plen

Privacy Policy

Last updated:

This Privacy Policy explains how WebImpact processes personal data in connection with the use of the "WebImpact AI Marketing Studio" platform. It describes what data we collect, for what purposes and on what legal bases, to whom we entrust it, and what rights are available to data subjects, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR (Regulation (EU) 2016/679)).

1. Data controller and processing roles

The data controller within the meaning of the GDPR is [TO BE COMPLETED: the full name and legal form of the company], with its registered office at [TO BE COMPLETED: registered office address], entered in the register under number [TO BE COMPLETED: KRS number or other relevant register number], VAT identification number (NIP) [TO BE COMPLETED: NIP] (hereinafter: "WebImpact", "we", "us").

WebImpact acts in two different roles, depending on the category of data. With respect to account data, registration data, login data and data on Users' use of the platform — WebImpact is the data controller of that data and independently determines the purposes and means of its processing.

With respect to data that the Client (the company using the platform) enters or generates in its separate workspace about its own customers or contractors — for example, leads and contact data obtained during calls handled by the voice agent, chatbot conversation content, data contained in uploaded documents, or the personnel data of the Client's employees — WebImpact acts as a data processor on the instruction of and on behalf of the Client. In such a case, the data controller of that data is the Client, and WebImpact processes it solely on the documented instruction of the Client, on the basis of a concluded data processing agreement (DPA).

If you are a person whose data reached the platform through one of our Clients (e.g. as a person calling a company that uses the voice agent), the data controller of your data is that Client, and this Policy describes only the extent to which WebImpact processes that data as a processor. In matters concerning such data, the appropriate addressee of requests is, in the first instance, that Client.

2. Contact regarding personal data

In all matters concerning the processing of personal data and the exercise of your rights, you may contact us at the email address: [email protected] or by correspondence to WebImpact's registered office address.

[TO BE COMPLETED: contact details of the data protection officer (DPO), if one has been appointed — full name, email address; otherwise this section may be omitted].

3. Scope of data processed

The scope of the data processed depends on how the platform is used and on which modules have been enabled for a given company. In particular, we process the following categories of data:

  • Account and profile data — full name, business email address, assigned company (workspace) and the User's role determining the scope of access.
  • Login and authentication data — data necessary for secure login, including, in the case of login via a Google account, the email address and basic identification data provided by the login provider; we do not store passwords in plain text.
  • Data on the use of the platform — information on activity in the panel, use of modules and limits, events recorded in the audit log, and basic technical data (e.g. timestamps of operations).
  • Uploaded and generated content — materials entered by the User (e.g. product photos, reference files, briefs, knowledge documents) and the results generated by the platform, saved in the company's Asset Library.
  • Data related to the voice agent and the chatbot (where the module is enabled) — recordings and summaries of conversations, transcripts, telephone numbers, and data necessary to return a call or handle a request, as well as lead data provided during a conversation.
  • Personnel data (where the HR module is enabled) — data of the Client's employees concerning working time, attendance records, and leave and absence requests.
  • Knowledge documents and contextual materials — documents and information that the Client adds in order to supply the modules with knowledge about its company.

4. Purposes and legal bases of processing

We process personal data solely for specific, explicit and legitimate purposes, on the following legal bases:

  • Provision of the service and performance of the contract — setting up and maintaining the account, making the enabled modules available, generating and storing results in the Asset Library, and providing User support (Article 6(1)(b) GDPR).
  • The legitimate interest of the controller — ensuring the security of the platform and data, preventing abuse, maintaining an event and audit log, developing and improving the service, and pursuing or defending against any potential claims (Article 6(1)(f) GDPR).
  • The consent of the data subject — to the extent that it is required for a given activity; consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal (Article 6(1)(a) GDPR).
  • Compliance with legal obligations incumbent on the controller — to the extent arising from the provisions to which we are subject (Article 6(1)(c) GDPR).
  • With respect to data processed as a processor on the Client's instruction, the basis and purpose of processing are determined by the Client as controller; we process it in accordance with its instructions and the data processing agreement (DPA).

5. Recipients of data and data processors (sub-processors)

In order to provide the service, we use trusted external providers who process data solely on our behalf, on the basis of concluded data processing agreements and only to the extent necessary to provide the service. We describe the recipients by category:

  • AI model providers — processing the content submitted to generate a result (e.g. text, image, video, voice).
  • Cloud infrastructure providers — in respect of application hosting and the storage of files and data (storage).
  • Authentication provider — in respect of handling login and identity management.
  • Email provider — in respect of sending transactional messages and notifications.
  • Providers of tools for error monitoring and maintaining the reliability of the service.
  • Advisers and service providers supporting us in conducting our business (e.g. legal and accounting services), to the extent necessary.

6. List of sub-processors

We do not disclose the trade names of specific providers in the text of this Policy. We make the current, complete list of sub-processors available on request; it also constitutes an annex to the data processing agreement (DPA). To obtain it, contact us at [email protected].

7. Transfers of data outside the European Economic Area (EEA)

Some of our providers may process data outside the European Economic Area. In such cases, we ensure that the transfer takes place on the basis of appropriate mechanisms provided for in the GDPR — primarily the Standard Contractual Clauses (SCC) approved by the European Commission, supplemented where necessary by additional security measures, or on the basis of an adequacy decision.

We provide information on the safeguards applied to a specific transfer on request, at [email protected].

8. Data retention period

We store personal data for as long as it is necessary to provide the service and for the period required by law or justified by the need to pursue or defend against claims.

  • Account data and the content associated with it — for the duration of the contract and while the account is maintained; after its deletion, the data is deleted or anonymised, subject to data that we are required to retain under the law.
  • Personal data contained in the recordings and logs of voice agent and chatbot conversations — for a limited period necessary to fulfil the purpose, after which it is deleted; retention may be configured in accordance with the arrangements made with the Client who is the controller of that data.
  • Results in the Asset Library and personnel data — for the period during which the relevant modules are used or in accordance with the instructions of the Client as controller.
  • Data may be exported and deleted at any time from within the panel, to the extent made available by the platform's features.

9. Rights of the data subject

In connection with the processing of personal data, you have the following rights:

  • The right of access to the data and to obtain a copy of it.
  • The right to rectification (correction) of inaccurate or incomplete data.
  • The right to erasure of data ("the right to be forgotten") in the cases provided for in the GDPR.
  • The right to restriction of processing.
  • The right to data portability, including its export in a structured, commonly used format.
  • The right to object to processing based on legitimate interest.
  • The right to withdraw consent at any time, where processing is based on it, without affecting the lawfulness of processing prior to withdrawal.
  • The right to lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (in Poland, the PUODO).
  • To exercise the above rights, write to us at [email protected]. Some of these rights — in particular the export and deletion of data — you can exercise yourself from within the panel. If the data to which a request relates is processed by us as a processor on the Client's instruction, we will forward your request to the appropriate controller (the Client) or ask you to direct it to that controller directly.

10. Data security

We apply appropriate technical and organisational measures ensuring the protection of personal data adequate to the risk, including:

  • Data isolation between companies — each company uses a separate, isolated workspace and has access only to its own data and to the modules enabled for it.
  • Role-based access control — the scope of a User's permissions results from the role assigned to them, in accordance with the principle of access minimisation.
  • Event and audit log — key operations are recorded, which enables accountability and the detection of irregularities.
  • Encryption in transit — data transmitted between your device and the platform is protected by encrypted connections.
  • Restricted staff access — only authorised persons have access to the data, to the extent necessary to perform their duties.

11. Cookies and session

The platform uses necessary cookies and session mechanisms required for the proper functioning of the service — in particular, to maintain the logged-in state and the security of the User's session. Without these files, logging in and using the panel would not be possible.

Necessary cookies do not require consent, as they serve solely to provide the requested service. If, in the future, we introduce cookies of an analytical or marketing nature, they will be used solely on the basis of separate consent.

12. Changes to the Privacy Policy

This Policy may be updated periodically, in particular in connection with changes in the functioning of the platform, the scope of services, or the applicable law. We will notify you of material changes in an appropriate manner, e.g. via the platform or by email.

The current version of the Policy is always available within the platform. We encourage you to review its content periodically.

13. Contact and effective date

For matters related to this Privacy Policy and the protection of personal data, please contact us at the email address: [email protected]. The law applicable to this Policy is Polish law.

Effective date: [to be completed upon publication].