Last updated:
This Privacy Policy describes how the Zadza platform collects, processes, and protects users' personal data. By using the site, you agree to the data processing terms outlined below.
Data controller
The operator of the Zadza Platform is currently undergoing formal registration. For matters concerning the processing of personal data during this transitional period, contact us at [email protected]. Use of the Platform remains subject to the mandatory provisions of the GDPR and applicable consumer-protection law. The full controller record will be published once registration is complete.
1. What data we collect
When using the platform, we may collect the following information:
- Phone number — for communication between users and account verification
- IP address and device data — to ensure security and prevent fraud
- Cookies — to save settings, language, and improve site performance
- Listing data — text, photos, and contact information that you add
- Browsing and activity data — for personalization and service improvement
2. How we use data
- Providing and maintaining platform functionality
- Content moderation and fraud prevention
- Improving user experience and personalization
- Communicating with users regarding support issues
3. Data protection
Identifying user data (IP addresses, device identifiers, session identifiers) is stored as salted hashes — a one-way operation used as a pseudonymisation measure under Art. 32(1)(a) GDPR. The only exception is the phone number, which is kept in plaintext because it is published in listings to enable direct user-to-user contact. The lawful basis for processing the phone number is the controller's legitimate interest — Art. 6(1)(f) GDPR / RODO (enabling communication between users of a classifieds platform). The Legitimate Interest Assessment (LIA) is available on request at [email protected].
Additional security measures:
- Data encryption during transmission (HTTPS/TLS)
- Hashing of personal data when stored in the database
- Limited access to data within the team
- Regular security audits and threat monitoring
4. Cookies and tracking
We use cookies for the correct operation of the site: saving language, authorization, and user settings. You can disable cookies in your browser settings, but this may limit the functionality of the site.
We do not use third-party advertising trackers and do not sell data to third parties.
Cross-border data transfers
Your personal data is stored and processed on our technical operator's servers located in Ukraine. Because Ukraine does not have an adequacy decision from the European Commission (GDPR Art. 45), the transfer is carried out under the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914 of 4 June 2021) — GDPR Art. 46(2)(c). We apply additional technical and organisational measures (TLS in transit, encryption and pseudonymisation at rest, access control) consistent with the EDPB 01/2020 recommendations. A copy of the clauses applied is available on request at: [email protected].
5. Transfer of data to third parties
We do not sell or transfer your personal data to third parties. Since all data is stored in hashed form, we cannot technically provide users' personal information.
At the request of law enforcement agencies, we can only provide:
- The phone number linked to the account
- Information published by the user in the listing (text, photos, contacts)
6. Your rights
You have the right to:
- Request access to your personal data
- Demand correction of inaccurate data
- Request deletion of your account and all associated data
- Withdraw consent to data processing
- Request data portability in a machine-readable format
- Object to processing of data based on legitimate interests
- Lodge a complaint with UODO (Urząd Ochrony Danych Osobowych)
To exercise these rights, contact us at [email protected] or via the "Write to us" section. We respond within 30 days in accordance with the GDPR / RODO. Independently, you have the right to lodge a complaint with UODO (Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Polska) — https://uodo.gov.pl/.
7. Data retention period
Retention periods depend on the category of data: account data and listing content — for the duration of service use, then deleted within 30 days after account deletion; accounting and tax records (if any) — 5 years from the end of the fiscal year, per Art. 86 § 1 of the Polish Tax Ordinance and CIT/VAT obligations; server access logs — up to 12 months; backups — up to 90 days with automatic rotation; phone-deduplication ledger (digest of the number) — 12 months from the last account activity. These periods may be extended where required by law or to defend legal claims.
8. Changes to the policy
We may update this Privacy Policy. The current version is always available on this page. By continuing to use the site after changes, you agree to the updated policy.