# PRIVACY POLICY — TRACEBRAND PLATFORM

Effective from: 2026-08-16
Version: 1.0

This document describes what personal data we collect in connection with the use of the Tracebrand platform, for what purpose we process it, to whom we disclose it, and what rights are available to the data subjects.

## 1. Data Controller

1. The controller of personal data is Mayko Sp. z o.o. with its registered office in Białystok, at ul. Jana Henryka Dąbrowskiego 28, 15-872 Białystok, NIP 5423234127, REGON 200815339, entered in the register of entrepreneurs kept by the District Court in Białystok, XII Commercial Division of the National Court Register under KRS number 0000483918 (hereinafter: the "Controller" or "we").
2. Contact for matters concerning personal data: m.kosierkiewicz@mayko.pl.
3. The Controller has not appointed a Data Protection Officer.
4. Definitions of capitalized terms not defined in this document are set out in the Terms of Service available at https://app.tracebrand.ai/terms.

## 2. What Data We Process

1. **Account data:** first name, email address, password stored as a cryptographic hash, organization membership, role and permissions, date of last login.
2. **Billing data:** company name, address, VAT number, invoice and payment history. We do not collect or store payment card data. The card is handled directly by the payment operator.
3. **Work content:** the monitored brand, its domain, the list of competitors, the content of saved queries (Prompts), the responses of the artificial intelligence models, and the sources indicated in them.
4. **Technical data:** IP address, session identifiers, access timestamps, application logs, error events, and audit log entries documenting staff access to the account.
5. We do not collect special categories of data and do not request that they be provided. The Terms of Service prohibit entering such data into the Platform.

## 3. Purposes of Processing, Legal Bases, and Retention Periods

| Purpose | Legal basis | Retention period |
|---|---|---|
| Account maintenance and service provision | Art. 6(1)(b) GDPR — performance of a contract | For the duration of the contract |
| Storage of model result history | Art. 6(1)(b) GDPR — performance of a contract | 3, 12, or 24 months, depending on the plan, in accordance with § 6 of the Terms of Service |
| Billing and accounting records | Art. 6(1)(c) GDPR — legal obligation | 5 years from the end of the year in which the tax payment deadline expired |
| Handling complaints and support requests | Art. 6(1)(b) and (f) GDPR | 12 months from closing the request |
| Ensuring security and troubleshooting | Art. 6(1)(f) GDPR — legitimate interest | 90 days for technical logs |
| Establishment, exercise, and defense of legal claims | Art. 6(1)(f) GDPR — legitimate interest | Until the expiry of the limitation period for claims |
| Sending transactional messages (address confirmation, password reset, invitations, payment notifications) | Art. 6(1)(b) GDPR — performance of a contract | For the duration of the contract |

We do not send marketing communications and do not process data for marketing purposes.

After termination of the contract, we delete account data and work content following the 14-day read-only period described in § 19 of the Terms of Service, within 30 days. We delete backup copies containing this data within 90 days of contract termination and do not use them for any other purpose during that period. This does not apply to billing records and data whose retention is required by law.

## 4. The Controller's Role Regarding Content Entered by the Client

1. We are the controller with respect to account data, billing data, and technical data.
2. As a rule, the client's work content does not contain personal data. To the extent that the client enters personal data into the Platform, we process it on the client's behalf as a processor, on the terms set out in the Data Processing Agreement constituting Annex No. 1 to the Terms of Service.
3. We do not use content entered by the client for our own analytical or marketing purposes.

## 5. Recipients of Data

We use providers who process data on our behalf. The list below is complete as of the effective date of this version of the document.

| Entity | Data received | Purpose | Place of processing |
|---|---|---|---|
| Railway | the entire database and the application | hosting | The Netherlands (Amsterdam), European Economic Area |
| OpenAI | content of Prompts | model responses | outside the EEA |
| Google | content of Prompts | model responses | outside the EEA |
| Perplexity | content of Prompts | model responses | outside the EEA |
| OpenRouter | content of Prompts | access to additional models | outside the EEA |
| SerpApi | content of Prompts | retrieval of Google AI Overview | outside the EEA |
| Langfuse | content of Prompts and model responses | diagnostics and monitoring of AI queries | outside the EEA |
| Stripe | billing data and payment data | payment and invoice processing | Ireland and outside the EEA |
| Resend | email address and message content | sending transactional messages | outside the EEA |
| Decodo | network traffic when retrieving web pages | network intermediation, exit node in the country indicated in the project settings | outside the EEA |

We also disclose data to entities authorized under applicable law and to our legal and accounting advisors, to the extent necessary to perform the services provided to us.

The list is updated by amending this Policy, in the manner described in Section 13.

## 6. Transfer of Data Outside the European Economic Area

1. The Platform's database and the application itself are stored and processed within the European Economic Area, in a data center in Amsterdam, the Netherlands. This applies to account data, billing data, and work content.
2. We transfer outside the European Economic Area: 1) the content of Prompts — to the artificial intelligence model providers listed in Section 5; 2) the email address and the content of transactional messages — to the email service provider; 3) billing data — to the payment operator, to the extent resulting from its organizational structure; 4) error events — to the diagnostic tool provider, insofar as its account is not maintained in the European region.
3. The basis for the transfer is an adequacy decision of the European Commission with respect to providers participating in the EU-US Data Privacy Framework, and, with respect to the remaining providers, standard contractual clauses included in the data processing agreements with those providers.
4. A copy of the safeguards applied to the transfer can be obtained at the address indicated in Section 1(2).

## 7. Queries Directed to Artificial Intelligence Models

1. A saved Prompt is sent to each enabled model provider once a day, automatically, throughout the term of the contract. This is not a one-time transfer.
2. The content of the Prompt is sent to the model providers. We do not disclose account data or billing data to them.
3. The content of Prompts and model responses is sent to the Langfuse diagnostic tool, which we use to monitor the accuracy and cost of queries. Langfuse is a recipient of this data.
4. We do not use content entered into the Platform to train artificial intelligence models.

## 8. Access by Our Staff to Client Accounts

1. The Platform's operator panel allows an authorized employee to access a client's account and view what the client sees. This function is used to handle support and complaint requests and to diagnose failures.
2. Each such access requires stating a reason and is recorded in an audit log that includes the employee's identity, the time of access, and the reason given.
3. We retain audit log records for 24 months.

## 9. Cookies

1. The Platform uses only cookies that are strictly necessary for its operation: user session cookies and a cookie that remembers the selected language.
2. We do not use analytical or marketing cookies, or third-party tracking tools.
3. Given the scope indicated in paragraph 1, using the Platform does not require consent to cookies.

## 10. Rights of Data Subjects

1. You have the right to: 1) access your data and obtain a copy of it; 2) rectify your data; 3) erase your data; 4) restrict processing; 5) data portability; 6) object to processing based on our legitimate interest.
2. You submit a request to the address indicated in Section 1(2). We respond within one month of receiving the request.
3. You have the right to lodge a complaint with the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.
4. Providing account data and billing data is voluntary but necessary for concluding and performing the contract. Without providing them, use of the Platform is not possible.
5. The Platform does not offer self-service account deletion. We carry out deletion requests manually, upon a request submitted in the manner indicated in paragraph 2.

## 11. Automated Decision-Making

We do not make decisions concerning you based solely on automated processing that would produce legal effects or similarly significantly affect you. We do not profile users.

## 12. Data Security

1. We store passwords only in the form of cryptographic hashes.
2. Data transmission between the browser and the Platform is encrypted.
3. Access to production data is granted only to authorized employees, to the extent necessary to perform their duties, based on named permissions.
4. Staff access to client accounts is logged in the manner described in Section 8.
5. We review and update security measures at least once a year. A detailed list of these measures is set out in Annex No. 2 to the Data Processing Agreement.

## 13. Changes to the Privacy Policy

1. We notify you of a change to the Privacy Policy by a message sent to the email address assigned to the account and by a notice in the Panel, no later than 14 days before the date the change takes effect.
2. We archive previous versions of the Privacy Policy together with the periods during which they were in effect.

---
