- Vesta Usługi i Szkolenia Marcin Makowskiul. Wrzosowa 33, 84-300 Lębork, PolandNIP (Polish tax ID): 841-161-18-09e-mail: kontakt@varilo.euWebsite: varilo.pl
1. Data Controller
The controller of personal data processed in connection with operating the Varilo Service, managing accounts, entering into and performing agreements and communicating with users is Vesta Usługi i Szkolenia Marcin Makowski, ul. Wrzosowa 33, 84-300 Lębork, Poland, NIP 841-161-18-09.
Privacy and data protection contact: kontakt@varilo.eu.
Varilo is a Software as a Service (SaaS) platform for creating and completing checklists, checks, inspections and rounds, making them available, among other methods, through QR codes or NFC tags, recording non-conformities and creating reports and statistics.
2. The two data protection roles of Varilo
2.1. Varilo as controller
Varilo acts as a controller where it independently determines the purposes and means of processing, in particular in relation to persons creating an account, account administrators, representatives of Customers, persons contacting Varilo, billing data and technical data required to ensure the security and proper operation of the Service.
2.2. Varilo as processor
Where a Customer enters personal data of other persons into Varilo in checklists, inspections, reports, comments, photographs or attachments, the Customer is, as a rule, the controller of those data and Varilo processes them on the Customer’s behalf as a processor.
This also applies where a person completes a Checklist after scanning a QR code or NFC tag or opening a shared link without creating their own Varilo account. The Customer is responsible for establishing a lawful basis for collecting such data and for providing the required privacy information to those persons.
Detailed rules governing such processing are set out in the Varilo Data Processing Agreement (DPA).
3. Data we process as controller
- account and user data: name and surname, e-mail address, organisation, role, information about permissions and the account;
- Customer and billing data: company name, NIP/tax identification number, address, contact person details, selected Plan, invoice and payment information;
- contact data and correspondence provided when contacting Varilo;
- technical data: IP address, date and time of connection, browser and device information, session data, login logs and security-related events;
- other data voluntarily provided to Varilo in connection with account servicing, a technical support request or entering into an agreement.
Varilo does not currently process card payments or online payments. Payment for the Service is made by bank transfer to the bank account specified on the invoice issued by the Service Provider.
4. Purposes and legal bases for processing
| Purpose | Legal basis |
|---|---|
| Creating an account and providing the Service | Article 6(1)(b) GDPR - entering into and performance of a contract |
| Order, billing and payment handling | Article 6(1)(b) GDPR and Article 6(1)(c) GDPR - tax and accounting obligations |
| Contact and handling enquiries | Article 6(1)(b) GDPR where contact concerns a contract, or Article 6(1)(f) GDPR - legitimate interest in correspondence and business relationship management |
| Technical support and handling reports | Article 6(1)(b) GDPR and Article 6(1)(f) GDPR |
| Service security, abuse prevention and error diagnostics | Article 6(1)(f) GDPR - the Controller’s legitimate interest |
| Establishment, exercise or defence of legal claims | Article 6(1)(f) GDPR |
| Electronic marketing, if carried out | Consent required under applicable law, including Article 398 of the Polish Electronic Communications Law; under the GDPR the relevant basis is consent or legitimate interest depending on the circumstances |
5. Data processed on behalf of the Customer
The Customer determines the scope of data contained in Checklists and Inspections. Such data may include, in particular, name and surname, job title or department, identifiers of equipment, machinery, vehicles or locations, form responses, date and time of an Inspection, comments, photographs, attachments, information about non-conformities and other data entered by the Customer or by the person carrying out an Inspection.
The Customer should apply the data minimisation principle and should not collect through Varilo data that are not necessary for the purpose of a particular Inspection.
Special categories of personal data referred to in Article 9 GDPR should be processed in Varilo only where this is genuinely necessary and the Customer has an appropriate legal basis and safeguards.
6. Hosting and recipients of data
The primary provider of hosting infrastructure used to operate Varilo and store data is Name.com. To the extent that Name.com processes data stored in the hosting environment on behalf of Varilo, it acts as a sub-processor.
Data may also be disclosed to other entities only to the extent necessary to provide the Service or comply with legal obligations, including providers of technical support, accounting or legal services where Varilo uses such services, and competent public authorities where disclosure is required by law.
Varilo does not sell personal data of Customers or Users.
7. Transfers outside the European Economic Area
Name.com is a provider established in the United States. Under Name.com’s publicly available terms applicable to hosting services, data related to the provision of those services may be transferred outside the European Economic Area (EEA) and processed in the United States.
Where the provision of Varilo involves a transfer of personal data outside the EEA, the transfer is carried out using a mechanism permitted under Chapter V GDPR that is appropriate to the recipient and circumstances of the transfer, in particular an adequacy decision of the European Commission or appropriate contractual safeguards such as Standard Contractual Clauses.
Information about the safeguards used may be requested at kontakt@varilo.eu.
8. Data retention
- account and contract data - for the duration of the agreement and, after its termination, for the period necessary for settlements and protection against claims;
- billing and tax documentation - for the period required by applicable law;
- correspondence and support requests - for the time necessary to handle the matter and subsequently for a period justified by possible establishment, exercise or defence of claims;
- technical data and logs - for the period necessary for security, diagnostics and accountability, in accordance with the applicable retention policy;
- data processed on behalf of the Customer - for the duration of the Service and thereafter in accordance with the Customer’s instructions and the DPA, taking into account the backup deletion cycle.
9. Rights of data subjects
In the cases provided for by the GDPR, a data subject has the right of access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent where processing is based on consent.
Requests may be sent to kontakt@varilo.eu. If a request concerns data entered into Varilo by a Customer acting as controller, Varilo may forward the request to the relevant Customer or inform the person that they should contact that Customer.
A person who believes that their data are processed unlawfully has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych - UODO) in Poland or, where applicable, another competent supervisory authority.
10. Mandatory or voluntary provision of data
Providing data required to create an account, enter into an agreement or issue an invoice is voluntary, but failure to provide such data may make it impossible to enter into or perform the agreement. The Customer acting as controller determines the scope of data collected in Checklists.
11. Automated decision-making
Varilo does not make decisions concerning individuals that produce legal effects or similarly significantly affect them solely on the basis of automated processing within the meaning of Article 22 GDPR.
12. Data security
Varilo applies technical and organisational measures appropriate to the nature of the Service and the risks involved, including access-control mechanisms, protection of data transmission, protection of administrative accounts, software updates and solutions aimed at maintaining availability and restoring data. The scope of these measures is periodically adjusted as the Service and infrastructure develop.
13. Cookies and similar technologies
The Service may use cookies, browser local storage and other similar technologies. Necessary technologies may be used to ensure operation of the Service, security, session handling, authentication and storage of user settings.
Cookies or similar technologies that are not necessary for providing the Service, in particular analytical or marketing technologies, may be used only after obtaining the consent required under applicable law, including Article 399 of the Polish Electronic Communications Law. The user should be able to refuse such technologies and later change their decision.
A detailed list of technologies currently in use may be displayed in the consent management panel or cookie banner in the Service. Users can also manage cookies through their browser settings.
14. Marketing communications
Varilo may send commercial information or direct marketing by e-mail or other means of electronic communication only after the requirements of applicable law have been met, in particular after obtaining prior consent where required. Consent may be withdrawn at any time.
15. Changes to this Policy
This Policy may be updated due to changes in law, operation of the Service, infrastructure, providers or scope of processing. The current version is published in the Service together with its version date.
16. Contact
For matters relating to privacy and data protection, please contact: kontakt@varilo.eu.
Postal address: Vesta Usługi i Szkolenia Marcin Makowski, ul. Wrzosowa 33, 84-300 Lębork, Poland.
Language note: this English version is a translation of the Polish document. In the event of an interpretative discrepancy, the Polish version prevails to the extent permitted by applicable law.

