Legal document

Privacy Policy

VARDIC – Greenwashing analysis system  |  Version 1.0.0  |  Last updated: 21 July 2026

Unofficial translation. This is an English translation of the VARDIC Privacy Policy provided for convenience. The Polish-language version is the authoritative, legally binding text; in case of any discrepancy, the Polish version prevails. Read the authoritative version: Polityka Prywatności (PL).

1. Who we are and who is the controller of your data

The provider of the VARDIC system

The provider of the VARDIC system is the law firm Kałużna Legal – Roksana Kałużna-Bałazy, an attorney-at-law (adwokat) entered on the roll of advocates kept by the District Bar Council (Okręgowa Rada Adwokacka) in Warsaw under no. WAW/ADW/10396, conducting business under the name "Usługi prawne Roksana Kałużna-Bałazy", NIP: 7471779156, REGON: 387989152 ("Kałużna Legal", "we"). Kałużna Legal is the author of the analytical methodology on which the VARDIC system is based.

Who is the controller of your data

The controller of the personal data processed in connection with the use of the VARDIC system is Kałużna Legal – the law firm run by attorney-at-law (adwokat) Roksana Kałużna-Bałazy. It is Kałużna Legal that decides on the purposes and means of processing your personal data within the meaning of Art. 4(7) GDPR.

The external service providers listed in section 4 (hosting, AI models, error monitoring, analytics, and others) act as processors within the meaning of Art. 4(8) GDPR – they process data solely on the documented instructions of Kałużna Legal, under the data processing agreements concluded with them.

Important: For matters concerning the processing of your personal data and to exercise your rights, contact Kałużna Legal – contact details are in section 10 of this policy.


2. What data we process and where it comes from

In connection with the operation of the VARDIC system, the following categories of data may be processed:

Data category Description Source
User account data First name, surname, e-mail address, organisation name, role in the system Provided by the organisation granting access or by the user at registration
Data entered for analysis The content of communications, marketing materials or reports submitted for analysis by the user Directly from the user
Technical data and logs IP address, session identifier, date and time of login, device and browser data Automatically, during use of the system
System usage data Analysis history, results generated by the system, user queries Generated in the course of using the system

Reminder: Only publicly available communications and marketing materials should be entered for analysis. Do not enter personal data (e.g. names, addresses, national ID numbers) or information constituting a trade secret. See section 8 for more.


3. The purposes and legal bases for processing your data

Purpose of processing Legal basis (GDPR)
Providing the VARDIC service – performing greenwashing analyses Art. 6(1)(b) – performance of the contract for use of the VARDIC system; Art. 6(1)(f) – legitimate interest (provision and improvement of the service)
Managing user accounts and access to the system Art. 6(1)(b) – performance of a contract; Art. 6(1)(f) – legitimate interest
Ensuring system security and detecting abuse Art. 6(1)(f) – the controller's legitimate interest
Complying with legal obligations (including the AI Act and tax regulations) Art. 6(1)(c) – legal obligation
Improving and developing the system (solely in anonymised form) Art. 6(1)(f) – legitimate interest

We do not process users' personal data for marketing purposes, nor do we sell personal data to third parties.


4. Transfer of data to external AI providers

Processing by external language-model providers

The VARDIC system operates on external AI language models (LLMs). This means that the content of communications entered for analysis is sent to external AI model providers in order to generate results. Kałużna Legal carefully selects providers and concludes GDPR-compliant data processing agreements with them.

Current AI model providers

Provider Server location Basis for data transfer
Google Cloud (Vertex AI) European Union / EEA – europe-central2 region (Warsaw) No transfer outside the EEA – processing takes place exclusively within Google infrastructure located in the EU/EEA

The content of communications entered for analysis on the main analysis path (the Vertex AI language model) is processed exclusively within the European Union / European Economic Area (EEA) – the europe-central2 region (Warsaw) – and is not transferred to third countries. Query data is not used to train AI models. Certain ancillary functions use a global Google endpoint; the related transfer outside the EEA is described below (see the paragraph after the processors table).

On-premises processing option

For organisations that require data to be processed solely on their own infrastructure (without sending content to external AI providers), an on-premises configuration is available. In this configuration, no data leaves the client's infrastructure. Contact us to learn more.

Other third parties

Data may also be transferred to:

  • providers of technical infrastructure and hosting (as processors),
  • providers of software supporting system security,
  • public authorities – only where required by applicable law.

Entities processing data on behalf of Kałużna Legal (processors)

Processor Purpose Location
Google Cloud Platform (GCP) Database hosting, file storage (Google Cloud Storage), infrastructure logs EU – europe-central2 (Warsaw)
Google Cloud – Vertex AI (Gemini) Language model – analysis of content submitted for audit and image text recognition (OCR) EU/EEA – europe-central2 (Warsaw)
Google – Gemini Developer API Vector embeddings and certificate verification Google's global endpoint (not EU-only) – possible transfer outside the EEA, safeguarded by Google's Standard Contractual Clauses (SCC) under Art. 46 GDPR
Firebase Authentication (Google) User account authentication (email address, account identifier) Google – the service is not pinned to an EU region by default; possible transfer outside the EEA, safeguarded by Google's Standard Contractual Clauses (SCC) under Art. 46 GDPR
Sentry Application error monitoring EU (Frankfurt) – PII scrubbed before transmission
PostHog Product analytics (no session recording, no autocapture) EU (Frankfurt) – loaded only after the user grants consent in the consent banner (consent management platform)
Langfuse LLM observability (logging of model prompts and responses) EU – Langfuse Cloud (EU region)
Stripe Payments and subscriptions (purchase of analysis credits) Billing data processed under Stripe's data processing agreement (DPA); any transfer outside the EEA is safeguarded by Standard Contractual Clauses (Art. 46 GDPR)
Qdrant Vector database (embeddings of document and knowledge-base content) EU – self-hosted infrastructure (VM on GCP, europe-central2)

Data transfers outside the EEA

The main analysis path (the Vertex AI language model) and image text recognition (OCR) take place exclusively in the EU/EEA region (europe-central2, Warsaw) and do not involve any transfer of data outside the EEA. A transfer outside the EEA may, however, occur for the following ancillary functions and services:

  • vector embeddings and certificate verification – performed via Google's global endpoint (Gemini Developer API),
  • user account authentication (Firebase Authentication), which is not pinned to an EU region by default.

These transfers are safeguarded by the Standard Contractual Clauses (SCC) approved by the European Commission, which constitute appropriate safeguards within the meaning of Art. 46 GDPR. The scope of these functions is limited and ancillary to the main analysis, which remains within the EEA.

Data is not sold or shared with third parties for marketing or commercial purposes.


5. How long we retain data

Data category Retention period
User account data For the duration of your account in the VARDIC system, and thereafter for up to 12 months after it is closed, or until a deletion request is made
Analysis content and results By default 90 days (approx. 3 months) from the date of analysis. After a deletion request is made, data is anonymised and then permanently deleted after 30 days.
Technical data and system logs System logs (GCP Cloud Logging): up to 30 days. Other technical data linked to an analysis: up to 90 days, unless a longer period is required by law.
Data transferred to AI model providers In accordance with the provider's policy (Google) – query data is not used to train models and is not retained beyond the period necessary to fulfil the query and a short abuse-monitoring period
Data for accounting purposes 5 years in accordance with tax law

6. Your rights

As the controller of your personal data, Kałużna Legal ensures that the rights arising under the GDPR can be exercised. You can exercise some of them directly in the VARDIC system (including access to and export of your data, and requesting deletion of your account); for all other matters, contact us using the details in section 10.

You have the following rights:

Right Description
Right of access (Art. 15 GDPR) You can obtain information about which of your data is processed and for what purpose
Right to rectification (Art. 16 GDPR) You can request correction of inaccurate data or completion of incomplete data
Right to erasure (Art. 17 GDPR) You can request deletion of data where there is no basis for its further processing
Right to restriction of processing (Art. 18 GDPR) You can request restriction of processing in the cases specified in the GDPR
Right to data portability (Art. 20 GDPR) You can receive your data in a structured, commonly used format
Right to object (Art. 21 GDPR) You can object to processing based on legitimate interest
Right to lodge a complaint You can lodge a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, www.uodo.gov.pl

The VARDIC system does not make solely automated decisions producing legal effects or similarly significantly affecting users within the meaning of Art. 22 GDPR. All analysis results are subject to mandatory human review.


7. Data security

Kałużna Legal applies appropriate technical and organisational measures to protect the processed data against unauthorised access, loss or destruction, including:

  • encryption of data in transit (TLS/HTTPS),
  • role-based access control,
  • monitoring and logging of access to the system,
  • security incident response procedures,
  • regular system security reviews.

In the event of a personal data breach, Kałużna Legal, as the controller, will report the breach to the supervisory authority (the President of the UODO) without undue delay in accordance with Art. 33 GDPR and – where the breach is likely to result in a high risk to your rights and freedoms – will notify you of the breach in accordance with Art. 34 GDPR.


8. Sensitive data and trade secrets

The VARDIC system is not intended for processing personal data or confidential information. Only publicly available communications and marketing materials should be entered for analysis.

In particular, it is prohibited to enter into the system:

  • personal data – names and surnames, addresses, national ID (PESEL) numbers, contact details, identifying data of natural persons,
  • special categories of data (sensitive data) within the meaning of Art. 9 GDPR – including data on health, political opinions, and biometric data,
  • information constituting a trade secret – business strategies, non-public financial data, confidential information, data covered by non-disclosure agreements (NDAs),
  • data covered by professional secrecy – in particular attorney, legal-adviser or medical confidentiality.

The user is obliged to comply with the above restriction. Where access to the VARDIC system is granted to you by an employer or another organisation, that organisation should additionally implement appropriate organisational measures to prevent such data from being entered into the system.


9. Changes to this privacy policy

Kałużna Legal reserves the right to update this privacy policy, in particular in connection with changes to the law, to guidance from supervisory authorities, or to the functioning of the VARDIC system. We will inform users of material changes at least 14 days in advance. The current version of the policy is always available in the VARDIC system.


10. Contact

For matters relating to this privacy policy or to the processing of your personal data by Kałużna Legal as the controller, please contact:

Kałużna Legal – Usługi prawne Roksana Kałużna-Bałazy

Roksana Kałużna-Bałazy, attorney-at-law (adwokat) – ORA in Warsaw, no. WAW/ADW/10396

ul. Portowa 17/7, 03-197 Warsaw, Poland  |  NIP: 7471779156  |  REGON: 387989152

E-mail: [email protected] / [email protected]

Phone: (+48) 515 539 787