Privacy Policy

Version 1.0 | Effective Date: March 12, 2026

1. Introduction

This Privacy Policy sets out the rules for the processing and protection of personal data in connection with the use of the BetterCX platform available at https://app.bettercx.ai/ (hereinafter: the “Platform” or the “System”).

This Policy has been prepared in accordance with applicable legislation, in particular:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (hereinafter: the “GDPR”);
  • the Act of 10 May 2018 on the Protection of Personal Data;
  • the Act of 18 July 2002 on the Provision of Electronic Services;
  • the Act of 16 July 2004 – Telecommunications Law;
  • Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act);
  • other applicable provisions of Polish and EU law.

2. Data Controller

The controller of personal data processed in connection with the operation of the Platform is:

AppWave Sp. z o.o. with its registered office in Łódź (address: ul. Kolumny 147E/1, 93-611 Łódź), entered into the Register of Entrepreneurs of the National Court Register under KRS number: 0001193213, NIP: 9820394623, REGON: 542683999 (hereinafter: the “Controller”).

Contact for data protection matters:

[email protected]

3. Definitions

  • Platform – the BetterCX web application available at https://app.bettercx.ai/, used for the automation of client communication using artificial intelligence.
  • User – an entity (entrepreneur or their employee) that has registered an account on the Platform and uses its functionalities.
  • End User – a natural person (a client of the User) whose personal data is processed via the Platform as part of communication conducted by the User.
  • AI / Artificial Intelligence – a system based on language models provided by OpenAI, used within the Platform for text analysis, response generation and communication automation.
  • Personal Data – any information relating to an identified or identifiable natural person within the meaning of Article 4(1) of the GDPR.

4. Roles in Personal Data Processing

4.1. Data Controller

AppWave Sp. z o.o. acts as the controller of personal data of the Platform’s Users, i.e. persons who register an account, use the Platform’s functionalities, make payments, and contact the Controller.

4.2. Data Processor

With respect to the personal data of End Users (clients of our Users), AppWave Sp. z o.o. acts as a data processor within the meaning of Article 28 of the GDPR. The controller of such data is the Platform’s User, who independently determines the purposes and means of processing their clients’ data.

The processing of End Users’ data is carried out on the basis of a Data Processing Agreement (DPA) concluded between AppWave Sp. z o.o. and the User.

5. Categories and Scope of Processed Personal Data

5.1. Data of Platform Users

In connection with registration and use of the Platform, we process the following User data:

  • first and last name;
  • email address;
  • password (in encrypted form);
  • phone number (required for account activation – SMS code verification);
  • billing data (in connection with payment processing via Stripe);
  • data relating to account configuration and AI system settings;
  • Platform activity logs.

5.2. Data of End Users

The Platform may process End User data, the scope of which depends on the AI system configuration made by the User. This may include in particular:

  • first and last name;
  • email address;
  • phone number;
  • content of correspondence (email, chat, social media messages);
  • other data voluntarily provided during communication with the AI system (e.g. outstanding balance, order number, preferences – depending on the User’s configuration).

The scope of End Users’ data is determined by the User (the controller of such data).

The Platform Controller has no control over what data the End User provides during communication with the AI system.

6. Purposes and Legal Bases for Data Processing

Purpose of ProcessingData ScopeLegal Basis
Registration and maintenance of a User accountName, surname, email, phone, password (encrypted)Article 6(1)(b) GDPR (performance of a contract)
Identity verification (SMS)Phone numberArticle 6(1)(b) GDPR
Provision of Platform services – processing of End Users’ dataData as defined by the User’s configurationArticle 6(1)(b) GDPR; Article 28 GDPR (data processing agreement)
Payment processing (Stripe / Stripe Connect)Billing data, email, transaction identifierArticle 6(1)(b) GDPR; Article 6(1)(c) GDPR
SMS notifications about potential clientsUser’s phone numberArticle 6(1)(a) GDPR (consent) or (f)
Security and continuity of Platform operationLogs, technical data, IPArticle 6(1)(f) GDPR
Handling correspondence and enquiriesName, email, message contentArticle 6(1)(f) GDPR
Legal obligations (accounting, taxes)Billing dataArticle 6(1)(c) GDPR
Direct marketingName, emailArticle 6(1)(a) or (f) GDPR

7. Data Processing Using Artificial Intelligence

7.1. General Information

The BetterCX Platform utilises artificial intelligence models provided by OpenAI (OpenAI, L.L.C., San Francisco, USA) via the API interface. The AI system is used for:

  • analysis of incoming message content (email, chat, social media);
  • automatic generation and sending of responses;
  • collection of personal data provided by End Users during conversations;
  • servicing Users’ clients on websites, in chats and via messaging services.

7.2. Principles of Data Processing by OpenAI

Data transmitted to OpenAI via the API is processed in accordance with the following principles declared by OpenAI:

  • OpenAI does not use data submitted via the API to train its AI models (by default);
  • input and output data is retained in OpenAI’s logs for up to 30 days for the purpose of abuse monitoring, after which it is automatically deleted;
  • data is encrypted at rest (AES-256) and in transit (TLS 1.2+);
  • OpenAI holds SOC 2 Type 2 certification;
  • OpenAI is a certified participant in the EU-US Data Privacy Framework.

Detailed information on OpenAI’s data protection policy: https://openai.com/business-data/ | https://developers.openai.com/api/docs/guides/your-data/ | https://openai.com/policies/

7.3. Automated Decision-Making and Profiling

The AI system automatically analyses message content for the purpose of generating responses and collecting data. However, this does not constitute automated decision-making producing legal effects or similarly significantly affecting the individuals concerned, within the meaning of Article 22 of the GDPR. The AI system serves as a tool supporting communication, and the User retains full control over the configuration and content of responses generated by the AI.

The End User has the right to obtain human intervention from the User (the controller of their data), to express their point of view, and to contest a decision based solely on automated processing.

7.4. Information Obligations Under the AI Act

In accordance with Regulation (EU) 2024/1689 (AI Act), we hereby inform that:

  • the Platform utilises an artificial intelligence system based on large language models (LLMs) provided by OpenAI;
  • content generated by the AI may not be fully accurate – Users should verify key information;
  • End Users communicating via the chat, email or messaging services operated by the Platform should be informed that they are communicating with an AI system;
  • the Platform’s User is responsible for ensuring that AI-driven communication is properly labelled to their clients.

8. Data Recipients and Processors

For the purpose of providing Platform services, personal data may be disclosed to the following categories of recipients:

8.1. AI Service Provider

OpenAI, L.L.C. (San Francisco, USA) – data processing via the API for the purpose of text analysis and response generation. Data transfer to the USA is carried out on the basis of the EU-US Data Privacy Framework and Standard Contractual Clauses (SCCs).

8.2. Infrastructure and Hosting

Amazon Web Services (AWS) – servers located in Europe (EU region) on which Platform data and the User database are stored.

8.3. Payment Processing

Stripe, Inc. (USA / Ireland) – processing of payments, including under the Stripe Connect model allowing for the collection of prepayments on behalf of Users in connection with calendar bookings.

Stripe acts as an independent data controller with respect to the execution of payment transactions. Payment data (card data) is processed directly by Stripe – the Platform Controller does not have access to it.

8.4. Integrations with External Platforms

The Platform enables integration with the following external services:

  • Email: Microsoft Outlook, Gmail (Google), own SMTP/IMAP mailboxes;
  • Social media and messaging: Instagram, WhatsApp, Facebook Messenger (Meta Platforms);
  • E-commerce platforms: Shopify, WooCommerce, PrestaShop;
  • Calendars: Google Calendar, Outlook Calendar;

As part of the integration, the System reads incoming messages, automatically generates responses, and may send them on behalf of the User.

8.5. Other Data Recipients

  • entities providing legal and advisory services;
  • entities providing accounting and bookkeeping services;
  • public authorities – exclusively to the extent required by applicable law.

9. Transfer of Data to Third Countries

Data processed in connection with the use of the Platform is stored on AWS servers located within the European Economic Area (EEA).

In connection with the use of OpenAI and Stripe services, data may be transferred to the United States. Such transfer is carried out on the basis of:

  • Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 establishing an adequate level of protection of personal data under the EU-US Data Privacy Framework;
  • Standard Contractual Clauses approved by the European Commission (SCCs).

The current certification status of entities under the DPF: https://www.dataprivacyframework.gov/s/participant-search

As part of integrations with Meta, Google and Microsoft platforms, data may also be transferred to the USA on analogous legal bases.

10. Data Security

The Controller applies appropriate technical and organisational measures:

  • encryption of data in transit (TLS 1.2+) and at rest;
  • storage of passwords exclusively in encrypted (hashed) form;
  • hosting on AWS servers in the EEA with ISO 27001 and SOC 2 certification;
  • access control based on the principle of least privilege;
  • regular security reviews and log monitoring;
  • securing data transmission to OpenAI (AES-256 encryption at rest, TLS 1.2+ in transit).

11. Data Retention Period

  • User account data: for the duration of the contract, and subsequently for the limitation period for claims (as a rule, 3 years) or longer if required by applicable law.
  • Billing data: 5 years from the end of the tax year in which the tax liability arose.
  • End User data: for the period resulting from the User’s configuration. Upon account deletion, data is removed within 30 days, unless its retention is required by law.
  • System logs: up to 12 months from the date of their creation.
  • Marketing data: until consent is withdrawn or an objection is raised.
  • Data in OpenAI logs: up to 30 days (OpenAI’s API retention policy), unless OpenAI is required to retain it for a longer period by virtue of a legal order.

12. Rights of Data Subjects

12.1. Rights of Users

As a person whose data we process in the capacity of controller, you have the right to:

  • access your personal data (Article 15 GDPR);
  • rectification of inaccurate data (Article 16 GDPR);
  • erasure of data (Article 17 GDPR);
  • restriction of processing (Article 18 GDPR);
  • data portability (Article 20 GDPR);
  • object to processing based on legitimate interest, including direct marketing (Article 21 GDPR);
  • withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal (Article 7(3) GDPR).

Requests regarding the exercise of rights may be submitted to the following email address:

[email protected]

The Controller shall process the request without undue delay, no later than within 1 month. In justified cases, the deadline may be extended by an additional 2 months.

12.2. Rights of End Users

If you are an End User (a client of our User), the controller of your data is the Platform’s User with whom you communicate. To exercise your rights, please contact that entity directly.

AppWave Sp. z o.o. supports Users in fulfilling End Users’ requests to the extent required by Article 28 of the GDPR.

13. Cookies and Tracking Technologies

The BetterCX Platform may use cookies and similar technologies for the purpose of:

  • ensuring the proper operation and security of the Platform (essential cookies);
  • remembering User preferences (functional cookies);
  • conducting analyses of the use of the Platform (analytical cookies);
  • conducting marketing activities (marketing cookies).

Upon first visit to the Platform website, the User is informed about the cookies used and has the option to consent to individual categories or to reject them (with the exception of essential cookies).

14. Age Requirements and Processing of Minors’ Data

The BetterCX Platform is intended exclusively for business entities and adults (18+). Registration of an account on the Platform requires being at least 18 years of age. The Controller does not knowingly process data of minors in the capacity of Platform Users.

In the event that the Controller becomes aware that an account on the Platform has been created by a minor, the account will be immediately suspended and the data deleted. With respect to End Users’ data (clients of our Users), it is the Platform’s User – as the controller of their clients’ data – who bears responsibility for ensuring compliance with the provisions on the processing of minors’ data, including obtaining any required consent of a legal guardian.

15. Obligations of Platform Users

The Platform’s User, as the controller of their clients’ data, is obliged in particular to:

  • have a valid legal basis for the processing of End Users’ data;
  • fulfil the information obligation towards End Users, including informing them about the use of the AI system in communication;
  • ensure the exercise of the rights of data subjects whose data is processed via the Platform;
  • conclude a Data Processing Agreement (DPA) with the Platform Controller;
  • configure the AI system in a manner adequate to the purposes of processing and in accordance with the principle of data minimisation;
  • refrain from processing special categories of personal data (Article 9 GDPR) via the Platform, unless the User has a valid legal basis and the explicit consent of the data subject.

16. Right to Lodge a Complaint

If you believe that the processing of your personal data infringes the provisions of the GDPR, you have the right to lodge a complaint with the supervisory authority:

President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Infoline: 606-950-000, Email: [email protected], Website: https://uodo.gov.pl/

17. Amendments to the Privacy Policy

The Controller reserves the right to amend this Privacy Policy. Users shall be notified of material changes via the Platform or by email with reasonable advance notice.

Continued use of the Platform after the amended Privacy Policy takes effect shall constitute acceptance thereof.

The current version of the Privacy Policy is always available on the Platform website.

AppWave Sp. z o.o. | KRS 0001193213 | NIP 9820394623