Legal
Privacy policy
This is the plain version of what we do with personal data, and it is also the complete version — there is no second policy behind it. We are based in the EU, we store data in the EU, we never keep a raw IP address, and we sell nothing to anyone.
Last updated
This document is not finished yet
The company behind SoftSelect has not been registered yet, so the details this document depends on are still shown as placeholders. They are filled in as soon as the entity exists, and until then this page is kept out of search results.
Still to fill in
{{CONTACT_EMAIL}}{{DPO_EMAIL}}{{LEGAL_ENTITY_ADDRESS}}{{LEGAL_ENTITY_COUNTRY}}{{LEGAL_ENTITY_FORM}}{{LEGAL_ENTITY_NAME}}{{SUPERVISORY_AUTHORITY}}
In short
- We collect what an account, a review and a verification actually need. Not more.
- Reviews are public by design. Everything behind them is not.
- Your IP address is hashed the moment it reaches us and is never stored raw.
- LinkedIn data is used to verify who you are, and for nothing else.
- No advertising trackers, no data sold, and no analytics until you say yes.
01
Who is responsible for your data
The controller of the personal data described here, in the sense of Article 4(7) of the GDPR — RODO in Polish — is:
- Controller
- {{LEGAL_ENTITY_NAME}} {{LEGAL_ENTITY_FORM}}
- Address
- {{LEGAL_ENTITY_ADDRESS}}, {{LEGAL_ENTITY_COUNTRY}}
- Data protection contact
- {{DPO_EMAIL}}
- General contact
- {{CONTACT_EMAIL}}
Write to the data protection address about anything in this document. You will get an answer from a person, within a month at the very latest and usually far sooner.
02
What this covers
This policy covers the SoftSelect website, the accounts on it, the reviews published through it, and the dashboards vendors use to manage their listings.
It does not cover the vendors themselves. When you click through to a vendor’s own site you are on their site, under their policy, and what happens there is outside our control.
03
What we collect
- Account data
- Your name, email address, password (stored only as a hash that cannot be reversed), job title, employer, and the language you read the site in.
- Review content
- Everything you write in a review, plus the ratings, the use case, the company size and the industry you select. This part is published.
- Verification data
- Whether your email was confirmed, what LinkedIn told us when you signed in, the outcome of the role match, and the evidence behind a moderation decision.
- Vendor data
- For vendor accounts: the organisation, its members, the profile content they publish and the responses they write.
- Technical data
- Browser and device type, the pages you request, and a salted hash of your IP address. Never the address itself.
- Usage data
- Which pages and products are viewed and compared, in aggregate, and only after you have accepted analytics.
- Messages
- Support requests, complaints, reports about a review and legal notices, together with whatever you put in them.
- Payment data
- Only once vendor billing goes live. Payments run through Stripe, and card numbers never reach our servers.
04
Why we use it, and what allows us to
Every purpose below names its legal basis under Article 6 of the GDPR and the period we keep the data for.
| What we do | Legal basis | How long we keep it |
|---|---|---|
| Run your account and sign you in | Performance of a contract, Art. 6(1)(b) | Until you delete the account |
| Publish your review with its verification badge | Contract and legitimate interest in an honest catalogue, Art. 6(1)(b) and (f) | As long as the review is published; deleted with it |
| Verify who you are — email, LinkedIn, role match | Contract and legitimate interest in preventing fake reviews, Art. 6(1)(b) and (f) | Evidence deleted after 24 months |
| Detect fraud and abuse — hashed IP, network reputation, rate limits | Legitimate interest, Art. 6(1)(f) | 24 months |
| Send transactional email — verification, moderation outcomes, vendor replies | Contract, Art. 6(1)(b) | Delivery logs for 30 days |
| Measure how the site is used | Consent, Art. 6(1)(a) | Raw events 90 days, then aggregated with no identifier |
| Send a newsletter or product updates | Consent, Art. 6(1)(a) | Until you unsubscribe |
| Answer support requests, complaints and legal notices | Legitimate interest, and legal obligation where one applies, Art. 6(1)(f) and (c) | Until the related claim period ends |
| Bill vendor subscriptions | Contract and legal obligation, Art. 6(1)(b) and (c) | As long as tax law requires |
Where we rely on a legitimate interest, we have weighed it against your interests and written the assessment down. Ask, and we will show you the reasoning for the case that concerns you.
05
Reviews are public
A review is published with your name or your initials, your job title, your employer, your verification badge and the date. That is the deal a review site runs on, and it is the part buyers rely on.
Everything else — your email address, the hash of your IP, your LinkedIn data, your moderation history — is never published, never shown to the vendor and never sold.
06
LinkedIn and identity verification
If you choose to verify with LinkedIn, we receive the identity LinkedIn confirms and, where you grant it, your current position. We use it to decide the verification badge on your review, and for nothing else: not for marketing, not for the vendor, and not combined with data bought from a third party, because we do not buy data.
The evidence behind a verification is kept for 24 months and then deleted. You can unlink LinkedIn whenever you like.
07
IP addresses
Hashed on arrival, never stored raw
An IP address identifies a person under the GDPR, so we do not keep one. Each address is hashed with a secret salt that rotates on a schedule, and only the hash is stored, for 24 months. It lets us notice two reviews arriving from one network; it cannot be reversed into an address, and rotating the salt means old hashes stop being comparable to new ones by design.
Our hosting provider processes IP addresses in transit in order to route requests and block attacks, as any provider must. Those logs are theirs, they are short-lived, and they are covered by our data processing agreement with them.
09
Analytics
We measure how the site is used through our hosting provider’s own analytics, which records events at the edge and rolls them up nightly into counts. Raw events are deleted after 90 days; what survives is aggregate numbers with no identifier in them.
Vendors see statistics about their own listing — views, comparisons, outbound clicks. They never see who you are.
11
Where your data is
The database sits in the European Union, and we pick EU regions wherever a provider offers one. Some providers are established outside the EU or run a global network; where personal data reaches them, the transfer runs on the European Commission’s standard contractual clauses or on an adequacy decision, with the additional measures those require.
The current list of processors and the countries involved is available from {{DPO_EMAIL}} on request.
12
Automated decisions
Two things happen without a human. A review written by an employee of the vendor is rejected automatically, and fraud signals decide how urgently a review is looked at. Neither produces a legal effect on you in the sense of Article 22 of the GDPR, but you should know they exist.
If an automatic rejection is wrong, write to us and a person will look at it. That right exists here whether or not Article 22 applies.
13
Your rights
Under the GDPR, and RODO in Poland, you can:
- Ask what we hold about you and get a copy of it (Art. 15).
- Have anything inaccurate corrected (Art. 16).
- Have your data erased (Art. 17). Published reviews are included: delete them, or keep them published with your name removed.
- Restrict how we use it while a dispute is open (Art. 18).
- Take it with you in a machine-readable file (Art. 20).
- Object to processing we base on a legitimate interest (Art. 21).
- Withdraw a consent at any time, without affecting what was done before you withdrew it (Art. 7(3)).
Write to {{DPO_EMAIL}}. We answer within one month and we do not charge for it. If we ever refuse a request we say why, and you can take that refusal to a supervisory authority.
You can complain to the data protection authority where you live or work. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa. The lead authority for us is {{SUPERVISORY_AUTHORITY}}.
14
How we protect it
- Everything is served over HTTPS. Nothing on the site works without it.
- Passwords are hashed with a modern algorithm. Nobody here can read yours.
- Access to production data is limited to the people who need it, and administrative actions are logged.
- The database lives in the EU, with encrypted backups.
- If a breach ever puts you at risk, we tell you and the supervisory authority within the deadlines the GDPR sets.
15
Not a service for children
SoftSelect is a tool for people evaluating software at work. It is not directed at children, and we do not knowingly create accounts for anyone under 16. If you believe a child holds an account, tell us and we will remove it.
16
Changes to this policy
The date at the top is the version. When something material changes — a new purpose, a new processor, a longer retention period — we say so on the site before it takes effect, and we email account holders where the change affects them.