§1 Data Controller
§1.1. The controller of personal data of users of the GEORate Platform (hereinafter referred to as the "Platform"), available at georate.ai, is:
Codeandlove Piotr Makowski
Małopanewska 12/1, 54-212 Wrocław, Poland
NIP (Tax ID): 8982085219, REGON: 021197822
Email: [email protected]
Legal form: sole proprietorship registered in CEIDG (Central Registration and Information on Business Activity)
(hereinafter referred to as the "Controller")
§1.2 — Data Protection Officer (DPO). The Controller has not appointed a Data Protection Officer. In accordance with Article 37(1) of Regulation (EU) 2016/679 (GDPR), the Controller has analyzed the mandatory DPO appointment criteria and determined that:
- The Controller is not a public authority or body (Article 37(1)(a) GDPR — not applicable);
- The Controller's core activities do not consist of processing operations requiring regular and systematic large-scale monitoring of data subjects — the business activity consists of monitoring brand presence in AI responses, and the processing of users' personal data (email address, IP address) is merely ancillary and incidental (Article 37(1)(b) GDPR — not applicable);
- The Controller does not process on a large scale special categories of data pursuant to Article 9 GDPR, nor personal data relating to criminal convictions and offences pursuant to Article 10 GDPR (Article 37(1)(c) GDPR — not applicable).
The above assessment is subject to regular review and may change if the nature or scale of the Controller's activities changes. For data protection matters, please contact the Controller directly at: [email protected].
§2 Legal Bases for Processing
§2.1. The Controller processes personal data on the following legal bases:
- Article 6(1)(b) GDPR (performance of a contract) – to the extent necessary to provide the Platform service: creating and managing the User's account, storing configuration (brands, products, projects, prompts), performing analyses (snapshots), and providing results and metrics;
- Article 6(1)(c) GDPR (legal obligation) – to the extent required by law, in particular storing accounting and tax data related to invoices;
- Article 6(1)(f) GDPR (legitimate interests of the Controller) – for the following purposes:
- ensuring Platform security and preventing abuse (rate limiting, server logs);
- anonymous visitor statistics of the Platform;
- handling correspondence from the contact form;
- establishing, exercising, or defending legal claims.
- Article 6(1)(a) GDPR (consent) – for analytical and marketing cookies (Google Analytics 4) – consent given via the cookie banner.
§3 Scope and Categories of Data
§3.1. Depending on the scope of Platform use, the Controller processes the following categories of personal data:
a) Account data (required for entering into and performing the agreement):
- email address (serving as a login identifier);
- password hash (bcrypt algorithm, 12 rounds of salting – the password is never stored or processed in plain text);
- registration date and time of last activity;
- user identifier (UUID) assigned by the authentication system.
b) Configuration and business data (voluntary but necessary to use Platform features):
- brand names and their aliases;
- product names and their aliases;
- competitor names and their aliases;
- prompt content (queries to AI models);
- projects and prompt clusters.
c) Analytical data (automatically generated as a result of Platform operation):
- snapshot results – AI model responses containing mentions, ranking positions, entities;
- aggregated metrics – visibility indicators, sentiment, AI Share of Voice (AI SOV);
- alerts and events generated based on analyses.
d) Technical data (automatic, cannot be disabled):
- IP address – processed in web server logs (stored up to 30 days) and in the application's operational memory for rate limiting (not saved to the database, cleared on server restart);
- anonymous visit statistics – URL path, referrer hostname (without IP address or user identifier);
- browser type and version, operating system – processed only in standard HTTP headers, not logged.
e) Payment data:
- Stripe customer identifier (stripe_customer_id) – stored in the Controller's database;
- subscription status and Stripe subscription identifier (stripe_subscription_id);
- invoice history – retrieved from Stripe API at the User's request;
- Credit card numbers are not processed or stored by the Controller – they are processed exclusively by Stripe, Inc. within its secure payment infrastructure (PCI DSS Level 1).
f) Correspondence data (voluntary):
- name, email address, message content – sent via the contact form or directly to the Controller's email address.
§4 Purposes of Data Processing
§4.1. Users' personal data is processed for the following purposes:
- Provision of Platform services – account management, authentication, configuration storage, performing snapshots, generating reports and metrics, sharing analysis results;
- Communication with the User – handling inquiries and complaints, notifications about changes to the Terms, Privacy Policy, or subscription plans;
- Payments and billing – subscription management, invoicing, payment processing via Stripe;
- Platform security – detecting and preventing abuse, protecting against unauthorized access, rate limiting;
- Analytics – Google Analytics 4 (only with the User's prior consent) to analyze Platform usage and optimize the service;
- Compliance with legal obligations – storing accounting and tax data, responding to supervisory authority requests.
§5 Data Processors
§5.1. The Controller uses the following data processors based on documented instructions (data processing agreements):
| Processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Mikr.us (UW-TEAM.ORG Jakub Mrugalski, Poland) | VPS server hosting – database, application, and server log storage | Finland (Helsinki) – EEA | Art. 45 GDPR (no transfer) |
| Supabase, Inc. (USA) | Authentication, configuration database with metrics, real-time updates | EU (Frankfurt, Germany) | Art. 45 GDPR (EEA) |
| Stripe, Inc. (USA) | Payment processing, subscription management, invoicing | USA (Stripe servers) | Standard Contractual Clauses (SCC) – EC Decision 2021/914 |
| Google LLC (USA) – Google Analytics 4 | Web analytics (only with User's consent) | USA / EEA | SCC + Consent Mode v2 – User consent (Art. 49(1)(a) GDPR) |
| n8n GmbH – workflow automation (self-hosted on Mikr.us VPS) | Analytical process automation, storage of raw analytical data in isolated database schemas | Finland (Helsinki – EEA) | Art. 45 GDPR (no transfer) |
§5.2. The Controller does not use Meta Pixel, TikTok Pixel, Hotjar, or any other external advertising or tracking tools beyond Google Analytics 4, which is only activated after obtaining the User's consent.
§5.3. The Controller does not sell Users' personal data nor share it with third parties for commercial purposes unrelated to providing the service.
§6 International Data Transfers
§6.1. Users' personal data is generally stored and processed on servers located in the European Economic Area (EEA):
- Mikr.us (UW-TEAM.ORG Jakub Mrugalski) – Helsinki, Finland (EEA);
- Supabase, Inc. – Frankfurt, Germany (EU region);
- n8n GmbH – self-hosted on Mikr.us server in Helsinki (EEA).
§6.2. Personal data may be transferred to third countries (outside the EEA) in the following cases:
- Stripe, Inc. (USA) – the Stripe customer identifier and data necessary for payment processing are transferred to Stripe based on Standard Contractual Clauses (SCC) approved by European Commission Decision 2021/914. Stripe holds PCI DSS Level 1 certification.
- Google LLC (USA) – if the User consents to analytics, data about Platform activity (anonymous) may be transferred to Google Analytics 4 based on SCC and Consent Mode v2, which ensures data is sent only after obtaining proper consent.
§6.3. The Controller does not transfer Users' personal data to third countries for purposes other than those specified above.
§7 Data Retention Periods
§7.1. The Controller retains personal data for the following periods:
| Data type | Retention period |
|---|---|
| Account data (email, password hash) | For the duration of the User's account |
| Configuration data (brands, products, prompts) | For the duration of the User's account |
| Snapshots and raw analytical data (analytics database) | Up to 12 months from the snapshot date, not longer than until account deletion |
| Aggregated metrics (configuration database) | Up to 12 months from generation; deleted with the account |
| Web server logs (IP addresses) | Maximum 30 days, then automatically rotated |
| Rate limiting data (operational memory) | RAM only – cleared on server restart |
| Anonymous visit statistics | Up to 90 days |
| Email correspondence (contact form) | Up to 2 years from last contact or until the matter is resolved |
| Accounting and tax data (invoices) | 5 years from the end of the tax year, in accordance with accounting regulations |
§7.2 – Automatic deletion after inactivity. A User account with no login for 90 consecutive days is automatically deleted along with all associated data. The User is informed of this when attempting to log in after the period of inactivity.
§7.3 – Data in Google Analytics 4. The data retention period in Google Analytics 4 is determined by Google's policy and defaults to 14 months. The User may withdraw consent for analytics at any time via the cookie banner.
§8 Your Rights (Art. 15-22 GDPR)
§8.1. In connection with the processing of personal data by the Controller, you have the following rights:
- Right of access (Art. 15 GDPR) – you may request confirmation as to whether we process your personal data and obtain a copy of the data;
- Right to rectification (Art. 16 GDPR) – you may request the immediate correction of inaccurate or incomplete personal data;
- Right to erasure ("right to be forgotten", Art. 17 GDPR) – you may request the deletion of personal data if it is no longer necessary for the purposes for which it was collected, or if you have withdrawn consent and the processing is not lawful. You can delete your account independently in the user panel (Settings → Delete Account);
- Right to restriction of processing (Art. 18 GDPR) – you may request the suspension of data processing in situations specified in the GDPR (e.g., when you contest the accuracy of the data);
- Right to data portability (Art. 20 GDPR) – you may receive your data in a structured, commonly used, machine-readable format (JSON);
- Right to object (Art. 21 GDPR) – you may object to processing based on the Controller's legitimate interests (Art. 6(1)(f) GDPR). The Controller will review the objection and cease processing unless compelling legitimate grounds for continued processing override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims;
- Right to withdraw consent – if processing is based on consent (Art. 6(1)(a) GDPR), you have the right to withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal;
- Right to lodge a complaint (Art. 77 GDPR) – if you believe that data processing violates GDPR provisions, you have the right to lodge a complaint with the supervisory authority: President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, email: [email protected].
§8.2. To exercise the above rights, please contact the Controller at: [email protected]. The Controller processes requests within one month of receipt, with the possibility of extending by a further two months in justified cases (the data subject will be informed accordingly).
§9 Data Security
§9.1. The Controller has implemented appropriate technical and organizational measures to ensure the security of personal data, in particular:
- Password encryption – passwords are stored exclusively in encrypted form (bcrypt, 12 rounds of salting). The Controller has no access to passwords in plain text;
- Transmission encryption – all communication with the Platform occurs via HTTPS (TLS 1.2+);
- Secure session cookies – JWT session token stored in cookies with
HttpOnly,Secure,SameSite=Strictflags; - Row-level data isolation – the configuration database uses access policies that restrict data access exclusively to the authenticated User who owns the data;
- Analytics database isolation – each User's analytical data is stored in separate, isolated database schemas;
- Rate limiting – API request limits (60 requests per minute per user) to prevent abuse;
- Service key – access to internal API endpoints is protected by a shared secret (
x-internal-secret) and is not accessible externally; - Regular updates – the Platform software is regularly updated to patch known vulnerabilities.
§11 Changes to This Policy
§11.1. The Controller reserves the right to amend this Privacy Policy in connection with changes in legislation, changes in Platform functionality, or changes in the scope of data processing.
§11.2. Users will be notified of material changes by electronic means (email) with at least 14 days' notice. Editorial or adaptive changes take effect on the date of publication.
§11.3. The date of the last update of this Privacy Policy is July 20, 2026.
§12 Contact Regarding Personal Data
§12.1. For all matters concerning the processing of personal data, including the exercise of rights under the GDPR, please contact the Controller:
- Preferred method: email: [email protected] (response within 5 business days);
- Written form: Codeandlove Piotr Makowski, Małopanewska 12/1, 54-212 Wrocław, Poland.