Privacy Policy
Last updated: April 2026 · Enginious Group S.A.
⚠ Draft — for internal review. GDPR-compliant final version to be reviewed by DPO before public launch.
1. Data Controller
Enginious Group S.A., KRS 0001007157, with registered office in Łódź, Poland, is the data controller for personal data processed through Persona 3.0.
2. Data We Collect
- Account data: email address, name (via Clerk authentication)
- Billing data: payment information processed by Stripe (we do not store card numbers)
- Avatar data: photos you upload for avatar generation
- Voice data: audio samples provided for voice cloning (Pro+ plans)
- Conversation data: transcripts and audio from voice conversations
- Usage data: conversation minutes, feature usage, API calls
- Technical data: IP address, browser type, device information
3. Legal Basis (GDPR Art. 6)
- Contract performance: account management, service delivery, billing
- Legitimate interest: security, fraud prevention, service improvement
- Consent: marketing communications, optional analytics
- Legal obligation: tax records, regulatory compliance
4. Data Storage & Location
All personal data is stored within the European Union:
- Database: Supabase (EU region)
- File storage: Cloudflare R2 (EU region)
- Authentication: Clerk (EU-compliant processing)
- Payments: Stripe (EU-compliant, PCI DSS Level 1)
5. Data Retention
- Account data: retained while account is active + 30 days after deletion
- Avatar/voice data: deleted within 30 days of account deletion or on request
- Conversation transcripts: retained for 90 days, then anonymised
- Billing records: retained for 7 years (Polish tax law)
6. Your Rights (GDPR)
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability (export your data)
- Object to processing
- Withdraw consent at any time
- Lodge a complaint with UODO (Polish DPA)
7. Third-Party Processors
8. Cookies
We use essential cookies for authentication and session management. Optional analytics cookies are only set with your consent. No third-party advertising cookies are used.
9. Contact
Data protection inquiries: privacy@enginious.tech
Enginious Group S.A., Łódź, Poland