1. Scope of this Privacy Policy
This Privacy Policy describes how ArcShield Michał Kasjanowicz (“Marta”, “we”, “us”, or “our”) processes personal data when you visit trymarta.com, contact us, subscribe to updates, or use the Marta Trust Center software-as-a-service platform (together, the “Service”).
This policy applies when we act as a data controller — for example, for our marketing website, customer relationship data, and account administration for the Marta application at app.trymarta.com.
When a business customer uses Marta Trust Center to publish security and compliance content, we often process personal data contained in that content as a data processor on the customer’s instructions. In those cases, the customer’s privacy notice and our Data Processing Agreement (DPA), available on request at privacy@trymarta.com, govern that processing.
This policy does not apply to third-party websites, products, or services that you may access through links on our site or integrations you enable in the product. Those providers have their own privacy practices.
2. Who we are
The data controller for the processing described in this policy is ArcShield Michał Kasjanowicz, NIP 1133000531, REGON 383806752, Poland, European Union. Registered address: ul. Igańska 34/1, 04-083 Warszawa, Poland.
Marta is the product brand operated by ArcShield Michał Kasjanowicz. Our registered office is at ul. Igańska 34/1, 04-083 Warszawa, Poland.
For privacy-related questions or to exercise your rights, contact us at privacy@trymarta.com. For security matters, contact security@trymarta.com.
3. Audience and B2B focus
Marta Trust Center is designed primarily for businesses and professionals evaluating or purchasing B2B software. Most users interact with us in a professional capacity (for example, as an employee or contractor of a prospective or existing customer).
If you are a consumer using the Service outside a business context, additional mandatory information duties and rights may apply under Polish and EU law. Where those rules provide stronger protections, we will honour them to the extent required.
TODO: Confirm with counsel whether consumer sign-up paths require additional disclosures beyond this policy.
4. Information we collect
We collect personal data in several ways depending on how you interact with us. The categories below are representative; not every category applies to every individual.
4.1 Account and identity data
When you or your organization registers for the Marta application, we may process work email address, name, job title, company name, authentication credentials, account preferences, and audit-relevant activity metadata necessary to operate your account.
If you choose **Sign in with Google** on app.trymarta.com, we receive from Google the information you authorize under the openid, email, and profile scopes — typically your Google account email address, display name, and profile picture URL. We use this only to authenticate you and maintain your account; we do not receive your Google password.
Account administration for the product application is primarily handled in app.trymarta.com.
4.2 Contact, lead, and communications data
- Email address, name, company, and optional message content when you request a demo, contact sales or support, or submit a form on trymarta.com.
- Newsletter subscription data when you opt in to blog or product updates.
- Records of email correspondence, support tickets, and meeting notes when you communicate with us.
- Scheduling details if you book a demo through an integrated calendar provider (for example, Cal.com when enabled).
4.3 Billing and commercial data
For paid plans, we or our payment providers may process billing contact details, subscription plan, invoice history, tax identifiers, and payment status.
4.4 Usage, technical, and device data
- Internet protocol (IP) address, browser type and version, device type, operating system, language preferences, and referrer URL.
- Pages viewed, links clicked, session duration, and aggregate interaction data on trymarta.com.
- Server and application logs generated for security, debugging, and service reliability.
- Cookie and consent preference data stored in your browser (see our Cookie Policy at /legal/cookies).
4.5 Customer Trust Center content
Organizations using Marta Trust Center may upload or publish policies, controls, certifications, subprocessors, documents, FAQs, branding assets, and related metadata. That content may include personal data — for example, names in document metadata, access-request details, or contact information in published policies.
In most cases, the customer determines what is published and remains the data controller for personal data in Customer Content. We process that data to host, display, and deliver the Trust Center according to the customer’s instructions.
4.6 Information from other sources
- Publicly available professional information (for example, company websites or business directories) to maintain accurate customer records.
- Referral or event partners when you interact with us at a conference, webinar, or co-marketed activity, subject to the partner’s notice and your choices.
- Service providers that help us operate the Service, such as form delivery or hosting vendors.
5. How we use personal data
We use personal data for the following purposes, depending on context:
- Providing, operating, maintaining, and improving the Service, including hosting Trust Centers and administering accounts.
- Responding to demo requests, support inquiries, and other communications you initiate.
- Sending service-related messages (for example, account notices, security alerts, or changes to terms) that are part of operating the Service.
- Sending marketing communications about Marta products, blog content, or events where permitted by law and, where required, based on your consent. You may opt out at any time.
- Analysing aggregate website traffic to improve content and usability, only after you opt in to analytics cookies where consent is required.
- Detecting, preventing, and investigating fraud, abuse, security incidents, and violations of our terms.
- Complying with legal obligations, responding to lawful requests, and establishing, exercising, or defending legal claims.
- Managing our business operations, including accounting, reporting, and internal analytics in aggregated or de-identified form.
6. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on one or more of the following legal bases:
- Performance of a contract or steps prior to entering a contract (Art. 6(1)(b)) — for example, providing the Service, administering your account, or responding to a demo request you submit.
- Legitimate interests (Art. 6(1)(f)) — for example, securing our systems, improving the Service, communicating with business prospects, and preventing abuse, balanced against your rights.
- Consent (Art. 6(1)(a)) — for example, non-essential analytics cookies, certain marketing emails, or other processing where consent is required. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — for example, tax, accounting, or responding to binding requests from authorities.
- Processor role — when we process personal data in Customer Content on a customer’s behalf, we act on the customer’s instructions as processor under applicable law and our DPA.
7. Marketing communications
We may send newsletters, product updates, or event invitations if you subscribe or where otherwise permitted. Marketing emails include an unsubscribe link or instructions to opt out.
Opting out of marketing does not affect service-related communications necessary to operate your account or respond to your requests.
8. Customer data and processor role
When a customer uses Marta Trust Center, we typically process personal data in Customer Content as a processor and the customer remains the controller. The customer is responsible for having a lawful basis to publish content and for providing appropriate notices to its buyers and visitors.
A Data Processing Agreement (DPA) describing security measures and international transfers is available to business customers on request at privacy@trymarta.com.
9. How we share and disclose information
We do not sell personal data. We share personal data only as described below:
- Service providers who help us deliver the Service (hosting, analytics after consent, form processing, email delivery, and similar functions), bound by confidentiality and data protection obligations.
- Google LLC when you use Sign in with Google — Google processes authentication according to its own privacy policy (https://policies.google.com/privacy). We receive only the profile fields described in section 4.1.
- Professional advisers (lawyers, accountants, insurers) where necessary and subject to duty of confidentiality.
- Affiliates or successors in the event of a merger, acquisition, reorganization, or sale of assets, subject to appropriate safeguards.
- Law enforcement, regulators, courts, or other parties when required by law or necessary to protect rights, safety, and security.
- With your direction or consent — for example, when you ask us to share information with an integration partner.
10. International data transfers
We aim to process data in the European Union where practicable. Some providers may process data in the United States or other countries.
When personal data is transferred outside the EU/EEA to a country without an adequacy decision, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, unless another valid transfer mechanism applies.
11. Data retention
We retain personal data only as long as necessary for the purposes described in this policy, unless a longer period is required by law.
- Account data: for the life of the account and a reasonable period thereafter (typically up to 24 months) to resolve disputes, comply with law, and maintain business records.
- Demo and lead data: typically up to 24 months from last interaction, unless you object earlier or we have an ongoing commercial relationship.
- Marketing subscription data: until you unsubscribe or withdraw consent, plus a short suppression record to honour opt-out requests.
- Server and security logs: typically up to 90 days, unless a longer period is needed for an incident investigation.
- Cookie consent preferences (local storage): until you clear site data or we bump the consent policy version, after which we may ask for your preferences again.
- Customer Content: according to the customer’s subscription and our DPA, generally deleted within a reasonable period after account termination unless retention is legally required.
12. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS), access controls, and least-privilege principles for administrative access.
See /security for an honest overview of our practices. We do not claim certifications, audits, or monitoring capabilities we have not earned.
No method of transmission or storage is completely secure. You are responsible for maintaining the confidentiality of your account credentials.
13. Your rights
Depending on applicable law (including the GDPR), you may have the following rights regarding your personal data:
- Access — request a copy of personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion in certain circumstances.
- Restriction — request that we limit processing in certain circumstances.
- Data portability — receive data you provided in a structured, commonly used format where processing is based on consent or contract and carried out by automated means.
- Objection — object to processing based on legitimate interests, including direct marketing.
- Withdraw consent — where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
How to exercise your rights
Email privacy@trymarta.com. We may need to verify your identity before responding. We aim to respond within one month as required by the GDPR, subject to permitted extensions for complex requests.
If we process your data as a processor on behalf of a Marta customer, please contact that customer first; we will assist the customer as required by our DPA.
14. Supervisory authority
You have the right to lodge a complaint with a supervisory authority. In Poland, the competent authority is:
President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych — UODO), ul. Stawki 2, 00-193 Warszawa, Poland — https://uodo.gov.pl
15. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects concerning individuals.
16. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe we have collected data from a child, contact us at privacy@trymarta.com and we will take appropriate steps to delete it.
17. Cookies and similar technologies
We use cookies, local storage, and similar technologies as described in our Cookie Policy (/legal/cookies). Non-essential analytics load only after you consent through our cookie banner.
You can change your preferences at any time via “Cookie settings” in the website footer.
18. Third-party links and integrations
Our website may link to third-party sites (for example, documentation, social profiles, or scheduling tools). We are not responsible for their privacy practices.
If demo scheduling through Cal.com or similar tools is enabled, those providers may collect data according to their own policies when you interact with their embed or redirect.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law, our practices, or the Service. We will post the updated version on this page with a revised “Last updated” date.
If changes materially affect your rights, we will provide additional notice (for example, by email or a prominent notice on the website) where required by law.
Continued use of the Service after the effective date of an update constitutes acceptance of the revised policy, except where your consent is required by law.
20. Contact us
Privacy inquiries and rights requests: privacy@trymarta.com
Security reports: security@trymarta.com
General contact: hi@trymarta.com
Postal address: ArcShield Michał Kasjanowicz, ul. Igańska 34/1, 04-083 Warszawa, Poland