Privacy Policy
This Policy is effective as of November 12, 2025.
1. Personal Data Controller
The controller of your personal data is Digital Source Marcin Sadowski with its registered office in Warsaw (01-164), ul. Radziwie 3/67, NIP (Tax ID No.): 4990370530, REGON (National Business Registry No.): 320563942, contact e-mail: support@masterphrase.com (hereinafter: "Controller").
The Controller has not appointed a Data Protection Officer - in matters related to data protection, you can contact us at the e-mail address provided above.
2. Purposes and Legal Bases for Data Processing
We process personal data for the following purposes:
| Purpose of processing | Scope of data | Legal basis | Storage period |
|---|---|---|---|
| Account creation | name, e-mail, password | Art. 6(1)(b) GDPR | for the duration of the contract |
| Integration with Stripe payments | transaction data, invoice data | Art. 6(1)(b) and (f) GDPR | for the duration of the contract |
| Issuing invoices | billing data | Art. 6(1)(c) GDPR | for the period required by law (e.g., 5 years) |
| Communication and handling of inquiries | e-mail, content of correspondence | Art. 6(1)(f) GDPR | up to 3 years for evidentiary purposes |
| Marketing (if consent is given) | e-mail, preferences | Art. 6(1)(a) GDPR | until consent is withdrawn |
| Security and fraud prevention (system logs, login attempts, errors) | IP address, timestamps, user ID | Art. 6(1)(f) GDPR | up to 12 months |
| Generating, analyzing, or processing content using artificial intelligence (AI) | user-inputted content, contextual data | Art. 6(1)(b) and (f) GDPR | for the duration of the contract or until the completion of a given process |
The Controller processes only the data that is necessary for the stated purposes and stores it for no longer than is necessary for their fulfillment.
3. Data Recipients, Data Transfers outside the EEA, and Analytical Tools
Personal data may be transferred to trusted third parties, in particular to providers of technological services, payment systems, accounting services, and analytical and marketing tools that are necessary for the proper functioning of the MasterPhrase platform, infrastructure maintenance, billing, and analysis of the effectiveness of activities.
3.1 Categories of Data Recipients
Your data may be transferred to the following categories of recipients:
- Hosting and IT infrastructure providers - ensure the continuous and secure operation of the service (e.g., ADMIN.NET.PL S.C.),
- Payment system providers - for handling online payments and settlements (e.g., Stripe Technology Europe Limited),
- Accounting office - for the fulfillment of tax and accounting obligations,
- Providers of analytical and marketing tools - for traffic analysis, statistics, and campaign effectiveness (e.g., Google Analytics, Google Ads),
- Providers of artificial intelligence and voice/text processing services - if the user uses generative or voice functions (e.g., OpenAI, Google AI, ElevenLabs).
All data recipients process them only to the extent necessary to perform specific services for the Controller, in accordance with the concluded personal data processing agreements.
3.2 Analytical and Marketing Tools
The Controller uses analytical and advertising tools that may use cookies or similar technologies, only with the user's consent.
These are, in particular:
- Google Analytics (Google Ireland Ltd.) - used to analyze website traffic and user behavior; data is processed anonymously (IP addresses may be shortened),
- Google Ads (Google Ireland Ltd.) - allows for conducting advertising campaigns and measuring conversions.
The legal basis for processing data for these purposes is Art. 6(1)(a) GDPR (user consent). Consent can be given or withdrawn at any time through the consent management panel (CMP) available on the website.
3.3 Data Transfer outside the European Economic Area (EEA) and Data Location
Some of our technology partners have server infrastructure both within the European Economic Area (EEA) and outside of it (including in the United States). Therefore, in some cases, personal data may be transferred outside the EEA.
Data Storage in the EU
The data of MasterPhrase platform users is primarily processed and stored on servers located in the European Union or the European Economic Area, as long as it is technically possible and consistent with the configuration of our providers' services.
Our key technology partners offer infrastructure within the EU:
- Google Ireland Ltd. - processes data within infrastructure located in the EU (including Ireland, the Netherlands, Germany),
- Stripe Technology Europe Limited (Ireland) - handles payments within the European infrastructure,
- OpenAI Ireland Ltd. - enables data processing in the European region as part of the Data Residency in Europe option,
- ElevenLabs Inc. - offers the possibility of data processing in the EU region as part of a dedicated European infrastructure.
- Google Cloud / Google Vertex AI (Google Ireland Ltd.) - as part of the artificial intelligence functions, data may be processed using Google AI tools (e.g., Vertex AI, Gemini). The data is processed solely for the purpose of providing MasterPhrase services, based on a data processing agreement, is not used to train Google models, and is stored in an infrastructure compliant with GDPR, including in the European Union region.
Possibility of Data Transfer outside the EEA
In some cases, data may be transferred outside the EEA (e.g., to the United States) if it is necessary for the provision of services by the aforementioned providers or their subcontractors. In such a case, the data transfer takes place only with the use of appropriate legal safeguards, in particular:
- based on the European Commission's adequacy decision (Data Privacy Framework), or
- using standard contractual clauses (SCCs) adopted by the European Commission.
The Controller ensures that all data transfers are carried out with a high level of security and in accordance with the principles set out in Chapter V of the GDPR.
4. User Rights
You have the right to:
- access your data,
- rectify them,
- request their erasure ("right to be forgotten"),
- restrict processing,
- object to processing,
- data portability.
In matters concerning the exercise of your rights, you can contact us at the e-mail address: support@masterphrase.com. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) if you believe that the processing of your data violates the provisions of the GDPR. The exercise of rights may require user identity verification.
5. Consent and Withdrawal of Consent
If we process data on the basis of consent (e.g., for marketing), you can withdraw it at any time by contacting us at the e-mail address provided above. Withdrawal of consent may also occur by changing the settings in the consent management panel (CMP).
6. Obligation / Voluntariness of Data Provision
The provision of data is voluntary but necessary to conclude and perform the contract (creating an account, using the platform). Failure to provide data makes it impossible to provide services.
7. Cookies
The website uses cookies and similar technologies (e.g., Local Storage, Pixel). Cookies may be used for the following purposes:
- necessary for the operation of the service (e.g., login, session maintenance),
- analytical (e.g., Google Analytics),
- marketing (e.g., Google Ads).
The legal basis for processing data from cookies is the legitimate interest of the Controller for technical cookies (Art. 6(1)(f) GDPR) and the user's consent for analytical and marketing cookies (Art. 6(1)(a) GDPR).
A full description of the cookies used can be found in the consent management panel (CMP). Cookie data can be managed in the CMP panel or in your browser settings.
8. Security Measures
We care about the security of your data - we use SSL encryption, access control, strong password hashing, security monitoring, and other technical and organizational measures that ensure an appropriate level of protection. Security systems are regularly tested and updated to protect data against loss, unauthorized access, or disclosure.
The solutions applied take into account the principle of privacy by design and by default (Art. 25 GDPR).
9. Changes to the Policy
We reserve the right to change this privacy policy.
The current version is always available at https://masterphrase.com/docs/privacy-policy.