Privacy Policy
Last updated: 23 September 2026
STAiMP is a brand owned and operated by Xentavi Spółka z ograniczoną odpowiedzialnością. This policy explains how Xentavi handles personal data in connection with STAiMP. Our services are directed at businesses and professionals, not consumers.
1. Who we are
The data controller for this website and related services is:
Xentavi Spółka z ograniczoną odpowiedzialnością
ul. Domaniewska 47/406, 02-672 Warszawa, Poland
KRS 0001258350 · NIP 5214175567 · REGON 545420830
hm@xentavi.com · xentavi.com
2. Our role: controller and processor
For account, billing, contact, and website-usage data, Xentavi acts as the data controller. For personal data that may be contained within content you submit to STAiMP for scanning — for example, if a submitted image depicts an identifiable individual — Xentavi acts as a data processor on your behalf; you remain the controller of that data. If you require a data processing agreement for your own compliance purposes, contact us at hm@xentavi.com.
3. What data we collect and why
We collect only what we need to operate and improve the Service.
| Data category | What it includes | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Scanned content | Files or text you submit to STAiMP for AI-detection and provenance analysis | Performing the scan and generating your compliance report | Performance of contract (Art. 6(1)(b) GDPR); where content includes third-party personal data, processed as a processor on your instructions | Deleted immediately after analysis, unless you create an account and choose to save scan history |
| Contact / lead data | Work email and details you share via the contact form, demo request, or account signup | Delivering the response you requested; product updates only if you opt in | Legitimate interest in responding to your request (Art. 6(1)(f)); consent for marketing updates (Art. 6(1)(a)) | Only as long as needed to handle your request and any resulting relationship; deleted on request |
| Account data | Name, email, billing details, plan tier | Providing and billing the Service | Performance of contract (Art. 6(1)(b)) | Duration of your account, plus 5 years for financial records (Art. 74, Polish Accounting Act) |
| Analytics data | Pages visited, general usage patterns, device and browser type | Understanding usage and improving the Service | Consent (Art. 6(1)(a)), collected only after you accept analytics cookies | As configured in the analytics tool; raw events are not kept longer than necessary |
We do not collect special-category data (health, ethnicity, biometric data, etc.), and our detection models analyze technical file signals only — STAiMP does not perform facial recognition or biometric identification of any individuals who may appear in submitted content.
4. Cookies
Strictly necessary storage — required for the site to function (sign-in session, your cookie choice, guest scan counter). No consent needed.
Analytics cookies — anonymized usage data via our analytics tooling. Set only after you actively consent through the cookie banner shown on first visit.
You can withdraw consent at any time via or your browser settings. Details: Cookie Policy.
5. Who we share data with
We do not sell your data. We share it only where necessary:
Service providers acting as data processors — hosting, email delivery, CRM, and analytics tools — each bound by a data processing agreement.
AI/LLM providers — to generate scan results and suggested usage guidance, submitted content may be sent via API to third-party AI model providers acting as sub-processors on our instructions. The specific providers are still being finalized; once selected, they will be listed here or made available on request. Each will be bound by a data processing agreement, with advance notice of any new sub-processor and an opportunity to object, consistent with Article 28(2) GDPR.
Professional advisers — accountants and lawyers — where legally required.
Authorities — if required by law or to protect our legal rights.
Where any provider is based outside the European Economic Area — which is likely for at least some AI/LLM providers — we ensure appropriate safeguards such as the European Commission's Standard Contractual Clauses (2021 version), reliance on the EU-U.S. Data Privacy Framework where the provider is certified, and, where applicable, a UK International Data Transfer Addendum.
6. How long we keep your data
Retention periods are set out per data category in the table in Section 3. In general, we keep personal data only as long as necessary for the purpose it was collected for, or as required by law (for example, Polish accounting law requires certain financial records to be kept for 5 years).
7. Your rights
Under GDPR (RODO), you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data, where applicable
- Restrict or object to processing
- Data portability
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal
To exercise any of these rights, contact us at hm@xentavi.com. We will respond within one month, extendable by a further two months for complex requests, as permitted under GDPR.
If you are located in the EEA, you may also lodge a complaint with your own national supervisory authority, or with Poland's Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa — uodo.gov.pl
If you are located in the United Kingdom, the UK GDPR applies to processing subject to UK jurisdiction, and you may contact the UK Information Commissioner's Office at ico.org.uk.
US State Privacy Rights. If you are a resident of a US state with its own privacy law (for example, California, Colorado, Connecticut, Virginia, or Utah), you may have rights to know, access, delete, or correct your personal data, and to opt out of its sale or sharing. We do not sell or share personal data as those terms are defined under such laws. To exercise these rights, contact hm@xentavi.com; we will not discriminate against you for exercising them.
8. Data security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, or loss, including encryption of data in transit, access controls limiting who at Xentavi can view submitted content, and prompt deletion of scanned content after analysis.
9. International transfers
Where we or our processors transfer personal data outside the European Economic Area, we rely on adequacy decisions or Standard Contractual Clauses, and impose contractual safeguards on the receiving party.
10. Changes to this policy
We may update this policy as our services evolve. Material changes will be communicated by posting an updated version with a new "Last updated" date, and by email where you have an account with us.
11. Contact
Questions about this policy or how we handle your data: hm@xentavi.com