Privacy Policy

How we collect, use, and protect your personal data

Last updated: June 2026  ·  Covers: yolkfolk.pl website & YolkOS mobile app

This policy replaces and supersedes the cookie policy at yolkfolk.pl/cookie-policy. It covers both the website and the YolkOS mobile app. The cookie-specific information from the existing policy is retained in Section 9 below.

1. Who We Are

YOLK Spółka z ograniczoną odpowiedzialnością, ul. Józefa Sarego 5/4, 31-047 Kraków, Poland (KRS: 818889, NIP: 6762575400) is the Data Controller for all personal data described in this policy.

Contact for privacy matters: hello@yolkfolk.pl

2. What Data We Collect

2.1 Membership & Account Data

Collected when you register or onboard:

  • Full name and email address
  • Phone number (optional)
  • Company name and role/title
  • Profile photo (uploaded voluntarily)
  • One-liner bio and interests (entered voluntarily during App onboarding)
  • Tax identification number (for invoice purposes, where applicable)
  • Membership plan and payment status (read from OfficeRnD)

2.2 Access & Operational Data

Collected automatically as part of providing the service:

  • Door unlock events: door ID, timestamp, and member identity — logged via UniFi Access for security purposes
  • Check-in records: date and time of workspace entry — logged via OfficeRnD
  • Meeting room bookings: room, date, time, and duration — logged via OfficeRnD
  • CCTV footage: recorded in all areas of the Yolk premises for the safety of people and property (see Section 1 of the main T&Cs)

2.3 App Usage Data (with consent)

If you gave analytics consent during App onboarding:

  • App screens visited and features used
  • Session frequency and duration
  • Push notification interaction (opened / dismissed)
  • Random Coffee match and completion status (aggregated)

Analytics consent is separate from the core service. You can withdraw it at any time in App profile settings.

2.4 Community Content

Content you voluntarily create within the App:

  • Chat messages posted to the #general community channel
  • Direct messages sent to other members
  • Profile information (bio, interests, skills, Open to Chat status)
  • Random Coffee participation history

2.5 Website Data

When you visit yolkfolk.pl:

  • IP address, browser type, and pages visited (via Google Analytics — anonymised)
  • Chat interaction history with the HubSpot live chat widget
  • Booking form submissions

3. Why We Process Your Data (Legal Bases)

Performance of contract (Art. 6(1)(b) GDPR)

Membership account creation and management; door access provisioning and logging; meeting room bookings; invoicing and payment processing; OTP authentication for App login.

Legitimate interests (Art. 6(1)(f) GDPR)

Security CCTV; fraud prevention; community moderation; improving the App and services; aggregated analytics to understand community health trends.

Consent (Art. 6(1)(a) GDPR)

App analytics data; marketing emails and newsletters; Random Coffee pairing (profile data shared with match); directory visibility; promotional photography/filming (as stated in T&Cs Section 7).

Legal obligation (Art. 6(1)(c) GDPR)

Retention of financial records; responding to lawful requests from Polish authorities.

4. Data Retention

  • Door unlock logs — 12 months, then deleted (unless required for incident investigation)
  • CCTV footage — 30 days, then overwritten
  • Community chat messages (#general) — 30 days, then automatically deleted
  • Direct messages — duration of membership + 90 days after termination
  • Membership & account data — duration of membership + 5 years (legal/financial obligation)
  • Financial records (invoices, payments) — 5 years from the end of the financial year (Polish Accounting Act)
  • App analytics data — retained in aggregated form; individual-level data deleted within 90 days of consent withdrawal
  • Profile content (bio, interests, photo) — deleted within 30 days of membership termination on request

5. Who We Share Data With

We do not sell personal data. We share data only with the following categories of recipients, and only to the extent necessary:

  • Supabase (Ireland) — database, authentication, realtime messaging. EU-hosted.
  • OfficeRnD (UK/EU) — membership status, bookings, check-ins. Data processed under their DPA.
  • Ubiquiti / UniFi (USA) — door control. Access events processed locally on-premises; no personal data sent to Ubiquiti cloud.
  • Brevo (France) — OTP email and transactional email delivery. EU-based.
  • Apple / Google — push notification delivery via APNs / FCM. Only device tokens and notification payloads are transmitted; no personal data beyond what is necessary.
  • Google Analytics — anonymised website usage data.
  • HubSpot — website live chat. May process contact data for marketing if you consent.
  • Polish courts or authorities — if required by law.

6. International Transfers

Supabase and Brevo are hosted within the EU/EEA. Ubiquiti (UniFi) processes door access events locally on YOLK's premises; no personal data is transmitted to Ubiquiti's cloud servers.

Apple and Google receive device tokens for push notification delivery. Both companies operate under EU Standard Contractual Clauses (SCCs) for data transfers from the EEA to the USA.

Full details of transfer mechanisms are available on request.

7. Your Rights Under GDPR

As a data subject in Poland / the EU, you have the following rights:

  • Right of access — request a copy of the personal data we hold about you
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure — request deletion of your data (subject to legal retention obligations)
  • Right to restriction — limit how we process your data in certain circumstances
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interests
  • Right to withdraw consent — at any time, for consent-based processing (this does not affect lawfulness of prior processing)
  • Right to lodge a complaint — with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl

To exercise any right, contact hello@yolkfolk.pl. We will respond within 30 days. Some requests (e.g. full erasure) may be limited by our legal obligations to retain financial records.

8. Security

We use the following measures to protect your data:

  • All data in transit is encrypted via HTTPS / TLS 1.2+
  • Supabase database access is protected by Row Level Security (RLS) — members can only access their own data and data they are explicitly permitted to see
  • App authentication uses time-limited OTP codes; no passwords are stored
  • API access between the App and backend requires a signed JWT token (720-hour expiry)
  • Physical access to server infrastructure is restricted to YOLK staff

No system is perfectly secure. In the event of a data breach that poses a risk to your rights, we will notify you and the UODO in accordance with GDPR Article 33/34 requirements.

9. Cookies (Website)

This section covers yolkfolk.pl only. The YolkOS mobile app does not use browser cookies.

The website uses the following categories of cookies:

Necessary

Essential for the website to function. Cannot be disabled. Includes session management and security tokens.

Analytics — Google Analytics (via Google Tag Manager)

Helps us understand how visitors navigate the site. Data is anonymised; no personally identifiable information is collected. You can opt out via Google's opt-out browser add-on.

Functional — HubSpot

Powers the live chat widget and remembers returning visitors. See HubSpot's cookie policy.

Functional — OfficeRnD

Set by booking widgets embedded on the site. Required for the booking flow to work correctly.

Marketing

Used to measure campaign effectiveness. You can decline these via the cookie consent banner when you first visit the site, or by adjusting your browser settings.

Managing Cookies

You can control cookies via your browser settings. Disabling necessary cookies may affect website functionality. Your consent preferences can be updated at any time by clearing site data in your browser.

10. Changes to This Policy

We may update this policy from time to time. The version date at the top of this document shows when it was last revised. Material changes will be notified to active members via email or App push notification with at least 14 days' notice.

Continued use of the App or website after changes take effect constitutes acceptance of the updated policy.

11. Contact

For any privacy-related questions, requests, or complaints:

YOLK Sp. z o.o.
ul. Józefa Sarego 5/4, 31-047 Kraków, Poland
admin@yolkfolk.pl
KRS: 818889  ·  NIP: 6762575400