Przejdź do treści

Privacy policy

Last updated: 2026-05-03

TODO: review by counsel before sending to any customer or publishing publicly. This policy describes Secruna's handling of personal data. It must be reviewed by a CEE- qualified privacy lawyer (Polish + at least one further CEE jurisdiction) before publication.


1. Who we are

Secruna sp. z o.o. (controller entity name pending — TODO confirm with founder) is a Polish-incorporated SaaS provider of EU AI Act compliance tooling. Secruna operates the service available at app.secruna.com and the API at api.secruna.com.

Contact: TODO legal@secruna.com (alias to be configured).

2. Scope

This policy applies to:

  • Visitors to our marketing site (secruna.com).
  • Users of the Secruna platform (app.secruna.com, api.secruna.com) operating under their employer's tenant.
  • Recipients of transactional emails from us.

It does not apply to AI systems we discover within a customer's environment via a connector — those are governed by the customer's own privacy notices to its employees and end-users, supplemented by the Data Processing Agreement.

3. Personal data we process and why

3.1 As controller (about visitors and prospects)

Data Source Purpose Legal basis
Email address You give it to us via contact form, email, or sign-up Reply to your enquiry; account creation Performance of contract / pre-contract steps (Art 6(1)(b))
Name, job title, company You give it to us Sales context, account creation Pre-contract steps
Cookie data on secruna.com Browser Strict-necessary only by default; analytics cookies require consent banner (consent banner deployment is in P0 of our roadmap; until then we do not set non-essential cookies) Consent (Art 6(1)(a)) when applicable

3.2 As processor (about our customers' users)

When your employer onboards your team to Secruna, we process the following on behalf of that employer (the controller):

  • Microsoft Entra ID identifier, email, and display name (for authentication).
  • IP address and user-agent (for rate limiting and audit).
  • Audit-log entries for actions you perform inside the platform.

The full list, retention windows, and security controls are documented in the DPA template. Your employer is the data controller for these activities; please contact your employer's data protection officer for rights requests.

3.3 As processor (about systems we discover)

The connectors documented under connectors/ read management-plane metadata about your employer's AI systems. The categories of data and the legal basis are governed by the DPA between Secruna and your employer, not by this policy.

4. Cookies

secruna.com and app.secruna.com use the following cookies:

Cookie Purpose Type Lifetime
rekognise_session Authenticates a logged-in user Strictly necessary 24h sliding
(CSRF tokens — Next.js framework cookies) Security Strictly necessary Session

We do not currently use analytics or marketing cookies on the authenticated platform. The marketing site secruna.com will deploy a consent banner before any analytics tracking is added (this is a tracked roadmap item, not a future ambition).

5. Sharing and subprocessors

5.1 Subprocessors

We use the third parties listed at subprocessors.md to operate the service. Each is bound by contract to use personal data only for the agreed purpose and to apply security measures equivalent to ours.

5.2 Disclosure to law enforcement

We disclose personal data in response to legal process only when:

  1. We are compelled by a court order or other binding legal instrument from a competent authority;
  2. The order has been reviewed for legality by counsel;
  3. Where lawful and not prohibited by the issuing authority, we notify the affected controller in advance.

We publish an annual transparency report counting such requests (planned, P2).

5.3 Sale of data

We do not sell personal data. We do not engage in cross-context behavioural advertising.

6. International transfers

The service is hosted in the EU (Azure Sweden Central). Personal data is transferred outside the EEA only to the subprocessors listed under subprocessors.md, under the Standard Contractual Clauses (EU 2021/914) with appropriate supplementary measures. Copies are available on request.

7. Retention

Retention periods are documented in data-retention.md. Summary:

  • Authentication and account data — lifetime of the tenant + 30 days grace.
  • Audit log entries — 7 years (matches AI Act Article 12 + GDPR Article 30).
  • System artefacts — 90 days post-disconnect of source connector.
  • Marketing leads (visitor to prospect) — until you ask us to delete, or 24 months of inactivity, whichever comes first.

8. Your rights

You have the right to:

  • Access (Art 15) the personal data we hold about you.
  • Rectify (Art 16) inaccurate data.
  • Erase (Art 17) data we no longer need to retain.
  • Restrict (Art 18) processing in defined circumstances.
  • Receive a portable copy (Art 20) of structured data you have given us.
  • Object (Art 21) to processing based on legitimate interest (Secruna does not currently rely on this basis).
  • Not be subject (Art 22) to a decision based solely on automated processing producing legal or similarly significant effects on you.
  • Withdraw consent (Art 7) at any time where processing is based on consent.
  • Lodge a complaint with the Polish data protection authority (Urząd Ochrony Danych Osobowych — UODO) or with the supervisory authority of your habitual residence.

To exercise any of these rights, email legal@secruna.com (TODO: configure alias) with proof of identity.

We respond to verifiable requests within 30 calendar days.

When you exercise a right concerning processing performed by Secruna as a processor on behalf of your employer, we forward your request to your employer per Article 28(3)(e) GDPR — they are the controller and must respond.

9. Security

A summary of our technical and organisational measures appears in §6 of the DPA template. In short:

  • TLS 1.2+ everywhere; encryption at rest with AES-256.
  • Secrets in Azure Key Vault.
  • Microsoft Entra ID OIDC for authentication, RLS for tenant isolation, 2-eyes for impersonation.
  • Single-region (Sweden Central) with documented manual DR (RTO ≈ 6h).
  • 7-year audit log, 30-day app-log retention.

We have not yet completed SOC 2 or ISO 27001 audits; we disclose this honestly and intend to attest to SOC 2 Type 1 during the post-MVP period (see public roadmap).

10. Children

We do not knowingly process personal data of individuals under the age of 16. The service is targeted at enterprise compliance teams.

11. Changes to this policy

When we materially change this policy, we will:

  1. Update the Last updated date.
  2. Email account-owner contacts at every active tenant.
  3. Post a banner notice in app.secruna.com for 30 days.

Trivial corrections (typos, link fixes) ship without notice.

12. Contact

  • Privacy questions / rights requests: TODO legal@secruna.com
  • Security disclosures: TODO security@secruna.com
  • General support: TODO support@secruna.com

Postal address: TODO insert registered Polish entity address when finalised.


TODO: review by counsel before sending to any customer or publishing publicly.