Legal
Legal documents
Terms, privacy, data processing, security, and compliance documents for the Exceptao platform. All documents are drafts pending legal review.
Core legal
What we provide, what's prohibited, suspension, term, governing law (Poland — EU jurisdiction).
● DraftWhat we collect, why, how long, who has access. GDPR Art. 6 bases. Right-to-erasure pseudonymisation.
● DraftFull GDPR Art. 28 DPA. Subject matter, security measures, sub-processor list, 72h breach notification, data return on termination.
● DraftNo abuse, no tenant-isolation circumvention, no unauthorised pen-testing. Enforcement procedure.
● DraftSession cookie (required). No third-party tracking on the marketing or app site.
● DraftSecurity & compliance
RLS isolation, audit chain, encryption, MFA, OIDC/SAML, backups, key management. Honest "not yet" section (SOC 2, ISO 27001).
● DraftCloudflare (CDN/R2/Tunnel), Backblaze B2 (backups), Microsoft Graph (email). 30-day change notification.
● DraftDirective (EU) 2022/2555 read for an international entity: the Art. 21(2) measure-by-measure mapping, the Art. 23 24h/72h/30d cadence, and an explicit list of what the platform does not do — including the designation record it has no model for.
● DraftThe Operator's own GDPR Art. 30(1) record — six activities where we are controller, not processor. Retention periods are what the code enforces, which for the audit chain means the life of the account.
● DraftWhen and how Operator engineers may impersonate a User to diagnose a ticket. Three-layer model: Tenant-Admin Approval, Break-Glass (2h cooling), Emergency Access Event. Two-chain audit. Controller controls.
● DraftCompany
Registered details of the operating entity (METAMORFOZIS GLETSCHMANN sp. j.): legal form, KRS, NIP, REGON, registered office, contact, supervisory authority.
● Draft