Privacy Policy - AWIFIN
Effective as of: 01.05.2025
Dear Customer,
We make every effort to ensure the security and confidentiality of your personal data. We care about your privacy when you visit our website, register an account, use AwiFin services, create project updates and reports, contact us by email or other communication channels, subscribe to our communications, or interact with our social media channels.
We process personal data in accordance with applicable law, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation, hereinafter referred to as the "GDPR."
This Privacy Policy explains what personal data we process, why we process it, on what legal basis, for how long, who may receive it, and what rights you have.
1. Who is the controller of your personal data?
The controller of your personal data is: eRapid Studio, Machowa 25a, 39-220 Pilzno, Poland, NIP: 8722318796, REGON: 362035564.
Email: contact@awifin.com
In this Privacy Policy, "AwiFin," "we," "us," or "our" means eRapid Studio operating the AwiFin service available at AwiFin.com.
For account, billing, support, website, analytics, marketing, and service administration data, eRapid Studio acts as the controller.
For project content, workspace data, updates, reports, stakeholder information, imported data, and other content added to AwiFin by a customer or user, eRapid Studio may act as a processor on behalf of the customer, where the customer determines the purposes and means of processing.
If you use AwiFin on behalf of a company, team, client, or other organisation, that organisation may be the controller of personal data contained in workspace content. In that case, eRapid Studio processes such data as processor under Article 28 GDPR. A Data Processing Agreement may be made available on request and may form part of the contract between the customer and eRapid Studio.
2. How do we obtain your personal data?
We may obtain personal data directly from you when you:
- ▪ visit our website;
- ▪ register an AwiFin account;
- ▪ create or join a workspace;
- ▪ create projects, updates, reports, blockers, risks, decisions, or stakeholder profiles;
- ▪ generate AI-assisted summaries or reports;
- ▪ share reports using public or private links;
- ▪ connect integrations such as Slack or Jira;
- ▪ purchase a subscription or use paid services;
- ▪ contact us by email, form, chat, or another communication channel;
- ▪ subscribe to marketing or product communications;
- ▪ interact with our social media pages.
We may also collect some technical data automatically when you use the website or service, including IP address, browser type, device data, operating system, pages visited, usage events, log data, and cookie identifiers.
3. What categories of personal data do we process?
Depending on how you use AwiFin, we may process the following categories of data.
Account and user data: name; email address; password hash or authentication provider identifier; account settings; workspace membership; role and permissions; login and authentication data.
Workspace and company data: workspace name; company or team name; invited users; team roles; subscription status; workspace configuration.
Product and project data: project names and descriptions; project updates; status reports; blockers; risks; decisions; next steps; action items; stakeholder profiles; audience preferences; generated summaries; shared report links; report metadata.
AwiFin is not intended for processing special categories of personal data under Article 9 GDPR, such as health data, biometric data, political opinions, religious beliefs, trade union membership, or data concerning sex life or sexual orientation. Users should not submit such data to AwiFin unless they have a valid legal basis and authority to do so.
If you connect third-party tools, we may process data necessary to provide the integration, such as Slack webhook configuration, Jira imported issue or project data, integration account identifiers, access tokens or API credentials, and integration logs.
Billing and payment data processed may include subscription status, Stripe customer ID, selected plan, invoice details, billing email, transaction metadata, tax-related information, and payment status. We do not store full payment card numbers - card processing is handled by Stripe.
Support and communication data: email address; message content; support requests; issue reports; product feedback; communication history.
Technical and usage data: IP address; browser type; operating system; device data; log data; session data; pages and features used; error logs; security logs; cookie and analytics identifiers.
Marketing and analytics data: email address; newsletter subscription status; campaign interaction data; website analytics events; approximate location; referral source; marketing consent status.
4. For what purposes, on what legal basis, and for how long do we process your data?
We process personal data for the following purposes.
4.1. Creating and maintaining your AwiFin account
We process your data to register your account, authenticate you, maintain your profile, manage your workspace access, and provide the AwiFin service.
Legal basis: Article 6(1)(b) GDPR - processing necessary for the performance of a contract or to take steps before entering into a contract.
Retention period: For the duration of your account and service use. After account deletion or contract termination, some data may be retained for the period necessary to establish, pursue, or defend claims, or to comply with legal obligations.
4.2. Providing the AwiFin service
We process project updates, reports, stakeholder profiles, workspace data, shared report data, and other content to provide the core AwiFin functionality, including creating and storing project updates, generating reports, managing workspace access, and supporting Slack and Jira integrations.
Legal basis: Article 6(1)(b) GDPR - performance of contract. Where we process customer content on behalf of a business customer, we may act as processor under Article 28 GDPR.
Retention period: For as long as the account, workspace, or relevant project data remains active, unless deleted earlier by the customer or user. Backup copies may remain for a limited period according to our backup retention schedule.
4.3. AI-assisted report generation
AwiFin uses artificial intelligence features to generate summaries, project reports, stakeholder-specific updates, executive snapshots, and similar content. We use OpenAI as an AI service provider.
Depending on the feature used, project updates, reports, stakeholder profile settings, blockers, risks, decisions, action items, and related workspace content may be sent to OpenAI to generate summaries or drafts.
AwiFin does not use customer content to train its own AI models. Where AwiFin uses OpenAI through business or API services, customer inputs and outputs are not used by OpenAI to train models by default.
Legal basis: Article 6(1)(b) GDPR - performance of contract.
Retention period: Generated outputs are stored as part of reports or report drafts unless deleted by the user or customer. Technical AI request metadata may be retained for a limited period for debugging and abuse prevention.
Important: AI-generated content may be inaccurate, incomplete, or unsuitable for a specific audience. Users should review all generated content before sharing it or relying on it.
4.4. Payments, subscriptions, invoices, and tax obligations
We process billing and payment-related data to manage subscriptions, process payments, issue invoices, verify payment status, and comply with accounting and tax obligations. Payment data is processed by Stripe.
Legal basis: Article 6(1)(b) GDPR - performance of contract, for payment and subscription handling; Article 6(1)(c) GDPR - compliance with legal obligations, for accounting and tax records.
Retention period: For the period required by applicable accounting and tax law, and until the expiry of relevant limitation periods.
4.5. Security, fraud prevention, and service reliability
We process technical data, logs, access records, and security events to protect AwiFin, prevent abuse, detect errors, maintain service availability, and secure personal data. AwiFin is hosted using Fly.io infrastructure.
Legal basis: Article 6(1)(f) GDPR - our legitimate interest in ensuring the security, reliability, and integrity of the service.
Retention period: For as long as necessary for security, troubleshooting, fraud prevention, and system administration.
4.6. Customer support and communication
We process data submitted in support requests, emails, or contact forms to respond to your questions, resolve issues, and provide assistance. We may use email service providers such as Mailgun and MailerLite to send transactional, product, or marketing emails.
Legal basis: Article 6(1)(f) GDPR - our legitimate interest in communicating with users and responding to requests.
Retention period: For the period necessary to handle the request, and afterwards until the expiry of applicable limitation periods.
4.7. Analytics and service improvement
We use Google Analytics to understand how users interact with the website or service, improve AwiFin, identify errors, measure feature usage, and develop product improvements. We use Google Analytics only where required consent has been obtained through our cookie banner.
Legal basis: Article 6(1)(a) GDPR - consent, where Google Analytics or similar non-essential analytics cookies or technologies are used.
Retention period: Until consent is withdrawn or the purpose of processing is achieved, subject to the retention settings of the analytics tool used.
4.8. Marketing and product communication
We may process your contact data to send you product updates, early access information, newsletters, promotional messages, or similar communications. We may use Mailgun and MailerLite to send these communications.
Legal basis: Article 6(1)(a) GDPR - consent, for newsletters and optional marketing communications; Article 6(1)(f) GDPR - our legitimate interest in marketing our own products, where permitted by law.
Retention period: Until you withdraw consent, unsubscribe, raise a valid objection, or the purpose of processing is achieved.
4.9. Social media pages
If you interact with our social media pages, we may process data visible through your profile and data related to your interaction with our posts, messages, comments, or pages.
Legal basis: Article 6(1)(f) GDPR - our legitimate interest in promoting AwiFin, communicating with users, and managing our public profiles.
Retention period: For as long as necessary for communication, page administration, or until you delete your interaction or the purpose is achieved.
4.10. Establishing, pursuing, or defending legal claims
We may process personal data to establish, pursue, or defend legal claims, handle disputes, enforce our terms, or respond to legal requests.
Legal basis: Article 6(1)(f) GDPR - our legitimate interest in protecting our rights.
Retention period: Until the expiry of applicable limitation periods or until final resolution of the relevant proceedings.
4.11. Notion integration
If a user chooses to connect a Notion workspace, the user creates an integration in their own Notion workspace and provides its access token to AwiFin. AwiFin uses it only to read the Notion pages the user has shared with that integration. AwiFin never writes to Notion.
When a user links a Notion page to a client record, AwiFin stores the page title, link, last-edited date, and a plain-text copy of the page content. The Notion access token is stored encrypted. The user can revoke it at any time in Notion.
The stored page text may be sent to OpenAI to generate client summaries, message drafts, suggested next steps, and notes. The user can exclude any linked page from AI features.
Legal basis: Article 6(1)(b) GDPR - performance of contract. Where the page content contains personal data controlled by the customer, we process it as processor under Article 28 GDPR.
Retention period: Until the user unlinks the page, or the client record or account is deleted. Disconnecting Notion deletes the access token and removes the connection between AwiFin and Notion; stored page copies stay on the client record until the page is unlinked.
4.12. monday.com integration
If a user chooses to connect a monday.com account, the user provides their personal monday.com API token to AwiFin. The token gives access to the boards the user can see in monday.com. AwiFin uses it only to read the items and boards the user chooses to link. AwiFin never writes to monday.com.
When a user links a monday.com item or board to a client record, AwiFin stores its name, board name, link, last-updated date, and a plain-text copy of its content (column values, subitems, and updates, or for a board, its description and items). The monday.com API token is stored encrypted. The user can revoke it at any time by regenerating it in monday.com.
The stored text may be sent to OpenAI to generate client summaries, message drafts, suggested next steps, and notes. The user can exclude any linked item or board from AI features.
Legal basis: Article 6(1)(b) GDPR - performance of contract. Where the content contains personal data controlled by the customer, we process it as processor under Article 28 GDPR.
Retention period: Until the user unlinks the item or board, or the client record or account is deleted. Disconnecting monday.com deletes the API token and removes the connection between AwiFin and monday.com; stored copies stay on the client record until they are unlinked.
5. What personal data do we process as a processor?
When a customer uses AwiFin to store or process workspace content, project updates, reports, stakeholder information, imported data, or other business content, the customer may be the controller of that data, and eRapid Studio may act as the processor.
In such cases, we process personal data only on documented instructions from the customer, including through the customer's use and configuration of AwiFin.
As processor, we may process: project updates; reports; stakeholder profiles; team member information; imported Jira data; Slack integration data; AI prompt and output data; shared report data.
We apply appropriate technical and organisational measures under Article 32 GDPR. After the end of the service, we will delete or return personal data processed on behalf of the customer, unless applicable law requires further storage.
Where required, a separate Data Processing Agreement may apply or may be provided on request.
6. Who may receive your personal data?
We may share personal data with trusted service providers only where necessary to provide, secure, maintain, or improve AwiFin.
Recipients may include:
- ▪ hosting and infrastructure provider: Fly.io;
- ▪ payment provider: Stripe;
- ▪ email providers: Mailgun and MailerLite;
- ▪ analytics provider: Google Analytics;
- ▪ AI provider: OpenAI;
- ▪ integration providers: Slack, Jira, Notion, and monday.com, if enabled by the user;
- ▪ accounting service providers;
- ▪ legal, accounting, or professional advisors;
- ▪ authorised public authorities, where required by law.
Each provider receives only the data necessary for its role and is required to provide appropriate data protection and confidentiality safeguards.
7. Do we transfer personal data outside the EEA?
In general, we aim to process personal data within the European Union or European Economic Area where possible.
However, some providers used to operate AwiFin may process personal data outside the EEA, including in the United States or other third countries. This may apply in particular to providers such as OpenAI, Stripe, Google Analytics, Mailgun, MailerLite, Fly.io, Slack, Jira, Notion, and monday.com.
Where personal data is transferred outside the EEA, we use appropriate safeguards required by GDPR, such as an adequacy decision by the European Commission, Standard Contractual Clauses adopted by the European Commission, additional technical and organisational safeguards where required, or other lawful transfer mechanisms available under GDPR.
8. Do we use AI providers?
Yes. AwiFin uses OpenAI to support AI-assisted report generation and summarisation.
Depending on the feature used, content submitted to AwiFin may be processed by OpenAI to generate stakeholder-specific summaries, executive snapshots, project reports, blocker summaries, risk summaries, decision summaries, action-required summaries, and email or Slack update drafts. Where the user has linked Notion pages or monday.com items and boards to a client, their stored text may also be included (see sections 4.11 and 4.12).
AwiFin does not use customer content to train its own AI models. Where AwiFin uses OpenAI through business or API services, customer inputs and outputs are not used by OpenAI to train models by default, unless such use is explicitly enabled or separately agreed.
We recommend that users avoid submitting unnecessary personal data, special-category data, confidential third-party information, or data they are not authorised to process. AI-generated content should be reviewed by the user before being shared.
9. Do we use cookies?
Yes. We use cookies and similar technologies on the website and, where relevant, in the AwiFin application. Cookies are small text files stored on your device.
Necessary cookies: Required for the website or service to work properly. They may support login, authentication, security, session handling, and service functionality. These cookies do not require consent where they are strictly necessary.
Analytics cookies: Help us understand how users interact with the website or service. We use analytics cookies only where consent has been obtained through the cookie banner.
Marketing cookies: May be used to measure campaigns, personalise communication, or display relevant advertising. We use marketing cookies only where required consent has been obtained.
You can manage or withdraw cookie consent through the cookie banner or cookie settings, if available. You can also restrict cookies through your browser settings. Disabling some cookies may affect the functionality of the website.
10. Do we profile your personal data?
We may analyse user activity on the website or in the service to understand product usage, improve AwiFin, and provide more relevant communication.
Where Google Analytics or similar tools are used, they may involve limited profiling, such as assessing interests based on website activity, approximate location, referral source, or interaction with product pages.
We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you. AI-assisted report generation in AwiFin is intended to support users in drafting and summarising content - it does not make legally binding decisions about individuals.
11. Public and shared reports
AwiFin may allow users to generate and share reports through links. Depending on the selected settings, shared reports may be accessible to people who receive the link. Users are responsible for ensuring that shared reports do not contain personal data, confidential information, or third-party data that they are not authorised to share.
Shared reports remain available until deleted, disabled, expired, or otherwise restricted by the user or workspace administrator.
12. How do we protect your data?
We use technical and organisational measures appropriate to the nature, scope, context, and risk of processing. These measures may include:
- ▪ TLS encryption for data transmission;
- ▪ access controls;
- ▪ role-based access restrictions;
- ▪ authentication mechanisms;
- ▪ secure password storage;
- ▪ backup procedures;
- ▪ monitoring and logging;
- ▪ incident response procedures;
- ▪ confidentiality obligations for authorised persons;
- ▪ limited access to production systems;
- ▪ data minimisation where possible;
- ▪ infrastructure security controls;
- ▪ regular review of security measures.
No online service can guarantee absolute security. However, we take reasonable steps to protect personal data against unauthorised access, loss, alteration, disclosure, or destruction.
13. How long do we keep your data?
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Account data is kept for the duration of the account, then for the limitation period for claims where necessary. Workspace and project content is kept until deleted by the user or customer, or until account or workspace termination, subject to backup retention. Billing and invoice data is kept for the period required by accounting and tax law. Support communication is kept until the request is handled, then for limitation periods where necessary. Server and security logs are kept for a limited period necessary for administration, troubleshooting, and security. Marketing data is kept until unsubscribe, withdrawal of consent, or end of purpose.
Backup copies may remain for a limited period after deletion before being overwritten or permanently removed.
14. What rights do data subjects have?
Depending on the circumstances and legal basis of processing, you may have the right to:
- ▪ access your personal data;
- ▪ receive a copy of your personal data;
- ▪ correct inaccurate data;
- ▪ request deletion of your data;
- ▪ restrict processing;
- ▪ object to processing;
- ▪ transfer your data;
- ▪ withdraw consent where processing is based on consent;
- ▪ lodge a complaint with a supervisory authority.
These rights are not absolute. In some cases, we may refuse or limit a request where permitted by law, for example where retention is required by legal obligations or for legal claims.
We will respond to your request without undue delay and no later than one month after receiving it. If the request is complex or we receive many requests, we may extend the response period by up to two additional months.
To exercise your rights, contact us at: contact@awifin.com
15. How can you complain about irregularities in personal data processing?
If you believe that we process your personal data unlawfully, you may lodge a complaint with the supervisory authority.
In Poland, the supervisory authority is: President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland. Website: uodo.gov.pl
16. Children's data
AwiFin is intended for business and professional use. It is not directed to children. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate legal basis, we will take steps to delete such data.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the law, technology, service functionality, providers, or our processing activities.
If we make material changes, we will inform registered users by email or through the AwiFin service. The current version of the Privacy Policy will be available on our website.
18. Contact
For questions about this Privacy Policy or your personal data, contact us at: contact@awifin.com