Legal
Privacy policy
Drafted to the EU standard with an Australian annex, because that is the strictest of the three regimes we operate under - European Economic Area, United Kingdom, Australia.
Tanthrall Services Sp. z o.o. - Version 1.0 - Effective 11 August 2026 - Last updated 11 August 2026
Scope of this document. This Privacy Policy covers the Tanthrall website, user accounts, project specifications, quotes, bank-transfer orders, project delivery, defect handling and related communications.
At a glance:
- Tanthrall is established in Poland and generally acts as the data controller for the processing described in this Policy.
- We use operational cookies and local storage only. We do not use advertising pixels, behavioural analytics or cross-site tracking.
- We send transactional and service-related messages only. We do not currently operate a newsletter or promotional mailing programme.
- Payments are made by bank transfer. We do not process or store payment-card credentials.
1. Who we are
This Privacy Policy explains how Tanthrall Services Sp. z o.o. ("Tanthrall", "we", "us" or "our") collects, uses, stores, shares and protects personal data in connection with the Tanthrall website and services.
Our company details are:
- Legal entity: Tanthrall Services Sp. z o.o.
- KRS: 0001179170
- NIP: 7792590008
- REGON: 542026528
- Registered address: ul. Głogowska 82/22, 60-741 Poznań, Poland
- Website: tanthrall.com
- Email and privacy contact: studio@tanthrall.com
For the processing described in this Policy, Tanthrall Services Sp. z o.o. is generally the data controller, meaning that we determine why and how personal data is processed.
We have not appointed a Data Protection Officer. Privacy enquiries and requests may be sent directly to studio@tanthrall.com.
This Policy is written primarily for processing governed by the General Data Protection Regulation, Regulation (EU) 2016/679 ("GDPR"), and applicable Polish law. Any mandatory rights you may have under another applicable law remain unaffected.
2. What this Policy covers
This Policy applies when you:
- visit or use the Tanthrall website;
- create, access or close an account;
- place services in your basket;
- complete a project specification;
- request or receive a quote;
- approve a quote or Statement of Work;
- place or manage an order;
- make a payment by bank transfer;
- view a private project preview;
- submit content, instructions or revision requests;
- download deliverables or a connection guide;
- receive access to a guide or learning module through your account;
- report a defect or request support;
- communicate with us by email; or
- exercise a privacy or other legal right.
This Policy does not apply to third-party websites or services that we merely link to.
After handover. This Policy does not govern the website or application we build for you after it has been handed over. We do not host, connect or operate the delivered website. Once you or a service provider chosen by you deploys it, you are responsible for determining what that live website collects and for providing its own privacy and cookie notices.
3. Personal data contained in client project content
You may send us text, photographs, testimonials, team biographies, product information or other project content that contains personal data about other people.
Where we process that personal data solely to build your website according to your instructions:
- you or your organisation will generally act as the data controller;
- Tanthrall will generally act as your data processor;
- the processing should be governed by a separate data processing agreement meeting Article 28 GDPR; and
- you are responsible for ensuring that you have a lawful basis for providing and publishing that personal data.
Please do not send us health data, biometric data, political opinions, religious beliefs, trade-union information, information about sexual life or orientation, criminal-conviction data, or other special-category or highly sensitive personal data unless we have expressly agreed in writing that such processing is necessary and appropriate.
We may refuse or securely delete client content that contains unnecessary or unexpected sensitive personal data.
4. Personal data we collect
The precise information we collect depends on how you use the service.
4.1 Account and authentication data
When you create or use an account, we may process:
- your name;
- email address;
- password hash;
- email-verification status;
- verification and password-reset tokens;
- account creation, update and closure dates;
- server-side session identifiers;
- login timestamps and outcomes; and
- security events connected to your account.
We do not store your password in readable form. Passwords are processed using bcrypt hashing.
4.2 Basket, specification and quote data
When you prepare or request a project, we may process:
- the package, design and add-ons you selected;
- the contents of your basket;
- whether you are buying as an individual or for a business;
- your business name, registration or tax details where applicable;
- your business description;
- the purpose and intended audience of the website;
- proposed website content;
- page requirements and requested functionality;
- visual and technical preferences;
- files, text and images you provide;
- your specification answers;
- the price snapshot applicable when the quote was prepared;
- the quote and its validity period; and
- the applicable Statement of Work.
Free-text fields may contain personal data if you choose to include it. Please provide only information that is relevant to the project.
4.3 Contract, declaration and audit data
We may keep records showing:
- the quote and Terms version you approved;
- the exact wording of consumer withdrawal or early-performance acknowledgements shown to you;
- whether and when each acknowledgement was selected;
- the acknowledgement version, including the applicable version identifier;
- the date and time of approval;
- order status changes;
- significant administrative actions;
- the user or authorised team member responsible for an action; and
- other audit information needed to demonstrate how the contract was formed and performed.
4.4 Project and delivery data
During a project, we may process:
- client content and project files;
- design and implementation decisions;
- revision requests and responses;
- private preview links and access records;
- project status information;
- approval and sign-off records;
- delivery dates;
- download events;
- defect reports;
- technical diagnostic information; and
- correspondence relating to the project.
Private preview access information may be used to secure the preview, investigate unauthorised access and show whether a preview or deliverable was accessed.
4.5 Payment and accounting data
We accept payment by bank transfer only. We may receive and retain:
- payer name;
- bank-transfer date and amount;
- currency;
- transfer reference;
- account name;
- bank account identifiers included by the banks in the transfer record;
- billing address;
- VAT or other tax identifier;
- invoice details;
- refund details; and
- reconciliation and accounting records.
We do not process or store credit-card numbers, card expiry dates, security codes or other payment-card credentials.
4.6 Communications data
When you contact us or when we communicate about your account or order, we may process:
- your name and email address;
- the content of your message;
- attachments;
- the date and time of correspondence;
- the account or order connected to the message; and
- technical delivery, bounce or failure information generated by our email provider.
We send transactional and service-related messages only. These may include email verification, password reset, quotes, payment instructions, order confirmations, project updates, preview notices, delivery messages, defect correspondence and legally required notices.
4.7 Technical and security data
When you use the website, our systems and hosting providers may automatically process:
- IP address;
- user-agent and browser information;
- requested page or technical endpoint;
- date and time of the request;
- session identifier;
- response and error information;
- login and security events; and
- information required to prevent fraud, abuse, attacks or unauthorised access.
We do not use this information for advertising, cross-site tracking or behavioural profiling.
4.8 Guide or learning access
Where access to a written guide, course or learning module is provided through an account, we may process:
- the material to which access was granted;
- the date access was granted;
- access and completion status; and
- related technical and support records.
5. Where the data comes from
We obtain personal data:
- directly from you;
- from a person acting on behalf of your business;
- from another authorised user within your organisation;
- from your bank and our bank when a transfer is made;
- automatically from your device and our technical systems;
- from the service providers that operate our infrastructure; and
- from records generated while we prepare and perform your order.
We do not purchase marketing lists or collect personal contact details from public sources for unsolicited marketing.
6. Why we process personal data
We process personal data only where we have a lawful basis. For each purpose, the GDPR lawful basis is stated alongside it.
- Operating the public website and providing requested website functions. Our legitimate interests under Article 6(1)(f) in operating a stable, functional and secure service.
- Creating and authenticating an account. Article 6(1)(b), taking steps at your request and performing our contract; and Article 6(1)(f) for account security.
- Remembering a basket and receiving a project specification. Article 6(1)(b), taking steps at your request before entering into a contract.
- Preparing, sending and managing a quote or Statement of Work. Article 6(1)(b).
- Recording approvals, declarations and consumer acknowledgements. Article 6(1)(b), Article 6(1)(c) where records are required by law, and Article 6(1)(f) for evidence and dispute prevention.
- Building, previewing, revising and delivering the ordered website or application. Article 6(1)(b).
- Providing a guide or account-based learning material. Article 6(1)(b), or Article 6(1)(f) where access is provided outside a paid contract at your request.
- Processing and reconciling bank transfers. Article 6(1)(b).
- Issuing invoices and maintaining accounting and tax records. Article 6(1)(c), compliance with Polish legal obligations.
- Sending account, security, order and delivery communications. Article 6(1)(b), Article 6(1)(c), or Article 6(1)(f), depending on the message.
- Responding to enquiries from prospective customers or other persons. Article 6(1)(f), our legitimate interest in responding to people who contact us.
- Preventing fraud, abuse, unauthorised access and technical attacks. Article 6(1)(f), our legitimate interest in protecting our systems and users; and Article 6(1)(c) where security measures are legally required.
- Handling defects, complaints, refunds or disputes. Article 6(1)(b) and Article 6(1)(f).
- Establishing, exercising or defending legal claims. Article 6(1)(f).
- Responding to courts, regulators or public authorities. Article 6(1)(c), or Article 6(1)(f) where disclosure is legally permitted and necessary.
- Managing a corporate reorganisation, acquisition or sale. Article 6(1)(f), subject to appropriate confidentiality and data-protection safeguards.
Where we rely on legitimate interests, our relevant interests include operating and securing the service, responding to enquiries, maintaining evidence of transactions, preventing abuse and protecting legal rights. You may object to processing based on legitimate interests as explained in section 14.
7. Information you must provide
Fields marked as required are necessary for the relevant function.
Without the required account information, we cannot create or secure an account. Without the required specification information, we may be unable to prepare an accurate quote or Statement of Work. Without required billing information and confirmation of payment, we may be unable to issue an invoice or perform the contract.
Optional fields may be left blank unless we explain otherwise.
8. Marketing and profiling
We do not currently:
- send newsletters or promotional email campaigns;
- use customer data for direct marketing;
- sell or rent personal data;
- create advertising audiences;
- run behavioural advertising;
- use advertising pixels;
- use cross-site trackers;
- score sales leads;
- profile users for marketing; or
- make automated credit or eligibility decisions.
Transactional and service-related messages are not marketing messages. They are sent because they are necessary to secure an account, respond to a request, perform an order or comply with law.
If we introduce marketing or non-essential analytics in the future, we will update this Policy and obtain any consent required by law before beginning that processing.
9. Cookies and local storage
We use only the following operational cookies or local-storage items:
meridian_session- Holds a random session token used to keep you signed in and secure access to your account. Up to 14 days.meridian_basket- Remembers the contents of an unfinished basket or enquiry. Up to 30 days.meridian_cookie_choice- Remembers your interaction with the cookie notice so that it is not repeatedly displayed. Until you clear the website's local storage in your browser.
These technologies are not used for advertising, analytics, user profiling or tracking across websites.
They are used only where necessary to provide a function requested by the user or to retain a related interface preference. Where a cookie or similar technology is strictly necessary to provide the requested electronic service, we do not rely on consent for its use.
You may clear cookies and local storage through your browser settings. Doing so may sign you out, remove the contents of your basket or cause the cookie notice to be shown again.
More information is provided in our separate Cookies Policy.
10. Who receives personal data
We disclose personal data only where necessary for the purposes described in this Policy.
Our main service providers include:
10.1 Vercel
We use Vercel for website and application hosting, delivery infrastructure, deployment and related technical services. Vercel operates global infrastructure. Depending on the service and configuration, personal data and technical logs may be processed in the United States or other countries as well as within Europe.
10.2 Supabase
We use Supabase for our PostgreSQL database and related infrastructure. Our primary database region is configured in Stockholm, Sweden. However, Supabase personnel, affiliates and subprocessors may operate from other countries where necessary to provide support, security and infrastructure services.
10.3 Resend
We use Resend to send transactional emails such as verification, password-reset, quote, order and delivery messages. Our email infrastructure is configured to use an Irish or European region where the service supports that configuration. Resend and its subprocessors may nevertheless process limited message, account or technical data outside the EEA.
10.4 Namecheap Private Email
We use Namecheap Private Email to receive and manage messages sent to our business mailbox. Namecheap and its service providers may process mailbox and technical information outside the EEA.
10.5 Banks, accountants and professional advisers
We may disclose relevant data to:
- our bank;
- accounting, bookkeeping and tax providers;
- auditors;
- legal advisers;
- information-security advisers; and
- other professional advisers subject to confidentiality obligations.
10.6 Personnel and contractors
Authorised employees or contractors may access personal data only where required to perform their role. Access is limited according to the nature of the task and is subject to contractual or professional confidentiality obligations.
10.7 Authorities and legal recipients
We may disclose data to a court, regulator, tax authority, law-enforcement body or other public authority where legally required or where disclosure is necessary to establish, exercise or defend legal rights.
We do not disclose personal data to third parties for their independent advertising or marketing purposes.
11. International data transfers
Some of our providers, their corporate entities or their subprocessors are located outside the European Economic Area or may permit support or technical access from outside the EEA.
Where personal data is transferred outside the EEA, we use an applicable transfer mechanism, which may include:
- a European Commission adequacy decision;
- the EU-US Data Privacy Framework, where the recipient is validly certified and the framework is available for the relevant transfer;
- European Commission Standard Contractual Clauses;
- contractual and technical supplementary safeguards; or
- another transfer mechanism permitted by Chapter V GDPR.
The use of a European primary storage region does not necessarily mean that all support, security, routing, backup or administrative processing remains exclusively within the EEA.
You may contact us for further information about the safeguard used for a particular transfer. Where legally permitted, we may provide a copy or summary with commercially confidential or security-sensitive information removed.
12. How long we keep personal data
We do not keep personal data indefinitely merely because storage is technically possible. Our intended retention schedule is:
- Session identifier. Up to 14 days.
- Unfinished basket. Up to 30 days.
- Cookie-notice preference. Until cleared through the browser.
- Email-verification and password-reset tokens. Until used, replaced or expired under the applicable security setting.
- Unverified account. Normally deleted or anonymised within 30 days if verification is not completed.
- Active account information. While the account is active.
- Inactive account without an order. Up to 24 months after the last meaningful account activity, unless the account is closed earlier.
- Closed account. Deleted or anonymised after closure, except for information linked to an order, legal obligation, security event or continuing claim.
- Abandoned specification or unaccepted quote. Up to 12 months after the quote expires or the last relevant activity.
- Project source content, private preview and downloadable deliverables. Normally up to 60 days after sign-off or delivery, unless longer retention is needed to complete defect handling, resolve a dispute or comply with law.
- Quote, Statement of Work, contract, approvals, acknowledgements, order history and core audit trail. Up to six years following the end of the calendar year in which the contract was completed or terminated, depending on the applicable legal limitation period.
- Payment, invoice, tax and accounting records. For the period required under applicable Polish accounting and tax law, generally at least five years and longer where an audit, proceeding or other legal obligation requires it.
- Project correspondence and defect records linked to an order. Retained with the relevant contract record where necessary.
- General correspondence not resulting in an order. Up to three years after the last substantive communication.
- Security and server logs. Normally up to 12 months, unless a longer period is necessary to investigate an incident.
- Privacy-rights requests and complaints. Up to three years after the request or complaint is closed.
- Records subject to a dispute, investigation or legal hold. Until the matter is finally resolved and the relevant limitation or retention period has expired.
When a retention period expires, personal data is deleted, anonymised or isolated from ordinary use unless continued storage is legally required.
Deleted data may remain for a limited period in encrypted or access-restricted backups until those backups are overwritten through the provider's normal backup cycle. Backup data is not restored for ordinary business use and is used only where necessary for security, continuity or disaster recovery.
Anonymous information that can no longer be linked to an identifiable person may be retained for statistical, security or operational purposes.
13. Security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
Depending on the system and risk, these measures include:
- encrypted HTTPS/TLS connections;
- passwords stored as bcrypt hashes rather than in plaintext;
- random verification, password-reset and session tokens;
- server-side sessions;
- httpOnly and secure session-cookie settings;
- role-based and need-to-know access restrictions;
- audit and security logging;
- access revocation procedures;
- provider data-processing terms;
- backups and recovery procedures; and
- incident investigation and response procedures.
Do not send account credentials. We do not need access to your domain, hosting, banking or other third-party accounts to deliver our standard service. Please do not send us passwords, private keys or access tokens for such accounts.
No internet-based system can be guaranteed to be completely secure. Where a personal data breach occurs, we will investigate it and make notifications to the competent supervisory authority and affected individuals where required by law.
14. Your GDPR rights
Subject to the conditions and exceptions in applicable law, you may have the following rights.
14.1 Access
You may ask whether we process your personal data and request a copy of the data and related processing information.
14.2 Rectification
You may ask us to correct inaccurate data or complete incomplete data.
14.3 Erasure
You may ask us to delete personal data where there is no longer a lawful reason to retain it. The right to erasure does not require us to delete information that must be retained for legal obligations, accounting, tax, fraud prevention, security, disputes or legal claims.
14.4 Restriction
You may ask us to restrict the use of personal data in certain circumstances, including while accuracy or an objection is being assessed.
14.5 Data portability
Where processing is automated and based on your consent or a contract, you may request personal data you provided to us in a structured, commonly used and machine-readable format. Where technically feasible, you may ask us to transmit it directly to another controller.
14.6 Objection
You may object to processing based on Article 6(1)(f) GDPR. Where you object, we will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is necessary for legal claims. We do not currently process personal data for direct marketing. Were that to change, an objection to direct marketing would be honoured without requiring you to provide a reason.
14.7 Withdrawal of consent
Where any processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn. At present, our core account, ordering and delivery processing does not rely on consent as its GDPR lawful basis.
14.8 Complaint to a supervisory authority
You have the right to lodge a complaint with the supervisory authority in the country of your habitual residence, your place of work or the place of the alleged infringement.
In Poland, the relevant authority is:
President of the Personal Data Protection Office
Urząd Ochrony Danych Osobowych - UODO
ul. Stanisława Moniuszki 1A
00-014 Warsaw
Poland
14.9 How to exercise your rights
Send your request to studio@tanthrall.com.
Please describe the right you wish to exercise and provide enough information for us to identify the relevant account, order or correspondence.
We may ask for proportionate information to verify your identity. We will not ask for more identification information than is reasonably necessary.
We will respond without undue delay and normally within one month of receiving the request. Where a request is particularly complex or numerous, the response period may be extended by up to two further months. If that happens, we will notify you within the first month and explain the reason.
Requests are normally handled without charge. A reasonable fee may be charged, or a request may be refused, where it is manifestly unfounded or excessive, particularly because it is repetitive, as permitted by law.
15. Automated decision-making
We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning you.
Prices may be calculated automatically from the published package, design and add-on selections. This is a catalogue calculation, not profiling.
Orders or enquiries above the applicable review threshold, currently USD 2,500, are referred for human review. A person decides whether and on what terms a quote is issued.
We do not use automated systems to assess creditworthiness, personal reliability or eligibility for the service.
16. Children
Tanthrall accounts and paid services are intended only for persons aged 18 or over.
We do not knowingly permit children to create accounts or enter into contracts through the service. If we learn that an account was created by a child, we may suspend the account and delete the information unless retention is required to address a legal or security issue.
17. Changes to this Policy
We may update this Policy where:
- our services or processing activities change;
- a service provider changes;
- a legal or regulatory requirement changes;
- a security or operational change affects the information provided here; or
- clarification is needed.
The current version will be published with a new "Last updated" date.
Where a change materially affects an existing account or order, we may provide additional notice by email or through the account area. We will not retrospectively use previously collected personal data for a materially different purpose without first establishing an appropriate lawful basis and providing any notice or consent required by law.
18. Contact
Questions, requests or complaints concerning this Policy or our use of personal data should be sent to:
Tanthrall Services Sp. z o.o.
ul. Głogowska 82/22
60-741 Poznań
Poland
Email: studio@tanthrall.com
Website: https://www.tanthrall.com