WebDisk Next Privacy Policy
Version: 1.0 · Effective from: 2026-07-25
The Polish version is the legally binding version. This English translation is provided for convenience only.
This Privacy Policy describes how we process the personal data of Customers of the WebDisk Next service and of persons visiting the next.webdisk.io website.
Scope of the document. The Policy concerns data for which the Provider is the controller — account data, billing data and technical operational data. Personal data which the Customer enters inside its Nextcloud instance (files, user accounts, contacts, calendars) is processed by us solely as a processor, on the Customer's instruction and on the terms set out in the Data Processing Agreement; the controller of that data is the Customer.
1. Data controller
1.1. The controller of personal data is Mazura sp. z o.o. with its registered office in Ząbki, ul. Baśniowa 1C/2, 05-091 Ząbki, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 14th Commercial Division of the National Court Register, under number KRS 0000971559, NIP 1251732787 — owner of the WebDisk brand.
1.2. Contact in personal data protection matters: iod@webdisk.io. Other matters: office@webdisk.io, tel. +48 502 049 866, correspondence address: ul. Baśniowa 1C/2, 05-091 Ząbki.
2. Scope and categories of data processed
2.1. Account data: the email address serving as the login, first name and surname or the name of the entity, authentication data stored in a form that makes it impossible to read the password.
2.2. Billing data: the invoicing name and address, the tax identification number, the history of payments and of invoices issued. We do not store payment card data — it is processed solely by the payment operator.
2.3. Technical and operational data: the IP addresses from which the connection to the panel is made, the log of operations performed on the instance (launch, stop, plan change, taking and restoring a snapshot, migration), the parameters and status of the instance, and also — if the Customer has enabled monitoring — the availability and performance metrics of the instance.
2.4. Data inside the Nextcloud instance is not covered by this Policy. We process it as a processor on the Customer's instruction — see the Data Processing Agreement.
3. Purposes and legal bases of processing
| Purpose of processing | Legal basis |
|---|---|
| Providing the Service, managing the account and the instance, handling the contract | Article 6(1)(b) GDPR — necessity for the performance of a contract |
| Billing, issuing and retaining accounting documents | Article 6(1)(c) GDPR — legal obligation (accounting and tax regulations) |
| Ensuring the security of the Service, logging operations, counteracting abuse | Article 6(1)(f) GDPR — legitimate interest consisting in the protection of the infrastructure and of Customers |
| Handling tickets, complaints and correspondence | Article 6(1)(b) and (f) GDPR |
| Establishment, exercise or defence of claims | Article 6(1)(f) GDPR |
| Monitoring of the availability and performance of the instance (optional function) | Article 6(1)(b) GDPR — at the request of the Customer who enabled the function |
4. Data recipients
4.1. Data may be made available to processors acting on our instruction, in particular: the supplier of the compute and storage infrastructure, the payment operator, the email operator and entities providing accounting and legal services. The list of categories of processors is contained in section 10 of the Next Terms.
4.2. Data may be made available to public authorities where such an obligation arises from the provisions of law.
5. Transfers of data outside the European Economic Area
5.1. We process data on infrastructure located in the territory of the Republic of Poland.
5.2. A transfer of data outside the European Economic Area may occur solely in connection with the handling of payments by the payment operator — on the basis of standard contractual clauses approved by the European Commission, constituting an appropriate safeguard within the meaning of Article 46 GDPR.
6. Data retention period
| Category of data | Retention period |
|---|---|
| Account and instance data | for the duration of the contract and the 30-day grace period after decommissioning of the instance |
| Accounting documentation (invoices, amounts, NIP) | for the period required by accounting and tax regulations — as a rule 5 years from the end of the financial year |
| Infrastructure operations log | 12 months |
| Data processed for the purpose of establishing, exercising or defending claims | until the expiry of the limitation period for claims |
7. Rights of data subjects
7.1. You have the right to: access the data (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), portability of the data (Article 20) and objection to processing based on a legitimate interest (Article 21).
7.2. Rights are exercised through the Customer panel or upon a request submitted to iod@webdisk.io.
7.3. You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) (ul. Stawki 2, 00-193 Warsaw).
7.4. Requests concerning data located inside the Nextcloud instance should be directed to the Customer, which is the controller of that data and has the tools to fulfil them. The Provider supports the Customer in fulfilling such requests on the terms set out in the Data Processing Agreement.
7.5. The provision of data is voluntary, but necessary for the conclusion and performance of the contract and for the issuance of accounting documents.
8. Cookies
8.1. The next.webdisk.io website uses cookies necessary for its proper operation, in particular for maintaining the session and for authentication. Their use does not require consent.
8.2. Other cookies, including analytical and marketing cookies, are used solely after consent has been given via the consent management mechanism available on the website. Consent may be withdrawn at any time in the settings of that mechanism.
8.3. Detailed information is contained in the Cookie Policy.
9. Data security
9.1. We apply technical and organisational measures corresponding to the risk, referred to in Article 32 GDPR, in particular:
- encryption of connections with the TLS protocol,
- access control to the infrastructure, including administrative access solely through a dedicated jump host with cryptographic key authentication,
- isolation of individual Customers' instances at the level of separate virtual machines,
- separation of the production, test and development environments,
- logging of administrative operations and security monitoring of the infrastructure,
- regular security updates and periodic security testing.
9.2. A detailed list of the technical and organisational measures applied to the entrusted data is contained in §5 of the Data Processing Agreement.
10. Automated decision-making
The data is not used for automated decision-making producing legal effects or similarly significantly affecting the data subject, including profiling.
11. Amendments to the Privacy Policy
11.1. The Policy may be updated. The version and the date of effect are indicated at the beginning of the document. We inform about material amendments by email or in the Customer panel 30 days in advance.
11.2. In the event of discrepancies between the Polish and the English version of the Policy, the Polish version is binding.
Mazura sp. z o.o. · WebDisk Next · Privacy Policy · version 1.0 · effective from 2026-07-25