Privacy Policy
Last updated:
This policy explains what personal data we process in connection with smartcamp.ai (including the blog at smartcamp.ai/blog), why we do it, on what legal basis, who processes it on our behalf and what rights you have. We keep the language plain — we do not enjoy reading walls of text either.
1. Who the data controller is
The controller of your personal data is Karol Otręba, a sole trader operating as SmartCamp.AI Karol Otręba, ul. Mickiewicza 23/1, 76-200 Słupsk, Poland, tax ID (NIP) 8392860752, REGON 382382480.
For anything related to personal data, write to hello@smartcamp.ai or call +48 518 894 156. We have not appointed a data protection officer — at our scale there is no such obligation. You are dealing directly with the controller.
2. What data we collect and where it comes from
- Contact form on the home page and the form on the blog: first name, e-mail address, message, selected language, the page the form was sent from, campaign parameters from the URL (UTM, gclid), the consent wording and the date and time you gave it. We infer the company name from the e-mail domain; free mailbox domains (e.g. gmail.com) are skipped.
- Direct contact: whatever you share with us by e-mail, by phone or when booking a meeting through our HubSpot calendar (full name, e-mail, phone number, topic).
- Voice assistant on the site (ElevenLabs widget): a recording of your voice and a transcript of the conversation — only if you start it yourself. A conversation never starts automatically.
- Technical data: IP address, browser and device type, pages visited, time of visit and referrer — collected by analytics tools and server logs.
- We do not collect special categories of data (e.g. health or opinions). Please do not send us such information through the form.
3. Why we process data and on what legal basis
- Replying to your enquiry and discussing possible cooperation — your consent given by ticking the box next to the form (Art. 6(1)(a) GDPR). When you e-mail or call us, the basis is steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
- Keeping a contact database (CRM) and correspondence history for people who contacted us themselves — our legitimate interest (Art. 6(1)(f) GDPR). We do not send newsletters or offers without separate consent.
- Concluding and performing a contract if we start working together (Art. 6(1)(b) GDPR), and accounting and tax obligations (Art. 6(1)(c) GDPR).
- Visitor statistics and improving the site — legitimate interest (Art. 6(1)(f) GDPR). Details in the cookies section.
- Security, spam and abuse prevention (including a hidden trap field in the forms and server logs) — legitimate interest (Art. 6(1)(f) GDPR).
- Establishing, exercising or defending legal claims — legitimate interest (Art. 6(1)(f) GDPR).
Providing your data is voluntary, but without a first name, an e-mail address and consent we cannot reply to a message sent through the form.
4. Who processes data on our behalf
We use service providers that process data on our behalf and only on our instructions:
- Vercel Inc. (USA) — website hosting and CDN; European traffic is served by edge locations including Frankfurt.
- Hostinger International Ltd. — our own virtual server (VPS) located in Vilnius (EU), which runs the tooling that handles the forms (n8n) and the database in which enquiries are stored (Supabase).
- HubSpot Inc. (USA / Ireland) — the CRM in which we keep contacts and meeting bookings.
- Google Ireland Ltd. — e-mail (Google Workspace), including the automatic confirmation that your form was received, and Google Analytics 4.
- Microsoft Ireland Operations Ltd. — Microsoft Clarity (analysis of how the site is used).
- ElevenLabs Inc. (USA) — the voice assistant available on the site.
- Telegram — internal notification to the controller about a new form enquiry.
- FormSubmit.co — emergency forwarding of a form message by e-mail, used only when our own infrastructure does not respond.
Data may also be disclosed to bodies entitled to receive it under the law (e.g. public authorities) and, if we work together, to our accounting office. We do not sell personal data and do not hand it to other companies for their own marketing.
5. Transfers outside the European Economic Area
Some providers (Vercel, Google, Microsoft, HubSpot, ElevenLabs) are established in the USA. Transfers rely on the European Commission adequacy decision (EU-U.S. Data Privacy Framework, for certified providers) or on Standard Contractual Clauses approved by the Commission (Art. 46(2)(c) GDPR). You can obtain a copy of the safeguards in use by writing to hello@smartcamp.ai.
Notifications sent through Telegram may be processed on servers outside the EEA. We keep them to the minimum needed to reply to an enquiry quickly.
6. How long we keep data
- Form enquiries and correspondence: until the matter is closed and then for up to 3 years from the last contact (limitation period for claims) — unless you withdraw consent or object earlier.
- Contact details in the CRM: up to 3 years from the last contact or until you object.
- Voice assistant conversations: recordings and transcripts for up to 12 months, unless you ask us to delete them earlier.
- Contract and invoice data: for the period required by law, as a rule 5 years from the end of the tax year.
- Analytics data: Google Analytics — up to 14 months; Microsoft Clarity — session recordings up to 30 days, aggregated data up to 13 months.
- Server logs: up to 30 days.
7. Your rights
You have the right to:
- access your data and receive a copy of it,
- have inaccurate or incomplete data corrected,
- have your data erased (the right to be forgotten),
- restrict processing,
- data portability for data processed on the basis of consent or a contract,
- object to processing based on our legitimate interest,
- withdraw consent at any time — without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, write to hello@smartcamp.ai. We reply within one month at the latest. If you believe we process data unlawfully, you can lodge a complaint with the President of the Polish Personal Data Protection Office (Prezes UODO, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) or with the supervisory authority in your country.
8. Cookies and analytics tools
The site uses cookies and similar technologies. Your language and colour-theme preferences are stored in your browser (localStorage and sessionStorage) — these are not cookies and never reach our servers. For statistics we use:
- Google Analytics 4 (cookies _ga and _ga_*, kept for up to 2 years) — number of visits, traffic sources, content popularity. GA4 does not store full IP addresses.
- Microsoft Clarity (cookies _clck and _clsk, up to 13 months / 1 day) — heatmaps and session recordings showing how visitors move around the site. Text typed into form fields is masked.
- The ElevenLabs voice assistant loads only after your first interaction with the page and may store its own technical data in the browser.
You can block or delete cookies in your browser settings; the site remains fully usable. You can also disable Google Analytics tracking with the Google Analytics Opt-out add-on (tools.google.com/dlpage/gaoptout).
9. Automated decisions and profiling
We do not make automated decisions that would produce legal effects concerning you or similarly significantly affect you. Analytics and CRM tools group contacts by simple criteria (language, referral source) solely so that we can reply more accurately.
10. Security
All traffic on the site is encrypted (HTTPS). Only people who need it have authenticated access to the enquiry database and the CRM. The enquiry database runs on a server in the European Union and is backed up regularly. The forms are protected by an anti-spam mechanism that does not ask you to solve puzzles.
11. External links and affiliate links
The site links to third-party sites (including LinkedIn, GitHub, n8n.io, our Notion portfolio and our clients' websites). On the blog some links are affiliate links, always disclosed in the post. After clicking, you land on the partner's site, which uses its own cookies and its own privacy policy. Affiliate programmes may pass us basic information about transactions made on our referral — solely to settle commissions.
12. Children
Our services are aimed at businesses. We do not direct them at people under 16 and do not knowingly collect their data.
13. Changes to this policy
We publish updates on this page and change the date at the top of the document. We will additionally inform people whose data we hold about material changes (e.g. new processing purposes). The Polish version is binding; translations are provided for information.