Privacy Policy
Last updated: 7 August 2026
This Privacy Policy explains how we collect, use and protect personal data in connection with the Prezzly service, available at prezzly.ai and related domains (app.prezzly.ai, api.prezzly.ai). It has been prepared in accordance with Regulation (EU) 2016/679 (GDPR).
Please read this Policy before using the Service. Capitalised terms (such as Service, User, Content, Guest Account) have the meaning given to them in the Terms of Service.
1. Data controller
The controller of personal data is:
- TAG CONCIERGE Spółka z ograniczoną odpowiedzialnością
- ul. Józefa Sarego 18/1, 31-047 Kraków, Poland
- KRS: 0001056414, NIP (VAT): 6762650811, REGON: 526317480
- Contact address for data protection matters: [email protected]
(the “Controller”, “we”, “us”).
We have not appointed a Data Protection Officer, as we are not required to do so. For all data protection matters, please contact us at the address above.
2. Two roles of the Controller - when we process data “on your behalf”
This distinction is key to understanding the whole Policy:
- We act as the controller where we determine the purposes and means of processing - this covers account data, sign-in, plan and usage limits, security, communication and the contact form. These cases are described in this Policy.
- We act as a processor (and you are the controller) with respect to personal data that you place in the Content you upload to the Service (presentations, dashboards, audience questions). You decide about that data and you are responsible for the legal basis for processing it. The rules of this entrustment are set out in the Data Processing Agreement (DPA), which is an annex to the Terms of Service.
3. What data we process, for what purposes and on what legal basis
3.1. Account and authentication
- Scope: email address, name or display name (if provided), identifiers at the sign-in provider, sign-in method (email, magic link, Google, Microsoft, SSO).
- Purpose: creating and operating the account, enabling sign-in, providing the Service.
- Legal basis: Art. 6(1)(b) GDPR (performance of the contract for the Service).
3.2. Guest Account (upload without registration)
- Scope: technical guest identifier stored in a cookie (
prezzly_guest_uid), a synthetic (system) email address, uploaded files. - Purpose: enabling upload and sharing of Content without an account, and later transfer (claim) of that Content by a registered User.
- Legal basis: Art. 6(1)(b) GDPR (steps prior to entering into a contract and provision of the Service) and Art. 6(1)(f) GDPR (our legitimate interest in operating the registration funnel).
- Important: Guest Account Content is time-limited. The view link is valid for 72 hours and the management (claim) link for 7 days. After that, unclaimed Content and orphaned Guest Accounts are automatically and permanently deleted.
3.3. User Content
- Scope: HTML files and assets (presentations, dashboards), speaker notes, titles, folder structure, revision history. This Content may contain personal data of third parties if the User places it there.
- Purpose: storing, serving and sharing Content in accordance with the Service.
- Role and basis: here we act as a processor under the DPA. The controller of that data is the User.
3.4. Sharing and audience questions (pins / Q&A)
- Scope: audience questions and comments, an optional signature/nickname, association with a presentation session.
- Purpose: the feature for collecting questions and interacting with the audience.
- Role: data entered by the audience as part of User Content is processed by us as a processor on behalf of the User running the presentation.
3.5. Technical data and security
- Scope: IP address, browser/device information, request logs, live presentation session events (WebSocket relay), open counters.
- Purpose: ensuring security, preventing abuse (rate limiting, bot protection), diagnostics and maintenance of the Service.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security and stability of the Service).
3.6. Contact form
- Scope: email address, phone number (optional), message content.
- Purpose: handling the enquiry and replying to it.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries) and, where it leads to a contract, Art. 6(1)(b) GDPR.
3.7. API keys and MCP access
- Scope: generated API keys, association with the account, scope and time of use.
- Purpose: enabling access to the Service through a programmatic interface (including the MCP server used by AI tools acting on behalf of the User).
- Legal basis: Art. 6(1)(b) GDPR (performance of the contract).
3.8. Claims and legal obligations
- Purpose: establishing, pursuing or defending claims and complying with legal obligations (e.g. responding to justified requests from authorities, handling reports of illegal content under the Digital Services Act - DSA).
- Legal basis: Art. 6(1)(c) GDPR (legal obligation) and Art. 6(1)(f) GDPR (legitimate interest).
4. Analytics and marketing
As at the date of publication of this Policy, we do not carry out marketing tracking or extensive behavioural analytics in the Service, other than a basic counter of opens of shared Content. We do not use marketing or analytics cookies, we do not build advertising profiles and we do not share cookie data for marketing purposes. If we introduce such tools in the future, we will update this Policy and - where the law requires it - ask for consent (e.g. through a cookie consent banner).
5. Recipients and processors (subprocessors)
To provide the Service we use trusted providers that process data on our behalf or as independent controllers:
| Provider | Role / scope | Transfer notes |
|---|---|---|
| Cloudflare, Inc. | Cloud infrastructure: hosting of the application and API, database, file storage (R2), live sessions, abuse protection, sending emails. | US entity. Content file storage is configured in the European Union jurisdiction. Transfer based on the safeguards referred to in section 6. |
| Clerk, Inc. | Authentication and sign-in management (email, magic link, Google, Microsoft, SSO). | US entity. Transfer based on the safeguards referred to in section 6. |
| Sign-in providers (Google, Microsoft) | Authentication, if you choose to sign in with their account. They act as independent controllers for their own services. | Governed by their own privacy policies. |
We provide an up-to-date list of processors on request sent to the contact address. Data may also be disclosed to authorised authorities where required by law.
6. Transfers outside the European Economic Area (EEA)
Some of our providers (Cloudflare, Clerk) are based in the United States, which may involve a transfer of data outside the EEA. Such transfers take place on the basis of the mechanisms provided for in Chapter V GDPR, in particular:
- a European Commission adequacy decision (Data Privacy Framework), where the provider is certified under it, or
- Standard Contractual Clauses (SCC) approved by the European Commission, together with additional safeguards.
We store Content files in infrastructure configured for the European Union jurisdiction in order to limit the scope of transfers.
7. Data retention
- Account data: for the duration of the account. After account deletion we delete or anonymise the data within a reasonable period, except for data necessary to establish or defend claims, which we retain until the relevant limitation periods expire.
- User Content: for the duration of the account or until deleted by the User. After account deletion, Content is deleted within a reasonable period.
- Guest Account Content: as set out in section 3.2 - view link 72 hours, management link 7 days; after that, unclaimed Content and orphaned Guest Accounts are deleted automatically.
- Technical data and security logs: for the period necessary for security and diagnostics, usually no longer than 12 months, unless a longer period is justified by a specific incident or claim.
- Contact form: for the time necessary to handle the enquiry and then for evidentiary purposes, no longer than 12 months after the correspondence ends, unless it develops into a contractual relationship.
Accounts and Content may also be deleted in connection with account inactivity or discontinuation of a plan, on the terms described in the Terms of Service - always with prior notice.
8. Your rights
To the extent that we are the controller of your data, you have the right to:
- access your data and obtain a copy,
- rectify your data,
- erase your data (“right to be forgotten”),
- restrict processing,
- data portability,
- object to processing based on legitimate interest,
- withdraw consent at any time (where processing is based on consent) - without affecting the lawfulness of processing before withdrawal.
To exercise these rights, write to [email protected]. We respond without undue delay and no later than within one month (extendable in accordance with the GDPR).
If personal data is contained in Content uploaded by a User and you are not that User, the controller of that data is the User. We will forward your request to the relevant User or - if needed - help you identify the relevant controller.
You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warszawa.
9. Provision of data is voluntary
Providing data is voluntary but necessary to use the Service or its individual features. Without account data it is not possible to create an account and use features available to signed-in Users.
10. Automated decision-making
We do not make decisions about you based solely on automated processing, including profiling, that would produce legal effects concerning you or similarly significantly affect you. Automated mechanisms (e.g. rate limiting, bot protection, automatic deletion of expired Guest Content) serve solely the security and maintenance of the Service.
11. Security
We apply appropriate technical and organisational measures to protect data, including encryption of transmission (HTTPS), access control, isolation of served Content in a sandbox environment, and secret management. However, no method of transmission or storage is 100% secure - the rules on liability and the obligation to make your own backups are set out in the Terms of Service.
12. Cookies
The rules for using cookies and similar technologies are described in a separate Cookie Policy. The Service uses only cookies necessary for its operation (session, Guest Account association, authentication).
13. Changes to this Privacy Policy
We may amend this Policy, in particular where the law, our providers, the scope of data or the features of the Service change. We will inform you of material changes in the Service or by email with appropriate advance notice. The current version is always available at the address where the Policy is published, with the date of the last update.