PLEN

Privacy Policy

Last updated: 23 October 2025.
This Privacy Policy (the “Policy”) sets out the rules for the processing of personal data by Askee Sp. z o.o., with its registered office in Gdańsk, ul. Gostyńska 91, 80-298 Gdańsk, Poland, VAT ID (NIP): 5223018301, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court Gdańsk-Północ in Gdańsk, 7th Commercial Division of the National Court Register, under number 0000522010 (“Askee”, the “Controller” or the “Processor”), in connection with the use of the Askee – AI Assistant application (the “Service”) provided under a SaaS model.
The Policy complies with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the “GDPR”), the Polish Personal Data Protection Act of 10 May 2018 and other applicable laws, including those governing artificial intelligence (e.g. the AI Act).

1. Data controller and contact details

The controller of the personal data of Customers and Users of the Service is Askee Sp. z o.o., ul. Gostyńska 91, 80-298 Gdańsk, Poland, e-mail: kontakt@askee.pl.
For matters relating to personal data protection, please contact us at: kontakt@askee.pl or by post to Askee’s registered office.
Where Askee processes personal data on behalf of the Customer (e.g. data entered into the Service by the Customer), it acts as a data processor, and the rules of processing are set out in the Data Processing Agreement annexed to the Service Terms and Conditions.

2. Purposes and legal bases of processing

Askee processes personal data for the following purposes and on the following legal bases:

Providing the Askee – AI Assistant Service:

  • Purpose: Performance of the Agreement, including granting access to the Service, generating AI responses, storing interaction history and providing technical support.
  • Legal basis: Performance of a contract (Article 6(1)(b) GDPR) or, for data processed on behalf of the Customer, entrustment of data processing (Article 28 GDPR).
  • Data: First name, surname, e-mail address, behavioural data (e.g. query history) and other data entered by the Customer or Users.

Account management and billing:

  • Purpose: Creating and administering the Customer Account, issuing invoices and handling payments.
  • Legal basis: Performance of a contract (Article 6(1)(b) GDPR) and a legal obligation (Article 6(1)(c) GDPR, e.g. tax regulations).
  • Data: Identification data (e.g. first name, surname, VAT ID, address) and billing data.

Technical support and customer service:

  • Purpose: Handling enquiries, complaints and technical requests.
  • Legal basis: Performance of a contract (Article 6(1)(b) GDPR) or the legitimate interest of the Controller (Article 6(1)(f) GDPR – ensuring the quality of the Service).
  • Data: Contact details and the content of requests.

Ensuring the security of the Service:

  • Purpose: Monitoring system security, detecting and preventing incidents (e.g. cyberattacks).
  • Legal basis: The legitimate interest of the Controller (Article 6(1)(f) GDPR – protecting systems and data).
  • Data: Sign-in data, IP addresses, behavioural data.

Legal compliance and defence against claims:

  • Purpose: Meeting legal obligations (e.g. GDPR, the AI Act) and defending against third-party claims.
  • Legal basis: A legal obligation (Article 6(1)(c) GDPR) and the legitimate interest of the Controller (Article 6(1)(f) GDPR – protecting legal interests).
  • Data: Data relating to the use of the Service and the content of claims.

Improving the Service:

  • Purpose: Analysing use of the Service in order to improve it (e.g. analysing usage statistics).
  • Legal basis: The legitimate interest of the Controller (Article 6(1)(f) GDPR – improving functionality).
  • Data: Anonymised statistical data and behavioural data.

3. Categories of data processed

Askee processes the following categories of personal data:

  • Customer data: First name, surname, e-mail address, telephone number, VAT ID, billing data and Account data.
  • User data: Data entered by Users (e.g. the content of queries, interaction history).
  • Technical data: IP addresses, sign-in data, device information and behavioural data (e.g. time spent using the Service).
  • Data entered by the Customer: Any data, including personal data, that the Customer transfers into the Service (e.g. counterparty data, analytical data, attributes). Askee processes such data as a processor on behalf of the Customer, in accordance with the Data Processing Agreement.

4. Data recipients

Personal data may be transferred to the following recipients:

  • Sub-processors: Entities supporting Askee in providing the Service, e.g. cloud service providers (the list of sub-processors is available on ask.ee in the “Privacy Policy” section).
  • Public authorities: In cases required by law (e.g. at the request of law enforcement authorities or the President of the Personal Data Protection Office).
  • Technical partners: Providers of technical support services, subject to confidentiality and GDPR compliance.

Askee ensures that all data recipients are bound by agreements providing an adequate level of data protection in accordance with the GDPR.

5. Data retention period

Personal data is retained for the following periods:

  • Providing the Service: For the term of the Agreement, in accordance with the Terms and Conditions.
  • Billing: For the period required by tax regulations (usually 5 years from the end of the tax year).
  • Claims: Until the limitation period for claims expires (usually 3 years, in accordance with the Polish Civil Code).
  • Data entered by the Customer: Up to 30 days after the Agreement ends, unless the Customer requests the return of the data or the law requires longer retention.

Once the retention period has passed, data is deleted or anonymised, unless the law requires longer retention.

6. Rights of data subjects

Data subjects have the right to:

  • Access their data (Article 15 GDPR).
  • Rectify their data (Article 16 GDPR).
  • Erase their data (the “right to be forgotten”, Article 17 GDPR).
  • Restrict processing (Article 18 GDPR).
  • Data portability (Article 20 GDPR).
  • Object to processing (Article 21 GDPR).
  • Lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).

Requests concerning the exercise of these rights can be submitted to: kontakt@askee.pl. Askee handles requests within 30 days, which may be extended to 60 days in complex cases.
Where Askee processes data as a processor, requests from data subjects are forwarded to the Customer (the Controller), who is responsible for handling them.

7. Security measures

Askee applies appropriate technical and organisational measures to protect data, including:

  • Encryption of data in transit (SSL/TLS).
  • Two-factor authentication for Account access.
  • Regular data backups.
  • Monitoring and protection against unauthorised access.
  • Staff training on data protection.

A detailed description of the security measures is available in the annex to the Data Processing Agreement.
Askee has implemented mechanisms for monitoring data entered by Customers in order to minimise the risk of processing unlawful data. If such data is detected, Askee may suspend its processing and notify the Customer.

8. Nature of AI-generated content

Content generated by Askee – AI Assistant is advisory in nature and does not replace professional advice (e.g. legal, medical or financial). The Customer is responsible for verifying and using such content.
Askee exercises due care to ensure that content generated by the Service does not infringe the intellectual property rights of third parties. However, given the nature of AI technology, Askee does not guarantee that such content is free from potential infringements. The Customer undertakes to notify Askee without delay of any claims relating to the infringement of intellectual property rights.
Askee is not liable for decisions taken by the Customer or third parties on the basis of content generated by the Service, where those decisions have led to damage.

9. Compliance with artificial intelligence regulations

Askee declares that the Service complies with applicable artificial intelligence regulations, including the Regulation of the European Parliament and of the Council (EU) on artificial intelligence (the AI Act), to the extent in force as at 23 October 2025.
Should the regulations change, Askee reserves the right to adapt the Service or this Privacy Policy in order to ensure compliance; Customers will be notified 14 days in advance.
The Customer undertakes to use the Service in a manner compliant with the AI Act and to enter only lawful data.

10. Responsibility for data entered by the Customer

The Customer is solely responsible for the legality and lawfulness of the data entered into the Service, including obtaining the consent of data subjects and complying with the GDPR and other regulations.
Askee is not liable for third-party claims arising from the unlawful entry of data by the Customer, including infringements of intellectual property rights or personal data protection.
In the event of third-party claims relating to data entered by the Customer, the Customer undertakes to release Askee from liability and to cover the costs of legal defence and any damages.

11. Cookies and tracking technologies

The Service uses cookies and similar technologies in order to:

  • Ensure the Service works correctly (strictly necessary cookies).
  • Analyse usage statistics (analytics cookies, subject to consent).
  • Personalise the Service (functional cookies, subject to consent).

The Customer can manage cookie settings through the settings panel on ask.ee. Detailed information about cookies is available in the “Cookie policy” section on ask.ee.
Data collected via cookies is processed on the basis of consent (Article 6(1)(a) GDPR) or the legitimate interest of the Controller (Article 6(1)(f) GDPR – for strictly necessary cookies).

12. Changes to the Privacy Policy

Askee reserves the right to amend this Privacy Policy in the event of changes in the law, new Service functionality or changes to data processing operations.
Customers will be notified of any changes 14 days in advance by e-mail or through a message in the user panel. Continued use of the Service after the changes take effect constitutes acceptance of them.

13. Final provisions

Matters not governed by this Policy are subject to the GDPR, the Polish Personal Data Protection Act, the Polish Civil Code and the Service Terms and Conditions.
Any disputes relating to data processing shall be settled by the court having jurisdiction over Askee’s registered office, unless the Customer is a consumer – in which case jurisdiction is determined by general rules.
If you have any questions or concerns, please contact us at: kontakt@askee.pl.

Annexes:

  • List of sub-processors
  • Description of technical and organisational measures