How we collect, use, and protect your data under the GDPR.
01
Controller
The data controller is SmashOne AI Sp. z o.o., Aleja Rzeczypospolitej 6/U19, 02-972 Warsaw, Poland (KRS 0001249992, NIP 9512650941). The supervisory authority is the President of the Personal Data Protection Office (UODO), Warsaw, Poland. This Privacy Policy applies to the smashone.ai European public surface.
02
Scope
This policy covers the information you give us when you create an account, the information collected when you use SmashOne, and the information received from the social media platforms you choose to connect: Facebook, Instagram, Telegram, WhatsApp Business, and Google Business Profile, each once that channel is enabled for your account.
03
Connected channels
We process data from a channel only when you connect that channel to an AI employee, it is enabled for your account, and the connected third-party platform provides the data needed for the feature. Charges for a channel start on Day 15 after the 14-day free trial unless the checkout says otherwise. If a channel is unavailable, withdrawn, or removed for platform access, legal, safety, or policy reasons, we stop collecting new data from that removed channel where technically possible, stop future charges for that removed channel, and keep our customer-facing availability statements aligned with UCPD rules against misleading commercial claims.
04
Data we collect
We collect account details, business profile information, connected platform metadata, catalog items, scheduled content, messages, billing records, support communications, security logs, and product usage events needed to operate the service. Catalog items may include photographs and other media you upload. Where those photographs show identifiable people — for example your staff, models or customers — they are personal data of those people, and you remain the controller for them.
05
How we use data
We use data to provide publishing, messaging, AI assistant, analytics, billing, security, support, product improvement, abuse prevention, and legal compliance.
06
Legal bases (GDPR Article 6)
We process personal data only where we have a legal basis under Article 6 GDPR. The table below maps our main purposes to their legal basis.
Purpose
Data categories
Legal basis (Art. 6 GDPR)
Providing the service (publishing, messaging, scheduling, catalog, AI assistant)
Account, content, connected-platform data
Performance of a contract — Art. 6(1)(b)
AI assistant replying to your customers on your behalf
Customer-conversation content (we act as processor for you)
Performance of a contract — Art. 6(1)(b)
Billing, setup fee, payments and invoicing
Billing and transaction data
Contract — Art. 6(1)(b); and legal obligation for accounting/tax records — Art. 6(1)(c)
Security, fraud and abuse prevention, audit logging
Account, usage, device/IP data
Legitimate interests — Art. 6(1)(f) (keeping the service and accounts secure)
Support
Contact and ticket data
Contract — Art. 6(1)(b) and legitimate interests — Art. 6(1)(f)
Product improvement and service analytics
Usage data (aggregated where possible)
Legitimate interests — Art. 6(1)(f)
Optional analytics or marketing cookies (only if you enable them)
Cookie and usage data
Consent — Art. 6(1)(a)
Legal compliance (responding to lawful requests, DSA notices, record-keeping)
As required
Legal obligation — Art. 6(1)(c)
Where we rely on legitimate interests, we balance our interest against your rights and only proceed where your interests do not override ours; you may object at any time. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
07
Social platform data
Connected social account data is used only to deliver requested publishing, messaging, analytics, and AI assistant features. We do not sell personal information.
08
AI processing of your content
The assistant uses your business profile, FAQ, catalog, connected platform messages, and configured tone to draft answers. Sensitive or off-script items can be escalated for human review. AI employees also generate content for you: post text and images produced from the photographs in your catalog. Generated media is created on your instructions, stored with your other content, and published only to the channels you have connected.
09
Service providers
We use service providers for hosting, analytics, payments, communications, monitoring, and AI processing. They process data only for the service purposes we authorize.
10
Sub-processors and international transfers
We use the following sub-processors to operate the service: Hetzner Online GmbH (Germany) for EU application hosting and compute; DigitalOcean, LLC (Frankfurt, Germany) for managed PostgreSQL, Valkey cache, and object storage including backups; Stripe Payments Europe, Ltd. (Ireland), with Stripe, Inc. group affiliates in the United States, for payment processing; Brevo (Sendinblue SAS, France) for transactional email; Google Workspace (Gmail) for inbound email processing at info@smashone.ai; Google LLC (Vertex AI) for AI processing — assistant replies and generated content, including text and images — currently configured with a global processing location; Cloudflare, Inc. for DNS, CDN, WAF, and TLS edge security; Sentry (Functional Software, Inc.) for error monitoring with PII minimisation; PostHog (EU Cloud) for pseudonymous server-side product analytics; and ScrapingBee SAS (France) to retrieve your public business website for the assistant’s knowledge base. Where a sub-processor is US-incorporated or processes data outside the EEA (DigitalOcean, Stripe, Google, Cloudflare, Sentry, PostHog), transfers rely on the EU-US Data Privacy Framework adequacy decision where applicable or Standard Contractual Clauses with supplementary safeguards. The current list, with regions and dates, is maintained on our Sub-processors page; we notify customers at least 30 days before adding a new sub-processor.
11
Connected social platforms as independent controllers
When you connect a social platform to SmashOne, that platform processes personal data as an independent controller under GDPR Articles 13 and 14 — not as a SmashOne sub-processor. This is different from the sub-processors above: those process personal data only on SmashOne’s documented instructions under Article 28 GDPR, while a connected social platform decides how it processes personal data on its own platform, for its own purposes, under its own privacy policy. We disclose the platforms below as recipients and independent controllers so you know who receives your data and can read their policies before you connect. The platforms listed below exchange data with SmashOne only for the channels you have connected and that are enabled for your account. SmashOne is not responsible for how these independent platforms process personal data under their own policies. Where a platform and SmashOne genuinely determine purposes and means together for a specific activity, that activity is instead governed as joint controllership under Article 26 GDPR; this section covers platforms acting as separate, independent controllers.
Platform (independent controller)
Data shared
Purpose of their processing
Their privacy policy
Facebook — Meta Platforms Ireland Limited
Page and account identifiers, access tokens you authorise, published content, comments and messages exchanged with your audience, engagement metrics
Meta operates Facebook for its own purposes under its own privacy policy, independently of SmashOne
Professional-account identifiers, access tokens you authorise, posts and reels, comments and direct messages exchanged with your audience, engagement metrics
Meta operates Instagram for its own purposes under its own privacy policy, independently of SmashOne
WhatsApp Business — WhatsApp Ireland Limited (Meta)
Business phone-number identifiers, WhatsApp Business account metadata, messages and media exchanged with your audience (when you connect WhatsApp Business to an AI employee)
WhatsApp Ireland Limited operates WhatsApp for its own purposes under its own privacy policy, independently of SmashOne
Business-profile identifiers, access tokens you authorise, posts, offers, photos and review replies you publish, customer questions and answers (when you connect Google Business Profile to an AI employee)
Google operates Google Business Profile for its own purposes under its own privacy policy, independently of SmashOne
These platforms are independent controllers, not SmashOne sub-processors: they are not listed on our Sub-processors page and do not act on our instructions. To exercise data-protection rights against a platform, use the controls and contacts in its own privacy policy linked above.
12
GDPR rights
EU users may request access, deletion, correction, restriction, portability, or objection. Poland data-protection authority reference: UODO. SmashOne does not sell personal information. Send requests to info@smashone.ai.
13
Responding to your requests
We answer data-subject requests within one month of receiving them, free of charge. For complex or numerous requests we may extend this by a further two months, and we will tell you within the first month if we need the extension and why. We may ask you to verify your identity before we act, and if a request is manifestly unfounded or excessive we may charge a reasonable fee or decline, explaining why. Where we rely on your consent, you can withdraw it at any time without affecting processing carried out before withdrawal. SmashOne does not make decisions producing legal or similarly significant effects about you based solely on automated processing. You also have the right to lodge a complaint with the Polish supervisory authority — the Urząd Ochrony Danych Osobowych (UODO) — or with your local EU data-protection authority. To exercise any right, contact info@smashone.ai.
14
Retention
We keep personal data only as long as necessary for the purpose it was collected, then delete or anonymise it. The table below sets out how long we keep each category.
Data category
Retention
Account and profile data
For the life of your account; deleted or anonymised within 90 days after account closure
Content, posts and drafts
For the life of your account; deleted on account deletion
Media generated for you
For the life of your account; deleted on account deletion, or earlier on your request
Connected-platform access tokens
Until you disconnect the platform or close your account; revoked on disconnection
Customer-conversation / CRM data (we process on your instructions)
For the life of your account, or per your documented instructions as controller
Billing, invoices and tax records
Up to 5 years from the end of the relevant financial year, as required by Polish accounting and tax law
Security and audit logs
Up to 12 months, then deleted or anonymised
Support tickets
Up to 24 months after resolution
Server logs
Up to 30 days
Optional analytics data (if enabled)
Aggregated; up to 14 months
Backups
Rolling backups overwritten within a 35-day cycle
On a verified erasure request we delete your data within the response time set out above, except where we must keep specific records to meet a legal obligation (for example billing and tax records).
15
Contact
Privacy requests: info@smashone.ai. Data controller: SmashOne AI Sp. z o.o., Aleja Rzeczypospolitej 6/U19, 02-972 Warsaw, Poland (KRS 0001249992, NIP 9512650941).
Nova · SmashOne assistant
AI answers, humans review
AI answers, humans review. Replies are AI-generated; a human reviews escalations.