This is an informational translation. The legally binding Polish version of this document is here. Using AdActa requires acceptance of the Polish documents: Privacy policy, Terms of Service, and Security.
Effective from July 13, 2026
Privacy policy
1. General information
This policy explains how DONE CHECKED Sp. z o.o. processes personal data in connection with the AdActa service, in line with the GDPR and Polish law.
2. Data controller
The controller of personal data related to your account and use of AdActa is DONE CHECKED Sp. z o.o., ul. Pańska 96/83, 00-837 Warsaw, KRS 0001078605, NIP 5273091211, REGON 527315017. Data protection contact: contact@adacta.digital.
3. Categories of data
Depending on how you use the Service, we may process:
- account data (e.g. name or identifier, email, sign-in data, technical identifiers);
- content you voluntarily enter (including documents and matter metadata);
- technical and operational data (logs, device or session identifiers) needed for security and operations;
- billing data if you pay for plans (e.g. transaction identifiers at the payment provider; we do not store full card numbers in AdActa unless your payment provider’s flow states otherwise).
4. Purposes of processing
We process data for:
- providing the Service, including account, documents, AI features, and in-app communication;
- IT security, diagnostics, and abuse prevention;
- billing, debt collection, and legal handling of the relationship;
- legal obligations (e.g. retention, responses to authorities when required).
Legal bases (Art. 6 GDPR)
Depending on the purpose, we rely on:
- Art. 6(1)(b) GDPR — performance of the Service contract;
- Art. 6(1)(c) GDPR — legal obligation;
- Art. 6(1)(f) GDPR — legitimate interests (e.g. security, fraud prevention, product analytics where permitted);
- Art. 6(1)(a) GDPR — consent where we collect it separately (e.g. optional marketing), withdrawable at any time.
5. Recipients and processors
Data may be shared with processors supporting the Service under appropriate agreements, including:
- cloud hosting and infrastructure providers;
- email and transactional messaging providers;
- payment processors (e.g. Stripe) if you use paid plans;
- LLM / AI providers (in the EU or outside) when you invoke AI features — parts of prompts may be sent per product configuration and contracts;
- IT and support subcontractors — only as necessary.
6. Artificial intelligence: no training on matter or document data, and optional assistant personalisation
We do not use content from your matters or documents to train or improve vendors’ global AI models, nor to build training datasets shared with other organisations.
If you ask for it, the virtual assistant may infer preferences from your conversation so it can better match how you want it to respond in future chats. That information is stored only on your account, as configuration files. It is deleted when your account is deleted. You can turn this off at any time in the app settings — the assistant will then stop saving and applying that personalisation.
7. Retention
We keep data for the life of the contract (account) and afterwards only as long as law or legitimate interest requires (e.g. claims defence), then delete or anonymise. Detailed periods may follow product retention settings and internal procedures — contact us if unsure.
8. Transfers outside the EEA
If we use providers outside the European Economic Area, we apply GDPR mechanisms (e.g. EU standard clauses) where required. Further detail on specific AI providers may be provided on request or in a separate processor list.
9. Data subject rights
You have in particular the following rights (subject to GDPR conditions and exceptions):
- access and copy;
- rectification;
- erasure (“right to be forgotten”) where applicable;
- restriction of processing;
- data portability;
- objection to processing based on Art. 6(1)(f) GDPR;
- withdraw consent at any time where processing is consent-based, without affecting lawfulness before withdrawal.
10. Cookies and similar technologies
We use cookies and similar technologies required for sessions and security and — if you enable them in settings — additional features. Details may appear in a banner or in-app privacy settings.
11. Supervisory authority
You may lodge a complaint with the President of the Polish Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl.