Privacy Policy of PicoToolkit.com

1. Controller and Contact

This Privacy Policy explains how we process personal data of users of the website PicoToolkit.com (the "Service").

The controller of your personal data is: RR-Soft ul. Kierbedzia 8A 00-728 Warszawa, Poland VAT-EU: PL921-192-91-92 (hereinafter the "Controller", "we", "us").

You can contact us via the contact form.

2. Scope of this Privacy Policy

This Privacy Policy applies to the processing of personal data in connection with:

  • use of the Service and its tools for text editing and data extraction,
  • use of the banner editor,
  • creation and use of user accounts,
  • use of cookies and similar technologies, including Google Analytics 4 and Google Tag Manager.

3. Categories of Data We Process

In particular, we may process the following categories of data:

  • Account data — e.g. email address, password (stored in hashed form), username and other details you provide in your profile.
  • Service usage data — e.g. logs related to your use of the tools, timestamps, basic technical information about your browser and device.
  • Content you submit — text and data that you paste or upload into the tools (for processing at your request).
  • Analytics data — information collected via cookies and similar technologies, including Google Analytics 4 (GA4), such as approximate location (country/region), device type, operating system, browser type, pages viewed and events tracked.

4. Purposes and Legal Bases of Processing

We process personal data for the following purposes:

  • Providing the Service
    To enable you to use the text tools, data extraction tools and banner editor, to maintain your user account, and to ensure the technical operation of the Service.
    Legal basis: performance of a contract (Art. 6(1)(b) GDPR) or steps taken at your request before entering into a contract.
  • Ensuring security and preventing abuse
    To monitor and prevent misuse, attacks and other violations of the Service, and to maintain logs for security and troubleshooting.
    Legal basis: legitimate interests of the Controller (Art. 6(1)(f) GDPR), i.e. protecting the Service and users.
  • Analytics and statistics (Google Analytics 4)
    To analyse how the Service is used, improve features, usability and performance, and understand aggregated user behaviour.
    Legal basis: your consent (Art. 6(1)(a) GDPR), given via the cookie and tracking preferences banner, where applicable.
  • Communication with you
    To respond to your messages sent via the contact form and to handle requests and complaints.
    Legal basis: performance of a contract or steps taken at your request (Art. 6(1)(b) GDPR) and/or legitimate interests (Art. 6(1)(f) GDPR), i.e. responding to user queries.
  • Compliance with legal obligations
    To fulfil obligations under applicable law, including accounting and tax regulations, if relevant.
    Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).

5. User Accounts

You may create a user account in the Service to access certain functionalities (for example, saving settings, projects or content).

For this purpose, we process in particular:

  • email address,
  • password (stored only in hashed form and never in plain text),
  • username or display name,
  • information related to your use of the account (e.g. saved projects).

You can request deletion of your account at any time. Deleting the account may result in loss of access to previously saved projects or settings.

6. Processing of Content You Submit

The text and data that you paste or upload into our tools are processed solely for the purpose of providing the functionality you have requested (e.g. format conversion, extraction, banner generation).

We do not use your content for marketing purposes or for training external machine learning models, unless we explicitly inform you and you agree to such use.

We recommend that you do not submit content containing special categories of personal data (e.g. health data, data revealing racial or ethnic origin, political opinions, etc.), unless it is strictly necessary and you are authorised to process such data.

7. Google Analytics 4 and Google Tag Manager

We use Google Analytics 4 (GA4) to obtain statistical and analytical information about how users interact with the Service. GA4 is provided by Google Ireland Limited (for users in the EU/EEA).

In particular:

  • Google Analytics 4 collects information such as pages viewed, time spent on pages, type of device and browser, basic demographic data (if available), and interactions with the Service.
  • We use IP anonymisation features where available so that your full IP address is not stored in GA4.
  • Data collected via GA4 is processed on the basis of your consent (where required). You can withdraw your consent at any time through your cookie settings or browser settings.

We also use Google Tag Manager to manage scripts and tags in the Service. Google Tag Manager itself does not collect personal data that can directly identify you; it is a tool for managing other scripts (such as GA4).

You can control or block the use of cookies through your browser settings. Disabling analytics cookies may affect the completeness of statistics but does not prevent use of the Service.

8. Cookies and Similar Technologies

The Service uses cookies and similar technologies to ensure proper operation and to conduct analytics.

We may use, in particular:

  • Necessary cookies — required for the basic functioning of the Service (e.g. session cookies, preferences). These may be used without your prior consent.
  • Analytics cookies — for statistical and analytical purposes (e.g. GA4). These are used on the basis of your consent, where required by law.

You can manage your cookie preferences via the Service (if a cookie banner or preference centre is available) and via your browser settings.

9. Recipients of Data

We may share personal data with the following categories of recipients:

  • providers of hosting and IT infrastructure services,
  • providers of analytics tools (in particular Google Analytics 4),
  • entities providing technical and support services to the Controller (e.g. maintenance, security, monitoring),
  • public authorities and bodies, if required by applicable law.

In some cases, data may be transferred outside the European Economic Area (EEA), e.g. to the United States, in connection with the use of services provided by Google. In such cases, we ensure that appropriate safeguards are in place, in accordance with GDPR (such as standard contractual clauses or other legal mechanisms), unless there is an adequacy decision by the European Commission.

10. Data Retention Periods

We store personal data for no longer than is necessary for the purposes for which it is processed, in particular:

  • account data — for the duration of the existence of your account and for a reasonable period after its deletion, if required to protect against claims or to comply with legal obligations,
  • communication data (e.g. messages sent via the contact form) — for the time needed to handle the request and for a reasonable period afterwards, if necessary,
  • analytics data — in accordance with the standard retention periods configured in Google Analytics 4 or as required by law.

11. Your Rights under GDPR

As a data subject, you have the following rights, subject to the conditions and limitations set out in GDPR:

  • Right of access — to obtain confirmation whether we process your personal data and to receive a copy of such data.
  • Right to rectification — to have inaccurate personal data corrected and incomplete data completed.
  • Right to erasure ("right to be forgotten") — to request deletion of your personal data in certain circumstances.
  • Right to restriction of processing — to request limitation of processing in certain situations.
  • Right to data portability — to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit it to another controller, where technically feasible.
  • Right to object — to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 6(1)(f) GDPR).
  • Right to withdraw consent — where processing is based on your consent, you may withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Right to lodge a complaint — you have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or place of the alleged infringement. In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).

To exercise your rights, you can contact us via the contact form.

12. Automated Decision-Making

We do not use personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.

13. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, in particular in the event of changes in the law, technology or the functioning of the Service.

The updated Privacy Policy will be published in the Service with an indication of the date from which it applies.

14. Final Provisions

This Privacy Policy is intended to implement the information obligations under Regulation (EU) 2016/679 (GDPR) and applicable Polish data protection laws.

The Policy is available in the Service in a form that allows it to be saved and printed by the user.

© PicoToolkit 2022-2025 All rights reserved. Before using this website read and accept terms of use and privacy policy. Icons by Icons8