§ Terms & Policies
Terms of Service, policies and annexes of the SCCOT application
Terms of Service of SCCOT
§ 1. General provisions and Service Provider details
1.These Terms of Service set out the rules for the provision by electronic means of services of access to the SCCOT application (the "Application"), available at app.sccot.pl, as well as the conditions for concluding and terminating agreements, the complaint procedure and the rules of liability. These Terms of Service constitute terms and conditions within the meaning of Article 8 of the Polish Act of 18 July 2002 on the Provision of Electronic Services and a standard form contract within the meaning of Article 384 of the Polish Civil Code.
2.The Service Provider is Appi Soft Sp. z o.o., with its registered office in Chodzież, ul. Zwycięstwa 23, 64-800 Chodzież, entered in the Register of Entrepreneurs of the National Court Register under KRS number 0000867371, kept by the District Court for Poznań – Nowe Miasto i Wilda in Poznań, 9th Commercial Division of the National Court Register, NIP 6070090336, REGON 387392804, share capital PLN 12,500.00 (the "Service Provider").
3.Contact with the Service Provider: e-mail [email protected], technical support: [email protected], chat in the Application, correspondence address as above, telephone 502 634 517. Matters concerning personal data: [email protected].
4.The Terms of Service are made available free of charge at sccot.pl/regulaminy before the agreement is concluded, in a form that allows them to be downloaded, stored and printed.
5.The Polish version of the Terms of Service is binding. The English version is for information purposes only.
6.The following form an integral part of the agreement: (a) the Price List available at sccot.pl/cennik, (b) the Module-Specific Terms (Annex 2 to the Terms of Service), (c) the Data Processing Agreement together with the List of Sub-processors. In the event of any conflict, the Module-Specific Terms of a given module shall prevail over the Terms of Service with respect to that module.
§ 2. Definitions
1.Subscriber means an entrepreneur (a natural person conducting business activity, a legal person or an organisational unit without legal personality to which the law grants legal capacity), with its registered office in Poland or abroad, that has concluded with the Service Provider an agreement for the provision of Services in connection with its business or professional activity.
2.Entrepreneur with Consumer Rights (ECR) means a Subscriber who is a natural person concluding an agreement directly related to their business activity, where the content of the agreement shows that it is not of a professional nature for that person, arising in particular from the subject of the business activity performed, as made available in CEIDG.
3.User means a natural person using the Application within the Subscriber's Account, including the account owner and the Subscriber's employees and associates for whom the Subscriber has created accounts.
4.Account means the Subscriber's account in the Application together with the Users' accounts.
5.Services means the functionalities of the Application made available under the selected Plan, as described in § 3 and in the Module-Specific Terms.
6.Plan means a package of Services (Free, Basic, Standard, Premium or another indicated in the Price List).
7.Billing Period means the period for which a fee is charged, in accordance with the Price List.
8.Subscriber Data means any data and content entered into the Application by the Subscriber or Users (including records, offers, projects, invoices and files), excluding the RMS System Database.
9.End Customer means a counterparty of the Subscriber to whom the Subscriber makes offers or documents available via the Application.
10.Technical Break means a scheduled temporary shutdown of the Application, in whole or in part, for the purpose of maintenance, updating or expansion.
§ 3. Scope of the Services
1.As part of the Services, the Service Provider makes available, depending on the Plan: (a) Quoting, (b) Client Interface (making offers and documents available to End Customers by means of a link), (c) Projects (Orders), (d) RMS Own Database, (e) RMS System Database, (f) Tickets (Service Requests), (g) Calendar with integration with Google Calendar, (h) Invoicing with KSeF support, (i) the CRM module, (j) Document Library, (k) API and integrations.
2.Individual functionalities are available from the moment they are made available in the Application. Until then, the provisions of the Terms of Service and the Module-Specific Terms relating to them do not apply. The Service Provider posts information on the availability of a new functionality in the Application.
3.The detailed scope of functionalities of individual Plans is set out in the Price List. Modules subject to specific rules are governed by the Module-Specific Terms.
4.The Service Provider may develop and change the Application, including by adding, changing and withdrawing functionalities. The Service Provider shall give at least 14 days' advance notice of changes that materially restrict the use of the Services; in such a case, the Subscriber may terminate the agreement with immediate effect and receive a refund of the proportionate part of the fee for the unused Billing Period.
5.Document localisation. The Application enables documents to be generated in a selected language (only the fixed fields of templates are translated, not the content of items and records), in a selected currency (with conversion at National Bank of Poland (NBP) exchange rates), with a selected time zone, date format and VAT rates. These are auxiliary tools. The Service Provider does not warrant that documents generated in the Application comply with the requirements of the law of any country other than Poland; the Subscriber is responsible for the compliance of documents with the regulations applicable to the Subscriber and its customers. Exchange rates are for information purposes only and the Subscriber shall verify them before use, in particular for tax purposes.
§ 4. Technical requirements and risks
1.The following are required to use the Application: a device with Internet access, a current version of any web browser with JavaScript enabled and with the cookies necessary for the operation of the Application enabled, and an active e-mail address.
2.The use of services provided by electronic means involves risks typical of the Internet, in particular: interception of login credentials (phishing), malware, unauthorised access where a logged-in session is left on a shared device, and interception of a link to a shared offer or calendar. The Service Provider recommends using strong passwords, logging out on shared devices and not sharing links with unauthorised persons. The Subscriber may also log in to the Application using a Google account, making use of the security features of that account.
§ 5. Conclusion of the agreement and the Account
1.The agreement for the provision of Services is concluded upon the creation of an Account by completing the registration form and accepting the Terms of Service, or by registering with a Google account and accepting the Terms of Service.
2.The person creating an Account on behalf of the Subscriber represents that they are authorised to represent the Subscriber.
3.The Subscriber creates User accounts and grants them permissions. The Subscriber is liable for the actions of Users as for its own actions, for keeping their data up to date and for ensuring that Users are familiar with and comply with the Terms of Service.
4.Login credentials are confidential. Sharing a single User account among several persons is prohibited.
5.After creating an Account, the Subscriber receives a free trial period of 7 days, during which it may use the Premium Plan. After the trial period ends, if the Subscriber does not select a paid Plan, the Account is switched to the Free Plan.
6.The Subscriber confirms the e-mail address provided during registration by clicking the link sent to that address. Until confirmation, the Service Provider may restrict access to the Services and, if 14 days have elapsed from registration without confirmation, suspend access to the Account until the address is confirmed.
§ 6. Price List, payments and invoices
1.The fees for the Services are set out in the Price List available at sccot.pl/cennik. Prices are stated as net amounts; VAT at the applicable rates is added to the prices, subject to para. 7. The Free Plan is free of charge.
2.Fees are charged in advance for the selected Billing Period. Payments are handled by Stripe Payments Europe, Ltd. (Ireland). The available payment methods are payment card, BLIK, instant transfer (Przelewy24) and traditional bank transfer. The Service Provider does not store full payment card data.
3.Automatically renewing subscription. If the Subscriber pays for the Services by payment card with the card saved, the subscription renews automatically for a further Billing Period of the same length, unless the Subscriber cancels it before the end of the current period. The Service Provider sends an e-mail reminder of the upcoming renewal and the amount of the fee at least 7 days before renewal. Failure to receive the reminder does not affect the effectiveness of the renewal.
4.One-off payment. The Subscriber may pay for the selected Billing Period as a one-off payment, by BLIK or bank transfer, without saving a payment card. In such a case, the subscription does not renew automatically: access to the paid Plan expires at the end of the paid Billing Period and the Account is switched to the Free Plan. The Subscriber may extend access by making a further payment before or after the end of the paid period.
5.The Subscriber may cancel a paid Plan at any time in the Account settings. The cancellation takes effect at the end of the paid Billing Period; thereafter the Account is switched to the Free Plan and the Subscriber Data are retained. An upgrade to a higher Plan takes effect immediately with a proportionate additional payment, and a downgrade to a lower Plan takes effect from the beginning of the next Billing Period.
6.The Service Provider issues structured invoices in the National e-Invoicing System (KSeF), including for foreign Subscribers; a visualisation of the invoice is sent to the Subscriber's e-mail address. At the Subscriber's request, an invoice may be issued in a currency other than PLN.
7.The reverse charge mechanism applies to Subscribers from another EU Member State holding a valid EU VAT number. The Subscriber is obliged to provide a correct EU VAT number; the Service Provider verifies it in the VIES system. If the number proves to be invalid, the Service Provider adds VAT at the Polish rate.
8.Individual discounts are granted by the Service Provider at its discretion. In the event of a downgrade to a lower Plan or a reduction in the number of Users below the number on the basis of which the discount was granted, the discount may be reduced accordingly or expire, unless the parties agree otherwise.
9.In the event of non-payment, the Service Provider may, after an unsuccessful demand for payment setting a 7-day deadline, switch the Account to the Free Plan or restrict access to paid functions. Subscriber Data are not deleted for this reason.
§ 7. Rules for using the Application
1.The Subscriber and Users undertake to use the Application in accordance with the law, the Terms of Service and good practice, and in particular not to enter unlawful content, content infringing the rights of third parties (including copyright in photographs, descriptions and documents) or malware, and not to take any actions disrupting the operation of the Application.
2.The following are prohibited: (a) circumventing security measures and Plan limits, (b) automated retrieval of data from the Application other than through the API made available, in particular bulk copying of the RMS System Database, (c) generating load in a manner that threatens the stability of the Application, (d) sending unsolicited commercial information by means of the Application.
3.Specially protected data. The Application is not intended for processing special categories of personal data (e.g. health data), PESEL numbers or scans of identity documents. If the Subscriber nevertheless enters such data, it does so at its own risk as the controller of such data and shall ensure that there is a legal basis for their processing.
4.If the Subscriber uses functions showing Users' activity (e.g. presence in the Application), it is responsible for ensuring that such use complies with labour law and personal data protection law in relation to its employees and associates.
§ 8. Offers, calculations and document templates
1.The Application is a tool supporting the preparation of offers, cost estimates, projects and invoices. Before sending or using a document, the Subscriber shall check its content, including items, quantities, prices, discounts, totals and taxes, in the preview or in the generated PDF file. Agreements with End Customers are concluded by the Subscriber in its own name; the Service Provider is not a party to them.
2.If an error in calculations or in the presentation of a document is identified, the Subscriber shall report it without delay as a complaint (§ 11). To determine the cause of the error, the parties shall use the history of changes and versions of the document recorded in the Application.
3.Document templates may contain sample texts (e.g. terms of cooperation or warranty terms). These are sample templates which do not constitute legal advice and must be adapted by the Subscriber to its situation and the applicable regulations, in particular consumer protection regulations if the End Customer is a consumer. The Subscriber is responsible for the content of the documents sent.
4.The data in the RMS System Database are for information and illustrative purposes, on the terms set out in the Module-Specific Terms for the RMS System Database module.
§ 9. Availability, Technical Breaks and backups
1.The Service Provider exercises due diligence to ensure that the Application is available continuously, but does not guarantee its uninterrupted availability. The Service Provider is not liable for interruptions in the availability of the Application resulting in particular from Technical Breaks, failures, force majeure, the operation of third-party services over which the Service Provider has no control (including Google, payment operators and the KSeF system), or actions of the Subscriber.
2.The Service Provider remedies failures without undue delay. Interruptions in the availability of the Application lasting in total no more than 48 hours in a calendar month, as well as the interruptions referred to in para. 1, do not constitute non-performance or improper performance of the agreement and do not entitle the Subscriber to a reduction of the fee.
3.The Service Provider gives notice of Technical Breaks in the Application or by e-mail.
4.The Service Provider makes backups of the Application database, as a rule daily, and retains them for 7 days. Backups do not cover files stored in the Application (attachments, photographs, documents). Backups serve solely to restore the Application after a failure and do not replace the Subscriber's own copies. The Subscriber may download its data at any time in accordance with § 17 and, if it is unable to do so itself, may request that they be made available by e-mail to [email protected].
§ 10. Technical support and Service Provider access to the Account
1.Technical support is provided on business days, as a rule via chat in the Application during the hours 7:00–17:00 and by e-mail during the hours 7:00–15:00. The Service Provider does not guarantee the time within which a response will be given or a request resolved.
2.Authorised employees and associates of the Service Provider may access the Account and Subscriber Data to the extent necessary to provide the Services, in particular to provide technical support at the request of the Subscriber or a User, to remedy a failure or error, to ensure the security of the Application and to perform obligations arising from the law.
3.The persons referred to in para. 2 are bound by confidentiality. Access does not include the use of Subscriber Data for purposes other than those indicated in para. 2.
§ 11. Complaints
1.Complaints concerning the Services may be submitted by e-mail to [email protected] or in writing to the Service Provider's address. A complaint should contain the Subscriber's details, a description of the problem and, if possible, the date on which it occurred and screenshots. The Subscriber may use the model form constituting Annex 5; use of this model is not mandatory.
2.The Service Provider shall consider a complaint within 14 days of its receipt and shall notify the outcome by e-mail. Failure to respond within this period to a Subscriber who is an ECR shall mean that the complaint has been accepted.
3.If a complaint is upheld, the Service Provider shall remove its cause within a reasonable time. This does not limit the claims of an ECR arising from the provisions on the conformity of a digital service with the agreement (§ 14).
§ 12. Liability
1.The Service Provider provides the Services with due diligence. The Subscriber acknowledges that the Application, like any software, is not and will not be free of errors. The Service Provider remedies reported errors without undue delay; remedying an error constitutes the Service Provider's sole performance in this respect, subject to para. 5.
2.The Service Provider is not liable for: (a) the content of Subscriber Data and of documents sent by the Subscriber to End Customers, (b) the consequences of failure to check documents before sending them (§ 8(1)), (c) the operation of third-party services with which the Subscriber integrates the Application (e.g. Google, e-mail providers, providers of data to the RMS System Database), (d) the consequences of the Subscriber or Users disclosing login credentials or links to third parties, (e) the consequences of errors in the Application, including errors in calculations or in the presentation of documents, in particular errors detectable in the course of the verification referred to in § 8(1), (f) administrative, tax or fiscal penal sanctions imposed on the Subscriber.
3.National e-Invoicing System. The Service Provider is not liable for the availability, operation or changes of the National e-Invoicing System, in particular for interruptions in its operation, the rejection of a document by that system or the consequences of changes introduced by administrative authorities. The Service Provider exercises due diligence to ensure that the Application functions supporting KSeF comply with the applicable logical structure of the structured invoice and, if any non-compliance is identified, remedies it without undue delay.
4.The total liability of the Service Provider towards the Subscriber under the agreement, irrespective of the legal basis, is limited to actual loss, but not more than the amount of the fee paid by the Subscriber for the Billing Period in which the event causing the damage occurred. The Service Provider is not liable for lost profits. The Service Provider bears no liability for damages towards a Subscriber using the Free Plan or the free trial period.
5.The limitations and exclusions of liability in § 12(2)–(4) do not apply: (a) to damage caused intentionally or through gross negligence, (b) towards an ECR to the extent that the law does not permit their exclusion or limitation.
§ 13. Illegal content (DSA notices)
1.Any person may notify the Service Provider of content available in the Application or via a shared link which that person considers to be illegal, by e-mail to [email protected] or via the form available at sccot.pl.
2.A notice should contain: a sufficiently substantiated explanation of the reasons why the notifying person considers the content to be illegal; a clear indication of the exact electronic location of the content (URL address); the name or business name and e-mail address of the notifying person (except for notices concerning offences referred to in Articles 3–7 of Directive 2011/93/EU); and a statement that the notifying person is acting in good faith and believes the information contained in the notice to be accurate and complete.
3.The Service Provider processes notices without undue delay, in an objective and non-arbitrary manner. If content is removed, access to it is restricted or the Account is restricted, the Service Provider provides the Subscriber with a statement of reasons for the decision, together with its basis, information on how it was taken and information on the possibility of challenging it.
4.Point of contact for the authorities of the Member States, the European Commission and the European Board for Digital Services, and for recipients of the service: [email protected]. The languages of communication are Polish and English.
§ 14. Entrepreneurs with Consumer Rights
1.The provisions of this section apply solely to Subscribers who are ECRs.
2.Withdrawal from the agreement. An ECR may withdraw from the agreement without giving any reason within 14 days of its conclusion and, where a paid Plan was purchased after the expiry of that period, also within 14 days of the date of the first payment for that Plan. The statement of withdrawal may be submitted in particular by e-mail to [email protected] or using the model form constituting Annex 4. If the ECR requested that the provision of a paid Service begin before the expiry of the withdrawal period and acknowledged the consequences of that request, the ECR shall pay remuneration proportionate to the period of provision until the moment of withdrawal.
3.Conformity of the Services with the agreement. The Service Provider is liable towards an ECR for the conformity of the Services with the agreement on the terms of Chapter 5b of the Polish Consumer Rights Act. In the event of non-conformity, the ECR may demand that the Service be brought into conformity and, in the cases specified in that Act, a price reduction or withdrawal from the agreement.
4.A change to the Services which materially and adversely affects the ECR's access to or use of the Services entitles the ECR to terminate the agreement within 30 days of the change or of being informed of it.
5.§ 20(3) (competent court) does not apply to an ECR if this would be contrary to mandatory provisions of law.
§ 15. Intellectual property rights
1.The Application, its code, layout, graphics, documentation and the RMS System Database (except for the supplier data referred to in the Module-Specific Terms) are the property of the Service Provider or are licensed to it.
2.The Service Provider grants the Subscriber a non-exclusive, non-transferable licence to use the Application via a web browser for the term of the agreement, within the scope of the selected Plan. The licence does not include the right to decompile or modify the Application or to make it available to third parties other than Users.
3.Subscriber Data belong to the Subscriber. The Subscriber grants the Service Provider a free-of-charge licence to store, process, reproduce and display Subscriber Data solely to the extent necessary to provide the Services (including making them available to End Customers indicated by the Subscriber), to make backups and to perform legal obligations.
4.The Subscriber may use documents generated in the Application without time limitation, including after the termination of the agreement.
5.The Subscriber warrants that it holds the rights to the content entered into the Application (including photographs, descriptions, logos and attachments) and releases the Service Provider from liability towards third parties in this respect.
6.The Service Provider may use, free of charge, suggestions and feedback concerning the development of the Application submitted by the Subscriber or Users.
7.The Service Provider analyses the manner in which the Application is used for the purpose of its development, improving the quality and security of the Services and planning new functions. The analysis covers data on the use of individual functions, including data linked to the Account and to the characteristics of the Subscriber's business (size, industry, selected Plan). The analysis does not cover the content of Subscriber Data (offers, records, documents, correspondence or files). The Service Provider uses and discloses the results of the analyses solely in aggregated form that does not allow the Subscriber or any User to be identified.
8.The rules for the use of external analytics and marketing tools, including the conditions of consent, are set out in the Cookie Policy.
§ 16. Information on cooperation in the Service Provider's materials
1.The Subscriber consents to its name and logo being placed on the Service Provider's list of customers on the sccot.pl website and in informational materials. This consent may be withdrawn at any time in the Account settings or by e-mail; the Service Provider then removes the information within 14 days.
2.The preparation of a case study, including one containing statements or the image of persons acting on behalf of the Subscriber, requires the separate consent of the Subscriber and of those persons.
§ 17. Switching providers, data export and termination of the agreement
1.The Subscriber may terminate the agreement at any time by submitting a notice by e-mail to [email protected] or by deleting the Account in the Application settings, if this function is available. Cancellation of a paid Plan does not constitute termination of the agreement (§ 6(5)).
2.The Subscriber may at any time, including for the purpose of switching providers or transferring data to its own infrastructure, download Subscriber Data comprising: counterparties, offers, projects, invoices, tickets and records of the RMS Own Database in spreadsheet format (XLSX), and files and attachments in a ZIP archive, with their names and assignment to documents preserved. The export does not cover the RMS System Database; the rules for exporting records created on its basis are set out in Module 5 paras. 5–7 of the Module-Specific Terms.
3.Until the self-service export function is made available, the Service Provider prepares and makes Subscriber Data available at the Subscriber's request sent to [email protected], free of charge, within 14 days of the request.
4.After termination of the agreement, the Subscriber has 30 days to download the Subscriber Data (transition period). At the Subscriber's justified request, this period may be extended once. During this time, the Service Provider provides assistance with the export. The Service Provider does not charge any fees for switching providers or for data export.
5.After the expiry of the period referred to in para. 4, the Service Provider permanently deletes Subscriber Data from production systems within 7 days, and from backups within their rotation period, no later than after a further 7 days, except for data whose retention is required by law (e.g. data for the Service Provider's invoices).
6.The Service Provider may delete an Account on the Free Plan that has not been used for at least 12 months, after notifying the Subscriber by e-mail at least 30 days in advance. Before deletion, the Subscriber may download the Subscriber Data in accordance with § 17(2)–(3).
7.The Service Provider may terminate the agreement with 30 days' notice for important reasons, in particular the discontinuation or material change of the provision of the Services, a change in the law, or technical or security reasons. The Service Provider may terminate the agreement with immediate effect if the Subscriber grossly or persistently breaches the Terms of Service, in particular § 7, after an unsuccessful demand to cease the breaches (unless the breach threatens the security of the Application or of other Subscribers). § 17(4)–(5) apply accordingly.
§ 18. Amendments to the Terms of Service
1.The Service Provider may amend the Terms of Service for important reasons, which are: (a) a change in the law or a decision of an authority, (b) the introduction, change or withdrawal of functionalities or modules, (c) a change in payment methods or service providers, (d) the need to ensure security, (e) a change of prices in the Price List, (f) improving clarity or removing ambiguities.
2.The Service Provider notifies the Subscriber of an amendment by e-mail and in the Application at least 14 days before it enters into force, and in the case of a price change at least 30 days before it enters into force. Amendments required by law or by a decision of an authority may enter into force within the time limit required thereby.
3.A Subscriber who does not accept the amendments may terminate the agreement before the date on which they enter into force, with effect as of that date. Failure to terminate the agreement before the date on which the amendments enter into force constitutes acceptance of the amendments. A price change does not apply to a Billing Period that has already been paid for.
4.The Application records the acceptance of each version of the Terms of Service (date, version, User).
§ 19. Personal data
1.The rules for the processing of personal data for which the Service Provider is the controller are set out in the Privacy Policy available at sccot.pl/regulaminy. The rules for the use of cookies are set out in the Cookie Policy.
2.With respect to Subscriber Data containing personal data, the Service Provider acts as a processor under the Data Processing Agreement, which constitutes an annex to the Terms of Service and is concluded together with the agreement for the provision of Services.
3.The use by the Subscriber of the functions of the Application in accordance with the Terms of Service, in particular the activation of a module or integration and a change of Plan, constitutes an instruction for processing within the meaning of Article 28(3)(a) GDPR.
§ 20. Final provisions
1.The agreement is governed by Polish law, including in relations with foreign Subscribers.
2.The parties shall seek to resolve disputes amicably.
3.Disputes shall be resolved by the common court having jurisdiction over the Service Provider's registered office, subject to § 14(5).
4.The Terms of Service enter into force on 1 November 2026. With respect to Subscribers who concluded the agreement before that date, the procedure for amending the Terms of Service (§ 18) applies.
5.Confidentiality. Each party undertakes to keep confidential the non-public information of the other party obtained in connection with the performance of the agreement, in particular Subscriber Data, individually agreed commercial terms and technical and commercial information concerning the Application, and to use such information solely for the purpose of performing the agreement. This obligation applies for the term of the agreement and for 3 years after its termination. It does not apply to publicly available information, information whose disclosure is required by law or by a competent authority, or information disclosed to entities acting on behalf of a party who are bound by confidentiality.
Annexes
Annex 1: Price List (sccot.pl/cennik)
Annex 2: Module-Specific Terms (separate document)
Annex 3: Data Processing Agreement together with the List of Sub-processors (separate document)
Annex 4: Model Withdrawal Form (for ECRs)
Annex 5: Model Complaint Form
Privacy Policy of SCCOT
1. Controller of personal data
The controller of the personal data referred to in this Privacy Policy is Appi Soft Sp. z o.o., with its registered office in Chodzież, ul. Zwycięstwa 23, 64-800 Chodzież, entered in the register of entrepreneurs of the National Court Register under KRS number 0000867371, NIP 6070090336, REGON 387392804 (hereinafter: the "Controller"). In matters concerning the protection of personal data, the Controller may be contacted at the e-mail address [email protected], by telephone at 502 634 517, or in writing at the address of the registered office. Capitalised terms have the meanings given to them in the Terms of Service of SCCOT.
2. Role of the Controller
1.The Controller acts as the controller of the personal data of: Users of the Application (with respect to maintaining the Account, logging in, billing, technical support, security, communication, analytics and marketing), persons contacting the Controller and its business partners, visitors to the sccot.pl website, persons reporting illegal content, as well as data obtained from Google within an integration activated by the User (section 5).
2.The Controller processes data on behalf of Subscribers with respect to the data entered by them into the Application, in particular data of their customers, business partners, contact persons, recipients of offers and documents, and correspondence conducted in the CRM module. The Subscriber is the controller of such data, and the Controller acts as a processor on the basis of the Data Processing Agreement. A person who has received an offer or a document via the Application should direct requests concerning their data to the sender; the Controller assists the sender in fulfilling such requests.
3. Scope, purposes and legal bases of processing
3.1. Users of the Application
| Purpose | Data | Legal basis | Retention period |
|---|---|---|---|
| Creating and maintaining the Account, logging in (including via Google), provision of services | E-mail, password (stored in secured form), first name, surname, telephone, position or role, language, Google identifier, company data, year of birth and gender (if provided) | Contract (Article 6(1)(b) GDPR); with respect to employees and associates of the Subscriber: the Controller's legitimate interest consisting in the provision of the Services to the Subscriber (Article 6(1)(f) GDPR) | For the duration of the contract, including under the Free Plan; after deletion of the Account: 30 days to download the data, followed by deletion within 7 days; from backups in their rotation cycle, within a further 7 days |
| Adapting the Application to the Subscriber's business profile (onboarding wizard) | Industries, number of persons preparing offers, number of offers | Contract / legitimate interest | As above |
| Billing and invoices | Invoicing data, NIP, address, payment history (without card number) | Legal obligation (Article 6(1)(c) GDPR): tax and accounting regulations | 5 years from the end of the year in which the tax liability arose |
| Technical support (chat, e-mail) | Account data, content of correspondence | Contract / legitimate interest | 3 years from the end of the correspondence |
| Security, abuse prevention, form protection (reCAPTCHA), technical logs, error monitoring | IP address, browser data, identifiers, event logs | Legitimate interest of the Controller (Article 6(1)(f) GDPR) | 14 days |
| Information on presence in the Application visible to other Users of the Subscriber | Date of last activity, current session | Legitimate interest of the Subscriber and the Controller (organisation of work at the Subscriber) | Overwritten on an ongoing basis |
| Communication concerning the Services (changes, renewals, payment reminders, outages) | E-mail, first name | Contract | For the duration of the contract |
| Direct marketing (newsletter, commercial information) | E-mail, first name, telephone | Consent (Article 6(1)(a) GDPR, Article 398 of the Polish Electronic Communications Law) | Until consent is withdrawn |
| Application usage analytics: statistics, measurement of feature effectiveness, interface analysis | Cookie identifiers, addresses of views visited, events, the User's identifier in the Application and basic information about the Subscriber and the Account (e.g. Plan, industry, number of offers, role), session recordings with masked text content (only the screen layout and cursor movement are recorded) | Consent (Article 6(1)(a) GDPR; Article 399 of the Polish Electronic Communications Law) | In accordance with the Cookie Policy |
| Marketing and measurement of advertising effectiveness (Google Ads, Meta pixel) | Advertising identifiers in cookies, events (registration, start of trial period, purchase including amount, currency and plan name) | Consent | In accordance with the Cookie Policy |
| Development of the Application and Subscriber support: analysis of feature usage carried out without the involvement of external tools | Described in section 3.5 | Legitimate interest (Article 6(1)(f) GDPR) and, for part of the data, consent | Section 3.5 |
| Establishment of and defence against claims | Data from the contract and correspondence | Legitimate interest | Until the limitation period for claims expires |
3.2. Business partners and persons contacting the Controller
| Purpose | Data | Legal basis | Retention period |
|---|---|---|---|
| Handling enquiries and correspondence | First name, surname, company, e-mail, telephone, content of the message | Legitimate interest of the Controller (Article 6(1)(f) GDPR) | 3 years from the last contact |
| Conducting business relations and sales, arranging meetings | Contact details, position, history of contacts and meetings, sales notes | Legitimate interest | 3 years from the last contact |
| Sending commercial information | E-mail, telephone | Consent | Until consent is withdrawn |
3.3. Visitors to the sccot.pl website
In connection with the use of the sccot.pl website, the Controller processes data provided in forms and data collected by means of cookies, on the terms set out in the Cookie Policy (section 4).
| Purpose | Data | Legal basis | Retention period |
|---|---|---|---|
| Responding to a message sent via the contact form and conducting further business discussions | First name, surname, company, e-mail, telephone, content of the message | Legitimate interest (Article 6(1)(f) GDPR) | 3 years from the last contact |
| Business contact by electronic means or by telephone, where consent has been given in the form | E-mail, telephone | Consent (Article 6(1)(a) GDPR, Article 398 of the Polish Electronic Communications Law) | Until consent is withdrawn |
| Scheduling a presentation of the Application via the Brevo calendar | First name, surname, e-mail, telephone, company, selected date | Steps taken at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR) | 3 years from the last contact |
| Registration for and participation in online training | First name, surname, company, e-mail, telephone | Contract (Article 6(1)(b) GDPR) | 3 years from the training |
| Sending the profitability calculator result to the indicated e-mail address | E-mail and data entered into the calculator | Action at the request of the data subject (Article 6(1)(b) GDPR) | Data are not stored; they are used solely for a one-time dispatch |
| Protection of forms against automated submissions (reCAPTCHA), server logs | IP address, browser data | Legitimate interest (Article 6(1)(f) GDPR) | 14 days |
| Statistics and measurement of advertising effectiveness | Identifiers in cookies, subpages visited | Consent (Article 6(1)(a) GDPR, Article 399 of the Polish Electronic Communications Law) | In accordance with the Cookie Policy |
3.4. Persons reporting illegal content (DSA)
Where content is reported which the reporting person considers illegal, the Controller processes the data provided in the report: first name and surname or name, e-mail address, the content of the report and the identification of the content to which the report relates.
| Purpose | Legal basis | Retention period |
|---|---|---|
| Receiving and handling the report, notification of the decision and its statement of reasons | Legal obligation (Article 6(1)(c) GDPR) arising from Articles 16–17 of the Digital Services Act (DSA) | The time necessary to handle the report, followed by the period required by law |
| Data provided voluntarily beyond the scope necessary to handle the report | Consent (Article 6(1)(a) GDPR) | Until consent is withdrawn |
| Execution of orders of authorities and notification of suspected criminal offences (Article 18 DSA) | Legal obligation (Article 6(1)(c) GDPR) | The period required by law |
3.5. Analysis of the use of the Application
The Controller analyses the manner in which the Application is used, including the extent of use of individual modules, the types of devices used and account activity. The analysis covers all Users, including employees and associates of the Subscriber. The data used for this purpose are processed exclusively by the Controller and are not transferred to providers of external analytics tools.
Purposes of processing: development and improvement of the Application, adaptation of the interface to the devices used by Users, identification of accounts with low activity in order to offer support to the Subscriber, and preparation of statistical summaries.
Data processed without the User's consent
| Scope of data | Source | Legal basis |
|---|---|---|
| Sessions: date and time of start and end, separately for each device, and the marking of the first session on the Account | Operation of the Application | Legitimate interest of the Controller (Article 6(1)(f) GDPR): development of the Services and Subscriber support |
| Device type (computer, phone, tablet), operating system and its version, browser and its version | Information sent automatically by the browser | As above |
| Activity: number and creation dates of offers, projects, tickets, records and RMS items, and the method of creating an offer (from scratch, from a template, from a copy) | Data stored in the Application | As above |
Data processed solely on the basis of the User's consent
Upon consent being given to the use of cookies in the "analytics" category, the Application additionally reads: the browser window width, the browser language, the time zone, the connection quality, information on the use of the Application installed on the device, and information on whether the device has a touch screen. This information serves to adapt the layout of the Application to the User's device.
The legal basis for processing is the User's consent (Article 6(1)(a) GDPR) in conjunction with Article 399 of the Polish Electronic Communications Law. Consent may be withdrawn at any time on the "Privacy settings" screen in the account menu in the Application. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. Refusal of consent does not limit the ability to use the Application.
Scope excluded from the analysis
For the purposes of analysing the use of the Application, the Controller does not record the User's IP address or location data and does not track the User's activity outside the Application.
Retention period
| Data | Period |
|---|---|
| Sessions | 24 months from the end of the session, followed by automatic deletion |
| First session on the Account | For the lifetime of the Account; after 24 months only the date and device type are retained |
| All sessions after deletion of the Account | Deleted or anonymised |
| Data processed on the basis of consent | After consent is withdrawn, data are no longer collected. Data collected previously are retained until 24 months have elapsed, or deleted earlier at the User's request |
4. Voluntary nature of providing data
Providing the data necessary to create an Account is voluntary but is a condition for using the Application. Providing invoicing data is mandatory in the case of paid Plans, as required by tax law. Giving consent to receive commercial information and to the use of cookies other than strictly necessary cookies is voluntary, and refusal does not limit the ability to use the Application.
5. Data obtained from Google and e-mail correspondence
5.1. Logging in with Google
Where the User logs in with a Google account, the Controller receives the Google account identifier, the e-mail address and the first name and surname of the User, solely for the purpose of creating the Account and logging in. The Controller does not store the profile picture or any other data from the Google account and does not retain access to the Google account after logging in.
5.2. Google Calendar integration
The integration is optional and is activated by the User independently in the Application settings. The Application requires full access to Google Calendar, because the function of taking over events as tickets requires the ability to write to the User's calendar. Access is used solely within the scope of the functions described below.
Data sent to Google: names of tickets, projects and offers assigned to the User, their dates and time zone, and an identifier enabling an event to be linked to a ticket, and in the case of tickets also their description, notes, type, priority and status, the names of the related business partner, offer and project together with a link to the Application, and the first names and surnames of the assigned persons. This content is entered by Users and may contain customer data. Amounts, attachments and participant data are not sent to Google. Once connected, the Application creates a "SCCOT Tickety" calendar in the User's Google account and saves the User's tickets in it. Saving projects and offers in the "SCCOT Projekty" and "SCCOT Oferty" calendars is enabled by the User independently in the profile settings in the Application. Events are saved exclusively in these calendars and in events taken over by the User as a ticket. Changes to a ticket taken over from an event, including its deletion, are carried over to that event in the User's calendar.
Data read from Google: the e-mail address of the Google account and the list of calendars; events from the primary calendar (this function can be disabled in the settings; only their title and times are displayed in the Application); with the consent of co-workers: their busy time slots (without titles); within the "take over as ticket" function: the event indicated by the User; changes made in Google to events created by the Application and to events taken over as a ticket, which are carried over to the Application. For this purpose, the Application receives notifications from Google about changes in the primary calendar and in the calendars created by the Application.
Sensitive data: the content of events in the User's calendar is unrestricted and may contain particularly sensitive information (e.g. concerning a medical appointment). The Controller does not save the content of the User's private events in the database, does not analyse it and does not disclose it to anyone other than the User, including the owner of the Subscriber's account. Event data received from Google are stored temporarily in server memory, for no longer than 2 minutes, in order to speed up the display of the calendar. Only an event taken over by the User as a ticket is saved in the database.
Data stored: encrypted Google Calendar access credentials, the e-mail address of the Google account, calendar identifiers and links between events and tickets.
Disconnecting the integration: upon disconnection of the integration, the Controller deletes the access credentials and links and disables notifications about changes in the calendar. Calendars created by the Application remain in the User's Google account, and the User may delete them independently. The User may also revoke access at any time in the Google account settings. Upon deletion of the Account in the Application, the integration data are deleted.
Access to data: data from the integration are available exclusively to the User. The Controller's staff may view the integration settings only in connection with handling a User's request and with the User's consent, for security purposes (e.g. investigating an error or abuse), or where required by law.
Restrictions: data obtained from Google are used solely for the operation of the functions described. The Controller does not sell such data and does not use them for advertising purposes, creditworthiness assessment, or the development, training or improvement of artificial intelligence or machine learning models. Such data are not transferred to other entities unless this is necessary for the operation of the functions, required by law or necessary for security reasons.
The use and transfer to other applications of information received from Google APIs is carried out in accordance with the Google API Services User Data Policy, including the Limited Use requirements.
5.3. Calendar link (ICS)
The User may generate an address containing a random key at which the titles and dates of the User's tickets, projects, warranties and offers are available, in order to subscribe to them in another calendar program. Any person who knows this address has access to such data without logging in; therefore, the address should not be shared with third parties. The User may generate a new address at any time, which immediately invalidates the previous one.
5.4. E-mail correspondence
Messages sent by the Controller (registration confirmation, password change, notifications, payment reminders, newsletter) are sent via Sendinblue SAS (Brevo), with its registered office in France. The data are processed within the territory of the European Union.
E-mail in the CRM module is sent and received via the mail server indicated by the Subscriber in the mailbox settings; the e-mail provider is chosen by the Subscriber. The content and attachments of such correspondence are stored in the Application by the Controller as a processor, on the terms set out in the Data Processing Agreement.
6. Recipients of data
Personal data may be transferred to entities providing services to the Controller that are necessary for conducting its business and acting on its instructions, as well as to entities authorised under the law. Current list of recipients:
| Recipient | Purpose | Location / transfer |
|---|---|---|
| Hetzner Online GmbH | Application and database servers, backups | Falkenstein, Germany (EEA) |
| Amazon Web Services EMEA SARL | File storage: attachments, photos, CRM correspondence | Frankfurt, Germany (EEA) |
| Sendinblue SAS (Brevo) | Transactional e-mail, newsletter, meeting booking | France (EEA) |
| Marcin Ćwiertnia JC HOST.PL, Modlniczka | Hosting of the sccot.pl website and handling of website forms | Poland |
| Stripe Payments Europe, Ltd. | Payment processing (card, BLIK, Przelewy24, bank transfer) | Ireland; part of the processing in the USA (DPF/SCC) |
| Fakturownia sp. z o.o. | Issuing the Controller's invoices | Poland |
| Intercom R&D Unlimited Company | Support chat | United States (EU–US Data Privacy Framework) |
| Functional Software, Inc. (Sentry) | Error monitoring (technical identifiers, no data from documents) | EU region (Germany); possible access from the USA (DPF) |
| Google Ireland Ltd | Logging in, Google Calendar (at the User's request), form protection (reCAPTCHA), website scripts, fonts | EEA + USA (DPF) |
| Google Ireland Ltd (Analytics and Ads) | Application usage statistics, measurement of advertising effectiveness | EEA + USA (DPF) |
| Meta Platforms Ireland Ltd | Measurement of advertising effectiveness (pixel) | EEA + USA (DPF) |
| Microsoft Corporation (Clarity) | Interface analysis: session recordings and heatmaps | USA (DPF) |
| Accounting firm and law firm serving the Controller | Accounting, legal services | Poland |
6.1. Head of the National Revenue Administration (KSeF)
Where functions for issuing, sending or receiving structured invoices are used, the data contained in invoices are transferred via the National e-Invoicing System (KSeF). The transfer takes place on the instructions of the Subscriber, in connection with the performance of its obligations under tax law. With respect to the processing of data in KSeF, the Head of the National Revenue Administration (KAS) acts as a separate controller under the law; detailed information is provided in the information clauses of the National Revenue Administration.
7. Transfer of data to third countries
Personal data are, as a rule, processed within the European Economic Area. The Application servers and files are located in Germany, and e-mail is sent from France. Where data are processed by a provider outside the EEA (section 6), the transfer takes place on the basis of a European Commission decision finding an adequate level of protection (including the EU–US Data Privacy Framework with respect to certified entities) or standard contractual clauses approved by the European Commission. A copy of the safeguards applied may be obtained by contacting the Controller.
8. Rights of data subjects
The data subject has the right of access to the data and to obtain a copy thereof, the right to rectification, erasure, restriction of processing and data portability, the right to withdraw consent at any time (without affecting the lawfulness of processing carried out before its withdrawal), and the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) (ul. Stawki 2, 00-193 Warszawa). Consent to receive commercial information may be withdrawn in the account settings or electronically, and consent to the use of cookies via the "Cookie settings" link in the website footer or on the "Privacy settings" screen in the account menu in the Application. The right to object is described in section 10.
The User may download a copy of the data from the Application independently in the account settings and, until this function is made available, upon request sent to [email protected], free of charge, within 14 days.
9. Account activity score and automated decision-making
On the basis of the data described in section 3.5, the Controller calculates an account activity score, which determines the degree of use of the Application by the Subscriber, in particular the frequency of logging in and of creating offers, projects and tickets. The score is calculated for the Subscriber as a whole, and not for individual Users, and serves to identify accounts with low activity in order to offer support to the Subscriber.
The calculation of the score constitutes profiling within the meaning of Article 4(4) GDPR. It does not constitute automated decision-making within the meaning of Article 22 GDPR: the score does not produce legal effects or similarly significantly affect the User's situation, does not determine access to, the scope of or the price of the Services, and the decision to contact the Subscriber is taken by a member of the Controller's staff.
The Controller does not take decisions based solely on automated processing which would produce legal effects concerning the data subject or similarly significantly affect the data subject.
10. Right to object
The data subject has the right to object at any time to the processing of their data on the basis of the Controller's legitimate interest, including to the analysis of the use of the Application (section 3.5) and the calculation of the account activity score (section 9), on grounds relating to their particular situation. Upon receipt of an objection, the Controller shall cease processing such data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject.
An objection to the processing of data for direct marketing purposes may be lodged at any time and does not require justification. Upon its receipt, the Controller shall promptly cease processing the data for that purpose.
An objection may be submitted to [email protected] or in writing to the address of the Controller's registered office.
11. Cookies
The rules for the use of cookies and similar technologies are set out in the Cookie Policy available at sccot.pl/regulaminy. Consent to the use of cookies other than strictly necessary cookies may be changed at any time: on the sccot.pl website via the "Cookie settings" link in the footer, and in the Application on the "Privacy settings" screen in the account menu.
12. Changes to the Privacy Policy
The Controller informs of material changes to the Privacy Policy electronically or in the Application. Previous versions are available at sccot.pl/regulaminy.
Google user data (Limited Use disclosure)
SCCOT’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Cookie Policy of SCCOT
1. Cookies and similar technologies
Cookies are small text files stored in the web browser of the User's terminal device. A similar function is performed by browser storage (localStorage, sessionStorage). Cookies and browser storage are used in the SCCOT Application and on the sccot.pl website. The controller of the data collected in this manner is Appi Soft Sp. z o.o. (hereinafter: the "Controller"; contact details are provided in the Privacy Policy) and, in the case of third-party tools, also their providers. Capitalised terms have the meaning given to them in the Terms of Service of SCCOT.
2. Rules of use and consent
1.Cookies necessary for the operation of the Application (login, security, remembering settings selected by the User) are used without consent, on the basis of Article 399(3) of the Polish Electronic Communications Law.
2.Analytics and marketing cookies are used only after consent has been given via the banner. Until consent is given, the tools described in section 3.2 are not launched.
3.Consent may be changed or withdrawn at any time: on the sccot.pl website by means of the "Cookie settings" link in the footer, and in the Application on the "Privacy settings" screen in the account menu. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
4.Refusal of consent does not restrict the possibility of using the Application. Giving consent is not a condition for using the Services.
5.The Controller records the date and scope of the consent given in order to demonstrate that it has been given.
6.The support chat (Intercom) is launched only after the User clicks the chat icon.
3. List of cookies and data stored in the browser
3.1. The Controller's cookies (strictly necessary and functional)
| Name | Purpose | Category | Retention period |
|---|---|---|---|
| sccot_session | Maintaining the logged-in session | Strictly necessary | 120 minutes |
| XSRF-TOKEN | Protection against actions being performed on behalf of the User by other websites | Strictly necessary | Session duration |
| remember_panel_* | Remembering the login | Strictly necessary (at the User's request) | 5 years |
| hideSystemResults | Remembering that suggestions in the RMS catalogue are hidden | Functional | 5 years |
| id_token (localStorage) | Panel login status | Strictly necessary | Until logout |
| lang, config, builderTab, first_steps_collapsed, calendar_mini_collapsed (localStorage) | Language and interface appearance settings | Functional | Until deleted by the browser |
| onboardingReplay (sessionStorage) | Replaying the tutorial | Functional | Until the tab is closed |
| cookielawinfo-checkbox-* (6 items) | Recording the choice made on the consent banner | Strictly necessary | 6 months |
| _GRECAPTCHA (reCAPTCHA) | Protection of login and registration forms against automated submissions | Strictly necessary | 6 months |
3.2. Third-party tools (requiring consent)
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| _ga, _ga_CRJ5C45P0Y | Google Analytics 4 | Application usage statistics together with the User identifier and basic information about the Subscriber | Analytics | 2 years |
| _gcl_* | Google Ads | Measuring advertising effectiveness (registration, start of trial period, purchase) | Marketing | 90 days |
| _fbp | Meta Platforms Ireland | Pixel: page views, registration, purchase together with amount and plan | Marketing | 90 days |
| _clck, _clsk | Microsoft (Clarity) | Session recording and heatmaps (analysis of the interface layout); all text content, including text entered in form fields, is masked | Analytics | _clck: 1 year, _clsk: 1 day |
| sib_cuid | Brevo (Sendinblue SAS) | Recognising the User upon return from the payment page | Functional / marketing | 6 months |
| intercom-* | Intercom | Support chat | Functional | identifier: 9 months, session: 7 days |
3.3. Information read from the terminal device
After consent has been given in the "analytics" category, the Application reads from the User's browser the information about the terminal device indicated in the table below. Such reading does not involve storing cookies or tracking the User's activity outside the Application.
| Scope of information | Purpose |
|---|---|
| Browser window width | Adapting the Application layout to the screen size |
| Browser language | Selecting the interface language |
| Time zone | Correct display of times and dates |
| Connection quality | Adapting the way views are loaded |
| Use of the Application installed on the device | Statistics on the manner of using the Application |
| Presence of a touch screen | Distinguishing the type of device |
The legal basis for processing is the User's consent in connection with Article 399 of the Polish Electronic Communications Law. Detailed information is provided in the Privacy Policy, section 3.5.
4. The sccot.pl website
The sccot.pl website uses the same third-party tools and cookies as the Application (section 3.2), on the same terms.
In addition, the following cookies are used on the sccot.pl website:
| Name | Provider | Purpose | Category | Duration |
|---|---|---|---|---|
| cookielawinfo-checkbox-* (6 items) | SCCOT | Recording the choice made on the consent banner | Strictly necessary | 6 months |
| viewed_cookie_policy | SCCOT | Remembering that the consent banner has already been displayed | Strictly necessary | 6 months |
| _GRECAPTCHA | Protection of contact forms against automated submissions | Strictly necessary | 6 months |
5. Resources loaded from external servers
When the Application and shared offers are displayed, the User's browser may download fonts and icons from the servers of third-party providers (Google Fonts, Font Awesome, jsDelivr, Cloudflare), which involves the transfer of the User's IP address to those providers.
6. Managing cookies in the browser
The User may delete and block cookies in the web browser settings. Blocking strictly necessary cookies makes it impossible to log in to the Application.


