Privacy Policy
This policy explains how Dawid Tomaszewicz, operator of VORKIVO (“we”), handles personal data.
1. Our roles
For account, website, support and service-administration data, VORKIVO generally acts as controller. For personal data a business user enters about its own customers, the business user generally acts as controller and VORKIVO as processor under the DPA. Paddle handles buyer/payment data as Merchant of Record under its own terms.
2. Data
We may process account email and identifiers; business settings; customer, quote, job, invoice and expense information entered by users; support messages; subscription/license metadata; technical/security logs; preferences; and content intentionally sent to VorkiBot. We do not need or intend to receive full payment-card numbers; Paddle handles payment processing.
3. Why we process it
We process data to create and secure accounts, provide and synchronize features, manage access, respond to support, prevent abuse, diagnose problems, comply with law and establish or defend claims. Where GDPR applies, bases may include contract, legitimate interests, legal obligation, consent where requested, or a customer's documented instructions.
4. AI
When VorkiBot is used, the submitted message and limited app context may be sent to our AI provider. Do not intentionally include sensitive data, card data, credentials or secrets.
5. Providers
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database and backend infrastructure. |
| Cloudflare | Application delivery, network and security infrastructure. |
| Resend | Transactional account email. |
| OpenAI | VorkiBot processing when used. |
| Paddle | Merchant of Record, checkout, subscriptions and billing. |
6. International transfers
Providers may process data outside the EEA. Where required, legally recognized transfer mechanisms and contractual or other safeguards are used.
7. Retention
We retain data only as reasonably necessary for service, security, legal, accounting and dispute purposes. Customer Content may remain temporarily in backups after deletion.
8. Security
We use measures designed to protect data, including authenticated access, access controls, encrypted network transport and database security controls. No online service can guarantee absolute security.
9. Rights
Depending on location, you may have rights of access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a supervisory authority. If your data was entered by a VORKIVO business user, contact that business first; we will assist it where required.
10. Children
VORKIVO is a business service and is not intended for children.
11. Contact
Controller/operator: Dawid Tomaszewicz, ul. Kasztanowa 10/10, 55-010 Święta Katarzyna, Poland.
Privacy requests: support@vorkivo.com