Version: 1.0
Last updated: 26 August 2026
Effective date: 26.08.2026
This notice explains how personal data is handled when ASAI Labs - Auditting System is used to administer Stores, send Protocol requests, collect Protocol Submissions and support ASAI Labs - Auditting System users. It is intended to provide the information required by Articles 12, 13 and 14 of the General Data Protection Regulation (GDPR).
The Organization using ASAI Labs - Auditting System must complete the Organization-specific fields below before this notice is shown to its Store Contacts or other personnel. The approved vendor, transfer and retention record must also replace the marked publication fields before release.
1. Who is responsible for your data
Responsibility depends on why the data is processed.
Your Organization
For Store Contact information, Store assignments, Protocol Notifications and Protocol Submissions—including precise submission Location, comments, Protocol Images, annotations and review results—the Organization that requested the work determines why and how the data is used. It is the controller for that processing (Article 4(7) GDPR).
- Organization legal name: ASAI Labs Poland Sp.z.o.o.
- Registered address: ul. Złota 7, m. 28, 00-019, Warsaw, Poland
- Organization privacy contact: [email protected]
- Organization-specific lawful-basis and retention information: https://asailabs.com/privacy-policy
ASAI Labs processes this information for the Organization and on its documented instructions. For that processing, ASAI Labs is a processor (Articles 4(8) and 28 GDPR), not the controller that chooses the Organization's employment, inspection or operational purpose.
If a Protocol request does not identify the Organization or its privacy contact, contact ASAI Labs at [email protected]. ASAI Labs will help identify the relevant controller and route the request.
ASAI Labs
ASAI Labs is the controller for its own ASAI Labs - Auditting System account administration, authentication, service security, direct support, privacy-case records and legal obligations.
- Legal name: ASAI LABS POLAND SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
- Registered office: Ul. Złota 7, m. 28, 00-019 Warsaw, Poland
- KRS: 0001236627
- Email: [email protected]
ASAI Labs has not named an EEA representative because it is established in Poland. Privacy enquiries are handled through the contact above.
2. Who this notice covers
This notice may apply to:
- Organization administrators and regional managers;
- Store Contacts and other people who receive Protocol Notifications or submit Protocols;
- people whose image may incidentally appear in a Protocol Image;
- users who request support or enable optional support chat or Web Push; and
- people whose identifiers appear in necessary service-security or audit records.
ASAI Labs - Auditting System is a business service and is not directed to children. An Organization must not use it to intentionally collect children's data without a separately documented lawful basis and appropriate safeguards. Article 8 GDPR may apply where processing relies on consent for an information-society service offered directly to a child.
3. Personal data we process
Depending on how ASAI Labs - Auditting System is configured and used, the service processes the following categories of personal data (Article 4(1) GDPR):
- Identity and business contact data: name, business email address, phone number, role, Organization, Store and region assignments.
- Account and authentication data: account identifiers, password hashes, Store login codes, session identifiers, roles, account creation time and credential or enrolment status. ASAI Labs does not store account passwords in readable form.
- Public Integration API data: credential label, key prefix and hash, creation, last-use and revocation timestamps, Organization scope and the customer-directed records exchanged through the API. Plain API keys are not retained after issue.
- Store and operational data: Store name, address, coordinates, opening hours, schedules, expositions, configuration and external business identifiers.
- Protocol Notification data: recipient details, notification channel, delivery status, provider message identifier, failure information and related timestamps.
- Protocol Submission data: Protocol identifier, status and timestamps; comments; precise device coordinates at submission; capture time; calculated distance from the assigned Store; suspicious-location result; requested Protocol Images; annotations; fill-rate results; and human review decisions.
- Image-processing data: a temporary secured image awaiting sanitisation and face blurring, the privacy-ready image, processing status and technical image metadata. Faces are detected only to blur them. ASAI Labs - Auditting System does not use face recognition, identify people, match faces, create biometric templates, infer sensitive traits, train models on the images or reuse the images for an unrelated purpose.
- Web Push data: push subscription endpoint, public encryption key, authentication secret, browser user agent, registration and delivery status, and expiry or revocation information.
- Support data: the information a user provides in a support request. If a user separately enables optional Intercom chat, this can include their account or Store identifier, name, role, email address when available, browser-session details and chat messages.
- Security and audit data: user or Store identifier, Organization, action, affected record, permitted changed values, outcome, request identifier, timestamp, IP address, user-agent information and limited error details. Audit records exclude passwords, login codes, tokens, API keys, signed URLs, raw image bytes, message bodies and wholesale request or provider payloads.
- Browser information and preferences: authentication cookies, language and sidebar preferences, Protocol-scoped navigation state, optional-chat choice and, when enabled by the user, service-worker and Web Push state.
Protocol Images may incidentally reveal information about a person. Users are asked to avoid including people where possible. ASAI Labs - Auditting System is not intended to collect or infer special-category data listed in Article 9(1) GDPR. If an Organization's planned use is likely to involve such data, that Organization must establish an Article 9(2) condition and complete any required data protection impact assessment before using ASAI Labs - Auditting System for that purpose (Article 35 GDPR).
4. Why we process data and the applicable legal basis
Processing for which ASAI Labs is controller
| Purpose | Data normally used | Legal basis |
|---|---|---|
| Create and administer ASAI Labs - Auditting System accounts and provide authenticated access | Identity, business contact, role, account and authentication data | Performance of a contract where the individual is personally party to it (Article 6(1)(b)); otherwise ASAI Labs' legitimate interests in administering access to its business service (Article 6(1)(f)) |
| Authenticate users, prevent abuse, secure the service and investigate incidents | Authentication, session, IP address, user agent, security and limited audit data | ASAI Labs' legitimate interests in protecting users, Organizations and the service (Article 6(1)(f)); compliance with a legal obligation where a specific obligation applies (Article 6(1)(c)) |
| Provide direct support and respond to service enquiries | Account, contact and information included in the support request | Performance of a contract where applicable (Article 6(1)(b)); otherwise legitimate interests in supporting and operating the service (Article 6(1)(f)) |
| Provide optional Intercom support chat after the user chooses to enable it | Account or Store identifier, name, role, email when available, browser-session details and chat messages | Consent (Article 6(1)(a)), subject to the conditions in Article 7 |
| Handle privacy requests, complaints, disputes and personal-data incidents | Contact data, identity-verification result and minimum case evidence | Compliance with legal obligations (Article 6(1)(c)); establishment, exercise or defence of legal claims where applicable (Article 6(1)(f)) |
Where ASAI Labs relies on legitimate interests, those interests are the secure and accountable operation of a business service, access administration, fraud and abuse prevention, incident investigation and direct support. ASAI Labs must not use this basis where the individual's interests or fundamental rights override those interests (Article 6(1)(f); Recital 47). You may object as described in section 12.
Processing for which the Organization is controller
The Organization determines the purpose and lawful basis for:
- creating and maintaining Store and Store Contact records;
- assigning, scheduling and sending Protocol work;
- collecting comments, precise submission Location and requested Protocol Images;
- verifying submission proximity and investigating suspicious submissions;
- reviewing Protocol evidence and fill-rate results;
- sending email, SMS or Web Push notifications; and
- making Organization data available to its authorized users or integrations.
ASAI Labs performs these activities as the Organization's processor under Article 28 GDPR. The Organization must identify its lawful basis under Article 6 and, where applicable, its condition under Article 9. An employment or business relationship does not by itself mean that Article 6(1)(b) applies to the individual.
5. Where the data comes from
We receive personal data:
- from you, when you sign in, submit a Protocol, share Location, upload an image, enable Web Push, contact support or choose optional chat;
- from the Organization, which may provide administrator, manager, Store and Store Contact details, normally in connection with an employment, customer, supplier or contracting relationship;
- from your device and browser, including Location when you actively allow it, IP address, user agent, cookies, session state and a Web Push subscription when you enable notifications;
- from the service itself, which generates status, distance, analysis, review, delivery, security and audit records; and
- from service providers, which return delivery, processing, security and support status needed to operate ASAI Labs - Auditting System.
Where an Organization supplied your details rather than collecting them through ASAI Labs - Auditting System directly, the Organization must provide its Article 14 information no later than the applicable Article 14(3) deadline. The first Protocol message should identify the Organization and link to this completed notice.
6. What is required and what is optional
Account and Store Contact details are required where they are needed to create access and deliver configured Protocol requests. If required details are not provided, the relevant account or notification cannot be provided.
Precise Location and the requested Protocol Images are required to complete a Protocol configured with those evidence requirements. If you decline Location or do not provide the requested images, that Protocol cannot be submitted through the configured flow. ASAI Labs - Auditting System does not use Location for continuous or background tracking, advertising or unrelated worker profiling.
Comments are optional unless the Organization has made a comment necessary for its documented review process. Web Push and Intercom support chat are optional; declining either does not prevent the core Protocol workflow.
You may withdraw optional-chat consent at any time without affecting processing that occurred before withdrawal (Article 7(3) GDPR) by opening Privacy Preferences in the application sidebar and turning off Support Chat. You may also contact [email protected].
7. Location, images and automated analysis
When Location is required, ASAI Labs - Auditting System asks the browser for a device Location in the Protocol flow. The service stores the submitted coordinates, capture time, distance from the assigned Store and verification result. It does not request continuous background Location.
Protocol Images enter a secured processing path. A temporary unblurred copy exists while the image is validated and faces are blurred. Raw, failed and superseded images are not intended for user delivery. Authorized Organization reviewers receive the privacy-ready image. Users should avoid photographing people where possible.
ASAI Labs - Auditting System may automatically estimate product-display fill rate from a privacy-ready Protocol Image. It may also calculate the distance between the submission and Store coordinates and flag, or where configured temporarily block, a suspicious submission. The inputs are the relevant image or coordinates and Store coordinates; the outputs are a fill-rate estimate or a distance/verification result. Authorized Organization personnel remain responsible for operational review. The approved ASAI Labs - Auditting System workflow does not authorize an Organization to use an automated output as the sole basis for a decision that produces legal or similarly significant effects. An Organization proposing such a use must first establish an Article 22 GDPR exception, provide meaningful information about the logic and consequences, and implement the required safeguards.
8. Who receives the data
Personal data is made available only as needed to:
- authorized users of the relevant Organization, according to their role and Organization scope;
- authorized ASAI Labs personnel and contractors who operate, secure or support ASAI Labs - Auditting System;
- the service providers used to host, store, process and deliver the service;
- a browser push provider when a user enables Web Push;
- professional advisers, auditors, insurers, courts, regulators or public authorities where disclosure is legally required or necessary to establish, exercise or defend legal claims; and
- a recipient involved in a corporate transaction, subject to appropriate confidentiality and data-protection safeguards.
The current service-provider categories include:
| Provider or category | Purpose |
|---|---|
| Cloudflare | Pages and application delivery, Containers/Workers, R2 object storage, queues, image sanitisation and approved AI/image-processing infrastructure |
| Neon | PostgreSQL database hosting, backups and recovery |
| Resend | Organization-directed email delivery |
| Twilio | Organization-directed SMS delivery |
| Browser Web Push providers | Delivery of notifications to a device after the user enables Web Push |
| Better Stack or the approved telemetry endpoint | Payload-minimized server security and reliability telemetry; browser identity/session tracking is disabled |
| Intercom | Optional support chat only after the user enables it |
| OpenStreetMap/Nominatim | Administrator-requested Store-address geocoding; the current browser request can disclose the address query, IP address and referrer to the provider |
Inbound email image collection, advertising, marketing profiling, unapproved analytics and unlisted personal-data recipients are not part of the approved baseline. A current, versioned list of active providers, legal entities, processing countries and provider privacy terms will be published at: https://trust.asailabs.com
Service providers acting as processors or subprocessors must be bound by the protections required by Article 28 GDPR. A service that a user opens through a clearly labelled external link, such as external navigation, may act as an independent controller under its own privacy notice.
9. International transfers
Some service providers or their support personnel may process personal data outside the European Economic Area. Before publication, the active-vendor register must identify each destination and remote-access country and the applicable safeguard: an adequacy decision under Article 45 GDPR or an Article 46 safeguard such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required.
| Recipient and purpose | Personal data transferred | Destination | Transfer mechanism |
|---|---|---|---|
| Cloudflare, Inc. – application hosting, object storage, content delivery, security, logs and image/AI processing | Account and device identifiers, IP addresses, inspection records, images, location data and technical logs | United States, R2 Image Storage Jurisdiction set to EEA | European Commission adequacy decision for recipients participating in the EU-US Data Privacy Framework under GDPR Art. 45. Where that framework does not apply, the European Commission Standard Contractual Clauses under Art. 46(2)(c), together with supplementary contractual, security and encryption measures, apply under Cloudflare’s DPA. |
| Neon, Inc. – managed PostgreSQL database | Account, organisation, store, contact, inspection, notification, location and related application records | United States; the production database region is configured in the EEA | EU-US Data Privacy Framework under Art. 45. Where it does not apply, the 2021 European Commission Standard Contractual Clauses under Art. 46(2)(c) apply under Neon’s DPA. |
| Plus Five Five, Inc., trading as Resend – transactional email delivery | Recipient email address, store or location name, inspection link, scheduled time and email delivery records | United States | EU-US Data Privacy Framework under Art. 45 and the European Commission Standard Contractual Clauses under Art. 46(2)(c), incorporated into Resend’s DPA. |
| Twilio Inc. and its affiliates – SMS delivery | Telephone number, store or location name, inspection link and message delivery status | United States and, where necessary, the destination associated with the recipient’s telephone number | EU-US Data Privacy Framework under Art. 45. Depending on the applicable Twilio entity and service, Twilio’s Binding Corporate Rules under Art. 47 or the European Commission Standard Contractual Clauses under Art. 46(2)(c) may apply. |
| Browser and device push-notification providers, including Google, Apple and Mozilla | Push-subscription endpoint and keys, protocol identifier, location title and inspection link; notification payloads are encrypted for delivery | United States, depending on the browser or device selected by the user | EU-US Data Privacy Framework under Art. 45 where the recipient is certified, or European Commission Standard Contractual Clauses under Art. 46(2)(c). Push notifications are used only where the user has enabled them. |
| Intercom group– optional customer-support chat | Account or store identifier, name, role, email address, browser-session information and chat messages | United States | EU-US Data Privacy Framework under Art. 45, with the European Commission Standard Contractual Clauses under Art. 46(2)(c) as a fallback. Intercom is loaded only after the user chooses to enable the support chat. |
You may request information about the applicable transfer safeguard by emailing [email protected]. International transfers must comply with Articles 44–49 GDPR.
10. How long data is retained
Personal data must be kept no longer than necessary for its stated purpose (Article 5(1)(e) GDPR). The following periods or criteria apply to the current implementation; shorter customer instructions or a legal hold may apply.
| Data category | Retention period or criterion |
|---|---|
| Authentication cookies and active server sessions | Up to 30 days from issue and renewed for up to 30 days when an active session approaches expiry; deleted on sign-out where supported and invalidated when expired |
| ASAI Labs security and database audit records | 90 days |
| Account data | While access remains authorized and the relevant service relationship or support purpose continues, then until deletion can be completed subject to legal obligations and claim periods |
| Store, Store Contact and Organization records | While needed for the Organization's documented service purpose, then deleted, returned or anonymized on the Organization's instruction or at the end of services, subject to the controller's lawful retention requirements |
| Protocol records, submitted Location, privacy-ready images, comments, analysis and review results | While needed for the Organization's active Protocol, evidence, dispute and audit purpose, then deleted or anonymized on its documented instruction or at service end, subject to applicable legal holds |
| Temporary unblurred, failed or superseded images | Only for the secured validation, blur and retry process, then removed under the approved object-lifecycle rule |
| Notification delivery records and provider identifiers | Until delivery troubleshooting and the Organization's operational evidence purpose ends |
| Web Push subscription | Until the user unsubscribes, the endpoint expires or becomes invalid, the Store relationship ends, or the Organization instructs deletion |
| Optional Intercom support data | Until consent is withdrawn and the support purpose and applicable claim period end |
| Privacy-request, complaint, breach and legal-claim evidence | Only for the applicable legal obligation or limitation period, using case IDs, decisions, dates, receipts and evidence hashes where possible |
| Backups and recovery copies | Until the applicable rolling backup or snapshot expires; approved erasure instructions must be reapplied after a restore |
Expired or obsolete data may remain in restricted backups until the applicable backup cycle expires. It will not be restored to active use except for disaster recovery, and approved deletion instructions must be reapplied after a restore.
11. Cookies, browser storage and device features
ASAI Labs - Auditting System uses the following browser technologies. A separate browser-storage notice should publish the exact keys, lifetimes and deletion triggers.
| Technology | Purpose | Status |
|---|---|---|
admin_session and store_session HttpOnly cookies | Sign-in, authentication and Organization-scoped access | Strictly necessary; up to 30 days with renewal |
PARAGLIDE_LOCALE cookie | Remember the language selected or inferred for the service | Functional preference; 400 days |
sidebar_state cookie | Remember whether the navigation sidebar is open | Functional preference; seven days |
theme local storage | Remember the selected light or dark appearance | Functional preference; until changed or browser storage is cleared |
protocol-location:[Protocol ID] | Allow an in-progress Protocol to move between steps or retry without requesting Location again | Required for the configured in-progress submission |
protocol-upload-step:[Protocol ID] | Resume the current upload step | Functional Protocol state |
pwa-enrollment-created-links:v1 | Let an administrator retrieve recently generated enrollment links | Administrative convenience |
| Service worker | Prepare the application for Web Push | Currently registered when the application loads |
exponata-push-config cache and push subscription | Deliver Web Push and preserve the configuration needed to renew a user-enabled subscription | Optional; created after the user enables Web Push |
exponata-cookie-consent:v1:[User ID] | Store the version, timestamp, method and purposes for the user's browser-storage choices | Consent/preference record; remains until changed or browser storage is cleared |
| Intercom storage, cookies and requests | Provide support chat | Optional; created only after the user accepts |
Strictly necessary authentication storage is used to provide the service requested by the user. Optional third-party storage must not be set before the required choice. Browser Better Stack identity/session tracking, advertising and marketing cookies are disabled in the approved baseline.
12. Your data-protection rights
Subject to the conditions and exceptions in the GDPR, you may have the right to:
- access your personal data and receive a copy (Article 15);
- correct inaccurate or incomplete data (Article 16);
- request erasure (Article 17);
- restrict processing (Article 18);
- receive certain data in a portable format (Article 20);
- object to processing based on legitimate interests (Article 21);
- withdraw consent at any time, without affecting earlier lawful processing (Article 7(3)); and
- not be subject to a qualifying decision based solely on automated processing (Article 22).
These rights are not absolute and depend on the processing purpose and legal basis. We may request proportionate information to verify identity where there are reasonable doubts (Article 12(6)); an identity-document copy is not required by default.
For Organization-controlled Store Contact and Protocol data, send the request to the Organization privacy contact in section 1. A request sent to ASAI Labs at [email protected] will be routed to the relevant Organization and supported under its documented instructions. For processing controlled by ASAI Labs, email [email protected] or write to the postal address in section 1.
The controller normally responds without undue delay and within one month. That period may be extended by two further months for complex or numerous requests, with notice and reasons given within the first month (Article 12(3)).
13. Complaints
You may lodge a complaint with the supervisory authority where you live or work, or where an alleged infringement occurred (Article 77 GDPR).
ASAI Labs' lead supervisory authority is:
- Authority: President of the Personal Data Protection Office (Prezes UODO)
- Office: Urząd Ochrony Danych Osobowych
- Address: ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland
- Guidance: UODO information for individuals
UODO recommends first addressing the request to the relevant controller.
14. Security
ASAI Labs uses technical and organizational measures appropriate to the risk, including Organization-scoped access, role-based authorization, protected session secrets, restricted object storage and processing paths, face blurring before authorized image delivery, data-minimized audit records, security telemetry and tested recovery processes. No security measure can eliminate all risk. Measures are reviewed as the service and risks change (Articles 25 and 32 GDPR).
15. Changes to this notice
The effective version and date will be shown at the top of this notice. Material changes will be communicated through an appropriate service or Organization channel before they take effect where required. Previous versions will be available on request from [email protected].
16. Contact
Questions about ASAI Labs' processing or this notice can be sent to:
ASAI LABS POLAND SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Ul. Złota 7, m. 28, 00-019 Warszawa, Polska
Questions about Store Contact data or a Protocol Submission should ordinarily be sent to the Organization controller identified in section 1.