Version 4.0 · Effective date: July 1, 2026
Data Controller: SETOR AI Spółka z ograniczoną odpowiedzialnością, ul. Tomasza Zana 1, 20-601 Lublin, Poland · KRS 0001202220 · NIP 7123502599
Contact: [email protected]
Data Controller: SETOR AI Spółka z ograniczoną odpowiedzialnością, ul. Tomasza Zana 1, 20-601 Lublin, Poland · KRS 0001202220 · NIP 7123502599
Contact: [email protected]
Data Processing Details
What data is collected
What data is collected
Setor AI collects the following categories of personal data:Account data
- Identification: name, job title, business role
- Contact details: work email, phone number
- Company information: name, size, website, industry
- Authentication: username, hashed password, MFA data
- Subscription status, selected plan, trial information
- Consent records: timestamp and version of accepted Terms and Privacy Policy, IP address and browser identifier at consent time
- Business/creator account identifiers, profile information (username, display name, profile picture, follower count, account category)
- Permissions and access tokens granted through Meta OAuth
- Account connection status and engagement metrics (as authorised by you)
- Incoming and outgoing message content
- Conversation thread metadata (timestamps, message IDs, participant IDs)
- Automated response content and conversation classification data (lead qualification scores, sentiment indicators)
- Billing name and address
- Last four digits of payment card, transaction identifiers, invoices
- Card details are collected and stored exclusively by Stripe — they never touch Setor AI servers.
- Full IP address (used for security, fraud prevention, and routing — constitutes personal data per CJEU C-582/14 Breyer)
- Server-side geolocation derived from IP (approximate country, city, region — not precise GPS location)
- Browser type and version, operating system, device type, referring URL, timezone, language settings
- UTM parameters, click identifiers (e.g.
fbclid), referring page - Conversion events, quiz result identifiers
- Hashed identifiers (
ip_hash— a pseudonym linked to quiz result ID only; raw IP is never stored in analytics systems)
How your data is used
How your data is used
Setor AI processes your data under the following purposes and legal bases:
Message content is processed transiently to generate responses and is not used to train AI models. Advertising and ad-tech purposes (pixels, Conversions API, session recording, remarketing) are based solely on your consent — never on legitimate interest — consistent with CJEU C-252/21.
AI processing
AI processing
Setor AI uses multiple AI sub-processors to analyse messages, understand context, generate responses, and process voice and video content. AI processing is an integral part of the service and is necessary for contract performance.Key protections:
- No training on client data: Setor AI does not use your data or your end users’ message content to train general AI models. Agreements with all AI sub-processors contractually prohibit this.
- Transient processing: AI input and output data are processed in real time. AI sub-processors do not retain data after session completion, except for limited abuse-prevention logging (typically 30 days, then auto-deleted).
- No cross-customer data use: One customer’s data is never used to improve the service for another customer.
- Aggregated improvement only: Setor AI may use irreversibly anonymised, aggregated data (e.g. effectiveness statistics, error rates) to improve service quality, under legitimate interest (Art. 6(1)(f) GDPR).
Your GDPR rights
Your GDPR rights
As a data subject, you have the following rights under the GDPR:To exercise any right: email [email protected]. We confirm receipt within 5 business days and respond substantively within 30 calendar days.To lodge a complaint: contact the President of the Office for Personal Data Protection (UODO), ul. Stawki 2, 00-193 Warsaw, Poland — uodo.gov.pl. We encourage you to contact us first so we can resolve issues directly.
Access
Request a copy of the personal data Setor AI holds about you.
Rectification
Ask us to correct inaccurate or incomplete data.
Erasure
Request deletion of your data where no legal basis for continued retention exists.
Portability
Receive your data in a structured, machine-readable format.
Restriction
Request that we restrict processing of your data in certain circumstances.
Objection
Object to processing based on legitimate interest (including direct marketing).
Data retention
Data retention
When your account is closed, your data is deleted or anonymised within the periods above. You may request deletion of individual conversations at any time from within the app.
International transfers
International transfers
Setor AI’s primary database is located within the EEA. Some sub-processors are based outside the EEA, including in the United States. All transfers outside the EEA use at least one of the following safeguards:
- Standard Contractual Clauses (SCC): Commission Implementing Decision (EU) 2021/914, supplemented by Transfer Impact Assessments (TIA) where required.
- EU-US Data Privacy Framework (DPF): For certified US entities. If a DPF certification expires or is revoked, SCC automatically applies as a fallback with no service interruption.
- Adequacy Decision: For countries recognised by the European Commission as providing adequate protection (GDPR Article 45).
Sub-processors
Sub-processors
Setor AI uses third-party sub-processors to deliver the service. Categories include:
- AI model providers — response generation, audio transcription, voice synthesis, image/profile picture analysis
- Hosting and infrastructure — servers, CDN, frontend delivery, data storage (primary database within the EEA, provided by Hetzner Online GmbH, Germany; CDN via Cloudflare)
- Payments — Stripe, Inc. (PCI-DSS Level 1 certified; card details never touch Setor AI servers)
- Email delivery — transactional email (Resend)
- Analytics — PostHog (EU data residency, Frankfurt); consent required
- Session recording — Microsoft Clarity (consent required; all input fields masked)
- Marketing attribution — Meta Pixel and Conversions API (consent required); hashed identifiers used; raw IP never stored in analytics
- CRM and scheduling — Attio, Calendly, Cal.com
- Public profile verification — Apify (verifies public Instagram profile data only)
- Video hosting — Wistia
Security
Security
Setor AI applies industry-standard technical and organisational measures to protect your data:
- Encryption at rest: AES-256 for all stored data, including OAuth tokens and sensitive fields
- Encryption in transit: TLS 1.3 for all data transmissions
- Network protection: Cloudflare WAF and DDoS protection; network segmentation; intrusion detection
- Audit logging: Immutable audit logs with 12-month retention
- Access controls: Least-privilege principle; multi-factor authentication (MFA); quarterly access reviews
- Session recording: All session recording tools mask text fields and input data
- Incident response: Documented plan with annual tabletop exercises; breach notification to UODO within 72 hours; notification to you within 24 hours if your processor data is affected
- Vendor assessment: Security evaluation before engagement and annual review of all sub-processors
The full Privacy Policy is available at https://setor.ai/privacy-policy. For all privacy and data protection matters, contact [email protected].
.jpg?fit=max&auto=format&n=MTh-1jctBcDntiY0&q=85&s=f9ee2b7761caeebddaa17911cbc09989)