House of Product - Product Development Studio Logo

Privacy Policy

House of Product Sp. z o.o.

Effective date: 5 February 2026Last updated: 5 February 2026

1) Who we are and what this Policy covers

This Privacy Policy explains how House of Product Sp. z o.o. ("House of Product", "we", "us") collects and processes personal data when you interact with us through: • our public website houseofproduct.co • our training and education services, including HoP Academy (e.g., academy.houseofproduct.co) • our events (online and in-person), including registrations, attendance, communications, recordings, and photos • our professional services delivered to clients (consulting, strategy, research, design, product delivery) • our internal tools used by our team, including an internal application for planning, approving, and scheduling LinkedIn posts ("Internal LinkedIn Scheduling App") This Policy applies where we act as a data controller (we decide why and how personal data is processed). In some client engagements we may process data as a processor on behalf of a client (see section 8).

2) Data Controller and contact

Data Controller: House of Product Sp. z o.o. Registered address: ul. Na Polance 12/5, 51-109 Wrocław, Poland General contact: [email protected] Privacy (GDPR) contact: [email protected]

3) What personal data we collect

We collect personal data depending on how you interact with us. 3.1 Website visitors • Technical data: IP address, browser type, device type, operating system, timestamps • Usage data: pages viewed, referral URL, clicks (where available) • Security logs and diagnostics necessary to operate and secure the website 3.2 Enquiries and business communications • Contact data: name, email address, company, role/title (if provided) • Communication content: messages, attachments, correspondence history • Meeting metadata: date/time, participants; and notes (where necessary) 3.3 Trainings, HoP Academy, webinars, workshops • Registration data: name, email, company/role, invoice details (if applicable) • Participation data: attendance confirmations, certificates (if applicable) • Content you submit: questions, chat messages, feedback, assignments (only if you submit them) 3.4 Events (online and in-person) • Registration and attendance data • Event communications: Q&A, chat, feedback forms, interactions • Recordings and images: your image, voice, and statements if the event is recorded/photographed 3.5 Professional services to clients • Business contact data of client representatives • Project communications and materials needed to deliver the engagement • If research is part of the engagement: participant scheduling details, consent records, research responses and recordings (as applicable to the project and agreed scope) 3.6 Payments and invoicing • Invoice data: name/company, address, tax ID (if applicable) • Payment status and transaction confirmations We do not store full payment card details if processed by external payment providers. 3.7 Internal LinkedIn Scheduling App (internal use) We process personal data of authorized users (e.g., employees and contractors) and LinkedIn integration data to plan, approve, and schedule LinkedIn posts. This may include: • Internal user account data: name, email, role/permissions, authentication identifiers (e.g., SSO), security access logs • Content and scheduling data: post drafts, captions, hashtags, links, media (images/videos), publish dates/times, approval status, audit history (who created/edited/approved/published) • LinkedIn integration data: identifiers needed to connect to LinkedIn (e.g., page/organization identifiers, permission scopes) and OAuth tokens or similar credentials required to publish via the LinkedIn API • Technical and security logs: IP address, device/browser details, timestamps, error logs, activity logs We do not request or store LinkedIn passwords in the Internal LinkedIn Scheduling App. Access is granted using LinkedIn authorization (e.g., OAuth), and permissions can be revoked in LinkedIn settings.

4) Why we process personal data (purposes)

We process personal data to: • operate our website and respond to enquiries • deliver trainings, webinars, workshops, and academy services • organize and run events (including communications and follow-ups) • deliver client services and manage the client relationship • manage billing, accounting, taxes, and legal obligations • ensure security, prevent abuse, troubleshoot, and improve our services • operate internal tools (including the Internal LinkedIn Scheduling App), manage access, approvals, audit trails, and troubleshooting

5) Legal bases for processing (GDPR)

We process personal data based on one or more of the following legal bases: • Contract necessity (GDPR Art. 6(1)(b)) — delivering trainings, services, events, and client engagements • Consent (Art. 6(1)(a)) — where required (e.g., certain marketing, non-essential cookies, specific optional uses) • Legitimate interests (Art. 6(1)(f)) — security, service improvement, communications, internal administration, fraud prevention • Legal obligation (Art. 6(1)(c)) — accounting, tax, compliance obligations

6) Cookies and analytics

We use cookies and similar technologies primarily for essential functionality and security (e.g., session management). We currently do not run analytics on our website. If/when we enable Google Analytics, we will: • provide a cookie notice/consent mechanism where required • allow you to manage cookie preferences You can also control cookies via browser settings. Disabling certain cookies may affect site functionality.

7) Sharing and disclosure of personal data

We do not sell personal data. We may share data only when necessary: 7.1 Service providers (processors) We use trusted providers for hosting, email, learning platforms, forms/surveys, video conferencing, scheduling, and IT services. These providers process data under agreements and appropriate safeguards. 7.2 LinkedIn / social media APIs (Internal App) When the Internal LinkedIn Scheduling App publishes or schedules content, we transmit relevant data to LinkedIn (e.g., post content, media, scheduling metadata, and authorization tokens) to perform the requested action. LinkedIn processes data under its own terms and privacy policy and may act as an independent controller for its processing. 7.3 Legal requirements and protection We may disclose data if required by law, court order, or regulator, or to protect our rights, users, and security.

8) Client projects: controller vs processor

In some client engagements we may process data: • as a controller (we decide purposes/means), or • as a processor acting on the client's instructions (the client is the controller) If we act as a processor, the client's privacy information and instructions apply to that processing.

9) International transfers

Some providers (including LinkedIn and certain IT tools) may process data outside the EEA. Where required, we apply appropriate safeguards such as Standard Contractual Clauses (SCCs) and additional measures where necessary.

10) Data retention

We keep personal data only as long as necessary for the purposes described above, then delete or anonymize it. Typical approach: • enquiries and correspondence: for the duration of communication and reasonable follow-up, plus limited archiving where needed to handle claims • training/event records: as needed for delivery, support, and any legal/accounting requirements • invoices/accounting: for the period required by applicable law • client engagement records: as agreed in contract and/or required to defend claims Internal LinkedIn Scheduling App: • content and schedules: retained as long as needed for operational continuity • OAuth tokens/integration credentials: retained only while the integration is active; deleted/invalidated upon disconnection • security/audit logs: retained for up to 24 months, unless a longer period is needed for incident investigation or legal compliance

11) Your rights

Depending on applicable law (including GDPR), you may have the right to: • access your data • rectify inaccurate data • delete your data (in certain cases) • restrict processing (in certain cases) • object to processing based on legitimate interests • data portability (where applicable) • withdraw consent at any time (where consent is the basis) To exercise your rights, contact: [email protected]

12) Supervisory authority (Poland)

You may lodge a complaint with the Polish supervisory authority: Urząd Ochrony Danych Osobowych (UODO) ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland tel. +48 22 531 03 00 email: [email protected]

13) Security

We apply appropriate technical and organizational measures (access controls, least privilege, secure hosting practices). No method of transmission is 100% secure, but we work to reduce risk.

14) Recordings and photos at events

Some events may be recorded or photographed. We will provide notice in advance (e.g., event page/registration) and/or at the start of the event. Where feasible, we provide practical opt-out options (e.g., camera off, anonymous Q&A).

15) Children's privacy

Our services are not intended for minors. We do not knowingly collect personal data from children.

16) Changes to this Policy

We may update this Policy from time to time. We will publish the updated version and change the "Last updated" date.

17) Contact

House of Product Sp. z o.o. ul. Na Polance 12/5, 51-109 Wrocław, Poland Privacy: [email protected] General: [email protected]