Privacy and cookies policy
Who processes the data, for what purpose, on what legal basis, for how long, and to whom we entrust it. Without deferring to another document in the places that matter most.
This is an English rendering for convenience. The binding version is the Polish one, available at aivatary.com/pl/prywatnosc/. In case of discrepancy, the Polish text prevails.
Contents
- Controller and contact
- Scope and our two roles
- Whose data we process
- Where the data comes from
- What data we process
- Purposes and legal bases
- Legitimate interests
- Artificial intelligence systems
- Recipients
- Transfers outside the European Economic Area
- Retention
- What happens when the contract ends
- Your rights
- Marketing
- Automated decisions and profiling
- Security
- Cookies and browser storage
- Changes to this policy
Part I. In short
This part is a summary and does not replace the detail in Part II.
Who processes the data. MH Daniel Możdżyński, ul. Sędziwoja 49 lok. 3, 61-063 Poznań, Poland. For all data matters: contact@aivatary.com.
Why. To run your account, let the agent answer questions from your customers, settle payments, keep the platform secure and, with consent, send product information.
Three things worth knowing before you start:
- Conversation content is sent to a language model provider. Without it the agent could not phrase an answer. The contract is with an entity established in the European Union; details are in section 9 and in the separate subprocessor register.
- For conversations with your customers we are a processor, not a controller. You decide what goes into the knowledge base and how long conversations are kept. Section 2 sets out the split of roles.
- The agent answers only from content you published. An answer without coverage in the sources is never sent, so the scope of processing is set by your knowledge base, not by the model's training data.
What we do not do. We do not sell data. We do not profile anyone for advertising. We make no decisions producing legal effects solely by automated means. This website runs no analytics and no advertising tool, which is why there is no consent banner here: there is nothing to declare.
Part II. Detail
1. Controller and contact
- The controller is Daniel Możdżyński, a sole trader operating as MH Daniel Możdżyński, ul. Sędziwoja 49 lok. 3, 61-063 Poznań, Poland, tax number (NIP) 8522140767, statistical number (REGON) 811228847, entered in the Polish Central Register and Information on Business Activity (CEIDG).
- For all matters concerning personal data, write to contact@aivatary.com or to the registered address.
- We have not appointed a data protection officer. For all matters concerning personal data, use the address given in point 2.
2. Scope and our two roles
- This policy covers aivatary.com, the panel at app.aivatary.com and the widget our customers embed on their own sites.
- We act in two different roles, and that distinction is the most important thing in this document:
| Role | When | Whose data |
|---|---|---|
| Controller | Panel account, correspondence, billing, platform security, the conversation with Ada on this site | People representing our customer, operators in the panel, and people writing to us |
| Processor | Conversations the agent holds with our customer's customers, knowledge base content | End customer data. Our customer is the controller and we act on their instruction |
- For the second role the basis is the data processing agreement. A person whose data appeared in a conversation with our customer's agent addresses their request to that customer, and we provide technical support.
3. Whose data we process
- People creating and running an account in the panel.
- Operators granted access to the conversation inbox by our customer.
- People writing to our contact address or talking to Ada on this site.
- End customers of our customers, to the extent their data appears in a conversation.
4. Where the data comes from
- Directly from you, when creating an account, in correspondence and in conversation with the agent.
- From our customer, when they grant access to an operator.
- From automatic platform records, described in section 5.
5. What data we process
| Category | Contents |
|---|---|
| Account data | Email address, display name, role in the organisation, password hash |
| Organisation data | Name, identifier, allowed widget domains, retention settings |
| Conversation content | Messages sent and received, session identifier, channel, timestamps |
| Voice session data | Audio stream processed in real time, turn transcript, latency measurements |
| Knowledge base content | Articles, procedures and policies uploaded or imported by our customer |
| Technical records | IP address, browser type, audit log events, usage counters |
| Billing data | Invoice details, payment history, chosen deployment scope |
The audit log stores events after sensitive data is redacted. National identification numbers (checksum verified), IBAN numbers (mod 97 verified), phone numbers, email addresses, card numbers and tokens are replaced with markers before the event reaches the log at all.
6. Purposes and legal bases
| Purpose | Legal basis | Data categories |
|---|---|---|
| Running the account and providing the panel | Art. 6(1)(b) GDPR, performance of a contract | Account data, organisation data |
| Operating the agent and answering questions | Art. 6(1)(b) GDPR, and towards end customers acting on the controller's instruction | Conversation content, knowledge base content |
| Browser voice sessions | Art. 6(1)(b) GDPR | Voice session data |
| Billing and accounting records | Art. 6(1)(c) GDPR, legal obligation | Billing data |
| Platform security and abuse prevention | Art. 6(1)(f) GDPR, legitimate interest | Technical records |
| Handling enquiries and correspondence | Art. 6(1)(f) GDPR, legitimate interest | Account data, correspondence content |
| The conversation with Ada on this site | Art. 6(1)(f) GDPR, legitimate interest in presenting the product | Conversation content, technical records |
| Establishing and pursuing claims | Art. 6(1)(f) GDPR, legitimate interest | Account data, billing data, audit log |
| Product information | Art. 6(1)(a) GDPR, consent | Email address |
7. Legitimate interests
Where we rely on legitimate interest, we balanced it against the rights of the people concerned. The interest is keeping a working and secure platform, defending against abuse, and being able to show how the agent reached a particular decision. The scope is limited technically: the audit log accepts only redacted data, and technical records are not used to build a profile of anyone. A right to object applies, described in section 13.
8. Artificial intelligence systems
The agent uses a language model, and voice sessions additionally use speech recognition and synthesis. The scope of that processing, what happens to content sent to the model, and the rules of human oversight are set out in a separate document: the AI systems notice. It carries its own version and date, so changing a model provider does not force a change to the whole privacy policy.
9. Recipients
- We entrust data to entities providing our infrastructure and specific platform functions: the language model provider, speech synthesis, message delivery and the data centre operator.
- The current list of those entities, with the scope of entrustment, place of processing and the basis for any transfer outside the European Economic Area, is published separately as the subprocessor register.
- That register carries its own version number and date. Changing a provider updates the register, not this policy, so the policy version does not move for reasons unrelated to your rights.
- Beyond that, data may reach entities authorised under statute, our accountants and our legal advisers, to the extent necessary to defend claims.
10. Transfers outside the European Economic Area
- Application servers and the database run in the European Union, in Warsaw.
- Some functions, however, use providers whose parent companies are established outside the European Economic Area. So we do not claim that no data ever leaves that area. For each such case the subprocessor register states the country of processing and the transfer basis, that is an adequacy decision under Article 45 GDPR or standard contractual clauses under Article 46(2)(c) GDPR together with a transfer impact assessment.
11. Retention
| Category | Period |
|---|---|
| Account and organisation data | For the term of the contract |
| Conversation content and voice session data | The period set by our customer in the organisation settings. They decide, because it is their data |
| Knowledge base content | Until deleted by our customer or the contract ends |
| Audit log | For the term of the contract and 12 months afterwards, to be able to show how matters proceeded |
| Accounting records | 5 years from the end of the year in which the tax obligation arose |
| Correspondence | Up to 12 months from the last message, unless it concerns a dispute |
| Marketing consent and its record | Until consent is withdrawn; the record for the limitation period of claims |
12. What happens when the contract ends
- We delete or return the data entrusted by our customer, according to their decision and the data processing agreement.
- The knowledge base belongs to our customer and is exported in an open format on request.
- We keep only what statute requires, primarily accounting records, and what is needed to defend claims.
13. Your rights
| Right | Basis | How to use it |
|---|---|---|
| Access | Art. 15 GDPR | Message to contact@aivatary.com |
| Rectification | Art. 16 GDPR | In the panel yourself, or by message |
| Erasure | Art. 17 GDPR | Message to contact@aivatary.com |
| Restriction | Art. 18 GDPR | Message to contact@aivatary.com |
| Portability | Art. 20 GDPR | We export the knowledge base and conversation history in an open format |
| Objection | Art. 21 GDPR | Message to contact@aivatary.com stating your particular situation |
| Withdrawal of consent | Art. 7(3) GDPR | Link in the message, or a message to the contact address |
| Complaint to a supervisory authority | Art. 77 GDPR | President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland |
- We respond without undue delay and no later than one month. For complex matters we may extend that by two months, telling you beforehand.
- If we cannot confirm the identity of the person making the request, we ask for more information. Not to obstruct, but so that we do not hand data to someone else.
- If the request concerns a conversation held by our customer's agent, we pass it to that customer, because they are the controller, and we tell the requester that we did.
14. Marketing
Product information goes only to people who consented. Consent can be withdrawn at any time, and withdrawal does not affect the lawfulness of processing before it. We do not pass email addresses to third parties for marketing.
15. Automated decisions and profiling
We make no decisions about anyone based solely on automated processing that would produce legal effects or similarly significantly affect them. The agent phrases answers, but every operation that changes data requires human approval, described on the confirmation cards page. We do not profile anyone for advertising or behavioural marketing.
Enquiry fit scoring. When you book a demo through the chat window on this site, we compute an auxiliary fit score. We use only the data you entered in the booking form: the domain of your e-mail address, the company name, the company website address and the text of the "what would you like to see" field. The content of your conversation with the assistant is not used for this.
The score considers whether the address comes from a company domain or a free mailbox, whether a website was given and whether it matches the e-mail domain, and whether the company name or the description contains words we flagged in advance as relevant or disqualifying.
The score serves only to prepare the person running the demo and to set the order of contact. On its own it causes no refusal of a meeting, no refusal to enter a contract, no price change and no other legal or similarly significant effect. A human decides how the enquiry is handled. The score is not stored: we compute it each time from current data, and we keep only the form data itself, together with the booking.
The basis is our legitimate interest in handling sales enquiries efficiently (Article 6(1)(f) GDPR). You have the right to object to this processing (Article 21 GDPR); a message to contact@aivatary.com is enough.
16. Security
We apply technical and organisational measures appropriate to the risk: encrypted connections, encrypted channel credentials in the database, separation of organisations at query level, role based access control, an append only audit log, and protection of content import against reaching internal network addresses. Details are on the security page.
17. Cookies and browser storage
- This site sets no cookies. No Google Analytics, no Tag Manager, no advertising pixel, no other analytics or marketing tool. We say so explicitly, because the absence of a tool is as much information as its presence.
- The site uses browser storage as described in the table
below. Persistent storage (
localStorage) keeps a value until it is removed or the stated period elapses; session storage (sessionStorage) disappears when the tab is closed. None of these values is sent to our server.The chat record appears only once you write something to the assistant. Opening the chat window, including automatically, stores nothing. The chat window carries a "Delete from this browser" button; after using it we store nothing for the rest of the visit.Entry Where What it holds When it appears How long themepersistent the light or dark choice when the theme is changed indefinitely caip:widget:memo2persistent your own chat messages (up to 12, 400 characters each); the assistant's replies are not stored at your first message 6 hours from the last message, cleared on a timer caip:widget:resumepersistent the label of the page the assistant opened (up to 80 characters), no content on a move suggested by the assistant 5 minutes caip:widget:teaserpersistent the timestamp of dismissing the invitation bubble when you click to dismiss it 30 days caip:widget:closedsession that the chat window was closed on closing the window until the tab is closed caip:widget:voice-noticesession that you read the notice shown before the microphone is switched on after clicking "Start the conversation" in that notice until the tab is closed caip:widget:memo-offsession that you opted out of remembering the chat after clicking "delete from this browser" until the tab is closed - The conversation with Ada started from this page connects to app.aivatary.com, our own infrastructure. We load no assets from a content delivery network or another company's servers, which is why there is no consent banner.
- The panel at app.aivatary.com sets no cookies. The authentication token is held in the browser tab's memory and in session storage, and disappears when the session ends. The storage is strictly necessary to keep you signed in, so it is not subject to consent.
- Browser settings let you clear stored values at any time.
Removing the
themeentry restores the default theme.
18. Changes to this policy
- We announce material changes in advance by email and by a notice in the panel.
- Every release carries a version number and an effective date, shown at the top of the document.
- A change to the subprocessor register does not change this policy's version number, because the register is a separate document with its own version.
A data question this page does not answer
Just write. The message reaches the product team, not a ticket system.