Last updated: 2026-05-25
K0nsult CNC is committed to protecting your privacy. We do not use third-party tracking tools, do not sell your data, and process only the minimum information necessary to provide our services. K0nsult provides independent audits of AI systems as paid services (packages and pricing at /audyt).
K0nsult uses Anthropic Claude (a large language model) to classify incoming messages, support users, and generate audit-related content. Any content produced by AI is labelled "π€ AI-generated". A human supervises all AI output (human-in-the-loop): no decision affecting your rights is fully automated. AI is used as an assistive tool only; the final responsibility for every audit deliverable and every decision rests with a human auditor.
Automated decision-making (Art. 22 GDPR): K0nsult does not take decisions based solely on automated processing β including profiling β that produce legal effects concerning you or similarly significantly affect you, without human oversight. This is consistent with Art. 22 GDPR and Art. 14 of the EU AI Act (human oversight of high-risk AI systems).
The data controller responsible for your personal data is:
When you submit our contact form, we collect:
K0nsult uses server-side request logs only for usage analytics. No third-party analytics scripts, tracking pixels, or advertising cookies are used. Specifically, we record:
No cookies are set for analytics purposes. No third-party pixels (Google Analytics, Facebook Pixel, etc.) are loaded. If a privacy-friendly, cookie-free analytics tool is used in the future (e.g., Plausible.io β EU-hosted, no cookies, no cross-site tracking), this policy will be updated accordingly. This data cannot be used to identify individual users.
We process your personal data for the following purposes:
Under the General Data Protection Regulation (GDPR), we process your data on the following legal bases:
You may request deletion of your personal data at any time by contacting us at kontakt@k0nsult.cloud.
During the free pilot phase, when you request an independent audit of an AI system, we process the following categories of data:
Legal basis: Art. 6(1)(b) GDPR (performance of a contract / pre-contractual measures at your request).
Retention: Pilot audit records are retained for 7 years to satisfy audit documentation requirements (ISO 42001). After the pilot ends, data is anonymized and may be used for research and development. You may request deletion of your data at any time at kontakt@k0nsult.cloud.
Under GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, contact us at kontakt@k0nsult.cloud. We will respond within 30 days.
We use only essential cookies and localStorage for the following purposes:
We do not use:
We use the following sub-processors to provide our services:
We do not sell, trade, or otherwise transfer your personal data to third parties for their own purposes. Your data is used solely by K0nsult CNC and the sub-processors listed above for the purposes described in this policy.
Your data is stored and processed within the European Union:
Our services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately.
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Any updates will be posted on this page with a revised "Last updated" date. We encourage you to review this page periodically.
If you believe that our processing of your personal data violates GDPR, you have the right to lodge a complaint with the supervisory authority:
UrzΔ
d Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
uodo.gov.pl
You may also lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
| Sub-processor | Purpose | Location | Data / Certifications |
|---|---|---|---|
| Fly.io Inc. | Application and database hosting | Frankfurt, EU | All data; SOC2 Type II |
| Anthropic | AI inference (Claude) | USA | Prompts + responses; SOC2 Type II, no training on customer data |
| Stripe Inc. | Payment processing | USA/EU | Payment data; PCI DSS Level 1, SOC2 |
| LH.pl | SMTP/IMAP email | Poland, EU | Email headers + content |
| Let's Encrypt | TLS certificates | USA | No personal data |
| Plausible.io | Analytics (optional / not currently active) | Germany, EU | Anonymized data; cookie-free |
Contact for personal data protection matters: kontakt@k0nsult.cloud
Data Controller: K0nsult Sp. z o.o., KRS 0001239441, NIP 5253089872, ul. Aleja SolidarnoΕci 68/121, 00-240 Warsaw β kontakt@k0nsult.cloud
Under Art. 17 GDPR, you have the right to request deletion of your personal data.
For any questions or requests regarding this Privacy Policy or your personal data, please contact:
K0nsult Sp. z o.o.
KRS 0001239441 | NIP 5253089872 | REGON 544723272
ul. Aleja SolidarnoΕci 68/121, 00-240 Warsaw, Poland
Email: kontakt@k0nsult.cloud
A Data Processing Agreement is available upon request for enterprise clients.
Sub-processor changes: Clients will be notified 30 days before any new sub-processor is added. Clients may object within 14 days.
DPA includes: Standard Contractual Clauses (SCCs), technical and organizational measures (TOMs), breach notification obligations.
To request a DPA: kontakt@k0nsult.cloud
K0nsult maintains a documented incident response procedure covering:
Report a security incident: security@k0nsult.cloud
Emergency contact available 24/7 for P1 incidents