Skip to content

Lenslist AdminHub · Updated 2 October 2026

Privacy policy

How we handle identity, account security and administrative activity when you use Lenslist AdminHub.

Who is responsible

This policy covers Lenslist AdminHub at admin.backoffice.lenslist.co, the administration workspace for Lenslist and XR Bazaar. The controller is Lenslist sp. z o.o., ul. Solec 81B/73A, 00-382 Warsaw, Poland, KRS 0000929279, NIP 5213944791. Contact [email protected] about this policy or your personal data.

This policy describes administration accounts and activity. Public content managed through AdminHub may also be covered by the privacy notices of the service where it appears.

Information we handle

Account information includes your name, email address, identity-provider identifier and verification status, and profile image when provided. We also maintain invitations, organization and group membership, permissions, and linked agent or application authorizations.

Security and operational information can include session identifiers, authentication and MFA status, IP addresses, browser or device information, request times, errors, and records of administrative actions. WorkOS processes authentication credentials and authentication factors. A passkey’s private key remains with its authenticator.

Administrative records include changes you submit, approval decisions, notes, uploaded media, agent operations and the identity responsible for an action. Depending on your permissions, these records may contain personal information about creators, collaborators or other users. Do not add personal information that is unnecessary for the task.

Google sign-in

When you choose Google sign-in, Google and WorkOS verify your identity and provide basic identity information such as your account identifier, email address, verification status, name and profile image. AdminHub uses this information to identify your account and check access. Signing in does not grant organization membership or permissions by itself.

AdminHub Google sign-in does not request access to Gmail messages, Google Drive files, contacts or calendars. We do not use Google sign-in information for advertising or sell it. You can remove the connection through your Google Account’s third-party connections settings; this does not by itself delete AdminHub records or revoke every existing AdminHub session.

Why we use this information

We use information to admit authorized users, operate the workspace, deliver requested administrative functions, support collaboration and agent access, and respond to support requests. Where needed to perform our agreement with you, the legal basis is Article 6(1)(b) GDPR.

Access control, security monitoring, incident investigation, audit trails and protecting the service rely on our legitimate interests under Article 6(1)(f) GDPR. Where processing is required by law, Article 6(1)(c) applies. Providing account information is necessary to use protected functions; you may read this homepage and legal information without an account.

Who receives information

Authorized administrators and collaborators can see information within the access granted to them. Content you publish can become visible on the connected public service. A connected agent can receive data only through its authorized access; when you connect an external agent, consider the operator and provider of that agent before granting access.

We use WorkOS for authentication and account security, Amazon Web Services for hosting and infrastructure, and Cloudflare for network delivery and protection. These providers process information needed to provide their services. We may also disclose information to professional advisers or public authorities when necessary to meet legal obligations or protect rights.

Service providers may process information outside the European Economic Area. Applicable safeguards, such as an adequacy decision or standard contractual clauses, are required for such transfers. Contact [email protected] for information about the safeguards applicable to your data.

Retention and security

Where a record has a configured retention period, that schedule applies. Account and administrative records without an automatic deletion schedule are retained until removal is requested, unless they are deleted earlier because they are no longer needed. Send removal requests to [email protected]. We assess requests under applicable law; information needed to meet legal obligations or establish, exercise or defend legal claims may need to be retained. Ending access, or the expiry of a session or invitation, does not itself delete the underlying record. Backups and archives are subject to their own retention schedules and applicable preservation requirements.

We restrict access through authentication and permissions, and use security controls for stored information and transmission. No service can guarantee absolute security. Report suspected unauthorized access to [email protected] promptly.

Cookies and browser storage

AdminHub uses cookies and browser storage to maintain authenticated sessions, protect sign-in flows and remember interface preferences. Blocking essential cookies can prevent sign-in or account security functions from working. Hosted authentication pages and your identity provider also use storage governed by their own notices.

Your rights and requests

Subject to applicable law, you may request access, correction, deletion, restriction or portability of your personal data, and object to processing based on legitimate interests. If a use relies on consent, you may withdraw it without affecting earlier lawful processing. We may need to verify your identity before responding.

Send requests to [email protected]. You may also complain to the Polish President of the Personal Data Protection Office at uodo.gov.pl or another competent supervisory authority. Removal of account access and deletion of personal data are separate requests; records may need to remain where a lawful retention obligation applies.

Changes to this policy

We will update this page when our practices change and identify its revision date. Where a change materially affects your rights or requires notice or consent, we will provide the information required by applicable law.