DINPanel Data Protection Notice (GDPR-Aligned)

Privacy Policy

Last updated: April 16, 2026

Policy hash: e83832e5cb90e8faccd2e32ddbf55d9402f0e3f72e484c132ccb1676b389a8d9

This Privacy Policy explains how DINPanel processes personal data when you use DINPanel websites, applications, and API-related services.

DINPanel follows data minimization, purpose limitation, and security-by-design principles. You are responsible for ensuring data you upload is lawful and necessary.

1. Data Controller and DPO / IODO Contact

The data controller for personal data processed through DINPanel services is DINPanel.

Data Protection Officer / IODO contact: Pawel Gruszka, info@dinpanel.com.

2. Categories of Personal Data

Depending on context, DINPanel may process account/profile data, organizational/workspace data, support communications, technical identifiers, log events, billing/invoice integration data, and operational telemetry needed to provide and secure the service.

  • DINPanel is not designed as a repository for sensitive personal data unless legally justified and explicitly required.
  • Users should avoid entering unnecessary personal data into project content.
  • For invoice integrations, DINPanel may process buyer and (if overridden) seller invoice data submitted by the user for issuance.
  • DINPanel stores invoice provider connection settings, including encrypted credentials/secrets required for API calls.
  • DINPanel stores invoice issue request logs (for example: request ID, provider key, integration template key, status, external invoice identifier/number if returned, and error metadata).
  • DINPanel does not provide accounting/tax validation and does not maintain full accounting records on behalf of users unless explicitly stated in product documentation.

4. Retention Periods

Personal data is retained only as long as necessary for the purposes described and applicable legal requirements.

  • Service/account records: active lifecycle plus limited post-termination period for security and legal handling.
  • Financial/statutory records: retained as required by law.
  • Security and support records: retained according to operational and compliance needs.
  • Invoice provider credentials/secrets: retained while the provider connection is active, and removed when the user disconnects or rotates integration data (subject to backup retention cycles).
  • Invoice issue request logs: retained for operational integrity, security, auditability, and legal defense for a period proportionate to those purposes.

5. Data Sharing and Processors

DINPanel may share data with trusted subprocessors and providers under contractual safeguards, solely to deliver and protect the service.

  • Infrastructure, hosting, communications, and support tooling providers.
  • Invoice providers selected by users in configuration (for example: Fakturownia, inFakt, Comarch Betterfly, and future country-specific providers).
  • Advisers and authorities where legally required.
  • DINPanel does not sell personal data as an independent commercial product.

6. International Transfers

Where international transfers occur, DINPanel relies on lawful safeguards (such as adequacy decisions and/or Standard Contractual Clauses) where applicable.

Invoice data sent to third-party providers may be processed in jurisdictions relevant to those providers, their infrastructure, or your selected operating country.

7. Security Controls

DINPanel applies administrative, technical, and organizational safeguards proportional to risk, including access restrictions, monitoring, secure transmission, and incident management.

  • Invoice provider credentials are encrypted at rest and used only for authenticated API communication with the configured provider.
  • Credential values are not intended to be openly displayed in user interfaces after storage.
  • Invoice issue operations are logged with technical metadata necessary for incident investigation and reliability.
  • No environment can guarantee zero risk.
  • Customers remain responsible for endpoint security, access hygiene, and safe handling of exported data.

8. Data Subject Rights

Subject to legal limitations, you may request access, correction, deletion, processing restriction, portability, objection, and consent withdrawal (where consent applies).

Requests should be sent to info@dinpanel.com.

  • Identity verification may be required before request fulfillment.
  • You may remove invoice provider connections in product settings; this prevents further invoice issuance through that connection.
  • Deletion requests may be limited where DINPanel must retain specific records to comply with law, resolve disputes, prevent abuse, or protect legal claims.

9. Supervisory Authority Complaints

You may lodge a complaint with your competent data protection supervisory authority if you believe processing violates applicable law.

10. Automated Decision-Making

DINPanel does not ordinarily perform solely automated decision-making that produces legal or similarly significant effects under GDPR Article 22.

11. Children

DINPanel services are not intended for children and are not knowingly directed to minors without valid legal grounds.

12. Responsibility Boundaries

DINPanel provides privacy and security controls at the platform level. You remain solely responsible for what data you submit, disclose, or distribute to third parties, including invoice data submitted to external providers.

  • DINPanel is not responsible for customer-side legal classification errors, unauthorized sharing, weak credential practices, or downstream misuse outside DINPanel control.

13. Cookies and Browser Storage

DINPanel uses cookies and browser storage technologies only to operate the service, keep sessions secure, and remember user-selected settings.

  • Essential authentication cookies: set by DINPanel API to maintain secure sign-in sessions and request protection.
  • localStorage/sessionStorage: used for language, theme, offline flags, and temporary UI/session continuity data.
  • IndexedDB: used to store offline queue records and cached project data for synchronization after reconnecting.
  • DINPanel frontend currently does not load third-party advertising cookies or marketing tracking pixels.

14. Invoice Integrations and External Provider Responsibility

DINPanel acts as an integration layer between your project workflow and external invoice providers. The provider selected by the user remains an independent data recipient/controller for processing inside that provider’s own environment.

Users are responsible for selecting an appropriate provider, configuring credentials lawfully, and ensuring buyer/seller data submitted for invoicing is accurate and legally valid.

  • Provider-side retention, legal basis details, and data subject handling are governed by each provider’s own privacy and legal documentation.
  • If provider-side errors occur, DINPanel may store sanitized user-facing errors and technical diagnostics for support and security handling.

15. Policy Changes

DINPanel may update this Policy periodically. The current version and effective date are published on this page.