1.Who processes your data
The controller is Moadlab s. r. o., Konopná ul. 3059/5, 934 01 Levice, Slovak Republic, company ID (IČO) 57 704 406, registered in the Commercial Register of the District Court Nitra, section: Sro, entry no. 70213/N. We run the AIPráce service at www.aiprace.tech.
Contact for data protection matters: info@aiprace.tech, or moadlab@moadlab.com.
We have not appointed a data protection officer (DPO) and we are not required to. We are not a public authority, our core activity is neither large-scale regular and systematic monitoring of people nor large-scale processing of special categories of data, so we do not meet the Article 37 GDPR conditions for a mandatory appointment. Everything about your data is handled directly by the controller at the address above.
This document is written as plainly as Article 12 GDPR requires. If anything is unclear, write to us and we will explain it.
2.What data we process
- Account: e-mail address, password (stored only as an irreversible hash, we never see it), your name if you provide one, interface language and sign-up date.
- Profile: university, faculty, study programme, thesis type and topic. These are optional and only pre-fill the forms.
- Credits and payments: credit balance, the history of credits added and spent, a payment identifier and the amount. Billing details (name and address) are entered directly in the payment gateway. The gateway needs them to process the payment and to send you its receipt for the price, and for us they are evidence of the country you are buying from. We do not store the address in our own database, we only see it in our account with the gateway, and the name is used to address the order confirmation. The payment gateway sends you an invoice by email automatically. We are not a VAT payer, so it contains no VAT. Clause 6.3 of the Terms explains this in detail. Your card number never reaches us.
- Generation inputs: topic, outline, keywords, instructions, selected sources and the text the service generates for you, including earlier versions.
- Uploaded files: interview transcripts, questionnaires, data tables, PDFs, documents and images we extract text from. These have their own article 4.
- Communication: the e-mails we send you, the record that they were sent, and your messages to our address.
- Referrals: your referral code, the sign-ups that came through it and the credits awarded.
- Consent evidence: which consent you gave or refused (registration, credit order, the choice in the cookie banner), which version of the document you accepted, when, and from which IP address. For the cookie banner this also includes a random identifier of the browser the choice was made in; if the visitor is not signed in, the record is not linked to any account. The law requires us to be able to prove consent.
- Technical data: IP address, browser and device type, access time and technical error reports.
- Web analytics: only if you consent in the cookie banner.
3.Why we process the data and on what legal basis
- Providing the service (account, generation, credits, history, export): Article 6(1)(b) GDPR, performance of the contract you enter into with us.
- Service e-mails (order confirmation, generation finished, password reset): also performance of the contract under Article 6(1)(b).
- Payments and accounting: Article 6(1)(c), compliance with our legal obligations. This covers the receipt for the price under Section 4(1)(a) of Act No. 108/2024 Coll., which the payment gateway sends, our accounting and tax duties, and evidence of the buyer's country for cross-border VAT rules. The invoice is sent by the payment gateway; it is not an invoice under Section 74 of Act No. 222/2004 Coll., because we are not a VAT payer.
- Security and diagnostics (rate limiting, protection against abuse and attacks, debugging, backups): Article 6(1)(f), legitimate interest. That interest is specifically keeping the service running and preventing abuse or loss of your data. You can object to this processing, see article 9.
- Reminder and marketing e-mails (unfinished thesis, news, offers): Article 6(1)(a), your consent. You can withdraw it at any time through the link in the footer of every e-mail or by writing to info@aiprace.tech.
- Web analytics: Article 6(1)(a), your consent from the cookie banner. Without it the analytics tool does not load at all.
- Proving consent and defending legal claims: Article 6(1)(c) and (f). The law requires the trader to be able to prove that the consumer was informed and that consent was given, and Section 109(8) of Act No. 452/2021 Coll. requires demonstrable consent for web analytics as well. That is why we keep a server-side record of every choice, including a refusal in the cookie banner.
4.Material you upload to the service
Interview transcripts, completed questionnaires and data files often contain other people's personal data, for example respondents or employees of the company you are studying.
For this content we act as a processor: we work with it only on your instructions and only to produce your output. You are the controller of that data. For account, payment and analytics data we are the controller instead.
That means you are responsible for the data you upload:
- you must have a legal basis for putting it into the service (for example the respondents' consent or your university's assignment),
- you must tell the people concerned what happens to their data, as Articles 13 and 14 GDPR require,
- you should anonymise or at least pseudonymise it whenever possible. The quality of your thesis does not depend on the respondents' names.
Uploading special categories of data under Article 9 GDPR (health, religion, political opinions, sex life, biometric and genetic data, racial or ethnic origin) and criminal-offence data under Article 10 without a proper legal basis is prohibited. If you upload such content without one, you are in breach of the Terms and you carry the consequences.
You can delete uploaded interview transcripts at any time in the editor of your work, under Attachments, except while the work is being written or its generation is still unfinished. Only the respondent codes (R1, R2) then remain in the work. The same tab deletes the attachments of your work. To delete any other uploaded file, such as a questionnaire, write to info@aiprace.tech and we will delete it. All uploaded files are also deleted when you close your account.
5.Who we share data with
We do not sell your data and we do not give it to anyone for advertising. We pass it on only to those without whom the service would not work:
- providers of large language models established in the USA (text generation, source search and verification, review passes). They receive your inputs and uploaded content to the extent needed for the processing.
- hosting of the database, file storage and sign-in,
- hosting of the website and the application interface,
- payment gateway,
- e-mail delivery,
- application error diagnostics,
- web analytics, only if you consented,
- our accountant, where needed a lawyer, and public authorities where the law requires it.
We list categories so the document does not go stale every time a supplier changes. We will send you the full list of named processors on request at info@aiprace.tech.
6.Transfers outside the EEA
Some recipients are established outside the European Economic Area, in particular in the USA and in Singapore.
Where a recipient is certified under a European Commission adequacy decision (for example the EU-US Data Privacy Framework), the transfer relies on that decision. For the remaining recipients, which is the case for most of our AI suppliers, the transfer relies on the European Commission's Standard Contractual Clauses together with supplementary measures, in particular encrypted transmission, limiting the scope of the data sent, and a contractual ban on using it for any other purpose.
We do not claim that all of our US suppliers are certified, because that is not true. We will send you a copy of the safeguards on request.
7.How long we keep the data
- Account and its content (profile, theses, sources, credit history): for as long as you have an account with us. When you close it you have 30 days to change your mind, and after that the data is irreversibly deleted. It leaves the backups within 7 days at the latest, as backups are rotated.
- Accounting and tax documents: 10 years, as accounting and tax rules require. We cannot delete these earlier, not even at your request.
- Consent evidence: for as long as we must be able to prove that you gave or refused consent, that is, while the choice stands and then for the period in which it can be subject to a supervisory inspection or in which claims from the related contract can run. This record survives both account closure and the clearing of your browser data, but it holds only the necessary minimum: the type of consent, the version of the document, the time, the IP address and the browser or account identifier.
- E-mail opt-out record: for as long as we run the service. If we deleted it, we would write to you again.
- Technical logs and error reports: briefly, as a rule up to 90 days.
- Web analytics: according to the analytics tool's settings, the details are in the cookie document.
8.Cookies and web analytics
Without your consent we store only what is strictly necessary for the service to work, that is your sign-in and your chosen language.
Google Analytics loads only after you accept in the cookie banner, and we delete its cookies when you withdraw consent. You can withdraw at any time through the Cookie settings link in the site footer. Refusing is as easy as accepting and nothing is pre-ticked.
Besides the browser, we also record your cookie-banner choice on our server, because we have to be able to prove consent. The record holds the choice, its time, the IP address and a random browser identifier.
The details are in the separate cookie document.
9.Your rights
- Access: ask what we process about you and get a copy of the data. Most of it you can download directly in your account.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have your data deleted when it is no longer needed or when you withdraw consent. This does not cover documents we must keep by law.
- Restriction of processing: ask us to pause working with the data, for example while a dispute about its accuracy is resolved.
- Portability: receive your data in a machine-readable format and move it elsewhere.
- Objection: object to processing that rests on our legitimate interest. You can object to direct marketing at any time and we stop immediately.
- Withdrawal of consent: at any time and without giving a reason. This does not affect the lawfulness of processing before the withdrawal.
- Not to be subject to automated decision-making under Article 22, see article 11.
- Complaint: Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava 27, Slovakia, www.dataprotection.gov.sk. If you live in another EU country you can also complain to the supervisory authority where you reside. You also have the right to go to court.
Send requests to info@aiprace.tech, ideally from the e-mail you registered with so we know it is really you. We reply within one month. If the request is complex we may extend that by up to two further months and will tell you. Handling it is free of charge.
10.Do you have to provide the data?
An e-mail address and a password are necessary for the account to exist at all. Without them we cannot enter into a contract with you or provide the service. Billing details at payment are required by the payment gateway so that it can process the payment and send you the receipt for the price, and for us they are evidence of the country you are buying from. Without them the credit purchase cannot go through. The generation inputs are up to you, but without them we cannot produce an output.
Profile data, consent to marketing e-mails and consent to web analytics are entirely voluntary. If you do not give them, you keep using the service normally, you will just fill in some fields by hand.
11.Automated decision-making and profiling
Your output is generated by artificial intelligence, but that is not a decision about you. We do not take automated decisions with legal or similarly significant effects under Article 22 GDPR, and we do not profile you to assess personality, behaviour or creditworthiness.
The only automated steps are technical ones, such as rate limiting, deducting credits for a generation, or blocking obvious abuse. If one of them affects you, write to info@aiprace.tech and a human will look at it.
12.Security and changes to this policy
Traffic between your browser and the server is encrypted with HTTPS/TLS. Passwords are stored only as a hash, so we can neither read nor restore them. Access to the database and to storage is restricted at the level of individual rows and files, so you only reach your own content. Payments are handled by a PCI DSS certified payment gateway and your card details never reach us.
If a personal data breach happens anyway, we report it to the supervisory authority within 72 hours under Article 33 GDPR, and if it is likely to put you at high risk we tell you as well under Article 34.
We may change this policy, for example when a new feature or supplier is added. The current version and effective date are shown at the top. We will notify you of material changes by e-mail or in the app, and we will send you an earlier version on request.