Legal

Privacy Policy

Version 1.0 | Last updated: 7 September 2026

Table of contents

1. Controller and contact details

The controller of the personal data described in this Policy is ASKSPOT SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office in Kraków at al. Jana Pawła II 43B, 31-864 Kraków, Poland, National Court Register (KRS) number 0000993175, tax identification number (NIP) 6751770919 (“AskSpot”, “we”, “us”).

For matters concerning personal data or to exercise your rights, you can contact us at kontakt@askspot.io or at the postal address above.

2. When this Policy applies

This Policy describes the processing of data relating to people who visit our websites, contact us, are interested in our offering, or create or operate an AskSpot account. It also covers people representing our customers and business partners and the contact persons they designate.

When a store or another customer uses AskSpot to serve its users, we process the data entrusted to us on that customer’s behalf. The terms of that relationship are set out in the Data Processing Agreement (DPA), which is an annex to the AskSpot Terms and Conditions. The relevant controller is responsible for informing the users of that store or customer about the processing of their data. For matters concerning a conversation with an agent on a store’s website, please contact the store first; if we receive a request concerning that conversation, we will forward it to the relevant customer.

This Policy does not constitute consent to marketing and does not replace the DPA. Using AI tools to process data entrusted by a customer does not authorise us to use that data for our own marketing.

3. What data we receive and where it comes from

We receive data directly from you when you complete a form, create an account, order a service, write to us or use the website. Depending on the circumstances, this includes your name, business email address, telephone number, company, job title, website address, account details, billing details and the content of correspondence, support requests and attachments you provide. The scope depends on the matter and the feature selected; not every form requires all of these details.

We may also receive your business details from your employer or the company you represent, another authorised person at that company, public company websites, business registers and public professional profiles, or business contact information providers. In such cases, the data consists of identification and contact details associated with your professional role, company and potential or existing business relationship. We provide the information required by the GDPR, including the source of the data and your rights, no later than one month after obtaining the data; if we contact you or disclose the data to another recipient sooner, we provide that information no later than the first such contact or disclosure, subject to the exceptions provided by the GDPR. Making an address publicly available does not constitute consent to receive electronic marketing.

When you use the website or an account, technical data is also processed, such as your IP address, session and device identifiers, browser type, and information about pages visited, events and errors. Additional analytics and advertising identifiers depend on your choices concerning cookies and similar technologies described in section 9.

4. Purposes and legal bases for processing

The legal bases below refer to Article 6(1) of Regulation (EU) 2016/679 (“GDPR”).

PurposeLegal basis and explanation
Responding to enquiries, presenting a requested offer, demonstrating the service and making arrangements before entering into a contractPoint (b): taking steps at your request before entering into a contract, if you will be a party to it; otherwise, point (f): our legitimate interest in handling correspondence and maintaining business relationships.
Creating and operating an account, performing the contract, handling support requests and sending service communicationsPoint (b): where you are a party to the contract; point (f): where you act as a representative or user of a customer’s account, for the purposes of carrying out our business relationship with that company, managing access and providing support.
Billing, invoicing and complying with legal obligationsPoint (c): obligations under tax and accounting law; point (b) or (f), as applicable, for processing payments and managing the business relationship itself.
Website and account security, preventing abuse, diagnostics and keeping the service operationalPoint (f): our legitimate interest in protecting systems, data and users and resolving technical problems.
Establishing, exercising or defending legal claims, keeping evidence of consent and requests handledPoint (f): protecting our rights and demonstrating proper conduct; point (c): to the extent of legal obligations relating to the handling of individuals’ rights.
Maintaining business relationships and marketing our own servicesPoint (f): our legitimate interest in presenting our services and maintaining business relationships. You may object to marketing at any time. Marketing by email, telephone or any other channel requiring consent is carried out only after obtaining the appropriate consent for that channel.
Additional website analytics, campaign measurement and advertising using non-essential cookies or similar identifiersPoint (a): consent to specified purposes given in the cookie settings; you may withdraw it.

If we request consent for another, separately described purpose, we identify that purpose when collecting consent. We do not make creating an account or purchasing a service conditional on consent to marketing or non-essential cookies.

5. Whether you must provide data

Providing data is voluntary, but details marked as required are needed to carry out a particular action, such as responding to a message, creating an account or entering into a contract. Without them, we may be unable to carry out that action. Data needed to issue an invoice and comply with other legal obligations is determined by applicable law. Additional details and consent to marketing or non-essential cookies remain optional.

6. Who we share data with

Authorised people working for AskSpot and service providers have access to data to the extent necessary to perform their tasks. Recipients may include providers of hosting, cloud and security services, email and communications, CRM and support tools, invoicing and payment systems, and accounting, legal and audit services. Cloudflare Turnstile helps protect forms against abuse. For additional analytics and advertising, recipients also include the providers of tools listed in section 9, in accordance with the consent choices made.

Service providers processing data on our behalf are subject to appropriate agreements and instructions. Organisations fulfilling their own obligations, such as banks or professional advisers, may act as separate controllers. Authorised public bodies may also receive data where disclosure is required by applicable law. We do not disclose the entire dataset to all of these recipients.

7. Transfers of data outside the EEA

Using international technology services may involve processing of, or access to, data outside the European Economic Area, particularly in the United States. Storing data on a server in the EEA does not itself rule out access from another country.

Such transfers require a mechanism compliant with Chapter V of the GDPR. We rely on an applicable European Commission adequacy decision or appropriate safeguards, in particular the European Commission’s standard contractual clauses together with the required assessment and supplementary measures. For recipients in the United States, we may rely on the EU–US Data Privacy Framework only where the recipient holds appropriate, current certification covering the transfer concerned.

To obtain information about the mechanism applied to your data or a copy of the relevant safeguards, contact kontakt@askspot.io. The copy may take account of the need to protect confidential information and other individuals’ data. Consent to cookies or acceptance of the Terms and Conditions does not replace the required transfer safeguards.

8. How long we retain data

The retention period depends on the purpose and type of data. We delete or irreversibly anonymise data once there is no longer a basis for retaining it.

Type of dataRetention period or criteria used to determine it
Enquiries and discussions about our offeringUntil a response has been provided and the matter or discussions about a business relationship have concluded; afterwards, we retain only what is needed for any resulting contract, legal obligation or legal claim.
Account and contact details used in a business relationshipFor as long as the account or business relationship is maintained and the activities associated with ending it are carried out; afterwards, only what is required for billing, demonstrating compliance with obligations or legal claims is retained.
Billing documentsFor the retention period required by tax and accounting law, calculated under the rules applicable to the document concerned; longer where proceedings or another legal obligation require it.
Data needed for legal claimsUntil the applicable limitation period expires or, if proceedings begin before then, until they are finally concluded and any required enforcement steps are completed. This does not mean that all account data is retained.
Marketing and consent recordsUntil an effective objection to marketing, withdrawal of the relevant consent or earlier termination of the purpose concerned. A limited record of an objection or withdrawal may be retained to honour it; evidence of consent and its use may be retained to the extent needed to demonstrate compliance or defend legal claims.
Diagnostic and security dataFor the time needed to detect and investigate errors or abuse and verify the effectiveness of remedial action. We determine the period by considering the types of events, the time needed to detect an incident and the scope of the data. An extract relating to a specific incident is retained until the incident is investigated and remedial action is completed, and afterwards only to the extent necessary for a legal obligation or legal claim.
Analytics and advertising data stored outside the browserWe determine the period separately from the lifetime of cookies, taking into account the duration of the campaign or analysis, the period needed to compare its results and the scope of consent. Once those purposes and the grounds for further processing cease to apply, we delete or irreversibly anonymise the data. Withdrawal of consent ends further processing based on that consent, retaining only data required to demonstrate that consent was given, comply with a legal obligation or protect legal claims.
Cookies and data in browser storageIn accordance with the periods in section 9; the time an identifier remains in the browser is not the same as the retention period for all data held by its provider. The scope of further processing depends on the purpose, consent and the rules of the relevant tool.

Data entrusted by our customers is subject to the return and deletion rules in their contract and DPA. While the Services are provided, the standard retention period is 2 years for conversation history and 30 days for full conversation logs; other periods may be lawfully agreed with the customer. Ending the relationship and the customer’s instructions are governed by the DPA, preserving the applicable data retrieval period. The periods above relating to AskSpot’s own purposes do not automatically extend the retention of entrusted data.

9. Cookies and similar technologies

Cookies are small files stored in your browser. We also use browser local storage (localStorage) and similar identifiers. Essential technologies enable requested features to work and remember privacy choices. Analytics and advertising technologies require prior consent; you may refuse them without losing access to the basic website.

You can change your choices through the cookie settings in the website footer. You may accept selected categories, reject non-essential technologies or change a previous choice. Withdrawing consent does not affect the lawfulness of earlier processing. You can also remove data already stored in your browser through its settings; withdrawing consent does not necessarily remove all such stored data. Blocking essential technologies may limit the operation of certain features.

The list below relates to the AskSpot website. The specific set depends on the page, feature and consent choices; not every item will necessarily be used during every visit.

Identifier / toolPurposePeriod in the browser
cc_cookie — AskSpot, cookie settings mechanismRemembering consent choicesUp to 6 months
askspot_attr — AskSpotIdentifying the source of a visit and campaign attributionUp to 90 days
_ga, _ga_* — Google AnalyticsWebsite usage statistics and visit measurementUp to 2 years
__hstc, hubspotutk — HubSpotVisit analytics and recognising a returning browserUp to 6 months
__hssc — HubSpotInformation about the current sessionUp to 30 minutes
__hssrc — HubSpotDetecting a browser restartUntil the end of the session
apolloAnonId — Apollo, localStorageVisit identifier also used to match a visit to a company or business profilePersistent storage, until website data is deleted
[appId]_eventQueue — Apollo, localStorage; the prefix depends on the applicationQueue of events awaiting transmissionUntil the events are sent or website data is deleted
liveIntentData — LiveIntent through Apollo, localStorageMatching a visit to a marketing profilePersistent storage, until website data is deleted

Periods may restart when an identifier is stored or renewed, according to the tool’s function and the consent given. Google Tag Manager manages when tools are activated; it does not constitute separate consent for their operation. Google Analytics and HubSpot are used for additional analytics. Apollo, including the use of LiveIntent through Apollo as described in the settings, may match a visit to a company or business profile and help prioritise sales outreach. These features are subject to the choice concerning advertising technologies. You can also find information about the providers in the Google privacy policy, HubSpot privacy policy, Apollo privacy policy and LiveIntent privacy policy.

If we introduce other technologies requiring consent or a new purpose for their use, the relevant information and choice will be made available before they are activated. Cookie settings on the AskSpot website do not replace choices on our customers’ websites or in providers’ separate services.

10. Automation and profiling

Analytics and advertising tools may automatically combine information about visits and interactions to measure campaign performance, recognise returning browsers, match a visit to a company or profile, prioritise sales outreach and tailor content. To the extent this relates to an individual, it may constitute profiling. This takes place in accordance with choices concerning non-essential technologies; you may withdraw consent and object to marketing. Identifying a visit does not itself constitute consent to marketing by email or telephone.

Such profiling is used to tailor and measure marketing communications, rather than to determine your rights or obligations. If a separate feature were to make decisions based solely on automated processing that produce legal effects or similarly significantly affect you, we would provide the appropriate information about the basis, operation, effects and safeguards available to you before using it. Processing by an agent acting on a customer’s behalf falls within the scope described in section 2.

11. Your rights

Under the conditions set out in the GDPR, you may request access to your data and a copy of it, rectification, erasure or restriction of processing. The right to data portability applies to data you have provided that is processed by automated means on the basis of consent or a contract.

You may object at any time to direct marketing, including related profiling. Following an objection, we do not process your data for that purpose. If we process data on the basis of legitimate interests for another purpose, you may object on grounds relating to your particular situation; we will consider the objection in accordance with the GDPR.

You may withdraw consent at any time without affecting the lawfulness of earlier processing. For marketing, use the unsubscribe option in the message or contact us; for cookies, use the settings described in section 9. To exercise your other rights, contact kontakt@askspot.io. If we have reasonable doubts, we may request information necessary to confirm your identity.

We respond without undue delay, generally within one month of receiving a request. Where the complexity or number of requests makes an extension necessary, the GDPR allows the period to be extended by a further two months; we will inform you of the extension and the reasons for it within the first month. We will also explain any refusal and the remedies available.

You may lodge a complaint with the President of the Polish Personal Data Protection Office — information is available at uodo.gov.pl — or another competent supervisory authority, in particular in the country of your habitual residence, place of work or the alleged infringement.

12. Changes to this Policy

We update this Policy when the processes, tools or legal requirements it describes change. The current version shows its date at the beginning of the document. We notify you of material changes in a manner appropriate to their scope and provide information about any new purpose before processing data for that purpose. A change to this Policy does not extend the consent you have given; if new consent is needed, we request it separately.

Ready to make every conversation sell?

Book a demo and see AskSpot on your own catalog. Onboarding takes a few days.