top of page

MIEJSCE.AI PRIVACY POLICY

§ 1. General provisions
  1. This Privacy Policy describes the principles of personal data processing in connection with the use of the Miejsce.ai website, available at https://www.miejsce.ai, as well as related forms, surveys, subpages, ordering and payment mechanisms and tools for providing services, hereinafter collectively referred to as the "Website".

  2. The privacy policy applies in particular to the processing of Users' personal data:

    • visitors to the Website,

    • completing the Survey,

    • sending photos of rooms, floor plans or other materials,

    • those placing orders,

    • making payments,

    • using Additional Services,

    • contacting the Administrator,

    • those submitting complaints,

    • expressing marketing consents,

  3. The Controller of personal data is: Krzysztof Czubaszek, conducting business activity under the name Usługi Informatyczne Krzysztof Czubaszek, with its registered office at: Rydygiera 12 lok. 25, 01-793 Warsaw, Masovian Voivodeship, NIP: 5242627337, REGON: 147312375, entered into the CEIDG, e-mail address: info@miejsce.ai, hereinafter referred to as the "Controller".

  4. Contact with the Administrator is possible:

    • electronically at the e-mail address: info@miejsce.ai,

    • in writing to the address of the Controller's registered office: Rydygiera 12 lok. 25, 01-793 Warsaw,

  5. The Administrator processes personal data in accordance with the GDPR, the Personal Data Protection Act, the Act on the Provision of Electronic Services, the Consumer Rights Act, the provisions on cookies and other relevant provisions.

  6. The Administrator takes special care to protect data related to photos of children's rooms, surveys regarding the child's functional needs and materials provided to generate the Visual Proposal.

  7. The website is not intended for children as direct users. Orders should only be placed by adults.

  8. The Privacy Policy should be read in conjunction with the Website Regulations, which define the rules for using the Website and providing Services.

§ 2. Most important privacy rules
  1. The Administrator adheres to the principle of data minimization. This means that the Administrator strives to process only the data necessary for a specific purpose, in particular for the provision of the Service, payment processing, contact, complaints, billing, security, or compliance with legal obligations.

  2. For the purposes of providing the Services, the User should not submit photos of the child, other persons, documents, addresses, medical data, school data, financial data or other information that is not needed to prepare the Arrangement Proposal.

  3. Before sending a photo, the User should remove, cover or crop any elements identifying persons or places, in particular images of persons, names and surnames, family photos, documents, correspondence, addresses, telephone numbers, medical data, school data, financial data, and other personal data of third parties.

  4. The Administrator does not require the provision of medical diagnoses, information about the child's health, or other specific categories of personal data. If the Survey includes questions about the functional needs of the room, please respond in a general manner, describing the design needs, for example, quietness, concentration, play, learning, storage, or limiting stimuli.

  5. Photos and other materials are processed primarily for the purpose of performing the Service, i.e. generating or developing an Arrangement Proposal.

  6. Photos, projections, Design Proposals and Client materials are not used for marketing purposes without a separate legal basis, in particular without the Client's voluntary consent, unless they have been effectively anonymized beforehand.

  7. The Administrator does not store full payment card details. Payments are processed by Stripe.

  8. Survey data, payment statuses, adaptation orders, promotional codes, uploaded photos and generated Design Proposals are technically stored on servers located within the European Economic Area (EEA).

  9. The Administrator does not sell Users' personal data.

  10. The Administrator may use the services of external suppliers, such as Wix.com Inc., home.pl, Stripe, Alphabet Inc., to the extent necessary for the operation of the Website and the provision of the Services.

§ 3. Definitions
  1. The terms used in the Privacy Policy have the meaning given to them in the Regulations, unless the Privacy Policy states otherwise.

    • Survey - a form completed by the User in order to prepare a Visual Proposal, including in particular the selection of a room, a motif or arrangement style, a bed arrangement, the scope of changes, the number of children, the age of the child or children, functional, color and aesthetic preferences and other parameters necessary to generate the Arrangement Proposal.

    • GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

    • Personal data - information about an identified or identifiable natural person.

    • Processing - operations on personal data, such as collecting, recording, storing, viewing, organizing, modifying, transmitting, making available, restricting, deleting or destroying.

    • User - a person using the Website, including a person visiting the website, completing a Survey, placing an order or contacting the Administrator.

    • Customer - User who has concluded an agreement with the Administrator for the provision of the Service.

    • Input materials - photos, projections, descriptions, dimensions, Survey responses, comments and other materials provided by the User for the purpose of providing the Service.

    • Arrangement Proposal - an image or set of images generated, processed or developed using AI tools based on the Input Materials.

§ 4. Technical infrastructure of the Website
  1. The website uses the following infrastructure and tools:

    • information page - Wix.com Inc.,

    • hosting provider - home.pl,

    • payments - Stripe,

    • Generating AI Arrangement Proposals - Gemini API,

    • sending emails - Gmail / Google Workspace.

  2. The Website may store in its database, in particular:

    • payment statuses of survey sessions,

    • session identifiers,

    • package names,

    • counters of generated images,

    • adaptation orders,

    • name, e-mail, telephone number, room dimensions and comments as part of adaptation orders,

    • promotional codes,

    • technical data needed to process orders.

  3. The server hosting the Website is physically located within the European Economic Area. However, this does not mean that all data processed within the Website always remains solely within the EEA, as the Administrator also uses external providers such as Google/Gemini API, Google Workspace, Wix.com Inc., and Stripe.

  4. Result documents, including graphical Arrangement Proposals, Arrangement Proposal Variants, "How to implement it?" documents and PDF files, may be technically saved on the server as result files associated with a given session, order or e-mail address of the User, to the extent necessary to perform the Service, make the results available to the Client, handle complaints and defend against claims.

  5. The Controller may change the technical infrastructure, service providers, file storage method, payment operator or AI tool provider if this is justified by technical, organisational or security reasons or a change in the service provision model.

  6. If a change in infrastructure has a significant impact on the processing of personal data, the Administrator will update the Privacy Policy or provide Users with appropriate information in another manner required by law.

§ 5. Categories of data processed
  1. The Administrator may process the following categories of personal data:

    • Service Outputs and Output Documents, such as graphical Design Proposals, Design Proposal Variants, "How to Make It Happen" Documents, PDF files, print files, generation history, theme name, description of the selected variant, and other digital materials created as part of the Service.

    • Output documents may also include textual, AI-generated or co-created descriptions of possible design actions, such as "How to implement it?", including general guidelines on colors, materials, workflow, furniture, lighting, decorations, textiles, wall elements, or other components of the concept.

    • Identification and contact data, such as name and surname; email address; telephone number, if provided; company details if the order is placed as an entrepreneur; billing address; other data required to process the order, invoice or contact.

    • Order data, such as the selected package; price; order date; payment status; session ID; order number, if any; contact history; information about the implementation of the Service; information about the number of images generated; information about promotional codes used.

    • Payment and billing data, such as payment status; transaction identifier; amount; currency; payment method to the extent provided by Stripe; invoice data; information needed to process refunds, where full payment card details are processed by Stripe and not by the Controller.

    • Survey data, such as: room selection, design theme or style, bed arrangement, scope of changes, number of children, age of the child or children, functional preferences, color preferences, storage, learning, play or relaxation needs, information about which elements of the room are to remain unchanged and which are to be changed, and other responses provided by the User in the form.

    • Input materials such as photos of rooms; floor plans; sketches; descriptions; graphic files; dimensional information; inspiration; other materials submitted by the User.

    • Data relating to adaptation orders, such as name and surname; e-mail address; telephone number; room dimensions; comments; plans; attachments; other information provided for the purpose of implementing the adaptation.

    • Arrangement Proposals and Service outputs, such as generated images; arrangement variants; output files; Proposal Descriptions; generation history; uploaded files.

    • Technical data, such as IP address; cookie identifiers; device data; browser data; operating system data; server logs; approximate location resulting from the IP address; information about activity on the Website; information about technical errors.

    • Communication data, such as the content of e-mail messages; the content of contact forms; the content of complaints; the content of inquiries; the Administrator’s responses; attachments sent in correspondence.

    • Marketing data, such as marketing consents; opinions; testimonials; consents to publish materials; communication preferences.

  2. The Administrator does not want or require the receipt of special categories of data, in particular data on the child's health, diagnoses, therapy, disability, judgments, biometric data or other sensitive information.

  3. If the User, despite the recommendations, provides data of special categories, the Administrator may process them only to the extent necessary to process the application, provide the Service, delete the data, secure claims or fulfill legal obligations, and the basis for processing may be, in particular, express consent, the need to establish, pursue or defend claims or another appropriate basis arising from the GDPR.

  4. The Administrator may delete, anonymize or omit materials containing excess personal data if they are not necessary to provide the Service.

§ 6. Purposes and legal basis of data processing
  1. The Controller processes personal data for specific purposes and on legal bases arising from the GDPR.

    1. Handling enquiries and pre-contractual contact:

      1. purpose: responding to a message, preparing an offer, explaining the rules of operation of the Website, handling questions concerning packages or Additional Services,

      2. scope of data: contact details, message content, technical data relating to correspondence,

      3. legal basis: Article 6(1)(b) GDPR, where the contact is aimed at entering into an agreement, or Article 6(1)(f) GDPR, i.e. the legitimate interest of the Controller consisting in conducting communication.

    2. Conclusion and performance of the agreement for the provision of the Service:

      1. purpose: accepting the order, processing payment, generating the Interior Arrangement Proposal, preparing the Proposal Description, providing Additional Services, delivering the results of the Service,

      2. scope of data: contact details, order details, Questionnaire data, Input Materials, Interior Arrangement Proposals, technical data,

      3. legal basis: Article 6(1)(b) GDPR.

    3. Processing photographs, floor plans and Questionnaires for the purpose of preparing the Interior Arrangement Proposal:

      1. purpose: analysing Input Materials, generating the Interior Arrangement Proposal, preparing the visual Proposal, adapting the result to the User’s preferences,

      2. scope of data: photographs, floor plans, dimensions, preferences, Questionnaire responses, technical prompt, generation result,

      3. legal basis: Article 6(1)(b) GDPR, because the processing is necessary for the performance of the agreement.

    4. Transferring a photograph of the room and Questionnaire data to AI:

      1. purpose: generating or developing the Interior Arrangement Proposal using AI tools,

      2. scope of data: photograph of the room, Questionnaire responses, description of preferences, technical prompt, and, where applicable, other information necessary to perform the Service,

      3. legal basis: Article 6(1)(b) GDPR, because the processing is necessary for the performance of the agreement, and, with respect to the organisation of the technological process, also Article 6(1)(f) GDPR.

    5. Processing payments via Stripe:

      1. purpose: accepting payment, confirming the transaction, handling refunds, preventing payment fraud,

      2. scope of data: transaction data, payment status, payment identifier, billing data, technical payment data,

      3. legal basis: Article 6(1)(b) GDPR, Article 6(1)(c) GDPR and Article 6(1)(f) GDPR.

    6. Issuing invoices and maintaining accounting records:

      1. purpose: fulfilling tax and accounting obligations,

      2. scope of data: identification data, billing data, transaction data,

      3. legal basis: Article 6(1)(c) GDPR.

    7. Handling complaints, withdrawal from the agreement and submissions:

      1. purpose: considering complaints, providing responses, fulfilling Client requests, handling possible refunds,

      2. scope of data: contact details, order details, content of the complaint, history of Service performance, files and Interior Arrangement Proposals, payment data,

      3. legal basis: Article 6(1)(b) GDPR, Article 6(1)(c) GDPR and Article 6(1)(f) GDPR.

    8. Establishment, exercise or defence of claims:

      1. purpose: protecting the legal interests of the Controller, the Client or third parties,

      2. scope of data: order details, correspondence, Input Materials, Interior Arrangement Proposals, logs, payment data,

      3. legal basis: Article 6(1)(f) GDPR.

    9. Ensuring the security and proper operation of the Website:

      1. purpose: keeping logs, preventing abuse, protecting against attacks, ensuring continuity of operation, diagnosing errors, protecting infrastructure,

      2. scope of data: IP address, logs, device data, browser data, error information, session data,

      3. legal basis: Article 6(1)(f) GDPR.

    10. Analytics and statistics concerning the operation of the Website:

      1. purpose: analysing visits, improving functionality, measuring the effectiveness of marketing activities, developing the Website,

      2. scope of data: cookie data, technical data, information about behaviour on the Website,

      3. legal basis: Article 6(1)(f) GDPR or the User’s consent, where consent is required for specific cookies or similar technologies.

    11. Controller’s own marketing:

      1. purpose: informing about services, promotions and news, where the User has given consent or where the communication falls within the Controller’s legitimate interest,

      2. scope of data: e-mail address, marketing consents, communication history,

      3. legal basis: Article 6(1)(f) GDPR or the User’s consent, where consent is required for electronic communication.

    12. Publication of reviews, portfolio, case studies or marketing materials:

      1. purpose: promoting the Website, presenting the results of the Service, building a portfolio,

      2. scope of data: content of the review, first name or pseudonym, Interior Arrangement Proposals, “before and after” materials, description of the result,

      3. legal basis: the User’s consent, Article 6(1)(a) GDPR, or the legitimate interest of the Controller, Article 6(1)(f) GDPR, where the materials have been effectively anonymised and do not concern an identified or identifiable person.

    13. Evidentiary and technical archiving:

      1. purpose: demonstrating the course of the order, the content of consents, the content of declarations, payment status and the proper performance of the Service,

      2. scope of data: session data, order details, logs, checkbox content, date and time of declarations,

      3. legal basis: Article 6(1)(f) GDPR.

    14. Preparation and provision of output documents, including Interior Arrangement Proposals, Variants of Interior Arrangement Proposals, “How to implement it?” Documents and PDF files:

      1. purpose: performing the Service, providing the results to the Client, enabling download, printing or saving as PDF, handling complaints and defending against claims,

      2. scope of data: Input Materials, Questionnaire data, photograph of the room, generated Interior Arrangement Proposals, textual implementation descriptions, PDF files, order details,

      3. legal basis: Article 6(1)(b) GDPR, and, with respect to complaints and defence against claims, also Article 6(1)(f) GDPR.

§ 7. Data regarding children and special needs
  1. The purpose of the Website is to provide services aimed specifically at arranging children's rooms or playrooms. However, the Website is not directed at children as direct users.

  2. Orders should be placed by adults, in particular parents or legal guardians.

  3. The Administrator does not require the child's name, surname, exact date of birth, child's image, child's documents, information about the school, address, health condition, diagnoses or therapy.

  4. If the Website asks about the child's age, preferred room function or functional needs, this data should be provided in a general scope, necessary to tailor the Arrangement Proposal.

  5. If the User wishes to indicate a child's specific needs, they should limit themselves to neutral and general arrangement information, such as the need for quiet, the need for a study space, the need for a play space, the need for reduced stimuli, the need for more storage, or the need for a flexible room layout.

  6. The User should not provide medical diagnoses, information about treatment, therapy, mental or physical condition of the child or other special categories of data for the purpose of executing the Arrangement Proposal.

  7. If such data is transferred, the Controller may delete, anonymize or process it only to the extent necessary to achieve the purpose for which it was transferred, in accordance with the GDPR.

  8. If the User notices that he or she has sent material containing data of a child or other person that is not needed to provide the Service, he or she should contact the Administrator to remove or restrict the processing of such material, if possible.

  9. The Administrator may process general information regarding the number of children and the age of the child(ren) solely for the purpose of tailoring the Visual Proposal to the room's function, the age of the room's occupants, the bed layout, and design needs. The Administrator does not require the provision of children's names, surnames, exact dates of birth, ID numbers, school details, medical data, or information about diagnoses or therapies.

§ 8. Technical requirements
  1. Personal data may be transferred to entities whose services the Administrator uses to run the Website and provide the Services, however, such transfer always takes place in compliance with the standards applicable to the Administrator and in accordance with the law.

  2. The recipients of data may be, in particular:

    1. Wix.com Inc. – provider of the Website's information page,

    2. home.pl - hosting infrastructure provider,

    3. Stripe - payment operator,

    4. Alphabet Inc. – provider of AI tools used to generate Arrangement Proposals, provider of email used for order processing and communication,

    5. Other IT service providers,

    6. security tool suppliers,

    7. accounting office,

    8. law firms and advisors,

    9. public authorities, if the obligation to provide data results from legal provisions.

  3. Entities processing data on behalf of the Controller should process data on the basis of appropriate personal data processing agreements or other appropriate legal bases.

  4. Some providers, in particular Stripe, Alphabet Inc., or Wix.com Inc., may act as independent controllers, joint controllers, or processors in certain areas. The exact role depends on the specific service, configuration, processing purpose, and the provider's documentation.

  5. Data transferred to external technology providers is limited to the extent necessary to achieve the specific purpose.

§ 9. Artificial Intelligence
  1. The Administrator uses the AI model prepared by Alphabet Inc., i.e. Gemini API, to generate or support the generation of the Arrangement Proposal or Proposal Description.

  2. In particular, the following data can be transferred to the AI model:

    1. photo of the room sent by the User,

    2. description of arrangement preferences,

    3. responses from the Survey,

    4. technical prompt,

    5. other information needed to generate the Arrangement Proposal.

  3. The Controller uses the AI model in an appropriate configuration to provide services to users from the European Economic Area, in particular in a paid model, if the terms of use of the AI model so require.

  4. The Administrator has configured the AI model in a way that limits the use of User data for purposes other than the provision of the Service, if such settings are available.

  5. The Administrator periodically verifies the terms of use of the AI model, data processing documentation, retention rules, transfer mechanisms and rules for using data to train or improve models.

  6. The User acknowledges that using the function of generating the Design Proposal requires the technical transfer of a photo of the room and information from the Survey to the AI model.

  7. The User should not send to the Website photos or descriptions containing sensitive data, medical data, images of children, documents, addresses or other information unnecessary for the provision of the Service.

  8. The output of an AI model may be nondeterministic. This means that similar inputs can lead to different outcomes, and the generated Arrangement Proposals may contain elements that are imperfect, distorted, inaccurate, or require human verification.

  9. The Administrator does not use the AI model to make decisions regarding the User that produce legal effects or similarly significantly affect the User within the meaning of Article 22 of the GDPR.

§ 10. Payment Services
  1. Payments on the Website are handled by Stripe.

  2. In connection with payment processing, Stripe may process, in particular, identification and contact data; transaction data; payment method data; data used to prevent abuse and payment fraud; technical data related to the transaction or information about payment refunds.

  3. The Administrator does not store the User's full payment card details.

  4. Stripe may act as an independent controller, joint controller or processor, depending on the specific scope of processing and payment service.

  5. Detailed rules for data processing by Stripe result from Stripe documents.

  6. You should refer to Stripe's documentation for detailed information on how Stripe processes data in connection with payments.

§ 11. Website and email
  1. The information page of the Website operates using the Wix platform.

  2. Wix.com Inc. may process technical data related to the use of the website, in particular IP address, cookie identifiers, information about the device, browser, activity on the website and other data necessary for the operation of the information website.

  3. The survey, ordering application, technical mechanisms for order fulfillment, database and user files run on servers belonging to home.pl.

  4. Alphabet Inc. Services may be used to send messages related to orders, complaints, customer service and communication with the User.

  5. Data sent by the Administrator may include the User's e-mail address, order data, message content and attachments.

  6. The Administrator limits the scope of data sent by e-mail to the data needed to handle a specific case.

§ 12. Transfer of data outside the European Economic Area
  1. Some of the data is processed within the European Economic Area, in particular data stored on home.pl servers physically located in Germany.

  2. However, personal data may be transferred outside the European Economic Area if this results from the use of technology providers, in particular Alphabet Inc., Wix.com Inc. or Stripe.

  3. Data may be transferred outside the EEA only using the mechanisms provided for in the GDPR, in particular:

    1. decision of the European Commission establishing an adequate level of protection,

    2. standard contractual clauses,

    3. additional security measures,

    4. other appropriate basis provided for in the GDPR.

  4. The Controller verifies whether suppliers outside the EEA ensure an adequate level of data protection.

  5. The Controller maintains an up-to-date list of suppliers who may process data outside the EEA and a list of the transfer mechanisms used.

  6. If the User wishes to obtain additional information about the transfer mechanisms used, he or she may contact the Administrator.

§ 13. Data storage period
  1. Personal data is stored for the period necessary to achieve the purposes for which it was collected, and then for the period required by law or the limitation period for claims.

  2. Data relating to the order and performance of the contract are stored for the duration of the Service and then for the limitation period for claims.

  3. Accounting and tax data are stored for the period required by law, generally for 5 years calculated in accordance with tax regulations.

  4. Correspondence is stored for the period necessary to process the case and then for the limitation period for any claims.

  5. Data processed on the basis of consent are stored until the consent is withdrawn, unless further storage is justified by another legal basis, for example a legal obligation or defense against claims.

  6. Technical logs may be stored for a period of 12 months, unless longer storage is necessary for security reasons, the detection of abuse or the pursuit of claims.

  7. Photos of rooms, floor plans and other Input Materials stored in technical folders are stored for the period necessary to perform the Service, handle complaints and secure claims, but no longer than 24 months from the performance of the Service, unless:

    1. The customer has consented to longer storage,

    2. materials are needed to process the complaint,

    3. the materials are needed to establish, pursue or defend claims,

    4. legal provisions require longer storage,

    5. the materials were effectively anonymized.

  8. "How to implement it?" documents, PDF files, Arrangement Proposal Variants and other resultant documents are stored for the period necessary to perform the Service, enable their download, handle complaints and defend against claims, no longer than 24 months from the performance of the Service, unless the Client has consented to longer storage, the materials are necessary to handle complaints, defend against claims, fulfill legal obligations or have been effectively anonymized.

  9. Generated Arrangement Proposals and Proposal Descriptions are stored for the period necessary to perform the Service, enable the download of effects, handle complaints and secure claims, but no longer than 24 months from the performance of the Service, unless one of the grounds indicated in paragraph 7 applies.

  10. Data in the database, in particular payment statuses of survey sessions, session identifiers, package names, counters of generated images, adaptation orders and promotional codes, are stored for the period necessary to process orders, complaints, settlements, security and defense against claims, but no longer than 24 months, unless legal provisions or the legitimate interest of the Controller require longer storage.

  11. Materials used for marketing purposes based on consent are stored and published until consent is withdrawn, the marketing purpose is terminated or the material is deleted by the Administrator.

  12. The controller should implement technical or organisational rules for periodically deleting or anonymising data that no longer needs to be stored.

  13. After the retention period has expired, the data may be deleted, anonymized or restricted, depending on the nature of the data and the purpose of processing.

§ 14. Marketing use of photos and arrangement proposals
  1. The Administrator may use photos of rooms, floor plans, Design Proposals, descriptions of effects, opinions or other materials of the Client for marketing purposes only if he has an appropriate legal basis to do so.

  2. The basis for the marketing use of the Client's materials is voluntary, specific and informed consent.

  3. Marketing consent may include, in particular, the use of materials on the website; in the portfolio; in social media; in advertisements; in the newsletter; in presentations; in case studies or other promotional materials.

  4. Marketing consent is not a condition for concluding a contract or providing the Service.

  5. Before publishing the materials, the Administrator should remove or obscure personal data and elements identifying persons, if any.

  6. In particular, images of people; names and surnames; addresses; documents; family photos; school data; medical data or other elements enabling the identification of a person should be removed or obscured before publication.

  7. Withdrawal of marketing consent does not affect the lawfulness of actions taken before its withdrawal.

  8. After withdrawal of consent, the Administrator will cease further use of the materials within the scope of the withdrawn consent, taking into account the technical and organizational possibilities of removing the materials from individual channels.

  9. The Administrator does not publish photos depicting a child or other persons without an appropriate, separate legal basis.

  10. If the material has been effectively anonymised and does not allow for the identification of the User, child, premises or any other person, it may be used for statistical, qualitative, analytical or marketing purposes, provided that this does not violate the law.

§ 15. Cookies and similar technologies
  1. The website may use cookies and similar technologies, such as pixels, tags, local browser storage, or analytical identifiers.

  2. Cookies may be used in particular to ensure the proper operation of the Website; maintain sessions; process forms and payments; remember settings; keep statistics; analyse traffic; conduct marketing activities; ensure security or diagnose technical errors.

  3. The website may use cookies or similar technologies provided by:

    1. Wix.com Inc.,

    2. Stripe,

    3. Alphabet Inc.,

    4. home.pl,

    5. other tools implemented on the Website.

  4. The Administrator may use the following categories of cookies:

    1. necessary - necessary for the operation of the Website,

    2. analytical - used to analyze how the Website is used,

    3. marketing – used to conduct advertising activities and measure their effectiveness,

    4. functional – enabling the User's preferences to be remembered.

  5. Non-essential cookies should be used based on the User's consent, if such consent is required by law.

  6. The User may manage cookie consents using the mechanism available on the Website, if implemented.

  7. The user can also change cookie settings in their browser settings.

  8. Restricting the use of cookies may affect some of the Website's functions, in particular the handling of forms, payments, sessions or remembering settings.

  9. The Administrator maintains an up-to-date list of cookies and similar technologies used and applies the cookie banner to the solutions actually used.

§ 15. Cookies and similar technologies
  1. A User whose personal data are processed by the Controller has the rights set out in the GDPR. The extent to which each right may be exercised may depend on the legal basis for processing, the type of data and the purpose of their processing.

  2. Right of access to personal data — Article 15 GDPR — The User has the right to obtain confirmation from the Controller as to whether his or her personal data are being processed. Where the data are being processed, the User has the right to access such data and to obtain information concerning the processing, in particular information about the purposes of processing, categories of data, recipients of the data, the planned storage period and the rights available to the User.

  3. Right to receive a copy of the data — The User has the right to receive a copy of the personal data undergoing processing. The first copy of the data is, as a rule, free of charge, whereas for any further copies the Controller may charge a reasonable fee based on administrative costs, where permitted by law.

  4. Right to rectification — Article 16 GDPR — The User has the right to request rectification of personal data that are inaccurate, outdated or incomplete. Depending on the purpose of processing, the User may also request that incomplete data be completed, including by providing an additional statement.

  5. Right to erasure — Article 17 GDPR — The User has the right to request the erasure of his or her personal data in the cases provided for by law. This applies in particular where the data are no longer necessary for the purposes for which they were collected, where the User has withdrawn consent and there is no other legal basis for processing, where the User has effectively objected to the processing, where the data have been processed unlawfully, or where the obligation to erase the data results from legal provisions. The right to erasure may be subject to limitations where further processing is necessary, for example, for compliance with a legal obligation or for the establishment, exercise or defence of claims.

  6. Right to restriction of processing — Article 18 GDPR — The User has the right to request restriction of data processing in the cases provided for in the GDPR. This may apply in particular where the User contests the accuracy of the data, where the processing is unlawful but the User opposes erasure of the data, where the Controller no longer needs the data for its own purposes but the data are required by the User for the establishment, exercise or defence of claims, or where the User has objected to the processing and verification is pending as to whether the Controller’s legitimate grounds override the grounds of the objection.

  7. Right to data portability — Article 20 GDPR — The User has the right to receive the personal data which he or she has provided to the Controller in a structured, commonly used and machine-readable format, where the processing is based on consent or on an agreement and is carried out by automated means. The User also has the right to transmit those data to another controller, where technically feasible.

  8. Right to object — Article 21 GDPR — The User has the right to object to the processing of his or her personal data where the processing is based on the Controller’s legitimate interest. In such a case, the Controller shall cease processing the data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the User, or grounds for the establishment, exercise or defence of claims. The User also has the right to object to the processing of data for direct marketing purposes.

  9. Right to withdraw consent — Where data processing is based on consent, the User has the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal. After consent is withdrawn, the Controller shall cease processing the data for the purpose covered by the consent, unless there is another legal basis for further processing.

  10. Right to lodge a complaint with a supervisory authority — The User has the right to lodge a complaint with the President of the Personal Data Protection Office if the User considers that the processing of his or her personal data infringes the GDPR or other personal data protection regulations.

  11. Personal Data Protection Office
    ul. Moniuszki 1A
    00-014 Warsaw
    Poland

  12. Tel. +48 22 531 03 00
    Fax +48 22 243 05 69

  13. E-mail: kancelaria@uodo.gov.pl; zwme@uodo.gov.pl

  14. Website: https://uodo.gov.pl/

  15. Requests concerning personal data may be sent to: info@miejsce.ai. The Controller may ask the User to provide additional information necessary to confirm the User’s identity or to clarify the request, where this is necessary for the proper exercise of the rights of the data subject.

§ 17. Right of objection
  1. The User has the right to object to the processing of personal data based on the Controller's legitimate interest. The objection should specify the processing with which the User disagrees and, where possible, the reasons relating to the User's particular situation.

  2. In the event of an objection, the Controller will cease processing the personal data subject to the objection, unless it demonstrates the existence of important, legitimate grounds for processing that override the interests, rights and freedoms of the User, or that the data are necessary to establish, pursue or defend against claims.

  3. The User has the right to object to the processing of data for direct marketing purposes at any time. If such an objection is made, the Administrator will cease processing the data for direct marketing purposes.

  4. An objection may be submitted by contacting the Administrator at info@miejsce.ai. If the Website provides an account panel, consent panel, or other preference management tool, the objection may also be submitted using such a tool, if implemented.

§ 18. Automated processing and AI
  1. The Administrator uses automatic tools, including AI tools, to generate Arrangement Proposals and Proposal Descriptions, process Input Materials, analyze arrangement preferences and prepare the effects of the Service.

  2. This processing serves the purpose of performing the Service ordered by the User and consists in the technical processing of a photo, Survey or other data in order to generate a Visual Proposal.

  3. AI tools can analyze a photo of the room, a description of preferences, Survey responses, and other information provided by the User to generate a Design Proposal that meets the requirements of the order.

  4. The Controller shall not make any decisions regarding the User based solely on automated processing that would produce legal effects for the User or similarly significantly affect the User within the meaning of Article 22 of the GDPR, unless this is indicated separately in a specific case and is based on an appropriate legal basis.

  5. The effects generated by AI are conceptual, inspirational and supportive.

  6. Design Proposals can be marked as AI-generated or AI-processed.

  7. The user should independently verify the AI effect before using it, in particular before purchasing furniture, starting renovation work, ordering a built-in unit or handing over materials to a contractor.

§ 19. Data security
  1. The Administrator applies technical and organisational measures appropriate to the risks associated with the processing of personal data.

  2. These measures may include, in particular:

    • data transmission encryption using HTTPS,

    • VPS network access control,

    • restricting access to the database,

    • restricting access to data storage folders,

    • limiting access to data only to authorized persons,

    • use of passwords and system security,

    • updating applications and application dependencies,

    • using backups,

    • monitoring the security of the Website,

    • verification of technology suppliers,

    • procedures for deleting or anonymizing data,

    • minimizing the scope of data transferred to suppliers,

    • restricting administrative access,

    • email security,

    1. periodic review of data stored in technical folders.

  3. The Administrator ensures that only those persons who need it to perform specific tasks have access to the data.

  4. The User should take care of the security of his/her device, e-mail and access to links enabling downloading the effects of the Service on his/her own.

  5. The User should immediately inform the Administrator if he or she suspects unauthorized access to his or her data, incorrect data transmission or a security breach.

§ 20. Data protection violations
  1. In the event of a breach of personal data protection, the Administrator takes action in accordance with the GDPR.

  2. The Controller analyses the nature of the breach, the scope of data, the number of people, the possible consequences and the risk of violating the rights or freedoms of natural persons.

  3. If the breach may result in a risk of violating the rights or freedoms of natural persons, the Controller will report the breach to the President of the Personal Data Protection Office, if required.

  4. If the breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller will also notify the data subject, if required.

  5. The Administrator may keep a register of personal data protection violations in accordance with the GDPR.

§ 21. Obligation or voluntary provision of data
  1. Providing data is voluntary, but in certain cases necessary to place an order; perform the Service; generate an Arrangement Proposal; make a payment; issue an invoice; handle complaints; respond to an inquiry or provide an Additional Service.

  2. Failure to provide the data necessary to perform the Service may prevent its implementation.

  3. Providing marketing data, marketing consents and consent to the publication of materials is voluntary and does not affect the possibility of ordering the Service.

  4. Providing excess data, in particular child data, images of people, medical data, documents or addresses, is not required and should be avoided.

§ 22. Changes to the Privacy Policy
  1. The Administrator may change the Privacy Policy, in particular in the event of a change in legal provisions, a change in the functionality of the Website or a change in the scope of data processed.

  2. The current version of the Privacy Policy is published on the Website.

  3. If a change to the Privacy Policy significantly affects the rights or freedoms of Users, the Administrator may inform about it additionally, for example through a message on the Website or an e-mail message, if it has the User's e-mail address and it is justified.

  4. The privacy policy is effective from June 17, 2026.

bottom of page