Skip to content

Privacy Policy

Last updated: August 24, 2026

Version: 2026-08-24 · Effective: 24 August 2026

Controller: Uladzimir Pranevich, sole proprietor registered in Poland, NIP 8992922668, REGON 521728250, ul. Kabacki Dukt 14/56, 02-798 Warsaw, Poland. Contact: privacy@novastorm.ai.

1. Scope and roles

This Policy covers novastorm.ai, the Novastorm application, support and billing. We normally control account, website, usage and billing data. When a business customer supplies leads, audiences or other personal data and instructs processing, the customer is normally controller and we are its processor; the binding DPA in Section 5 of the Termsapplies automatically.

2. Data we collect

  • Account and contact data, authentication provider, country, language and preferences.
  • Billing identifiers, subscriptions, invoices, tax, refunds and disputes; Stripe handles full card details.
  • Authorised platform identifiers, tokens, pages, ad accounts, campaigns, creatives, insights, leads and pixel or conversion events.
  • Prompts, generated content, media, websites or pages you ask us to analyse, brand and campaign data.
  • Device, consent, cookie, IP, security, audit, diagnostic, usage and support information.
  • Legal-document versions, content hashes, time and acceptance method used to prove an agreement or acknowledgement.

3. Sources and required data

We obtain data from you and your device; authentication, payment, hosting, analytics and support providers; services and advertising accounts you choose to connect; websites you ask us to analyse; and outputs or inferences generated from that material. Account, authentication and payment details are contractual requirements for the relevant account or paid feature. Other fields and connections are optional unless a feature clearly requires them.

4. Purposes and legal bases

  • Contract and requested pre-contract steps: authentication, accounts, requested features, payments and support.
  • Legitimate interests: security, debugging, improvement, fraud prevention and audit, balanced against your rights.
  • Legal obligation: tax, accounting, sanctions, lawful requests and consumer compliance.
  • Consent: optional Hotjar and Microsoft Clarity analytics and communications where required. Clarity receives an analytics-storage grant only after that choice; we send ad storage as denied. Withdrawal does not affect earlier lawful processing.

5. Recipients, processors and independent controllers

We share only as needed with infrastructure and hosting providers (including Hetzner and Cloudflare), storage/CDN providers, Stripe, email and support providers, Google Tag Manager, Google Analytics, Hotjar, Microsoft Clarity, Stape and Meta Pixel/Conversions API after the applicable consent, AI or media providers, and connected services such as Meta/Facebook/Instagram and Google. Providers act under their own terms or our instructions. Microsoft and Novastorm act as independent controllers for personal data processed through Clarity, rather than Microsoft acting as our processor. Clarity assigns a unique user identifier and can collect page interactions such as mouse movements, clicks, scrolling, navigation and performance data. We do not knowingly send sensitive data. Under the Clarity Terms, Microsoft may use personal data under the Microsoft Privacy Statement, including to provide and improve services and create advertising profiles; Microsoft may use non-personal data for research, development and AI model training, fine-tuning and evaluation. Reject or withdraw Analytics in Cookie Settings to prevent future Clarity collection by this site. We may disclose for law, safety, professional advice, a corporate transaction or at your direction. We do not sell personal data for money. Optional Meta measurement may count as “sharing”, targeted advertising or cross-context behavioural advertising under some US state laws; it remains off unless Marketing consent is allowed, and Global Privacy Control keeps it off.

6. International transfers

Data may be processed outside your country. A restricted transfer is made only where an applicable lawful mechanism has been put in place for that transfer. Depending on the provider and destination, this may be an adequacy decision, executed Standard Contractual Clauses or another legally recognised safeguard. Contact us to request the current mechanism for a particular provider; not every listed mechanism applies to every provider.

7. Retention and deletion

Account content is normally kept while active. A deletion request has a 14-day restoration window, after which active-system data is deleted or anonymised unless retention is required. Backups roll off under their cycle. Billing and tax records are retained for the period required by Polish law. Security, legal-acceptance and deletion evidence is retained only as reasonably necessary for compliance, limitation periods and legal claims, with identifiers minimised or pseudonymised where practical. Connected-platform data is removed when no longer needed, subject to provider and legal requirements.

8. Your rights

Depending on location, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent and human review of solely automated significant decisions. Where applicable, you may opt out of sale, sharing or targeted advertising; we currently do not sell personal data. Email privacy@novastorm.ai. We may verify identity and respond within the legal period. You may complain to Poland's UODO or your local authority.

9. Cookies, consent and GPC

Necessary browser storage records security and the choices you request. Hotjar and Microsoft Clarity load only after Analytics consent. Clarity receives analytics storage as granted and ad storage as denied. Because the current Google Tag Manager container combines Google Analytics with Meta Pixel/CAPI marketing measurement, that container stays unloaded unless both Analytics and Marketing are allowed. Global Privacy Control forces Marketing off. Rejecting optional storage does not block access. You can reject or change choices in Cookie Settings. See the Cookie Policy for the current storage table.

10. Security and children

We use access controls, encrypted transport and appropriate credential, logging, backup, incident and vendor controls, but no online service is risk-free. Do not submit sensitive data unless necessary and authorised. Novastorm is not directed to children and does not knowingly allow accounts below 18.

11. AI and automated processing

AI helps generate recommendations, content and automation suggestions. It does not make legal or similarly significant decisions about individuals on our behalf. Customers must review outputs and make required disclosures. We do not use customer content to train our own general-purpose model without separate permission.

12. Updates and contact

We publish changes with a fixed version and effective date and provide additional notice or request a renewed acknowledgement where required.

ULADZIMIR PRANEVICH
Sole proprietor / jednoosobowa działalność gospodarcza
ul. Kabacki Dukt 14 lok. 56
02-798 Warszawa, Poland
NIP: 8992922668 · REGON: 521728250
Email: privacy@novastorm.ai
Business/support phone: +48 571 943 884