Legal
Privacy Policy
Last updated: 16 June 2026 · Applies to regually.com and app.regually.com
This Privacy Policy explains how ReguAlly — the trading name of Michał Mackiewicz, a natural person established in Poland, as identified in the Legal Notice (“ReguAlly”, “the Operator”, “we”, “us”) — processes personal data as a controller: that is, the personal data of website visitors, of people who create or administer an account, of billing contacts, and of people who contact us.
Important scope note. The compliance content you and your colleagues put into the platform — your answers, uploaded documents and generated documents — is processed by us as a processor on your instructions, under our Data Processing Agreement. For that content, your organisation is the controller and its own privacy notice applies. This Privacy Policy does not govern that content.
1. Controller and contact
Controller: ReguAlly — Michał Mackiewicz, natural person, Poland; full details (address, NIP/REGON) in the Legal Notice. Contact for data protection: privacy [at] regually.com .
2. What we collect, why, and on what legal basis
| Personal data | Purpose | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Account data — name, work email, organisation, role, password (hashed) | Create and manage your account; authenticate you; provide the Services | Contract — Art. 6(1)(b) |
| Billing contact data — name, email, billing address, country, tax/VAT ID, payment metadata | Take and manage payment via our Merchant of Record; invoicing; fraud prevention | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) (fraud prevention) |
| Usage data — log data, device/browser info, feature usage, in-product events | Operate, secure and improve the Services; troubleshoot; measure product usage | Legitimate interests — Art. 6(1)(f) |
| Support data — the content of your messages and our correspondence | Respond to enquiries and provide support | Contract / legitimate interests — Art. 6(1)(b)/(f) |
| Website analytics — pseudonymous usage measurement (see §5) | Understand and improve our website | Legitimate interests — Art. 6(1)(f); no information stored on or read from your device (see §5) |
Website analytics (Google Analytics 4) — session and behaviour data, device identifiers, cookies _ga, _ga_* | Measure website traffic and visitor behaviour; content performance | Consent — Art. 6(1)(a); only activated after opt-in via cookie banner |
| Marketing data — email you give us to receive updates | Send you the updates you asked for | Consent — Art. 6(1)(a) |
We do not deliberately collect special-category data about visitors or account admins. Please do not send us such data through support channels.
3. Where your data comes from
Mostly from you directly. Usage and analytics data is generated automatically when you use our website or the Services. Billing data comes partly from you and partly from our Merchant of Record when you make a purchase.
4. Who we share it with
We share personal data only with service providers who process it on our behalf under contract, and with parties where we are legally required to. Our processors and their roles, locations and safeguards are listed in the DPA & Subprocessors document. They currently include our hosting and database provider, application-hosting provider, AI model provider, transactional-email provider, product-analytics provider, and our Merchant of Record for payments.
We do not sell personal data, and we do not share it for third-party advertising.
5. Cookies and analytics
Strictly necessary cookies. We use a small number of strictly necessary cookies and equivalent storage to keep you logged in, secure your session, and remember essential preferences (including your cookie consent choice). These are required for the website to function and do not require consent under Article 5(3) of the ePrivacy Directive.
Privacy-first analytics — PostHog (no consent required). We use PostHog (EU Cloud, Frankfurt) to understand how our website and product are used. PostHog runs in cookieless mode: it does not store or read any information on your device — no cookies, no localStorage, no sessionStorage. Visitor counts are derived from a short-lived server-side hash; IP addresses are not retained. Because no information is stored on or accessed from your device, this does not fall within Article 5(3) of the ePrivacy Directive and does not require consent. We rely on our legitimate interest in measuring and improving our website (Art. 6(1)(f) GDPR). PostHog processes data within the EU (Frankfurt); no personal data leaves the EEA.
Website traffic analytics — Google Analytics 4 (consent required). We use Google Analytics 4 to measure website traffic and visitor behaviour. GA4 sets cookies on your device (_ga, _ga_*) and sends data to Google LLC (US). This falls within Article 5(3) of the ePrivacy Directive and requires your prior consent. GA4 is disabled by default and is only activated if you opt in via our cookie banner. You can withdraw consent at any time through the Cookie preferences control in the footer. Where data is transferred to the US, Google LLC is certified under the EU–US Data Privacy Framework; processing is governed by Google’s data processing terms. Analytics cookies are stored for up to 2 years and can be deleted via your browser settings at any time.
Managing your preferences. You can change your cookie choices at any time via the Cookie preferences control in the footer of our website, and through your browser settings. See our Cookie Policy for full details.
6. Electronic communications and marketing
Service messages. We send you operational messages necessary to provide the Services (for example account, security, billing and important service notices). These are part of the Services and are not marketing.
Marketing messages. We send commercial or marketing messages by electronic means only where you have given prior consent, and you can withdraw that consent or unsubscribe at any time using the link in each message or by contacting privacy [at] regually.com .
7. International transfers
Where a recipient processes personal data outside the European Economic Area, we ensure an appropriate safeguard is in place under Chapter V GDPR — typically the EU–US Data Privacy Framework (for certified US recipients) and/or the European Commission’s Standard Contractual Clauses, with supplementary measures where needed. The applicable mechanism for each subprocessor is shown in the DPA & Subprocessors document. You can request a copy of the relevant safeguards at privacy [at] regually.com .
8. How long we keep it
We keep personal data only as long as necessary for the purposes above:
- Account & usage data: for the life of your account and then up to 12 months after closure, unless a longer period is needed to resolve disputes or meet legal obligations.
- Billing/tax records: for the statutory retention period applicable in our jurisdiction (typically 6–10 years).
- Support data: up to 24 months after the matter is resolved.
- Marketing: until you unsubscribe or withdraw consent.
9. Your rights
Subject to the conditions in the GDPR, you have the right to: access your data (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction (Art. 18); data portability (Art. 20); and objection to processing based on legitimate interests (Art. 21), including direct marketing. Where we rely on consent, you may withdraw it at any time without affecting prior processing (Art. 7(3)).
To exercise any right, contact privacy [at] regually.com . We will respond within one month (Art. 12(3)). You also have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA country where you live or work or where the issue arose. Our lead supervisory authority is the Polish President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych — UODO), ul. Stawki 2, 00-193 Warsaw.
10. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing within the meaning of Art. 22 GDPR. AI features that generate documents and analyses are tools used under human control; their nature and limits are described in the AI Terms.
11. Security
We use appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, access controls, and hosting in the EU/EEA region. No system is perfectly secure; we maintain procedures to detect and respond to incidents.
12. Children
The Services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18.
13. Changes
We may update this Policy. We will post the new version with a revised date and, for material changes, notify account admins by email.