ServiceConnectPeak // Integration Hub Online
ServiceConnectPeak API & Integration
Home / Legal
Compliance Schedule

Legal & Governance Documentation

Chronological compliance schedule detailing data retention, handling lifecycle, client rights, and security audit protocols for all integration services.

Last Revised: September 2026 // ServiceConnectPeak

01

Privacy Policy

Data Collection, Processing & Retention

1.1 Data Controller

ServiceConnectPeak (hereinafter "the Company"), registered at ul. Narutowicza 35, 20-016 Lublin, Poland, acts as the data controller for all personal information collected through our website, integration platforms, and client communication channels. All data processing activities comply with Regulation (EU) 2016/679 (General Data Protection Regulation).

1.2 Categories of Personal Data

We collect and process the following categories of personal data:

  • • Contact identifiers: full name, business email address, phone number
  • • Organization data: company name, job title, business jurisdiction
  • • Integration metadata: API endpoint configurations, data schema descriptions
  • • Usage telemetry: platform access logs, service utilization metrics

1.3 Legal Basis for Processing

Personal data is processed under Article 6(1)(b) of the GDPR (performance of a contract) for service delivery, and Article 6(1)(f) (legitimate interest) for security monitoring and service improvement. Consent-based processing under Article 6(1)(a) is applied only where explicitly requested.

1.4 Data Retention Schedule

Client contact data is retained for the duration of the active business relationship plus 36 months following the final invoice settlement. Integration metadata and API configurations are purged within 90 days of project completion unless an active SLA retainer is in effect. Security audit logs are retained for 24 months per regulatory requirement.

1.5 Data Subject Rights

In accordance with Articles 15–22 of the GDPR, you have the right to access, rectify, erase, restrict processing, and port your personal data. To exercise these rights, contact our Data Protection Officer at [email protected]. Requests are processed within 30 calendar days.

02

Terms of Service

Service Agreement & Intellectual Property

2.1 Scope of Services

ServiceConnectPeak provides API integration engineering, middleware development, data connector implementation, and integration support services as described in individual Statements of Work (SOW) executed between the Company and the Client. All deliverables are defined exclusively within the executed SOW.

2.2 Intellectual Property Transfer

Upon full settlement of all commercial invoices associated with a given SOW, ServiceConnectPeak assigns all worldwide intellectual property rights in client-specific software deliverables, custom API code, integration configurations, and documentation directly to the Client. The Company retains no license, lien, or encumbrance over completed work product.

2.3 Client Obligations

The Client is responsible for providing accurate system access credentials, API keys, and technical documentation required for integration delivery. Delays in providing required access may extend delivery timelines proportionally. The Client shall maintain responsibility for the security of their own API credentials following handover.

2.4 Limitation of Liability

ServiceConnectPeak's aggregate liability under any SOW shall not exceed the total fees paid by the Client for the specific service giving rise to the claim. The Company shall not be liable for indirect, consequential, or incidental damages arising from integration performance, including data loss or third-party service interruptions.

2.5 Termination

Either party may terminate an SOW with 30 days written notice. Upon termination, the Client shall pay for all work completed up to the termination date. Completed deliverables and source code are transferred to the Client regardless of termination status.

03

Cookie Policy

Session Cookies & Tracking Technologies

3.1 Essential Cookies

ServiceConnectPeak employs strictly necessary cookies to maintain secure session integrity, authenticate user requests, and enable middleware routing. These cookies are required for the website to function and cannot be disabled. They are stored in your browser and persist for the duration of your session or until explicitly cleared.

3.2 Functional Cookies

Functional cookies enable personalized features such as cookie consent persistence and form state retention. These cookies do not track browsing activity across other websites. You may disable functional cookies through your browser settings, though certain site features may become unavailable.

3.3 No Third-Party Tracking

ServiceConnectPeak does not utilize third-party advertising cookies, social media trackers, or cross-site tracking pixels. We do not sell or share cookie data with advertising networks. Analytics data, if collected, is processed internally using privacy-respecting telemetry tools with IP anonymization enabled.

3.4 Managing Cookies

You can manage cookie preferences through our cookie consent banner displayed on your first visit, or by adjusting your browser settings. Clearing your browser cookies will restore the consent banner on your next visit. For questions about our cookie practices, contact [email protected].

04

Refund & Reimbursement Policy

Financial Terms & Reimbursement Schedule

4.1 Pre-Project Deposits

A 50% deposit is required to initiate any integration project. This deposit is non-refundable once the Company has commenced work on the project, including system audit, architecture design, or any development activity. Prior to commencement, deposits are fully refundable within 14 calendar days of payment.

4.2 Milestone-Based Payments

Projects exceeding $2,000 USD are structured with milestone-based payment schedules. Each milestone payment becomes non-refundable upon delivery and acceptance of the corresponding deliverable. Deliverable acceptance is confirmed by the Client via written approval or continued use of the delivered functionality.

4.3 Subscription & Retainer Refunds

Monthly SLA retainer subscriptions may be cancelled at any time with 30 days written notice. No partial-month refunds are issued for retainer services already rendered. Annual retainer commitments are refundable on a prorated basis for unused months, subject to a 15% administrative processing fee.

4.4 Dispute Resolution

Refund requests must be submitted in writing to [email protected] within 30 calendar days of the invoice date. Disputes shall first be addressed through good-faith mediation. If mediation fails, disputes shall be resolved under the jurisdiction of the Lublin District Court, Poland.

4.5 Processing Timeline

Approved refunds are processed within 14 business days to the original payment method. Bank transfer refunds may require additional processing time depending on the financial institution. The Client will receive email confirmation once a refund has been initiated.

05

Security & Compliance Audits

Infrastructure Security & Audit Schedule

5.1 Infrastructure Security

All integration middleware and API endpoints are hosted on SOC 2 Type II compliant cloud infrastructure with AES-256 encryption at rest and TLS 1.3 in transit. Server access is controlled via role-based access control (RBAC) with mandatory multi-factor authentication for all administrative operations.

5.2 Internal Audit Schedule

ServiceConnectPeak conducts quarterly internal security audits covering vulnerability scanning, dependency patching, access review, and penetration testing. Annual external audits are performed by independent third-party assessors. Audit reports are available to clients upon request under a mutual NDA.

5.3 Incident Response

In the event of a security incident affecting client data, ServiceConnectPeak will notify affected clients within 72 hours of discovery, in accordance with GDPR Article 33. Notification will include the nature of the incident, data categories affected, mitigation measures taken, and contact information for our Data Protection Officer.

5.4 Sub-Processor Management

ServiceConnectPeak maintains a current list of sub-processors involved in service delivery. Clients will be notified of any changes to sub-processor arrangements with 30 days advance notice. All sub-processors are contractually bound to equivalent data protection obligations.

Data Controller: ServiceConnectPeak | ul. Narutowicza 35, 20-016 Lublin, Poland
Data Protection Officer: [email protected]