Privacy Policy
This Privacy Policy applies to people who use the Heroify platform as Clients (companies and organizations purchasing services) and Users (recruiters, managers, account administrators), as well as to people who contact Heroify and visitors to heroify.co.
If you are a Candidate/Participant taking part in a competency assessment, please read the separate Privacy Policy for Candidates/Participants: https://heroify.co/privacy-policy-candidates.
1. Controller of personal data
The controller of your personal data is Heroify sp. z o.o. with its registered office in Warsaw, ul. Padewska 23/7, 00-777 Warsaw, Poland, KRS: 0000903229, NIP: 5213930518 (hereinafter: Heroify, we).
In relation to Clients and Users, Heroify is the data controller. In relation to Clients' candidates, Heroify acts as a rule as a processor on the Client's behalf, under the Data Processing Agreement (DPA): https://heroify.co/dpa.
Contact for data protection matters: gdpr@heroify.co. Postal address: Heroify sp. z o.o., ul. Padewska 23/7, 00-777 Warsaw, Poland.
2. Who this Policy applies to
This Policy governs the processing of personal data of:
- people representing Clients and billing contacts,
- Users of the platform acting on behalf of a Client,
- people contacting Heroify about sales, support, or in connection with webinars and materials,
- visitors to heroify.co, including people using the public tools on the site.
This Policy doesn't govern the processing of Candidates'/Participants' data. That is described in the Privacy Policy for Candidates/Participants.
3. What data we collect
3.1. Data you provide when creating an Account and using the platform: first name (and last name, if you provide it), work e-mail address, password (stored only as an irreversible hash), organization name, job title, role in the platform, answers to a short sign-up survey (e.g. company size, purpose of use), the content of support requests.
3.2. Billing data (from 22 September 2026): company name and address, country, tax ID (NIP) or EU VAT number (or a declaration of business status for entities outside the EU), e-mail address for invoices, first and last name of the person making the purchase, purchase and invoice history, payment status. You provide your payment card details directly to the payment operator Stripe; Heroify neither sees nor stores them.
3.3. Data collected automatically: IP address and connection data, browser type and version, operating system, data on how you use the platform (screens visited, session duration, actions performed), session identifiers, system and diagnostic logs, cookies (Section 10).
3.4. Data from external sources: contact details from publicly available business sources (e.g. professional profiles on services such as LinkedIn) solely for the purpose of establishing B2B cooperation, on the basis of Heroify's legitimate interest. We provide information about the processing (Article 14 GDPR) at the first contact, no later than one month after obtaining the data. You can request their deletion at any time.
3.5. Data from public tools on the site: if you use the "Assessment Method Recommender", we process the content you enter (e.g. a job description) and the technical logs of the request, in order to generate the recommendation and maintain the tool (Article 6(1)(f) GDPR). The content is passed to the language model provider without your identifying data and is not used to train models. We delete the entered content and logs after 30 days. Don't enter other people's personal data there; if such data is entered, we delete it on request (gdpr@heroify.co).
4. Purposes and legal bases of processing
We process only the data necessary for specific purposes (the data minimization principle, Article 5(1)(c) GDPR). Providing the data marked as required at sign-up and purchase is a condition of concluding the contract and using the platform; providing the remaining data (e.g. answers in the sign-up survey, consent to the newsletter) is voluntary.
| Purpose | Legal basis |
|---|---|
| Concluding and performing the contract: creating and maintaining the Account, providing the platform services, system and onboarding communication | Article 6(1)(b) GDPR, when you are a party to the contract (e.g. you are a sole trader); Article 6(1)(f) GDPR, when you act on behalf of an organization that is the Client (our and the Client's legitimate interest in performing the contract) |
| Handling purchases: collecting payment, tax verification (VIES), handling complaints | Article 6(1)(b) GDPR, when you are a party to the contract; Article 6(1)(f) GDPR, when you make a purchase or are the invoice contact on behalf of an organization |
| Issuing and storing invoices, tax and accounting settlements | Article 6(1)(c) GDPR (tax and accounting regulations) |
| Customer service and technical support | Article 6(1)(b) GDPR, when you are a party to the contract; Article 6(1)(f) GDPR, when you submit a request on behalf of an organization |
| Platform security and abuse prevention (monitoring, detecting unauthorized access, protecting Clients' and candidates' data) | Article 6(1)(f) GDPR |
| Analyzing how the platform is used and product development (product analytics, sign-up survey) | Article 6(1)(f) GDPR |
| Marketing: newsletter and contact with new people | consent (Article 6(1)(a) GDPR) and the consent required by electronic communications regulations; can be withdrawn at any time |
| Marketing: information about new features and similar services to existing Clients | Article 6(1)(f) GDPR; sent by e-mail only after the consent required by electronic communications regulations; you can object or withdraw consent at any time |
| Establishing and defending legal claims | Article 6(1)(f) GDPR |
| Handling your rights and our obligations towards public authorities | Article 6(1)(c) GDPR |
5. Automated decision-making and profiling
Heroify doesn't make automated decisions about Clients or Users that produce legal effects or similarly significant effects (Article 22 GDPR). Decisions concerning the business relationship are made by people.
We may analyze how the platform is used in order to improve it and tailor our messages. Technical rules, such as blocking sign-ups from addresses in public e-mail domains or holding a purchase until the EU VAT number is verified, are not decisions within the meaning of Article 22 GDPR; if you run into a problem, contact us.
The artificial intelligence systems on the platform are used to evaluate the answers of Candidates/Participants, not Users. You'll find their description in the Privacy Policy for Candidates/Participants and on the AI information page: https://heroify.co/ai.
6. Who we share your data with
We use the services of entities that process data on our behalf (processors) and of entities that are separate controllers:
- Processors (categories): hosting provider (servers in the EU), system e-mail provider, product analytics provider (EU), error monitoring provider, traffic protection and CDN provider, internal communication tool for handling requests, CRM system, newsletter tool, webinar platform, website analytics tool (after consent), language model provider (for the public "Assessment Method Recommender" and for features supporting Assessment configuration on the platform: suggestions of job level, competencies and questions based on the job description and organization values entered by the User; without Account data and without candidate data), providers of AI tools supporting the work of the Heroify team (e.g. organizing sales inquiries and correspondence; without using the data to train models), invoicing system, accounting firm to the extent of keeping our books on our behalf.
- Separate controllers: payment operator (in respect of payment data), the European Commission (VIES system, EU VAT verification), law firms and advisors to the extent necessary to handle a specific matter.
- Public authorities: only where required by a legal obligation.
We provide information about specific recipients on request (gdpr@heroify.co). The Sub-processors of Candidates'/Participants' data are listed in the List of Sub-processors attached to the DPA, made available to Clients when they accept the DPA and on request.
7. Data transfers outside the EEA
The Platform's main infrastructure (application and databases) is located on servers in the European Union. Some providers (including traffic protection, system e-mail, error monitoring, payments, website analytics and the language model) may process data in the USA. In each such case we base the transfer on a European Commission adequacy decision (Article 45 GDPR; the EU-US Data Privacy Framework for certified US providers) or on Standard Contractual Clauses (Article 46 GDPR), together with a transfer impact assessment. We provide a copy of the safeguards applied on request. Details for each provider are contained in a list made available on request.
8. How long we keep data
| Category | Period |
|---|---|
| Account and User data | For the duration of the contract. An Account that no User has logged into for 24 months and that has no active Subscription or valid units may be closed after two e-mail notifications, 60 and 30 days in advance (Terms and Conditions § 4.12) |
| Account not confirmed after sign-up | Up to 30 days from sign-up |
| Billing data, invoices, payment history | For the period required by tax and accounting regulations: 5 years from the end of the calendar year in which the tax payment deadline expired (legal obligation; not subject to earlier deletion on request) |
| Sales and support correspondence | 3 years from the last contact |
| Data of potential clients (leads) where no contract is concluded | 24 months from the last contact |
| Marketing data based on consent | Until consent is withdrawn |
| Analytics data and technical logs | Server logs and error reports up to 30 days; language model request logs (metadata and the content of the query, which contains no identifying data) up to 90 days; product analytics on the platform up to 12 months; website analytics up to 2 months |
| Data necessary to defend legal claims | Until the limitation period for the relevant claim expires, only for data covered by the dispute |
You can request deletion of your User account by writing to contact@heroify.co; this doesn't close the organization's Account, which its administrator can request in accordance with the Terms and Conditions (contact@heroify.co). We'll delete the data within 30 days, except for data we must keep under the law (e.g. invoices) or in connection with an unresolved dispute. Candidates'/Participants' data entrusted by your organization is deleted in accordance with the DPA (after the contract ends and the export window expires, Section 9 of the DPA).
9. Data security
We apply technical and organizational data protection measures appropriate to the risk, including encryption, access control and separation of organizations' data. We'll inform you of a personal data breach that may result in a high risk to your rights in accordance with the GDPR.
10. Cookies
The Platform and the heroify.co website use cookies and similar technologies:
- Necessary: maintaining the session, security, remembering settings. They don't require consent.
- Analytics: website visit statistics and product analytics on the platform. We run these scripts only after you give consent in the cookie banner; without consent, or after it is withdrawn, they don't collect events. You can change your consent at any time in the cookie settings.
- Security and diagnostics: bot protection and error reports (message, page address without parameters, browser, technical identifier; without field contents, cookies or IP address). We don't record sessions. They are necessary for the secure operation of the service.
You'll find detailed information about individual cookies and their lifetime in the cookie settings on the site.
11. Your rights
You have the right to: access your data and obtain a copy (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), portability of data processed on the basis of a contract or consent (Article 20), object to processing based on legitimate interest, including marketing (Article 21), and withdraw consent at any time without affecting earlier processing.
To exercise your rights, write to gdpr@heroify.co. We respond without undue delay, at the latest within one month; in complex cases we may extend this period by a further two months, in which case we'll inform you within the first month together with the reason. You can also lodge a complaint with the President of the Personal Data Protection Office (UODO) (ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland, uodo.gov.pl).
12. Changes to this Policy
We may update this Policy as our services develop and the law changes. We inform you about changes concerning how your data is processed before they take effect. The date of the last update is given at the beginning of the document. The Polish version prevails in the event of any discrepancy with the English version.
13. Contact
E-mail: gdpr@heroify.co Address: Heroify sp. z o.o., ul. Padewska 23/7, 00-777 Warsaw, Poland Website: https://heroify.co