Privacy Policy
Last updated: August 15, 2026
Version: 2026-08-15 · Effective: 15 August 2026
Controller: Uladzimir Pranevich, sole proprietor registered in Poland, NIP 8992922668, REGON 521728250, ul. Kabacki Dukt 14/56, 02-798 Warsaw, Poland. Contact: [email protected].
1. Scope and roles
This Policy covers novastorm.ai, the Novastorm application, support and billing. We normally control account, website, usage and billing data. When a business customer supplies leads, audiences or other personal data and instructs processing, the customer is normally controller and we are its processor; the binding DPA in Section 5 of the Termsapplies automatically.
2. Data we collect
- Account and contact data, authentication provider, country, language and preferences.
- Billing identifiers, subscriptions, invoices, tax, refunds and disputes; Stripe handles full card details.
- Authorised platform identifiers, tokens, pages, ad accounts, campaigns, creatives, insights, leads and pixel or conversion events.
- Prompts, generated content, media, websites or pages you ask us to analyse, brand and campaign data.
- Device, consent, cookie, IP, security, audit, diagnostic, usage and support information.
- Legal-document versions, content hashes, time and acceptance method used to prove an agreement or acknowledgement.
3. Sources and required data
We obtain data from you and your device; authentication, payment, hosting, analytics and support providers; services and advertising accounts you choose to connect; websites you ask us to analyse; and outputs or inferences generated from that material. Account, authentication and payment details are contractual requirements for the relevant account or paid feature. Other fields and connections are optional unless a feature clearly requires them.
4. Purposes and legal bases
- Contract and requested pre-contract steps: authentication, accounts, requested features, payments and support.
- Legitimate interests: security, debugging, improvement, fraud prevention and audit, balanced against your rights.
- Legal obligation: tax, accounting, sanctions, lawful requests and consumer compliance.
- Consent: optional analytics and communications where required. Withdrawal does not affect earlier lawful processing.
5. Recipients and processors
We share only as needed with infrastructure and hosting providers (including Hetzner and Cloudflare), storage/CDN providers, Stripe, email and support providers, Google Tag Manager, Google Analytics, Hotjar, Stape and Meta Pixel/Conversions API after the applicable consent, AI or media providers, and connected services such as Meta/Facebook/Instagram and Google. Providers act under their own terms or our instructions. We may disclose for law, safety, professional advice, a corporate transaction or at your direction. We do not sell personal data for money. Optional Meta measurement may count as “sharing”, targeted advertising or cross-context behavioural advertising under some US state laws; it remains off unless Marketing consent is allowed, and Global Privacy Control keeps it off.
6. International transfers
Data may be processed outside your country. A restricted transfer is made only where an applicable lawful mechanism has been put in place for that transfer. Depending on the provider and destination, this may be an adequacy decision, executed Standard Contractual Clauses or another legally recognised safeguard. Contact us to request the current mechanism for a particular provider; not every listed mechanism applies to every provider.
7. Retention and deletion
Account content is normally kept while active. A deletion request has a 14-day restoration window, after which active-system data is deleted or anonymised unless retention is required. Backups roll off under their cycle. Billing and tax records are retained for the period required by Polish law. Security, legal-acceptance and deletion evidence is retained only as reasonably necessary for compliance, limitation periods and legal claims, with identifiers minimised or pseudonymised where practical. Connected-platform data is removed when no longer needed, subject to provider and legal requirements.
8. Your rights
Depending on location, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent and human review of solely automated significant decisions. Where applicable, you may opt out of sale, sharing or targeted advertising; we currently do not sell personal data. Email [email protected]. We may verify identity and respond within the legal period. You may complain to Poland's UODO or your local authority.
10. Security and children
We use access controls, encrypted transport and appropriate credential, logging, backup, incident and vendor controls, but no online service is risk-free. Do not submit sensitive data unless necessary and authorised. Novastorm is not directed to children and does not knowingly allow accounts below 18.
11. AI and automated processing
AI helps generate recommendations, content and automation suggestions. It does not make legal or similarly significant decisions about individuals on our behalf. Customers must review outputs and make required disclosures. We do not use customer content to train our own general-purpose model without separate permission.
12. Updates and contact
We publish changes with a fixed version and effective date and provide additional notice or request a renewed acknowledgement where required.
ULADZIMIR PRANEVICHSole proprietor / jednoosobowa działalność gospodarcza
ul. Kabacki Dukt 14 lok. 56
02-798 Warszawa, Poland
NIP: 8992922668 · REGON: 521728250
Email: [email protected]
Business/support phone: +48 571 943 884