Privacy Policy
DAIRY CHAT
PRIVACY POLICY
Version 1.0 | Effective: 09.07.2026
Dairy Chat Sp. z o.o. | Kraków, Poland | Governing Law: Polish Civil Code | Jurisdiction: Warsaw Courts
IMPORTANT NOTICE: This Privacy Policy describes how Dairy Chat Sp. z o.o. collects, uses, and protects personal data in connection with the Dairy Chat platform. It applies to Subscribers and their Authorised Users who access the Service. Please read it carefully before subscribing.
1. DATA CONTROLLER
The data controller responsible for processing your personal data in connection with the Dairy Chat platform is:
| Legal name | Dairy Chat Spółka z ograniczoną odpowiedzialnością (Dairy Chat Sp. z o.o.) |
|---|---|
| KRS number | 0001246289 |
| NIP | 6751829475 |
| REGON | 544952819 |
| Registered address | ul. Zygmunta Augusta 5, lok. 2, 31-504 Kraków, Poland |
| Data protection contact | privacy@dairychat.com |
References in this Policy to “we”, “us”, or “our” are to Dairy Chat Sp. z o.o. in its capacity as data controller.
2. SCOPE AND APPLICATION
This Policy applies to the processing of personal data of natural persons who:
- are employed by, or act as representatives of, legal entities that subscribe to the Dairy Chat platform (B2B Subscribers); or
- access the platform as Authorised Users on behalf of a Subscriber.
The Dairy Chat platform is a business-to-business (B2B) service only. It is not directed at consumers (konsumenci) within the meaning of Article 22¹ of the Polish Civil Code. We do not knowingly collect personal data from individuals acting outside a business or professional context.
This Policy applies in respect of personal data processed by Dairy Chat Sp. z o.o. as data controller. Where the Subscriber submits personal data of its own data subjects through the platform (for example, personal data embedded in query text), the Subscriber acts as data controller and Dairy Chat acts as data processor in respect of that data; that processing relationship is governed by the Data Processing Agreement (DPA) available at available on request at privacy@dairychat.com.
3. LEGAL FRAMEWORK
We process personal data in compliance with:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation — GDPR), as directly applicable in Poland;
- the Polish Act of 10 May 2018 on Personal Data Protection (Ustawa o ochronie danych osobowych, Dz.U. 2018 poz. 1000, as amended), implementing the GDPR in Poland;
- the Polish Act of 18 July 2002 on Providing Services by Electronic Means (Ustawa o świadczeniu usług drogą elektroniczną), governing electronic service delivery; and
- the Polish Act of 12 July 2024 on Communications Law (Prawo komunikacji elektronicznej), transposing the ePrivacy Directive in Poland.
4. WHAT PERSONAL DATA WE COLLECT AND WHY
We collect and process personal data across the following activities. For each activity we identify the categories of data, the purpose, and the lawful basis under Article 6 GDPR.
4.1 Account Registration
| Category | Data points | Purpose | Lawful basis |
|---|---|---|---|
| Identity and contact | Name, business email address, country, hashed password | Creating and managing your account; delivering the Service; communicating about your subscription | Art. 6(1)(b) GDPR — performance of a contract to which the data subject is party (the B2B Terms & Conditions) |
4.2 Query Processing — Real-Time AI Output Generation
When you submit a natural language query through the platform, we process the query text to retrieve relevant data from our Knowledge Base and generate an AI Output in response.
| Category | Data points | Purpose | Lawful basis |
|---|---|---|---|
| Query content | Text of Subscriber Query as submitted; AI Output returned | Delivering the core Service: processing your query and returning AI-generated market intelligence | Art. 6(1)(b) GDPR — performance of the contract. Query processing is the core contractual obligation. |
Important: Query text and AI Output are processed in real time to generate your response. We do not use your query content to train AI models. Our AI inference provider(s) process queries under contractual terms that prohibit use of query data for model training. Current AI inference provider details are set out in Section 6 (Sub-Processors).
4.3 Query Logging — Security, Abuse Prevention, and Dispute Resolution
Separately from real-time query processing, we maintain an operational log of query activity for security, platform integrity, and dispute resolution purposes.
| Category | Data points | Purpose | Lawful basis |
|---|---|---|---|
| Operational log | Session ID Timestamp Query text Answer preview (first 200 characters of AI Output) Source references returned Guardrail flag (boolean) | Security monitoring and abuse prevention; detecting and investigating misuse of the platform; evidential record for dispute resolution; platform integrity and reliability | Art. 6(1)(f) GDPR — legitimate interests. Our legitimate interests: protecting the platform from abuse; maintaining service integrity; preserving evidence for dispute resolution with Subscribers. A Legitimate Interests Assessment (LIA) has been conducted and documented. The three-stage balancing test under Article 6(1)(f) GDPR has been completed, confirming that these legitimate interests are not overridden by the interests or fundamental rights of data subjects, having regard to the B2B context, the limited categories of data logged, the 12-month retention period applied, and the availability of the right to object under Article 21 GDPR (see Section 9). |
Right to object: Where we rely on legitimate interests under Art. 6(1)(f) GDPR, you have the right to object to that processing at any time. See Section 9 (Your Rights) for how to exercise this right.
4.4 Subscription and Billing Records
| Category | Data points | Purpose | Lawful basis |
|---|---|---|---|
| Subscription data | Subscription tier, subscription period start/end dates, payment status, invoice references | Managing your subscription; processing renewals and cancellations; financial record-keeping in compliance with Polish tax law | Art. 6(1)(b) GDPR (subscription management) and Art. 6(1)(c) GDPR (legal obligation — Polish Ordynacja podatkowa, 5-year accounting retention requirement) |
Payment: Fees are invoiced directly by Dairy Chat Sp. z o.o. and paid by bank transfer. We do not collect, process, or store payment card data.
4.5 Free Trial Data
Where you register for a Free Trial, the same categories of data described in Sections 4.1, 4.2, and 4.3 are processed under the same lawful bases. Upon expiry of the Free Trial, if you do not subscribe to a paid tier, your account data is retained for thirty (30) days and then permanently deleted in accordance with Section 7 (Retention Periods).
Where an application for access to the platform is rejected, account registration data (Section 4.1) is retained for twelve (12) months from the date of rejection under Art. 6(1)(f) GDPR (legitimate interests: fraud prevention and dispute resolution) and then permanently deleted. Where an account is suspended, account registration data is retained for twelve (12) months from the date of suspension under Art. 6(1)(f) GDPR (legitimate interests: security, fraud prevention, dispute resolution, and evidence preservation) and then permanently deleted. In both cases, you have the right to object to this retention under Article 21 GDPR (see Section 9).
5. SPECIAL CATEGORIES OF DATA AND CHILDREN
We do not process special categories of personal data (Article 9 GDPR: health data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning sex life or sexual orientation) in connection with the Dairy Chat platform.
Subscribers must not submit special category data through the platform. Where query text submitted by a Subscriber incidentally contains special category data of third parties, this constitutes a misuse of the platform and the Subscriber is solely responsible as data controller for that data.
The Dairy Chat platform is a B2B service not directed at children. We do not knowingly collect personal data from individuals under 18 years of age.
6. SUB-PROCESSORS AND INTERNATIONAL DATA TRANSFERS
We share personal data with the following categories of sub-processors in order to deliver the Service. All sub-processors are engaged under written data processing agreements compliant with Article 28 GDPR. Where personal data is transferred to processors outside the European Economic Area (EEA), we ensure an appropriate transfer mechanism is in place in accordance with Chapter V GDPR.
| Sub-processor | Role | Location | Transfer mechanism |
|---|---|---|---|
| Mistral AI SAS | AI inference: processes query text to generate AI Output | France (EEA) | No Chapter V transfer applicable — EEA entity. |
| Supabase Pte. Ltd | Database and authentication: stores account registration data and conversation history | Singapore. Data stored on AWS eu-west-1 (Ireland, EEA). | Standard Contractual Clauses (Module Two — controller to processor) pursuant to EU Commission Implementing Decision 2021/914 of 4 June 2021. Data Processing Agreement incorporating applicable SCCs executed 9 July 2026. Data stored on AWS eu-west-1 (Ireland, EEA). |
| Hostinger UAB | VPS hosting: RAG API, vector database (Qdrant), and embeddings processing | Germany, Frankfurt (EEA) | No Chapter V transfer applicable — EEA entity. |
| Vercel, Inc. | Frontend hosting and edge functions | USA (EU data processed via Vercel’s European infrastructure) | EU–U.S. Data Privacy Framework (DPF) adequacy decision — Vercel certified under DPF. Verified active: 18 May 2026 (dataprivacyframework.gov). |
| Resend, Inc. | Transactional email delivery (account activation, subscription notifications) | USA | EU–U.S. Data Privacy Framework (DPF) adequacy decision — Resend certified under DPF. Verified active: 18 May 2026 (dataprivacyframework.gov). |
| [PAYMENT PROCESSOR — PLACEHOLDER] | Payment processing: subscription billing, renewal, and invoicing | [To be completed when payment processing is activated] | [To be completed when payment processing is activated] |
DPF monitoring: We monitor the certification status of US sub-processors certified under the EU–U.S. Data Privacy Framework at dataprivacyframework.gov. If any US sub-processor’s DPF certification lapses or is revoked, we will implement Standard Contractual Clauses (Module 2) as a fallback transfer mechanism before continued processing.
Sub-processor updates: We will update this sub-processor schedule when material changes to our processor chain occur. Subscribers who have executed a Data Processing Agreement with us will be notified of sub-processor changes in accordance with the terms of that DPA.
We do not transfer personal data to any country outside the EEA other than to the United States via the mechanisms described above. We do not rely on Article 49 GDPR derogations for any routine or systematic transfers.
7. RETENTION PERIODS
We retain personal data for no longer than is necessary for the purposes for which it was collected, in accordance with the principle of storage limitation under Article 5(1)(e) GDPR. The retention periods applicable to each category of data are set out below.
| Data category | Retention period | Basis / justification |
|---|---|---|
| Account registration data (name, email, country) | Duration of subscription, plus 3 years from account termination | Polish Civil Code Art. 118 — general 3-year limitation period for claims arising from the contractual relationship. Data retained to enable resolution of disputes or claims arising post-termination. |
| Query text and AI Output (real-time processing) | Not persistently stored beyond session delivery, unless also captured in the operational log (see below) | Art. 5(1)(e) GDPR — data minimisation and storage limitation. Query content is processed in real time to generate AI Output and is not retained in a persistent store beyond what is captured in the operational log. |
| Operational query log (session ID, timestamp, query text, answer preview, source references, guardrail flag) | 12 months from the date of each log entry | Art. 5(1)(e) GDPR. Retained for security monitoring, abuse prevention, and dispute resolution. 12-month period reflects the standard contractual dispute window and our operational security review cycle. |
| Subscription and billing records (subscription tier, period, payment status, invoice references) | 5 years from the end of the tax year in which the transaction occurred | Polish Act of 29 August 1997 — Tax Ordinance (Ordynacja podatkowa) — mandatory 5-year accounting records retention. |
| Free Trial account data (all categories above) | 30 days from trial expiry, then permanent deletion | Art. 5(1)(e) GDPR. 30-day window maintained to permit trial reactivation. Data permanently deleted at expiry of window if no paid subscription is activated. |
At the expiry of each retention period, personal data is permanently deleted or irreversibly anonymised. Deletion obligations flow down to our sub-processors under the applicable Data Processing Agreements.
8. COOKIES AND TRACKING TECHNOLOGIES
The Dairy Chat platform uses a single session authentication cookie (httpOnly JSON Web Token — JWT) to maintain your authenticated session while you are logged in. This cookie is strictly necessary for the delivery of the Service and does not require your consent under Article 173 of the Polish Communications Law Act (Prawo komunikacji elektronicznej) and the applicable ePrivacy framework.
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| Session JWT | httpOnly, Secure, SameSite=Strict | Authentication — maintains your logged-in session. Not accessible to JavaScript. Not used for tracking or analytics. | Session duration (deleted on logout or browser close) |
We do not use advertising cookies, analytics cookies, third-party tracking technologies, or any cookie that requires consent under applicable ePrivacy law. If we add any such technologies in the future, this Policy and the platform’s cookie interface will be updated before deployment, and consent will be sought where legally required.
9. YOUR RIGHTS AS A DATA SUBJECT
As a data subject whose personal data we process, you have the following rights under GDPR and applicable Polish data protection law. These rights apply subject to the conditions and limitations set out in the GDPR and the Polish Act of 10 May 2018 on Personal Data Protection.
| Right | Description | Applies to our processing? |
|---|---|---|
| Access (Art. 15) | Right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data and related processing information. | Yes — all processing activities. |
| Rectification (Art. 16) | Right to have inaccurate personal data corrected and incomplete data completed. | Yes — account registration data. |
| Erasure (Art. 17) | Right to request deletion of personal data where, among other grounds, it is no longer necessary for the purpose for which it was collected, or the lawful basis no longer applies. | Yes, subject to overriding retention obligations (e.g., tax law — 5-year billing record retention; contractual limitation period — 3-year account data retention). |
| Restriction (Art. 18) | Right to restrict processing in certain circumstances (e.g., while accuracy is contested, or pending a legitimate interests objection). | Yes. |
| Data portability (Art. 20) | Right to receive personal data provided to us in a structured, commonly used, machine-readable format, and to transmit it to another controller, where processing is based on Art. 6(1)(b) and carried out by automated means. | Yes — applies to account registration data processed under Art. 6(1)(b) (name, email, country). Does not apply to query logs, which are processed under Art. 6(1)(f) and fall outside the scope of Art. 20 GDPR. |
| Objection (Art. 21) | Right to object at any time to processing based on Art. 6(1)(f) (legitimate interests). Where an objection is made, we will cease the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms. | Yes — applies to query logging under Art. 6(1)(f) (Section 4.3) and to retention of rejected and suspended account data under Art. 6(1)(f) (Section 4.5). Does not apply to processing under Art. 6(1)(b) (contract performance). |
| Withdrawal of consent (Art. 7(3)) | Right to withdraw consent at any time where processing is based on consent. | Not currently applicable — we do not rely on consent as a lawful basis for any processing activity described in this Policy. |
| Lodge a complaint (Art. 77) | Right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. | Yes — the competent supervisory authority for Dairy Chat Sp. z o.o. is the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych — UODO), ul. Stawki 2, 00-193 Warszawa, www.uodo.gov.pl. |
How to exercise your rights: Submit your request by email to privacy@dairychat.com. We will respond within one calendar month of receipt of your request (Art. 12(3) GDPR). Where requests are complex or numerous, we may extend this period by a further two months with prior notice. We will not charge a fee for handling requests unless they are manifestly unfounded or excessive.
Identity verification: We may ask you to verify your identity before processing a rights request, to prevent unauthorised access to personal data.
10. ARTIFICIAL INTELLIGENCE — EU AI ACT DISCLOSURE
Pursuant to Article 50 of Regulation (EU) 2024/1689 (EU AI Act), you are hereby informed that the Dairy Chat platform incorporates artificial intelligence systems, including large language models and retrieval-augmented generation technology, to generate AI Output in response to Subscriber Queries.
Dairy Chat Sp. z o.o. operates as a deployer of AI systems within the meaning of the EU AI Act. The AI systems used in the platform have been assessed as not constituting high-risk AI systems within the meaning of Annex III of the EU AI Act. AI Output constitutes general market intelligence only and does not involve automated decision-making with legal or similarly significant effects on any natural person for the purposes of Article 22 GDPR.
AI Output is generated automatically without human review prior to delivery. You are advised to independently verify AI Output before acting upon it. For full terms governing AI Output, see Section 7 of the B2B Terms and Conditions.
11. SECURITY
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, in accordance with Article 32 GDPR. Our current measures include:
- Data in transit: TLS 1.2 or higher for all data transmission between the platform and end users (frontend to user). Internal service-to-service communication between backend components is currently secured by shared secret authentication and IP-restricted access controls. End-to-end TLS across all internal service communication is on the implementation roadmap prior to launch; this Policy will be updated when that configuration is confirmed.
- Data at rest: encryption of personal data stored in our database infrastructure.
- Access controls: role-based access controls limiting access to personal data to authorised personnel only.
- Authentication: httpOnly, Secure, SameSite session tokens; no persistent client-side credential storage.
- Sub-processor security: contractual requirements imposed on all sub-processors to maintain appropriate technical and organisational measures.
No method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we are committed to maintaining appropriate safeguards and to notifying affected parties of any breach as required by Articles 33 and 34 GDPR.
12. PERSONAL DATA BREACH NOTIFICATION
In the event of a personal data breach, we will comply with our obligations under Articles 33 and 34 GDPR:
- Notification to UODO (Art. 33): Where a breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the President of UODO without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
- Notification to affected data subjects (Art. 34): Where a breach is likely to result in a high risk to the rights and freedoms of natural persons, we will communicate the breach to the affected data subjects without undue delay.
- Breach register (Art. 33(5)): We maintain an internal register of personal data breaches regardless of whether notification to UODO or data subjects is required.
If you become aware of any security incident or suspected breach involving your data, please notify us immediately at privacy@dairychat.com.
13. DATA PROTECTION OFFICER
Based on our current processing activities, Dairy Chat Sp. z o.o. is not required to appoint a Data Protection Officer (DPO) under Article 37 GDPR. The three mandatory triggers for DPO appointment (public authority or body; large-scale systematic monitoring of data subjects; large-scale processing of special categories of data) do not apply to our current operations.
All data protection queries, rights requests, and complaints should be directed to our data protection contact at privacy@dairychat.com. We will keep the need for DPO appointment under review as our operations develop.
14. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time to reflect changes in our data processing activities, applicable law, or operational practices. Material changes will be communicated to Subscribers by email to the registered account address at least 30 days before the change takes effect.
The current version of this Policy is always available at https://dairychat.com/privacy-policy. The version number and effective date at the top of this document indicate when it was last updated.
15. GOVERNING LAW AND SUPERVISORY AUTHORITY
This Privacy Policy and any non-contractual obligations arising out of or in connection with it are governed by the laws of Poland.
The competent supervisory authority is:
| Authority | President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych — UODO) |
|---|---|
| Address | ul. Stawki 2, 00-193 Warszawa, Poland |
| Website | www.uodo.gov.pl |
| Telephone | +48 22 531 03 00 |
You have the right to lodge a complaint with UODO at any time if you consider that our processing of your personal data violates applicable data protection law. We would, however, ask that you contact us at privacy@dairychat.com in the first instance so that we have the opportunity to address your concern.
16. CONTACT
For any questions about this Privacy Policy, to exercise your data subject rights, or to raise a data protection concern, please contact us:
| privacy@dairychat.com | |
|---|---|
| Post | Dairy Chat Sp. z o.o., ul. Zygmunta Augusta 5, lok. 2, 31-504 Kraków, Poland |
| Response time | Within one calendar month of receipt (Art. 12(3) GDPR) |
Version 1.0 — Effective Date: 09.07.2026
Dairy Chat Sp. z o.o. | KRS: 0001246289 | NIP: 6751829475 | REGON: 544952819 | Kraków, Poland
privacy@dairychat.com