WebDisk VM Privacy Policy
Version: 1.0 · Effective from: 2026-07-25
The Polish version is the legally binding version. This English translation is provided for convenience only.
This Privacy Policy describes how we process the personal data of Customers of the WebDisk VM service and of persons visiting the vm.webdisk.io website.
Scope of the document. The Policy concerns solely data for which the Provider is the controller — account data, billing data and technical operational data of the virtual server. The Policy does not cover data which the Customer independently enters, stores or processes on its virtual server. The Customer has exclusive administrative access to the server, and the Provider does not obtain insight into that data. The rules concerning that data and the allocation of roles between the parties are set out in the document Personal Data Processing Rules for the WebDisk VM Service.
1. Data controller
1.1. The controller of personal data is Mazura sp. z o.o. with its registered office in Ząbki, ul. Baśniowa 1C/2, 05-091 Ząbki, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under number KRS 0000971559, NIP 1251732787 — owner of the WebDisk brand.
1.2. Contact in personal data protection matters: iod@webdisk.io. Other matters: office@webdisk.io, tel. +48 502 049 866, correspondence address: ul. Baśniowa 1C/2, 05-091 Ząbki.
2. Scope and categories of data processed
2.1. Account data: the email address serving as the login, first name and surname or the name of the entity, authentication data stored in a form that makes it impossible to read the password.
2.2. Billing data: the invoicing name and address, the tax identification number, the history of payments and of invoices issued. We do not store payment card data — it is processed solely by the payment operator.
2.3. Technical and operational data: the allocated public IP address and the PTR record, the IP addresses from which the connection to the panel is made, the log of operations performed on the server via the panel (launch, restart, restore from an image, taking and restoring a snapshot, change of resources, migration), and also the status and parameters of the server.
2.4. What we do not process as a controller. The content and data stored and processed inside the operating system of the Customer's virtual server. In the course of ongoing operations the Provider does not obtain access to it (see the VM Terms, clause 3.3).
3. Purposes and legal bases of processing
| Purpose of processing | Legal basis |
|---|---|
| Providing the Service, managing the account and the server, handling the contract | Article 6(1)(b) GDPR — necessity for the performance of a contract |
| Billing, issuing and retaining accounting documents | Article 6(1)(c) GDPR — legal obligation (accounting and tax regulations) |
| Ensuring the security of the infrastructure, handling abuse reports, protecting the network and other Customers | Article 6(1)(f) GDPR — legitimate interest |
| Handling tickets, complaints and correspondence | Article 6(1)(b) and (f) GDPR |
| Establishment, exercise or defence of claims | Article 6(1)(f) GDPR |
4. Data recipients
4.1. Data may be made available to processors acting on our instruction, in particular: the supplier of the compute and storage infrastructure, the payment operator, the email operator and entities providing accounting and legal services. The list of categories of processors is contained in section 10 of the VM Terms.
4.2. Data may be made available to public authorities where such an obligation arises from the provisions of law. To the extent technically possible and required by law, a request from an authority may also cover the release of a disk image or a snapshot of the server. We inform the Customer about a request if the law permits it.
5. Transfers of data outside the European Economic Area
5.1. We process data on infrastructure located in the territory of the Republic of Poland.
5.2. A transfer of data outside the European Economic Area may occur solely in connection with the handling of payments by the payment operator — on the basis of standard contractual clauses approved by the European Commission (Article 46 GDPR).
5.3. Data transfers carried out by workloads run by the Customer on its server remain outside the scope of this Policy and the Customer is responsible for them.
6. Data retention period
| Category of data | Retention period |
|---|---|
| Account and server data | for the duration of the contract and the 30-day grace period after decommissioning of the server |
| Accounting documentation (invoices, amounts, NIP) | for the period required by accounting and tax regulations — as a rule 5 years from the end of the financial year |
| Infrastructure operations log | 12 months |
| Data processed for the purpose of establishing, exercising or defending claims | until the expiry of the limitation period for claims |
7. Rights of data subjects
7.1. You have the right to: access the data (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), portability of the data (Article 20) and objection to processing based on a legitimate interest (Article 21).
7.2. Rights are exercised through the Customer panel or upon a request submitted to iod@webdisk.io.
7.3. You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) (ul. Stawki 2, 00-193 Warsaw).
7.4. Requests concerning data processed by the Customer inside the virtual server should be directed to the Customer directly. The Provider has no access to that data and is not able to fulfil such requests.
7.5. The provision of data is voluntary, but necessary for the conclusion and performance of the contract and for the issuance of accounting documents.
8. Cookies
8.1. The vm.webdisk.io website uses cookies necessary for its proper operation, in particular for maintaining the session and for authentication. Their use does not require consent.
8.2. Other cookies, including analytical and marketing cookies, are used solely after consent has been given via the consent management mechanism available on the website. Consent may be withdrawn at any time in the settings of that mechanism.
8.3. Detailed information is contained in the Cookie Policy.
9. Data security
9.1. We apply technical and organisational measures corresponding to the risk, referred to in Article 32 GDPR — at the infrastructure layer, in particular:
- encryption of connections with the TLS protocol for the Customer panel,
- access control to the infrastructure, including administrative access solely through a dedicated jump host with cryptographic key authentication,
- isolation of individual Customers' servers at the level of the virtualisation layer,
- separation of the production, test and development environments,
- logging of administrative operations and security monitoring of the infrastructure,
- regular security updates and periodic security testing.
9.2. Security inside the virtual server — the operating system, the software, the configuration and the data — is ensured by the Customer (VM Terms, clause 3.2).
9.3. The data carriers of the virtual servers and the snapshots are not currently encrypted at rest on the Provider's side. A Customer processing data requiring encryption at rest should apply encryption on its own (VM Terms, clause 3.4).
10. Automated decision-making
The data is not used for automated decision-making producing legal effects or similarly significantly affecting the data subject, including profiling.
11. Amendments to the Privacy Policy
11.1. The Policy may be updated. The version and the date of effect are indicated at the beginning of the document. We inform about material amendments by email or in the Customer panel 30 days in advance.
11.2. In the event of discrepancies between the Polish and the English version of the Policy, the Polish version is binding.
Mazura sp. z o.o. · WebDisk VM · Privacy Policy · version 1.0 · effective from 2026-07-25
Version 1.0 · EN