Wrenwire Privacy Policy — target version (DRAFT)
Status: content and decisions filled in (AI legal analysis, authorized by Piotr in lieu of a lawyer until the SaaS scales) — this is NOT a lawyer’s opinion. The Polish version (Privacy Policy (PL)) is the source text. As of 2026-08-01 this is the only Privacy Policy in force: it superseded both the app’s earlier, separate
/privacypage and the interim policy (privacy-policy-interim.html — its Meta section is folded in as §7). The Art. 14 prospect notice (§5) and the profiling disclosure must not be lost in edits.
§1. Controller and contact
- The data controller is Geeknauts sp. z o.o. (limited liability company), ul. Ulubiona 34, 32-085 Modlnica, Poland, KRS 0000362389, VAT (NIP) 5130210402, REGON 121307472 (“we”).
- Privacy contact: campaign.studio@geeknauts.com.
- We have not appointed a Data Protection Officer — confirmed: under Art. 37 GDPR no DPO is required, as the Provider’s core activity involves neither large-scale regular and systematic monitoring of data subjects nor large-scale processing of special-category data, at the Provider’s current scale. This conclusion is to be periodically re-assessed if the processing scale changes materially (AI analysis, to be verified by a lawyer before publication).
§2. Roles: when we are controller vs processor
| Data category | Our role | Governing document |
|---|---|---|
| Account/User data (registration, login, billing) | controller | this policy |
| Prospect data entered/acquired by a SaaS Customer within their organization | processor (the Customer is controller) | DPA; prospect information duties rest with the Customer |
| Prospect data we acquire for our own sales (Vicoop prospecting) | controller | §5 (Art. 14 notice) |
| Meta integration data (ad accounts connected by the Customer) | controller for tokens/configuration; acting on the Customer’s instructions for ad objects | §7 |
§3. What we process and why
3a. User (account) data
- email address (stored encrypted), password (bcrypt hash), name (if provided), organization data (name, slug);
- billing data (plan, subscription status; card data stays with Stripe — we never see it) — once payments launch;
- audit logs (login time, IP);
- product usage events (PostHog EU analytics — once deployed; no prospect data).
Purposes and bases: contract performance (Art. 6(1)(b) GDPR) — account, billing; legitimate interest (f) — security, logs, product analytics; legal obligation (c) — accounting/tax.
3b. Prospect data (on the Customer’s behalf)
- company data: name, address, phone, website; enrichments (technologies, sector, buying signals);
- person data: name, business email, job title, professional profile URL.
The Customer is the controller (basis: its legitimate interest — Art. 6(1)(f)). We process this data solely under the DPA.
§4. Profiling
The Service scores how well a prospect’s COMPANY fits a customer profile — profiling within the meaning of Art. 4(4) GDPR. We make no automated decisions producing legal or similarly significant effects (Art. 22 GDPR does not apply): the score is a recommendation to a human who decides about contact.
§5. Notice to prospects — data from public sources (Art. 14 GDPR)
(applies to prospecting where we are the controller; SaaS Customers issue their own notices — DPA §5)
If we obtained your data not from you but from publicly available sources related to your professional activity — Google Maps business listings, your company’s public website, business contact databases (Snov.io), and, where that was the source, your public LinkedIn posts — this notice is addressed to you:
- Data scope: identification and business contact data (name, job title, business email, professional profile URL), company data (name, address, phone, website), and — for the LinkedIn source — the content of the public post we want to respond to.
- Purpose and basis: initiating B2B commercial contact and tailoring our offer, based on our legitimate interest (Art. 6(1)(f) GDPR) — direct marketing of our own services.
- Profiling: as in §4 — we score your COMPANY’s fit; no Art. 22 decisions.
- Retention: data of persons we did not end up contacting is deleted per our retention policy; LinkedIn-sourced data — after 30 days. Objection records are kept indefinitely so the objection remains permanently effective.
- Objection (Art. 21(2) GDPR): at any time, without giving reasons, you may object to processing for direct marketing — via the opt-out link in a message or by email to the address in §1. After an objection we no longer process your data for this purpose.
§6. Recipients and transfers outside the EEA
- We use the processors listed in the subprocessor list: Subprocessor list (published with the service). Key ones: OVH (hosting, EU), Resend (transactional email, EU region), OpenRouter (AI models — prospect data enters prompts; further model providers sit behind OpenRouter), OpenAI (vector index/search), Outscraper (Google Maps company data), Stripe (payments — once live), PostHog EU (analytics — once live).
- Snov.io is not our processor — the Customer connects their own Snov.io account and contracts with that vendor directly; we pass data to Snov.io on the Customer’s instructions.
- Error monitoring runs on our own EU infrastructure (self-hosted) — no third party involved.
- Some vendors are US-based — transfers rely on the European Commission’s Standard Contractual Clauses. For the three US-anchored transfers (OpenRouter, OpenAI, Outscraper) a Transfer Impact Assessment has been performed at summary level, using the EDPB six-step methodology, with the conclusion: given (i) only business/professional-context personal data is involved, no special categories, (ii) SCCs are in place, and (iii) supplementary technical measures are applied (TLS in transit, field-level encryption at rest for sensitive data, contractual audit rights), the transfers can proceed on the SCC basis (AI analysis, to be verified by a lawyer before publication).
§7. Meta (Facebook) integration
(carries over the 2026-07-15 interim policy)
- When you connect a Meta account (Facebook Login for Business), we process only the data needed to operate advertising on the accounts you connect: your account identifier and basic profile data, identifiers and configuration of ad accounts/business assets/pages, ad objects (campaigns, ad sets, ads, creatives) and their performance, and the access tokens issued by Meta (stored encrypted).
- Access is via the Meta Marketing API, strictly to perform actions you request in the application. We do not use your Meta data to advertise to you and we do not sell it.
- Data is exchanged with Meta Platforms Ireland Ltd.; you can revoke the application’s access at any time in your Meta settings (Business settings → connected apps). On disconnection or a deletion request we remove the tokens and stop accessing your Meta data.
§8. Cookies
We use strictly necessary cookies only: auth_token (session, JWT),
om_selected_org (selected organization), locale (language),
om_demo_notice_ack, om_cookie_notice_ack (banner acknowledgements). No
advertising or third-party profiling cookies. [VERIFY BEFORE PUBLICATION: whether PostHog EU adds cookies/localStorage after S11 — if so, update and consider consent]
§9. Retention
- account data — until the User deletes the account (+ export window after subscription end per ToS §12);
- billing data/invoices — for the period required by tax law;
- prospect data — per the retention policy (LinkedIn: 30 days; other windows per §5); objection/opt-out records — indefinitely;
- audit logs (core) — 30 days; audit logs (non-core) — 72 hours;
- technical error logs — 90 days (self-hosted system, EU).
§10. Data subject rights
You have the right of access and copy, rectification, erasure, restriction, data portability, objection, and to lodge a complaint with the Polish supervisory authority (President of UODO). Requests: address in §1. Where a request concerns data controlled by a SaaS Customer, we will forward it to that Customer and assist in fulfilling it (DPA §5).
§11. Security
Sensitive data (email addresses, prospect data) is encrypted at the database level with AES-256-GCM; passwords are stored as bcrypt hashes; connections use TLS 1.2+; access is role-restricted (RBAC) with tenant isolation. Details: TOMs annex to the DPA.
Snov.io affiliate disclosure
We participate in Snov.io’s affiliate program and may earn a commission on signups referred through our referral link. This does not affect the price paid by the Customer or how the integration processes data. Full disclosure: Snov.io affiliate disclosure.
§12. Changes
We announce material changes in the application and update the version date. Last updated: [TO BE COMPLETED at publication].