Umova · GDPR

Privacy Policy

This document also serves as the information notice on data processing (art. 13 GDPR). Version for the the beta — it may change; we will notify you of any material changes.

1. Data controller

The controller of your data is DevOps Jakub Pazdyga, VAT ID 2220682818, ul. Powstańców Śląskich 57a, 44-361 Syrynia, Poland. Contact for data matters: contact@umova.eu.

Data about your counterparties that you enter into Umova is processed on your behalf — in that case you are the controller and Umova is the processor (under a data processing agreement).

If you enable your private mail alias, we treat messages sent to that address exactly like content you paste yourself: their text goes into the deal thread as evidence (with the quoted history stripped), and from it we propose terms that you confirm. We do not store the raw message with its headers, nor the sender's address; of attachments we keep the name, type, size and checksum, without their content. You remain the controller of this data.

The »contract« referred to below as a legal basis is the contract for the supply of services by electronic means, the content of which is set out in the Terms of Service; you conclude it when you create an account.

2. What data, why, and on what basis

DataPurposeBasis
E-mail (nickname optional)Account and password-free sign-in (magic link)contract
Business details (name, VAT ID, address, IBAN)E-invoices and settlementscontract / legal obligation
Deal and terms dataThe core function of the servicecontract
Authentication secrets (TOTP code, passkeys)Strong identity confirmationlegitimate interest — security
Counterparty data (VAT number, VAT status)Due diligencelegitimate interest
Social account metrics and tokens (if you connect them)Media kit / pricing — your own metricsconsent / contract
Banking data (if you connect it)Detecting payments against invoicesconsent / contract
Media for analysisChecking an acceptance criterion — we do not store the contentcontract (ephemeral)
Technical data (IP for rate limits, session)Security, abuse preventionlegitimate interest
Marketing consent (optional)News about what's newconsent — withdrawable
Withdrawal data (date, amount, refund status)Handling withdrawal from the contract and refunding paymentlegal obligation
Voice recording (dictation)Speech-to-text in the instruction field — we do not store the recordings, we delete them after recognitioncontract (ephemeral)
Source of the visit to the siteChecking which routes creators reach us bylegitimate interest
Reason for cancelling (if you give one)Improving the service — the free-text field is filled in voluntarilylegitimate interest

Minimisation: we collect the minimum. We do not store the content of analysed media. The IP address used for rate limits is not kept in raw form (a hash). We do not write message content, e-mail addresses or sign-in links to our logs — we do write technical identifiers of the account and of the case, needed to diagnose reports.

3. Artificial intelligence

AI in Umova only suggests; every outgoing action is approved by a human. We do not take fully automated decisions producing legal effects concerning you (Article 22 GDPR).

Inference takes place in EU regions — we use European profiles exclusively; global profiles are excluded in the configuration. The provider (Amazon Bedrock) states that by default it does not store model inputs or outputs, that service operators have no access to them, and that model providers have no access to prompts or completions.

Amounts and dates written in figures are masked before being sent to the model and substituted back by deterministic code — in the terms engine and in the UmovAI assistant; there, the model sees no number at all. In media analysis and in the public tools, the model receives in full the text or the image you pass to it. Numbers written out in words (“two thousand zlotys”) are not masked.

4. Who we entrust data to (sub-processors)

We do not sell data. No advertising. 0% commission.

With your consent we use measurement tools: Google Analytics 4 and Google Ads (Google Ireland Limited), Meta Pixel (Meta Platforms Ireland Limited) and TikTok Pixel (TikTok Information Technologies UK Limited). Without consent none of them loads. “No ads” above means we do not show ads inside the service — not that we do not measure our own campaigns.

  • Amazon Web Services — database, working files, AI inference, speech recognition, secrets, logs and queues — in the EU region (eu-central-1); AI models exclusively through European profiles.
  • Amazon Web Services — edge services (CloudFront, Route 53, TLS certificate): HTTP traffic is handled globally, the certificate is stored outside the EU. This is a deliberate departure from the principle of processing in the EU, limited to the transport layer.
  • Mailgun (Sinch) — outgoing and incoming mail (sign-in links, demand letters, notifications, deal intake): the recipient's address, the subject and the full content — servers in the EU region; a non-EU company, standard contractual clauses.
  • ForwardEmail and home.pl — operation of the contact@umova.eu mailbox, that is, of the channel through which we receive your requests concerning data.
  • Ministerstwo Finansów (the Polish Ministry of Finance) — Krajowy System e-Faktur (the Polish national e-invoicing system): structured invoices for our service, together with the buyer's data. The public authority acts here as a separate controller on the basis of VAT legislation.
  • PayU and Revolut — handling payments for plans. This is not entrustment: payment operators act as separate controllers of the payer's data, because they have their own regulatory obligations.
  • Enable Banking (Finland) — retrieving account history if you connect your bank. The feature is currently switched off; you confirm payments manually.
  • Social platforms — only where you connect an account yourself, on the basis of the consent granted in that service.
  • Google Ireland Limited — traffic and campaign measurement (Google Analytics 4), only after your consent to analytics cookies. We send the event name and, for payments, the amount and currency — never your email address, account identifier or content from the service.

5. Transfers outside the EEA

Production processing (database, files, AI, email) takes place in EU regions (AWS eu-central-1, Mailgun EU). The providers — AWS and Mailgun (Sinch) — are non-EU entities operating under data processing agreements and standard contractual clauses (Decision 2021/914/EU). These providers' sub-processor lists include entities outside the EEA. That is why we speak of “processing in EU regions” rather than of excluding all access. Connecting a social media account involves transferring data to that platform's provider.

The measurement tools listed in section 4 process data outside the EEA (including in the USA) under the standard contractual clauses contained in those providers’ terms. Without your consent we send them nothing.

6. How long we keep data

  • Account and data — until you delete the account. We do not erase them automatically once time has passed: the material of a deal may be the only evidence in a dispute, and the limitation period depends on the case.
  • Material for analysis (image, audio, video) — we delete it after the analysis, we do not store it. What remains in the record is only the verdict and a short quotation-as-evidence from the audio layer, where the assessment of the criterion rests on it.
  • Voice recording from dictation — we delete it after speech recognition.
  • Technical data for rate limits — ephemeral.
  • Technical logs (identifiers of the account and of the case, without content) — deleting the account does not cover them; the log and metric store has its own, independent retention period.
  • Data required by law (for example settlement records) — for the period laid down by the regulations.
  • Withdrawal record — kept even after the account is deleted, with no link to you (proof that a legal obligation was fulfilled, basis for a corrective invoice).

7. Your rights

You have the right to: access, rectification, erasure, restriction, objection, data portability and withdrawal of consent. You may lodge a complaint with the supervisory authority (in Poland: the President of the Personal Data Protection Office). Umova lets you export your data and delete your account (which erases sessions, tokens and secrets). To exercise these rights: contact@umova.eu. You can withdraw a consent in your settings.

8. Security

Among other measures we use encryption of sensitive data at rest (AES-256: TOTP secret, IBAN, tokens), strong authentication for sensitive actions, transmission over TLS, data minimisation, no personal data in logs, and rate limiting.

Public forms are protected against automated abuse by a computational puzzle your browser solves. The mechanism runs on our own infrastructure — we send no IP address or other data to an external provider for this purpose.

9. Cookies

Essential session cookies (keeping you signed in) always work — without them the service will not run.

Beyond those we use analytics and advertising cookies, but only with your prior consent. There are two independent consents: analytics means traffic measurement (which pages are visited and where visitors come from), advertising means measuring our campaigns and ad targeting. We ask on your first visit; you can withdraw consent at any time in Settings.

We do not send these tools your email address, account identifier or any content from the service — only the event name (for example “purchase”) and, for payments, the amount and currency. Until you consent, these scripts do not load at all.

10. Connected social media accounts

If you connect your account on a social media service (YouTube, TikTok, Instagram, Facebook, LinkedIn, X, Snapchat), we retrieve from that service's official API only the public statistics of your own account: the account name and identifier, the number of followers, the number of accounts followed, the number of items published and the view count, and — where the platform makes them available — also the number of likes and the account type.

Purpose: to compose your creator card (media kit), which you alone decide to show to a brand. Legal basis: performance of a contract — Article 6(1)(b) GDPR. The access token is stored encrypted (AES-256) solely so that the figures can be refreshed at your request.

You may withdraw your consent at any time — in Umova (“Disconnect”) or directly with the service. Disconnecting deletes the token and the retrieved statistics. Consent also expires automatically after 180 days.

YouTube data: Umova's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • We do not read the content of your material or your private messages.
  • We do not retrieve other users' data — only your own.
  • We do not publish anything on your behalf and change nothing.
  • We do not share this data with third parties.
  • We do not use it for advertising, profiling or training AI models.

11. Contact

DevOps Jakub Pazdyga, ul. Powstańców Śląskich 57a, 44-361 Syrynia, Poland, contact@umova.eu.

Draft version for the beta — the final wording, contact details and transfer safeguards will be confirmed before public launch. In the event of any discrepancy between language versions, the Polish version prevails.