Privacy Policy

Effective date: [DD.MM.YYYY]

This Policy explains what personal data we process in connection with the poracap.com website, the Plugin and the PoraCap service, for what purpose and on what basis, whom we entrust it to, and what rights you have. This is a translation of the Polish version; in case of discrepancy, the Polish version prevails.

1. Data Controller

The controller of personal data is [Company full name], [legal form], registered office at [address], Tax ID (NIP) [NIP], REGON [REGON][, KRS [KRS]] ("Controller", "we").

Contact for data matters: sorokastudios@gmail.com.

2. Data we process

3. Purposes and legal bases (GDPR)

PurposeLegal basis
Creating and running an account, providing the ServiceArt. 6(1)(b) GDPR (performance of a contract)
Billing, invoicing, accounting and tax obligationsArt. 6(1)(c) GDPR (legal obligation)
Security, abuse prevention, device limits, enforcing the TermsArt. 6(1)(f) GDPR (legitimate interest)
Handling inquiries, complaints and contactArt. 6(1)(b) and (f) GDPR
Marketing (if any), newsletterArt. 6(1)(a) GDPR (consent) or (f)

4. Recipients and processors

We entrust data to trusted providers who process it on our behalf only as necessary:

ProviderRoleNotes
OpenAITranscription and text processing by AI modelsData sent via the API is not used to train models; retained up to 30 days for abuse monitoring unless law requires otherwise. Transfers outside the EEA under Standard Contractual Clauses.
SupabaseDatabase, authentication, server functionsEU region (Frankfurt).
GoogleGoogle sign-in (OAuth)Only if you choose Google sign-in.
Payment provider (e.g. Stripe)Payment processingOnce online payments launch. Payment data is handled by the provider.
NetlifyHosting of poracap.com
E-mail / invoicing providerMessage delivery, accounting documentsAs necessary.

Data may be disclosed to competent authorities where required by law.

5. International transfers

Some providers (e.g., OpenAI, payment provider) may process data outside the European Economic Area. In such cases transfers are based on appropriate safeguards, in particular Standard Contractual Clauses approved by the European Commission.

6. Retention

7. Your rights

You have the right to: access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interest, and withdrawal of consent (without affecting the lawfulness of processing before withdrawal).

You also have the right to lodge a complaint with the supervisory authority (in Poland: President of the Personal Data Protection Office, PUODO, ul. Stawki 2, 00-193 Warsaw).

To exercise your rights, contact: sorokastudios@gmail.com.

8. Cookies and local storage

The Website uses browser local storage (localStorage) and necessary mechanisms to maintain the login session and remember settings. We do not use advertising tracking cookies without your consent. You can manage browser-stored data in your browser settings.

9. Security

We apply technical and organizational measures appropriate to the risk, including encrypted connections (HTTPS), restricted data access and storing passwords only as hashes. Access keys to external AI services remain server-side and are not shared with Users.

10. Children

The Service is not intended for persons under 16. We do not knowingly collect their data.

11. Changes to this Policy

We may update this Policy. We will notify you of material changes via the Website or e-mail. The current version is effective from [DD.MM.YYYY].

Template to be adapted. We recommend review by a data-protection specialist / lawyer, especially regarding the list of processors, retention periods and transfers outside the EEA.