Privacy Policy
Version 1.0 · Effective from 5 October 2026
1. Controller
The controller of your personal data is Custom Service Arleta Marczyńska, ul. Bielska 107, 32-652 Bulowice, Poland, NIP (tax ID) 5492373228, REGON 528250567 ("we"). We have not appointed a data protection officer. For all data-related matters, write to hej@wojs.app.
This Policy fulfils the information obligation under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). Capitalised terms have the meaning given to them in the Terms of Service.
2. When we are the controller and when we process data on someone else's behalf
- We are the controller of the data of your Account, personal Workspace, billing, correspondence with us and the security of the Service.
- When you use a team Workspace of your employer or another organisation, a Creator's training product, or training embedded on another website, the controller of the data in that Workspace (conversations, Reports, progress, assignments) is that organisation or that Creator. We process the data on their behalf under a data processing agreement. For matters concerning this data, please contact them first, and we will assist them.
- Stripe Payments Europe, Limited is an independent controller of payment data.
3. What data we process, for what purpose and on what legal basis
- Data
- Email address, display name, language, time zone, form of address, date of acceptance of the Terms
- Purpose
- Creating and maintaining the Account, sign-in by link, contact about the service
- Legal basis (GDPR)
- Article 6(1)(b) (contract)
- Data
- Content of practice conversations (your statements and the AI Counterpart's replies), duration, mode (chat or voice)
- Purpose
- Conducting the exercise, preparing the Report, history and progress
- Legal basis (GDPR)
- Article 6(1)(b) (contract)
- Data
- Voice during a voice conversation
- Purpose
- Speech recognition and live response from the AI Counterpart. We do not record your voice. Only the transcript reaches the Service
- Legal basis (GDPR)
- Article 6(1)(b) (contract)
- Data
- Reports: score, criteria, quotations, suggestions, certificates (with first name and surname)
- Purpose
- Feedback, progress, certificate of completion
- Legal basis (GDPR)
- Article 6(1)(b) (contract)
- Data
- Creators' materials and scenarios, uploaded recordings of real-life conversations (when the feature is enabled)
- Purpose
- Creating scenarios, analysing a recording at the User's request
- Legal basis (GDPR)
- Article 6(1)(b) (contract)
- Data
- Billing data: email, Workspace name, orders, invoices, Minute usage
- Purpose
- Selling Plans, accounting for Minutes, issuing invoices, tax and accounting obligations
- Legal basis (GDPR)
- Article 6(1)(b) (contract) and (c) (legal obligation)
- Data
- Activity log (who did what and when in a Workspace, without conversation content), hashes of IP addresses and email addresses in rate-limit counters, technical logs
- Purpose
- Security, abuse prevention, accountability, establishment and defence of legal claims
- Legal basis (GDPR)
- Article 6(1)(f) (legitimate interest)
- Data
- Correspondence with us, complaints, content notices
- Purpose
- Replying, handling complaints and notices
- Legal basis (GDPR)
- Article 6(1)(b), (c) and (f)
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address, display name, language, time zone, form of address, date of acceptance of the Terms | Creating and maintaining the Account, sign-in by link, contact about the service | Article 6(1)(b) (contract) |
| Content of practice conversations (your statements and the AI Counterpart's replies), duration, mode (chat or voice) | Conducting the exercise, preparing the Report, history and progress | Article 6(1)(b) (contract) |
| Voice during a voice conversation | Speech recognition and live response from the AI Counterpart. We do not record your voice. Only the transcript reaches the Service | Article 6(1)(b) (contract) |
| Reports: score, criteria, quotations, suggestions, certificates (with first name and surname) | Feedback, progress, certificate of completion | Article 6(1)(b) (contract) |
| Creators' materials and scenarios, uploaded recordings of real-life conversations (when the feature is enabled) | Creating scenarios, analysing a recording at the User's request | Article 6(1)(b) (contract) |
| Billing data: email, Workspace name, orders, invoices, Minute usage | Selling Plans, accounting for Minutes, issuing invoices, tax and accounting obligations | Article 6(1)(b) (contract) and (c) (legal obligation) |
| Activity log (who did what and when in a Workspace, without conversation content), hashes of IP addresses and email addresses in rate-limit counters, technical logs | Security, abuse prevention, accountability, establishment and defence of legal claims | Article 6(1)(f) (legitimate interest) |
| Correspondence with us, complaints, content notices | Replying, handling complaints and notices | Article 6(1)(b), (c) and (f) |
Providing an email address is a condition for creating an Account. You provide other data voluntarily, but without it some features will not work (e.g. no conversation means no Report, no billing data means no purchase).
We do not collect special categories of data (e.g. about health or beliefs). Please do not enter them into conversations or materials. If you enter them, you can delete them together with the conversation in the Service, and we will delete them at your request.
We do not process data for marketing purposes, we do not profile for advertising purposes and we do not sell data.
4. Artificial intelligence and automated decisions
The AI Counterpart, Reports, hints and draft scenarios are generated automatically by the models of the providers listed in section 6. The models receive the conversation content and scenario instructions, not your email address.
We do not train models on your conversations. At OpenAI we use the API, under which customer data is not used to train models, and response storage is disabled. At the voice provider (ElevenLabs), voice recording is disabled and the conversation record is deleted after 30 days.
A Report and the automatic completion of a programme (certificate) are assessments of an exercise, not a decision producing legal effects concerning you within the meaning of Article 22 GDPR. If an organisation uses the results in HR matters, it is responsible for human involvement in the decision and may request information from us about how the assessment works. You can ask for an explanation of a Report and flag a result you disagree with.
5. What others can see
- Personal Workspace: only you can see your conversations and Reports, unless you share them yourself.
- Team Workspace: depending on the Workspace Administrator's settings, managers and trainers see a summary of results or also transcripts. The visibility settings are shown in the Workspace.
- Creator product: the Creator sees the results and completions of the Learners of their product.
- Sharing: a conversation or Report can be seen by the person, or anyone with the link, with whom you share it. The link expires after the set time.
- Certificate: the verification page with first name and surname, programme, issuer and result is available to anyone who knows the certificate number and is not indexed by search engines.
- Creator integrations (API, webhooks): a Creator can retrieve their Learners' results and receive them on their server. The Creator learns your account identifier only after you accept the access.
6. Data recipients and transfers outside the EEA
We entrust data to providers without which the Service cannot operate. Each of them acts under an agreement that obliges it to protect the data. The current list with descriptions is on the Subprocessors page.
- Recipient
- Supabase, Inc.
- Purpose
- database, authentication, file storage
- Place of processing and transfer basis
- EU (Frankfurt, Germany); access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses
- Recipient
- Vercel Inc.
- Purpose
- application and serverless hosting, technical logs
- Place of processing and transfer basis
- EU (Frankfurt, Germany) and global edge network; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses
- Recipient
- OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.)
- Purpose
- AI counterpart in chat, Reports, hints, scenario builder, transcription of uploaded recordings
- Place of processing and transfer basis
- US and EU; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses. API data is not used for model training, response storage disabled, up to 30 days for abuse monitoring
- Recipient
- Eleven Labs Inc.
- Purpose
- voice conversations: speech recognition, AI counterpart voice
- Place of processing and transfer basis
- US; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses. Conversation record at the provider deleted after 30 days
- Recipient
- Plus Five Five, Inc. (Resend)
- Purpose
- email delivery (sign-in link, account notifications)
- Place of processing and transfer basis
- US; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses
- Recipient
- nazwa.pl sp. z o.o.
- Purpose
- mailbox for contact and complaints
- Place of processing and transfer basis
- Poland; no transfer outside the EEA
- Recipient
- Stripe Payments Europe, Limited
- Purpose
- payment processing, invoices, customer portal
- Place of processing and transfer basis
- Ireland (EU), with access by the Stripe group from the US; Stripe is an independent controller for payment data; transfers under the Stripe privacy policy
| Recipient | Purpose | Place of processing and transfer basis |
|---|---|---|
| Supabase, Inc. | database, authentication, file storage | EU (Frankfurt, Germany); access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses |
| Vercel Inc. | application and serverless hosting, technical logs | EU (Frankfurt, Germany) and global edge network; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses |
| OpenAI (OpenAI Ireland Ltd / OpenAI, L.L.C.) | AI counterpart in chat, Reports, hints, scenario builder, transcription of uploaded recordings | US and EU; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses. API data is not used for model training, response storage disabled, up to 30 days for abuse monitoring |
| Eleven Labs Inc. | voice conversations: speech recognition, AI counterpart voice | US; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses. Conversation record at the provider deleted after 30 days |
| Plus Five Five, Inc. (Resend) | email delivery (sign-in link, account notifications) | US; access from the US possible: EU-US Data Privacy Framework (where certified) or standard contractual clauses |
| nazwa.pl sp. z o.o. | mailbox for contact and complaints | Poland; no transfer outside the EEA |
| Stripe Payments Europe, Limited | payment processing, invoices, customer portal | Ireland (EU), with access by the Stripe group from the US; Stripe is an independent controller for payment data; transfers under the Stripe privacy policy |
Data is transferred to countries outside the European Economic Area on the basis of a European Commission adequacy decision (EU-US Data Privacy Framework) in respect of certified recipients, and otherwise on the basis of standard contractual clauses adopted by the Commission (Article 46(2)(c) GDPR). You can obtain a copy of the safeguards by writing to the address given in section 1.
Data may also be received by: the Creator or organisation to the extent set out in section 5, the webhook address set by the Creator, our accountants (billing data) and public authorities where required by law.
7. How long we keep data
- Data
- Account and profile
- Period
- until the Account is deleted
- Data
- Conversation content (transcripts), quotations in Reports (evidence, summary, quoted statements), comments attached to statements
- Period
- by default 365 days from the end of the conversation. The Workspace Administrator of a team Workspace may set a different period (from 7 days to 10 years). Earlier if you delete the conversation or the Account
- Data
- Voice in a voice conversation
- Period
- not recorded. The conversation record at the voice provider (transcript and technical data) is deleted after 30 days
- Data
- Uploaded recordings of real-life conversations
- Period
- by default 30 days from upload (the Workspace Administrator may set a different period)
- Data
- Results, Reports without quotations, progress, certificates
- Period
- until the conversation or the Account is deleted (after the Account is deleted, certificates are revoked and the name is removed)
- Data
- Orders, invoices, Minute usage
- Period
- 5 years from the end of the calendar year in which the tax payment deadline expired
- Data
- Activity log
- Period
- 2 years
- Data
- Technical data: webhook deliveries and provider events
- Period
- 90 days
- Data
- API idempotency keys (without conversation content)
- Period
- 30 days
- Data
- Rate-limit counters (hashes of IP and email addresses)
- Period
- about one day
- Data
- Server logs
- Period
- briefly, usually a few days, according to the hosting provider's settings
- Data
- Correspondence and complaints
- Period
- until the matter is closed and then until the limitation period for claims expires
- Data
- Database backups
- Period
- daily backups overwritten in the provider's cycle. Deleted data disappears from backups as they rotate
| Data | Period |
|---|---|
| Account and profile | until the Account is deleted |
| Conversation content (transcripts), quotations in Reports (evidence, summary, quoted statements), comments attached to statements | by default 365 days from the end of the conversation. The Workspace Administrator of a team Workspace may set a different period (from 7 days to 10 years). Earlier if you delete the conversation or the Account |
| Voice in a voice conversation | not recorded. The conversation record at the voice provider (transcript and technical data) is deleted after 30 days |
| Uploaded recordings of real-life conversations | by default 30 days from upload (the Workspace Administrator may set a different period) |
| Results, Reports without quotations, progress, certificates | until the conversation or the Account is deleted (after the Account is deleted, certificates are revoked and the name is removed) |
| Orders, invoices, Minute usage | 5 years from the end of the calendar year in which the tax payment deadline expired |
| Activity log | 2 years |
| Technical data: webhook deliveries and provider events | 90 days |
| API idempotency keys (without conversation content) | 30 days |
| Rate-limit counters (hashes of IP and email addresses) | about one day |
| Server logs | briefly, usually a few days, according to the hosting provider's settings |
| Correspondence and complaints | until the matter is closed and then until the limitation period for claims expires |
| Database backups | daily backups overwritten in the provider's cycle. Deleted data disappears from backups as they rotate |
8. Your rights
You have the right to:
- access your data and obtain a copy of it (Article 15). You can download a data export in JSON format yourself in the Account settings,
- rectification of your data (Article 16). You can change your display name and settings in your Account,
- erasure of your data (Article 17). Deletion of the Account and of individual conversations is available in the settings,
- restriction of processing (Article 18),
- data portability (Article 20), including through the export,
- object to processing based on legitimate interest (Article 21),
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal,
- lodge a complaint with the President of the Personal Data Protection Office (Prezes UODO) (ul. Stawki 2, 00-193 Warsaw, Poland) or with the supervisory authority in the country where you live or work.
Send requests to hej@wojs.app from the address associated with your Account. We reply without undue delay and at the latest within one month. Where the data comes from an organisation's or Creator's Workspace, we will forward the request to the controller and help them fulfil it.
Deleting the Account deletes conversation content, recordings, comments, shares, memberships and your name. What remains is data we are required by law to keep (e.g. invoices), and results without conversation content in organisations' Workspaces in which you practised, unless the organisation deletes them.
9. Security
Our measures include: encrypted connections (HTTPS with HSTS), isolation of Workspace data at database level (Row Level Security), storing API keys, invitation tokens and share links only as hashes, passwordless sign-in, rate limits, webhook signatures, logging of administrative actions and regular backups. Hidden scenario instructions never reach the participant's browser. Technical details are described in the Data Processing Agreement.
We will inform you without undue delay of a personal data breach that is likely to result in a high risk to your rights.
11. Age
The Service is intended for people aged 16 or over. We do not knowingly collect data of younger people. If we learn of such an Account, we will delete it.
12. Changes to this Policy
We notify material changes in the Service and by email before they take effect. The version and effective date are shown at the top of the document.