Who controls your personal data?
The controller of your personal data is Apresly spółka z ograniczoną odpowiedzialnością, with its registered office in Mielec at Żeromskiego 19/308, 39-300 Mielec, Poland, entered in the National Court Register kept by the District Court in Rzeszów, 12th Commercial Division of the National Court Register.
- KRS: 0001151612
- NIP: 8172219243
- REGON: 54073069000000
- Share capital: PLN 5,000
For privacy-related questions or requests, email us at contact@apresly.com.
What data do we process?
Depending on how you use Tropado, we may process:
- Signup and contact data: your email address, phone number and information you include in a message to us.
- Consent data: the wording and time of a consent or subscription, and information about its withdrawal.
- Account and transaction data: details needed to provide the service, manage your subscription, issue invoices and handle payments or complaints.
- Technical data: IP address, browser and device information, request date and time, referring page and server logs.
- Monitored content: content and metadata from Facebook groups selected for monitoring, as described in section 9.
We do not ask you to connect your private Facebook account or provide your Facebook password.
Why and for how long do we process data?
| Purpose | Legal basis | Retention |
|---|---|---|
| Handling an access reservation, contacting you by email or phone and taking steps before entering into a contract | Article 6(1)(b) GDPR | Until the request is resolved, then for the period needed to establish, pursue or defend claims |
| Sending Tropado updates and commercial information | Your consent, Article 6(1)(a) GDPR | Until you withdraw consent or unsubscribe |
| Providing and supporting the Tropado service | Performance of a contract, Article 6(1)(b) GDPR | For the duration of the contract and the applicable claims period |
| Accounting, tax and legal obligations | Article 6(1)(c) GDPR | For the period required by applicable law |
| Website security, abuse prevention and service administration | Our legitimate interest, Article 6(1)(f) GDPR | Only for as long as necessary for security and administration |
| Finding and delivering matching opportunities from selected groups | Performance of a contract or our legitimate interest, Article 6(1)(b) or (f) GDPR. Where we act for a customer, we may process data on that customer's behalf | For as long as necessary to provide the service and according to the applicable service settings or agreement |
Where processing is based on our legitimate interest, that interest consists of operating and securing Tropado, communicating with users, improving the service and protecting or pursuing legal claims.
Where does the data come from?
Most personal data comes directly from you, for example when you submit the signup form, contact us or become a customer. Technical data is generated when your device communicates with our website. Monitored content comes from Facebook groups selected for the Tropado service and is processed only where access to that content is lawful.
Providing data is voluntary, but an email address and phone number are necessary for us to handle your access reservation and contact you about the setup. Data required for a contract, payment or invoice must be provided if you decide to use the paid service.
Who may receive your data?
We disclose data only when it is necessary to operate Tropado or required by law. Recipients may include:
- UAB MailerLite, J. Basanavičiaus 15, LT-03108 Vilnius, Lithuania, for signup forms and email delivery.
- Hosting, cloud infrastructure, security and IT support providers.
- Email, customer support, payment, accounting and legal service providers, where their services are used for your account or request.
- Google Ireland Limited and Google LLC, because the website currently loads fonts from Google Fonts.
- Public authorities, if disclosure is required by law.
Service providers process data under agreements and only to the extent needed to perform their tasks. You may contact us for more information about the providers currently involved in processing your data.
International data transfers
Some service providers may process data outside the European Economic Area. In such cases, we use safeguards required by data protection law, such as an adequacy decision or the European Commission's standard contractual clauses, together with supplementary measures where appropriate.
What rights do you have?
Subject to the conditions set out in the GDPR, you may request:
- access to your personal data and a copy of it,
- correction of inaccurate data,
- deletion of data,
- restriction of processing,
- data portability,
- an objection to processing based on legitimate interests,
- withdrawal of consent at any time, without affecting processing carried out before withdrawal.
You also have the right to lodge a complaint with the competent supervisory authority. In Poland this is the President of the Personal Data Protection Office. To exercise your rights, write to contact@apresly.com. We may ask for information needed to confirm your identity.
Facebook group content
Tropado is designed to detect relevant customer requests in Facebook groups selected for monitoring. Content processed for this purpose may include a post's text, display name, publication time, group name, link and other metadata available with the post.
We process only content to which access is lawful and only to the extent needed to identify and deliver a matching signal. A Tropado customer is responsible for using received information lawfully, respecting group rules and the rights of the people whose posts they view.
Tropado does not require customers to connect their private Facebook accounts. We do not ask for or store their Facebook passwords.
AI matching and automated analysis
Tropado uses automated analysis to assess whether a post matches criteria defined for a customer. This helps reduce irrelevant alerts. The analysis does not make decisions that produce legal effects or similarly significant effects for the author of a post or for a Tropado customer.
How do we protect data?
We apply technical and organisational measures appropriate to the nature of the data and the risks involved. These include limiting access, using trusted providers, protecting data in transit where supported and reviewing how data is collected and retained. No internet service can guarantee absolute security, but we work to prevent unauthorised access, loss, alteration or disclosure.
Changes to this policy and contact
We may update this policy when the service, our providers or applicable law changes. The current version and its effective date will always be published on this page. If a change materially affects how we use data, we will provide an additional notice where appropriate.
Questions about privacy?
contact@apresly.com