Current version: 1 · Effective date: 5 September 2026 · Last updated: 5 September 2026
1. General Provisions
- The controller of personal data within the meaning of applicable data-protection regulations is REVONG MAREK POTARGOWICZ spółka komandytowa, with its registered office at ul. Rakowska 16/130, 02-237 Warsaw, Poland, entered in the Register of Entrepreneurs maintained by the District Court for the Capital City of Warsaw in Warsaw, XIV Commercial Division of the National Court Register, KRS 0001010291, NIP 5223245103 (the Administrator).
- The Administrator processes personal data in accordance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the GDPR); and
- the Polish Act of 10 May 2018 on the Protection of Personal Data.
- Questions about personal-data protection and requests to exercise data-subject rights should be sent to support@revong.com.
- The Administrator gives particular attention to the privacy of people contacting the Administrator and its clients (collectively, Users). Personal data is collected with due care, kept confidential, and protected from unauthorized access.
- The Administrator uses appropriate organizational, IT, and technical safeguards to protect personal data against accidental, unlawful, or unauthorized destruction, loss, alteration, disclosure, use, or access.
- Personal data is disclosed only to entities that need it to perform their tasks and is processed only for the purposes described in this Policy.
2. User Rights
Subject to the conditions and limitations established by applicable law, a User has the right to:- Access personal data — obtain confirmation whether the Administrator processes the User’s personal data, access that data, receive information about the purpose and categories of processing, recipients, and the planned retention period or the criteria used to determine it, and receive a free copy. The Administrator may charge a reasonable fee based on administrative costs for additional copies.
- Rectify personal data — correct inaccurate data and complete incomplete data.
- Erase personal data — request deletion when the data is no longer necessary, consent has been withdrawn and no other legal basis applies, the User has successfully objected, processing was unlawful, deletion is required by law, or the data was collected in connection with information-society services.
- Restrict processing — request restriction while accuracy is verified, when processing is unlawful but the User opposes deletion, when the Administrator no longer needs the data but the User needs it for legal claims, or while an objection is being assessed.
- Object to processing — object where processing is based on legitimate interests, including an unconditional right to object to processing for direct-marketing purposes.
- Data portability — receive personal data provided by the User in a structured, commonly used, machine-readable format and, where technically feasible, request its direct transmission to another controller.
- Withdraw consent — withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Lodge a complaint — submit a complaint to the President of the Polish Personal Data Protection Office if the User believes that processing infringes the GDPR.
3. Data Recipients
- The Administrator uses external service providers where necessary to operate the Platform and provide professional services. The Administrator selects providers that give sufficient guarantees that processing will meet GDPR requirements and protect data-subject rights.
- Recipients may include providers of:
- accounting, legal, advisory, and debt-collection services;
- hosting and cloud-computing services;
- CRM, invoicing, and payment systems;
- software, email, live-chat, marketing-automation, AI, business-management, and technical-support services; and
- other services necessary to operate the Platform and provide contracted services.
- Processors entrusted with personal data must apply appropriate protection and security measures. Where required, the Administrator enters into a data-processing agreement compliant with Article 28(3) GDPR.
- The Administrator may disclose information to authorized public authorities when required by a lawful request and only to the extent required by that request.
4. Purposes, Legal Bases, Retention, and Data Scope
Email Contact
Platform Chat Contact
Client Account Agreement
Accounting and Tax Records
Legal Claims
Marketing and Online Presence
AI Assistant
AI Assistant data notice. Information submitted to the AI Assistant may be transferred to an external AI service provider to provide the requested functionality. Do not submit personal data, confidential information, or credentials unless it is necessary, authorized, and permitted by your organization’s policy.
5. Cookies
- The Platform uses cookies: small text files stored on the User’s device that can be read by the Platform’s systems.
- During the first visit, the Platform presents information about cookie use and, where required, requests consent. Users can change cookie choices in the Platform or browser and can delete cookies stored on their device.
- Disabling cookies may prevent authentication, preference retention, or other Platform functionality from working correctly.
- First-party cookies are used to operate the Platform. Features delivered by third parties may use third-party cookies.
- Cookies may be used to:
- identify and authenticate Users;
- remember Platform activity, preferences, completed-form data, or login state;
- protect sessions and prevent abuse; and
- measure Platform usage and maintain statistics.
- Browser cookie settings can affect whether cookies are accepted. Where consent is required, Users can withhold or withdraw it through the available cookie controls or browser settings.
Analytics and Advertising Services
The Administrator may use Google Analytics to create statistics, analyze Platform usage, and improve Platform operation. Information collected by that service may be transmitted to Google systems in accordance with Google’s applicable terms and privacy controls. The Administrator may also use Google Ads and Meta advertising tools, including Facebook and Instagram advertising services, subject to the User’s cookie choices and applicable law.6. Server Logs
- Using the Platform causes requests to be sent to the servers and services that operate it. Requests may be recorded in technical and security logs.
- Logs can include the User’s IP address, request date and time, browser and operating-system information, request metadata, correlation identifiers, and security or error information.
- Logs are used for Platform administration, security, reliability, incident response, support, and technical diagnosis. They are disclosed only to authorized personnel and service providers that require access for those purposes.
- Depending on the contracted Plan and assigned permissions, Users may have limited access to logs and operational evidence for their own RevoEngine instance.
7. Final Provisions
- This Policy may be updated when processing activities, Platform functionality, providers, or applicable law change.
- The Administrator will provide advance notice when required by law or when a change materially affects Users.
- The version published on this page is the current version of the Policy.

