Opening 1 September

The roster is hiring from day one.

See what’s included
Legal · Privacy

Privacy Policy

Last updated: 18 July 2026

Your privacy at SmashOne

How we collect, use, and protect your data under the GDPR.

01

Controller

The data controller is SmashOne AI Sp. z o.o., Aleja Rzeczypospolitej 6/U19, 02-972 Warsaw, Poland (KRS 0001249992, NIP 9512650941). The supervisory authority is the President of the Personal Data Protection Office (UODO), Warsaw, Poland. This Privacy Policy applies to the smashone.ai European public surface.

02

Scope

This policy covers the information you give us when you create an account, the information collected when you use SmashOne, and the information received from the social media platforms you choose to connect: Facebook, Instagram, Telegram, WhatsApp Business, and Google Business Profile, each once that channel is enabled for your account.

03

Connected channels

We process data from a channel only when you connect that channel to an AI employee, it is enabled for your account, and the connected third-party platform provides the data needed for the feature. Charges for a channel start on Day 15 after the 14-day free trial unless the checkout says otherwise. If a channel is unavailable, withdrawn, or removed for platform access, legal, safety, or policy reasons, we stop collecting new data from that removed channel where technically possible, stop future charges for that removed channel, and keep our customer-facing availability statements aligned with UCPD rules against misleading commercial claims.

04

Data we collect

We collect account details, business profile information, connected platform metadata, catalog items, scheduled content, messages, billing records, support communications, security logs, and product usage events needed to operate the service. Catalog items may include photographs and other media you upload. Where those photographs show identifiable people — for example your staff, models or customers — they are personal data of those people, and you remain the controller for them.

05

How we use data

We use data to provide publishing, messaging, AI assistant, analytics, billing, security, support, product improvement, abuse prevention, and legal compliance.

06

Legal bases (GDPR Article 6)

We process personal data only where we have a legal basis under Article 6 GDPR. The table below maps our main purposes to their legal basis.

PurposeData categoriesLegal basis (Art. 6 GDPR)
Providing the service (publishing, messaging, scheduling, catalog, AI assistant)Account, content, connected-platform dataPerformance of a contract — Art. 6(1)(b)
AI assistant replying to your customers on your behalfCustomer-conversation content (we act as processor for you)Performance of a contract — Art. 6(1)(b)
Billing, setup fee, payments and invoicingBilling and transaction dataContract — Art. 6(1)(b); and legal obligation for accounting/tax records — Art. 6(1)(c)
Security, fraud and abuse prevention, audit loggingAccount, usage, device/IP dataLegitimate interests — Art. 6(1)(f) (keeping the service and accounts secure)
SupportContact and ticket dataContract — Art. 6(1)(b) and legitimate interests — Art. 6(1)(f)
Product improvement and service analyticsUsage data (aggregated where possible)Legitimate interests — Art. 6(1)(f)
Optional analytics or marketing cookies (only if you enable them)Cookie and usage dataConsent — Art. 6(1)(a)
Legal compliance (responding to lawful requests, DSA notices, record-keeping)As requiredLegal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, we balance our interest against your rights and only proceed where your interests do not override ours; you may object at any time. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.

07

Social platform data

Connected social account data is used only to deliver requested publishing, messaging, analytics, and AI assistant features. We do not sell personal information.

08

AI processing of your content

The assistant uses your business profile, FAQ, catalog, connected platform messages, and configured tone to draft answers. Sensitive or off-script items can be escalated for human review. AI employees also generate content for you: post text and images produced from the photographs in your catalog. Generated media is created on your instructions, stored with your other content, and published only to the channels you have connected.

09

Service providers

We use service providers for hosting, analytics, payments, communications, monitoring, and AI processing. They process data only for the service purposes we authorize.

10

Sub-processors and international transfers

We use the following sub-processors to operate the service: Hetzner Online GmbH (Germany) for EU application hosting and compute; DigitalOcean, LLC (Frankfurt, Germany) for managed PostgreSQL, Valkey cache, and object storage including backups; Stripe Payments Europe, Ltd. (Ireland), with Stripe, Inc. group affiliates in the United States, for payment processing; Brevo (Sendinblue SAS, France) for transactional email; Google Workspace (Gmail) for inbound email processing at info@smashone.ai; Google LLC (Vertex AI) for AI processing — assistant replies and generated content, including text and images — currently configured with a global processing location; Cloudflare, Inc. for DNS, CDN, WAF, and TLS edge security; Sentry (Functional Software, Inc.) for error monitoring with PII minimisation; PostHog (EU Cloud) for pseudonymous server-side product analytics; and ScrapingBee SAS (France) to retrieve your public business website for the assistant’s knowledge base. Where a sub-processor is US-incorporated or processes data outside the EEA (DigitalOcean, Stripe, Google, Cloudflare, Sentry, PostHog), transfers rely on the EU-US Data Privacy Framework adequacy decision where applicable or Standard Contractual Clauses with supplementary safeguards. The current list, with regions and dates, is maintained on our Sub-processors page; we notify customers at least 30 days before adding a new sub-processor.

11

Connected social platforms as independent controllers

When you connect a social platform to SmashOne, that platform processes personal data as an independent controller under GDPR Articles 13 and 14 — not as a SmashOne sub-processor. This is different from the sub-processors above: those process personal data only on SmashOne’s documented instructions under Article 28 GDPR, while a connected social platform decides how it processes personal data on its own platform, for its own purposes, under its own privacy policy. We disclose the platforms below as recipients and independent controllers so you know who receives your data and can read their policies before you connect. The platforms listed below exchange data with SmashOne only for the channels you have connected and that are enabled for your account. SmashOne is not responsible for how these independent platforms process personal data under their own policies. Where a platform and SmashOne genuinely determine purposes and means together for a specific activity, that activity is instead governed as joint controllership under Article 26 GDPR; this section covers platforms acting as separate, independent controllers.

Platform (independent controller)Data sharedPurpose of their processingTheir privacy policy
Facebook — Meta Platforms Ireland LimitedPage and account identifiers, access tokens you authorise, published content, comments and messages exchanged with your audience, engagement metricsMeta operates Facebook for its own purposes under its own privacy policy, independently of SmashOnewww.facebook.com/privacy/policy
Instagram — Meta Platforms Ireland LimitedProfessional-account identifiers, access tokens you authorise, posts and reels, comments and direct messages exchanged with your audience, engagement metricsMeta operates Instagram for its own purposes under its own privacy policy, independently of SmashOneprivacycenter.instagram.com/policy
Telegram — Telegram FZ-LLC (United Arab Emirates)Channel and bot identifiers, messages and attachments exchanged with your audience, Telegram user id and username, timestampsTelegram operates its messaging platform for its own purposes under its own privacy policy, independently of SmashOnetelegram.org/privacy
WhatsApp Business — WhatsApp Ireland Limited (Meta)Business phone-number identifiers, WhatsApp Business account metadata, messages and media exchanged with your audience (when you connect WhatsApp Business to an AI employee)WhatsApp Ireland Limited operates WhatsApp for its own purposes under its own privacy policy, independently of SmashOnewww.whatsapp.com/legal/privacy-policy
Google Business Profile — Google Ireland LimitedBusiness-profile identifiers, access tokens you authorise, posts, offers, photos and review replies you publish, customer questions and answers (when you connect Google Business Profile to an AI employee)Google operates Google Business Profile for its own purposes under its own privacy policy, independently of SmashOnepolicies.google.com/privacy

These platforms are independent controllers, not SmashOne sub-processors: they are not listed on our Sub-processors page and do not act on our instructions. To exercise data-protection rights against a platform, use the controls and contacts in its own privacy policy linked above.

12

GDPR rights

EU users may request access, deletion, correction, restriction, portability, or objection. Poland data-protection authority reference: UODO. SmashOne does not sell personal information. Send requests to info@smashone.ai.

13

Responding to your requests

We answer data-subject requests within one month of receiving them, free of charge. For complex or numerous requests we may extend this by a further two months, and we will tell you within the first month if we need the extension and why. We may ask you to verify your identity before we act, and if a request is manifestly unfounded or excessive we may charge a reasonable fee or decline, explaining why. Where we rely on your consent, you can withdraw it at any time without affecting processing carried out before withdrawal. SmashOne does not make decisions producing legal or similarly significant effects about you based solely on automated processing. You also have the right to lodge a complaint with the Polish supervisory authority — the Urząd Ochrony Danych Osobowych (UODO) — or with your local EU data-protection authority. To exercise any right, contact info@smashone.ai.

14

Retention

We keep personal data only as long as necessary for the purpose it was collected, then delete or anonymise it. The table below sets out how long we keep each category.

Data categoryRetention
Account and profile dataFor the life of your account; deleted or anonymised within 90 days after account closure
Content, posts and draftsFor the life of your account; deleted on account deletion
Media generated for youFor the life of your account; deleted on account deletion, or earlier on your request
Connected-platform access tokensUntil you disconnect the platform or close your account; revoked on disconnection
Customer-conversation / CRM data (we process on your instructions)For the life of your account, or per your documented instructions as controller
Billing, invoices and tax recordsUp to 5 years from the end of the relevant financial year, as required by Polish accounting and tax law
Security and audit logsUp to 12 months, then deleted or anonymised
Support ticketsUp to 24 months after resolution
Server logsUp to 30 days
Optional analytics data (if enabled)Aggregated; up to 14 months
BackupsRolling backups overwritten within a 35-day cycle

On a verified erasure request we delete your data within the response time set out above, except where we must keep specific records to meet a legal obligation (for example billing and tax records).

15

Contact

Privacy requests: info@smashone.ai. Data controller: SmashOne AI Sp. z o.o., Aleja Rzeczypospolitej 6/U19, 02-972 Warsaw, Poland (KRS 0001249992, NIP 9512650941).