Skip to main content

Privacy Policy

Last updated: 2026-06-01

Version 1.0


This Privacy Policy describes how Aurea Enterprises sp. z o.o., with its registered office at ul. Plac Bankowy 2, 00-095 Warszawa, NIP: 9591956107, KRS: 0000510950, hereinafter referred to as the "Controller", "we" or "Bezpieczna Kancelaria", processes personal data in connection with the use of the bezpiecznakancelaria.pl website and the Bezpieczna Kancelaria application.

For matters concerning personal data protection, you may contact us by e-mail at: privacy@bezpiecznakancelaria.pl.

1. What Bezpieczna Kancelaria is

Bezpieczna Kancelaria is a SaaS system intended for law firms and other professional entities, used, among other things, to manage cases, documents, recordings, transcriptions, calendars, user permissions, communications, invoicing and integrations with external services.

Bezpieczna Kancelaria is not a law firm and does not provide legal services to the end clients of law firms. Legal services are provided by the law firm or other entity using the system.

2. Our roles in data processing

Depending on the type of data, we perform different roles.

2.1. We are the data controller

We are the controller of personal data with respect to data processed for the purposes of:

  • operating the website,
  • creating and servicing user accounts,
  • entering into and performing contracts with customers,
  • processing payments and invoices,
  • sales contact and handling enquiries,
  • technical support,
  • ensuring application security,
  • conducting marketing activities concerning our services,
  • pursuing or defending against claims.

Within this scope, we determine the purposes and means of data processing.

2.2. We are the processor of customer data

With respect to data entered into the system by a law firm or another customer, such as case files, documents, data of the law firm's clients, recordings, transcriptions, notes, messages, calendar data, invoice data, data from integrations and other content stored in the system, we generally act as a processor processing data on behalf of the customer.

This means that the controller of such data is the customer using Bezpieczna Kancelaria, for example, a law firm, and we process such data solely for the purpose of providing the service, in accordance with the contract, terms and conditions, data processing agreement and the customer's instructions.

If you are a client of a law firm using Bezpieczna Kancelaria and wish to exercise your rights under RODO, please contact that law firm in the first instance. We may assist the law firm in fulfilling such requests, but we do not independently make decisions concerning data contained in the files of cases handled by the customer.

3. What data we process as the controller

As the controller, we may process the following categories of data:

3.1. Account user data

This includes in particular:

  • first name and surname,
  • e-mail address,
  • telephone number,
  • name of the organisation or law firm,
  • position or role within the organisation,
  • user identifier,
  • account settings,
  • information concerning permissions and roles within the system,
  • login and security event history.

3.2. Contractual and billing data

This includes in particular:

  • company or law firm details,
  • NIP, REGON, KRS, registered office address,
  • contact person details,
  • data required to issue an invoice,
  • payment history,
  • information concerning the selected package or scope of the service.

3.3. Technical data

This includes in particular:

  • IP address,
  • session identifiers,
  • browser type and version,
  • operating system,
  • device identifiers,
  • login date and time,
  • technical logs,
  • error logs,
  • security events,
  • information concerning the use of system functions.

3.4. Contact and support data

This includes in particular:

  • data provided in contact forms,
  • the content of e-mail messages,
  • service requests,
  • communication history,
  • files or screenshots provided as part of technical support.

Please do not provide sensitive data, case files, recordings or documents containing data of the law firm's clients in support requests unless this is necessary to resolve the request and is done in accordance with the security procedure.

4. What data may be processed in the system as customer data

Law firms and other customers using Bezpieczna Kancelaria may enter various data into the system, including the personal data of third parties. This may include in particular:

  • data of the law firm's clients,
  • data of parties to proceedings,
  • data of counterparties,
  • data of witnesses,
  • data of attorneys-in-fact,
  • data of employees and associates,
  • data contained in documents and case files,
  • data contained in audio recordings,
  • data contained in transcriptions,
  • calendar data,
  • invoice data,
  • data from integrations with external systems,
  • case reference numbers,
  • information concerning deadlines, activities and tasks.

Such data may also include special categories of personal data, data relating to criminal convictions, prohibited acts, court proceedings, or family, financial, health or professional circumstances, if such data is contained in materials processed by the customer.

Within this scope, we are not the controller of such data. The controller is the customer using the system, and we process the data solely as a technology service provider.

5.1. Account creation and servicing

We process data in order to create an account, authenticate the user, manage access, roles and permissions, and enable the use of the application.

Legal basis: performance of a contract or taking steps prior to entering into a contract, Article 6(1)(b) RODO.

5.2. Provision of the Bezpieczna Kancelaria service

We process data in order to provide the service, maintain the operation of the system, synchronise data, support integrations, save user settings and implement functions selected by the customer.

Legal basis: performance of a contract, Article 6(1)(b) RODO.

With respect to data entered into the system by the customer, we process the data as a processor on the basis of a data processing agreement.

5.3. Handling requests and contact

We process data in order to respond to enquiries, handle forms, conduct correspondence, resolve technical issues and handle complaints.

Legal basis: performance of a contract or our legitimate interest in handling contact and providing support, Article 6(1)(b) or (f) RODO.

5.4. Billing, invoices and accounting obligations

We process data in order to issue invoices, process payments, maintain accounting records and fulfil tax and accounting obligations.

Legal basis: a legal obligation incumbent on the Controller, Article 6(1)(c) RODO.

5.5. System security

We process technical data and logs in order to ensure application security, detect abuse, protect against unauthorised access, prevent incidents, audit events and ensure the accountability of user activities.

Legal basis: our legitimate interest in ensuring the security of the service, Article 6(1)(f) RODO.

5.6. Development and improvement of service quality

We process limited technical, diagnostic and statistical data in order to analyse errors and improve the stability, performance, usability and security of the application.

Legal basis: our legitimate interest in developing and improving the product, Article 6(1)(f) RODO.

Customer data stored in documents, files, recordings or transcriptions is not used for product development without a legal basis, the customer's consent or another express basis arising from the contract.

5.7. Own marketing

We may process contact data for the purpose of marketing our own products and services, insofar as this is permitted by law.

Legal basis: our legitimate interest, Article 6(1)(f) RODO, and in cases where consent is required - consent, Article 6(1)(a) RODO.

Consent may be withdrawn at any time.

5.8. Cookies and analytics

If we use cookies or similar analytical technologies that are not necessary for the operation of the website or application, we do so on the basis of the user's consent.

Consent may be withdrawn or changed in the cookie settings.

5.9. Establishment and defence of claims

We may process data for the purpose of establishing, pursuing or defending against claims.

Legal basis: our legitimate interest, Article 6(1)(f) RODO.

6. Encryption and access to client content

Bezpieczna Kancelaria has been designed with an emphasis on the confidentiality and security of law firm data.

In accordance with the adopted system architecture, the client's files and documents are encrypted. The client's authorised users have access to decrypted content in accordance with the account configuration, roles and permissions within the system.

We do not ask users to disclose passwords. A user's password should remain known exclusively to the user.

Depending on the service configuration, certain functions, such as transcription, AI analysis, content searching, integrations or exports, may require the processing of decrypted data during the user's active session or by designated subprocessors. Such processing takes place exclusively for the purpose of performing the function initiated by the client or user.

7. Recordings, transcriptions and AI functions

If the client uses recording, transcription or AI assistant functions, the following may be processed within the system:

  • audio files,
  • recording metadata,
  • voices of conversation participants,
  • transcriptions,
  • summaries,
  • notes,
  • user instructions,
  • responses generated by the system,
  • data contained in documents designated for analysis.

These functions are initiated by the client or user and serve exclusively to perform the selected function within the system.

If we use external technology providers to perform a function, we do so on the basis of appropriate agreements and safeguards required by RODO. The list of such providers is set out in the list of subprocessors (section "Data recipients").

8. Integrations with external services

Bezpieczna Kancelaria may enable integrations with external services, such as calendars, email systems, invoicing systems, KSeF, court systems or other tools used by the client.

Data from such integrations are processed exclusively to the extent necessary for the operation of the function enabled by the client or user.

The client or user may be required to grant appropriate permissions in the external system. The scope of such permissions depends on the specific integration.

9. Data recipients

Data may be transferred to the following categories of recipients:

  • server and cloud infrastructure providers,
  • email and transactional message providers,
  • technical monitoring and security system providers,
  • payment system providers,
  • the accounting firm,
  • law firms providing services to the Controller,
  • providers of transcription, speech recognition or AI services, if the client uses such functions,
  • support tool providers,
  • operators of external services to which the client has connected the account,
  • public authorities, courts or other authorised entities, where required by law.

We enter into appropriate data processing agreements with entities processing data on our behalf.

The current list of subprocessors we use:

  • Hetzner Online GmbH (Germany, European Economic Area) - server and hosting infrastructure (servers, databases, file storage).
  • OpenAI (USA) - transcription of recordings and AI functions; data are transferred outside the EEA on the basis of standard contractual clauses (SCCs).
  • ElevenLabs (USA) - transcription and speech recognition; data are transferred outside the EEA on the basis of standard contractual clauses (SCCs).

10. Transfers of data outside the European Economic Area

As a rule, we endeavour to ensure that data are processed within the European Economic Area.

If data are transferred outside the European Economic Area in connection with the use of specific providers or functions, this takes place exclusively using the mechanisms provided for by RODO, in particular a European Commission adequacy decision, standard contractual clauses or other required safeguards.

Information on transfers outside the EEA is set out in the list of subprocessors (section "Data recipients").

11. Data retention period

We retain data for no longer than is necessary to fulfil the purposes for which they were collected.

In particular:

  • we retain user account data for the duration of use of the service and subsequently for the period required for settlements, handling claims or complying with legal obligations,
  • we retain billing and accounting data for the period required by tax and accounting regulations,
  • we retain contact data processed in connection with an enquiry for the duration of handling the matter and subsequently for the period necessary to demonstrate the course of the matter or defend against claims,
  • we retain security logs for a period of 12 months,
  • we process marketing data until an objection is raised, consent is withdrawn or the data cease to be useful,
  • we retain data stored by the client in the system in accordance with the agreement, the account configuration and the retention policy selected by the client.

Following termination of the agreement, the client's data may be deleted, returned, exported or anonymised in accordance with the agreement and the procedure for terminating the provision of the service.

12. Rights of the data subject

To the extent that we are the data controller, the data subject has the right to:

  • access the data,
  • receive a copy of the data,
  • rectify the data,
  • erase the data,
  • restrict processing,
  • data portability,
  • object to processing based on our legitimate interest,
  • withdraw consent where processing is based on consent.

Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

To exercise these rights, please contact us at: privacy@bezpiecznakancelaria.pl.

We respond without undue delay, no later than within one month of receipt of the request. In complex cases, this period may be extended in accordance with RODO.

If the request concerns data processed by the client in the system, e.g. data contained in the case files of a matter handled by a law firm, we may forward the request to the relevant client or inform the data subject that the client should be contacted directly.

13. Right to lodge a complaint

The data subject has the right to lodge a complaint with the supervisory authority competent for personal data protection matters.

In Poland, this authority is the Prezes Urzędu Ochrony Danych Osobowych.

Contact details of UODO: Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa.

However, we encourage data subjects to contact us before lodging a complaint. Many matters can be resolved more quickly without formal proceedings.

14. Automated decision-making

We do not make decisions concerning users that are based solely on automated processing and that would produce legal effects concerning them or similarly significantly affect them.

AI, transcription, summarisation, search or document analysis functions are auxiliary in nature and are intended to support the user's work. Final decisions concerning matters, clients, documents or legal actions are made by the user or the client using the system.

15. Data Security

We implement technical and organisational measures intended to protect data against unauthorised access, loss, alteration, disclosure or destruction.

In particular, depending on the scope of the service, we implement:

  • data encryption,
  • access controls,
  • user roles and permissions,
  • event logging,
  • authentication mechanisms,
  • segregation of client data,
  • backups,
  • security monitoring,
  • incident response procedures,
  • restrictions on personnel access to data.

No IT system guarantees absolute security, but we design Bezpieczna Kancelaria so as to minimise the risks associated with the processing of law firm data.

16. Professional Confidentiality and Clients' Professional Secrecy

We understand that data processed in Bezpieczna Kancelaria may be subject to professional secrecy, advocate's secrecy, attorney-at-law secrecy, trade secrets or other confidentiality obligations.

Bezpieczna Kancelaria is a technological system, and responsibility for assessing which data may be entered into the system and which professional obligations apply rests with the client using the service.

We provide technical and organisational measures designed to protect data confidentiality, in accordance with the agreement, security documentation and system settings.

17. Children's Data

Bezpieczna Kancelaria is not a service directed specifically at children. We do not knowingly create accounts for persons who are not authorised users of the client.

However, children's data may be contained in documents or case files processed by clients of the system. In such a case, the client is the controller of such data, and we process it as a processor.

18. Amendments to the Privacy Policy

We may amend the Privacy Policy, in particular in the event of changes to the system, technological changes, changes of providers, legal changes or changes to the scope of services.

The current version of the Privacy Policy is published on the bezpiecznakancelaria.pl website.

We may also inform users of material changes in the application or by e-mail.

19. Contact

For matters concerning privacy and personal data protection, please contact:

Aurea Enterprises sp. z o.o., ul. Plac Bankowy 2, 00-095 Warszawa. E-mail: privacy@bezpiecznakancelaria.pl.


Language

This document is available in Polish and English. The Polish version is the source text; in case of any discrepancy between the versions, the Polish version prevails. The English version is a translation provided for convenience only.