Privacy Policy

Important: If you are from China, this is the Chinese version of the Privacy Policy.

Effective date: 01/02/2022
Last updated: 23/07/2025

This Privacy Policy explains how LMTS Sp. z o.o., the operator of the Tidaro platform, processes personal data of users and individuals contacting us. We operate in accordance with Regulation (EU) 2016/679 (GDPR) and the Polish Data Protection Act of May 10, 2018.

1. Data Controller and Processor

Depending on the nature of the data:

  • For data entered by Tidaro customers about their employees (e.g., names, emails, license plate numbers), LMTS Sp. z o.o. acts as a data processor under a data processing agreement with the customer, who remains the data controller.

  • For all other data (e.g., reservation history, analytics, support queries, marketing), LMTS Sp. z o.o. acts as a data controller.

2. What Data We Process and in What Role

Account data (Tidaro as data processor)
  • Full name

  • Email address

  • Vehicle license plate numbers

Operational data (Tidaro as data controller)
  • Reservation history (desks, parking spaces, rooms)

  • Actions taken in the application

  • Device type, operating system, browser

  • IP address, login timestamps

Communication and support (Tidaro as data controller)
  • Messages sent to support

  • Survey and feedback responses

  • Email correspondence history

Contact data from interested individuals (Tidaro as data controller)

If you contact us to learn about Tidaro, we may process:

  • Full name

  • Email address

  • Phone number (if voluntarily provided)

  • Company name

  • Message content

3. Purpose and Legal Basis for Processing

As a Data Processor

We process personal data only on behalf of and under the instructions of our customers based on a data processing agreement in accordance with Article 28 of the GDPR.

As a Data Controller, we process data for the following purposes:
  • Providing platform functionality and managing user accounts

  • Technical maintenance and system analytics

  • Responding to support requests

  • Marketing communication (with consent)

  • Ensuring system protection (e.g., via Google reCAPTCHA)

  • Handling inquiries and sales-related communication

Legal bases:

  • Art. 6(1)(b) GDPR – contract performance or pre-contractual measures

  • Art. 6(1)(f) GDPR – legitimate interest

  • Art. 6(1)(a) GDPR – consent

  • Art. 6(1)(c) GDPR – legal obligation

4. Sharing of Personal Data

We may share your data with:

  • Other users in your organization, for example to view shared booking calendars

  • IT service providers (e.g., hosting, technical support, user communication)

  • Brevo (Sendinblue) – for sending marketing and newsletter communications

  • Google Ireland Ltd. – to enable reCAPTCHA protection

  • Public authorities – when required by law

All data is stored and processed within the European Economic Area (EEA). All processors operate under contracts that ensure compliance with GDPR.

5. Data Transfers Outside the EEA

We do not transfer your personal data outside the European Economic Area (EEA).
All data is stored and processed exclusively on infrastructure located within the EEA.

6. Cookies and Google reCAPTCHA

We use cookies to:

  • Maintain session states

  • Personalize interface settings

  • Analyze website traffic and application usage

Some forms are protected by Google reCAPTCHA, which may collect user data to distinguish humans from bots. Learn more in Google’s Privacy Policy.

7. Email Marketing (Brevo)

With your consent, we may send you information about Tidaro’s features and updates using Brevo. You can unsubscribe at any time via the link in the email or by contacting us.

8. Data Retention

We retain personal data for the following durations:

  • For the duration of the contract with your organization

  • Until consent is withdrawn (if consent was the basis for processing)

  • Until a valid objection is raised

  • For the time required by applicable law or to defend legal claims

9. Your Rights

Under the GDPR, you have the right to:

  • Access your personal data

  • Rectify or update your data

  • Request deletion (“right to be forgotten”)

  • Restrict processing

  • Data portability

  • Object to processing

  • Withdraw your consent at any time (when applicable)

To exercise your rights, email us at privacy@tidaro.com

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO) in Poland.

10. Data Security

We implement appropriate technical and organizational measures to safeguard personal data, including:

  • Encrypted data transmission

  • Access controls and multi-factor authentication

  • Continuous monitoring and security audits

  • Trained staff and internal data protection policies

11. Changes to This Policy

We may update this Privacy Policy to reflect changes in laws or how we operate. Material changes will be communicated via email or in-app notifications.

12. Contact Us

LMTS Sp. z o.o.
ul. Partyzantów 17
75-900 Koszalin, Polska
Email: privacy@tidaro.com