Privacy Policy

GoUpTower - Privacy Policy

Privacy Policy

Data Protection Contact: gdpr@gouptower.com
General Support: support@gouptower.com

SECTION 1. DATA CONTROLLER IDENTIFICATION

1.1. The Data Controller for personal data processed on the GoUpTower Platform is Aleksander Chomiński, conducting unregistered business activity (działalność nierejestrowana) in Poland (hereinafter: "Controller").

1.2. For matters relating to personal data processing, data deletion, or exercising GDPR rights, contact the Controller at: gdpr@gouptower.com.

SECTION 2. SCOPE & CATEGORIES OF DATA COLLECTED
Data Category Collected Data Fields Collection Source
Account Identifiers First Name, Last Name, Email, Password Hash, Google OAuth ID. User registration & SSO.
Career & Qualification Profile GWO WINDA ID, GWO modules, OEM training, Medical certs, Expiration dates, turbine platforms, years of industry experience, list of projects, and custom certificate names. Voluntary input in Dashboard.
Rotation & Location Data Calendar inputs including planned rotation dates, days on project, home/vacation days, and geographical locations (city/country). Voluntary input in "My Rotation Plan".
Training Provider Directory Data Facility Name, Business Address, Contact Details, Offered GWO/OEM Modules. Publicly available sources (company websites, public business registries).
CV Builder Data Professional headline, personal summary, phone number, city, country, LinkedIn address, spoken languages, education history, manually added work experience, chosen CV style, and every named CV document you save as a draft. Project history is assembled from entries you made in "My Rotation Plan". In the App you may start a CV before signing in: that draft stays on your device until you save it to your Account, and PDFs made in the App are generated on the device. Voluntary input in CV Builder, plus data you already entered in Profile Details, My Certificates and My Rotation Plan.
Virtual CV Sharing A randomly generated share token, an on/off sharing flag, and which of your saved CVs is currently shared. Created only when you switch sharing on.
Device & Notifications (App) Apple Push token for the device, which push environment it belongs to, the device model name shown against your sign-ins, and your on/off choices for job offers and platform updates. Created when you allow notifications.
Location & Wind (App) Your device's position rounded to roughly one kilometre, the name of the nearest town, the wind limit you set, and the state of your high-wind alert. The full-precision position is used on the device and is not stored on the server. When you sign out, the stored position is deleted; your alert switch and limit stay on the phone so alerts can resume at your next sign-in. Only while you allow location; the stored copy only if high-wind alerts are on.
Travel & Reminders (App) Whether you have ticked "I fly to work", so the day-before reminder can mention flight check-in. Voluntary switch in the App.
Sign in with Apple (App) The identifier Apple issues for you, a token that lets the Controller revoke that sign-in when you delete your Account, and the email address Apple passes on — which may be one of Apple's private relay addresses if you chose to hide your real one. Only if you sign in with Apple.
Referral Programme Your invitation code, who invited you, who joined on your link and whether their points have been credited, your points balance, and what you have redeemed. Created when you or someone else uses an invitation link.
Notices under the bell The notices addressed to you, when you last read them, and which ones you deleted. Notices sent to everyone are shown to you only from the day your Account was created. Automated system logging.
Emergency tools (App) Defibrillator map: your device's position rounded to roughly one kilometre, sent to the Controller's server, which asks the OpenStreetMap database for defibrillators nearby. The position is not linked to your Account, not stored and not logged; only the search results, which contain no personal data, are kept for up to 24 hours. Hospital map: searched by Apple Maps directly from your device; nothing is sent to the Controller. Call 112 and "Share my location": handled by your phone and sent only to the number you call or the person or app you choose; the Controller receives nothing. Only when you open an Emergency map and allow location.
Kept on your device only (App) Your packing checklist; rotation events you export to the iPhone's Calendar; CV drafts you have not saved to your Account and the PDFs you create in the App; your Safety Book progress; the offline copy of the Education Hub; the last emergency map results; the layout of your Home widgets and your light or dark appearance choice. None of these is stored by the Controller. The Controller never reads your calendar; the App asks only for permission to add events to it. Stays on the device.
Usage & View Logging Which job offers your account opened and when (used to meter the weekly allowance and to make re-reading an offer free), apply click statistics, and whether you completed or skipped the introductory walk-through. Automated system logging.
Billing & Financials Subscription Plan ID, transaction IDs (Stripe Payments Europe Limited), and for purchases made in the App: the App Store transaction and original transaction identifiers, the product bought, its renewal and expiry dates, and an anonymous token tying the purchase to your Account. No card details reach the Controller by either route. Payment gateway integration; Apple's App Store server notifications.
SECTION 3. LEGAL BASES & PURPOSES (GDPR ART. 6)
Purpose GDPR Legal Basis Retention Period
Service delivery, Account management & Offer viewing Art. 6(1)(b) (Contract execution) Duration of active account.
Internal Statistical Analysis
Processing aggregated length of experience, platform types, project history, and rotation trends to improve services. Data is strictly internal and never sold or shared.
Art. 6(1)(f)
(Legitimate interest)
Duration of active account or until data is fully anonymized.
Public Training Center Directory Display
Displaying certified training facilities on the interactive map for user convenience (Art. 14 GDPR - data obtained from public sources).
Art. 6(1)(f)
(Legitimate interest)
Until an objection is raised or data is updated at source.
CV creation, storage and export
Building, saving and exporting CV documents from data you have entered.
Art. 6(1)(b)
(Contract execution)
Until you delete the CV, or until the account is deleted.
Publishing a Virtual CV
Making a CV readable by anyone holding the share link. See Section 6.
Art. 6(1)(a)
(Consent — you switch sharing on)
Until you switch sharing off, delete the CV, or delete the account.
Health data in certificates
Medical fitness certificates and their expiry dates are data concerning health. You are never required to enter them, and you may record only an expiry date without naming the condition or examination.
Art. 9(2)(a)
(Explicit consent), on top of Art. 6(1)(b)
Until you delete the entry or the account. Withdrawing consent means deleting the entry.
Offer view logging
Recording which offers you opened so the weekly allowance can be counted and so re-reading an offer you already opened does not cost a second view.
Art. 6(1)(b)
(Contract execution)
30 days, then automatically deleted. Only the last 7 days ever affect your allowance.
Service and onboarding emails
Occasional manually sent messages: a reminder to finish the introductory walk-through, or a reminder that a started upgrade was never completed. These are not newsletters and there is no automated campaign.
Art. 6(1)(f)
(Legitimate interest)
Duration of active account. You may object at any time — see Section 8.
Wind readings and high-wind alerts (App)
Reading the wind where your device is, and checking it periodically on the server so an alert can be sent while the App is closed.
Art. 6(1)(a)
(Consent — you allow location, and switch alerts on)
The stored position is replaced each time it is refreshed and deleted when you switch alerts off, sign out, or delete the account.
Push notifications (App)
Sending new job offers, platform announcements, referral points, and the reminder the day before a rotation starts or ends.
Art. 6(1)(a)
(Consent — the iOS permission and the switches in the App)
The device token is kept until you sign out, turn notifications off, or Apple reports it as dead. Notices are deleted after 120 days.
In-App Purchases (App)
Verifying with Apple that a subscription bought in the App is genuine, and keeping it in step when it renews, lapses or is refunded.
Art. 6(1)(b) (Contract) and Art. 6(1)(c) (Accounting) Duration of the subscription; accounting records 5 years from the end of the fiscal year.
Referral programme
Recording who invited whom, crediting points once both profiles are complete, and guarding against self-referral.
Art. 6(1)(b)
(Contract execution)
Until either account is deleted.
Apply-click counting
Counting how many people went on to apply for an offer. For guests this uses a one-way daily hash of IP address and browser, which cannot be turned back into either.
Art. 6(1)(f)
(Legitimate interest)
60 days, then automatically deleted.
Defibrillator map (App)
Finding defibrillators near you. The App sends a position rounded to about a kilometre to the Controller's server, which queries OpenStreetMap on your behalf, so the map service never learns who is asking.
Art. 6(1)(a)
(Consent — you allow location and open the map)
The position is used for that single search and not stored. Results, which contain no personal data, are cached per map area for up to 24 hours.
Social media links
Showing links to GoUpTower's own pages on social networks. Nothing is sent to those networks until you tap a link.
Art. 6(1)(f)
(Legitimate interest)
No personal data is processed by showing the links.
Automated Certificate Expiration Reminders Art. 6(1)(b) (Contract execution) Active subscription duration.
Payment processing & Accounting compliance Art. 6(1)(c) (Legal obligation) 5 years from end of fiscal year.
SECTION 4. SUB-PROCESSORS & THIRD-PARTY RECIPIENTS

4.1. Data is transferred only to trusted sub-processors under formal Data Processing Agreements (DPAs):

  • Hosting Provider: SEOHOST Sp. z o.o., ul. Obornicka 330, 60-689 Poznań, VAT: PL9721323212
  • Payment Gateway: Stripe Payments Europe Limited (SPEL), The One Building, 1 Lower Grand Canal Street, Dublin 2, Ireland — card and bank transfer processing. Card details are entered on Stripe's hosted checkout and are never received or stored by the Controller.
  • Google Ireland Limited: "Sign in with Google" (OAuth) for users who choose it, and Google Ads conversion measurement (see Section 7).
  • OpenStreetMap Foundation: Map tile rendering for training centers.
  • Overpass API (overpass-api.de, Germany): the public service that answers searches of OpenStreetMap data. It is used only for the defibrillator map in the App, and only by the Controller's server: it receives a position rounded to about one kilometre, never your IP address, your device or your identity.
  • Apple Distribution International Ltd. (Hollyhill Industrial Estate, Cork, Ireland) and Apple Inc. — for the App only: distribution through the App Store and TestFlight, billing of In-App Purchases, delivery of push notifications through the Apple Push Notification service, the wind readings shown in the App (Apple Weather / WeatherKit), "Sign in with Apple" for users who choose it, and the nearby-hospital search on the App's Emergency screen, which Apple Maps performs from your device. Apple acts as an independent controller for its own purposes in respect of App Store transactions and account data; its privacy policy governs those.

4.2. Content delivery networks. Some page assets (scripts, icons and webfonts) are loaded from third-party networks. Doing so discloses your IP address and browser details to them, which is technically unavoidable when a browser fetches a file:

  • Cloudflare, Inc. (cdnjs): JavaScript libraries, including the QR code generator.
  • Google Ireland Limited (Google Fonts): Webfonts.
  • unpkg / Cloudflare: A script used on the home page.

4.2a. Social media links. The App and the website may link to GoUpTower's pages on Instagram, Facebook, LinkedIn, TikTok, YouTube or X. Nothing is shared with those platforms until you tap a link; from then on you are on their service, and their privacy policy applies.

4.3. Recipients of a shared Virtual CV. If you switch on Virtual CV sharing, the recipients of that data are anyone who holds the link, including people you did not give it to directly. This is the intended purpose of the feature. See Section 6.

4.4. No sale of data. Personal data is never sold, rented, or supplied to advertisers, recruiters or data brokers.

SECTION 5. SECURITY

5.1. All database storage is encrypted at rest and in transit via TLS 1.3. Passwords are stored only as salted hashes and are never readable by the Controller.

5.2. Applications sent to employers. When you click an external apply link you leave the Platform. The Controller does not collect, receive, store or process the application you then submit to that employer, nor any CV file you upload on their system. What happens on the employer's site is governed by the employer's own privacy policy.

5.3. CV documents created on the Platform. Separately from the above, the Platform does store the CVs you build here, because that is what CV Builder is for. Those documents live in your account, are visible only to you, and are never sent to an employer by the Controller. They are described in Section 2 and Section 6.

SECTION 6. CV BUILDER & THE VIRTUAL CV SHARE LINK

6.1. What CV Builder does. It assembles a CV from data already in your account — profile details, certificates, and the project history recorded in "My Rotation Plan" — and lets you fill any gaps by hand. You may save any number of named drafts. Nothing is published anywhere by default.

6.2. Exports. Generating a PDF creates a file in your browser, or, in the App, on your device — the App builds the PDF itself and does not send it to the Controller. Once you download, email, share or print that file, it is outside the Controller's control.

6.3. The Virtual CV is a public link. If you switch sharing on, the Platform creates a long random address of the form gouptower.com/profile.php?t=…. Anyone who has that address can open your CV and download your contact details as a vCard, without logging in and without your further knowledge. Treat it as publishing, not as sending.

6.4. Controls you have. Sharing is off until you switch it on. The address is a random token, not a guessable number. The page instructs search engines not to index it (noindex, nofollow). The QR code is generated inside your own browser, so the address is never sent to a third-party QR service.

6.5. Limits of those controls. Switching sharing off disables the link immediately, and deleting your account disables it too. Neither can retrieve copies that were already opened, saved, screenshotted or forwarded. A search engine that ignores the no-index instruction cannot be forced to comply.

6.6. Sensitive content is your choice. A CV can contain medical certificate details. Consider whether you want health information on a link you may forward to people you do not know.

SECTION 7. COOKIES, TRACKING & ADVERTISING

7.1. Strictly necessary. A session cookie keeps you logged in and carries the security token that protects forms against cross-site request forgery. It cannot be switched off without breaking the Platform, and it requires no consent.

7.2. Local storage. Small preferences (for example a dismissed notice, or a collapsed menu) are kept in your browser only. They are never transmitted to the Controller.

7.3. Google Ads conversion measurement. The Platform loads Google's gtag.js to measure whether an advertisement led to a registration or purchase. This is advertising measurement, not anonymous analytics, and it involves Google Ireland Limited as an independent controller for its own purposes.

7.4. Your choice. Advertising and measurement tags require your prior consent and are not loaded until you give it. You can change or withdraw that choice at any time from the cookie settings link in the footer; withdrawal does not affect processing already carried out.

SECTION 8. YOUR RIGHTS UNDER THE GDPR

8.1. In relation to your personal data you have the right to:

  • Access (Art. 15) — obtain a copy of the data held about you.
  • Rectification (Art. 16) — correct anything inaccurate. Most fields can be edited directly in your Dashboard.
  • Erasure (Art. 17) — delete your account. This removes your profile, certificates, rotations, timesheets, CV documents, share links and offer view history. Records the Controller must keep by law, such as accounting records of a purchase, are retained for the statutory period.
  • Restriction (Art. 18) — ask that processing be paused while a dispute is resolved.
  • Portability (Art. 20) — receive the data you provided in a structured, machine-readable format.
  • Objection (Art. 21) — object to processing based on legitimate interest, including the service and onboarding emails described in Section 3.
  • Withdraw consent (Art. 7(3)) — where processing rests on consent, such as the Virtual CV share link, health data entries, or advertising measurement. Withdrawal does not affect processing already carried out.

8.1a. In the App, specifically. Location and notifications rest on consent you give on the device. Withdraw either at any time in iOS Settings → GoUpTower, or switch individual notifications off under Account → Notifications in the App; high-wind alerts can be switched off on the Wind screen, which also deletes the position stored for them. Deleting the Account from the App removes everything listed in 8.1, and additionally the device tokens, the stored wind position, your referral record and points, and — if you signed in with Apple — revokes that sign-in with Apple. Everything Section 2 lists as kept on your device only — the packing list, unsaved CV drafts, Safety Book progress, the offline Education Hub, emergency map results and your layout and appearance choices — goes when you delete the App. The defibrillator map works only while you allow location and can be avoided entirely by not opening it.

8.2. How to exercise them. Write to gdpr@gouptower.com. The Controller will respond within one month, extendable by two further months for complex requests, and will tell you if that extension is needed.

8.3. Right to complain. If you believe your data is being handled unlawfully you may lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. You may also complain to the authority in your own EU country of residence.

8.4. Is providing data mandatory? An email address and password are required to hold an account — without them the contract cannot be performed. Everything else, including your name, WINDA ID, certificates, rotations and CV content, is entirely optional, and the Platform works without it, though CV Builder will have less to work from.

SECTION 9. INTERNATIONAL TRANSFERS

9.1. Data is stored on servers in Poland (SEOHOST Sp. z o.o.).

9.2. Some recipients named in Section 4 are EU entities that may transfer data to parent companies outside the European Economic Area, principally in the United States — this applies to Stripe, Google, Cloudflare and Apple. Such transfers are made under the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU–US Data Privacy Framework.

9.3. You may request further information about the safeguards in place by writing to gdpr@gouptower.com.

SECTION 10. RETENTION, AUTOMATED DECISIONS & CHANGES

10.1. Retention in summary. Account and profile data is kept while the account is active. Offer view logs are deleted after 30 days. Apply-click records are deleted after 60 days, notices under the bell after 120 days, and app sign-in tokens expire after 90 days. The position stored for high-wind alerts is overwritten each time it refreshes and removed when alerts are switched off or you sign out. Defibrillator search results cached on the server per map area contain no personal data and are discarded after 24 hours; the position used for the search is not kept at all. Accounting records tied to a purchase are kept for 5 years from the end of the fiscal year, as Polish law requires. Everything else is deleted with the account.

10.2. Inactive accounts. The Controller may delete an account that has not been logged into for 36 months, after giving notice by email to the address on file.

10.3. No automated decision-making. The Platform does not carry out automated decision-making or profiling that produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR. Subscription limits are a straightforward count of offers opened, not a profile.

10.4. No children. The Platform is intended for working professionals and is not directed at anyone under 16. The App carries an App Store age rating consistent with that.

10.5. Changes. This policy carries a version number and a date at the top. Material changes will be announced on the Platform and, where the change requires it, by email before it takes effect.