Privacy policy
PERNO PRIVACY POLICY
Version 1.5 • document dated 5 August 2026 • effective upon publication on the PERNO website
This Policy covers the website, registration, the Account and all PERNO modules. It distinguishes between processing for Z3X’s own purposes and processing performed solely on the Customer’s behalf.
1. Controller and contact
The controller for processing described as Z3X’s own purposes is Z3X spółka z ograniczoną odpowiedzialnością, with its registered office in Gdańsk at al. Grunwaldzka 223, 80-236 Gdańsk, Poland, KRS 0000882886, NIP 5842801536, REGON 388133246 (“Z3X”, “we”). PERNO is a Z3X product and not a separate entity.
For privacy matters contact [email protected] or write to our registered office. Z3X has not appointed a data protection officer.
2. Scope, roles and no default consent
This Policy concerns website visitors, persons contacting Z3X, Customer or supplier representatives, persons registering an Account, PERNO or support users, and persons whose data a Customer places in active Modules.
Z3X is the controller for website, contact, B2B sales, registration, billing, security of its own service and support data. Where Z3X processes Platform data solely on the Customer’s documented instructions, the Customer remains controller and Z3X acts as processor under § 15 of the Terms or an individual DPA.
Selecting “I have read the Privacy Policy” is not consent. Consent is requested separately only where it is the proper legal basis and may be withdrawn without affecting prior lawful processing.
Capitalised terms not defined in this Policy have the meaning given in the PERNO Terms.
3. Sources and categories of data
We obtain data directly from the person, their organisation or Account administrator, from use of the website and Platform, from an integration enabled by the Customer or from lawful public sources. The scope depends on the relationship and Active Scope.
We may process identity and professional details, company and contact data, authority and roles, company-registration details, representatives and—where required by the selected PSP’s onboarding—beneficial owners and KYC or KYB documents supplied to Z3X. We also process Account and document-acceptance data, settings and activation history, product and PSP selections, the identifier, amount and status of the activation fee, correspondence and tickets, billing data, device and session identifiers, IP address, timestamps, logins, API calls, events, errors and diagnostic information.
Depending on the Module, data may include order, transaction, customer or ticket identifiers, amount, currency, payment method and status, payment token, and sales, delivery, return, event, admission, task, CRM, working-time and OKR data. PERNO is not intended to store a full card number or CVC/CVV.
Special-category and criminal-conviction data are not needed for standard PERNO use. The Customer should not enter them unless the feature has been expressly agreed, a valid legal basis exists and appropriate safeguards are in place.
4. Z3X purposes, legal bases and retention
Registration, Account and Agreement. We process data to create and manage the Account, evidence the conclusion and content of the Agreement, manage the Active Scope and communicate with the Customer. The basis is Article 6(1)(b) GDPR for an individual party and Article 6(1)(f) for representatives and Users—our interest in entering into and performing a B2B relationship. We retain data during the Agreement and then until applicable claim periods expire.
Onboarding and PSP configuration. We process company, representation, activation, selected-product and activation-payment data to configure the Account and transmit the Customer’s documented instruction and verification data to the selected PSP. For our own B2B relationship we rely on Article 6(1)(b), (c) or (f) GDPR depending on the person and purpose; the PSP independently determines the legal bases for its regulatory checks. We retain the onboarding record for the Agreement and claims periods, while documents collected solely for the PSP are erased or restricted after transfer unless further retention is required for law, security or claims.
Billing and legal duties. We process invoice and accounting data under Article 6(1)(c) GDPR and, for performance of the Agreement, Article 6(1)(b) or (f). We retain it for periods required by tax, accounting and claims law.
Platform operation and security. We process logs, technical identifiers and limited metadata under Article 6(1)(f) GDPR—our interest in security, diagnosis, abuse prevention and evidencing operation. We keep it only as long as needed and review retention; incident or claim data may be kept until closure.
Support and complaints. We process ticket content, attachments and handling history to perform the Agreement or under Article 6(1)(f)—our interest in resolving the matter and defending claims. Data remains until closure and for the applicable period needed to evidence handling.
B2B sales contact and marketing. We process professional data and contact content under Article 6(1)(f)—our interest in presenting an offer and maintaining relationships. We use e-mail, telephone or similar channels for marketing only after consent required by Polish Electronic Communications Law. We erase data after objection, consent withdrawal or loss of relevance.
Website and cookies. We process necessary technical data under Article 6(1)(f) to deliver and secure the website. Analytics, personalisation or marketing relies on consent where required. See section 9.
Providing data is voluntary, but data marked as required is necessary to answer a request, register, conclude or perform the Agreement, or meet a legal duty. Failure to provide it may prevent the relevant action or feature.
5. Data processed on the Customer’s behalf
Here the Customer determines the purposes, legal bases, scope and retention, while Z3X performs operations needed for active features. A data subject should generally address a request to the Customer with whom they have the direct relationship; Z3X assists under the DPA.
PERNO Orchestration. Buyer or payer data, customer, order and transaction identifiers, amount, currency, method, status, token and limited integration and technical metadata.
PERNO Store. User, staff, customer, buyer and recipient data; contact, address and billing details; and offer, order, delivery, sales document, complaint and return data.
PERNO PayEvento. User, buyer, payer and attendee data; contact and billing details; and event, order, ticket and QR, payment, refund, cancellation, scan and admission data.
PERNO Company. User, employee, contractor, customer, prospective-customer or other CRM-contact data; task, CRM relationship, working-time, OKR, permission and activity data. The Customer is responsible for lawful employee monitoring and notices.
Processing continues for the period set by the Customer, required for the active feature or agreed in the DPA. Afterwards data is returned, erased or anonymised under the Terms; backups expire in the ordinary security cycle.
6. PSPs and payment data
A PSP selected by the Customer may be a separate controller for merchant onboarding, KYC or KYB checks, payment execution and settlement, holding and paying out funds, security, fraud prevention, AML, refunds, chargebacks and regulatory duties. In that capacity it applies its own privacy policy and relationship with the Customer or payer.
Payment instrument data is entered in the PSP environment. PERNO may receive a token, identifier, status and limited metadata but is not intended to receive or store a full card number or CVC/CVV.
The active PSP follows from the Account or another documented Customer instruction. Selecting a PSP instructs transmission of data necessary for configuration and verification; the PSP’s privacy policy governs the scope and retention of data it processes. Merely listing a PSP among supported integrations does not activate it or cause data disclosure.
7. Recipients and sub-processors
Data may be received by authorised Z3X personnel, hosting and cloud, communications, security, monitoring, support, billing and accounting providers, legal advisers and auditors, PSPs and integration providers selected by the Customer, and authorities entitled by law.
When Z3X acts as processor it uses sub-processors under § 15 of the Terms. A current list including their function and location is made available electronically; questions may be sent to [email protected].
We do not sell personal data. A recipient receives only what is needed for its task and is bound by contract, confidentiality or its own legal duties.
8. Transfers outside the EEA
Where a provider or integration requires a transfer outside the European Economic Area, Z3X relies on an adequacy decision, European Commission standard contractual clauses with a transfer assessment and additional measures where needed, or another basis under Chapter V GDPR.
Information on the country, recipient and mechanism and a copy of relevant safeguards may be requested at [email protected]. Where the Customer selects an integration, it is also responsible for the lawfulness of its instruction and required notices to persons.
9. Cookies and similar technologies
Without consent we use only files or mechanisms necessary to transmit a communication, maintain a session, provide security or deliver a feature expressly requested by the user.
Analytics, personalisation or marketing cookies are enabled only after required information and consent. The consent panel allows rejection as easily as acceptance and later changes; it contains the current tools, purposes, providers and operating periods.
Browser settings can block cookies, but disabling necessary mechanisms may prevent login or use of parts of the Platform.
10. Individual rights
Depending on the legal basis and circumstances, a person has rights of access, rectification, erasure, restriction, portability and objection to processing based on Article 6(1)(f) GDPR. Consent may be withdrawn at any time.
Requests concerning Z3X’s own processing may be sent to [email protected]. We may request information needed to verify identity. Where a request concerns data processed for a Customer, we forward it to that Customer or act on its instructions.
A complaint may be lodged with the President of the Polish Personal Data Protection Office or the supervisory authority for the person’s habitual residence, place of work or alleged infringement.
11. Automated decisions
For its own purposes Z3X does not make decisions based solely on automated processing that produce legal or similarly significant effects, and does not profile persons for its own marketing without a separate legal basis.
A Customer or PSP may use its own rules, risk scoring or automation. That entity is then responsible for the legal basis, transparency, individual rights and safeguards; information should be obtained directly from it.
12. Security and Customer duties
Z3X applies measures appropriate to risk and service scope, including access control, transmission protection, event logging, backups, vulnerability management and incident procedures. Personnel access is limited to need and subject to confidentiality.
The Customer is responsible for User roles and permissions, security of its systems and devices, integration correctness, data lawfulness and retention configuration. Suspected breaches should be reported promptly to [email protected].
No safeguard eliminates all risk. Z3X regularly reviews measures and updates them having regard to technology, cost, data nature and risk to persons.
13. Children and sensitive data
The PERNO Account is a B2B service and is not intended for children. A child’s data may appear in Store or PayEvento only within a Customer process, for example as recipient or event-attendee data; the Customer is responsible for the legal basis, guardian or child notice and data minimisation.
The Customer should not place data beyond what an active feature needs, particularly special-category data, unless expressly agreed and appropriately safeguarded.
14. Amendments and language versions
This Policy may change following changes in law, PERNO features, providers or data processes. The current version and effective date are published on the website. We communicate a material change affecting an ongoing relationship through an appropriate channel before changed processing begins where its nature requires this.
The Policy is available in Polish, English and Italian. In case of discrepancy, the Polish version prevails.