Legal documents

Terms, privacy, data processing, security, and compliance documents for the Exceptao platform. All documents are drafts pending legal review.

⚠ All documents are drafts — legal review required before publication

Core legal

EN · PL Terms of Service

What we provide, what's prohibited, suspension, term, governing law (Poland — EU jurisdiction).

● Draft
EN · PL Privacy Policy

What we collect, why, how long, who has access. GDPR Art. 6 bases. Right-to-erasure pseudonymisation.

● Draft
EN · PL Data Processing Agreement

Full GDPR Art. 28 DPA. Subject matter, security measures, sub-processor list, 72h breach notification, data return on termination.

● Draft
EN · PL Acceptable Use Policy

No abuse, no tenant-isolation circumvention, no unauthorised pen-testing. Enforcement procedure.

● Draft
EN · PL Cookie & Tracker Disclosure

Session cookie (required). No third-party tracking on the marketing or app site.

● Draft

Security & compliance

EN · PL Security Whitepaper

RLS isolation, audit chain, encryption, MFA, OIDC/SAML, backups, key management. Honest "not yet" section (SOC 2, ISO 27001).

● Draft
EN · PL Subprocessor List

Cloudflare (CDN/R2/Tunnel), Backblaze B2 (backups), Microsoft Graph (email). 30-day change notification.

● Draft
EN · PL Operator Support Access Policy

When and how Operator engineers may impersonate a User to diagnose a ticket. Three-layer model: Tenant-Admin Approval, Break-Glass (2h cooling), Emergency Access Event. Two-chain audit. Controller controls.

● Draft

Company

EN · PL Imprint / Dane rejestrowe

Registered details of the operating entity (METAMORFOZIS GLETSCHMANN sp. j.): legal form, KRS, NIP, REGON, registered office, contact, supervisory authority.

● Draft