This is an informational translation. The legally binding Polish version of this document is here. Using AdActa requires acceptance of the Polish documents: Privacy policy, Terms of Service, and Security.
Effective from July 13, 2026
Security
Below we describe our security approach factually. We do not claim certifications or attestations we do not hold.
1. Account and data protection in the product
We apply common web-application technical and organisational measures proportionate to risk, including:
- encryption between your browser and the service (HTTPS/TLS);
- authentication mechanisms, including optional passkeys (WebAuthn) where enabled on your account;
- access control within accounts and user data isolation as implemented in the product;
- logging of security-relevant events within the scope provided by the system.
2. Legal compliance — not a marketing badge
GDPR and Polish data protection law are legal obligations — not a purchasable “product certificate”. We do not state possession of certifications (e.g. SOC 2, ISO 27001) unless they are actually maintained.
- Personal data processing details are in the Privacy policy.
- Service terms are in the Terms of Service.
- This page does not replace external audits or SLA guarantees unless agreed separately.
3. Infrastructure and suppliers
The Service runs in the cloud with subcontractors (hosting, database, email, payments, AI). Continuity, backups, and monitoring depend on architecture and supplier contracts — we do not publicly promise a specific SLA or “24/7 monitoring” unless your contract says so.
- software updates and vulnerability remediation in the product lifecycle.
- backups and recovery — within the scope implemented by infrastructure and product configuration.
- protection against common network attacks — within supplier and service capabilities.
- specific supplier details may be shared with B2B partners on request where security is not compromised.
4. Reporting vulnerabilities
To report a vulnerability or security incident, email contact@adacta.digital with “security” in the subject. Please describe the issue without exploiting production. We review reports within a reasonable time. There is no public bug bounty programme unless separately agreed in writing.