Privacy Policy
What data we collect, why we collect it, and how long we keep it.
Updated: 03.09.2026
DockRay Privacy Policy
effective from the date of its publication on the Service
1. Data Controller and Contact
1.1. The controller of personal data processed in connection with the DockRay website, dashboard and service (the “Service”) is Dock sp. z o.o., with its registered office in Gdańsk, at ul. Rakoczego 9/73, 80-288 Gdańsk, Poland, entered in the Register of Entrepreneurs of the National Court Register under KRS number 0001105135, NIP (Tax Identification Number) 9571173402, REGON 524088178 (the “Controller”, “Dock” or “we”).
1.2. For matters relating to privacy, you can contact us at hello@dock.codes or in writing at our registered office address.
1.3. The Controller has appointed a Data Protection Officer, Miron Miotek. The Data Protection Officer can be contacted at m.miotk@dock.codes or by post at the Controller’s registered office address, with the note “Data Protection Officer”.
2. Scope and Roles in Data Processing
2.1. This Privacy Policy describes the processing of data relating to individuals who visit the DockRay website, create an Account, use the dashboard, place Orders, contact us, or represent Customers and suppliers.
2.2. With regard to Account data, dashboard users, billing, communications, Service security and Dock’s own marketing activities, Dock acts as the data controller and independently determines the purposes and means of processing.
2.3. Telemetry data transmitted from the Customer’s monitored applications, in particular error reports, information about HTTP transactions, IP addresses, user identifiers, URLs, headers and other information included by an Integration, is generally processed by us as a processor acting on the Customer’s instructions. The Customer remains the controller of such data. The terms of data processing are set out in the Terms of Service or in a separate agreement with the Customer.
2.4. The Customer determines what data is sent from its own systems to DockRay and is responsible for establishing a lawful basis for processing, fulfilling applicable transparency obligations, and properly configuring the Integration. A person whose data has been transmitted to DockRay from a monitored application should first direct any requests concerning such data to the controller of that application. We assist the Customer in handling such requests in accordance with the applicable data processing agreement.
3. Data We Process
- Account and User data – Account name, first name, last name, email address, telephone number, preferred language, roles and permissions, address verification status, and authentication settings;
- authentication and security data – password hash, encrypted TOTP secret, information about trusted devices or IP addresses, login dates, history of significant operations, IP address, session identifiers, and browser and device information;
- social login data – account identifier with the selected provider, email address, first name, last name, username or avatar URL provided by Google, Facebook or GitHub if the Customer uses such a login method;
- company and billing data – company or business name, NIP (Tax Identification Number) or another tax identification number, address, country, billing email address, selected Plan, currency, and history of Orders, payments and issued documents;
- payment data – payment method, transaction status and transaction identifier. Full payment card details are provided directly to the payment provider and are not stored by DockRay;
- contact data – information provided through a contact form, chat, email or support request, the content of correspondence, and information necessary to handle the matter;
- Service technical data – IP address, date and time of the request, requested URL, referring page address, response code, browser and operating system type, cookie identifiers, diagnostic data, and security-related events;
- Customer telemetry data – the scope depends on the configuration of the monitored application and may include error messages and stack traces, request and transaction data, identifiers, IP addresses, URLs, and information about the device, environment and software version.
We do not ask Customers to include passwords, API keys, session tokens, full payment card details, special categories of personal data, or data relating to criminal convictions and offences in telemetry data. Customers should use the filtering and anonymisation mechanisms provided by the Integrations.
4. Purposes, Legal Bases and Requirement to Provide Data
- creating and maintaining an Account, authentication, providing the Service, processing Orders and providing support – performance of a contract or steps taken prior to entering into a contract (Article 6(1)(b) GDPR), and, in the case of persons representing a Customer, our legitimate interest in performing the contract with the Customer and communicating with its personnel (Article 6(1)(f) GDPR);
- settlements, invoices, accounting and tax obligations – compliance with a legal obligation (Article 6(1)(c) GDPR) and performance of a contract;
- protecting Accounts, preventing abuse, handling incidents, maintaining logs and an audit trail – the legitimate interests of the Controller and Customers in ensuring the security, accountability and continuity of the Service (Article 6(1)(f) GDPR);
- responding to forms, chats and correspondence – steps taken prior to entering into a contract, performance of a contract, or a legitimate interest in handling enquiries and maintaining business relationships;
- establishing, pursuing and defending legal claims – the legitimate interest of the Controller (Article 6(1)(f) GDPR);
- analysing website usage, usability research and measuring the effectiveness of promotional activities – the user’s consent where the tool used stores information on the user’s device or accesses such information (Article 6(1)(a) GDPR and applicable electronic communications laws);
- sending commercial information or newsletters – consent, where separately provided by the user; irrespective of this, we may send existing Customers information relating to the operation or security of the purchased Service, as such communications do not constitute marketing.
Providing data marked as required is necessary to create an Account, process an Order or respond to an enquiry. Providing other data is voluntary. Failure to provide required data may make it impossible to perform the relevant action.
5. Sources of Data
We receive data directly from the data subject, from the Customer or another User managing the team, from the monitored application through an Integration, from the social login provider selected by the User, from the payment provider, and automatically from the user’s device when the Service is used. We may also obtain data concerning representatives of businesses from public registers and company websites.
6. Data Recipients and Service Providers
6.1. Data may be disclosed, only to the extent necessary, to:
- providers of hosting, cloud infrastructure, databases, backups and search services;
- providers of email, communication and support services;
- the payment provider Stripe, as well as banks and payment processing providers, where the relevant payment method is selected;
- Google, Facebook or GitHub authentication providers, where the User selects the relevant login method;
- Google in connection with reCAPTCHA, Google Tag Manager or services enabled through it, where applicable;
- Hotjar, where the behavioural analytics tool has been enabled;
- tawk.to, where the user uses the chat service available at the relevant time;
- providers of accounting, legal, auditing, security and software maintenance services;
- public authorities or other entities where disclosure is required by law.
6.2. Dock employees and contractors are granted access only to the extent necessary for their duties and assigned permissions and are required to maintain confidentiality.
6.3. The current configuration of the Service determines which optional tools are active. The mere inclusion of a provider in this Privacy Policy does not mean that its tool is active during every visit.
7. Transfers of Data Outside the EEA
Some technology providers may process data outside the European Economic Area, particularly in the United States. In such cases, we ensure that an appropriate legal basis for the transfer is in place as required by Chapter V of the GDPR, in particular an adequacy decision issued by the European Commission, including the EU–US Data Privacy Framework for participating organisations, or Standard Contractual Clauses together with a transfer impact assessment and supplementary measures where necessary. Information about the applicable safeguards can be obtained by contacting the Data Protection Officer.
8. Data Retention
- Account and User data – for the duration of the contract and, after its termination, until the applicable limitation period for claims has expired or any dispute has been resolved;
- accounting and tax data – for the period required by applicable law;
- Orders, payment confirmations and billing documents – for the period necessary to comply with legal obligations and defend against claims;
- correspondence and support requests – for the duration of handling the matter and subsequently until the limitation period for related claims has expired; enquiries that do not result in a contract are generally retained for no longer than 3 years;
- security logs and audit trails – for a period justified by security, auditing and accountability requirements, but no longer than necessary for those purposes;
- data processed on the basis of consent – until consent is withdrawn or the data is no longer useful for the relevant purpose, unless another legal basis exists for further retention;
- raw telemetry data – for the retention period specified by the Customer’s Plan and Project settings; after this period, it is automatically deleted;
- aggregated technical statistics that do not contain personal data – may be retained indefinitely.
After the applicable retention period expires, data is deleted or anonymised. Backups are overwritten according to their rotation cycle and, until then, remain isolated and are not used for other purposes.
9. Data Subject Rights
Subject to the conditions set out in the GDPR, data subjects have the right to:
- access their data and receive a copy of it;
- rectify inaccurate data or complete incomplete data;
- have their data erased;
- restrict processing;
- data portability where data is processed by automated means on the basis of consent or a contract;
- object to processing based on legitimate interests on grounds relating to their particular situation, and object at any time to direct marketing;
- withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
A request may be submitted to the Controller or the Data Protection Officer. We may ask for information necessary to securely verify the requester’s identity. If a request concerns data transmitted to DockRay by a Customer acting as the controller of a monitored application, we will forward the request to the relevant Customer or provide information on how to contact them.
You also have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland, uodo.gov.pl.
10. Automated Decision-Making
We do not make decisions concerning Users based solely on automated processing that produce legal effects or similarly significantly affect them. Security mechanisms may automatically assess the risk associated with a request, limit the number of attempts or require additional authentication. reCAPTCHA, where enabled, assesses the likelihood that a form is being operated automatically; if a form submission is rejected, this can be challenged by contacting us through another channel.
11. Security
We implement technical and organisational measures appropriate to the level of risk, including TLS encryption for data in transit, role-based access control, two-factor authentication, secure password hashing, encryption of selected secrets, separation of Customer data, logging of significant operations, backups, updates and infrastructure monitoring. However, no method of transmitting or storing data can guarantee absolute security.
12. Cookies and Similar Technologies
12.1. Cookies are small pieces of information stored on a user’s device. The Service may use:
- essential cookies – required to maintain sessions, enable login, protect forms, remember security settings, language and interface preferences; without them, some parts of the Service cannot function;
- analytics and functional cookies – used to measure traffic, analyse usability, remember additional preferences or provide chat functionality where the relevant tools are enabled;
- marketing cookies – used to measure campaigns or personalise communications, only where such tools have been enabled.
12.2. Essential cookies are used to provide the requested service and ensure security. Other cookies and similar identifiers may be used after obtaining consent where required by law. Consent can be withdrawn as easily as it was given. Withdrawal of consent does not affect the lawfulness of actions carried out before its withdrawal.
12.3. Cookies may be session cookies, which are deleted when the browser is closed, or persistent cookies, which are stored until the expiry date specified in their parameters or until manually deleted. If cookies other than essential cookies are enabled in the Service, a detailed list of active cookies, providers and retention periods will be made available through the consent management tool.
12.4. Users can delete and block cookies through their browser settings. Blocking essential cookies may prevent users from logging in, submitting forms or using the dashboard.
13. Third-Party Services on the Website
13.1. Registration, contact and Order forms may be protected by Google reCAPTCHA. When enabled, Google receives technical data necessary to assess whether a form is being operated by a human, including the IP address and information about the device and behaviour on the website. Google’s privacy policies also apply.
13.2. The website may use Google Tag Manager and tools enabled through it, as well as Hotjar to analyse how the website is used. These tools are optional, and their activation requires respecting the user’s cookie preferences.
13.3. During support hours, a tawk.to chat service may be available. The chat script is loaded only when chat is available; outside these hours, the button directs users to the contact form. Starting a chat results in technical data and the content of the conversation being transmitted to the provider.
13.4. Selecting login via Google, Facebook or GitHub redirects the User to the relevant provider. The provider receives information about the login attempt, while Dock receives the data specified on the authorisation screen. The User may alternatively log in using an email address and password.
14. Changes to This Policy
This Privacy Policy may be updated, in particular in the event of changes to applicable law, Service functionality, providers or processing practices. The current version is published on the Service together with its effective date. We may additionally notify Account holders of material changes by email or through a notification in the dashboard.