Dwujęzyczna polityka prywatności Bilingual privacy notice
Polityka prywatności Privacy Policy
Ostatnia aktualizacja Last updated: 2026-05-06
1. Administrator, procesor i kontakt Controller, processor, and contact
Administratorem danych konta w portalu jest Adam Rogacki prowadzący działalność gospodarczą pod firmą PC Games Adam Rogacki, NIP 5771948248, REGON 363887430. Dla dokumentów przesyłanych przez klienta AROG AI zwykle działa jako podmiot przetwarzający na podstawie DPA i udokumentowanych instrukcji klienta.
For account-level portal data, the controller is Adam Rogacki prowadzący działalność gospodarczą pod firmą PC Games Adam Rogacki, NIP 5771948248, REGON 363887430. For customer documents uploaded into the portal, AROG AI usually acts as a processor under the customer DPA and documented product instructions.
Publiczna identyfikacja podmiotu Public entity reference: PC Games Adam Rogacki (JDG), NIP 5771948248, REGON 363887430. AROG AI plans to migrate the contracting entity to sp. z o.o. after launch; customers will be notified before any contract transfer or DPA update.
AROG AI has not appointed a formal Data Protection Officer at this stage. Privacy and data-subject requests are handled by the data protection contact at hello@arogai.net.
AROG AI nie wyznaczyło obecnie formalnego Inspektora Ochrony Danych. Zapytania dotyczące prywatności i praw osób obsługuje kontakt ds. ochrony danych: hello@arogai.net.
2. Jakie dane przetwarzamy What data we process
| Kategoria Category | Przykłady Examples | Cel Purpose |
|---|---|---|
| Dane konta i tożsamości Account and identity data | Imię i nazwisko, adres e-mail, identyfikatory użytkownika i organizacji, rola i status dostępu. Name, email address, user and organization identifiers, role, and access state. | Logowanie, izolacja tenantów, obsługa klienta, bezpieczeństwo i audyt dostępu. Authentication, tenant isolation, support, security, and access audit trails. |
| Dokumenty klienta Customer documents | Przesłane pliki, tekst OCR, wyodrębnione pola, notatki walidacyjne i raporty. Uploaded files, OCR text, extracted fields, validation notes, and reports. | OCR, ekstrakcja, walidacja, raportowanie oraz obsługa żądań klienta. OCR, extraction, validation, reporting, and customer-requested workflows. |
| Dane rozliczeniowe i uprawnienia Billing and entitlement data | Plan, status rozliczeń, uprawnienia produktowe, metadane checkout i referencje faktur. Plan, billing status, feature entitlements, checkout metadata, and invoice references. | Administracja subskrypcją, pilot manualny, zapobieganie nadużyciom i księgowość. Subscription administration, manual pilot enablement, fraud prevention, and accounting. |
| Logi operacyjne Operational logs | Metadane żądań, identyfikatory zadań, błędy, zdarzenia bezpieczeństwa i zapisy zgód. Request metadata, job identifiers, errors, security events, and consent records. | Niezawodność, reagowanie na incydenty, zapobieganie nadużyciom i dowody zgodności. Reliability, incident response, abuse prevention, and compliance evidence. |
3. Podstawy prawne Legal bases
- Wykonanie umowy: dostęp do konta, przetwarzanie dokumentów, wsparcie, workloady klienta objęte DPA i administracja subskrypcją. Contract performance: account access, document processing, support, DPA-backed customer workloads, and subscription administration.
- Prawnie uzasadniony interes: bezpieczeństwo, zapobieganie nadużyciom, niezawodność usługi i obrona roszczeń. Legitimate interests: security, fraud prevention, service reliability, and defense of legal claims.
- Obowiązki prawne: podatki, księgowość, współpraca z organami, ocena naruszeń i obowiązki retencyjne. Legal obligations: tax, accounting, regulatory cooperation, breach assessment, and retention duties.
- Zgoda: opcjonalne cookies, opcjonalna analityka i marketing tam, gdzie zgoda jest wymagana. Consent: optional cookies, optional analytics, and marketing where consent is required.
4. Dokumenty klienta i dane osób trzecich Uploaded documents and third-party data
Dokumenty klienta mogą zawierać dane osobowe najemców, wynajmujących, poręczycieli, pełnomocników, pracowników lub innych osób. Klient przesyłający dokument odpowiada za podstawę prawną przekazania danych do AROG AI oraz za wymagane informacje dla osób, których dane dotyczą.
Customer documents may contain personal data about tenants, landlords, guarantors, representatives, employees, or other third parties. The uploading customer is responsible for having a lawful basis to provide those documents to AROG AI and for giving required notices where applicable.
AROG AI processes uploaded documents only for requested OCR, extraction, validation, reporting, support, security, and deletion workflows. Under current sub-processor commitments and our DPA posture, customer documents are not used by AROG AI for model training.
5. AI i zautomatyzowane przetwarzanie AI and automated processing
Portal może używać OCR i ekstrakcji wspieranej AI do rozpoznawania tekstu, pól, klauzul, dat, stron i warunków finansowych w dokumentach. Wyniki są narzędziem informacyjnym do weryfikacji przez człowieka.
The portal may use OCR and AI-assisted extraction to identify text, fields, clauses, dates, parties, and financial terms. Outputs should be verified before legal, financial, or business reliance.
Portal does not implement GDPR Art. 22 solely automated decisions that produce legal or similarly significant effects concerning an individual. Where confidence is low or a workflow requires validation, users must review and approve the result.
6. Podwykonawcy i transfery Sub-processors and transfers
Niektórzy podwykonawcy mogą przetwarzać dane poza EOG. W takim przypadku AROG AI stosuje zabezpieczenia kontraktowe, organizacyjne i techniczne, takie jak DPA terms, transfer mechanisms, access controls i szyfrowanie w transporcie. Ta polityka nie deklaruje wyłącznej rezydencji danych w UE.
Some sub-processors may process data outside the EEA. Where that happens, AROG AI relies on contractual, organizational, and technical safeguards such as DPA terms, transfer mechanisms, access controls, and encryption in transit. This policy does not claim exclusive EU data residency.
| Podwykonawca Sub-processor | Rola Role | Lokalizacja Location |
|---|---|---|
| Managed cloud infrastructure provider | Application runtime, managed database, deployment operations, and service logs | EEA and approved third-country transfer safeguards where applicable |
| Network security and private object storage provider | DNS, TLS, edge security, private object storage, and access mediation | Global edge network with EEA controls where applicable |
| Identity and access management provider | User authentication, session handling, and organization access management | Approved third-country transfer safeguards where applicable |
| AI and OCR processing providers | OCR, layout extraction, classification, extraction, and validation support | EEA processing controls and approved transfer safeguards where applicable |
| Billing and payment provider | Billing, invoices, subscriptions, taxes, and payment administration | EEA and approved third-country transfer safeguards where applicable |
| Transactional email provider | Transactional email delivery and delivery-event processing | Approved third-country transfer safeguards where applicable |
| Operational monitoring and delivery providers | Error monitoring, diagnostics, release correlation, webhook delivery metadata, and optional product analytics | EEA and approved third-country transfer safeguards where applicable |
Customer DPA Annex B and the public sub-processor page contain the current portal sub-processor surface and should be reviewed together with this policy: Data Processing Agreement / Sub-processors.
7. Retencja i usuwanie Retention and deletion
| Dane Data | Okres lub kryteria Period or criteria |
|---|---|
| Anonimowe dokumenty self-service Anonymous self-service documents | 7 dni od utworzenia lub wartości retentionUntil, chyba że obowiązuje blokada prawna. 7 days from creation or retentionUntil, unless legal hold applies. |
| Dokumenty organizacji Organization documents | Domyślnie 365 dni, konfigurowalne przez ORG_DOCUMENT_RETENTION_DAYS albo wcześniejsze żądanie usunięcia; blokada prawna i obowiązki prawne mogą wstrzymać usunięcie. Default 365 days, configurable through ORG_DOCUMENT_RETENTION_DAYS or earlier deletion instruction; legal hold and legal duties can pause deletion. |
| Logi dostępu do linków udostępniania Share-link access logs | Domyślnie 90 dni, konfigurowalne przez ACCESS_LOG_TTL_DAYS. Default 90 days, configurable through ACCESS_LOG_TTL_DAYS. |
| Martwe kolejki zadań Dead-letter job records | Domyślnie 30 dni, konfigurowalne przez DLQ_RETENTION_DAYS. Default 30 days, configurable through DLQ_RETENTION_DAYS. |
| Logi audytowe i bezpieczeństwa Audit and security logs | Co najmniej 365 dni; dłużej, jeśli jest to konieczne dla bezpieczeństwa, sporu, księgowości albo obowiązku prawnego. At least 365 days; longer if needed for security, disputes, accounting, or legal duties. |
| Faktury i dane księgowe Invoices and accounting records | Przez okres wymagany przez przepisy podatkowe i księgowe. For the period required by tax and accounting law. |
Usunięcie może zostać wstrzymane przez blokadę prawną, bezpieczeństwo, obowiązki księgowe, spór albo wymóg prawny. Jeśli AROG AI działa jako procesor, wykonujemy udokumentowaną instrukcję administratora, chyba że prawo wymaga innego działania.
Deletion may be paused by legal hold, security, accounting, dispute, or legal obligations. If AROG AI acts as processor, deletion follows the controller's documented instruction unless law requires otherwise.
8. Prawa osób Your rights
W zależności od kontekstu i prawa możesz żądać dostępu, sprostowania, usunięcia, ograniczenia, przenoszenia, sprzeciwu, cofnięcia zgody lub wyjaśnienia przetwarzania zautomatyzowanego. Odpowiadamy w terminie 30 dni, chyba że RODO pozwala na przedłużenie.
Depending on context and applicable law, you may request access, rectification, erasure, restriction, portability, objection, withdrawal of consent, or review of automated-processing concerns. We respond within 30 days unless GDPR permits an extension.
If your data appears in a document uploaded by one of our customers, we may need to coordinate with that customer because the customer is usually the controller for document contents.
Skargę można złożyć do Prezesa Urzędu Ochrony Danych Osobowych: https://uodo.gov.pl. You may also lodge a complaint with the Polish supervisory authority.
9. Cookies i podobne technologie Cookies and similar technologies
Portal używa niezbędnych cookies dla sesji, bezpieczeństwa, stanu zgody i uwierzytelniania. Opcjonalne cookies analityczne lub preferencyjne są używane tylko wtedy, gdy pozwala na to konfiguracja środowiska i zgoda użytkownika.
Portal uses strictly necessary cookies for session, security, consent, and authentication. Optional analytics or preference cookies are used only where runtime configuration and consent permit them.
| Kategoria Category | Cel Purpose | Podstawa Basis |
|---|---|---|
| Niezbędne Strictly necessary | Sesja, bezpieczeństwo, consent state, uwierzytelnianie. Session, security, consent state, authentication. | Prawnie uzasadniony interes lub wykonanie umowy. Legitimate interests or contract performance. |
| Analityczne Analytics | Pomiar użycia produktu, jeśli konfiguracja środowiska i zgoda użytkownika na to pozwalają. Product usage measurement if runtime configuration and user consent allow it. | Zgoda. Consent. |
| Preferencje Preferences | Zapamiętanie preferencji użytkownika. Remembering user preferences. | Zgoda lub prawnie uzasadniony interes zależnie od funkcji. Consent or legitimate interests depending on the function. |
Cookie categories and consent controls are described on the Cookie Policy. Możesz zarządzać preferencjami w banerze lub ustawieniach cookies, jeżeli dana kategoria jest aktywna.
10. Środki bezpieczeństwa Security measures
- Kontrole autoryzacji uwzględniające tenanty na granicach API i workerów. Tenant-aware authorization checks at API and worker boundaries.
- Uwierzytelnianie użytkowników i organizacji przez zewnętrznego dostawcę tożsamości. External identity-provider-backed user and organization authentication.
- Szyfrowany transport dla ruchu portalu i komunikacji usług tam, gdzie jest wspierany. Encrypted transport for portal traffic and service communication where supported.
- Minimalizacja dostępu operacyjnego dla wsparcia i reagowania na incydenty. Access minimization for support and incident response.
- Workflowy usuwania, kontrole blokady prawnej i ponawialna obsługa outbox usuwania tam, gdzie ma zastosowanie. Deletion workflows, legal-hold checks, and retryable deletion/outbox handling where applicable.
- Skanowanie sekretów, polityka dowodów audytowych oraz kontrole pre-commit/CI dla zmian w repozytorium. Secret scanning, audit evidence policy, and pre-commit/CI controls for repository changes.
Żadne zabezpieczenie nie eliminuje całego ryzyka. Klienci powinni zarządzać dostępem użytkowników, weryfikować wyniki ekstrakcji i niezwłocznie zgłaszać problemy bezpieczeństwa.
No security control eliminates all risk. Customers should manage user access, verify extraction outputs, and report security concerns promptly.
11. Lite DPIA Mini-DPIA
Charakter, zakres, kontekst i cel: AROG AI przetwarza komercyjne dokumenty najmu i dokumenty prawne dla klientów biznesowych. Obejmuje to upload, OCR, ekstrakcję wspieraną AI, walidację, raportowanie, wsparcie, logi bezpieczeństwa i workflowy usuwania.
Nature, scope, context, and purpose: AROG AI processes commercial lease and legal-document workloads for business customers. Processing includes upload, OCR, AI-assisted extraction, validation, reporting, support, security logging, and deletion workflows.
Niezbędność i proporcjonalność: treść dokumentów jest przetwarzana dla żądanych workflowów i wsparcia operacyjnego. Produkt ogranicza dostęp tenantów, nie wykorzystuje dokumentów klientów do treningu modeli po stronie AROG AI i opiera przetwarzanie dokumentów klienta na DPA.
Necessity and proportionality: document contents are processed for requested workflows and operational support. The product separates tenant access, avoids AROG AI model training on customer documents, and exposes DPA terms for controller instructions.
Ryzyka dla osób: nieuprawniony dostęp, błędny wynik ekstrakcji, nadmierna retencja, dane osób trzecich w dokumentach, ryzyko transferu do podwykonawców albo opóźnione usunięcie przez blokadę prawną lub ponowienie.
Risks to data subjects: unauthorized access, mistaken extraction output, excessive retention, third-party data in uploaded contracts, vendor transfer risk, or delayed deletion caused by legal hold or retryable deletion states.
Mitigacje: kontrole autoryzacji tenantów, weryfikacja wyników przez człowieka, workflowy usuwania, ujawnienie podwykonawców, skanowanie sekretów, logowanie bezpieczeństwa, obsługa DSR, kontrole blokady prawnej oraz ocena naruszeń względem obowiązków notyfikacyjnych RODO. Mitigations include tenant authorization checks, human verification of outputs, deletion workflows, sub-processor disclosure, secret scanning, security logging, DSR handling, legal-hold checks, and breach assessment against GDPR notification duties.
12. Zmiany Changes
Możemy aktualizować tę politykę, gdy zmieni się produkt, lista podwykonawców, podmiot prawny lub zakres przetwarzania. Istotne zmiany kontraktowe będą obsługiwane zgodnie z właściwą umową lub procesem DPA.
We may update this policy when the product, sub-processor list, legal entity, or processing scope changes. Material customer-contract changes will be handled through the applicable agreement or DPA process.