DINPanel Data Protection Notice (GDPR-Aligned)
Privacy Policy
Last updated: April 16, 2026
Policy hash: e83832e5cb90e8faccd2e32ddbf55d9402f0e3f72e484c132ccb1676b389a8d9
This Privacy Policy explains how DINPanel processes personal data when you use DINPanel websites, applications, and API-related services.
DINPanel follows data minimization, purpose limitation, and security-by-design principles. You are responsible for ensuring data you upload is lawful and necessary.
1. Data Controller and DPO / IODO Contact
The data controller for personal data processed through DINPanel services is DINPanel.
Data Protection Officer / IODO contact: Pawel Gruszka, info@dinpanel.com.
2. Categories of Personal Data
Depending on context, DINPanel may process account/profile data, organizational/workspace data, support communications, technical identifiers, log events, billing/invoice integration data, and operational telemetry needed to provide and secure the service.
- DINPanel is not designed as a repository for sensitive personal data unless legally justified and explicitly required.
- Users should avoid entering unnecessary personal data into project content.
- For invoice integrations, DINPanel may process buyer and (if overridden) seller invoice data submitted by the user for issuance.
- DINPanel stores invoice provider connection settings, including encrypted credentials/secrets required for API calls.
- DINPanel stores invoice issue request logs (for example: request ID, provider key, integration template key, status, external invoice identifier/number if returned, and error metadata).
- DINPanel does not provide accounting/tax validation and does not maintain full accounting records on behalf of users unless explicitly stated in product documentation.
3. Purposes and Legal Bases (GDPR Art. 6)
DINPanel processes personal data only where an appropriate legal basis exists.
- Contract necessity (Art. 6(1)(b)): service provision, authentication, account administration, support.
- Legal obligation (Art. 6(1)(c)): compliance with accounting, tax, and lawful authority requirements.
- Legitimate interests (Art. 6(1)(f)): security, abuse prevention, diagnostics, service integrity and improvement.
- Consent (Art. 6(1)(a)), where required for optional processing.
- Invoice issuance purpose: transmitting user-provided invoice data to selected third-party invoice providers and storing the minimum technical evidence needed to operate, troubleshoot, and defend against abuse or disputes.
4. Retention Periods
Personal data is retained only as long as necessary for the purposes described and applicable legal requirements.
- Service/account records: active lifecycle plus limited post-termination period for security and legal handling.
- Financial/statutory records: retained as required by law.
- Security and support records: retained according to operational and compliance needs.
- Invoice provider credentials/secrets: retained while the provider connection is active, and removed when the user disconnects or rotates integration data (subject to backup retention cycles).
- Invoice issue request logs: retained for operational integrity, security, auditability, and legal defense for a period proportionate to those purposes.
6. International Transfers
Where international transfers occur, DINPanel relies on lawful safeguards (such as adequacy decisions and/or Standard Contractual Clauses) where applicable.
Invoice data sent to third-party providers may be processed in jurisdictions relevant to those providers, their infrastructure, or your selected operating country.
7. Security Controls
DINPanel applies administrative, technical, and organizational safeguards proportional to risk, including access restrictions, monitoring, secure transmission, and incident management.
- Invoice provider credentials are encrypted at rest and used only for authenticated API communication with the configured provider.
- Credential values are not intended to be openly displayed in user interfaces after storage.
- Invoice issue operations are logged with technical metadata necessary for incident investigation and reliability.
- No environment can guarantee zero risk.
- Customers remain responsible for endpoint security, access hygiene, and safe handling of exported data.
8. Data Subject Rights
Subject to legal limitations, you may request access, correction, deletion, processing restriction, portability, objection, and consent withdrawal (where consent applies).
Requests should be sent to info@dinpanel.com.
- Identity verification may be required before request fulfillment.
- You may remove invoice provider connections in product settings; this prevents further invoice issuance through that connection.
- Deletion requests may be limited where DINPanel must retain specific records to comply with law, resolve disputes, prevent abuse, or protect legal claims.
9. Supervisory Authority Complaints
You may lodge a complaint with your competent data protection supervisory authority if you believe processing violates applicable law.
10. Automated Decision-Making
DINPanel does not ordinarily perform solely automated decision-making that produces legal or similarly significant effects under GDPR Article 22.
11. Children
DINPanel services are not intended for children and are not knowingly directed to minors without valid legal grounds.
12. Responsibility Boundaries
DINPanel provides privacy and security controls at the platform level. You remain solely responsible for what data you submit, disclose, or distribute to third parties, including invoice data submitted to external providers.
- DINPanel is not responsible for customer-side legal classification errors, unauthorized sharing, weak credential practices, or downstream misuse outside DINPanel control.
14. Invoice Integrations and External Provider Responsibility
DINPanel acts as an integration layer between your project workflow and external invoice providers. The provider selected by the user remains an independent data recipient/controller for processing inside that provider’s own environment.
Users are responsible for selecting an appropriate provider, configuring credentials lawfully, and ensuring buyer/seller data submitted for invoicing is accurate and legally valid.
- Provider-side retention, legal basis details, and data subject handling are governed by each provider’s own privacy and legal documentation.
- If provider-side errors occur, DINPanel may store sanitized user-facing errors and technical diagnostics for support and security handling.
15. Policy Changes
DINPanel may update this Policy periodically. The current version and effective date are published on this page.