Legal

Privacy Policy

This policy explains what personal data we collect when you use myeasycms.com, why we process it, and the rights you have over it.

Last updated: 30 August 2026

Who we are

The controller of your personal data is:

DynamicDigital sp. z o.o. Al. Jerozolimskie 181B 02-222 Warszawa, Poland KRS: 0000521993 · NIP: 5213678094 · EU VAT: PL5213678094

Email: info@myeasycms.com Telephone: +48 509 937 137

We trade as easyCMS. If you have any question about this policy or about how we handle your data, write to us at the address above and a person will answer you.

We are not required to appoint a Data Protection Officer. Selling software and hardware is not “regular and systematic monitoring of data subjects on a large scale”, and we process no special-category data at scale, so none of the triggers in Article 37 GDPR applies. Polish law adds no further requirement for a private company. Data protection questions go to the address above.

What we collect, and why

We only collect data for specific purposes. This table is the complete picture.

What we collect When Why Legal basis
Name, email address, message You use the contact form To answer your enquiry Article 6(1)(b), steps before a contract; or 6(1)(f) legitimate interest in answering enquiries
Email address, billing address, order contents, amount paid You buy something To take payment, provide the licence or ship the goods, and meet our tax obligations Article 6(1)(b), performance of a contract; and 6(1)(c), legal obligation for invoicing
Payment card or account details You pay To take payment Handled entirely by Stripe, we never see or store your card details
Email address and an account username You buy software To create your CMS account and send you your credentials Article 6(1)(b), performance of a contract
The question you type, and any photo you attach, in the “Ask easyCMS” assistant You use the assistant To generate an answer Article 6(1)(f), legitimate interest in providing self-service support. See the AI section below.
Website usage statistics (pages viewed, approximate location, device type) Only if you accept analytics cookies To understand which pages are useful and improve the site Article 6(1)(a), your consent

Your shopping basket is stored in your own browser using local storage. It is not sent to us until you begin checkout.

We do not buy personal data from third parties and we do not sell your data to anyone.

Automated fraud screening. Stripe screens payments automatically for fraud, and a payment can be declined by that automated check. If a payment of yours is refused and you believe it was wrong, contact us, a person will look at it, you can explain your situation, and you can contest the outcome. Apart from this, we do not make decisions about you by purely automated means.

The “Ask easyCMS” AI assistant

Our knowledge base offers an optional AI assistant. You should understand what happens when you use it:

  • The question you type, and any photo of your screen that you choose to attach, is sent to Google for processing by a Google Gemini model, through Firebase AI Logic.
  • Google processes this to generate the answer and returns it to your browser.
  • Using the assistant is entirely optional. If you would rather not send anything to Google, use the support guides directly or contact us instead.
  • Please do not type passwords, payment details, or other people’s personal data into the assistant. Photos of a screen can contain more than you intend, check before attaching one.
  • We do not store your conversation. It exists only in your browser tab and is gone when you close or reload the page. We keep no server-side record of what you asked.
  • The one exception is if you choose to escalate. If you click through to the support form from the assistant, the conversation is attached to that support request and emailed to us, so we can see what you already tried. That copy then lives in our support mailbox and is kept as described under How long we keep it below.

Google acts as our processor for this feature. Details of Google’s handling are in the Firebase Data Processing Terms.

Where this is processed. Google’s documentation for Firebase AI Logic states that requests are handled by an available model anywhere in Google’s global pool, and that a processing location cannot be specified. We therefore cannot guarantee that what you send to the assistant stays inside the European Economic Area. This is the main reason we ask you not to put personal or confidential information into it.

Is your question used to train Google’s models? No. Because we are established in the European Economic Area, Google applies its paid-service terms to our use, and those terms state that inputs are not used to improve Google’s models.

Google’s two roles. Google acts as our processor for the question and answer themselves. For technical service data generated in the process, including your IP address, usage counts and safety-filter events, Google acts as an independent controller under its own terms.

[CONFIRM: the Google entity you actually contract with for this service, as named in your Google Cloud / Firebase agreement, and its US sub-processor. Check the agreement attached to billing account 0181F3-088B39-A044F3 rather than assuming.]

Who we share data with

We use a small number of carefully chosen service providers. Each one processes data only on our instructions, under a data processing agreement.

Provider What they do What they receive
Stripe (privacy) Takes payments Your name, email, billing address and payment details
Resend (privacy) Sends our transactional emails Your email address and the content of the message
Google Firebase (privacy) Hosts this website and runs our API Technical data such as your IP address in server logs
Google Analytics Website statistics, only after you consent Usage data with your IP address anonymised
Google (Firebase AI Logic) Powers the optional AI assistant The question and any photo you submit

We also disclose data where the law requires it, for example to tax authorities, or in response to a lawful order.

Where you order hardware, we pass your name, delivery address and contact details to international courier and postal operators so the order can be delivered, and to customs authorities where an international shipment requires it.

We do not use a CRM, and we do not share customer data with any Xibo Signage service: easyCMS is built on Xibo’s open-source software, which we host ourselves.

Where your data is processed

  • Our API (checkout, contact form, support requests, order emails) runs on Google Cloud Functions in the europe-west1 (Belgium) region. This is where your form submissions and order data are processed.
  • This website is served by Firebase Hosting from Google’s global content delivery network, so the pages themselves are cached on servers worldwide. That cache holds only public page content, never personal data, though the serving edge node records standard request logs including your IP address.
  • The easyCMS platform at app.myeasycms.com, where your account and media live, is hosted by us on Hetzner infrastructure inside the European Union.
  • The AI assistant is the one feature that leaves the EEA by design, as explained above. Everything else in the list is processed in the EU, apart from the provider transfers described next.

Some of our providers are based in the United States or may process data there. Where data goes outside the European Economic Area we rely on the European Commission’s Standard Contractual Clauses, and where the provider also holds it, certification under the EU–US Data Privacy Framework. You may request a copy of the safeguards we rely on by emailing us.

How long we keep it

Data Retention
Invoices and accounting records 5 years from the end of the tax year, as required by Polish tax law
Customer account and licence records For as long as your account is active, then 6 years after closure, to cover Polish tax and limitation periods
Contact form enquiries 24 months, then deleted
Support requests, including any assistant conversation you chose to attach 24 months, then deleted
Analytics data 14 months (the retention period set on our Google Analytics property)
Server logs 30 days (Google Cloud Logging default retention)

When data is no longer needed for the purpose it was collected for, we delete it or irreversibly anonymise it.

Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy
  • Rectify data that is inaccurate or incomplete
  • Erase your data (“right to be forgotten”), where we have no overriding reason to keep it
  • Restrict how we process your data while a concern is investigated
  • Data portability: receive data you gave us in a structured, machine-readable format, and have it sent to another controller
  • Object to processing based on our legitimate interests
  • Withdraw consent at any time, where we rely on consent, this does not affect processing carried out before you withdrew it

To exercise any of these, email info@myeasycms.com. We will respond within one month. We do not charge for this, and we may ask you to confirm your identity first so we do not disclose your data to someone else.

You can change your cookie choice at any time, see the Cookie Policy.

Your right to object

This right is set out separately because the law requires it to be.

You have the right to object at any time, on grounds relating to your particular situation, to our processing of your data where we rely on legitimate interests. If you object, we must stop unless we can show compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims.

Where we process your data for direct marketing, you may object at any time and we must stop immediately. No reason is needed and no balancing applies.

To object, email info@myeasycms.com.

Complaints

If you believe we have handled your data unlawfully, please tell us first so we can put it right. You also have the right to complain to the Polish supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (UODO) ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland Telephone: 22 531 03 00 · Email: kancelaria@uodo.gov.pl uodo.gov.pl

If you live in another EU country, you may complain to your own national data protection authority instead.

Is providing data required?

Where you buy from us, providing your name, email and billing address is a contractual requirement, we cannot deliver a licence, issue a valid invoice or ship hardware without it. Everything else, including analytics and the AI assistant, is entirely optional.

Security

We take reasonable technical and organisational measures to protect your data, including encryption in transit (HTTPS across the whole site), restricted access to customer records, and payment handling delegated to Stripe so that card details never reach our systems.

In practice this means:

  • Two-factor authentication is required on the administrator accounts that can reach customer data.
  • Access is limited to the people who need it to run the service, and payment card details never reach our systems at all: Stripe handles them directly.
  • Encryption in transit on every connection to this site, our API and the easyCMS platform.
  • Regular backups of the easyCMS platform, held within the European Union and restricted to the same administrators.

Changes to this policy

If we change this policy we will update the date at the top. Where a change materially affects your rights, we will tell you directly.