not use cookie authentication. Every mutation is recorded in an append-only audit log with the actor, the organisation and the changed columns; business events such as sign-in, export, purge, webhook and organisation deletion are recorded as well.
Service e-mails. Account confirmation, password reset, invitation to an organisation, welcome, confirmation of a final export (with the file name and its sha256), warning before an automatic purge, filing deadline reminders 30, 14 and 3 days before the date set by the organisation, and payment-related messages. Messages are queued in an outbox and dispatched by a background job.
Support correspondence. The address you write from and the content of your request, in order to answer it. Support is AI-assisted with human oversight; the assistant never quotes the values of your register data in the support channel.
Error and diagnostic data. Errors raised by the application are sent to an error tracker (an EU instance or a self-hosted one) and an external uptime monitor checks the health endpoint.
Legal bases. We process the data described in this section on the following legal bases of Article 6(1) of the GDPR:
- account data: point (b), the performance of the contract, where you are a party to the agreement with us, and point (f), our legitimate interest in performing the agreement with the client organisation, where you use the service on its behalf,
- sign-in and audit data: point (f), our legitimate interest in the security of the service and in the accountability of the actions taken in it,
- service e-mails: point (b) to the extent needed to perform the agreement, otherwise point (f), our legitimate interest in communicating properly with the users of the service,
- support correspondence: point (b) where it concerns the agreement or its performance, otherwise point (f), our legitimate interest in handling requests,
- error and diagnostic data: point (f), our legitimate interest in the security of the service, in diagnosing errors and in defending against abuse,
- the subscription and billing status of the organisation: points (b), (c) and (f),
- data needed to establish, exercise or defend legal claims and to demonstrate compliance: point (f), and point (c) where a legal obligation applies.
Providing personal data is voluntary, but some data are necessary to conclude the agreement, to create an account, to use the service or to receive an answer to a request, and without them we cannot perform that action.
4. Register data: you are the controller, we are the processor
The data you enter into a Register of Information - the metadata of your ICT contracts and of your providers - is processed by us only on your instructions, as a processor. You remain the controller of that data and requests concerning it are directed to you.
By design the service stores only the ICT contract metadata required by the register templates plus user accounts. It is not designed for transactional data or for personal data of your end customers.
The terms on which we process register data as a processor are set out in the Data Processing Agreement. It forms an integral part of the Terms of Service and applies from the moment we start processing personal data on your behalf. Its list of subprocessors is the list in section 6 of this policy.
5. Where we process data
Register data and backups stay in the European Union.
6. Subprocessors and recipients
Subprocessors: OVH (hosting of the application, the database and the operations host, in the EU), Scaleway (transactional e-mail, TEM, region PAR), Cloudflare (DNS, Pages for the public website, Email Routing for kontakt@, transitional analytics beacon).
We notify clients of a change of subprocessor 30 days in advance. A change of subprocessor is decided by a human, never automatically.
Paddle acts as a separate controller for the payment data of the buyer; card data never reaches us.
7. How long we keep data
The periods below are the ones the service applies. Where the service has no fixed period, the table states the rule that decides how long the data are kept.
| Data | Period | Note |
|---|---|---|
| Working register data and import files | Deleted a configured number of days after a final export; purge_after_days per organisation, default 30, or immediately on an OrgAdmin request |
Snapshots, generated packages and the audit log are not affected by this purge |
| Sent messages in the e-mail outbox | 90 days | Operational retention |
| Import jobs | 90 days | Operational retention |
| Validation runs | Last 5 per register | Operational retention |
| Backups | 30 daily and 12 monthly copies, encrypted | Rotation |
| Data of an organisation without an active subscription, including after cancellation | Kept for as long as the organisation exists. The service does not delete such an organisation automatically: it stays in the export-blocked state, and an OrgAdmin can delete it at any time (section 12 of the Terms) | Export-all stays available in every account state |
| User account data | For as long as the account exists, and after that for the period needed to settle the relationship, to meet legal obligations and to protect against claims | The service has no self-service deletion of a user account. Deletion on request, see section 8 |
| Records of acceptance of the legal documents (who, when, which version) | For as long as the account exists, and after that for the period needed to demonstrate compliance and to protect against claims, in particular the limitation period of claims | Rule, no fixed number of days |
| Audit log | For the period needed for accountability and to establish, exercise or defend legal claims. The log is append-only and is not removed by the automatic purge or by the deletion of an organisation | Rule, no fixed number of days |
| Technical logs and error reports | For the period needed for the security of the service, the analysis of events and the handling of incidents, and no longer than these purposes justify | Rule, no fixed number of days |
| Support correspondence | For the period needed to handle the request, and after that for the period needed to protect against claims | Rule, no fixed number of days |
8. Your rights
You may request access, rectification, erasure, restriction, portability, and object to processing based on a legitimate interest; where processing is based on consent you may withdraw it at any time. You may also lodge a complaint with a supervisory authority; for the place of establishment of the controller this is the President of the Personal Data Protection Office (uodo.gov.pl).
Requests: see the address in section 1. We answer without undue delay and at the latest within one month of receiving the request. That period may be extended on the terms of Article 12(3) of the GDPR.
9. Security
Transport is encrypted and backups are encrypted before they leave our infrastructure. Optional TOTP two-factor authentication is available and an organisation can require it from all members; the minimum password length is 12 characters, with lockout. Tenant isolation is enforced by the application and covered by automated tests. Security headers, rate limits and responses that do not reveal whether an account exists are part of the hardening scope.
10. Website analytics and cookies
The marketing website is a static site hosted on Cloudflare Pages. The application runs on a server in the EU.
Website. The website sets no cookies and does not use the local storage of your browser. It carries the Cloudflare Web Analytics beacon, a script of Cloudflare that counts page views. According to Cloudflare, this beacon sets no cookies. It was measured at the vendor on 21.08.2026 that this tool does not support custom events and does not log query strings or UTM parameters. The website carries no other analytics and no advertising scripts.
Application. The application authenticates with bearer tokens and does not use cookie authentication. Its web client keeps the access token in the memory of the browser tab and stores the refresh token and your interface selections in the local storage of your browser. These items are needed to provide the service you have signed in to use and are not used for analytics or advertising. The application carries no analytics or advertising scripts.
If we add a technology that requires your consent, we will update this policy before we start using it and, where the law requires it, ask for your consent first.
11. Changes to this policy
We give 30 days notice before a change of this policy takes effect.
The Privacy Policy is a versioned document in the application; a version bump forces every existing user to accept the current version again.