Privacy and cookie policy
Last updated: August 2026I. Introduction
Respecting the privacy of users visiting our application, TEST-DRIVE SP. Z O.O. applies this Privacy Policy to ensure proper protection of users' personal data. This Privacy Policy covers personal data that we may process for purposes related to the operation of the TEST-DRIVE SP. Z O.O. application published under the testdrive-files.com domain.
II. Data collection
When visiting our web application, data about visitors is collected, including: data gathered automatically and stored in server logs, and personal data provided knowingly by users and stored in databases. Server logs may include: HTTP requests sent to our server, public IP addresses, URLs of resources viewed, request and response timestamps, client host names identified by the HTTP protocol, browser information, the referring page address, and HTTP error information. Personal data is provided knowingly by users during registration, login and contact forms, and may include: full name or company name, a unique user identifier (login), e-mail address, phone number, and residence or company address.
III. Use of automatically collected data
TEST-DRIVE SP. Z O.O. ensures that data collected automatically in server logs is, as a rule, not disclosed to anyone except persons authorised to administer the server and the main site administrators. Identification of a specific person based on log data is attempted only in the event of attempts to breach system integrity by unauthorised persons. Statistics generated from log files contain no characteristics identifying visitors.
IV. Use of personal data
We process personal data solely in accordance with the purposes for which it was entrusted to TEST-DRIVE SP. Z O.O. Registration data is used to confirm the permissions of logged-in users and to communicate with users about the service. Contact form data is used for sales and after-sales support. We make every effort to keep personal data away from third parties, unless: this policy states otherwise; we receive the user's consent; the law is broken and related proceedings are pending; or the service is acquired by a third party bound by this Privacy Policy.
V. Legal bases, retention periods and data recipients
We process personal data in accordance with Regulation (EU) 2016/679 (GDPR), on the following
legal bases: Art. 6(1)(b) GDPR — conclusion and performance of a contract, i.e. maintaining
the user account and fulfilling orders; Art. 6(1)(c) GDPR — compliance with legal obligations
of the controller, in particular issuing and retaining billing documents as required by tax
and accounting regulations; Art. 6(1)(f) GDPR — the controller's legitimate interest, i.e.
ensuring portal security (including server log analysis), handling correspondence, and
establishing and pursuing claims. Providing data is voluntary but necessary to create an
account and fulfil orders.
Account data is stored for as long as the account exists, until its deletion (anonymisation).
Data contained in issued billing documents is stored for the period required by tax and
accounting regulations. Server logs are kept for a limited time necessary for security and
diagnostics. Data may be disclosed only to processors acting on our behalf under data
processing agreements (server infrastructure provider, e-mail service provider) and to public
authorities where disclosure is required by law. Data is stored on servers located within the
European Union and is not transferred to third countries. We do not make decisions concerning
users based solely on automated processing, including profiling, that would produce legal
effects for them (Art. 22 GDPR).
VI. Data security and user responsibilities
TEST-DRIVE SP. Z O.O. applies technical and organisational measures appropriate to the risk, in accordance with Art. 32 GDPR, in particular: all communication with the portal takes place over an encrypted connection (HTTPS/TLS); user passwords are stored solely as cryptographic hashes (we do not know and cannot read your password); authentication secrets (such as two-factor authentication keys) are encrypted in the database; access to data is limited to authorised persons; and regular backups are performed. The portal also offers a free two-factor authentication (2FA) option, which we recommend enabling — in particular because the account contains billing documents and invoices. Account security, however, also depends on the user: we recommend using a strong, unique password, not sharing login credentials with third parties, logging out on shared devices, and contacting us immediately if unauthorised account access is suspected.
VII. User rights, editing and deleting personal data
Every user has the right to access their data, to rectification, erasure, restriction of
processing, data portability, and to object to processing based on legitimate interest.
Users also have the right to lodge a complaint with the President of the Personal Data
Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw, Poland) if they consider that the
processing of their data infringes the GDPR.
Every user has the right to request correction or deletion of their personal data from our databases.
Requests should be sent by e-mail to , indicating which account or data the request
concerns. When deletion is requested, the administrator anonymises the account (removing the name and
e-mail from the database). This does not remove data from purchase records that must remain in the
system.
VIII. Cookies
When a user visits our site, small text files (cookies) may be stored on their computer. Our application uses cookies primarily to maintain the logged-in user's session and to remember preferences such as the selected language. Cookies do not collect any personal data, including names or e-mail addresses. Every user can change cookie settings in their browser, including disabling them entirely. Keeping cookies enabled constitutes consent to their storage. Rejecting all cookies will make it impossible to use some features of our site, in particular those requiring login.
IX. Changes to this policy
The date of the most recent changes is shown at the top of this Privacy Policy.
X. Disclaimers
No data transmission over the Internet can be guaranteed to be completely secure. Despite our best efforts, we cannot guarantee the security of information transmitted to and from our site. We recommend that users do not share information in their account that should not be disclosed. Our site may contain links to other websites; we accept no responsibility for the privacy practices of those sites.
XI. Data controller contact
The controller of personal data provided by users of this website is TEST-DRIVE SP. Z O.O., phone , e-mail: . Questions about this Privacy Policy should be sent to the e-mail address above.
