Privacy Policy
Last updated: July 2026
This Privacy Policy explains what personal data Soba Labs collects, how and why we use it, and the rights you have. It covers our website and the ways you can interact with us through it.
1.Introduction
Soba Labs Prosta Spółka Akcyjna (P.S.A.) ("Soba Labs", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and safeguard personal data when you visit our website at sobalabs.ai, contact us, book a call, or otherwise interact with our services (together, the "Services"), and it sets out your rights under data protection law. We process personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Polish law. This policy covers individuals, including the people we deal with at business contacts; it is not affected by the fact that we work mainly with organisations.
2.Who we are (data controller)
Soba Labs is the controller of the personal data described in this policy.
- Legal entity: Soba Labs Prosta Spółka Akcyjna (P.S.A.)
- Registered office: ul. Marsz. Józefa Piłsudskiego 91/1, 50-019 Wrocław, Poland
- KRS: 0001245101
- NIP (Tax ID): 8971973376
- REGON: 544942809
- VAT ID: PL8971973376
- Email: [email protected]
We have not appointed a Data Protection Officer, as we are not required to under the GDPR. For any privacy question, or to exercise your rights, contact us at [email protected].
3.The personal data we collect
We collect and process the following categories of personal data:
- Information you give us. When you contact us or book a call, we collect the details you provide, such as your name, email address, company, role, and the content of your message or enquiry.
- Booking data. When you schedule a call, our scheduling provider collects the information needed to arrange the meeting, such as your name, email address, chosen time, and any notes you add.
- Call recordings and notes. When you have a call with us, we may record it and generate a transcript, written notes, and a summary using our meeting-notes tool. We tell you at the start of the call, and you can ask us not to record. We use these recordings and notes only internally, to keep an accurate record of the conversation and to follow up with you; we do not share them with anyone outside Soba Labs and our provider, and we do not publish them.
- Usage and device data. When you visit the Services, we collect limited technical information such as pages visited, referring page, approximate location derived from your IP address, browser type, and device type. Our website uses a privacy-first, cookieless analytics service, so we do not use advertising or cross-site tracking cookies.
- Server logs. Our hosting and infrastructure providers process technical logs, including IP addresses, for security, diagnostics, and abuse prevention.
Providing this information is voluntary. However, if you do not give us the details needed to answer your enquiry or arrange a meeting, we will not be able to respond to you or hold the call.
We do not intentionally collect special categories of data, such as health, political, or biometric data, through the Services. Please do not send us such data in your messages.
4.Why we use your data and our legal bases
We only process your personal data where we have a lawful basis under Article 6(1) of the GDPR. The basis depends on the purpose:
- Responding to your enquiries and taking steps to discuss working together: Article 6(1)(b) (steps taken at your request before entering into a contract) and Article 6(1)(f) (our legitimate interest in responding to business enquiries).
- Arranging and holding a call you book: Article 6(1)(b) and Article 6(1)(f) (our legitimate interest in meeting people who ask to speak with us).
- Recording a call and generating notes: Article 6(1)(f) (our legitimate interest in keeping an accurate internal record of the conversation and preparing our follow-up). We tell you before we record, and you can ask us not to.
- Keeping the Services secure and preventing abuse (for example server logs): Article 6(1)(f) (our legitimate interest in the security and integrity of our systems).
- Understanding aggregate site usage through privacy-first analytics: Article 6(1)(f) (our legitimate interest in measuring and improving how our website performs).
- Meeting our legal, accounting, and tax obligations: Article 6(1)(c).
- Anything we do with your consent, such as sending you material you asked for: Article 6(1)(a). You can withdraw your consent at any time, without affecting processing carried out before you withdrew it.
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms, and you can object to that processing at any time (see "Your rights").
5.Cookies and analytics
Our website is designed to work without advertising or tracking cookies. We use a privacy-first, cookieless analytics service that helps us understand aggregate site usage without profiling individual visitors. Because it sets no cookies and stores or accesses nothing on your device, it does not require your consent, and we do not show a cookie banner. Any strictly necessary cookies that our hosting or security provider may set are used only to deliver and secure the site.
6.How we share your data
We do not sell or rent your personal data. We share personal data only with:
- Service providers (processors) who help us run the Services, under contracts that require them to protect your data and use it only on our instructions. These currently include our hosting and analytics provider, our email and productivity provider, our scheduling provider (Cal.com), and our meeting-recording and notes provider (Fathom).
- Authorities or others, where we are required to do so by law, or to establish, exercise, or defend legal claims.
7.International data transfers
Some of our providers are based in, or process data in, countries outside the European Economic Area (EEA), including the United States. Where personal data is transferred outside the EEA, we rely on a transfer mechanism recognised under the GDPR: either the European Commission's adequacy decision for the EU-US Data Privacy Framework, where the provider is certified under it, or the European Commission's Standard Contractual Clauses together with any additional safeguards needed. You can ask us for a copy of the relevant safeguards using the contact details below.
8.Data retention
We keep personal data only for as long as necessary for the purposes described in this policy, or as required by law:
- Enquiry and booking data is kept for as long as we need it to handle your request and manage our relationship with you, and for a reasonable period afterwards to deal with any follow-up or related legal claim.
- Call recordings and notes are kept only for as long as they are useful to the relationship, and are deleted when no longer needed. You can ask us to delete a recording or its notes at any time.
- Server logs are kept for a short period, no longer than needed for security and diagnostics.
- Accounting and tax records are kept for the period Polish law requires, generally five years from the end of the relevant year.
When personal data is no longer needed, we delete it or irreversibly anonymise it.
9.Automated decision-making and profiling
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
10.Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- ask us to correct inaccurate or incomplete data;
- ask us to erase your data (the "right to be forgotten");
- restrict or object to our processing of your data, including where we rely on legitimate interests;
- request portability of the data you provided to us, in a structured, machine-readable format;
- withdraw consent at any time, where we rely on consent; and
- lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at [email protected]. We will respond within the time limits set by law. You will not have to pay a fee unless the law allows it.
11.How we protect your data
We use appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, including access controls and the secure storage of credentials. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and keep our measures under review.
12.Children
The Services are intended for businesses and are not directed at children. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
13.Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Services, our providers, or legal requirements. The current version is always posted on this page with its "Last updated" date. Where changes are significant, we will take reasonable steps to highlight them.
14.Contact and complaints
For any question about this policy, or to exercise your rights, contact us at [email protected], or by post at our registered office above. If you are in the European Union and believe we have not handled your data properly, you have the right to complain to a supervisory authority. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw. You may also complain to the authority in your own country of residence.