Privacy Policy
Version 1.0 | Effective Date: December 1, 2025
Data Controller: MysticX, e-mail: contact@mysticx.vip
1. Data Processed
The Administrator processes only minimal data necessary for service delivery:
| Data Type | Purpose | Source |
| Nickname / Telegram ID | Customer identification, access delivery | Provided by user |
| Order ID | Order identification | Auto-generated |
| List of purchased content | Order fulfillment | System |
| Purchase date | Transaction documentation | System |
| Access status | Technical support | System |
The Administrator does NOT collect:
- Personal data (name, surname, address)
- Credit/payment card data
- IP addresses (beyond standard server logs)
- Sensitive data
2. Purpose and Legal Basis
2.1. Contract Performance (Art. 6(1)(b) GDPR)
- Delivery of access to digital content after payment
- Generation of unique access tokens/links
- Link delivery via Telegram bot
2.2. Complaint Handling and Technical Support
- Ability to restore access in case of technical problems
- Link regeneration in case of loss
- Responding to customer inquiries
2.3. Legitimate Interest (Art. 6(1)(f) GDPR)
- Protection against abuse
- Transaction documentation for tax/legal purposes
3. Scope and Data Retention Period
3.1. Retention Period
- Order data: maximum 3 years from purchase date
- Access tokens: 365 days (or according to purchased license)
- Technical logs: 30 days
3.2. Data Deletion
Data may be deleted earlier upon user request, provided:
- It does not conflict with active service delivery
- It is not required by law (e.g., tax documentation)
4. No Sensitive Data Collection
The Service:
- Does NOT collect sensitive data (health, orientation, political views, etc.)
- Does NOT collect credit card data (payments via external operators)
- Does NOT require registration or login
- Does NOT require residential address
5. User Rights (GDPR)
Users have the right to:
| Right | Description |
| Access | Information about processed data |
| Rectification | Correction of inaccurate data |
| Erasure | Request for data deletion ("right to be forgotten") |
| Restriction | Restriction of data processing |
| Portability | Receive data in structured format |
| Objection | Object to processing |
Response time: maximum 30 days.
6. Cookies / LocalStorage / Tracking
6.1. Mechanisms Used (technical only)
| Mechanism | Purpose | Data |
| localStorage | Cart memory | List of selected products |
| localStorage | Language preferences | "pl" or "en" |
| localStorage | Age verification | "ageVerified: true" |
| sessionStorage | User session | Temporary session data |
6.2. No Tracking
- The Service does NOT use analytics trackers (Google Analytics, Facebook Pixel, etc.)
- The Service does NOT use marketing trackers
- The Service does NOT use advertising cookies
- The Service does NOT profile users
7. Content Protection and License
7.1. Access Nature
- Content is provided as streaming / licensed access
- Content is NOT available for download
- License is non-exclusive and non-transferable
7.2. User Obligations
- User has no right to copy, distribute, or share content
- Upon license termination, user agrees to cease using content
8. Third Parties
8.1. Payment Operators
- Crypto Pay (cryptocurrency payments) - process payment data according to their own policy
- BLIK - processed through individual accounts
8.2. Infrastructure
- Bunny CDN - streaming hosting (does not process personal data)
- Airtable - order database (servers in EU/USA, GDPR compliant)
- Telegram - customer communication
8.3. Data Transfer
Data may be transferred to the USA (Airtable) based on Standard Contractual Clauses (SCC) ensuring adequate protection level.
9. Data Security
The Administrator implements appropriate technical and organizational measures:
- Transmission encryption (HTTPS/TLS)
- Unique access tokens
- Limited data access
- Regular security reviews
10. Privacy Policy Changes
- The Administrator reserves the right to change the Privacy Policy.
- Users will be informed of significant changes on the Service website.
- Current version always available at: mysticx.vip/legal/privacy-policy-en.html