011. Controller and the TacPrint ecosystem
The controller is SKYSYSNET sp. z o.o., ul. Krakusa 24/2, 30-530 Kraków, Poland, KRS 0001018100, tax ID 6793259574, REGON 524403301. TacPrint is the Company’s brand. Privacy contact: [email protected], +48 880 477 136 or the registered address marked “data protection”.
This Policy covers tacprint.com, the shop.tacprint.com store, the app.tacprint.com custom-print application, accounts, Model analysis and quotes, orders, payments, delivery, contact, complaints, newsletter and security events. These surfaces form one brand ecosystem with the same controller, while the ready-made store and quote application are separate technical systems with separate sessions, carts and order histories.
022. Sources and categories of data
Data comes from you, a person ordering for an organisation, a user naming a recipient, your browser or device and providers of payment, delivery, authentication or communication.
We may process identity and contact data, account data, company and billing data, delivery addresses, quotes, orders, payments and refunds, correspondence, complaints, consent records, Models and project documents, attachment metadata, IP address, browser and device data, session and security logs, errors and privacy settings.
Optional analytics and behaviour recordings are collected only after the relevant consent.
033. Contact, quotes and pre-contract steps
Form, email, phone and Model data are used to answer enquiries and prepare a Quote under Article 6(1)(b) GDPR where you ask us to take steps before a contract, or Article 6(1)(f) for general and B2B communication, abuse prevention and service administration.
Required fields are needed to handle the enquiry. Phone and attachments are optional unless the specific project cannot be assessed without them. The form checkbox acknowledges receipt of the privacy notice; it is not consent used as the basis for answering.
044. Account, order, payment and delivery
Account, Model, configuration, address, order and support data are used to contract, take payment, produce, inspect, deliver, refund and handle complaints under Article 6(1)(b) GDPR.
The store and quote application may verify a user against the same identity source but keep their own session tokens and customer records. A user identifier and basic account data are linked only as needed for sign-in and the relevant service; ready-made orders are not written directly into the custom-print database.
Sales, tax and accounting records rely on Article 6(1)(c). Fraud prevention, audit trails and legal claims rely on Article 6(1)(f). Full card numbers are not stored by us; Stripe may act as an independent controller for regulated payment and fraud-prevention purposes.
055. Models and confidentiality
Models and documentation are used only for analysis, quoting, production, inspection, delivery, complaints, backups and security. Access is limited to people and providers who need it for the task.
Models are not used to train publicly available AI models or published for marketing without a separate basis. Do not include sensitive-category data, child data or unnecessary secrets in a Model or description.
066. Newsletter and electronic marketing
Email and consent evidence are processed under Article 6(1)(a) GDPR and the consent required by Polish electronic communications law. Double opt-in is used. Consent is optional, is not required to order and can be withdrawn through every message or by contact.
After unsubscribe, a minimal suppression record may be retained to prove compliance, prevent renewed sending without fresh consent and defend legal claims. It is not used for further marketing.
077. Analytics, experience measurement and marketing
Google Analytics 4 measures traffic and events after analytics consent. Microsoft Clarity may create heatmaps and behaviour recordings after separate experience-measurement consent. Google Tag Manager may start configured marketing tags only after marketing consent.
Optional device access relies on consent under electronic communications law and further processing on Article 6(1)(a) GDPR. Refusal does not disable core features.
088. Security and error diagnostics
Logs, rate limits, bot detection, backups and error diagnostics protect availability, integrity and resilience under Article 6(1)(f) and, where applicable, contract performance.
Sentry may receive minimised error data without default user identity; query parameters, form content, cookies and confidential headers are removed. Cloudflare may process IP and request data for protection, routing and delivery. These functions are not advertising.
099. Recipients
Recipients may include authorised Company personnel and providers of infrastructure, private file storage, self-hosted authentication, Cloudflare, email and notifications, Sentry, Stripe, Sendcloud or other identified delivery operators, accounting, legal support, Google and Microsoft, only as required by the feature used.
Messages may be delivered through the current SMTP provider or Resend. If operational alerts are enabled, Slack may receive limited contact or newsletter event data such as contact details, subject and a short message preview so an operator can respond.
Providers may be processors or separate controllers, particularly payment and delivery providers in their regulated roles. We do not sell personal data.
1010. Transfers outside the EEA
Some providers use infrastructure outside the EEA, particularly in the United States. Transfers rely, as applicable, on an adequacy decision including the EU–US Data Privacy Framework for certified recipients, or Standard Contractual Clauses and supplementary safeguards.
Current provider, role and transfer details can be requested from [email protected].
1111. Retention
Account data is kept while active and afterwards as needed for orders, security and claims. Order, payment, invoice and accounting data is kept for statutory and limitation periods.
Enquiries and attachments remain until the matter ends and then for a period justified by project follow-up and claims. Unlinked temporary uploads may be removed after a short technical period; order files remain while fulfilment, complaints, backups or agreed repeat production requires them.
Newsletter data remains until withdrawal, with consent and suppression evidence kept as needed to demonstrate compliance. GA4 cookies normally last up to two years. Clarity recordings normally last 30 days and aggregated or labelled data up to 13 months. The local cookie preference expires after 180 days.
1212. Required and optional data
Required account, quote, payment and delivery data is necessary for the relevant contract or function. Invoice fields may be legally required. Optional fields, newsletter consent and optional technology consent are voluntary.
If you provide another person’s details, such as a recipient or colleague, you should have a lawful basis and provide this notice where required.
1313. Your rights
You may request access, rectification, erasure, restriction and, where applicable, portability. You may object to legitimate-interest processing for reasons related to your situation.
Consent can be withdrawn as easily as it was given without affecting earlier lawful processing. Contact [email protected]; identity verification may be required. We normally respond within one month and explain any lawful extension.
1414. Complaint, automated analysis and children
You may complain to the President of the Polish Personal Data Protection Office, ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland, uodo.gov.pl. Contacting us first is optional.
Geometry, time, material and price may be analysed automatically, but we do not make solely automated decisions producing legal or similarly significant effects; a project may be referred to a person.
The service is not directed at children. A minor should use it with a legal representative, who may report data supplied without a proper basis.
1515. Security and updates
Measures appropriate to risk include encrypted transport, access control, least privilege, private Model storage, backups, event logging and incident procedures. No system is absolutely secure.
We update this Policy when law, processing or providers change and show its version and effective date. Material changes affecting an active service are communicated through an appropriate channel.
IDController and service provider
SKYSYSNET Sp. z o.o. · operator of the TacPrint
ul. Krakusa 24/2
30-530 Kraków, Poland
KRS: 0001018100 · NIP: 6793259574 · REGON: 524403301
Share capital: 10 000,00 PLN
[email protected] · +48 880 477 136
This document describes the currently implemented system and does not limit rights granted by mandatory law.