1. Data Controller
This Privacy Policy applies to SuperOCR.ai, operated by:
BEO TECHNOLOGY SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ
Prezydenta Gabriela Narutowicza 40 / 1, 90-135 Łódź, Polska
KRS 0001103255
NIP 7252343252
VAT EU: PL7252343252
REGON 528493956
Contact for privacy matters: support@superocr.ai.
2. Scope
This Policy describes how we collect, use, disclose, and protect personal data when you use our website, application, APIs, and related services.
It is designed to address GDPR requirements for users in the EEA/UK/Switzerland and CCPA/CPRA requirements for California residents.
3. Categories of Personal Data
- Account data: name, email, password hash, authentication metadata.
- Billing and commercial data: plan selection, usage records, transactional data.
- Technical data: IP address, device/browser data, user agent, logs, approximate location.
- Product data: uploaded content, extraction schemas, output artifacts, support interactions.
- Security and fraud signals: abuse prevention, verification, risk indicators.
- Marketing and attribution data: campaign/referrer identifiers and conversion events.
4. Purposes and Legal Bases (GDPR Art. 6)
- Contract performance: account provisioning, service delivery, billing, support.
- Legitimate interests: security, abuse prevention, analytics, service improvement, business continuity.
- Legal obligations: tax/accounting, legal process, compliance duties.
- Consent: optional cookies and processing where required by law.
5. Advertising, Analytics, and Tagging Providers
We may use advertising, analytics, and tag-management providers for analytics, attribution, remarketing, and conversion measurement, including but not limited to:
Advertising platforms: Google Ads, Microsoft Advertising (Bing Ads), Meta Ads, TikTok Ads, Snapchat Ads, LinkedIn Ads, X Ads, Pinterest Ads, Reddit Ads.
Analytics platforms: Google Analytics, PostHog, Microsoft Clarity, Mixpanel, Amplitude, Hotjar, Heap, FullStory.
Tag infrastructure: Google Tag Manager, Server-side GTM, Stape.io, Taggrs.
Providers and configurations can change over time. We may add or replace tools with functionally similar services while keeping this policy updated.
6. Sharing and Recipients
We may share personal data with processors and service providers (infrastructure, hosting, analytics, email delivery, customer support, security, and payments), professional advisors, and competent authorities where legally required.
Infrastructure and security processing may be provided by Cloudflare services, including but not limited to Cloudflare Workers, Cloudflare D1, Cloudflare R2, Cloudflare Turnstile, Cloudflare Web Analytics, Cloudflare Logs.
For payment processing, invoicing, tax handling, and related compliance, we may use Dodo Payments (dodopayments.com) as Merchant of Record.
We do not sell personal information in exchange for money. Where applicable law defines certain advertising or analytics transfers as a "sale" or "sharing", you may exercise opt-out rights as described below.
7. International Data Transfers
Personal data may be processed outside your country of residence. For transfers from the EEA/UK/Switzerland, we rely on appropriate safeguards, such as Standard Contractual Clauses (SCCs), supplemented as needed by technical and organizational measures.
8. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, including contractual, legal, accounting, security, and dispute-resolution needs. Retention periods may vary by data category and plan.
9. Security
We apply reasonable technical and organizational safeguards to protect personal data, including access controls, encryption in transit where applicable, logging, and least-privilege practices. No method of transmission or storage is fully secure.
10. Your Privacy Rights (GDPR + CCPA/CPRA)
Depending on your jurisdiction, you may have rights to access, correct, delete, port, restrict, or object to certain processing, and to withdraw consent where processing is based on consent.
California residents may have rights to know, delete, correct, and opt out of sale/sharing for cross-context behavioral advertising, and to limit use/disclosure of sensitive personal information where applicable.
You can submit rights requests by contacting support@superocr.ai.
11. Cookie Policy
We use cookies and similar technologies for strictly necessary operations, security, performance, analytics, attribution, and advertising functions. We do not publish a fixed list of individual cookies in this document because cookie inventories may change over time.
Extended cookie details policy: https://cookietip.com/cookie-policy/T9sXmPsVpdkcazLSj1PbMUonNIBmv4TeAwPqS69vjR2lhZLwlRyx7eVbmeXfoDJJ
12. Children
Our services are not directed to children under 16. If you believe a child provided personal data to us, contact us and we will take appropriate steps.
13. Policy Updates
We may update this Privacy Policy from time to time. The latest version and effective date are published on this page. Material changes may require renewed acceptance.
14. Related Documents
Terms of Use: /terms-of-use
Current plans and pricing: /pricing#plans