Skip to content

Privacy Policy

Version 1.0 · Effective from 5 October 2026

1. Controller

The controller of your personal data is Custom Service Arleta Marczyńska, ul. Bielska 107, 32-652 Bulowice, Poland, NIP (tax ID) 5492373228, REGON 528250567 ("we"). We have not appointed a data protection officer. For all data-related matters, write to hej@wojs.app.

This Policy fulfils the information obligation under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). Capitalised terms have the meaning given to them in the Terms of Service.

2. When we are the controller and when we process data on someone else's behalf

  • We are the controller of the data of your Account, personal Workspace, billing, correspondence with us and the security of the Service.
  • When you use a team Workspace of your employer or another organisation, a Creator's training product, or training embedded on another website, the controller of the data in that Workspace (conversations, Reports, progress, assignments) is that organisation or that Creator. We process the data on their behalf under a data processing agreement. For matters concerning this data, please contact them first, and we will assist them.
  • Stripe Payments Europe, Limited is an independent controller of payment data.

3. What data we process, for what purpose and on what legal basis

  • Data
    Email address, display name, language, time zone, form of address, date of acceptance of the Terms
    Purpose
    Creating and maintaining the Account, sign-in by link, contact about the service
    Legal basis (GDPR)
    Article 6(1)(b) (contract)
  • Data
    Content of practice conversations (your statements and the AI Counterpart's replies), duration, mode (chat or voice)
    Purpose
    Conducting the exercise, preparing the Report, history and progress
    Legal basis (GDPR)
    Article 6(1)(b) (contract)
  • Data
    Voice during a voice conversation
    Purpose
    Speech recognition and live response from the AI Counterpart. We do not record your voice. Only the transcript reaches the Service
    Legal basis (GDPR)
    Article 6(1)(b) (contract)
  • Data
    Reports: score, criteria, quotations, suggestions, certificates (with first name and surname)
    Purpose
    Feedback, progress, certificate of completion
    Legal basis (GDPR)
    Article 6(1)(b) (contract)
  • Data
    Creators' materials and scenarios, uploaded recordings of real-life conversations (when the feature is enabled)
    Purpose
    Creating scenarios, analysing a recording at the User's request
    Legal basis (GDPR)
    Article 6(1)(b) (contract)
  • Data
    Billing data: email, Workspace name, orders, invoices, Minute usage
    Purpose
    Selling Plans, accounting for Minutes, issuing invoices, tax and accounting obligations
    Legal basis (GDPR)
    Article 6(1)(b) (contract) and (c) (legal obligation)
  • Data
    Activity log (who did what and when in a Workspace, without conversation content), hashes of IP addresses and email addresses in rate-limit counters, technical logs
    Purpose
    Security, abuse prevention, accountability, establishment and defence of legal claims
    Legal basis (GDPR)
    Article 6(1)(f) (legitimate interest)
  • Data
    Correspondence with us, complaints, content notices
    Purpose
    Replying, handling complaints and notices
    Legal basis (GDPR)
    Article 6(1)(b), (c) and (f)

Providing an email address is a condition for creating an Account. You provide other data voluntarily, but without it some features will not work (e.g. no conversation means no Report, no billing data means no purchase).

We do not collect special categories of data (e.g. about health or beliefs). Please do not enter them into conversations or materials. If you enter them, you can delete them together with the conversation in the Service, and we will delete them at your request.

We do not process data for marketing purposes, we do not profile for advertising purposes and we do not sell data.

4. Artificial intelligence and automated decisions

The AI Counterpart, Reports, hints and draft scenarios are generated automatically by the models of the providers listed in section 6. The models receive the conversation content and scenario instructions, not your email address.

We do not train models on your conversations. At OpenAI we use the API, under which customer data is not used to train models, and response storage is disabled. At the voice provider (ElevenLabs), voice recording is disabled and the conversation record is deleted after 30 days.

A Report and the automatic completion of a programme (certificate) are assessments of an exercise, not a decision producing legal effects concerning you within the meaning of Article 22 GDPR. If an organisation uses the results in HR matters, it is responsible for human involvement in the decision and may request information from us about how the assessment works. You can ask for an explanation of a Report and flag a result you disagree with.

5. What others can see

  • Personal Workspace: only you can see your conversations and Reports, unless you share them yourself.
  • Team Workspace: depending on the Workspace Administrator's settings, managers and trainers see a summary of results or also transcripts. The visibility settings are shown in the Workspace.
  • Creator product: the Creator sees the results and completions of the Learners of their product.
  • Sharing: a conversation or Report can be seen by the person, or anyone with the link, with whom you share it. The link expires after the set time.
  • Certificate: the verification page with first name and surname, programme, issuer and result is available to anyone who knows the certificate number and is not indexed by search engines.
  • Creator integrations (API, webhooks): a Creator can retrieve their Learners' results and receive them on their server. The Creator learns your account identifier only after you accept the access.

6. Data recipients and transfers outside the EEA

We entrust data to providers without which the Service cannot operate. Each of them acts under an agreement that obliges it to protect the data. The current list with descriptions is on the Subprocessors page.

  • Recipient
    Supabase, Inc.
    Purpose
    database, authentication, file storage
    Place of processing and transfer basis
    EU (Frankfurt, Germany); access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses
  • Recipient
    Vercel Inc.
    Purpose
    application and serverless hosting, technical logs
    Place of processing and transfer basis
    EU (Frankfurt, Germany) and global edge network; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses
  • Recipient
    OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.)
    Purpose
    AI counterpart in chat, Reports, hints, scenario builder, transcription of uploaded recordings
    Place of processing and transfer basis
    US and EU; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses. API data is not used for model training, response storage disabled, up to 30 days for abuse monitoring
  • Recipient
    Eleven Labs Inc.
    Purpose
    voice conversations: speech recognition, AI counterpart voice
    Place of processing and transfer basis
    US; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses. Conversation record at the provider deleted after 30 days
  • Recipient
    Plus Five Five, Inc. (Resend)
    Purpose
    email delivery (sign-in link, account notifications)
    Place of processing and transfer basis
    US; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses
  • Recipient
    nazwa.pl sp. z o.o.
    Purpose
    mailbox for contact and complaints
    Place of processing and transfer basis
    Poland; no transfer outside the EEA
  • Recipient
    Stripe Payments Europe, Limited
    Purpose
    payment processing, invoices, customer portal
    Place of processing and transfer basis
    Ireland (EU), with access by the Stripe group from the US; Stripe is an independent controller for payment data; transfers under the Stripe privacy policy

Data is transferred to countries outside the European Economic Area on the basis of a European Commission adequacy decision (EU-US Data Privacy Framework) in respect of certified recipients, and otherwise on the basis of standard contractual clauses adopted by the Commission (Article 46(2)(c) GDPR). You can obtain a copy of the safeguards by writing to the address given in section 1.

Data may also be received by: the Creator or organisation to the extent set out in section 5, the webhook address set by the Creator, our accountants (billing data) and public authorities where required by law.

7. How long we keep data

  • Data
    Account and profile
    Period
    until the Account is deleted
  • Data
    Conversation content (transcripts), quotations in Reports (evidence, summary, quoted statements), comments attached to statements
    Period
    by default 365 days from the end of the conversation. The Workspace Administrator of a team Workspace may set a different period (from 7 days to 10 years). Earlier if you delete the conversation or the Account
  • Data
    Voice in a voice conversation
    Period
    not recorded. The conversation record at the voice provider (transcript and technical data) is deleted after 30 days
  • Data
    Uploaded recordings of real-life conversations
    Period
    by default 30 days from upload (the Workspace Administrator may set a different period)
  • Data
    Results, Reports without quotations, progress, certificates
    Period
    until the conversation or the Account is deleted (after the Account is deleted, certificates are revoked and the name is removed)
  • Data
    Orders, invoices, Minute usage
    Period
    5 years from the end of the calendar year in which the tax payment deadline expired
  • Data
    Activity log
    Period
    2 years
  • Data
    Technical data: webhook deliveries and provider events
    Period
    90 days
  • Data
    API idempotency keys (without conversation content)
    Period
    30 days
  • Data
    Rate-limit counters (hashes of IP and email addresses)
    Period
    about one day
  • Data
    Server logs
    Period
    briefly, usually a few days, according to the hosting provider's settings
  • Data
    Correspondence and complaints
    Period
    until the matter is closed and then until the limitation period for claims expires
  • Data
    Database backups
    Period
    daily backups overwritten in the provider's cycle. Deleted data disappears from backups as they rotate

8. Your rights

You have the right to:

  • access your data and obtain a copy of it (Article 15). You can download a data export in JSON format yourself in the Account settings,
  • rectification of your data (Article 16). You can change your display name and settings in your Account,
  • erasure of your data (Article 17). Deletion of the Account and of individual conversations is available in the settings,
  • restriction of processing (Article 18),
  • data portability (Article 20), including through the export,
  • object to processing based on legitimate interest (Article 21),
  • withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal,
  • lodge a complaint with the President of the Personal Data Protection Office (Prezes UODO) (ul. Stawki 2, 00-193 Warsaw, Poland) or with the supervisory authority in the country where you live or work.

Send requests to hej@wojs.app from the address associated with your Account. We reply without undue delay and at the latest within one month. Where the data comes from an organisation's or Creator's Workspace, we will forward the request to the controller and help them fulfil it.

Deleting the Account deletes conversation content, recordings, comments, shares, memberships and your name. What remains is data we are required by law to keep (e.g. invoices), and results without conversation content in organisations' Workspaces in which you practised, unless the organisation deletes them.

9. Security

Our measures include: encrypted connections (HTTPS with HSTS), isolation of Workspace data at database level (Row Level Security), storing API keys, invitation tokens and share links only as hashes, passwordless sign-in, rate limits, webhook signatures, logging of administrative actions and regular backups. Hidden scenario instructions never reach the participant's browser. Technical details are described in the Data Processing Agreement.

We will inform you without undue delay of a personal data breach that is likely to result in a high risk to your rights.

10. Cookies

We use only cookies that are necessary for the Service to function and to remember your settings. We do not use analytics or advertising cookies. Details: Cookie Policy.

11. Age

The Service is intended for people aged 16 or over. We do not knowingly collect data of younger people. If we learn of such an Account, we will delete it.

12. Changes to this Policy

We notify material changes in the Service and by email before they take effect. The version and effective date are shown at the top of the document.