Privacy Policy of the smseagle.eu Website

Thank you for visiting our website available at https://smseagle.eu (hereinafter: “Smseagle.eu“, the “Website“). This Privacy Policy explains what personal data we collect and process in connection with the use of the Website, for what purposes and on what legal grounds we do so, how long we store the data, to whom we disclose it, and what rights data subjects have. Information regarding cookies and analytical tools is contained in a separate Cookie Policy available on the Website.

We invite you to review this Privacy Policy.
Smseagle.eu Team

 

1) General provisions

  1. This Privacy Policy of the Website is of an informational nature – it is not a source of obligations for Service Recipients of the Website. The Privacy Policy contains the rules concerning the processing of personal data by the Data Controller on the Website, including the grounds, purposes, scope, and periods of processing of personal data, as well as the rights of data subjects.
  2. The controller of personal data collected via the Website is PROXIMUS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office in Poznań (registered office address and address for service: ul. Piątkowska 163, 60-650 Poznań), entered into the Register of Entrepreneurs of the National Court Register under KRS number: 0000956902, registry court: District Court Poznań – Nowe Miasto i Wilda in Poznań, 8th Commercial Division of the National Court Register, share capital: PLN 400,000.00; NIP (Tax ID): 7812032643, REGON (Statistical ID): 521369644, contact telephone number: +48 61 671 34 13 (hereinafter: the “Data Controller“), which is also the Service Provider of the Website.
  3. Contact regarding personal data protection: In matters relating to the protection of personal data, you may contact the Data Controller at the dedicated e-mail address: odo@smseagle.eu, in writing at the Data Controller’s registered office address: ul. Piątkowska 163, 60-650 Poznań
  4. Data Protection Officer: The Data Controller informs that it has not appointed a Data Protection Officer (DPO). There is no obligation to appoint a DPO in the case of the Data Controller, as none of the conditions set out in Article 37(1) of the GDPR are met. In all matters concerning the protection of personal data, please contact the Data Controller directly, using the details indicated above.
  5. Personal data on the Website is processed by the Data Controller in accordance with applicable law, in particular in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – hereinafter referred to as “GDPR”. The official text of the GDPR is available at: eur-lex.europa.eu.
  6. Use of the Website is voluntary. Similarly, the provision of personal data by the Service Recipient in connection therewith is voluntary, subject to two exceptions: (1) conclusion of an agreement with the Data Controller – failure to provide the data necessary for the provision of a selected Electronic Service (e.g. a telephone number when registering for a Demo) will result in the inability to use that Service; (2) the Data Controller’s statutory obligations – the provision of personal data may be a statutory requirement, and failure to provide it will prevent the Data Controller from performing those obligations. The provision of data for marketing purposes, including subscribing to the Newsletter and choosing the channel of contact (e-mail or SMS message), is entirely voluntary. Refusal does not result in any negative consequences and does not affect the ability to use the Website or the other Electronic Services.
  7. The Data Controller exercises particular diligence in protecting the interests of the persons whose data it processes. The Data Controller ensures that the data collected is: (1) processed lawfully, fairly, and in a transparent manner; (2) collected for specified, lawful purposes; (3) adequate and limited to what is necessary; (4) accurate and kept up to date; (5) kept for no longer than is necessary; (6) processed in a manner that ensures appropriate security, using appropriate technical and organisational measures (including data encryption, an SSL certificate, and secure access passwords).
  8. All words, phrases, and acronyms used in this Privacy Policy and beginning with a capital letter should be understood in accordance with their definition set out in the Website’s Terms and Conditions available on the Website.

2) Grounds for data processing

The Data Controller is entitled to process personal data where at least one of the following conditions is met:

  1. the data subject has given consent to the processing of their personal data for one or more specified purposes (Article 6(1)(a) GDPR);
  2. processing is necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR);
  3. processing is necessary for compliance with a legal obligation to which the Data Controller is subject (Article 6(1)(c) GDPR);
  4. processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject (Article 6(1)(f) GDPR).

3) Purposes, grounds, and periods of data processing

In each case, the purpose, ground, period, and recipients of personal data processed by the Data Controller result from the actions taken by the given Service Recipient on the Website or by the Data Controller. The Data Controller processes personal data for the following purposes, on the following grounds, and for the following periods:

Purpose Legal ground Retention period
Performance of the agreement for the provision of an Electronic Service, or taking steps at the request of a person prior to entering into an agreement (including handling the Account, the Contact Form, the Demo Service, the Forum) Article 6(1)(b) GDPR (performance of a contract) For the period necessary for the performance, termination, or expiry of the concluded agreement for the provision of the Electronic Service
Marketing activities and commercial offers based on consent (including the Newsletter) Article 6(1)(a) GDPR (consent) Until the data subject withdraws their consent. Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal (Article 7(3) GDPR)
Handling of the Demo Service – registration, identity verification, provision of access to a trial device, and post-sale contact after the end of the trial period Article 6(1)(b) GDPR (steps taken prior to entering into an agreement) and Article 6(1)(f) GDPR (legitimate interest, for contact after the trial) For the duration of the Demo Service and the period necessary for its settlement, and thereafter for a period not exceeding 6 years from the end of the Demo
Keeping statistics and analysing traffic on the Website Article 6(1)(f) GDPR (legitimate interest) For as long as the legitimate interest exists, not longer than the limitation period for the Data Controller’s claims (generally 6 years)
Ensuring the proper functioning of the Website and the security of the IT system Article 6(1)(f) GDPR (legitimate interest) For as long as the legitimate interest exists, not longer than the limitation period for the Data Controller’s claims (generally 6 years)
Establishing, pursuing, or defending claims Article 6(1)(f) GDPR (legitimate interest) Up to 6 years (the longest limitation period under the Civil Code)
Handling technical support requests (service tickets via HubSpot and the support portal) Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (legitimate interest) For the duration of the agreement or the technical support agreement, and thereafter for 6 years from the date the ticket is closed
Keeping tax records Article 6(1)(c) GDPR in conjunction with Article 86 § 1 of the Tax Ordinance Until the expiry of the limitation period for the tax obligation

 

4) Data processing by category of data subject

This section describes in detail the processing of data from the perspective of individual categories of persons using the Website.

A. Users visiting the Website (browsing the site)
Visiting the Website’s pages involves the automatic transmission by the Service Recipient’s browser of certain technical information, such as the IP address, browser type and version, operating system, referring page, and the time and date of the visit. This data is collected by the Data Controller in the server log and via analytical tools (e.g. Google Analytics 4, MS Clarity) and marketing tools (e.g. Meta Pixel, LinkedIn) in order to ensure the proper functioning of the Website and to analyse traffic. The basis for processing is Article 6(1)(f) GDPR (legitimate interest) or, to the extent consent is required, Article 6(1)(a) GDPR (consent given via the cookie consent management tool). Detailed information regarding analytical tools and cookies is contained in the Cookie Policy.

B. Newsletter subscribers
Persons subscribing to the Newsletter provide their e-mail address and, where applicable, their first name, in order to receive marketing communications from the Data Controller regarding SMSEagle products, services, and news. Data processing is based on consent (Article 6(1)(a) GDPR). Data is processed until consent is withdrawn or an effective objection is raised. Consent may be withdrawn, or an objection raised, at any time – by clicking the unsubscribe link contained in each Newsletter message or by contacting: sales@smseagle.eu.

C. Persons registering for the Demo
Persons registering for the Demo provide at least an e-mail address and a telephone number (necessary for identity verification via an SMS code and for possible contact regarding support during the trial period). Data processing takes place on the basis of Article 6(1)(b) GDPR. Post-sale contact after the end of the trial period (offering sales and technical support) is based on Article 6(1)(f) GDPR or, in the case of marketing communication by electronic or telephone means, on the Service Recipient’s separate consent. Data is stored for the duration of the Demo Service and for 6 years thereafter.

D. Persons using the Contact Form
Persons sending inquiries via the Contact Form provide at least an e-mail address and the content of the message. Data is processed in order to respond to the inquiry, on the basis of Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. Data is stored for the period necessary to consider the inquiry and provide a response, and thereafter for 6 years for the purposes of demonstrating facts, and defending or pursuing claims.

E. Users of the Community and support portal (Community)
Persons actively participating in the Forum (posting content) may be required to provide an e-mail address or username. Data is processed on the basis of Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. Data is stored for the period of the Service Recipient’s activity on the Forum or until the Account is deleted.

The Data Controller also maintains public profiles (fan pages) on social media platforms:

  1. Facebook and Instagram – operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland;
  2. LinkedIn – operated by LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland.

In connection with maintaining these profiles, the Data Controller processes the personal data of persons who visit the profile, follow it, interact with it (likes, reactions, comments, shares, reviews), or contact the Data Controller via the platform. The scope of data includes: the user’s profile identifier and name, profile picture, and other data that the user has voluntarily made publicly available on their profile, the content of comments, reactions, and private messages, data contained in inquiries directed to the Data Controller, and aggregate (anonymised) statistical data regarding the profile’s audience, made available to the Data Controller by the platform as part of its statistics (Insights) function.

Data is processed on the basis of: a) Article 6(1)(f) GDPR – the Data Controller’s legitimate interest consisting of maintaining the profile, building and maintaining a community around the brand, promoting the Data Controller and its products and services, informing about its activities and events, conducting ongoing communication with users, and analysing profile statistics; b) Article 6(1)(b) GDPR – to the extent that communication conducted via the platform is aimed at concluding an agreement or relates to its performance.

With respect to statistical data concerning the profile, the Data Controller is a joint controller of the data together with, respectively, Meta Platforms Ireland Limited and LinkedIn Ireland Unlimited Company. The essence of the arrangement referred to in Article 26(2) GDPR is made available by these platforms at:

  1. Facebook and Instagram: facebook.com/legal/terms/page_controller_addendum
  2. LinkedIn: legal.linkedin.com/pages-joint-controller-addendum

F. Business contacts (B2B)
Contact details of representatives and employees of entities interested in SMSEagle products (business partners, potential B2B customers, contacts obtained at trade fairs or via the Contact Form) are processed for the purpose of establishing and maintaining business relationships. Processing is based on Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. This data usually includes: first and last name, position, business e-mail address, business telephone number, and company details. It is stored for the duration of the business relationship and for 3 years thereafter.

G. Users of the technical support portal (service tickets)
Persons submitting technical inquiries via the support portal (smseagle.eu/support) provide contact details and descriptions of technical problems. Data is processed via the HubSpot CRM/ticketing system. The basis for processing is Article 6(1)(b) GDPR or Article 6(1)(f) GDPR. Service tickets are stored for the duration of the service or warranty agreement, and thereafter for 3 years from the date the request is closed, unless the law requires a longer period. As part of remote technical support, the Data Controller may use remote access tools (AnyDesk or TeamViewer), used solely with the express consent and knowledge of the Service Recipient.

H. Chatbot users
A chatbot service may be available on the Website, through which Service Recipients can obtain information regarding SMSEagle products and services. The following personal data may be processed: the content of messages entered, the IP address, the date and time of using the chatbot, and, where voluntarily provided, the first name, e-mail address, or telephone number. The basis for processing is Article 6(1)(f) GDPR or Article 6(1)(b) GDPR. Data from chatbot conversations is stored for 3 years from the last interaction.

5) Profiling on the Website

  1. The Data Controller may use profiling on the Website for marketing and analytical purposes. Profiling consists of the automatic analysis or prediction of a given person’s behaviour on the Website’s pages, for example by analysing the pages viewed, the time and frequency of visits, traffic sources, and interactions with content. On the basis of this analysis, the Data Controller adjusts the advertisements displayed (remarketing), personalises e-mail communication, and may suggest content corresponding to the person’s anticipated interests.
  2. Decisions taken by the Data Controller on the basis of profiling do not concern the conclusion or refusal to conclude an agreement, or the ability to use the Electronic Services on the Website.
  3. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
  4. Profiling carried out within advertising tools (Google, Meta, LinkedIn remarketing) takes place in accordance with the rules described by these providers in their own privacy policies. Detailed information on managing advertising preferences is available in the Cookie Policy.

6) Recipients of data on the Website

  1. For the proper functioning of the Website, it is necessary for the Data Controller to use the services of external entities. The Data Controller uses only the services of processors who provide sufficient guarantees of implementing appropriate technical and organisational measures.
  2. Transfer of data by the Data Controller does not occur in every case, nor to all of the recipients indicated below – the Data Controller discloses data only where necessary for the implementation of a given purpose.
  3. Personal data of Service Recipients may be disclosed to the following categories of recipients: (a) service providers supplying the Data Controller with technical and IT solutions enabling the operation of the Website and the provision of Electronic Services, in particular providers of software, network, and hosting services; (b) providers of marketing and advertising services; (c) providers of accounting, auditing, legal, and advisory services.

7) Transfer of data outside the European Economic Area (EEA)

  1. In connection with the Data Controller’s use of the services of entities based, or subcontractors located, outside the European Economic Area (EEA), in particular in the United States of America (USA), the personal data of Service Recipients may be transferred to third countries.
  2. The Data Controller ensures that the transfer of data to third countries takes place on the basis of appropriate mechanisms ensuring an adequate level of protection of personal data, in particular: (a) the EU-US Data Privacy Framework (DPF); (b) Standard Contractual Clauses (SCC) adopted by the European Commission.
  3. The data subject has the right to obtain a copy of the safeguards applied by the Data Controller with regard to the transfer of data outside the EEA, by contacting: odo@smseagle.eu.

8) Rights of the data subject

  1. Right of access, rectification, restriction, erasure, or portability – the data subject has the right to request from the Data Controller access to their personal data, rectification, erasure (“the right to be forgotten”), or restriction of processing, and has the right to object to processing, as well as the right to data portability (Articles 15–21 GDPR).
  2. Right to withdraw consent at any time – a data subject whose data is processed on the basis of consent has the right to withdraw their consent at any time, without affecting the lawfulness of prior processing (Article 7(3) GDPR).
  3. Right to lodge a complaint with a supervisory authority – the supervisory authority in Poland is the President of the Personal Data Protection Office. Right to object – the data subject has the right to object at any time, on grounds relating to their particular situation, to processing based on Article 6(1)(e) or (f) GDPR, including profiling.
  4. Right to object to direct marketing – where personal data is processed for direct marketing, the data subject has the right to object at any time, including to profiling related to such marketing.
  5. In order to exercise the rights referred to in this point, you may contact the Data Controller by e-mail at: odo@smseagle.eu, or at the postal address indicated in point 1.2 above.

9) Final provisions

  1. The Website may contain links to other websites, including to the online store operated at https://store.smseagle.eu. This Privacy Policy applies exclusively to the smseagle.eu Website.
  2. The Data Controller reserves the right to make changes to this Privacy Policy if required by law or by changes in the processes and tools used for data processing. The Data Controller will inform Service Recipients of any material changes in a manner that is accessible and visible on the Website.

This Privacy Policy is effective as of 28 August 2026.

Thank you for reading carefully!

If you have any questions regarding the protection of personal data, please contact us at: privacy@smseagle.eu.

Smseagle.eu Team