1. Controller and processing roles
The controller is Dragan Atanasov, NIP PL6762491554, REGON 362195598, registered at Rakowicka 10b/4, 31-511 Kraków, Lesser Poland Voivodeship, Poland. Contact: hello@mosaicora.io.
We act as controller for account, billing, usage, security, and support data. When a customer directs us to process personal data contained in webpages, templates, or other Customer Content, the customer is generally the controller and we act as processor. Our Data Processing Agreement applies to that processing.
2. Personal data we collect
- Account data: name, email, identifiers, workspace membership, preferences, authentication records, and account status.
- Order and billing data: plan, subscription status, billing contact, address, tax details, transaction identifiers, amounts, refunds, and payment status.
- Customer Content: URLs, webpage metadata, screenshots, selected page elements, text, images, templates, brand settings, and generated assets.
- Technical and usage data: IP address, browser and device information, API activity, timestamps, approximate region, logs, diagnostics, and security events.
- Communications: support messages, attachments, feedback, and records of our correspondence.
- Consent and analytics: your analytics choice and, after consent, page views and product interactions.
We do not intentionally receive or store a full payment-card number or card security code. Link and Stripe collect payment credentials directly.
3. Where personal data comes from
We receive data directly from you, your organization’s account administrator, your use of the Service, Link or Stripe for purchases, and providers that help us operate the Service. When you submit a URL, we may retrieve public webpage content and metadata, which can contain information about authors, employees, customers, or other people. The customer submitting that URL is responsible for having the right and lawful basis to request that processing.
4. Purposes and legal bases
- Contract: create accounts, generate and deliver images, apply plan limits, manage subscriptions, and provide support.
- Legitimate interests: secure, monitor, debug, and improve the Service, prevent abuse and fraud, and maintain proportionate business records.
- Legal obligations: keep required accounting and tax records, respond to lawful requests, and establish or defend legal claims.
- Consent: optional analytics and marketing communications where consent is required. Consent can be withdrawn at any time.
5. Managed Payments by Stripe and Link
Eligible purchases may be provided as Sold through Link using Stripe Managed Payments. Sold through Link LLC acts as merchant of record for eligible transactions and independently processes data for checkout, payment collection, applicable indirect tax, fraud prevention, receipts, order management, disputes, refunds, and transaction-level support. Stripe may share contact, billing, tax, order, subscription, and transaction information with us to provision and support your account. Mosaicora remains responsible for operating and supporting the product.
See the Stripe Privacy Policy. Deleting a Link account may cancel subscriptions sold through Link. Contact both Stripe and us when you want each organization to address data it controls independently.
6. Recipients and subprocessors
We disclose personal data only as needed to provide the Service, including to payment, content-delivery, security, analytics, error-monitoring, transactional-email, and professional-service providers, and to authorities where legally required. We do not sell personal data.
Our Subprocessor List names current external providers and explains how to receive material-change notices.
7. International transfers
Some providers process data outside the European Economic Area. Where required, we use an adequacy decision, the EU-US Data Privacy Framework, the European Commission’s Standard Contractual Clauses, the UK Addendum, or another recognized safeguard.
8. Retention and deletion
- Account data and Customer Content are kept while the account is active. After a verified deletion request, active data is deleted or anonymized within 30 days, with residual copies removed through normal backup rotation.
- Security, access, and diagnostic logs are normally retained for up to 90 days.
- Consented product analytics are normally retained for up to 12 months.
- Financial and transaction records are retained for the statutory Polish tax and accounting period, generally five years calculated under applicable law.
- Support records are retained while the request is active and afterward only as needed for security, service history, or legal claims.
Email hello@mosaicora.io to request account closure or deletion. We verify the requester’s identity, address active billing where requested, delete eligible account data within 30 days, and retain only records required by law.
9. Security
We use measures designed to protect personal data, including access controls, encrypted transport, credential protection, logging, monitoring, backups, and restricted production access where appropriate. No online service can guarantee absolute security. Report suspected security issues to support@mosaicora.io.
11. Automated decision-making
We do not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects. Automated security and abuse checks may temporarily limit activity. You may contact support for review.
12. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing.
Send requests to hello@mosaicora.io. We may verify your identity and normally respond within one month. You may complain to the Polish Personal Data Protection Office (UODO) or another competent supervisory authority.
13. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data. Contact us if you believe a child has provided data to us.
14. Changes and contact
We may update this policy as the Service or law changes. We will post the new version, update the date above, and provide additional notice for material changes where appropriate.
Privacy questions and requests: hello@mosaicora.io.