back to 24/7 365

Terms & privacy

This is the entire legal compartment.

Covers 247365.pl and its extensions like auditcrowd.247365.pl. Last updated: 30 August 2026.

1. Who runs 247365.pl

I do: Rafał Ochmański, a sole trader registered in Poland (the business name is "Rafał Ochmański Ochmanski.com"). I alone am the party to everything here: the provider of the services, and the controller of the personal data described below.

You can reach me at the mailboxes in the site footers. For anything about your personal data, write to privacy@247365.pl.

2. What these sites are

247365.pl is my portfolio. It also carries the updates/newsletter list (§4.4).

auditcrowd reads Polish financial statement files (the XML you download from the National Court Register) and analyzes them in your browser. It also keeps a shared dataset of those public filings for enrichment and analyses across sessions and users (§4.2 and §4.3).

Self-service tools are free. Paid work — consulting, custom analyses, anything beyond self-serve — happens only by individual agreement, usually formed over email. Mentions of paid services anywhere on these sites are invitations to talk, not offers.

3. Rules of use

  • Everything is provided as-is and without warranty: no guarantee of availability, correctness, or continued existence, and no service level agreement. Features may change or retire without notice.
  • The numbers you see come from filings, which are usually just declarations, not necessarily error-free, then parsed here by enthusiastically vibecoded software, definitely not bug-free. Before making any consequential decision, manually review the source documents in the KRS.
  • Nothing on these sites is investment, legal, tax, or accounting advice.
  • The shared dataset is meant for public registry documents. Technically you can drop anything into it, and while I do some filtering, whatever you drop will be treated as a public registry document — upload accordingly.
  • Use the sites like a person, not like a botnet. Don't hammer the API or bulk-scrape the dataset. If you upset the WAF, your access may be limited.
  • My liability is limited to the fullest extent Polish law allows. Where the law gives you rights that can't be limited — consumer rights in particular — those stand untouched.
  • Technically, you need a current browser and Internet access. That's the whole requirement to use the site.

4. Privacy

4.1 In your browser

There are no accounts, no cookies, and no tracking — mostly because I don't see the value in any of them. Your theme, language, and any notes you write are kept in your browser's local storage; clearing your browser data deletes them. Analytics, where they run, are Cloudflare's cookieless kind: aggregate counts, nothing that follows you anywhere. Like every server on the internet, mine keep ordinary access logs (IP address and request) for security, deleted after 60 days at the latest.

4.2 auditcrowd: your file and the shared dataset

The analysis happens in your browser. Dropping a statement also uploads it to the shared auditcrowd dataset, where it is parsed and kept for future enrichment — so others (and you) get more data without hunting. These are public registry documents, and they name real people: board members and the officers who signed them. To be precise, the original files are stored, personal data and signature blocks included, but the enrichment uses none of that and the public pages display none of it. The legal basis for keeping these filings usable is legitimate interest (Art. 6(1)(f) GDPR) — the documents are public by law, and this is a better way to read them. Comments, corrections, objections, see §5.

4.3 The KRS mirror

auditcrowd also keeps its own copy of the public National Court Register (KRS), to power search, suggestions, and enrichment.

  • The source is the register's official open API (api-krs.ms.gov.pl, operated by the Ministry of Justice). The register is public by statute, and the mirror follows it with regular updates.
  • I keep the raw API responses, which contain exactly what the ministry itself publishes — including officers' and notaries' data in the ministry's own masking. This raw copy is internal. The basis for keeping it is legitimate interest (Art. 6(1)(f) GDPR), the data originating verbatim from a statutorily public register.
  • Everything user-facing is built from an extraction of the above, without the officers section. The search index hosted on Cloudflare is a further subset of that.
  • Worth knowing: some lookups in the app query the KRS API live from your browser, so your own machine contacts the ministry's API directly, as if you had opened the register yourself.

The authoritative source of register data is the KRS itself.

4.4 The updates list

That summary is accurate; here it is in full:

  • Signup is double opt-in. Nothing is subscribed until you click the link in the confirmation email. Unconfirmed signups are deleted after 7 days.
  • Stored: your email address, your language, the timestamps of your signup and confirmation, the random tokens that make your confirm/unsubscribe links work — and a log of which issues were sent to your address, when.
  • Not stored: your IP address (rate limiting uses a salted daily hash, unreadable and purged within 24 hours). The emails contain no tracking.
  • By subscribing you agree to hear about my projects and services, including commercial ones — that's the whole scope. This consent is the legal basis for the sending (Art. 6(1)(a) GDPR and the Polish electronic-communications law's consent for commercial information).
  • Every email has a one-click unsubscribe link. Using it withdraws your consent and deletes your subscriber record. What remains afterwards: a suppression entry (so your address can't be silently re-added) and the sending log — kept as evidence that the sending was lawful (Art. 6(1)(f) GDPR).

4.5 Email and orders

If you write to any of my mailboxes, I process your address and what you wrote, to answer you. If we reach a commercial agreement, this includes the terms and invoice details. The bases are the contract we're forming (Art. 6(1)(b) GDPR) and my legitimate interest in handling correspondence and possible claims (Art. 6(1)(f)).

I keep correspondence the way people usually keep email — indefinitely, in the mail archive and its backups, with no realistic mechanism for purging a single thread from either. So I make no deletion promises about ordinary correspondence.

4.6 Infrastructure

Everything runs on infrastructure in the EU or in countries the EU recognizes as adequate, under data processing agreements with each provider:

ProviderWhat runs thereWhere
Cloudflare, Inc.site hosting, forms, the subscriber database, the KRS search index, email routingdatabase in Frankfurt; global edge network under Cloudflare's standard DPA (SCCs / EU–US DPF)
Oracle (OCI)the auditcrowd API, its databases (including the KRS mirror), and the original statement filesZurich — Switzerland holds an EU adequacy decision
Backblaze, Inc.backupsEU region; backups are encrypted on my side before upload — Backblaze cannot read them
Vercom S.A. (EmailLabs)delivery of the updates emailsPoland, processing within the EEA only

4.7 Your rights

You have the GDPR set: access, rectification, erasure, restriction, objection, and portability. Write to gdprstuff@247365.pl and I'll answer within a month. You can also complain to the Polish supervisory authority, UODO (uodo.gov.pl).

Two practical notes. For the updates list you don't need to ask anyone — the unsubscribe link in every email is the fastest way to exercise everything at once. And erasure requests are assessed individually when they arrive: some records may be retained where the law permits it, in particular as evidence for the defense of claims (Art. 17(3)(e) GDPR).

5. You're named in a filing — or in the register

If you appear in a stored statement (as a board member or signatory) or in my copy of the KRS (exactly as the ministry publishes you), and you want to talk about your data, write to heythatsme@247365.pl. Here's how I handle it: I check what's actually stored versus what's shown — the public pages display no personal data (§4.2, §4.3) — and I assess your request individually, starting from the fact that the source is a public register: removing something here removes nothing from the registry it came from. For register records the real fix belongs at the KRS itself — the mirror follows the register, so corrections made there arrive here on their own. Where removal or redaction on my side is justified, I'll do it. This is also the channel for objections under Art. 21 GDPR, and for reporting a document that was filed to the registry in error.

6. Changes, law, language

When this document changes, the new version applies from publication and the date at the top moves. Polish law governs. This document is published in Polish and English; if the two ever disagree, the Polish text prevails.