Privacy Policy for Surveillant
Last updated: 28 July 2026
This policy explains what personal data Surveillant (surveillant.ai) collects, why we process it, who we
share it with, and what rights you have. The controller is Marketcode Sp. z o.o., a private limited company registered in Poland. This policy forms part of
our Terms of Service.
1. Data We Collect
- Account data: your name (if provided) and email address. Passwords are
stored only as cryptographic hashes — we cannot read them.
- Content you submit: the files, text and configuration you upload or create
in order to use the Service.
- Billing data: billing name, company details and payment history. Card details are handled by Stripe and never reach our servers.
- Technical data: IP address, browser and device type, timestamps and pages
requested. These are recorded in server logs and session records.
2. Why We Process It
- To perform our contract with you: creating and running your account and
delivering the features you use.
- Legitimate interests: keeping the Service secure, preventing abuse,
diagnosing faults, and supporting users.
- Legal obligations: retaining billing and accounting records.
3. Processors and Third Parties
We use a small number of providers that process data on our behalf:
- Cloud hosting provider — runs the application servers and database.
- Stripe — processes payments and subscriptions. Stripe acts as an independent controller for payment data.
- Transactional email provider — delivers system emails such as password
resets and account notifications.
We may disclose data where legally required. We do not sell personal data and
we do not share it with third parties for their own marketing.
4. Retention
- Account data is kept while your account is open. After deletion we remove or anonymise it.
- Content you submit is kept until you delete it or close your account.
- Billing records are retained for the period required by tax law.
- Server logs are retained only as long as needed for security and diagnostics.
5. Your Rights
Depending on where you live, you may have the right to access, correct, delete, restrict or
port your data, and to object to processing based on legitimate interests.
To exercise any of these, email
[email protected]. If you are in the EEA and
believe we have handled your data improperly, you may lodge a complaint with your national data
protection authority; in Poland this is the President of the Personal Data Protection Office (UODO).
6. Cookies
- Strictly necessary: keeping you signed in and protecting forms against
cross-site request forgery. The Service cannot work without these.
- Functional: remembering preferences such as your selected view.
You can control cookies in your browser, but blocking strictly
necessary cookies will prevent you from signing in.
7. Security
Traffic is encrypted in transit over HTTPS, passwords are hashed, and access to production data
is limited to the people who need it to operate the Service. No online service can be
guaranteed completely secure; if you believe you have found a vulnerability, please report it to
[email protected].
8. International Transfers
Our providers may process data outside your country, including outside the EEA. Where that
happens we rely on the safeguards offered by those providers, such as the European Commission's
standard contractual clauses.
9. Changes
We may update this policy. The current version is always available at
/privacy-policy with its effective date.
Contact: [email protected].