Skip to content
SoftSelect

Legal

Privacy policy

This is the plain version of what we do with personal data, and it is also the complete version — there is no second policy behind it. We are based in the EU, we store data in the EU, we never keep a raw IP address, and we sell nothing to anyone.

Last updated

Draft

The company behind SoftSelect has not been registered yet, so the details this document depends on are still shown as placeholders. They are filled in as soon as the entity exists, and until then this page is kept out of search results.

Still to fill in

  • {{CONTACT_EMAIL}}
  • {{DPO_EMAIL}}
  • {{LEGAL_ENTITY_ADDRESS}}
  • {{LEGAL_ENTITY_COUNTRY}}
  • {{LEGAL_ENTITY_FORM}}
  • {{LEGAL_ENTITY_NAME}}
  • {{SUPERVISORY_AUTHORITY}}

In short

  • We collect what an account, a review and a verification actually need. Not more.
  • Reviews are public by design. Everything behind them is not.
  • Your IP address is hashed the moment it reaches us and is never stored raw.
  • LinkedIn data is used to verify who you are, and for nothing else.
  • No advertising trackers, no data sold, and no analytics until you say yes.

01

Who is responsible for your data

The controller of the personal data described here, in the sense of Article 4(7) of the GDPR — RODO in Polish — is:

Controller
{{LEGAL_ENTITY_NAME}} {{LEGAL_ENTITY_FORM}}
Address
{{LEGAL_ENTITY_ADDRESS}}, {{LEGAL_ENTITY_COUNTRY}}
Data protection contact
{{DPO_EMAIL}}
General contact
{{CONTACT_EMAIL}}

Write to the data protection address about anything in this document. You will get an answer from a person, within a month at the very latest and usually far sooner.

02

What this covers

This policy covers the SoftSelect website, the accounts on it, the reviews published through it, and the dashboards vendors use to manage their listings.

It does not cover the vendors themselves. When you click through to a vendor’s own site you are on their site, under their policy, and what happens there is outside our control.

03

What we collect

Account data
Your name, email address, password (stored only as a hash that cannot be reversed), job title, employer, and the language you read the site in.
Review content
Everything you write in a review, plus the ratings, the use case, the company size and the industry you select. This part is published.
Verification data
Whether your email was confirmed, what LinkedIn told us when you signed in, the outcome of the role match, and the evidence behind a moderation decision.
Vendor data
For vendor accounts: the organisation, its members, the profile content they publish and the responses they write.
Technical data
Browser and device type, the pages you request, and a salted hash of your IP address. Never the address itself.
Usage data
Which pages and products are viewed and compared, in aggregate, and only after you have accepted analytics.
Messages
Support requests, complaints, reports about a review and legal notices, together with whatever you put in them.
Payment data
Only once vendor billing goes live. Payments run through Stripe, and card numbers never reach our servers.

04

Why we use it, and what allows us to

Every purpose below names its legal basis under Article 6 of the GDPR and the period we keep the data for.

What we doLegal basisHow long we keep it
Run your account and sign you inPerformance of a contract, Art. 6(1)(b)Until you delete the account
Publish your review with its verification badgeContract and legitimate interest in an honest catalogue, Art. 6(1)(b) and (f)As long as the review is published; deleted with it
Verify who you are — email, LinkedIn, role matchContract and legitimate interest in preventing fake reviews, Art. 6(1)(b) and (f)Evidence deleted after 24 months
Detect fraud and abuse — hashed IP, network reputation, rate limitsLegitimate interest, Art. 6(1)(f)24 months
Send transactional email — verification, moderation outcomes, vendor repliesContract, Art. 6(1)(b)Delivery logs for 30 days
Measure how the site is usedConsent, Art. 6(1)(a)Raw events 90 days, then aggregated with no identifier
Send a newsletter or product updatesConsent, Art. 6(1)(a)Until you unsubscribe
Answer support requests, complaints and legal noticesLegitimate interest, and legal obligation where one applies, Art. 6(1)(f) and (c)Until the related claim period ends
Bill vendor subscriptionsContract and legal obligation, Art. 6(1)(b) and (c)As long as tax law requires

Where we rely on a legitimate interest, we have weighed it against your interests and written the assessment down. Ask, and we will show you the reasoning for the case that concerns you.

05

Reviews are public

A review is published with your name or your initials, your job title, your employer, your verification badge and the date. That is the deal a review site runs on, and it is the part buyers rely on.

Everything else — your email address, the hash of your IP, your LinkedIn data, your moderation history — is never published, never shown to the vendor and never sold.

06

LinkedIn and identity verification

If you choose to verify with LinkedIn, we receive the identity LinkedIn confirms and, where you grant it, your current position. We use it to decide the verification badge on your review, and for nothing else: not for marketing, not for the vendor, and not combined with data bought from a third party, because we do not buy data.

The evidence behind a verification is kept for 24 months and then deleted. You can unlink LinkedIn whenever you like.

07

IP addresses

Hashed on arrival, never stored raw

An IP address identifies a person under the GDPR, so we do not keep one. Each address is hashed with a secret salt that rotates on a schedule, and only the hash is stored, for 24 months. It lets us notice two reviews arriving from one network; it cannot be reversed into an address, and rotating the salt means old hashes stop being comparable to new ones by design.

Our hosting provider processes IP addresses in transit in order to route requests and block attacks, as any provider must. Those logs are theirs, they are short-lived, and they are covered by our data processing agreement with them.

08

Cookies and consent

No non-essential script runs before you agree to it. There is no advertising cookie on this site at all.

  • A session cookie, so you stay signed in.
  • A CSRF token, so a form you submit really came from you.
  • A record of your cookie choice, so we stop asking.
  • A bot-protection cookie on pages with a form, to tell a person from a script.
  • Analytics cookies, and only after you say yes.
  • No advertising cookies, no cross-site tracking pixels, and nothing sold to a data broker.

You can change your mind at any time. The new choice is stored the same way, and it applies from the moment you make it.

09

Analytics

We measure how the site is used through our hosting provider’s own analytics, which records events at the edge and rolls them up nightly into counts. Raw events are deleted after 90 days; what survives is aggregate numbers with no identifier in them.

Vendors see statistics about their own listing — views, comparisons, outbound clicks. They never see who you are.

10

Who else touches your data

A small number of processors, each under a data processing agreement, each doing exactly one job:

ProcessorWhat it handles
CloudflareHosting, content delivery, bot protection and the anti-abuse checks on the review form
NeonThe main database — accounts, reviews, the catalogue
ResendTransactional email: verification links, moderation outcomes, notifications
SentryError reports when something breaks
StripeVendor payments, once billing goes live. We never see a card number.
LinkedIn and GoogleSign-in and identity verification, only if you choose them

We do not sell personal data, we share nothing with advertising networks, and we have no data broker relationships of any kind. We disclose data to an authority only where a law requires it, and we log it when we do.

11

Where your data is

The database sits in the European Union, and we pick EU regions wherever a provider offers one. Some providers are established outside the EU or run a global network; where personal data reaches them, the transfer runs on the European Commission’s standard contractual clauses or on an adequacy decision, with the additional measures those require.

The current list of processors and the countries involved is available from {{DPO_EMAIL}} on request.

12

Automated decisions

Two things happen without a human. A review written by an employee of the vendor is rejected automatically, and fraud signals decide how urgently a review is looked at. Neither produces a legal effect on you in the sense of Article 22 of the GDPR, but you should know they exist.

If an automatic rejection is wrong, write to us and a person will look at it. That right exists here whether or not Article 22 applies.

13

Your rights

Under the GDPR, and RODO in Poland, you can:

  • Ask what we hold about you and get a copy of it (Art. 15).
  • Have anything inaccurate corrected (Art. 16).
  • Have your data erased (Art. 17). Published reviews are included: delete them, or keep them published with your name removed.
  • Restrict how we use it while a dispute is open (Art. 18).
  • Take it with you in a machine-readable file (Art. 20).
  • Object to processing we base on a legitimate interest (Art. 21).
  • Withdraw a consent at any time, without affecting what was done before you withdrew it (Art. 7(3)).

Write to {{DPO_EMAIL}}. We answer within one month and we do not charge for it. If we ever refuse a request we say why, and you can take that refusal to a supervisory authority.

You can complain to the data protection authority where you live or work. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa. The lead authority for us is {{SUPERVISORY_AUTHORITY}}.

14

How we protect it

  • Everything is served over HTTPS. Nothing on the site works without it.
  • Passwords are hashed with a modern algorithm. Nobody here can read yours.
  • Access to production data is limited to the people who need it, and administrative actions are logged.
  • The database lives in the EU, with encrypted backups.
  • If a breach ever puts you at risk, we tell you and the supervisory authority within the deadlines the GDPR sets.

15

Not a service for children

SoftSelect is a tool for people evaluating software at work. It is not directed at children, and we do not knowingly create accounts for anyone under 16. If you believe a child holds an account, tell us and we will remove it.

16

Changes to this policy

The date at the top is the version. When something material changes — a new purpose, a new processor, a longer retention period — we say so on the site before it takes effect, and we email account holders where the change affects them.

The rest of the small print