Privacy Policy
Effective date: 1 October 2026
1. Who we are
This Privacy Policy describes how Rafał Migda – Lore Media ("we", "us", "our") processes personal data in connection with the Approvale website and application available at https://approvale.io.
Data Controller
The data controller responsible for the processing of personal data is:
Rafał Migda – Lore Media
ul. Zuchów 131/1
43-300 Bielsko-Biała
Poland
NIP: 8691983646
REGON: 360319820
For privacy-related requests, please contact:
2. What Approvale does
Approvale is a software service that allows customers to connect form providers, currently Typeform, and create approval workflows for submitted forms.
Approvale allows customers to:
- connect Typeform forms
- receive and process form submissions
- configure approval workflows
- review submissions
- approve or reject submissions
- configure workflow-related email notifications
- manage submission and approval history
3. Data we process
Depending on how you use Approvale, we may process the following categories of personal data.
3.1 Account data
When you create an Approvale account, we may process:
- first and last name
- email address
- company name, if provided
- password in securely hashed form
- email verification status
- account and subscription information
3.2 Product and workflow data
When you use Approvale, we may process:
- workflows
- workflow names and configuration
- workflow statuses
- connected forms
- submission data
- approval and rejection decisions
- comments
- attachments
- automation configuration
- email delivery configuration
- activity and audit history
3.3 Typeform data
If you connect Typeform, Approvale may process:
- Typeform account or integration identifiers
- form metadata
- form fields
- Typeform submissions
- answers submitted through Typeform
- information contained in those submissions
- information necessary to associate submissions with Approvale workflows
The content of Typeform submissions may contain personal data relating to individuals who submit information through forms created by our customers.
3.4 Integration credentials
When you connect Typeform, Approvale may process authentication credentials or access tokens required to communicate with Typeform.
Such credentials are stored using appropriate security measures, including encryption where implemented.
3.5 Email data
Approvale may process:
- recipient email addresses
- sender information
- email subject
- email content
- delivery status
- bounce information
- email event information
This may be necessary to send account-related, transactional and workflow-related emails.
3.6 Marketing data
If you voluntarily subscribe to marketing communications, we may process:
- email address
- name
- marketing consent status
- date and time of consent
- source of consent
- unsubscribe status
Marketing communications are sent only where the applicable legal requirements have been satisfied.
3.7 Payment and billing data
When you purchase a paid Approvale plan, payment processing may be handled by Paddle.
Approvale may receive and store information such as:
- customer name
- billing email address
- billing country
- subscription or purchase information
- plan information
- transaction identifiers
- payment status
Approvale does not store complete payment card numbers.
Payment card and other payment credentials are handled by Paddle in accordance with Paddle's own terms and privacy documentation.
3.8 Technical and security data
We may process technical information including:
- IP address
- browser type
- operating system
- device information
- user agent
- timestamps
- authentication events
- security events
- error logs
- server logs
This information may be used to secure the service, prevent abuse, diagnose technical problems and maintain service availability.
3.9 Cookie and consent data
Depending on your choices, we may process:
- cookie consent preferences
- consent categories
- consent timestamp
- consent version
- consent identifier
- visitor identifier
- information about the technologies for which consent was provided or refused
4. How we use personal data
We process personal data for the following purposes:
4.1 Providing the service
We use personal data to:
- create and manage Approvale accounts
- authenticate users
- provide access to the application
- connect Typeform integrations
- receive and process submissions
- operate approval workflows
- store workflow history
- send workflow notifications
- provide customer support
4.2 Security
We process technical and account information to:
- protect accounts
- prevent unauthorized access
- detect abuse
- detect and investigate security incidents
- maintain application and infrastructure security
- troubleshoot technical problems
4.3 Payments and billing
We process billing and transaction information to:
- process purchases
- manage subscriptions
- verify payment status
- provide invoices or billing information
- manage refunds where applicable
Payment processing is performed by Paddle.
4.4 Communications
We may send:
- account verification emails
- password reset emails
- security notifications
- service notifications
- workflow notifications
- transactional emails
- customer support communications
These communications are necessary for providing the service where applicable.
4.5 Marketing
Where required, we may send marketing communications only when the recipient has provided the required consent or another valid legal basis applies.
Marketing communications may include:
- product updates
- new features
- educational content
- offers
- announcements
You can unsubscribe from marketing communications at any time.
4.6 Analytics and service improvement
Where you have provided the required consent, we may use analytics technologies to understand how visitors use the Approvale website and improve the service.
We may use:
- Google Analytics
- Google Tag Manager
- Google Ads
- Meta advertising technologies
These technologies are subject to the applicable consent settings described in our Cookie Policy.
5. Legal bases for processing
Depending on the specific processing activity, we rely on one or more of the following legal bases under the GDPR:
Performance of a contract
We process personal data when necessary to:
- create and maintain your account
- provide Approvale services
- process your submissions
- operate workflows
- provide customer support
- process purchases and subscriptions
Legal obligations
We may process personal data where necessary to comply with legal obligations, including accounting, tax, financial and regulatory requirements.
Legitimate interests
We may process personal data where necessary for our legitimate interests, including:
- securing the service
- preventing fraud and abuse
- maintaining infrastructure
- troubleshooting
- improving reliability
- defending legal claims
- maintaining business records
Where we rely on legitimate interests, we consider the interests, rights and freedoms of the affected individuals.
Consent
Where required, we rely on consent for activities such as:
- certain cookies and tracking technologies
- analytics
- advertising and remarketing
- marketing communications
You may withdraw consent at any time where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
6. Typeform
Approvale integrates with Typeform.
When you connect Typeform, Approvale may access and process information from your Typeform account and forms according to the permissions and configuration you provide.
For customer-provided submission data, the Approvale customer generally determines the purposes and means of processing and may act as the data controller, while Approvale processes the data on the customer's behalf.
The customer is responsible for ensuring that the collection and processing of personal data through their Typeform forms has an appropriate legal basis and that required privacy information is provided to data subjects.
Typeform operates under its own privacy documentation and data processing terms.
More information is available in Typeform's privacy documentation:
https://www.typeform.com/legal/data-processing-agreement/
Typeform also publishes information about its subprocessors and international data transfers.
7. Email delivery – Brevo
Approvale may use Brevo for transactional and/or marketing email delivery.
Brevo may process information necessary to deliver emails, including:
- email addresses
- names
- email content
- delivery events
- bounce information
- unsubscribe information
- consent information where applicable
Brevo acts as a service provider / processor where it processes personal data on our behalf.
Brevo provides GDPR documentation and a Data Processing Agreement.
More information about Brevo's GDPR compliance is available at:
https://help.brevo.com/hc/en-us/articles/360001258744-How-does-Brevo-comply-with-the-GDPR
8. Payments – Paddle
Approvale may use Paddle for payment processing and subscription billing.
Paddle may process:
- customer identification information
- billing information
- payment information
- transaction information
- subscription information
- tax-related information
Paddle processes payment information in accordance with its own privacy policy and contractual terms.
Approvale does not store complete payment card information.
Paddle provides Data Processing Addendum documentation for applicable processing activities.
9. Hosting – Netcup
Approvale is hosted on infrastructure provided by netcup GmbH.
Netcup may process personal data stored or transmitted through the Approvale infrastructure, including application data, account data, technical information and server logs, to the extent necessary to provide hosting and infrastructure services.
Netcup provides a Data Processing Agreement for customers who use its infrastructure for processing personal data.
More information is available in Netcup's privacy documentation:
https://www.netcup.com/en/contact/data-privacy
and its information about data processing agreements:
https://www.netcup.com/en/helpcenter/documentation/general/dpa
10. Server management – Ploi
Approvale may use Ploi for server management, deployment and infrastructure administration.
Depending on the configuration and permissions granted to Ploi, the service may have technical access to server infrastructure used to operate Approvale.
Ploi is used for infrastructure management rather than for collecting personal data directly from Approvale users.
Access to production infrastructure is restricted to what is necessary for operating and maintaining the service.
11. Google Tag Manager
Approvale may use Google Tag Manager (GTM) to manage website tags and integrations.
GTM itself is primarily used as a tag management layer. Tags that process information for analytics or advertising purposes are configured to respect applicable consent requirements.
Where required, non-essential tags are not activated until the relevant consent has been provided.
Google provides Data Processing Terms applicable to Google Tag Manager customers subject to the GDPR.
12. Google Analytics
Approvale may use Google Analytics to understand website usage and improve the service.
Depending on the configuration and your consent choices, Google Analytics may process information such as:
- device information
- browser information
- approximate location
- pages viewed
- events and interactions
- referrer information
- technical identifiers
Google Analytics is used for statistical and analytical purposes.
Where required, analytics technologies are activated only after the appropriate consent has been provided.
Google provides Data Processing Terms applicable to Google Analytics customers subject to the GDPR.
13. Google Ads
Approvale may use Google Ads to advertise the service and measure advertising effectiveness.
Depending on the configuration, Google Ads technologies may process information such as:
- IP address
- device and browser information
- interaction with advertisements
- website visits
- conversion events
- advertising identifiers
- information relating to advertising campaigns
Where required, advertising and remarketing technologies are activated only after the appropriate consent has been provided.
Google's EU User Consent Policy requires advertisers to obtain consent where required for the use of cookies and for certain processing of personal data for advertising personalization.
14. Meta
Approvale may use Meta advertising technologies, including the Meta Pixel and related Meta Business Tools, for advertising measurement, campaign optimization and remarketing.
Depending on the configuration and your consent choices, Meta may process information such as:
- IP address
- browser and device information
- website interactions
- pages visited
- conversion events
- advertising identifiers
Where required, Meta advertising technologies are activated only after the appropriate consent has been provided.
Where customer data is uploaded to Meta for advertising purposes, such as Customer List Custom Audiences, we will only do so where we have an appropriate legal basis and where applicable contractual and privacy requirements have been satisfied.
Meta provides its own data processing and privacy documentation governing the use of its Business Tools.
15. Subprocessors and service providers
Depending on the features enabled and the production configuration, Approvale may use the following service providers:
| Provider | Purpose | Type of processing |
|---|---|---|
| Typeform | Form integration and submission data | Application data / submissions |
| Netcup | Hosting and infrastructure | Application and technical data |
| Ploi | Server management and deployment | Infrastructure / technical access |
| Brevo | Transactional and marketing email delivery | Email and contact data |
| Paddle | Payment and subscription processing | Billing and transaction data |
| Google Tag Manager | Tag management | Technical / consent-controlled tags |
| Google Analytics | Website analytics | Analytics data |
| Google Ads | Advertising and conversion measurement | Advertising data |
| Meta | Advertising and conversion measurement | Advertising data |
We may add, remove or replace service providers where necessary to operate and improve Approvale.
Where required by applicable law, we will ensure that appropriate contractual safeguards are in place with processors and subprocessors.
16. International data transfers
Some service providers used by Approvale may process personal data outside the European Economic Area.
Where personal data is transferred outside the EEA, we use an appropriate legal mechanism where required, which may include:
- an adequacy decision
- Standard Contractual Clauses approved by the European Commission
- other legally recognized transfer mechanisms
- appropriate supplementary safeguards where required
The actual location and transfer mechanism may differ depending on the service provider and the specific service configuration.
17. Cookies and similar technologies
Approvale uses cookies and similar technologies.
Cookies may be divided into the following categories:
Necessary cookies
These cookies are required for:
- authentication
- session management
- security
- consent storage
- basic application functionality
Necessary cookies cannot be disabled where they are strictly required to provide the requested service.
Preferences
Preference cookies may be used to remember choices such as language or interface preferences.
Statistics
Statistics cookies may be used to understand how visitors interact with Approvale.
This category may include Google Analytics.
Marketing
Marketing cookies and similar technologies may be used for advertising and conversion measurement.
This category may include:
- Google Ads
- Meta Pixel
- other advertising technologies
Optional categories are disabled until the required consent is provided.
You can change your consent preferences at any time using the Privacy settings link available on the Approvale website.
For more information, see our Cookie Policy.
18. Google Consent Mode
Where Google services are enabled, Approvale may use Google Consent Mode to communicate consent choices to Google services.
Consent signals may include:
ad_storageanalytics_storagead_user_dataad_personalization
The specific signals used may depend on the Google products and tags configured on the website.
Consent choices are managed through the Approvale consent management system.
19. Data retention
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Retention periods depend on the type of information.
Account data
Account information is generally retained while the account remains active.
After account closure, information may be retained for a limited period where necessary for:
- legal obligations
- accounting
- security
- fraud prevention
- dispute resolution
- establishment, exercise or defense of legal claims
Submission and workflow data
Submission and workflow data is retained according to the customer's use of the Approvale service and applicable account configuration.
Integration credentials
Integration credentials are retained while the associated integration remains active.
When an integration is disconnected, credentials are deleted or invalidated where technically applicable.
Marketing data
Marketing subscription information may be retained for as long as necessary to demonstrate consent, manage subscriptions and comply with applicable legal requirements.
Consent records
Consent records may be retained to demonstrate when and how consent was provided or withdrawn.
Security logs
Security and technical logs may be retained for a limited period appropriate to their security purpose.
20. Data security
We use reasonable technical and organizational measures designed to protect personal data against:
- unauthorized access
- unauthorized disclosure
- accidental loss
- destruction
- alteration
- misuse
Security measures may include:
- encrypted connections using HTTPS/TLS
- password hashing
- access controls
- restricted production access
- encrypted storage of sensitive credentials where implemented
- authentication controls
- logging and monitoring
- server and application security controls
- regular software and dependency updates
No internet-based service can guarantee absolute security.
21. Data breaches
Where required by applicable law, we will take appropriate steps in response to a personal data breach, including assessing the incident, containing the breach and notifying relevant authorities or affected individuals where legally required.
Where we use processors, we require them to provide appropriate assistance and notifications in accordance with applicable contractual and legal requirements.
22. Your rights
Subject to applicable law, you may have the right to:
- obtain access to your personal data
- correct inaccurate personal data
- request deletion of personal data
- request restriction of processing
- object to certain processing
- request data portability
- withdraw consent where processing is based on consent
You can exercise your rights by contacting:
We may need to verify your identity before processing a request.
You will not normally be charged for exercising your data protection rights.
We aim to respond to valid requests within the time required by applicable law.
23. Right to lodge a complaint
If you believe that your personal data has been processed in violation of applicable data protection law, you may lodge a complaint with the competent supervisory authority.
For the controller established in Poland, the relevant supervisory authority is:
Prezes Urzędu Ochrony Danych Osobowych (UODO)
24. Children
Approvale is not directed to children.
We do not knowingly collect personal data from children through the service.
If you believe that a child has provided personal data to us without the appropriate authorization, please contact us at:
25. Customer responsibility for submitted data
Customers using Approvale are responsible for ensuring that they have an appropriate legal basis for collecting and processing personal data through their forms and workflows.
Customers are also responsible for:
- providing appropriate privacy information to data subjects
- collecting required consents where applicable
- ensuring that data submitted to Approvale is processed lawfully
- configuring their Typeform forms appropriately
- determining the appropriate retention period for their data
- responding to data subject requests where the customer acts as controller
Approvale processes customer submission data primarily according to the customer's instructions and configuration.
26. Automated decision-making
Approvale does not make decisions about individuals based solely on automated processing that produce legal or similarly significant effects.
Approval and rejection actions within Approvale are performed by authorized users configuring and operating the relevant workflow.
27. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
When we make changes, we will publish an updated version through the Approvale legal document system.
The effective date at the beginning of this document indicates when the current version became effective.
Where required by law, we may notify users about material changes or request renewed acceptance.
28. Contact
For questions regarding this Privacy Policy or the processing of personal data by Approvale, please contact:
Rafał Migda – Lore Media
ul. Zuchów 131/1
43-300 Bielsko-Biała
Poland
NIP: 8691983646
REGON: 360319820
Email: support@approvale.io