Manager5 Public document

Manager5 Privacy Notice

Version: 1.0
Publication date: 30 July 2026
Effective date: 1 September 2026

1. Who is responsible for the data

The controller of personal data processed to operate Manager5, administer accounts, handle billing, maintain security, communicate and provide support is:

TJSOFT SP. Z O.O.
ul. Panewnicka 343C/7
40-774 Katowice, Poland
KRS: 0000646480
NIP: 6342877643
REGON: 365841751
email: kontakt@tjsoft.pl
service: https://manager5.com

For privacy questions or requests concerning personal data rights, contact us at kontakt@tjsoft.pl.

2. Who and what this notice covers

This notice applies to individuals whose data we process as a controller in connection with:

Manager5 is a business service. A person using an account on behalf of a customer must be authorised by that customer.

3. TJSOFT has two distinct roles

Depending on the type of data, we act in one of two roles:

  1. Controller – where we determine why and how data required to operate Manager5, administer accounts, bill customers, provide support, maintain security or comply with law is processed.
  2. Processor – where we process, on a customer's instructions, data entered into Manager5 by that customer or its users, referred to below as “Customer Data”. In that case the customer determines the purpose for which Customer Data is used and will normally be its controller.

TJSOFT's processing of Customer Data is governed by the Manager5 service agreement, including its data processing provisions. This notice does not change the allocation of roles agreed there.

4. Personal data we process as a controller

Depending on a person's relationship with Manager5, we may process:

We do not ask for data that is unnecessary for a stated purpose. Manager5 is not intended for storing categories of data prohibited by the service agreement.

5. Where the data comes from

We obtain personal data:

Where a customer provides another person's data, the customer is responsible for having a lawful basis to do so and for giving that person any required information.

6. Purposes and legal bases

We process personal data as a controller for the following purposes.

6.1. Entering into and performing a contract

We use data to create an account, provide an offer, accept an order, deliver the service, handle payments, communicate about the contract and manage the end of the relationship.

The legal basis is taking steps at an individual's request and performing a contract where that individual is a party, and our legitimate interest in performing a contract with a customer through its representatives and users.

6.2. Billing and legal obligations

We use data required for invoicing, accounting, tax, statutory records and responding to competent authorities.

The legal basis is compliance with a legal obligation that applies to TJSOFT.

6.3. Security and misuse prevention

We use data required to authenticate users, protect accounts and data, detect misuse, investigate incidents and preserve relevant security evidence.

The legal basis is our legitimate interest in providing a secure service, protecting customers and defending the service against misuse.

6.4. Service and quality support

We use correspondence and service operation information to answer questions, resolve requests and assess the quality and reliability of Manager5.

The legal basis is performance of the contract or our legitimate interest in providing support and keeping the service working properly. Where aggregated or anonymous information is sufficient for analysis, we use that form.

6.5. Legal claims and compliance

We process data where needed to establish, pursue or defend claims, carry out checks or demonstrate compliance with our obligations.

The legal basis is our legitimate interest in protecting TJSOFT's and customers' rights and, where applicable, compliance with a legal obligation.

6.6. Marketing

We send marketing communications on the basis of a separate consent where consent is required. Marketing consent is voluntary and is not a condition for using the core Manager5 service. It may be withdrawn at any time.

6.7. Website measurement and Google analytics

Manager5 uses first-party public website measurement as described in the Cookie Notice. We start a Google Analytics or Google Tag Manager script only after separate consent is given through the analytics dialog. Rejecting Google analytics does not restrict the core Manager5 service and is separate from any marketing choice.

7. Whether providing data is required

Data marked as required is necessary to create an account, enter into or perform a contract, handle a payment or answer a request. Without it, we may be unable to complete the relevant activity.

Data used solely on the basis of consent is voluntary. Refusing or withdrawing consent does not affect the lawfulness of earlier processing and does not restrict the core service, unless an optional feature inherently requires that processing.

8. Customer Data

The customer decides what Customer Data permitted by the agreement is entered into Manager5 and why it is used. For that data:

The customer must not place in Manager5 data prohibited by the agreement or data it is not entitled to process.

9. Recipients and service providers

Personal data may be received, only to the extent necessary, by:

Current information about service providers and other recipients involved in Manager5 is available at https://manager5.com/rules/subprocessors.

We do not sell personal data.

10. Transfers outside the European Economic Area

Where using a particular provider requires a transfer of personal data outside the European Economic Area, we use a mechanism permitted by law, in particular an adequacy decision or the European Commission's standard contractual clauses, together with supplementary safeguards where required.

Current information about processing locations and safeguards associated with particular recipients is provided in the service provider and recipient notice. A copy of relevant safeguards may be requested from us; confidential or legally protected information may be redacted.

11. How long we retain data

We retain personal data only for as long as required for the purpose for which it was collected, taking account of legal obligations and the need to protect legal claims:

After the relevant period, we delete or permanently anonymise the data unless continued retention is required by law.

12. Individual rights

To the extent provided by the GDPR, an individual may:

Information about submitting a complaint in Poland is available at https://uodo.gov.pl.

A request may be sent to kontakt@tjsoft.pl. We may ask for information required to confirm identity and protect personal data from disclosure to an unauthorised person.

If a request concerns Customer Data, the individual should contact the customer that decides how to handle the request. We will provide that customer with the necessary assistance.

13. Automated decisions

We do not make decisions about users based solely on automated processing where those decisions produce legal effects or similarly significantly affect them.

We may use automated measures to detect security events or misuse. These measures protect the service and do not replace human review where a decision could significantly affect a customer or user.

14. Children and minors

Manager5 is a business service and is not directed to children. User accounts should be created for people authorised to act in a professional setting.

If a customer processes data concerning a minor in Manager5, that customer is responsible for the lawfulness of the processing, the appropriate legal basis, required notices and limiting the data to what is necessary. TJSOFT processes such Customer Data only as a processor and in accordance with the agreement.

15. Security

We apply organisational and technical measures appropriate to the nature of the data, the way it is used and the relevant risks. These measures include access controls, account protection, permission limits, backups, event monitoring and incident response procedures.

No online service can eliminate all risk. Customers and users should protect sign-in details, grant access only to authorised persons and promptly report suspected security incidents.

16. Changes to this notice

We may update this notice if our processing, the service or applicable law changes. A new version will state its publication date and effective date. A change to this notice does not by itself amend rights and obligations under an existing agreement.

17. Contact

Privacy questions, requests and reports may be sent to:

kontakt@tjsoft.pl