Mivare Works privacy policy
The complete document in a clear HTML format — the same text as in the PDF.
1. Data controller
The controller of the personal data described in this Policy is MIVARE GROUP PROSTA SPÓŁKA AKCYJNA, with its registered office in Krasnobród (22-440 Krasnobród; the full registered office address is disclosed in the National Court Register (KRS)), entered in the Register of Entrepreneurs maintained by Sąd Rejonowy Lublin-Wschód w Lublinie z siedzibą w Świdniku, VI Wydział Gospodarczy KRS, under KRS number 0001268091, NIP 9223092251, REGON 545767254, operating under the Mivare Works brand, hereinafter “Mivare”.
Contact for personal data matters: hello@mivaregroup.com or in writing to the registered office address disclosed in the National Court Register (KRS). A Data Protection Officer has not been appointed.
2. Scope of the Policy
This Policy concerns data whose purposes and means of processing are determined by Mivare in connection with the Mivare Works service: data of persons who set up a Workshop Account and use the Application (Users), persons designated for billing, persons contacting customer support, and technical data connected with use of the Application.
This Policy does not concern data that the workshop (the Customer) enters into the Application about its clients, their vehicles, employees and other persons. The controller of that data is the workshop, and Mivare processes it solely on the workshop's behalf, on the basis of the Mivare Works Data Processing Agreement (MWK-LEG-003). Data subjects concerned by that data should direct their requests to the workshop; if a request reaches Mivare, Mivare will forward it to the workshop.
Capitalised terms have the meanings given to them in the Mivare Works Terms of Service (MWK-LEG-001).
3. Purposes, legal bases and retention periods
- Registration, maintenance of the Workshop Account and provision of the service (first name and surname, e-mail address, telephone number if provided, position, language, account settings): Article 6(1)(b) GDPR in respect of the person entering into the Contract, and in respect of the other Users Article 6(1)(f) GDPR — the legitimate interest in providing the service to the Customer. We retain the data for the term of the Contract and until deletion of the Workshop Account on the terms of the Terms of Service.
- Authentication and security (password in hashed form, two-factor authentication data, history of logins and failed login attempts, IP address, activity log in the Application): Article 6(1)(f) GDPR — the legitimate interest in protecting the Application and the data. The activity log is retained for the period set by the Customer, from 30 to 180 days (90 days by default); the other data — until deletion of the User's account.
- Record of acceptance of documents (document version, date, IP address): Article 6(1)(c) and (f) GDPR — demonstrating conclusion of the Contract. We retain it for the term of the Contract and until expiry of the limitation period for claims.
- Billing, payments and invoices (details of the company and of the person designated for billing, EU VAT number and the result of its verification in the VIES system, e-mail address for billing, payment history): Article 6(1)(b) and (c) GDPR. We retain billing documents for the period required by tax and accounting legislation, as a rule 5 years from the end of the calendar year in which the tax payment deadline expired.
- Handling of requests, complaints and correspondence: Article 6(1)(b) and (f) GDPR. We retain the data until the matter is closed and then until expiry of the limitation period for claims, no longer than 3 years from the last contact.
- Service messages concerning the service (security, changes to documents, payments, technical interruptions): Article 6(1)(b) and (f) GDPR. We do not send commercial information to Users without separate consent.
- Establishment, pursuit or defence of claims: Article 6(1)(f) GDPR, until expiry of the limitation period.
Providing data is voluntary but necessary to set up an account and use the service. The data of Users other than the person setting up the account is provided by the Account Administrator.
4. Recipients of data
- OVH Sp. z o.o. (OVHcloud group) — server infrastructure and e-mail, data centres in the European Union — as a processor.
- Stripe Payments Europe, Limited (Ireland) — processing of Subscription payments. Stripe receives the company name, the billing e-mail address, the country, the language and a technical account identifier; the Account Administrator enters the card details directly on the Stripe page, and Mivare does not receive or store them. With regard to payment data, fraud prevention and its own legal obligations, Stripe acts as a separate controller on the basis of its own privacy policy, and otherwise as a processor. Stripe does not receive Customer Data.
- European Commission (VIES system) — verification of the EU VAT number of a Customer from another Member State of the European Union, in order to determine the tax treatment.
- Professional advisers (legal, tax, accounting) bound by a duty of confidentiality — to the extent necessary to handle billing and legal matters.
- Public authorities — only where an obligation to disclose data arises from the law.
Mivare does not sell personal data and does not disclose it for marketing purposes.
5. External services in the browser
The Application dashboard displays a weather forecast for the workshop's town. The User's browser retrieves it directly from the Open-Meteo service (open-meteo.com), which consequently receives the device's IP address and the name or coordinates of the town. No account data or Customer Data is transmitted to that service.
The Application does not use any analytics, advertising or tracking tools. The Application's fonts, icons and libraries are loaded from the Mivare server.
6. Cookies
The Application uses only cookies necessary for its operation, which do not require consent:
- the Application's session cookie (name beginning with “MIVARE”) — maintaining the logged-in session; deleted when the browser is closed or on logging out; inaccessible to scripts, transmitted only over an encrypted connection;
- mw_td — remembering a trusted device after two-factor authentication, at the User's request; valid for 30 days;
- mw_viewport — screen width, allowing the layout of the Application to be adapted to the device; valid for 12 months; contains no identifying data.
Cookies can be deleted in the browser settings; blocking them makes it impossible to log in to the Application.
7. Transfers of data outside the European Economic Area
Mivare processes the data described in this Policy on servers in the European Union. Stripe, as the payment operator, may transfer billing data to entities of its group, including Stripe, Inc. in the United States, on the basis of the European Commission's adequacy decision (EU-U.S. Data Privacy Framework) and standard contractual clauses. Any other transfer of data outside the European Economic Area will take place only using a mechanism compliant with Chapter V GDPR, after this Policy has been updated beforehand.
8. Data-subject rights
You have the right of access to your data, the right to rectification, erasure, restriction of processing and data portability, and the right to object to processing based on legitimate interest. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before its withdrawal.
Please direct requests to hello@mivaregroup.com. We respond without undue delay and no later than one month after receipt of the request; in justified cases this period may be extended in accordance with the GDPR, of which we will inform you.
You have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, or with the supervisory authority in the Member State of the European Union of your habitual residence, place of work or place of the alleged infringement.
9. Automated decisions
Mivare does not take decisions concerning Users based solely on automated processing, including profiling, which produce legal effects concerning them or similarly significantly affect them. Automatic suspension of access following unsuccessful payment attempts results from the Payment Terms and concerns the Customer as an entrepreneur; the decision may be clarified with customer support at any time.
10. Security
Mivare applies technical and organisational measures appropriate to the risk, in particular encryption of connections, storage of passwords solely in the form of a cryptographic hash, two-factor authentication, logical separation of each workshop's data, event logging and backups. A detailed description is contained in the Data Processing Agreement (MWK-LEG-003).
11. Changes to the Policy
This Policy is updated whenever there is a change in the manner of data processing, the recipients or the legislation. We inform Account Administrators of material changes by e-mail and in the Application. The current version is available at https://mivaregroup.com/en/legal/works/privacy/
This Policy is made available in seven language versions; in the event of any discrepancy, the Polish version prevails. This Policy is effective from 1 October 2026.
MIVARE GROUP