> ## Documentation Index
> Fetch the complete documentation index at: https://docs.setor.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Setor AI Privacy Policy — Version 4.0, Effective July 2026

> How Setor AI collects, uses, and protects your personal data under GDPR. No AI model training on client data. Contact office@setor.ai with any questions.

Setor AI is operated by SETOR AI Spółka z ograniczoną odpowiedzialnością (Poland, KRS 0001202220, NIP 7123502599) and is subject to the GDPR and Polish data protection law. This page summarises how your personal data is handled when you visit setor.ai, use app.setor.ai, or interact with any Setor AI service. Using our website or service does **not** constitute consent for analytics, advertising, or electronic marketing — those activities only occur after separate, prior, granular consent.

<Note>
  **Version 4.0 · Effective date: July 1, 2026**<br />
  **Data Controller:** SETOR AI Spółka z ograniczoną odpowiedzialnością, ul. Tomasza Zana 1, 20-601 Lublin, Poland · KRS 0001202220 · NIP 7123502599<br />
  **Contact:** [office@setor.ai](mailto:office@setor.ai)
</Note>

## Data Processing Details

<Accordion title="What data is collected">
  Setor AI collects the following categories of personal data:

  **Account data**

  * Identification: name, job title, business role
  * Contact details: work email, phone number
  * Company information: name, size, website, industry
  * Authentication: username, hashed password, MFA data
  * Subscription status, selected plan, trial information
  * Consent records: timestamp and version of accepted Terms and Privacy Policy, IP address and browser identifier at consent time

  **Instagram account data (via Meta API)**

  * Business/creator account identifiers, profile information (username, display name, profile picture, follower count, account category)
  * Permissions and access tokens granted through Meta OAuth
  * Account connection status and engagement metrics (as authorised by you)

  Setor AI is a **Meta Verified Technology Partner**. Authentication occurs solely through Meta's OAuth 2.0 process — your Instagram login credentials are never accessed, stored, or processed by Setor AI.

  **DM message content and metadata**

  * Incoming and outgoing message content
  * Conversation thread metadata (timestamps, message IDs, participant IDs)
  * Automated response content and conversation classification data (lead qualification scores, sentiment indicators)

  Message content may contain personal data about your contacts (End Users). For this data, you are the controller; Setor AI processes it solely as a processor under the Data Processing Agreement.

  **Payment data (via Stripe)**

  * Billing name and address
  * Last four digits of payment card, transaction identifiers, invoices
  * Card details are collected and stored exclusively by Stripe — they never touch Setor AI servers.

  **Technical data**

  * Full IP address (used for security, fraud prevention, and routing — constitutes personal data per CJEU C-582/14 Breyer)
  * Server-side geolocation derived from IP (approximate country, city, region — not precise GPS location)
  * Browser type and version, operating system, device type, referring URL, timezone, language settings

  **Marketing attribution data (consent required)**

  * UTM parameters, click identifiers (e.g. `fbclid`), referring page
  * Conversion events, quiz result identifiers
  * Hashed identifiers (`ip_hash` — a pseudonym linked to quiz result ID only; raw IP is never stored in analytics systems)
</Accordion>

<Accordion title="How your data is used">
  Setor AI processes your data under the following purposes and legal bases:

  | Purpose                                      | Legal basis                                                              | Retention                                                    |
  | -------------------------------------------- | ------------------------------------------------------------------------ | ------------------------------------------------------------ |
  | Account creation and management              | Contract (Art. 6(1)(b))                                                  | Contract duration + 30 days                                  |
  | DM automation service delivery               | Contract (Art. 6(1)(b))                                                  | Contract duration + 180 days                                 |
  | AI model processing (response generation)    | Contract; Legitimate interest for anonymised quality improvement         | Transient; aggregated metrics up to 36 months                |
  | Instagram account integration                | Contract (Art. 6(1)(b))                                                  | Contract duration + 30 days; tokens revoked on disconnection |
  | Payment processing                           | Contract; Legal obligation (Art. 6(1)(b)(c))                             | 5 years from fiscal year-end                                 |
  | Product analytics and session recording      | **Consent only** (Art. 6(1)(a))                                          | Up to 36 months                                              |
  | Ad attribution (Meta Pixel, Conversions API) | **Consent only** (Art. 6(1)(a))                                          | Per Meta retention and your consent                          |
  | Email marketing                              | **Consent only** (opt-in, Polish Electronic Communications Act Art. 398) | Until withdrawal + 30 days                                   |
  | Customer support                             | Contract; Legitimate interest                                            | 24 months from issue resolution                              |
  | Security monitoring and IP/geolocation       | Legitimate interest (Recitals 47, 49)                                    | 12 months                                                    |

  **Message content** is processed transiently to generate responses and is not used to train AI models. **Advertising and ad-tech purposes** (pixels, Conversions API, session recording, remarketing) are based solely on your consent — never on legitimate interest — consistent with CJEU C-252/21.
</Accordion>

<Accordion title="AI processing">
  Setor AI uses multiple AI sub-processors to analyse messages, understand context, generate responses, and process voice and video content. AI processing is an integral part of the service and is necessary for contract performance.

  **Key protections:**

  * **No training on client data:** Setor AI does not use your data or your end users' message content to train general AI models. Agreements with all AI sub-processors contractually prohibit this.
  * **Transient processing:** AI input and output data are processed in real time. AI sub-processors do not retain data after session completion, except for limited abuse-prevention logging (typically 30 days, then auto-deleted).
  * **No cross-customer data use:** One customer's data is never used to improve the service for another customer.
  * **Aggregated improvement only:** Setor AI may use irreversibly anonymised, aggregated data (e.g. effectiveness statistics, error rates) to improve service quality, under legitimate interest (Art. 6(1)(f) GDPR).

  You retain full control over AI results: you can configure rules, review conversations, override or delete any response, and pause or disable AI automation at any time.
</Accordion>

<Accordion title="Your GDPR rights">
  As a data subject, you have the following rights under the GDPR:

  <CardGroup cols={2}>
    <Card title="Access" icon="eye">
      Request a copy of the personal data Setor AI holds about you.
    </Card>

    <Card title="Rectification" icon="pen">
      Ask us to correct inaccurate or incomplete data.
    </Card>

    <Card title="Erasure" icon="trash">
      Request deletion of your data where no legal basis for continued retention exists.
    </Card>

    <Card title="Portability" icon="file-export">
      Receive your data in a structured, machine-readable format.
    </Card>

    <Card title="Restriction" icon="lock">
      Request that we restrict processing of your data in certain circumstances.
    </Card>

    <Card title="Objection" icon="hand">
      Object to processing based on legitimate interest (including direct marketing).
    </Card>
  </CardGroup>

  **To exercise any right:** email [office@setor.ai](mailto:office@setor.ai). We confirm receipt within 5 business days and respond substantively within **30 calendar days**.

  **To lodge a complaint:** contact the **President of the Office for Personal Data Protection (UODO)**, ul. Stawki 2, 00-193 Warsaw, Poland — [uodo.gov.pl](https://uodo.gov.pl). We encourage you to contact us first so we can resolve issues directly.
</Accordion>

<Accordion title="Data retention">
  | Data category                                | Retention period                                                                |
  | -------------------------------------------- | ------------------------------------------------------------------------------- |
  | Account data                                 | Contract duration + 30 days                                                     |
  | DM message content and conversation metadata | Contract duration + 180 days                                                    |
  | Payment records and invoices                 | 5 years from fiscal year-end (Accounting Act obligation)                        |
  | Product analytics data                       | Up to 36 months, then deletion or anonymisation                                 |
  | Security and access logs                     | 12 months                                                                       |
  | Marketing consent records                    | 3 years from consent date                                                       |
  | Customer support records                     | 24 months from issue resolution                                                 |
  | Legal and compliance documentation           | Per applicable limitation periods (typically 3–6 years under Polish Civil Code) |

  When your account is closed, your data is deleted or anonymised within the periods above. You may request deletion of individual conversations at any time from within the app.
</Accordion>

<Accordion title="International transfers">
  Setor AI's primary database is located **within the EEA**. Some sub-processors are based outside the EEA, including in the United States. All transfers outside the EEA use at least one of the following safeguards:

  * **Standard Contractual Clauses (SCC):** Commission Implementing Decision (EU) 2021/914, supplemented by Transfer Impact Assessments (TIA) where required.
  * **EU-US Data Privacy Framework (DPF):** For certified US entities. If a DPF certification expires or is revoked, SCC automatically applies as a fallback with no service interruption.
  * **Adequacy Decision:** For countries recognised by the European Commission as providing adequate protection (GDPR Article 45).

  Per EDPB Recommendation 01/2020, Setor AI conducts TIAs for each sub-processor outside the EEA. You may request copies of applicable SCC and supplementing measures at [office@setor.ai](mailto:office@setor.ai).
</Accordion>

<Accordion title="Sub-processors">
  Setor AI uses third-party sub-processors to deliver the service. Categories include:

  * **AI model providers** — response generation, audio transcription, voice synthesis, image/profile picture analysis
  * **Hosting and infrastructure** — servers, CDN, frontend delivery, data storage (primary database within the EEA, provided by Hetzner Online GmbH, Germany; CDN via Cloudflare)
  * **Payments** — Stripe, Inc. (PCI-DSS Level 1 certified; card details never touch Setor AI servers)
  * **Email delivery** — transactional email (Resend)
  * **Analytics** — PostHog (EU data residency, Frankfurt); consent required
  * **Session recording** — Microsoft Clarity (consent required; all input fields masked)
  * **Marketing attribution** — Meta Pixel and Conversions API (consent required); hashed identifiers used; raw IP never stored in analytics
  * **CRM and scheduling** — Attio, Calendly, Cal.com
  * **Public profile verification** — Apify (verifies public Instagram profile data only)
  * **Video hosting** — Wistia

  No sub-processor uses your data to train its own AI models. The full named and versioned list is published at [setor.ai/subprocessors](https://setor.ai/subprocessors). Setor AI provides at least **14 days' advance notice** before adding or changing a sub-processor. You may object on documented data-protection grounds within the notice period.
</Accordion>

<Accordion title="Cookies">
  Setor AI uses three categories of cookies on setor.ai and app.setor.ai:

  * **Strictly necessary:** Required for the website and app to function (session management, security tokens, login state, consent storage). No consent required. Cannot be disabled.
  * **Analytics and session recording:** PostHog (product analytics) and Microsoft Clarity (session recording). **Require your prior active consent.** All session recording tools mask input fields — no form content is ever captured. Retained up to 36 months.
  * **Marketing:** Meta Pixel and Meta Conversions API for ad attribution and conversion tracking. **Require your prior active consent.** Hashed identifiers are used — raw IP addresses are never stored in analytics systems.

  A consent banner appears on first visit for all non-essential cookies. No pre-ticked boxes — your consent must be active and granular (CJEU C-673/17 Planet49). You can withdraw or change consent at any time via "Cookie Settings" in the website footer.

  Full details are in the [Cookie Policy](/legal/cookie-policy).
</Accordion>

<Accordion title="Security">
  Setor AI applies industry-standard technical and organisational measures to protect your data:

  * **Encryption at rest:** AES-256 for all stored data, including OAuth tokens and sensitive fields
  * **Encryption in transit:** TLS 1.3 for all data transmissions
  * **Network protection:** Cloudflare WAF and DDoS protection; network segmentation; intrusion detection
  * **Audit logging:** Immutable audit logs with 12-month retention
  * **Access controls:** Least-privilege principle; multi-factor authentication (MFA); quarterly access reviews
  * **Session recording:** All session recording tools mask text fields and input data
  * **Incident response:** Documented plan with annual tabletop exercises; breach notification to UODO within 72 hours; notification to you within 24 hours if your processor data is affected
  * **Vendor assessment:** Security evaluation before engagement and annual review of all sub-processors

  No internet transmission or electronic storage method is fully secure. Setor AI commits to commercially reasonable measures and prompt response to identified vulnerabilities.
</Accordion>

***

<Note>
  The full Privacy Policy is available at [https://setor.ai/privacy-policy](https://setor.ai/privacy-policy). For all privacy and data protection matters, contact [office@setor.ai](mailto:office@setor.ai).
</Note>
