Data Controller
The data controller of your personal data is AI Estimo Software sp. z o.o. (limited liability company), registered in Lublin, ul. Gospodarcza 26, 20-213 Lublin, Poland, entered into the registry of entrepreneurs held by the District Court Lublin-WschĂłd in Lublin with seat in Ĺšwidnik, VI Commercial Department, under registry no. (KRS) 0000778324, tax id. no. (NIP): 9462687496.
If you have any questions regarding this Privacy Policy or our use of your personal data, cookies or similar technologies, or in any other matter related to your personal data, please contact us by email at contact@apropo.io. For safety reasons we may need to authenticate your identity before fulfilling your request.
Personal data and privacy
In principle we only collect and process personal data that you provide to us. When you intend to use Apropo, you will have to register an account with us. When doing so, you will be asked to provide personal data, such as your first and last name, your email address or billing details (in particular billing address, tax id. no., other related data). This data is necessary for us to provide you with Apropo services. From time to time you may also be asked to provide additional data when interacting with Apropo or contacting customer service, as necessary under the circumstances to provide you with our services.
However, we also collect and process other data and personal information, such as the Internet protocol (IP) address used to connect to Apropo, location of your device or computer, and your activity on Apropo.
We also process personal data of persons representing our customers and potential customers, their employees (regardless of the legal nature of cooperation) or persons designated as contact persons. If you have not provided your personal data yourself, the source of your personal data may be your employer, supervisor, contractor or publicly available information. We process such data for performance of our obligations, provision of services, billing purpose, business communication and direct marketing. For these reasons, we usually process data such as name, surname, email address, telephone number, position, company name and sometimes other personal data provided to us or available in public registers.
We obtain some data by inference from publicly available sources. In this regard we cooperate with Open Rate: https://www.openrate.eu/.
Purpose of the processing for which the personal data are intended
Subject to the way you use Apropo, we use your personal information:
- to provide, improve and personalize our services;
- for marketing, direct marketing & newsletter, remarketing;
- for verification of identity and customer support;
- for billing and collections;
- to secure our systems and prevent fraud;
- to analyze and understand our users, improve and optimize Apropo (including our UI experience and our AI system).
Legal basis for the processing
Subject to the personal data concerned and context, our legal basis for processing of your personal data will be:
- Art. 6 sec. 1 point (b) of the GDPR Regulation – processing is necessary for conclusion and performance of a contract for use of Apropo.
- Art. 6 sec. 1 point (c) of the GDPR Regulation – processing is necessary for compliance with regulatory duties, including accounting and taxation.
- Art. 6 sec. 1 point (a) of the GDPR Regulation – your consent.
- Art. 6 sec. 1 point (f) of the GDPR Regulation – processing is necessary for the purposes of our legitimate interests and it is not overridden by your data protection interests or fundamental rights and freedoms: (i) to assess, verify, pursue or protect against legal claims, (ii) to conduct direct marketing, (iii) for analytical or statistical purposes to enhance Apropo, (iv) for client satisfaction survey.
Miscellaneous
All data provided in the course of registration of an account is obligatory for use of Apropo. Data provided in the course of setting up a paid plan is obligatory for use of such plan and for billing. All other data is provided voluntarily.
Depending on the data and the context, if you refuse to provide data: you may not be able to use Apropo, may not be able to use certain features of Apropo, may not be able to use the paid version of Apropo, or may not receive information about our promotions, special or personalized offers.
We use Amazon Web Services (AWS) to store your data. As a result, your personal data may be transferred outside the EU and the European Economic Area, to countries where AWS physically locates its servers or where AWS employees are located, in particular the USA. We rely on standard contractual clauses included in the AWS Data Processing Addendum (part of AWS terms of service) to ensure that your data is processed in compliance with the GDPR Regulation. More information: https://aws.amazon.com/service-terms/ and https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf.
Period of processing
We will process your data only for as long as necessary to ensure continued use of Apropo, as may be required by law, or until we have the legal basis to do so, depending on the type of your personal data and the context, until the later of the following events:
For example, we retain your projects history so that you can always compare or use your previous quoting proposals. We store your payment history as required by applicable tax regulations.
- lapse of a regulatory duty, including taxation, accounting, corporate reporting obligation, under which we are obligated to process your personal data;
- lapse of our need to assess, verify, pursue or protect against legal claims;
- you withdraw your consent, provided it was the basis for the processing;
- you object to the processing of your data, provided that the legal basis for the processing was our legitimate interest.
Data Security
When processing your personal data we use organizational and technical measures to ensure protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, such as by use of Secure Sockets Layer (SSL) encryption software, by engaging licensed payment procesors, by maintaining physical and electronic safeguards and requiring secure passwords.
It is vital that you keep your account login information (login details and password) confidential and secure, as they may be used to access the personal data included in your account.
What are your rights?
You are entitled to:
- to access your personal data, have it rectified or erased;
- to demand restriction of processing of your personal data;
- to demand transfer of your personal data (data portability);
- when the processing of your personal data is based on your consent, to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal;
- to object to the processing of your personal data on grounds relating to your particular situation when processing is based on our legitimate interest. In particular, you are entitled to object to the processing of your personal data for direct marketing. You can also always unsubscribe from our marketing mailing.
Feel free to contact us at any time whenever you have any question or concern regarding the processing of your personal data and applicable rights. You are also entitled to lodge a complaint with a supervisory data protection authority. Find your authority here: https://edpb.europa.eu/about-edpb/board/members_en.
If you received a quoting proposal from Apropo user
Please read this information carefully if you received a link to a quoting proposal created in Apropo.
We do not require you to provide any kind of personal data to review, copy or share a quoting proposal created in Apropo. However, whenever you click on the link to the proposal and review it in your browser, Apropo system will automatically try to analyze and process (record) your mouse movement and screen settings to assess how much time you spent on each component of the quoting proposal. We collect and process such information on behalf of our registered user (who in this case is your data controller), to fulfill our contractual obligations and provide Apropo services to our registered users.
The data is shared with a user responsible for the particular project that the quoting proposal you received relates to (usually the user who sent you the proposal), along with his supervisors (employer / manager), who will be able to watch the video of your interaction with the proposal received. We will keep the data for 12 months, after which it will be deleted. The data may be deleted earlier by users managing the project that the proposal relates to.
Also, we may store and process certain personal data of yours (such as your name or email address) provided to us by an Apropo user who contacted you with the quoting proposal. The data is shared with us in the process of creating and managing the project and sharing of the quoting proposal and we process it only for the purpose of providing our services.
Please note that all information included in this Privacy Policy, in particular information on Cookies, applies to you accordingly. Please write us an email if you have any questions at contact@apropo.io.
External services/recipients of data
We employ external service providers to perform functions on our behalf. These third-party entities may have access to your personal data and other data needed to perform their functions, but may not use it for other purposes. They must process personal information in accordance with this Privacy Notice and comply with all applicable data protection laws, including the GDPR Regulation.
We use Google Analytics to collect and process data. Please refer to “How Google uses data when you use our partners’ sites or apps”: https://policies.google.com/technologies/partner-sites. Please note that Google may transfer your data outside the EU or European Economic Area. We rely on standard contractual clauses included in Google’s privacy policy to ensure that your data is processed in compliance with the GDPR Regulation. More information: https://policies.google.com/privacy, https://policies.google.com/technologies/partner-sites, https://privacy.google.com/businesses/adsservices/, and ad personalisation opt-out: https://support.google.com/ads/answer/2662922?hl=en-GB.
- Payment procesors – to the extent necessary to process payment for our services;
- Lawyers – to the extent necessary to advise us in relation to the functioning of Apropo, assessment, preparation, pursuit or protection of legal claims and general compliance with applicable regulatory duties;
- Accountants – to the extent necessary to comply with tax, accounting and corporate obligations;
- Public administration bodies – to the extent required by laws;
- Marketing, advertising, communications, security, infrastructure and IT service providers – to customize, personalize and optimize our service, process customer surveys, analyze how our users interact with Apropo and display personalized ads in retargeting (remarketing) campaigns.