Wrenwire Privacy Policy

Document version: sha256-b64e53107621d542

This is an informative translation. The Polish version of this document is always the binding one. Read the binding Polish version

The Polish version (Privacy Policy (PL)) is the source text. As of 2026-08-01 this is the only Privacy Policy in force: it superseded both the app's earlier, separate /privacy page and the interim policy (privacy-policy-interim.html — its Meta section is folded in as §7). The Art. 14 prospect notice (§5) and the profiling disclosure must not be lost in edits. Correction 2026-08-27: the audit-log retention windows in §9 were brought down to the configuration actually deployed (measurement and rationale: our internal record of processing activities, §8a). Update 2026-08-28: that configuration has been fixed and deployed, so §9 returns to 30 days / 72 hours — as a description of what is enforced rather than an intention, and with two distinct windows instead of one. The new wording requires legal review before publication. Update 2026-08-31: added §3c — product newsletter, on consent (the first processing in this policy based on Art. 6(1)(a)), together with the consequential additions to §2, §6, §9 and §10. The clause is published before the signup consent checkbox exists — the Art. 13 duty arises when the data is collected, so the order has to be this one and not the reverse. Requires legal review before publication.

§1. Controller and contact

  1. The data controller is Geeknauts sp. z o.o. (limited liability company), ul. Ulubiona 34, 32-085 Modlnica, Poland, KRS 0000362389, VAT (NIP) 5130210402, REGON 121307472 ("we").
  2. Privacy contact: wrenwire@geeknauts.com.
  3. We have not appointed a Data Protection Officer — confirmed: under Art. 37 GDPR no DPO is required, as the Provider's core activity involves neither large-scale regular and systematic monitoring of data subjects nor large-scale processing of special-category data, at the Provider's current scale. This conclusion is to be periodically re-assessed if the processing scale changes materially.

§2. Roles: when we are controller vs processor

§3. What we process and why

3a. User (account) data

  • email address (stored encrypted), password (bcrypt hash), name (if provided), organization data (name, slug);
  • billing data (plan, subscription status; card data stays with Stripe — we never see it) — once payments launch;
  • audit logs (login time, IP);
  • product usage events (PostHog EU analytics — once deployed; no prospect data).

Purposes and bases: contract performance (Art. 6(1)(b) GDPR) — account, billing; legitimate interest (f) — security, logs, product analytics; legal obligation (c) — accounting/tax.

3b. Prospect data (on the Customer's behalf)

  • company data: name, address, phone, website; enrichments (technologies, sector, buying signals);
  • person data: name, business email, job title, professional profile URL.

The Customer is the controller (basis: its legitimate interest — Art. 6(1)(f)). We process this data solely under the DPA.

3c. Product newsletter (only with your consent)

  1. If you consent — via the checkbox when creating your account, or the toggle in the application (Profile → Marketing emails) — we send you product information by email: news, changes to the Service and related material. Consent is voluntary and entirely independent of the contract: withholding or withdrawing it does not affect your ability to create an account or to use the Service.
  2. What we process for this purpose: your account email address, plus the record of your consent — the date and time it was given, the IP address it was given from, the source (signup form or profile settings), and, once withdrawn, the date of withdrawal; each record carries a cryptographic digest that lets us detect later alteration. Only the email address and its unsubscribe status reach our email provider — we do not send your name there.
  3. Legal bases: your consent (Art. 6(1)(a) GDPR); for the email channel itself, the prior consent required by Art. 398 of the Polish Act of 12 July 2024 — Electronic Communications Law. We process the record of consent in order to demonstrate that it was given and that a withdrawal was acted on (Art. 6(1)(c) in conjunction with Art. 7(1) and Art. 5(2) GDPR).
  4. Withdrawing consent: at any time, without giving reasons and without affecting the lawfulness of processing carried out before the withdrawal (Art. 7(3) GDPR). Use the toggle in Profile → Marketing emails or the unsubscribe link in the message; withdrawal is as easy as giving consent and requires no contact with us. An unsubscribe made directly with our email provider is honoured in the same way — we write it back into our consent record, and the recipient list is a projection of that record: if it holds no active consent of yours, you are not on the list.
  5. We do not profile you for this mailing — everyone subscribed receives the same content. We do not share your address with other controllers, do not sell it, and do not pass it to AI models.

§4. Profiling

The Service scores how well a prospect's COMPANY fits a customer profile — profiling within the meaning of Art. 4(4) GDPR. We make no automated decisions producing legal or similarly significant effects (Art. 22 GDPR does not apply): the score is a recommendation to a human who decides about contact.

§5. Notice to prospects — data from public sources (Art. 14 GDPR)

(applies to prospecting where we are the controller; SaaS Customers issue their own notices — DPA §5)

If we obtained your data not from you but from publicly available sources related to your professional activity — Google Maps business listings, your company's public website, business contact databases (Snov.io), and, where that was the source, your public LinkedIn posts — this notice is addressed to you:

  • Data scope: identification and business contact data (name, job title, business email, professional profile URL), company data (name, address, phone, website), and — for the LinkedIn source — the content of the public post we want to respond to.
  • Purpose and basis: initiating B2B commercial contact and tailoring our offer, based on our legitimate interest (Art. 6(1)(f) GDPR) — direct marketing of our own services.
  • Profiling: as in §4 — we score your COMPANY's fit; no Art. 22 decisions.
  • Retention: data of persons we did not end up contacting is deleted per our retention policy; LinkedIn-sourced data — after 30 days. Objection records are kept indefinitely so the objection remains permanently effective.
  • Objection (Art. 21(2) GDPR): at any time, without giving reasons, you may object to processing for direct marketing — via the opt-out link in a message or by email to the address in §1. After an objection we no longer process your data for this purpose.

§6. Recipients and transfers outside the EEA

  1. We use the processors listed in the subprocessor list: Subprocessor list (published with the service). Key ones: OVH (hosting, EU), Resend (transactional email and — with your consent — the product newsletter of §3c; EU region, where your address is held together with its unsubscribe status so that an unsubscribe stays effective), OpenRouter (AI models — prospect data enters prompts; further model providers sit behind OpenRouter), OpenAI (vector index/search), Outscraper (Google Maps company data), Stripe (payments — once live), PostHog EU (analytics — once live).
  2. Snov.io is not our processor — the Customer connects their own Snov.io account and contracts with that vendor directly; we pass data to Snov.io on the Customer's instructions.
  3. Error monitoring runs on our own EU infrastructure (self-hosted) — no third party involved.
  4. Some vendors are US-based — transfers rely on the European Commission's Standard Contractual Clauses. For the three US-anchored transfers (OpenRouter, OpenAI, Outscraper) a Transfer Impact Assessment has been performed at summary level, using the EDPB six-step methodology, with the conclusion: given (i) only business/professional-context personal data is involved, no special categories, (ii) SCCs are in place, and (iii) supplementary technical measures are applied (TLS in transit, field-level encryption at rest for sensitive data, contractual audit rights), the transfers can proceed on the SCC basis.

§7. Meta (Facebook) integration

(carries over the 2026-07-15 interim policy)

  1. When you connect a Meta account (Facebook Login for Business), we process only the data needed to operate advertising on the accounts you connect: your account identifier and basic profile data, identifiers and configuration of ad accounts/business assets/pages, ad objects (campaigns, ad sets, ads, creatives) and their performance, and the access tokens issued by Meta (stored encrypted).
  2. Access is via the Meta Marketing API, strictly to perform actions you request in the application. We do not use your Meta data to advertise to you and we do not sell it.
  3. Data is exchanged with Meta Platforms Ireland Ltd.; you can revoke the application's access at any time in your Meta settings (Business settings → connected apps). On disconnection or a deletion request we remove the tokens and stop accessing your Meta data.

§8. Cookies

We use strictly necessary cookies only: auth_token (session, JWT), om_selected_org (selected organization), locale (language), om_demo_notice_ack, om_cookie_notice_ack (banner acknowledgements). No advertising or third-party profiling cookies. [VERIFY BEFORE PUBLICATION: whether PostHog EU adds cookies/localStorage after S11 — if so, update and consider consent]

§9. Retention

  • account data — until the User deletes the account (+ export window after subscription end per ToS §12);
  • billing data/invoices — for the period required by tax law;
  • prospect data — per the retention policy (LinkedIn: 30 days; other windows per §5); objection/opt-out records — indefinitely;
  • newsletter consent (§3c) and the record of it being given and withdrawn — for the lifetime of the account. Withdrawing consent does not delete that record; it stamps the withdrawal date into it, because without that we could not demonstrate that the opt-out was acted on. The record is deleted when the account is deleted — and in the same run we delete your contact at the email provider, so your address is left neither with us nor with them;
  • access audit logs (who read what) — 30 days for operations on user accounts and roles, and 72 hours for everything else; action audit logs (who changed what) — 30 days for all of them, on a single window; both windows are enforced automatically and rows are deleted permanently once the window elapses;
  • technical error logs — 90 days (self-hosted system, EU).

§10. Data subject rights

You have the right of access and copy, rectification, erasure, restriction, data portability, objection, and to lodge a complaint with the Polish supervisory authority (President of UODO). Requests: address in §1. Where a request concerns data controlled by a SaaS Customer, we will forward it to that Customer and assist in fulfilling it (DPA §5). For data processed on the basis of your consent (§3c) you additionally have the right to withdraw that consent at any time (Art. 7(3) GDPR), without affecting the lawfulness of processing carried out before the withdrawal; §3c explains how.

§11. Security

Sensitive data (email addresses, prospect data) is encrypted at the database level with AES-256-GCM; passwords are stored as bcrypt hashes; connections use TLS 1.2+; access is role-restricted (RBAC) with tenant isolation. Details: TOMs annex to the DPA.

Snov.io affiliate disclosure

We participate in Snov.io's affiliate program and may earn a commission on signups referred through our referral link. This does not affect the price paid by the Customer or how the integration processes data. Full disclosure: Snov.io affiliate disclosure.

§12. Changes

We announce material changes in the application and update the version date. Last updated: [TO BE COMPLETED at publication].

See also: Terms of Service