Privacy Policy

"Völundr" Platform — https://volundr.dev

Version 1.0 · Effective date: 20 July 2026

§ 1. Data Controller

The controller of personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the "GDPR") is:

Marek Rybka, conducting business under the name Järnhaus ul. Krótka 54/2, 60-185 Skórzewo, Poland Tax ID (NIP): 7831831894 · Business registry number (REGON): 388307456 E-mail (GDPR matters): rodo@volundr.dev E-mail (general correspondence): kontakt@volundr.dev Website: https://jarnhaus.dev · Platform: https://volundr.dev

This Privacy Policy (the "Policy") describes the rules governing the processing of personal data of Users of the Völundr Platform – a platform for the automatic generation of applications using artificial intelligence models. The Policy supplements the Terms of Service, available at https://volundr.dev/terms.

§ 2. What data we collect

2.1. Data provided by the User:

  • registration data: e-mail address, first and last name or company name, tax/VAT ID (optional – for invoicing purposes);
  • contact details provided in correspondence with the Controller;
  • the content of Prompts submitted for the purpose of generating an Application – to the extent that the User voluntarily includes information about themselves or third parties (see § 7 of the Policy);
  • data provided in complaint forms or Change Request (CR) submissions.

2.2. Data collected automatically:

  • IP address and device data (browser type, operating system, screen resolution);
  • data on activity on the Platform (pages visited, session duration, clicks);
  • cookies and similar technologies (local storage, session storage) – details in § 10 of the Policy;
  • system and technical logs for security and diagnostic purposes.

2.3. Data from third parties:

  • transaction data from Stripe, Inc. / Stripe Payments Europe, Ltd. (payment confirmation, transaction identifier); the Controller does not receive or process full payment card data.

§ 3. Purposes and legal bases for processing

3.1. Conclusion and performance of a contract (Article 6(1)(b) GDPR) — We process data for the purpose of registering an Account, carrying out Applications and Change Requests (CRs), providing the Hosting Service, handling payments, issuing invoices, and handling complaints. Providing data for this purpose is a condition for concluding the contract – without it, the provision of services is not possible.

3.2. Compliance with legal obligations (Article 6(1)(c) GDPR) — We process data in order to comply with obligations arising from tax and accounting law, in particular the issuance and retention of VAT invoices and accounting documentation.

3.3. Legitimate interest of the Controller (Article 6(1)(f) GDPR) — for the following purposes: ensuring the security and integrity of the Platform, including detecting and preventing abuse, attacks, and fraudulent activity; establishing, exercising, or defending against legal claims; marketing the Controller's own services (without profiling for the advertising purposes of third parties); analysis of anonymized statistical data in order to improve the Platform; cooperation with law enforcement and regulatory authorities to the extent required by law.

3.4. User consent (Article 6(1)(a) GDPR) — On the basis of voluntary consent, we process data in order to send newsletters and marketing information by electronic means. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.

§ 4. Data retention periods

We retain personal data for the following periods:

  • data necessary for the performance of the contract – for the duration of service provision and until the expiry of the limitation period for claims arising from the given contract;
  • accounting and tax documentation – for 5 years from the end of the calendar year in which the tax obligation arose (under tax law provisions);
  • data processed for the purpose of establishing, exercising, or defending against claims – for the limitation period of the relevant claims (generally 3 years for consumer and B2B claims pursuant to Article 118 of the Polish Civil Code, unless specific provisions state otherwise);
  • data provided to law enforcement or regulatory authorities – for the period required by those authorities or applicable law;
  • data processed on the basis of consent – until the consent is withdrawn or the purpose of processing ceases to apply;
  • anonymized statistical and technical data – indefinitely, to the extent that it does not constitute personal data within the meaning of the GDPR;
  • security and server logs – for 90 days from the date of their generation.

§ 5. Recipients of data

Users' personal data may be disclosed to the following categories of recipients:

  • Stripe, Inc. / Stripe Payments Europe, Ltd. – to the extent necessary for processing payments; processing by Stripe is governed by Stripe's own terms and privacy policy, available at stripe.com/privacy;
  • Anthropic, PBC – provider of AI language models (Claude); the content of Prompts and data necessary to provide the service are processed by Anthropic's models in accordance with Anthropic's privacy policy, available at anthropic.com/privacy;
  • Hetzner Online GmbH – provider of the cloud infrastructure (servers located in the EU – Germany/Finland) on which the Platform, its database, and the generated Applications run;
  • Resend, Inc. – provider of transactional e-mail delivery (e.g. verification and notification e-mails);
  • Cloudflare, Inc. – DNS provider for the Platform's domains (does not proxy traffic and does not receive Prompt content);
  • Providers of legal, accounting, and audit services – on behalf of the Controller, to the extent necessary to provide such services;
  • Law enforcement authorities, regulatory authorities, and courts – to the extent required by law or final judgments;
  • Other processors – on the basis of data processing agreements concluded in accordance with Article 28 GDPR.

The Controller does not sell Users' personal data to third parties.

§ 6. Transfers of data outside the EEA

In connection with the use of services of entities established outside the European Economic Area (in particular Anthropic, PBC and Resend, Inc., both based in the USA), Users' personal data may be transferred to third countries. Such transfers are carried out using the appropriate safeguards referred to in Article 46 GDPR, in particular standard contractual clauses (SCCs) adopted by the European Commission, or on the basis of an adequacy decision referred to in Article 45 GDPR where such a decision has been issued.

The User may obtain information about the transfer mechanisms applied by contacting the Controller at the e-mail address indicated in § 1 of the Policy.

§ 7. Personal data included in Prompts

  1. Prompts submitted by the User are processed by third-party AI models (in particular those of Anthropic, PBC), which involves their transfer to the infrastructure of those entities.
  2. The User is required not to include third parties' personal data in the content of Prompts, in particular names, addresses, identification numbers, health data, biometric data, or other special category data within the meaning of Article 9 GDPR.
  3. If carrying out a Project requires the use of personal data, the User should: anonymize or pseudonymize such data in advance; ensure that they have an appropriate legal basis for transferring such data for processing by third parties; review Anthropic's privacy policy, available at anthropic.com/privacy.
  4. The Controller is not responsible for the processing of personal data contained in Prompts by third parties.

§ 8. Automated decision-making

The pricing of a Project is generated automatically by the Platform's AI systems based on the content of the Prompt. The Controller advises that this process does not constitute automated decision-making producing legal effects concerning the User or similarly significantly affecting them within the meaning of Article 22 GDPR, because: the pricing is merely an offer and is not binding on the User – the User may reject it without any consequences; and the contract is concluded only as a result of the User's voluntary acceptance of the pricing and payment being made. The User has the right to obtain an explanation of the rules for generating the pricing by contacting the Controller at the address indicated in § 1 of the Policy.

§ 9. User rights

In connection with the processing of personal data, the User has the following rights:

  • Right of access (Article 15 GDPR) – to obtain information about what data the Controller processes, for what purpose, and on what basis.
  • Right to rectification (Article 16 GDPR) – to request the correction of inaccurate data or the completion of incomplete data.
  • Right to erasure (Article 17 GDPR) – the "right to be forgotten", provided that it does not apply to the extent that processing is necessary for compliance with a legal obligation or the establishment, exercise, or defense of legal claims.
  • Right to restriction of processing (Article 18 GDPR) – in specific cases.
  • Right to data portability (Article 20 GDPR) – to receive data processed on the basis of consent or a contract, in a structured, commonly used, machine-readable format.
  • Right to object (Article 21 GDPR) – to the processing of data on the basis of the Controller's legitimate interest, including for direct marketing purposes.
  • Right to withdraw consent (Article 7(3) GDPR) – without affecting the lawfulness of processing carried out before its withdrawal.

Requests concerning the exercise of the above rights should be directed to the e-mail address indicated in § 1 of the Policy. The Controller will process requests within one month of receipt, with the possibility of extending this period by a further two months in justified cases, of which the User will be informed.

The User has the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, www.uodo.gov.pl) if they consider that the processing of their data violates the GDPR.

§ 10. Cookies and tracking technologies

10.1. Types of cookies used — The Platform uses cookies and similar technologies (local storage, session storage). The following categories are used: necessary (do not require consent); analytical (used only with consent); marketing (used only with consent); functional (used only with consent).

10.2. Legal basis — Cookies are used in accordance with Article 173 of the Polish Telecommunications Law of 16 July 2004 and the provisions of the GDPR. Consent to cookies other than necessary ones is obtained via the consent management widget displayed on first entering the Platform. Consent is voluntary, granular, and may be withdrawn at any time by changing the settings in the widget or in the browser.

10.3. Cookies currently in use

  • session_id / auth_token – necessary, user session and authentication, Controller;
  • csrf_token – necessary, protection against CSRF attacks, session, Controller;
  • _stripe_sid / _stripe_mid – necessary (payments), Stripe, Inc.;
  • consent_preferences – necessary (storing consent choices), Controller.

The current list of cookies is always available in the consent management widget on the Platform. If, in the future, analytical or marketing cookies are introduced, they will be activated only after the User's consent, and this list and the Cookie Policy will be updated accordingly.

10.4. Data transfers via cookies — To the extent that any third-party cookies involve the transfer of data outside the EEA, such transfers are carried out using the mechanisms described in § 6 of the Policy.

§ 11. Data security

The Controller applies appropriate technical and organizational measures to protect personal data against unauthorized access, loss, destruction, or disclosure, in particular:

  • encryption of data in transit (TLS/HTTPS);
  • encryption of the User's API keys using the AES-256-GCM algorithm;
  • access control based on the principle of least privilege;
  • regular security testing and infrastructure monitoring;
  • security incident response procedures in accordance with Articles 33–34 GDPR.

In the event of a personal data breach that may result in a risk to the rights or freedoms of individuals, the Controller will report it to the President of the Personal Data Protection Office within 72 hours of detecting the breach and, if the risk is high, will notify the affected Users.

§ 12. Personal data of end users of Applications

To the extent that a User of the Platform deploys a generated Application and makes it available to third parties (end users), the User acts as an independent controller of the personal data of those individuals within the meaning of the GDPR. The Platform Controller (Järnhaus) is not a party to the relationship between the User and the User's end users and is not responsible for the processing of their personal data by the Application.

A Platform User who processes personal data through an Application is required, in particular, to: develop and implement its own privacy policy for the Application; ensure an appropriate legal basis for the processing of end users' personal data; implement appropriate technical and organizational data protection measures; fulfill the information obligations towards end users in accordance with Article 13 GDPR.

If a Platform User entrusts the Controller with the processing of the personal data of its end users (e.g. as part of the Hosting Service), a data processing agreement within the meaning of Article 28 GDPR applies, on the terms available at https://volundr.dev/dpa.

§ 13. Marketing and communication

The Controller processes Users' contact details in order to send marketing information about its own services (newsletter, notifications of new features, special offers) solely on the basis of the User's prior consent given during registration or in the Account settings.

The User may withdraw from receiving marketing communications at any time by: clicking the "Unsubscribe" link in the footer of each e-mail message; changing the settings in the Account panel on the Platform; or sending a request to the e-mail address indicated in § 1 of the Policy. Withdrawing from marketing communications does not affect the sending of transactional and technical messages necessary for the provision of the Services (payment confirmations, Project status notifications, information about changes to the Terms of Service).

§ 14. Changes to the Privacy Policy

The Controller reserves the right to amend this Policy in the event of: changes to data protection laws; changes to the manner of processing data resulting from the development of the Platform; changes in the tools used or the processors involved; decisions or guidelines issued by supervisory authorities.

The Controller will notify Users of material changes to the Policy by electronic means, to the e-mail address assigned to the Account, at least 14 days before the effective date of the changes. Continued use of the Platform after that date is deemed to constitute acceptance of the new version of the Policy. The current version of the Policy is always available on the Platform at https://volundr.dev/privacy.

§ 15. Final provisions

  1. This Privacy Policy is governed by Polish law. In matters not regulated herein, the provisions of the GDPR and the relevant provisions of Polish law shall apply, in particular the Act of 10 May 2018 on the Protection of Personal Data.
  2. The Policy does not affect Users' rights arising from mandatory provisions of law, in particular the rights guaranteed by the GDPR.
  3. In matters concerning the processing of personal data, the User may contact the Controller at the e-mail address indicated in § 1 of the Policy.

Last updated: 20 July 2026.