Privacy Policy — Proompi

Last updated: 1 May 2026  |  Version 1.0

ENGIT sp. z o.o.

ul. Stefana Jaracza 39, 33-100 Tarnów, Polska

KRS: 0001109234 · NIP: 8733296963 · REGON: 528839231

privacy@proompi.com

The Polish version is the binding version. Versions in other languages are for information purposes only.

1. Who we are (Data Controller)

The controller of your personal data is:

ENGIT spółka z ograniczoną odpowiedzialnością (ENGIT Ltd.), ul. Stefana Jaracza 39, 33-100 Tarnów, Poland, KRS: 0001109234, NIP: 8733296963, REGON: 528839231. General contact: hi@proompi.com. Data protection contact: privacy@proompi.com.

We operate the Proompi service (https://www.proompi.com) — an AI-powered SaaS platform for content creation.

In this Policy, "we" / "Proompi" / "Controller" refers to ENGIT sp. z o.o.; "you" / "User" refers to the data subject.

2. Data protection contact point

We have not appointed a formal Data Protection Officer (DPO) within the meaning of Art. 37 GDPR. Please address all data protection inquiries to: privacy@proompi.com or in writing to our registered office.

Data protection matters are handled internally by the management of ENGIT sp. z o.o. (Jacek Barwacz, CEO).

3. What data we process

3.1. Data you provide during registration and use of the Service

CategoryExample dataRequired / Optional
Login credentialsemail address, password (stored as bcrypt hash)Required
Profile dataname/pseudonym, profile pictureOptional
Preference datainterface language, preferred AI modelOptional
Onboarding dataprimary usage goal, industryOptional
Business data (B2B)VAT number, company name, addressRequired for B2B purchases

3.2. Data collected automatically

CategoryDataPurpose
IP addresscollected at registration/login — stored as irreversible SHA-256 hashSecurity, fraud detection, accountability
Countrydetected from IP, 2-letter code (e.g. "PL")Personalisation, analytics
User agentbrowser, operating systemSecurity, optimisation
Activity timelogin, last activitySecurity, retention
Device identifiersanonymous fingerprint for non-logged-in usersLimiting free trials

3.3. Data from OAuth login (Google, Facebook)

When you log in via Google or Facebook, we receive: provider account ID, email, first name, profile picture, and access tokens (stored encrypted).

3.4. Content you generate

  • Prompts (text input for generation)
  • Generated content (images, video, audio, text — stored in Google Cloud Storage, Warsaw region)
  • AI conversations
  • Workflows (your automation sequences)
  • Brand profiles (communication tone, keywords, industry, values)
  • Reference content uploads (images for editing, materials for variant generation)

3.5. Financial data

  • Stripe customer and transaction IDs (e.g. cus_..., sub_...)
  • Amounts paid, currency, transaction status
  • VAT invoices (for Entrepreneurs)
We never store your payment card data (card numbers, CVV codes, expiry dates). This data is processed exclusively by Stripe (PCI-DSS compliant).

3.6. Analytics data

  • In-app events (login, signup, content generation, purchases)
  • Usage statistics (number of prompts, AI models, Credits consumed)
  • Session data (duration, pages visited)

3.7. Social media data (if you connect accounts)

  • Platform account ID (Instagram, Facebook, TikTok, LinkedIn, Threads)
  • Login, display name, avatar
  • OAuth tokens (stored by bundle.social, not by us)
  • Post analytics data (impressions, reach, likes, comments) — from Proompi v2

3.8. Onboarding data and preferences (Proompi v2)

  • Primary usage goal (primaryGoal)
  • Industry (userIndustry)

3.9. Behavioural data — Brand Intelligence (Proompi v2)

The AI Brand Intelligence feature automatically analyses: average post length, emoji and hashtag usage (style, average count), posting hours and days, engagement rates per platform, content type effectiveness.

Behavioural profiling (Art. 4(4) GDPR). It does not produce legal effects or similarly significant effects under Art. 22(1) GDPR — you retain full control over publishing. You can disable Brand Intelligence in Account Settings or object under Art. 21 GDPR.

3.10. Data of persons invited to a Team (Team Workspace, Proompi v2)

Invited persons receive a full GDPR Art. 13 information clause in the invitation email.

  • Email address of the invited person
  • Invitation token (single-use, valid for 7 days)
  • Invitation status (pending / accepted / declined / expired)

4. Purposes and legal bases for processing

PurposeLegal basis (GDPR)Data
Account creation and maintenanceArt. 6(1)(b) — contract performancelogin credentials, profile data
Provision of AI ServicesArt. 6(1)(b)Prompts, generated content, brand profiles
Payment processing and invoicingArt. 6(1)(b) and Art. 6(1)(c) (tax obligations)financial data, business data
Transactional communicationsArt. 6(1)(b)email address, notification content
Marketing communications (newsletter)Art. 6(1)(a) — consentemail address
Team invitations (Team Workspace)Art. 6(1)(b) — pre-contractual measuresinvited person's email address
Brand Intelligence — behaviour analysisArt. 6(1)(f) — legitimate interestbehavioural data; with effective opt-out
Internal product analyticsArt. 6(1)(f) — legitimate interestevents, statistics
Security and fraud detectionArt. 6(1)(f) — legitimate interestIP address (hashed), user agent, logs
Handling complaints and claimsArt. 6(1)(f) — legitimate interestaccount data, ticket content
Analytics and marketing cookiesArt. 6(1)(a) — consentcookie identifiers
Training AI models on identifiable dataArt. 6(1)(a) — consent (opt-in)only after explicit consent in Account Settings
Tax and accounting complianceArt. 6(1)(c) — legal obligationfinancial data, invoices — for 5 years

5. Sources of data

The Trend Intelligence feature uses public data sources (Google Trends, RSS) — we do not collect your personal data in this process.

Most data is received directly from you. Some data is received from other sources:

SourceWhat data
OAuth providers (Google, Facebook)email address, name, account ID, avatar, permission scopes
bundle.socialpost analytics data, publication status
Stripetransaction data, payment status
AI sub-processorsusage signals (for credit billing)
IP geolocationcountry code (based on IP address)

6. Recipients of data (processors and joint controllers)

We share data with selected, vetted processors (sub-processors). We have concluded a data processing agreement under Art. 28 GDPR with each of them. For transfers outside the EEA, we apply Standard Contractual Clauses (SCCs) adopted by the European Commission.

6.1. Infrastructure (EU)

ProcessorPurposeLocation
Google Cloud Platform (Google Cloud EMEA Limited)application hosting, database, storageWarsaw, Poland (europe-central2)
Upstashcache, rate limitingFrankfurt, Germany (eu-central-1)
Cyberfolks (h88 S.A.)transactional email sending (SMTP)Poland

6.2. Payments

ProcessorPurposeLocation
Stripe Payments Europe Ltd.payment processingEU / USA

6.3. AI models (transfer outside EEA — USA)

ProcessorPurposeLocationData
Anthropic, PBCprompt enhancement, conversations, Content ScoreUSAPrompt content, conversation history
OpenAI, L.L.C.image generation, visual analysisUSAPrompt content, reference images
Together AI Inc.image generation (FLUX)USAPrompt content
Ideogram AItext-to-image generationUSAPrompt content
ElevenLabs Inc.music and narration generationUSAtext, musical description
Replicate Inc.video/audio generationUSAPrompt content
Luma AI Inc.video generationUSAvideo description
fal.aiphoto editing (background)USAimage uploaded by User

6.4. Other sub-processors

ProcessorPurposeLocation
bundle.socialsocial media publishing and analyticsEU
Sentry / Functional Software, Inc.error monitoring, session replayUSA
Google LLC (Google Analytics)usage analytics (with consent)USA
Meta Platforms, Inc. (Facebook Pixel)conversion tracking (with marketing consent)USA

6.5. Other data sharing scenarios

  • public authorities, where required by law (e.g. police, prosecutors, data protection authority),
  • legal, tax and audit advisors — to the extent necessary,
  • acquirer of the business or its part in M&A transactions — with data protection standards maintained.

7. International data transfers

You can obtain a copy of the transfer safeguards applied by contacting privacy@proompi.com.

Some sub-processors are located outside the European Economic Area (mainly in the USA). We apply the following safeguards:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission (Implementing Decision 2021/914), with additional technical and organisational measures following the Schrems II ruling.
  • Where possible — participation in Data Privacy Framework (DPF) programmes for the USA.
  • Pseudonymisation of data before transfer (including IP hashing).

8. How long we retain your data

After retention periods expire, data is permanently deleted or anonymised.
Data categoryRetention period
Active User Accountuntil deletion request (or 24 months of inactivity)
Account after deletion request30 days (grace period) → permanent deletion
Generated images (FREE)7 days
Generated images (SPARK)30 days
Generated images (ACCELERATOR)90 days
Generated images (PRO)365 days
Invoices and accounting data5 years (Tax Ordinance)
Access and security logs90 days
JWT sessions30 days
Email verification tokens24 hours
Password reset tokens1 hour
Anonymous usage limits30 days
Processing logs (DataProcessingLog)3 years
Google Analytics data14 months
Team invitations (not accepted)7 days → automatic deletion
Team invitations (accepted)until leaving the team or account deletion
Complaints and tickets3 years after closure

9. Your rights

Under GDPR, you have the following rights:

RightLegal basisHow to exercise
Right of accessArt. 15 GDPRSettings → Privacy → Download data or privacy@proompi.com
Right to rectificationArt. 16 GDPRSettings → Profile or privacy@proompi.com
Right to erasureArt. 17 GDPRSettings → Privacy → Delete account
Right to restriction of processingArt. 18 GDPRprivacy@proompi.com
Right to data portability (JSON format)Art. 20 GDPRSettings → Privacy → Export data
Right to objectArt. 21 GDPRSettings → Privacy → File objection or privacy@proompi.com
Right to withdraw consentArt. 7(3) GDPRSettings → Consents
Right to lodge a complaint with supervisory authorityArt. 77 GDPRPrezes UODO, ul. Stawki 2, 00-193 Warszawa, https://uodo.gov.pl
  • Response deadline: up to 1 month, extendable by another 2 months for complex cases (with prior notice).
  • Free of charge: Exercising rights is free unless a request is manifestly unfounded or excessive.
  • Identity verification: To protect against abuse, we may request identity confirmation.

10. Profiling and automated decision-making

10.1. Brand Intelligence (Proompi v2)

  • Do we use profiling? Yes — we automatically analyse your publishing patterns to recommend optimal posting times, hashtags and content formats.
  • Does it produce legal or similarly significant effects? No. You retain full control: recommendations are suggestions only.
  • Legal basis: Art. 6(1)(f) GDPR — legitimate interest (improving service quality).
  • Your rights: Right to object (Art. 21 GDPR), right to disable the feature.

10.2. Content Score (Proompi v2, ACCELERATOR+ plan)

Optional feature, triggered by you. An AI model evaluates the quality of your post on 4 criteria (hook strength, readability, hashtags, brand voice alignment). The score is a suggestion only. We never block publication regardless of the score.

10.3. Anti-fraud and security

  • We use automated fraud detection mechanisms (e.g. excessive credit usage, suspicious logins).
  • We do not make fully automated decisions with legal effects (e.g. account blocking) — every decision is subject to human review.

11. Cookies

You can change your preferences at any time: Settings → Cookie consents or by clicking the "Cookies" icon in the website footer.

Full information about cookies is available in the Cookie Policy at https://www.proompi.com/legal/cookies.

  • Necessary cookies (session, CSRF) — no consent required, based on Art. 6(1)(b) GDPR.
  • Analytics cookies (Google Analytics) — only with your consent.
  • Marketing cookies (Facebook Pixel) — only with your consent.

12. Data security

We apply advanced technical and organisational measures (Art. 32 GDPR):

  • Encryption: TLS 1.2+ on all connections, database encryption, token encryption.
  • Passwords: stored as irreversible hash (bcrypt, 10 rounds + random salt).
  • Pseudonymisation: IP addresses are hashed (HMAC-SHA256, salt in environment variable).
  • Access control: RBAC (role-based access control), data isolation per teamId/userId, audit trail.
  • Backup: daily, point-in-time recovery up to 7 days, multi-AZ replication.
  • Monitoring: fraud detection, cost alert thresholds, AI kill switch.
  • Secure engineering: Zod validation, sanitisation, Prisma ORM, automatic React escaping, CSRF tokens, SameSite/Secure/httpOnly cookies.

13. Children

The Proompi Service is intended exclusively for persons aged 18 or over. We do not knowingly collect data from children. If you have information that a child is using the Service, please contact us: privacy@proompi.com. We will immediately delete such an Account and associated data.

14. Personal data breaches

  • Within 72 hours we report the breach to the President of the UODO (Art. 33 GDPR), where it is likely to result in a risk to the rights and freedoms of natural persons.
  • We notify affected individuals without undue delay where the breach is likely to result in a high risk (Art. 34 GDPR).
  • Each breach is documented in an internal register.

15. Changes to this Privacy Policy

We may update this Privacy Policy upon changes to applicable law, data protection authority guidelines, changes in Services, or addition of new sub-processors.

We will notify you of material changes with at least 14 days' advance notice via: email notification, in-app Account panel message, homepage banner.

16. Contact

Email: privacy@proompi.com

Postal address: ENGIT sp. z o.o., ul. Stefana Jaracza 39, 33-100 Tarnów, Poland

You also have the right to lodge a complaint with the supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office), ul. Stawki 2, 00-193 Warsaw, tel. +48 22 531 03 00, https://uodo.gov.pl

Last updated: 1 May 2026  |  Version 1.0