Privacy Policy
Effective as of: November 28, 2025
Last updated: November 28, 2025
Welcome to SaaS Toolbox! We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you subscribe to our newsletter and visit our website.
We comply with the General Data Protection Regulation (GDPR) – Regulation (EU) 2016/679 – and other applicable data protection laws.
1. Who We Are
Data Controller:
Bartosz Sosna
Brzozowa 21, 55-040 Ślęza, Poland
Tax ID (NIP): PL6472446893
Contact: bart@saastoolbox.co
2. What Data We Collect
We collect only the data necessary to deliver our newsletter and operate the website:
- Email address
- First name (optional)
- Subscription date and time
- IP address
- Email engagement data (open rates, click rates)
- Cookies (essential, analytics, and—if you agree—marketing)
3. How We Use Your Data
We process your data for the following purposes:
- Newsletter delivery (legal basis: consent, Art. 6(1)(a) GDPR)
- Improving our service (legal basis: legitimate interest, Art. 6(1)(f) GDPR)
- Communication and support (legal basis: legitimate interest, Art. 6(1)(f) GDPR)
- Marketing and analytics, if you consent to marketing cookies (see Section 9 and Section 15)
We will never sell your data, send unrelated marketing, or share data with advertisers without your explicit consent.
4. How Long We Keep Your Data
- Active subscribers: as long as you stay subscribed
- After unsubscribe: deleted within 30 days (unless legally required otherwise)
- Analytics: anonymized after 12 months
5. Who Has Access to Your Data
We use trusted service providers who may process your data on our behalf:
- Sendy (self-hosted) — newsletter platform
- Amazon Web Services (AWS SES) — email delivery
- Hosting provider — EU-based web hosting
- Meta Platforms — only if you consent to Meta Pixel (see Section 15)
All providers operate under Data Processing Agreements and meet GDPR standards.
6. International Data Transfers
Some providers (e.g., AWS, Meta) may process data outside the EEA. When this occurs, we use:
- EU–US Data Privacy Framework
- Standard Contractual Clauses (SCC)
- Adequacy decisions (where applicable)
7. Your Rights Under GDPR
You have the right to:
- Access your data
- Rectify inaccuracies
- Request deletion
- Restrict processing
- Data portability
- Object to processing based on legitimate interest
- Withdraw consent at any time
Contact: bart@saastoolbox.co
8. How to Unsubscribe
You can unsubscribe by:
- Clicking the "Unsubscribe" link in any email
- Emailing bart@saastoolbox.co with the subject "Unsubscribe"
9. Cookies
Our website uses the following cookies:
- Essential cookies — required for functionality
- Analytics cookies — optional, based on your consent
- Marketing cookies — optional, used only with your explicit consent (Meta Pixel)
You can manage cookies through your browser or via our cookie banner.
10. Data Security
We use:
- TLS/SSL encryption
- Secure, password-protected systems
- Regular updates and monitoring
- Limited access to subscriber data
11. Children's Privacy
Our website is not intended for individuals under 16. We do not knowingly collect data from children.
12. Changes to This Policy
We may update this policy from time to time. Significant changes will be announced via email.
13. Complaints
You may file a complaint with the supervisory authority:
Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
Website: https://uodo.gov.pl
14. Contact Us
Email: bart@saastoolbox.co
Address: Brzozowa 21, 55-040 Ślęza, Poland
15. Meta (Facebook) Pixel
We use Meta Pixel (Facebook Pixel) for marketing, remarketing, and analytics — only if you give consent via the cookie banner.
Meta Pixel allows us to understand how visitors interact with our website and to display relevant ads on Meta platforms. The data processed through Meta Pixel may include:
- IP address
- Device identifiers
- Activity on our website
- Technical browser information
- Marketing events (e.g., page views)
This data may be transferred to Meta Platforms Ireland and Meta Platforms, Inc. (USA). These transfers rely on:
- Standard Contractual Clauses (SCC), and
- Meta's certification under the EU–US Data Privacy Framework
Legal basis: your consent (Art. 6(1)(a) GDPR).
If you do not consent, the Pixel will not load.
More details: https://www.facebook.com/privacy/policy