← Trust Center

Legal · Privacy Policy

Privacy Policy

Last updated: 23 September 2026

STAiMP is a brand owned and operated by Xentavi Spółka z ograniczoną odpowiedzialnością. This policy explains how Xentavi handles personal data in connection with STAiMP. Our services are directed at businesses and professionals, not consumers.

1. Who we are

The data controller for this website and related services is:

Xentavi Spółka z ograniczoną odpowiedzialnością
ul. Domaniewska 47/406, 02-672 Warszawa, Poland
KRS 0001258350 · NIP 5214175567 · REGON 545420830
hm@xentavi.com · xentavi.com

2. Our role: controller and processor

For account, billing, contact, and website-usage data, Xentavi acts as the data controller. For personal data that may be contained within content you submit to STAiMP for scanning — for example, if a submitted image depicts an identifiable individual — Xentavi acts as a data processor on your behalf; you remain the controller of that data. If you require a data processing agreement for your own compliance purposes, contact us at hm@xentavi.com.

3. What data we collect and why

We collect only what we need to operate and improve the Service.

Data categoryWhat it includesPurposeLegal basisRetention
Scanned contentFiles or text you submit to STAiMP for AI-detection and provenance analysisPerforming the scan and generating your compliance reportPerformance of contract (Art. 6(1)(b) GDPR); where content includes third-party personal data, processed as a processor on your instructionsDeleted immediately after analysis, unless you create an account and choose to save scan history
Contact / lead dataWork email and details you share via the contact form, demo request, or account signupDelivering the response you requested; product updates only if you opt inLegitimate interest in responding to your request (Art. 6(1)(f)); consent for marketing updates (Art. 6(1)(a))Only as long as needed to handle your request and any resulting relationship; deleted on request
Account dataName, email, billing details, plan tierProviding and billing the ServicePerformance of contract (Art. 6(1)(b))Duration of your account, plus 5 years for financial records (Art. 74, Polish Accounting Act)
Analytics dataPages visited, general usage patterns, device and browser typeUnderstanding usage and improving the ServiceConsent (Art. 6(1)(a)), collected only after you accept analytics cookiesAs configured in the analytics tool; raw events are not kept longer than necessary

We do not collect special-category data (health, ethnicity, biometric data, etc.), and our detection models analyze technical file signals only — STAiMP does not perform facial recognition or biometric identification of any individuals who may appear in submitted content.

4. Cookies

Strictly necessary storage — required for the site to function (sign-in session, your cookie choice, guest scan counter). No consent needed.

Analytics cookies — anonymized usage data via our analytics tooling. Set only after you actively consent through the cookie banner shown on first visit.

You can withdraw consent at any time via or your browser settings. Details: Cookie Policy.

5. Who we share data with

We do not sell your data. We share it only where necessary:

Service providers acting as data processors — hosting, email delivery, CRM, and analytics tools — each bound by a data processing agreement.

AI/LLM providers — to generate scan results and suggested usage guidance, submitted content may be sent via API to third-party AI model providers acting as sub-processors on our instructions. The specific providers are still being finalized; once selected, they will be listed here or made available on request. Each will be bound by a data processing agreement, with advance notice of any new sub-processor and an opportunity to object, consistent with Article 28(2) GDPR.

Professional advisers — accountants and lawyers — where legally required.

Authorities — if required by law or to protect our legal rights.

Where any provider is based outside the European Economic Area — which is likely for at least some AI/LLM providers — we ensure appropriate safeguards such as the European Commission's Standard Contractual Clauses (2021 version), reliance on the EU-U.S. Data Privacy Framework where the provider is certified, and, where applicable, a UK International Data Transfer Addendum.

6. How long we keep your data

Retention periods are set out per data category in the table in Section 3. In general, we keep personal data only as long as necessary for the purpose it was collected for, or as required by law (for example, Polish accounting law requires certain financial records to be kept for 5 years).

7. Your rights

Under GDPR (RODO), you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data, where applicable
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal

To exercise any of these rights, contact us at hm@xentavi.com. We will respond within one month, extendable by a further two months for complex requests, as permitted under GDPR.

If you are located in the EEA, you may also lodge a complaint with your own national supervisory authority, or with Poland's Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa — uodo.gov.pl

If you are located in the United Kingdom, the UK GDPR applies to processing subject to UK jurisdiction, and you may contact the UK Information Commissioner's Office at ico.org.uk.

US State Privacy Rights. If you are a resident of a US state with its own privacy law (for example, California, Colorado, Connecticut, Virginia, or Utah), you may have rights to know, access, delete, or correct your personal data, and to opt out of its sale or sharing. We do not sell or share personal data as those terms are defined under such laws. To exercise these rights, contact hm@xentavi.com; we will not discriminate against you for exercising them.

8. Data security

We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, or loss, including encryption of data in transit, access controls limiting who at Xentavi can view submitted content, and prompt deletion of scanned content after analysis.

9. International transfers

Where we or our processors transfer personal data outside the European Economic Area, we rely on adequacy decisions or Standard Contractual Clauses, and impose contractual safeguards on the receiving party.

10. Changes to this policy

We may update this policy as our services evolve. Material changes will be communicated by posting an updated version with a new "Last updated" date, and by email where you have an account with us.

11. Contact

Questions about this policy or how we handle your data: hm@xentavi.com