Legal documents

Privacy Policy (GDPR)

Last updated: 23 September 2026

This policy explains which personal data TarDigRada.ai processes, for which purposes, on which legal basis, and which rights you have. It follows Regulation (EU) 2016/679 (GDPR) and applicable national data protection law.

The controller of personal data is Ada Margo, author and owner of the TarDigRada.ai project (the “Controller”). Contact for data protection matters: ada@ada-margo.com, tel. +48 665 665 655. Application form submissions are delivered to: adriana.marglewska@gmail.com. Registration details of the operating entity will be added once the entity is formally registered.

Data we process

We process only the data needed to run the service and to respond to you.

  • Submission data: company or organisation name, contact person, email address, description of resources, competences or projects.
  • Account data for signed-in users: email address and authentication data, including Google sign-in data if you choose it.
  • Technical data: IP address, browser and device type, security and error events recorded in logs.
  • The content of email correspondence with us.

Purposes and legal bases

  • Handling submissions, assessing complementarity and replying to you — Art. 6(1)(b) and (f) GDPR (contract or pre-contractual steps, and legitimate interest).
  • Running accounts and authentication — Art. 6(1)(b) GDPR.
  • Service security, abuse prevention and error diagnostics — Art. 6(1)(f) GDPR.
  • Marketing and information messages where you consent — Art. 6(1)(a) GDPR; consent can be withdrawn at any time.
  • Compliance with legal obligations, including accounting and tax duties — Art. 6(1)(c) GDPR.

Retention

Submission data is kept for the duration of the conversation and up to 24 months after the last contact, unless you ask for deletion earlier. Account data is kept until the account is deleted. Technical logs are kept for up to 12 months. Data required by accounting law is kept for the statutory period.

Recipients and processors

Data may be entrusted to service providers acting on our instructions under data processing agreements: hosting and infrastructure providers, database and authentication providers, email providers and — for AI-assisted features — language and image model providers. We do not sell personal data.

Transfers outside the EEA

Some providers may process data outside the European Economic Area. Such transfers rely on a European Commission adequacy decision or on Standard Contractual Clauses, together with additional technical and organisational safeguards.

Your rights

You have the following rights, which we honour without undue delay and within one month at the latest.

  • Right of access and to receive a copy of your data (Art. 15 GDPR).
  • Right to rectification (Art. 16 GDPR).
  • Right to erasure (Art. 17 GDPR).
  • Right to restriction of processing (Art. 18 GDPR).
  • Right to data portability (Art. 20 GDPR).
  • Right to object to processing based on legitimate interest (Art. 21 GDPR).
  • Right to withdraw consent at any time, without affecting the lawfulness of earlier processing.
  • Right to lodge a complaint with a supervisory authority; in Poland: President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw.

Automated decisions and profiling

We do not make decisions with legal effects based solely on automated processing. AI-assisted tools only prepare suggestions and recommendations that a human reviews.

Security

We use encrypted transmission, role-based access control, data minimisation and security event logging. In the event of a personal data breach we notify the supervisory authority within 72 hours, and affected individuals where the breach poses a high risk to their rights.

Providing data is voluntary

Providing data is voluntary but necessary to handle a submission, maintain an account or answer a message.