StartAuto
Privacy policy
Information about the data we process, purposes, legal bases and user rights.
1. Controller
The controller of personal data is StartAuto.pl. Privacy contact: kontakt@podziel.pl. Full operator details are shown below.
2. Data and sources
- Account and profile data: email, display name, account type, verification and security settings.
- Listing and company-profile content, photos, categories, prices, location and publication history.
- Contact data provided voluntarily, including an encrypted phone number.
- Private messages, reports, appeals, support correspondence and complaint records.
- Favorites, searches, alerts, recent activity and consent or legal-acceptance records.
- Technical data: IP-derived security hashes, user agent, session identifiers, logs, request identifiers and device events.
- Imported data where the user or lawful source has supplied a listing for migration.
3. Purposes and legal bases
| Purpose | Legal basis | Examples |
|---|---|---|
| Provide account and listing services | Art. 6(1)(b) GDPR | Registration, sign-in, publication, messages, saved functions, export and deletion requests. |
| Security and abuse prevention | Art. 6(1)(f) GDPR | Rate limits, fraud and spam detection, session records, audit logs, duplicate and risk checks. |
| Legal compliance | Art. 6(1)(c) GDPR | Handling lawful authority requests, accounting where paid services exist, DSA notices and required records. |
| Claims and dispute resolution | Art. 6(1)(f) GDPR | Complaint evidence, moderation history and limited retention after account closure. |
| Optional analytics, advertising or marketing | Art. 6(1)(a) GDPR where consent is required | Loaded only in accordance with the user’s consent choices and production configuration. |
4. Automated protection and moderation
Rules and scoring may assess spam, fraud, duplicate content, contact-data leakage and category accuracy. Results may publish a low-risk listing, place it under monitoring, request correction or block a critical case. A human review path is available for materially adverse decisions.
5. Recipients
- Authorised personnel and service providers necessary for hosting, email delivery, backups, security and maintenance.
- Analytics or advertising providers only when enabled and permitted by consent.
- Public authorities or courts where disclosure is required by law.
- Other users only to the extent information is intentionally published or sent in a message.
6. Transfers outside the EEA
A provider may process data outside the EEA only where an applicable transfer mechanism and safeguards are in place. The operator must verify the production provider register before approval of these documents.
7. Retention
| Data category | Default period / rule |
|---|---|
| Account and active listings | For the duration of the account or service and until deletion, subject to legal holds. |
| Deleted account operational data | Normally removed or anonymised after the cancellation period; limited evidence may remain for claims or security. |
| Security and audit logs | Normally up to 180 days, longer only for an incident, investigation or claim. |
| Messages and reports | For the account/service period and up to 3 years after resolution where needed for disputes or safety. |
| Backups | Rotated according to backup policy, normally up to 90 days; deleted data disappears as backups expire. |
| Consent and legal-acceptance evidence | For the period necessary to demonstrate compliance and defend claims. |
8. Rights
- Access and a copy of data.
- Rectification of inaccurate data.
- Erasure where no overriding basis applies.
- Restriction of processing.
- Portability for eligible data processed by automated means on consent or contract.
- Objection to processing based on legitimate interests.
- Withdrawal of consent at any time for future processing.
- Complaint to the President of the Polish Personal Data Protection Office or another competent supervisory authority.
9. Required and optional data
Email and minimum account or listing fields are required to provide the requested service. Optional profile and contact data are marked as such. Refusal to provide required data may make the requested function unavailable.
10. Children
The service is not designed to independently conclude transactions with children. A person without full legal capacity should use the service only with the involvement and consent of a parent or legal guardian as required by law.
11. Security and changes
The service uses password hashing, encrypted sensitive contact data, restricted administrative access, session controls, backups and audit logs. No service can guarantee absolute security. Material policy changes will be versioned and dated.
Legal framework
The documents take into account the GDPR, the Digital Services Act, Polish rules on electronic services, electronic communications and mandatory consumer protection. Their final application depends on the operator’s actual business model and integrations.


