Mivare Sites privacy policy
The complete document in a clear HTML format — the same text as in the PDF.
1. Data controller
The controller of the personal data described in this Policy is MIVARE GROUP PROSTA SPÓŁKA AKCYJNA, with its registered office in Krasnobród (22-440 Krasnobród; the full registered office address is disclosed in the National Court Register (KRS)), entered in the Register of Entrepreneurs maintained by Sąd Rejonowy Lublin-Wschód w Lublinie z siedzibą w Świdniku, VI Wydział Gospodarczy KRS, under KRS number 0001268091, NIP 9223092251, REGON 545767254, operating under the Mivare Sites brand, hereinafter “Mivare”.
Contact for personal data matters: hello@mivaregroup.com or in writing to the registered office address disclosed in the National Court Register (KRS). A Data Protection Officer has not been appointed.
2. Scope of the Policy
This Policy concerns data whose purposes and means of processing are determined by Mivare in connection with the Mivare Sites service: data of persons who set up a Company Account and use the Application (Users), persons designated for billing, persons contacting customer support, and technical data connected with use of the Application.
This Policy does not concern data that the company (the Customer) enters into the Application about its clients, facilities, employees, crews, subcontractors and other persons — including attendance and working time records together with the device's position at the start and end of work — nor data provided by the company's clients through the public functions of the Application (project status, fire protection status, acceptances). The controller of that data is the company, and Mivare processes it solely on the company's behalf, on the basis of the Mivare Sites Data Processing Agreement (MWS-LEG-003). Data subjects concerned by that data should direct their requests to the company; if a request reaches Mivare, Mivare will forward it to the company.
Capitalised terms have the meanings given to them in the Mivare Sites Terms of Service (MWS-LEG-001).
3. Purposes, legal bases and retention periods
- Registration, maintenance of the Company Account and provision of the service (first name and surname, e-mail address, telephone number if provided, position, language, account settings): Article 6(1)(b) GDPR in respect of the person entering into the Contract, and in respect of the other Users Article 6(1)(f) GDPR — the legitimate interest in providing the service to the Customer. We retain the data for the term of the Contract and until deletion of the Company Account on the terms of the Terms of Service.
- Authentication and security (password in hashed form, two-factor authentication data, history of logins and failed login attempts, IP address, activity log in the Application): Article 6(1)(f) GDPR — the legitimate interest in protecting the Application and the data. The activity log is retained for the period set by the Customer, from 30 to 180 days (90 days by default); the other data — until deletion of the User's account.
- Record of acceptance of documents (document version, date, IP address): Article 6(1)(c) and (f) GDPR — demonstrating conclusion of the Contract. We retain it for the term of the Contract and until expiry of the limitation period for claims.
- Billing, payments and invoices (details of the company, EU VAT number and the result of its verification in the VIES system, e-mail address for billing, payment history): Article 6(1)(b) and (c) GDPR. We retain billing documents for the period required by tax and accounting legislation, as a rule 5 years from the end of the calendar year in which the tax payment deadline expired.
- Handling of requests, complaints and correspondence: Article 6(1)(b) and (f) GDPR. We retain the data until the matter is closed and then until expiry of the limitation period for claims, no longer than 3 years from the last contact.
- Service messages concerning the service (security, changes to documents, payments, technical interruptions): Article 6(1)(b) and (f) GDPR. We do not send commercial information to Users without separate consent.
- Establishment, pursuit or defence of claims: Article 6(1)(f) GDPR, until expiry of the limitation period.
Providing data is voluntary but necessary to set up an account and use the service. The data of Users other than the person setting up the account is provided by the Account Administrator.
4. Recipients of data
- OVH Sp. z o.o. (OVHcloud group) — server infrastructure and e-mail, data centres in the European Union — as a processor.
- Stripe Payments Europe, Limited (Ireland) — processing of Subscription payments. Stripe receives the company name, the billing e-mail address, the country, the language and a technical account identifier; the Account Administrator enters the card details directly on the Stripe page, and Mivare does not receive or store them. With regard to payment data, fraud prevention and its own legal obligations, Stripe acts as a separate controller on the basis of its own privacy policy, and otherwise as a processor. Stripe does not receive Customer Data.
- European Commission (VIES system) — verification of the EU VAT number of a Customer from another Member State of the European Union, in order to determine the tax treatment.
- Professional advisers (legal, tax, accounting) bound by a duty of confidentiality — to the extent necessary to handle billing and legal matters.
- Public authorities — only where an obligation to disclose data arises from the law.
Mivare does not sell personal data and does not disclose it for marketing purposes.
5. External services
The Application does not load any resources in the User's browser from servers other than those of Mivare. Maps of facilities and projects are drawn from data stored on the Mivare server, without external map services. The Application's fonts, icons and libraries are loaded from the Mivare server.
The Application retrieves exchange rates on the server side from the public tables of the National Bank of Poland and the European Central Bank; the queries contain no personal data.
The Application does not use any analytics, advertising or tracking tools.
6. Cookies and browser storage
The Application uses only cookies necessary for its operation, which do not require consent:
- the Application's session cookie (name beginning with “MIVARE”) — maintaining the logged-in session and, on public pages (project status, fire protection status, acceptances), maintaining access after verification; deleted when the browser is closed or on logging out; inaccessible to scripts, transmitted only over an encrypted connection;
- mw_td — remembering a trusted device after two-factor authentication, at the User's request; valid for 30 days;
- mw_viewport — screen width, allowing the layout of the Application to be adapted to the device; valid for 12 months; contains no identifying data.
In the browser storage (localStorage), the Application saves only the expanded or collapsed state of the side menu; it is not transmitted to the server.
Cookies can be deleted in the browser settings; blocking them makes it impossible to log in to the Application.
7. Device location
The Application reads the device's location only when the User records the start or end of work in the attendance records and permits this in the browser. A single location is saved for each of these actions; the Application does not track location in the background or between these actions. This data is Customer Data and falls within the scope of the Data Processing Agreement.
8. Transfers of data outside the European Economic Area
Mivare processes the data described in this Policy on servers in the European Union. Stripe, as the payment operator, may transfer billing data to entities of its group, including Stripe, Inc. in the United States, on the basis of the European Commission's adequacy decision (EU-U.S. Data Privacy Framework) and standard contractual clauses. Any other transfer of data outside the European Economic Area will take place only using a mechanism compliant with Chapter V GDPR, after this Policy has been updated beforehand.
9. Data-subject rights
You have the right of access to your data, the right to rectification, erasure, restriction of processing and data portability, and the right to object to processing based on legitimate interest. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before its withdrawal.
Please direct requests to hello@mivaregroup.com. We respond without undue delay and no later than one month after receipt of the request; in justified cases this period may be extended in accordance with the GDPR, of which we will inform you.
You have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, or with the supervisory authority in the Member State of the European Union of your habitual residence, place of work or place of the alleged infringement.
10. Automated decisions
Mivare does not take decisions concerning Users based solely on automated processing, including profiling, which produce legal effects concerning them or similarly significantly affect them. Automatic suspension of access following unsuccessful payment attempts results from the Payment Terms and concerns the Customer as an entrepreneur; the decision may be clarified with customer support at any time.
11. Security
Mivare applies technical and organisational measures appropriate to the risk, in particular encryption of connections, storage of passwords solely in the form of a cryptographic hash, two-factor authentication, logical separation of each company's data, event logging and backups. A detailed description is contained in the Data Processing Agreement (MWS-LEG-003).
12. Changes to the Policy
This Policy is updated whenever there is a change in the manner of data processing, the recipients or the legislation. We inform Account Administrators of material changes by e-mail and in the Application. The current version is available at https://mivaregroup.com/en/legal/sites/privacy/
This Policy is made available in seven language versions; in the event of any discrepancy, the Polish version prevails. This Policy is effective from 1 October 2026.
MIVARE GROUP