Legal document

Privacy Policy

VARDIC – Greenwashing analysis system  |  Version 1.0  |  June 2026

Unofficial translation. This is an English translation of the VARDIC Privacy Policy provided for convenience. The Polish-language version is the authoritative, legally binding text; in case of any discrepancy, the Polish version prevails. This translation is pending confirmation by Kałużna Legal. Read the authoritative version: Polityka Prywatności (PL).

1. Who we are and who is the controller of your data

The provider of the VARDIC system

The provider of the VARDIC system is the law firm Kałużna Legal, run by attorney-at-law (radca prawny) Roksana Kałużna-Bałazy ("Kałużna Legal", "we"). Kałużna Legal is the author of the analytical methodology on which the VARDIC system is based.

Who is the controller of your data

The controller of the personal data processed in connection with the use of the VARDIC system is the implementing entity, i.e. the company or organisation that has deployed VARDIC and given you access to the tool (your employer or service provider). It is the implementing entity that decides on the purposes and means of processing your data.

Kałużna Legal acts as a processor within the meaning of Art. 4(8) GDPR – it processes data solely on the documented instructions of the implementing entity and only to the extent necessary to provide the VARDIC service.

Important: For matters concerning the processing of your personal data by the implementing entity (your employer or the system operator), contact that entity directly or its Data Protection Officer. Kałużna Legal's contact details are in section 10 of this policy.


2. What data we process and where it comes from

In connection with the operation of the VARDIC system, the following categories of data may be processed:

Data category Description Source
User account data First name, surname, e-mail address, organisation name, role in the system Provided by the implementing entity or by the user at registration
Data entered for analysis The content of communications, marketing materials or reports submitted for analysis by the user Directly from the user
Technical data and logs IP address, session identifier, date and time of login, device and browser data Automatically, during use of the system
System usage data Analysis history, results generated by the system, user queries Generated in the course of using the system

Reminder: Only publicly available communications and marketing materials should be entered for analysis. Do not enter personal data (e.g. names, addresses, national ID numbers) or information constituting a trade secret. See section 8 for more.


3. The purposes and legal bases for processing your data

Purpose of processing Legal basis (GDPR)
Providing the VARDIC service – performing greenwashing analyses Art. 6(1)(b) – performance of the contract concluded with the implementing entity; Art. 6(1)(f) – legitimate interest (provision of the service)
Managing user accounts and access to the system Art. 6(1)(b) – performance of a contract; Art. 6(1)(f) – legitimate interest
Ensuring system security and detecting abuse Art. 6(1)(f) – the controller's legitimate interest
Complying with legal obligations (including the AI Act and tax regulations) Art. 6(1)(c) – legal obligation
Improving and developing the system (solely in anonymised form) Art. 6(1)(f) – legitimate interest

We do not process users' personal data for marketing purposes, nor do we sell personal data to third parties.


4. Transfer of data to external AI providers

Processing by external language-model providers

The VARDIC system operates on external AI language models (LLMs). This means that the content of communications entered for analysis is sent to external AI model providers in order to generate results. Kałużna Legal carefully selects providers and concludes GDPR-compliant data processing agreements with them.

Current AI model providers

Provider Server location Basis for data transfer
Google Cloud (Vertex AI) European Union / EEA – europe-central2 region (Warsaw) No transfer outside the EEA – processing takes place exclusively within Google infrastructure located in the EU/EEA

The content of communications entered for analysis is processed by AI models exclusively within the European Union / European Economic Area (EEA) and is not transferred to third countries. Because processing takes place within the EEA, there is no data transfer requiring the safeguards under Art. 46 GDPR. Query data is not used to train AI models.

On-premises processing option

For organisations that require data to be processed solely on their own infrastructure (without sending content to external AI providers), an on-premises configuration is available. In this configuration, no data leaves the client's infrastructure. Contact us to learn more.

Other third parties

Data may also be transferred to:

  • providers of technical infrastructure and hosting (as processors),
  • providers of software supporting system security,
  • public authorities – only where required by applicable law.

Data is not sold or shared with third parties for marketing or commercial purposes.


5. How long we retain data

Data category Retention period
User account data For the duration of the contract with the implementing entity, and thereafter for up to 12 months after its termination, or until a deletion request is made
Analysis content and results In accordance with the implementing entity's configuration; by default 90 days (approx. 3 months) from the date of analysis. After a deletion request is made, data is anonymised and then permanently deleted after 30 days.
Technical data and system logs System logs (GCP Cloud Logging): up to 30 days. Other technical data linked to an analysis: up to 90 days, unless a longer period is required by law.
Data transferred to AI model providers In accordance with the provider's policy (Google) – query data is not used to train models and is not retained beyond the period necessary to fulfil the query and a short abuse-monitoring period
Data for accounting purposes 5 years in accordance with tax law

6. Your rights

To the extent that Kałużna Legal processes your personal data as a processor, the rights arising under the GDPR are exercised through the data controller, i.e. the implementing entity. For matters concerning these rights, contact the implementing entity or its Data Protection Officer.

You have the following rights:

Right Description
Right of access (Art. 15 GDPR) You can obtain information about which of your data is processed and for what purpose
Right to rectification (Art. 16 GDPR) You can request correction of inaccurate data or completion of incomplete data
Right to erasure (Art. 17 GDPR) You can request deletion of data where there is no basis for its further processing
Right to restriction of processing (Art. 18 GDPR) You can request restriction of processing in the cases specified in the GDPR
Right to data portability (Art. 20 GDPR) You can receive your data in a structured, commonly used format
Right to object (Art. 21 GDPR) You can object to processing based on legitimate interest
Right to lodge a complaint You can lodge a complaint with the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, www.uodo.gov.pl

The VARDIC system does not make solely automated decisions producing legal effects or similarly significantly affecting users within the meaning of Art. 22 GDPR. All analysis results are subject to mandatory human review.


7. Data security

Kałużna Legal applies appropriate technical and organisational measures to protect the processed data against unauthorised access, loss or destruction, including:

  • encryption of data in transit (TLS/HTTPS),
  • role-based access control,
  • monitoring and logging of access to the system,
  • security incident response procedures,
  • regular system security reviews.

In the event of a personal data breach, Kałużna Legal will promptly inform the data controller (the implementing entity) in accordance with the requirements of Art. 33 GDPR, enabling it to fulfil its obligation to notify the supervisory authority of the breach.


8. Sensitive data and trade secrets

The VARDIC system is not intended for processing personal data or confidential information. Only publicly available communications and marketing materials should be entered for analysis.

In particular, it is prohibited to enter into the system:

  • personal data – names and surnames, addresses, national ID (PESEL) numbers, contact details, identifying data of natural persons,
  • special categories of data (sensitive data) within the meaning of Art. 9 GDPR – including data on health, political opinions, and biometric data,
  • information constituting a trade secret – business strategies, non-public financial data, confidential information, data covered by non-disclosure agreements (NDAs),
  • data covered by professional secrecy – in particular attorney, legal-adviser or medical confidentiality.

The implementing entity is obliged to inform users of the above restriction and to implement appropriate organisational measures to prevent such data from being entered into the system.


9. Changes to this privacy policy

Kałużna Legal reserves the right to update this privacy policy, in particular in connection with changes to the law, to guidance from supervisory authorities, or to the functioning of the VARDIC system. We will inform implementing entities of material changes at least 14 days in advance. The current version of the policy is always available in the VARDIC system.


10. Contact

For matters relating to this privacy policy or to the processing of data by Kałużna Legal as a processor, please contact:

Kałużna Legal

Roksana Kałużna-Bałazy, attorney-at-law (radca prawny)

E-mail: [email protected]

Phone: (+48) 515 539 787

For matters concerning the processing of your data by the implementing entity (your employer or the system operator), contact that entity directly.