Skip to main content
Setor AI is operated by SETOR AI Spółka z ograniczoną odpowiedzialnością (Poland, KRS 0001202220, NIP 7123502599) and is subject to the GDPR and Polish data protection law. This page summarises how your personal data is handled when you visit setor.ai, use app.setor.ai, or interact with any Setor AI service. Using our website or service does not constitute consent for analytics, advertising, or electronic marketing — those activities only occur after separate, prior, granular consent.
Version 4.0 · Effective date: July 1, 2026
Data Controller: SETOR AI Spółka z ograniczoną odpowiedzialnością, ul. Tomasza Zana 1, 20-601 Lublin, Poland · KRS 0001202220 · NIP 7123502599
Contact: [email protected]

Data Processing Details

Setor AI collects the following categories of personal data:Account data
  • Identification: name, job title, business role
  • Contact details: work email, phone number
  • Company information: name, size, website, industry
  • Authentication: username, hashed password, MFA data
  • Subscription status, selected plan, trial information
  • Consent records: timestamp and version of accepted Terms and Privacy Policy, IP address and browser identifier at consent time
Instagram account data (via Meta API)
  • Business/creator account identifiers, profile information (username, display name, profile picture, follower count, account category)
  • Permissions and access tokens granted through Meta OAuth
  • Account connection status and engagement metrics (as authorised by you)
Setor AI is a Meta Verified Technology Partner. Authentication occurs solely through Meta’s OAuth 2.0 process — your Instagram login credentials are never accessed, stored, or processed by Setor AI.DM message content and metadata
  • Incoming and outgoing message content
  • Conversation thread metadata (timestamps, message IDs, participant IDs)
  • Automated response content and conversation classification data (lead qualification scores, sentiment indicators)
Message content may contain personal data about your contacts (End Users). For this data, you are the controller; Setor AI processes it solely as a processor under the Data Processing Agreement.Payment data (via Stripe)
  • Billing name and address
  • Last four digits of payment card, transaction identifiers, invoices
  • Card details are collected and stored exclusively by Stripe — they never touch Setor AI servers.
Technical data
  • Full IP address (used for security, fraud prevention, and routing — constitutes personal data per CJEU C-582/14 Breyer)
  • Server-side geolocation derived from IP (approximate country, city, region — not precise GPS location)
  • Browser type and version, operating system, device type, referring URL, timezone, language settings
Marketing attribution data (consent required)
  • UTM parameters, click identifiers (e.g. fbclid), referring page
  • Conversion events, quiz result identifiers
  • Hashed identifiers (ip_hash — a pseudonym linked to quiz result ID only; raw IP is never stored in analytics systems)
Setor AI processes your data under the following purposes and legal bases:Message content is processed transiently to generate responses and is not used to train AI models. Advertising and ad-tech purposes (pixels, Conversions API, session recording, remarketing) are based solely on your consent — never on legitimate interest — consistent with CJEU C-252/21.
Setor AI uses multiple AI sub-processors to analyse messages, understand context, generate responses, and process voice and video content. AI processing is an integral part of the service and is necessary for contract performance.Key protections:
  • No training on client data: Setor AI does not use your data or your end users’ message content to train general AI models. Agreements with all AI sub-processors contractually prohibit this.
  • Transient processing: AI input and output data are processed in real time. AI sub-processors do not retain data after session completion, except for limited abuse-prevention logging (typically 30 days, then auto-deleted).
  • No cross-customer data use: One customer’s data is never used to improve the service for another customer.
  • Aggregated improvement only: Setor AI may use irreversibly anonymised, aggregated data (e.g. effectiveness statistics, error rates) to improve service quality, under legitimate interest (Art. 6(1)(f) GDPR).
You retain full control over AI results: you can configure rules, review conversations, override or delete any response, and pause or disable AI automation at any time.
As a data subject, you have the following rights under the GDPR:

Access

Request a copy of the personal data Setor AI holds about you.

Rectification

Ask us to correct inaccurate or incomplete data.

Erasure

Request deletion of your data where no legal basis for continued retention exists.

Portability

Receive your data in a structured, machine-readable format.

Restriction

Request that we restrict processing of your data in certain circumstances.

Objection

Object to processing based on legitimate interest (including direct marketing).
To exercise any right: email [email protected]. We confirm receipt within 5 business days and respond substantively within 30 calendar days.To lodge a complaint: contact the President of the Office for Personal Data Protection (UODO), ul. Stawki 2, 00-193 Warsaw, Poland — uodo.gov.pl. We encourage you to contact us first so we can resolve issues directly.
When your account is closed, your data is deleted or anonymised within the periods above. You may request deletion of individual conversations at any time from within the app.
Setor AI’s primary database is located within the EEA. Some sub-processors are based outside the EEA, including in the United States. All transfers outside the EEA use at least one of the following safeguards:
  • Standard Contractual Clauses (SCC): Commission Implementing Decision (EU) 2021/914, supplemented by Transfer Impact Assessments (TIA) where required.
  • EU-US Data Privacy Framework (DPF): For certified US entities. If a DPF certification expires or is revoked, SCC automatically applies as a fallback with no service interruption.
  • Adequacy Decision: For countries recognised by the European Commission as providing adequate protection (GDPR Article 45).
Per EDPB Recommendation 01/2020, Setor AI conducts TIAs for each sub-processor outside the EEA. You may request copies of applicable SCC and supplementing measures at [email protected].
Setor AI uses third-party sub-processors to deliver the service. Categories include:
  • AI model providers — response generation, audio transcription, voice synthesis, image/profile picture analysis
  • Hosting and infrastructure — servers, CDN, frontend delivery, data storage (primary database within the EEA, provided by Hetzner Online GmbH, Germany; CDN via Cloudflare)
  • Payments — Stripe, Inc. (PCI-DSS Level 1 certified; card details never touch Setor AI servers)
  • Email delivery — transactional email (Resend)
  • Analytics — PostHog (EU data residency, Frankfurt); consent required
  • Session recording — Microsoft Clarity (consent required; all input fields masked)
  • Marketing attribution — Meta Pixel and Conversions API (consent required); hashed identifiers used; raw IP never stored in analytics
  • CRM and scheduling — Attio, Calendly, Cal.com
  • Public profile verification — Apify (verifies public Instagram profile data only)
  • Video hosting — Wistia
No sub-processor uses your data to train its own AI models. The full named and versioned list is published at setor.ai/subprocessors. Setor AI provides at least 14 days’ advance notice before adding or changing a sub-processor. You may object on documented data-protection grounds within the notice period.
Setor AI uses three categories of cookies on setor.ai and app.setor.ai:
  • Strictly necessary: Required for the website and app to function (session management, security tokens, login state, consent storage). No consent required. Cannot be disabled.
  • Analytics and session recording: PostHog (product analytics) and Microsoft Clarity (session recording). Require your prior active consent. All session recording tools mask input fields — no form content is ever captured. Retained up to 36 months.
  • Marketing: Meta Pixel and Meta Conversions API for ad attribution and conversion tracking. Require your prior active consent. Hashed identifiers are used — raw IP addresses are never stored in analytics systems.
A consent banner appears on first visit for all non-essential cookies. No pre-ticked boxes — your consent must be active and granular (CJEU C-673/17 Planet49). You can withdraw or change consent at any time via “Cookie Settings” in the website footer.Full details are in the Cookie Policy.
Setor AI applies industry-standard technical and organisational measures to protect your data:
  • Encryption at rest: AES-256 for all stored data, including OAuth tokens and sensitive fields
  • Encryption in transit: TLS 1.3 for all data transmissions
  • Network protection: Cloudflare WAF and DDoS protection; network segmentation; intrusion detection
  • Audit logging: Immutable audit logs with 12-month retention
  • Access controls: Least-privilege principle; multi-factor authentication (MFA); quarterly access reviews
  • Session recording: All session recording tools mask text fields and input data
  • Incident response: Documented plan with annual tabletop exercises; breach notification to UODO within 72 hours; notification to you within 24 hours if your processor data is affected
  • Vendor assessment: Security evaluation before engagement and annual review of all sub-processors
No internet transmission or electronic storage method is fully secure. Setor AI commits to commercially reasonable measures and prompt response to identified vulnerabilities.

The full Privacy Policy is available at https://setor.ai/privacy-policy. For all privacy and data protection matters, contact [email protected].