Legal Information
Privacy Policy and Cookies
This policy describes the rules for processing personal data and the use of cookies on the Supple Mental website, available at supplemental.pl.
1. Data Controller
The controller of personal data is the owner of Supple Mental, operating at: ul. Florianska 6, 03-707 Warszawa, Poland ("Controller"). Contact details are available in the Contact section.
2. Scope of Processed Data
Depending on how you use the website, the Controller may process the following categories of data:
- data provided in the contact form (e.g. name, surname, company name, email address, phone number, content of the enquiry);
- data transmitted during conversations with the AI agent (content of queries, responses provided, technical data necessary for chat operation);
- technical data related to use of the website (e.g. IP address, date and time of visit, cookie identifiers, browser and operating system information);
- other data voluntarily provided in correspondence with the Controller.
3. Purposes and Legal Bases for Processing
Personal data may be processed for the following purposes and on the following legal bases:
- responding to enquiries submitted via the form or email - Art. 6(1)(b) and (f) GDPR (actions at the request of the data subject, and the legitimate interest of the Controller in responding and maintaining correspondence);
- conclusion and performance of a contract for the provision of legal services - Art. 6(1)(b) GDPR;
- ensuring the operation of the website, its security and maintaining usage statistics - Art. 6(1)(f) GDPR (legitimate interest of the Controller);
- direct marketing activities via electronic communication - Art. 6(1)(a) or (f) GDPR in conjunction with applicable electronic communications legislation;
- establishment, pursuit or defence against claims - Art. 6(1)(f) GDPR.
4. Data Retention Period
Personal data will be processed for the period necessary to achieve the above purposes, and subsequently for the period corresponding to the limitation period for claims arising from applicable law. Data processed on the basis of consent will be processed until such consent is withdrawn.
5. Data Recipients
Personal data may be transferred to entities cooperating with the Controller in the operation of the website, in particular:
- hosting and IT service providers;
- Anthropic, PBC (San Francisco, USA) - provider of the Claude language model on which the AI Assistant is based, to the extent necessary to generate a response to the User's query;
- Cloudflare, Inc. (San Francisco, USA) - infrastructure provider (hosting, CDN, Workers), to the extent necessary for network traffic handling and security;
- entities providing accounting, legal and advisory services;
- public authorities - to the extent and on the terms specified by law.
6. Rights of the Data Subject
The data subject has rights under the GDPR, in particular:
- right of access to data and to receive a copy thereof;
- right to rectification (correction) of data;
- right to erasure ("right to be forgotten") in cases provided by law;
- right to restriction of processing;
- right to data portability;
- right to object to processing based on Art. 6(1)(f) GDPR;
- right to withdraw consent at any time - to the extent that data is processed on the basis of consent;
- right to lodge a complaint with the supervisory authority (in Poland: President of the Personal Data Protection Office - UODO).
7. Cookies and Similar Technologies
The website may use cookies and similar technologies (e.g. local storage) for the following purposes:
- ensuring proper functioning of the site and maintaining user sessions;
- ensuring security (e.g. detecting abuse);
- creating anonymous usage statistics;
- operating external tools, in particular the AI chatbot.
You can independently determine the conditions for storing or accessing cookies in your browser settings, including disabling them entirely. However, restricting the use of cookies may affect some functions available on the website.
8. Data Collection within the AI Chatbot (AI Assistant)
The AI Assistant available on supplemental.pl is based on the Claude language model, provided by Anthropic, PBC, based in San Francisco, USA. The intermediary infrastructure (backend) operates on the Cloudflare Workers platform.
8.1. Scope of Data Processed within the Chatbot
The following data is processed when using the AI Assistant:
- content of queries entered by the User;
- conversation history within a given session (maximum 10 recent messages, stored exclusively in the User's browser memory);
- IP address - processed by Cloudflare for technical and security purposes;
- technical metadata of the HTTP request (browser headers, timestamp).
8.2. Data Transfer to Anthropic
The content of the query and conversation history are transmitted to the Anthropic API (https://api.anthropic.com) solely for the purpose of generating a response. The Controller does not transmit to Anthropic any data identifying the User (e.g. email address, name, phone number). Anthropic processes data in accordance with its privacy policy and API data usage policy. According to Anthropic's declaration, data sent via the API is not used for model training.
8.3. International Data Transfers
Due to the location of Anthropic's servers (USA) and Cloudflare (global CDN), data may be transferred outside the European Economic Area. The transfer is carried out on the basis of Standard Contractual Clauses (SCCs) applied by Cloudflare and compliance mechanisms declared by Anthropic.
8.4. Retention Period
Conversation history is stored exclusively in the User's browser memory (JavaScript session) and is deleted upon closing the chat window or refreshing the page. The Controller does not save or archive the content of conversations conducted with the chatbot. Cloudflare Workers technical logs (without conversation content) may be retained for up to 72 hours.
8.5. Recommendations for Users
The chatbot is informational in nature and does not replace individual legal advice. It is recommended not to transmit special categories of data (e.g. health data), sensitive data, trade secrets or other confidential information via the chatbot. If you need to discuss the details of a specific case, please contact the Controller via the contact form or email.
9. Voluntary Nature of Providing Data
Providing data is voluntary; however, in some cases failure to provide data may prevent the Controller from responding to an enquiry or concluding a contract.
10. Changes to the Privacy Policy
This privacy policy may be updated periodically, in particular in the event of changes to legislation or changes to the way the website operates. The current version of the policy is always available in this section.