plen

Privacy Policy

Last updated:

This Privacy Policy explains how WebImpact processes personal data in connection with the use of the "WebImpact AI Marketing Studio" platform. It describes what data we collect, for what purposes and on what legal bases, to whom we entrust it, and what rights are available to data subjects, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

1. Data controller and processing roles

The data controller within the meaning of the GDPR is Web Impact Sp. z o.o. sp. k., with its registered office at Rynek Główny 28, 31-010 Kraków, Poland, entered in the register of entrepreneurs of the Polish National Court Register (KRS) under number 0000754465, VAT identification number (NIP) 6762556673 (hereinafter: "WebImpact", "we", "us").

WebImpact acts in two different roles, depending on the category of data. With respect to account data, registration data, login data and data on Users' use of the platform - WebImpact is the data controller of that data and independently determines the purposes and means of its processing.

With respect to data that the Client (the company using the platform) enters or generates in its separate workspace about its own customers or contractors - for example, data of the Client's own end customers managed in the training studio, data contained in uploaded documents, or the personnel data of the Client's employees - WebImpact acts as a data processor on the instruction of and on behalf of the Client. In such a case, the data controller of that data is the Client, and WebImpact processes it solely on the documented instruction of the Client, on the basis of a concluded data processing agreement (DPA).

If you are a person whose data reached the platform through one of our Clients (e.g. as a customer enrolled for sessions in a training studio run by that company), the data controller of your data is that Client, and this Policy describes only the extent to which WebImpact processes that data as a processor. In matters concerning such data, the appropriate addressee of requests is, in the first instance, that Client.

2. Contact regarding personal data

In all matters concerning the processing of personal data and the exercise of your rights, you may contact us at the email address: [email protected] or by correspondence to WebImpact's registered office address.

3. Scope of data processed

The scope of the data processed depends on how the platform is used and on which modules have been enabled for a given company. In particular, we process the following categories of data:

  • Account and profile data - full name, business email address, assigned company (workspace) and the User's role determining the scope of access.
  • Login and authentication data - data necessary for secure login, including, in the case of login via a Google account, the email address and basic identification data provided by the login provider; we do not store passwords in plain text.
  • Data on the use of the platform - information on activity in the panel, use of modules and limits, events recorded in the audit log, and basic technical data (e.g. timestamps of operations).
  • Uploaded and generated content - materials entered by the User (e.g. product photos, reference files, briefs, documents) and the results generated by the platform, saved in the company's Asset Library.
  • Data of the Client's end customers (where the training studio module is enabled) - contact details, training goals, health notes, attendance history and the signature confirming participation in a session.
  • Personnel data (where the HR module is enabled) - data of the Client's employees concerning working time, attendance records, and leave and absence requests.
  • Contextual materials about the company - a description of the offering, tone of voice and facts about the Client, prepared on the WebImpact side and used by the generation modules.

4. Purposes and legal bases of processing

We process personal data solely for specific, explicit and legitimate purposes, on the following legal bases:

  • Provision of the service and performance of the contract - setting up and maintaining the account, making the enabled modules available, generating and storing results in the Asset Library, and providing User support (Article 6(1)(b) GDPR).
  • The legitimate interest of the controller - ensuring the security of the platform and data, preventing abuse, maintaining an event and audit log, developing and improving the service, and pursuing or defending against any potential claims (Article 6(1)(f) GDPR).
  • The consent of the data subject - to the extent that it is required for a given activity; consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal (Article 6(1)(a) GDPR).
  • Compliance with legal obligations incumbent on the controller - to the extent arising from the provisions to which we are subject (Article 6(1)(c) GDPR).
  • With respect to data processed as a processor on the Client's instruction, the basis and purpose of processing are determined by the Client as controller; we process it in accordance with its instructions and the data processing agreement (DPA).

5. Recipients of data and data processors (sub-processors)

In order to provide the service, we use trusted external providers who process data solely on our behalf, on the basis of concluded data processing agreements and only to the extent necessary to provide the service. We describe the recipients by category:

  • AI model providers - processing the content submitted to generate a result (e.g. text, image, video, voice).
  • Cloud infrastructure providers - in respect of application hosting and the storage of files and data (storage).
  • Authentication provider - in respect of handling login and identity management.
  • Email provider - in respect of sending transactional messages and notifications.
  • Providers of tools for error monitoring and maintaining the reliability of the service.
  • Advisers and service providers supporting us in conducting our business (e.g. legal and accounting services), to the extent necessary.

6. List of sub-processors

We publish the current list of sub-processors - with provider names, the purpose of processing, the place of processing and the basis for any transfer outside the EEA - at /en/subprocessors. The list also constitutes an annex to the data processing agreement (DPA).

We give the Client at least 30 days' notice of any intention to add a new sub-processor or replace an existing one, by updating that list and notifying the Client; the Client may raise a reasoned objection within that period. We also provide the list as a contractual annex on request, at [email protected].

7. Transfers of data outside the European Economic Area (EEA)

Some of our providers may process data outside the European Economic Area. In such cases, we ensure that the transfer takes place on the basis of appropriate mechanisms provided for in the GDPR - primarily the Standard Contractual Clauses (SCC) approved by the European Commission, supplemented where necessary by additional security measures, or on the basis of an adequacy decision.

We provide information on the safeguards applied to a specific transfer on request, at [email protected].

8. Data retention period

We store personal data for as long as it is necessary to provide the service and for the period required by law or justified by the need to pursue or defend against claims.

  • Account data and the content associated with it - for the duration of the contract and while the account is maintained; after its deletion, the data is deleted or anonymised, subject to data that we are required to retain under the law.
  • Personal data of third parties (the Client's end customers, employees) - for the period the module that collects it is in use, or in accordance with the instructions of the Client who is the controller of that data. Independently of the Client's instructions we apply our own maximum periods: the attendance signature and any notes on state of health are erased after 12 months, session notes and the contact details of closed client records after 24 months. The record that a given service took place (date, status, package settlement) remains, as it forms the Client's settlement documentation.
  • Results in the Asset Library - for as long as the platform is used. We deliberately do NOT erase them on a time limit: they are materials produced to the Client's order and owned by the Client, and the criterion for their erasure is the end of the engagement, not the age of the file. The Client erases them from the panel (individually or through the company data-erasure function); an erased item disappears from storage immediately, and the description it was created under is erased after 30 days.
  • Generation history (the job log) - the entry holding the date, module, title, status and cost is kept for the purposes of settlement with the Client and its verification. The content of the job, including uploaded reference material and error messages, is erased after 12 months.
  • Personnel data - for the period during which the relevant module is used or in accordance with the instructions of the Client as controller; the justifications given in leave requests are erased 12 months after the leave ends.
  • Data export and the erasure of generated content are available in the panel immediately and on a self-service basis. A request to delete the account is also filed from the panel; we handle it within one month of filing (Article 12(3) GDPR). Where the account is the sole owner account of a company, completion requires ownership to be transferred to another person first - we say so at the point the request is filed.

9. Rights of the data subject

In connection with the processing of personal data, you have the following rights:

  • The right of access to the data and to obtain a copy of it.
  • The right to rectification (correction) of inaccurate or incomplete data.
  • The right to erasure of data ("the right to be forgotten") in the cases provided for in the GDPR.
  • The right to restriction of processing.
  • The right to data portability, including its export in a structured, commonly used format.
  • The right to object to processing based on legitimate interest.
  • The right to withdraw consent at any time, where processing is based on it, without affecting the lawfulness of processing prior to withdrawal.
  • The right to lodge a complaint with the supervisory authority - the President of the Personal Data Protection Office (in Poland, the PUODO).
  • To exercise the above rights, write to us at [email protected]. Some of these rights - in particular the export and deletion of data - you can exercise yourself from within the panel. If the data to which a request relates is processed by us as a processor on the Client's instruction, we will forward your request to the appropriate controller (the Client) or ask you to direct it to that controller directly.

10. Data security

We apply appropriate technical and organisational measures ensuring the protection of personal data adequate to the risk, including:

  • Data isolation between companies - each company uses a separate, isolated workspace and has access only to its own data and to the modules enabled for it.
  • Role-based access control - the scope of a User's permissions results from the role assigned to them, in accordance with the principle of access minimisation.
  • Event and audit log - key operations are recorded, which enables accountability and the detection of irregularities.
  • Encryption in transit - data transmitted between your device and the platform is protected by encrypted connections.
  • Restricted staff access - only authorised persons have access to the data, to the extent necessary to perform their duties.

11. Cookies and session

The platform uses necessary cookies and session mechanisms required for the proper functioning of the service - in particular, to maintain the logged-in state and the security of the User's session. Without these files, logging in and using the panel would not be possible.

Necessary cookies do not require consent, as they serve solely to provide the requested service. If, in the future, we introduce cookies of an analytical or marketing nature, they will be used solely on the basis of separate consent.

12. Changes to the Privacy Policy

This Policy may be updated periodically, in particular in connection with changes in the functioning of the platform, the scope of services, or the applicable law. We will notify you of material changes in an appropriate manner, e.g. via the platform or by email.

The current version of the Policy is always available within the platform. We encourage you to review its content periodically.

13. Contact and effective date

For matters related to this Privacy Policy and the protection of personal data, please contact us at the email address: [email protected]. The law applicable to this Policy is Polish law.

Effective date: August 25, 2026.