Privacy Policy

Effective as of: November 28, 2025
Last updated: November 28, 2025

Welcome to SaaS Toolbox! We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you subscribe to our newsletter and visit our website.

We comply with the General Data Protection Regulation (GDPR) – Regulation (EU) 2016/679 – and other applicable data protection laws.

1. Who We Are

Data Controller:

Bartosz Sosna
Brzozowa 21, 55-040 Ślęza, Poland
Tax ID (NIP): PL6472446893

Contact: bart@saastoolbox.co

2. What Data We Collect

We collect only the data necessary to deliver our newsletter and operate the website:

  • Email address
  • First name (optional)
  • Subscription date and time
  • IP address
  • Email engagement data (open rates, click rates)
  • Cookies (essential, analytics, and—if you agree—marketing)

3. How We Use Your Data

We process your data for the following purposes:

  • Newsletter delivery (legal basis: consent, Art. 6(1)(a) GDPR)
  • Improving our service (legal basis: legitimate interest, Art. 6(1)(f) GDPR)
  • Communication and support (legal basis: legitimate interest, Art. 6(1)(f) GDPR)
  • Marketing and analytics, if you consent to marketing cookies (see Section 9 and Section 15)

We will never sell your data, send unrelated marketing, or share data with advertisers without your explicit consent.

4. How Long We Keep Your Data

  • Active subscribers: as long as you stay subscribed
  • After unsubscribe: deleted within 30 days (unless legally required otherwise)
  • Analytics: anonymized after 12 months

5. Who Has Access to Your Data

We use trusted service providers who may process your data on our behalf:

  • Sendy (self-hosted) — newsletter platform
  • Amazon Web Services (AWS SES) — email delivery
  • Hosting provider — EU-based web hosting
  • Meta Platforms — only if you consent to Meta Pixel (see Section 15)

All providers operate under Data Processing Agreements and meet GDPR standards.

6. International Data Transfers

Some providers (e.g., AWS, Meta) may process data outside the EEA. When this occurs, we use:

  • EU–US Data Privacy Framework
  • Standard Contractual Clauses (SCC)
  • Adequacy decisions (where applicable)

7. Your Rights Under GDPR

You have the right to:

  • Access your data
  • Rectify inaccuracies
  • Request deletion
  • Restrict processing
  • Data portability
  • Object to processing based on legitimate interest
  • Withdraw consent at any time

Contact: bart@saastoolbox.co

8. How to Unsubscribe

You can unsubscribe by:

  • Clicking the "Unsubscribe" link in any email
  • Emailing bart@saastoolbox.co with the subject "Unsubscribe"

9. Cookies

Our website uses the following cookies:

  • Essential cookies — required for functionality
  • Analytics cookies — optional, based on your consent
  • Marketing cookies — optional, used only with your explicit consent (Meta Pixel)

You can manage cookies through your browser or via our cookie banner.

10. Data Security

We use:

  • TLS/SSL encryption
  • Secure, password-protected systems
  • Regular updates and monitoring
  • Limited access to subscriber data

11. Children's Privacy

Our website is not intended for individuals under 16. We do not knowingly collect data from children.

12. Changes to This Policy

We may update this policy from time to time. Significant changes will be announced via email.

13. Complaints

You may file a complaint with the supervisory authority:

Urząd Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warsaw, Poland
Website: https://uodo.gov.pl

14. Contact Us

Email: bart@saastoolbox.co
Address: Brzozowa 21, 55-040 Ślęza, Poland

15. Meta (Facebook) Pixel

We use Meta Pixel (Facebook Pixel) for marketing, remarketing, and analytics — only if you give consent via the cookie banner.

Meta Pixel allows us to understand how visitors interact with our website and to display relevant ads on Meta platforms. The data processed through Meta Pixel may include:

  • IP address
  • Device identifiers
  • Activity on our website
  • Technical browser information
  • Marketing events (e.g., page views)

This data may be transferred to Meta Platforms Ireland and Meta Platforms, Inc. (USA). These transfers rely on:

  • Standard Contractual Clauses (SCC), and
  • Meta's certification under the EU–US Data Privacy Framework

Legal basis: your consent (Art. 6(1)(a) GDPR).
If you do not consent, the Pixel will not load.

More details: https://www.facebook.com/privacy/policy