DINPanel Data Protection Notice (GDPR)

Privacy Policy

Last updated: 16 April 2026

Policy hash: bb3916c329c0babd7c9ea5a08e2d7fd355cb6a6221084eaa12c6b412cb5676d6

This Privacy Policy explains how DINPanel processes personal data when you access or use DINPanel services.

DINPanel applies data minimisation, security-by-design, and purpose limitation principles. However, you remain responsible for ensuring that project content you upload is lawful and does not exceed what is necessary.

1. Data Controller and Data Protection Contact

The controller of personal data processed in connection with DINPanel is DINPanel.

Data Protection Officer / IODO contact: Pawel Gruszka, info@dinpanel.com.

2. Scope of Data Processing

DINPanel may process the following categories of personal data: account data (name, email, authentication and profile metadata), company/workspace details, support communications, technical logs, invoice integration data, and usage telemetry required for service reliability and security.

  • DINPanel is not intended for storing special category data under Article 9 GDPR unless explicitly required and lawfully justified by the user.
  • Users must avoid uploading unnecessary personal data to technical project fields.
  • For invoicing integrations, DINPanel may process buyer and (where overridden) seller data provided by the user to issue invoices.
  • DINPanel stores invoice provider connection settings, including encrypted credentials/secrets required for authenticated API calls.
  • DINPanel stores invoice issue request logs (for example: request identifier, provider/template keys, status, external invoice identifiers returned by providers, and technical error metadata).

3. Purposes and Legal Bases (GDPR Article 6)

Personal data is processed only where there is a valid legal basis under Article 6 GDPR.

  • Performance of contract (Art. 6(1)(b)): account operation, authentication, service delivery, support execution.
  • Legal obligations (Art. 6(1)(c)): compliance with tax, accounting, or lawful authority requests.
  • Legitimate interests (Art. 6(1)(f)): fraud prevention, abuse mitigation, security monitoring, service diagnostics, and quality improvement.
  • Consent (Art. 6(1)(a)), where required: optional communications or non-essential technologies.
  • Invoice issuance purpose: transmitting user-provided invoice data to selected third-party providers and retaining limited technical records needed for reliability, troubleshooting, and legal defence.

4. Data Retention

Data is retained no longer than necessary for the stated purposes and applicable legal obligations.

  • Account and operational data: for the active service period and a reasonable post-termination period for security, dispute handling, and legal compliance.
  • Financial and statutory records: retained for legally required periods.
  • Support records and logs: retained according to operational necessity and security policy.
  • Invoice provider credentials/secrets: retained while a provider connection is active and removed when disconnected or replaced (subject to backup retention cycles).
  • Invoice issue request logs: retained for operational integrity, auditability, abuse prevention, and legal defence for a period proportionate to those purposes.

5. Data Recipients and Processors

Data may be disclosed to trusted processors and infrastructure providers strictly to deliver and secure the service.

  • Hosting, infrastructure, analytics, and communication providers acting under data processing agreements.
  • Invoice providers selected by users (for example: Fakturownia, inFakt, Comarch Betterfly, and future country-specific providers).
  • Professional advisers and authorities where legally required.
  • Data is never sold as a standalone commercial dataset.

6. International Data Transfers

If personal data is transferred outside the EEA/UK, DINPanel applies appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, or equivalent lawful mechanisms.

Invoice data sent to external providers may be processed in jurisdictions relevant to those providers, their sub-processors, or your selected operating country.

7. Security Measures

DINPanel applies organisational and technical safeguards proportionate to risk, including access control, secure transport, monitoring, and incident response procedures.

  • Invoice provider credentials are encrypted at rest and used only for authenticated communication with the configured provider.
  • Stored credential values are not intended to be openly revealed in user interfaces.
  • Invoice issue actions are logged with technical metadata required for operational stability and incident handling.
  • No system can guarantee absolute security.
  • Users remain responsible for credential security, local endpoint security, and lawful handling of exported files.

8. Data Subject Rights (GDPR)

Subject to legal limitations, data subjects may request access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where consent is the legal basis.

Requests can be submitted to info@dinpanel.com.

  • DINPanel may request identity verification before fulfilling rights requests.
  • Users may remove invoice provider connections in settings to stop further issuance via that connection.
  • Certain records may still need to be retained where required by law, anti-abuse controls, or legal claims handling.

9. Supervisory Authority Complaint Right

You have the right to lodge a complaint with a competent supervisory authority if you believe your personal data is processed unlawfully.

10. Automated Decision-Making

DINPanel does not perform solely automated decision-making producing legal effects in the sense of Article 22 GDPR within standard service operation.

11. Children’s Data

DINPanel is not intended for children and does not knowingly target or collect personal data from minors without a valid legal basis.

12. Privacy Liability Boundaries

DINPanel secures and processes data within reasonable and legally required standards, but users remain fully responsible for data they upload, disclose, export, or share with third parties, including invoice providers.

  • DINPanel is not responsible for user-side misconfiguration, unauthorised sharing, weak credentials, or unlawful downstream processing performed by users or contractors.

13. Cookies and Browser Storage

DINPanel uses cookies and browser storage technologies only where needed to run the service, secure sessions, and remember user-selected preferences.

  • Essential authentication cookies: set by DINPanel API to maintain secure sign-in sessions and request protection.
  • localStorage/sessionStorage: used for language, theme, offline mode flags, and temporary session continuity state.
  • IndexedDB: used to store offline queue records and cached project data for later synchronisation.
  • DINPanel frontend currently does not load third-party advertising cookies or marketing tracking pixels.

14. Invoice Integrations and External Provider Responsibility

DINPanel operates as an integration layer between project workflows and external invoice providers. The selected provider remains an independent recipient/controller for processing performed within that provider environment.

Users are responsible for selecting an appropriate provider, lawfully configuring credentials, and ensuring buyer/seller invoice data submitted for issuance is accurate and legally valid.

  • Provider-side retention schedules, legal bases, and rights handling are governed by each provider’s own legal documentation.
  • Where provider errors occur, DINPanel may retain sanitised user-facing errors and technical diagnostics for support, reliability, and security purposes.

15. Changes to this Policy

This Policy may be updated from time to time. The latest effective version is published on this page with an updated date.