Privacy Policy

This translation is provided for convenience only. In the event of any discrepancies, the Polish version shall prevail.

This Privacy Policy describes the rules for storing and accessing data on the devices of Users who use the Service for services supplied electronically by the Administrator. It also explains how personal data voluntarily provided by Users through tools available in the Service is collected and processed.

This Privacy Policy forms an integral part of the Terms of Service, which define the rules, rights, and obligations applicable to Users of the Service.

1. Definitions

Service means the Laterlane website available at https://app.laterlane.com.

External Service means websites operated by partners, service providers, or recipients cooperating with the Administrator.

Service and Data Administrator means the Service Administrator and Data Administrator (hereinafter the Administrator), the natural person “Kamil Tyborowski,” providing electronic services through the Service.

User means a natural person to whom the Administrator provides electronic services through the Service.

Device means an electronic device and its software through which a User accesses the Service.

Cookies means text data collected in files stored on a User’s Device.

GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons concerning the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC.

Personal data means information relating to an identified or identifiable natural person. An identifiable person is someone who can be identified directly or indirectly, particularly by reference to a name, identification number, location data, online identifier, or factors specific to that person’s physical, physiological, genetic, mental, economic, cultural, or social identity.

Processing means any operation or set of operations performed on personal data, whether automated or not, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.

Restriction of processing means marking stored personal data to limit its future processing.

Profiling means automated processing that uses personal data to evaluate personal aspects of a natural person, particularly work performance, economic situation, health, preferences, interests, reliability, behaviour, location, or movements.

Consent means a freely given, specific, informed, and unambiguous indication of the data subject’s wishes, expressed through a statement or clear affirmative action, agreeing to the processing of personal data concerning them.

Personal data breach means a security breach resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored, or otherwise processed.

Pseudonymisation means processing personal data so it can no longer be attributed to a specific person without additional information, provided that information is stored separately and protected by technical and organisational safeguards.

Anonymisation means an irreversible operation that destroys or overwrites personal data so a record can no longer be identified or linked to a specific User or natural person.

2. Data Protection Officer

The Administrator has not appointed a Data Protection Officer under Article 37 of the GDPR.

Questions about data processing, including personal data, should be directed to the Administrator.

3. Types of Cookies

First-party Cookies are placed on and read from the User’s Device by the Service’s information system.

Third-party Cookies are placed on and read from the User’s Device by External Services. Scripts from External Services that may place Cookies on User Devices have been deliberately included through scripts and services installed in the Service.

Session Cookies are placed on and read from the User’s Device during one session and are removed when that session ends.

Persistent Cookies remain on the User’s Device until manually removed. They are not automatically deleted at the end of a session unless the Device is configured to remove Cookies at that time.

4. Data storage security

Cookie storage and access are handled through built-in browser mechanisms. These mechanisms do not permit access to unrelated data on the User’s Device or to data from other websites, including personal or confidential information. They also make transferring viruses, Trojan horses, or other malicious software through Cookies practically impossible.

First-party Cookies used by the Administrator are safe for User Devices and do not contain scripts, content, or information that could threaten personal data or Device security.

Third-party Cookies may be used by carefully selected partners. The Administrator makes reasonable efforts to verify partners and prioritises established providers with broad public trust. However, the Administrator does not fully control third-party Cookie content and, to the extent permitted by law, is not responsible for its security, contents, or use by scripts supplied by External Services. Relevant partners are listed later in this Policy.

Cookie controls

Users may change settings for storing, deleting, and accessing Cookies for any website at any time.

Instructions for managing Cookies are available from the providers of common browsers:

  • Cookie management in Chrome,
  • Cookie management in Opera,
  • Cookie management in Firefox,
  • Cookie management in Edge,
  • Cookie management in Safari,
  • Cookie management in Internet Explorer 11.

Users may delete all previously stored Cookies at any time using the tools available on the Device through which they access the Service.

Risks on the User’s side — the Administrator applies reasonable technical safeguards to protect Cookie data. Data security also depends on User activity. The Administrator is not responsible for interception, session impersonation, or deletion caused by deliberate or accidental User actions, viruses, Trojan horses, or spyware infecting a User’s Device. Users should follow safe internet practices.

Personal data storage — the Administrator makes every effort to keep voluntarily supplied personal data secure, restrict access, and use it only for its intended purposes. Appropriate physical and organisational safeguards are used to protect data against loss.

Password storage — passwords are stored in encrypted form using current standards and guidance. Decrypting account passwords supplied through the Service is practically impossible.

5. Purposes for which Cookies are used

  • improving and facilitating access to the Service,
  • personalising the Service for Users,
  • enabling sign-in to the Service.

6. Purposes of personal data processing

Personal data voluntarily supplied by Users may be processed to:

  • register and maintain a User account and related functionality,
  • communicate with Users about the Service and data protection,
  • pursue the Administrator’s legitimate interests.

Anonymous data collected automatically is processed to pursue the Administrator’s legitimate interests.

7. Cookies from External Services

The Service uses JavaScript scripts and web components supplied by partners that may place their own Cookies on User Devices. Users can decide which Cookies individual websites may use through their browser settings.

Email delivery service:

  • Brevo

Third-party services are outside the Administrator’s control. These providers may change their terms, privacy policies, processing purposes, and use of Cookies at any time.

8. Types of data collected

The Service collects User data. Some data is collected automatically and anonymously, while other personal data is supplied voluntarily when Users subscribe to or use particular services.

Anonymous data collected automatically:

  • IP address,
  • browser type,
  • screen resolution,
  • pages opened within the Service,
  • time spent on a page,
  • operating system,
  • previous page address,
  • referring page address,
  • browser language.

Data collected during registration:

  • email address, name.

Some non-identifying data may be stored in Cookies or transferred to a statistical service provider.

9. Third-party access to personal data

As a rule, the Administrator is the only recipient of personal data supplied by Users. Data collected while providing services is not transferred or sold to third parties.

Entities responsible for infrastructure and services needed to operate the Service may access data, most commonly under a data processing agreement. These include:

  • hosting companies and related service providers,
  • email delivery providers.

Email processing

The Administrator uses Brevo to send emails relating to the Service. Email addresses and other data required to prepare and deliver those messages are transferred to, stored by, and processed through that external provider. Brevo may amend its privacy policy without the Administrator’s consent.

Hosting, VPS, and dedicated server data processing

The Administrator uses external hosting, VPS, or dedicated server providers, including OVH sp. z o.o. and netcup GmbH. Data collected and processed through the Service is stored and processed within infrastructure located in the European Union. Provider personnel may access data while carrying out maintenance. Such access is governed by agreements between the Administrator and the provider.

10. How personal data is processed

Personal data supplied voluntarily by Users:

  • will not be transferred outside the European Union unless published through an individual User action, such as posting a comment or entry that becomes available to visitors,
  • will not be used for automated decision-making or profiling,
  • will not be sold to third parties.

Anonymous data collected automatically:

  • will not be transferred outside the European Union,
  • will not be used for automated decision-making or profiling,
  • will not be sold to third parties.

11. Legal bases for processing personal data

The Service collects and processes User data under:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016,
  • Article 6(1)(a) — the data subject has consented to processing for one or more specific purposes,
  • Article 6(1)(b) — processing is necessary to perform a contract or take pre-contractual steps at the data subject’s request,
  • Article 6(1)(f) — processing is necessary for legitimate interests pursued by the controller or a third party,
  • the Polish Act of 10 May 2018 on Personal Data Protection,
  • the Polish Telecommunications Law Act of 16 July 2004,
  • the Polish Act of 4 February 1994 on Copyright and Related Rights.

12. Personal data retention period

Personal data supplied voluntarily by Users is generally retained only while the Administrator provides the relevant Service. It is deleted or anonymised within 30 days after service ends, such as after account deletion.

An exception applies where the Administrator must protect legitimate interests requiring further processing. In such a case, data may be retained for no longer than three years following a deletion request where a User has breached or is suspected of breaching the Terms.

Anonymous data collected automatically that does not constitute personal data may be retained indefinitely for Service statistics.

13. User rights concerning personal data

Users have the following rights under applicable law:

Right of access — Users may request access to their personal data from the Administrator.

Right to rectification — Users may request prompt correction of inaccurate personal data or completion of incomplete data.

Right to erasure — Users may request prompt deletion of personal data. For User accounts, deletion may involve anonymising identifying data. The Administrator may delay erasure where necessary to protect legitimate interests, such as when a User has breached the Terms or data was obtained through correspondence.

Right to restrict processing — Users may request restriction in the circumstances set out in Article 18 of the GDPR, including when data accuracy is disputed.

Right to data portability — Users may request personal data in a structured, commonly used, machine-readable format.

Right to object — Users may object to processing in the circumstances set out in Article 21 of the GDPR.

Right to lodge a complaint — Users may lodge a complaint with the competent data protection supervisory authority.

14. Contacting the Administrator

Contact the Administrator at support@laterlane.com.

15. Service requirements

Restricting the storage of or access to Cookies on a User’s Device may prevent some Service functions from operating correctly.

The Administrator is not responsible for malfunctioning Service features where a User restricts the storage or reading of Cookies.

16. External links

The Service may contain links to external websites with which the Service owner does not cooperate. Linked websites or files may be unsafe for a User’s Device or data. The Administrator is not responsible for content located outside the Service.

17. Changes to this Privacy Policy

The Administrator may amend this Privacy Policy without notifying Users regarding the use of anonymous data or Cookies.

The Administrator may amend provisions concerning personal data processing and will notify Users who have accounts by email within seven days of the change. Continued use means the User has reviewed and accepted the amendment. A User who disagrees must delete their account.

Changes will be published on this page and take effect when published.

Last updated: August 4, 2026