Version: 1.0 · Effective: September 1, 2026
Manager5 Privacy Notice
Version: 1.0
Publication date: 30 July 2026
Effective date: 1 September 2026
1. Who is responsible for the data
The controller of personal data processed to operate Manager5, administer accounts, handle billing, maintain security, communicate and provide support is:
TJSOFT SP. Z O.O.
ul. Panewnicka 343C/7
40-774 Katowice, Poland
KRS: 0000646480
NIP: 6342877643
REGON: 365841751
email: kontakt@tjsoft.pl
service: https://manager5.com
For privacy questions or requests concerning personal data rights, contact us at kontakt@tjsoft.pl.
2. Who and what this notice covers
This notice applies to individuals whose data we process as a controller in connection with:
- visiting manager5.com;
- creating and administering a Manager5 account;
- representing a company or other organisation that is a Manager5 customer;
- entering into, performing and billing for a Manager5 service agreement;
- contacting sales, customer service or support;
- securing the service, preventing misuse and handling legal claims;
- managing cookie or marketing communication choices.
Manager5 is a business service. A person using an account on behalf of a customer must be authorised by that customer.
3. TJSOFT has two distinct roles
Depending on the type of data, we act in one of two roles:
- Controller – where we determine why and how data required to operate Manager5, administer accounts, bill customers, provide support, maintain security or comply with law is processed.
- Processor – where we process, on a customer's instructions, data entered into Manager5 by that customer or its users, referred to below as “Customer Data”. In that case the customer determines the purpose for which Customer Data is used and will normally be its controller.
TJSOFT's processing of Customer Data is governed by the Manager5 service agreement, including its data processing provisions. This notice does not change the allocation of roles agreed there.
4. Personal data we process as a controller
Depending on a person's relationship with Manager5, we may process:
- identity and business contact details, such as name, position, organisational role, business email address and telephone number;
- company, account, plan, order and user permission information;
- billing and payment information, including amounts, currency, payment status and accounting document details;
- correspondence, support requests and service-related arrangements;
- information about use of the service required for its operation and protection, including sign-in, device, browser, account event and suspected security misuse information;
- cookie, communication and consent choices;
- information required to establish, pursue or defend legal claims.
We do not ask for data that is unnecessary for a stated purpose. Manager5 is not intended for storing categories of data prohibited by the service agreement.
5. Where the data comes from
We obtain personal data:
- directly from the individual;
- from the customer, its representative or account administrator where they create an account or manage another person's access;
- through use of the Manager5 website and service;
- from providers supporting payments, communications or another requested function, only to the extent required to handle that activity;
- from correspondence and requests sent to TJSOFT.
Where a customer provides another person's data, the customer is responsible for having a lawful basis to do so and for giving that person any required information.
6. Purposes and legal bases
We process personal data as a controller for the following purposes.
6.1. Entering into and performing a contract
We use data to create an account, provide an offer, accept an order, deliver the service, handle payments, communicate about the contract and manage the end of the relationship.
The legal basis is taking steps at an individual's request and performing a contract where that individual is a party, and our legitimate interest in performing a contract with a customer through its representatives and users.
6.2. Billing and legal obligations
We use data required for invoicing, accounting, tax, statutory records and responding to competent authorities.
The legal basis is compliance with a legal obligation that applies to TJSOFT.
6.3. Security and misuse prevention
We use data required to authenticate users, protect accounts and data, detect misuse, investigate incidents and preserve relevant security evidence.
The legal basis is our legitimate interest in providing a secure service, protecting customers and defending the service against misuse.
6.4. Service and quality support
We use correspondence and service operation information to answer questions, resolve requests and assess the quality and reliability of Manager5.
The legal basis is performance of the contract or our legitimate interest in providing support and keeping the service working properly. Where aggregated or anonymous information is sufficient for analysis, we use that form.
6.5. Legal claims and compliance
We process data where needed to establish, pursue or defend claims, carry out checks or demonstrate compliance with our obligations.
The legal basis is our legitimate interest in protecting TJSOFT's and customers' rights and, where applicable, compliance with a legal obligation.
6.6. Marketing
We send marketing communications on the basis of a separate consent where consent is required. Marketing consent is voluntary and is not a condition for using the core Manager5 service. It may be withdrawn at any time.
6.7. Website measurement and Google analytics
Manager5 uses first-party public website measurement as described in the Cookie Notice. We start a Google Analytics or Google Tag Manager script only after separate consent is given through the analytics dialog. Rejecting Google analytics does not restrict the core Manager5 service and is separate from any marketing choice.
7. Whether providing data is required
Data marked as required is necessary to create an account, enter into or perform a contract, handle a payment or answer a request. Without it, we may be unable to complete the relevant activity.
Data used solely on the basis of consent is voluntary. Refusing or withdrawing consent does not affect the lawfulness of earlier processing and does not restrict the core service, unless an optional feature inherently requires that processing.
8. Customer Data
The customer decides what Customer Data permitted by the agreement is entered into Manager5 and why it is used. For that data:
- the customer is the controller or another party entitled to instruct processing;
- TJSOFT processes the data only on the customer's documented instructions and to the extent needed to provide the service;
- TJSOFT applies appropriate organisational and technical measures and supports the customer with duties set out in the agreement and applicable law;
- requests from individuals concerning Customer Data should first be sent to the customer. TJSOFT assists the customer in handling them in accordance with the agreement.
The customer must not place in Manager5 data prohibited by the agreement or data it is not entitled to process.
9. Recipients and service providers
Personal data may be received, only to the extent necessary, by:
- persons authorised by the customer;
- providers of infrastructure, data storage, communications, payments, billing, support and security services;
- legal, tax and accounting advisers and auditors who are bound by confidentiality;
- public authorities or other parties where disclosure is required by law or necessary to protect legal rights.
Current information about service providers and other recipients involved in Manager5 is available at https://manager5.com/rules/subprocessors.
We do not sell personal data.
10. Transfers outside the European Economic Area
Where using a particular provider requires a transfer of personal data outside the European Economic Area, we use a mechanism permitted by law, in particular an adequacy decision or the European Commission's standard contractual clauses, together with supplementary safeguards where required.
Current information about processing locations and safeguards associated with particular recipients is provided in the service provider and recipient notice. A copy of relevant safeguards may be requested from us; confidential or legally protected information may be redacted.
11. How long we retain data
We retain personal data only for as long as required for the purpose for which it was collected, taking account of legal obligations and the need to protect legal claims:
- account and business relationship data – for the duration of the customer relationship and then for the period required to settle it and protect legal claims;
- accounting and tax data – for the period required by law;
- correspondence and support requests – for the period required to handle the matter, maintain support continuity and protect legal claims;
- security information – for a period proportionate to the risk and required to detect misuse, investigate incidents and demonstrate security;
- consent records – until consent is withdrawn and then for as long as needed to demonstrate how it was given or withdrawn;
- marketing data – until consent is withdrawn or an objection is effective, while retaining the minimum information needed to honour that decision;
- Customer Data – in accordance with the customer's instructions, the agreement and the agreed return or deletion process after service termination.
After the relevant period, we delete or permanently anonymise the data unless continued retention is required by law.
12. Individual rights
To the extent provided by the GDPR, an individual may:
- obtain access to personal data and a copy of it;
- request correction of personal data;
- request deletion of personal data;
- request restriction of processing;
- receive personal data in a structured format and transmit it to another controller;
- object to processing based on legitimate interests and, at any time, to direct marketing;
- withdraw consent at any time without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with the President of the Polish Personal Data Protection Office or, where applicable, another competent supervisory authority.
Information about submitting a complaint in Poland is available at https://uodo.gov.pl.
A request may be sent to kontakt@tjsoft.pl. We may ask for information required to confirm identity and protect personal data from disclosure to an unauthorised person.
If a request concerns Customer Data, the individual should contact the customer that decides how to handle the request. We will provide that customer with the necessary assistance.
13. Automated decisions
We do not make decisions about users based solely on automated processing where those decisions produce legal effects or similarly significantly affect them.
We may use automated measures to detect security events or misuse. These measures protect the service and do not replace human review where a decision could significantly affect a customer or user.
14. Children and minors
Manager5 is a business service and is not directed to children. User accounts should be created for people authorised to act in a professional setting.
If a customer processes data concerning a minor in Manager5, that customer is responsible for the lawfulness of the processing, the appropriate legal basis, required notices and limiting the data to what is necessary. TJSOFT processes such Customer Data only as a processor and in accordance with the agreement.
15. Security
We apply organisational and technical measures appropriate to the nature of the data, the way it is used and the relevant risks. These measures include access controls, account protection, permission limits, backups, event monitoring and incident response procedures.
No online service can eliminate all risk. Customers and users should protect sign-in details, grant access only to authorised persons and promptly report suspected security incidents.
16. Changes to this notice
We may update this notice if our processing, the service or applicable law changes. A new version will state its publication date and effective date. A change to this notice does not by itself amend rights and obligations under an existing agreement.
17. Contact
Privacy questions, requests and reports may be sent to:
Document hash
d7412e344c353e58c3f36b3804fb126b1afe91b3cbdfac104f8ffd72db860294