SMSFLARE
Privacy and data

Privacy policy

How data is processed on the website, in the portal and when renting a server or instance with the SMSFLARE platform.

This document explains what data we process, why and on what legal basis, who may receive it and what rights data subjects have.

01

Controller and contact details

The controller of data relating to the website, business inquiries, user accounts, billing and our own customer service is Artur Januszczyk Usługi Informatyczne IN4SYSTEM, trading under the SMSFLARE brand, address: ul. Grodzieńska 9/65, 19-300 Ełk, Polska, Polish tax ID (NIP): 8481600751, REGON: 281090809.

For data protection matters, contact info@smsflare.net or call +48 600 827 406. We have not appointed a Data Protection Officer; privacy matters are handled directly by the controller.

02

When we are a controller and when we are a processor

We act as controller for data of people contacting us, portal users, representatives of customers and suppliers, and for billing data.

SMSFLARE rents a dedicated server or software instance to the Customer. We do not provide an SMS, VoIP or voice transmission service, sell telecommunications traffic, or select the Customer’s recipients, content, carriers or routes.

Where hosting, maintenance or support gives us technical access to data stored by the Customer — including numbers, content, OTP, CDR/DLR or call data — the Customer determines the purposes and means, while SMSFLARE acts solely as processor on documented instructions. Details are set out in the DPA, main agreement and access configuration.

The customer is responsible for having a valid legal basis to process and transmit production traffic data.
03

Categories of data

  • inquiries and contact: name, business email, company, telephone number, selected plan, area of interest, SMS volume, expected concurrent Voice/VoIP calls, destination countries, connection method, message content and technical form-submission data;
  • account and contract: user ID, company and contact details, roles, permissions, password hash, account status, login history and contractual arrangements;
  • billing: company name and address, tax number, invoices, payments, balances, credit terms and billing history;
  • technical and security data: IP address, session identifiers, timestamps, browser and device data, server logs, administrative and diagnostic events;
  • production service data: source and destination numbers, Sender ID, SMS or OTP content, message IDs, route and supplier, CDR, DLR, status, time, time zone, cost and attempt count;
  • URL and Voice features: domain and shortened URL, click event and clicked IP, call, TTS and Flash Call metadata, and a recognised OTP — only where the customer uses that feature.
04

Purposes and legal bases

  • responding to inquiries, preparing an offer and taking pre-contractual steps — Article 6(1)(b) GDPR;
  • entering into and performing a contract, operating an account, support and billing — Article 6(1)(b) GDPR;
  • invoicing, accounting, tax and statutory duties — Article 6(1)(c) GDPR;
  • system security, fraud prevention, diagnostics, legal claims and direct B2B contact concerning our own services — Article 6(1)(f) GDPR;
  • commercial communications or optional technologies where consent is required — Article 6(1)(a) GDPR and applicable electronic communications law;
  • customer traffic processing — Article 28 GDPR, documented customer instructions, the agreement and communications secrecy rules.
Our legitimate interests are secure and reliable service delivery, fraud prevention, maintaining business relationships and protecting the rights of the company and its customers.
05

Is providing data mandatory?

Providing form data is voluntary, but required fields are necessary to handle the inquiry. Account, company and billing details are necessary to enter into and perform a contract. Without required data, we may be unable to reply, create an account or provide the service.

06

Recipients and subprocessors

Data may be received only by entities that need it for a defined task: hosting and data-centre providers, email, security and IT maintenance suppliers, accountants, legal advisers, banks and payment operators. Telecommunications carriers and SMS, VoIP, numbering and routing suppliers are selected and configured by the Customer under its own agreements.

Data may also be disclosed to authorised public bodies where required by law. We enter into required processing arrangements and limit data to what is necessary.

07

Transfers outside the EEA

SMSFLARE does not select the Customer’s destination countries or traffic suppliers. If the Customer connects to a carrier or gateway outside the EEA, the Customer as controller is responsible for the legal basis of that transfer. SMSFLARE may access such data only within the agreed hosting or support scope.

For our own subprocessors, we use an appropriate transfer mechanism, such as a European Commission adequacy decision, Standard Contractual Clauses or another mechanism under Chapter V GDPR. Information on the mechanism applicable to a specific service is available on request.

08

Retention

  • business inquiries — up to 12 months after the last contact, and longer if they lead to a contract or are needed for legal claims;
  • account and contract records — for the contract term and then until relevant billing and claim periods expire;
  • accounting and tax records — for the statutory period;
  • security and diagnostic logs — generally up to 12 months, unless an incident, complaint or legal duty requires longer;
  • production traffic data — according to the agreement, DPA, customer retention configuration and mandatory law;
  • consent-based data — until consent is withdrawn, without affecting prior lawful processing.
09

Your rights

Subject to the conditions in the GDPR, you may request:

  • access to personal data and a copy;
  • rectification, erasure or restriction;
  • data portability where processing is automated and based on consent or contract;
  • an objection to processing based on legitimate interests;
  • withdrawal of consent at any time;
  • the right to lodge a complaint with the President of the Polish Personal Data Protection Office (UODO).
Send requests to info@smsflare.net. We may verify identity to the extent necessary to protect the data.
10

Automated decisions and profiling

We do not make decisions about users based solely on automated processing that produce legal or similarly significant effects. Automated routing, filtering, billing, DLR or abuse-detection rules are operational service functions and are not profiling of individuals within Article 22 GDPR.

11

Cookies and browser storage

The service currently uses only technologies necessary for the website and portal: recording cookie choices, maintaining a secure login session, storing basic signed-in user data and remembering language, appearance and interface settings. They include cc_cookie, smsflare_access_token, smsflare_user, smsflare-ui-settings-v1 and colorPref.

We do not currently use analytics or marketing cookies. Browser settings can remove stored data, but blocking necessary technologies may prevent login or preferences from being retained. If optional technologies are introduced, we will request any consent required before storing or accessing them.

12

Communications secrecy and security

We apply appropriate technical and organisational measures, including access controls, role separation, administrative event logging, transmission protection and service-appropriate backups. If maintenance or support gives us access to Customer communications data, we keep it confidential and restrict access to the necessary minimum.

No system can guarantee zero risk. Customers should protect credentials, use unique passwords, limit permissions and promptly report suspected incidents.

13

Policy changes

We may update this policy when services, technologies or laws change. The current version is published here with its revision date. Active customers will be notified in the portal or electronically of material changes.

14

Legal references and contact

For privacy questions, email info@smsflare.net. This policy takes account in particular of the GDPR, the Polish Act on Providing Services by Electronic Means and the Polish Electronic Communications Law.