Privacy is important to us. This document explains what personal data we collect in connection with your use of the Scenza application and related services, why we collect it, the legal basis for processing and the parties to whom it may be entrusted. This Policy forms an integral part of the Terms of Service.
§1. Data controller
- The controller of your personal data within the meaning of Regulation (EU) 2016/679 (the GDPR) is:
- Controller
- Scenza (operator registration details pending)
- Registered office
- —
- KRS
- —
- Tax ID (NIP)
- —
- REGON
- —
- Contact
- info@scenza.pl
Given the nature and scale of the processing, we have not appointed a Data Protection Officer. For all privacy matters, please contact the Controller at the email address above.
§2. Definitions
Capitalised terms such as Application, User, Account, Premium Plan and App Store have the meanings given in the Terms of Service.
§3. Categories of data collected
3.1. Data provided during registration and use of the Application
- Email registration: email address, password (stored only as a cryptographic hash) and, optionally, first name.
- Google / Facebook login: provider identifier (Google ID / Facebook ID), email address, first name, surname, profile picture URL and access token, to the extent made available by the provider and covered by the consent you give when logging in.
- Profile: display name, date of birth, gender and profile picture, if provided.
- Fragrance preferences: perfumes marked as liked or disliked, favourite fragrance notes, quiz answers and onboarding step.
- User Content: mappings of barcodes to bottles, ratings, comments and messages to the Sommelier assistant.
- Tokens: email verification, password reset and session refresh tokens, processed solely for authentication.
3.2. Data collected automatically
- Technical data: IP address, mobile device identifier, operating system type and version, Application version and timestamps in server logs.
- Diagnostic data: crash events, response delays and error codes, used to maintain Application stability.
- Account usage history: Account creation date, most recent login and most recent activity.
3.3. Data collected with system permission
- Camera — used for two features:
- Barcode scanner — the image stream is analysed locally on the device to read an EAN code; the image itself is not sent to our servers.
- Visual search — if you photograph a perfume with the camera, the photo is sent to our servers to identify the product under the rules for photos described below.
- Photo library / photos — if you select an image from the photo library for visual search, it is sent to our servers in encoded form, reduced to no more than 1024×1024 pixels, solely to identify the perfume shown and return matches. We do not access or browse any other content in your photo library.
The current version of the Application does not use location, the microphone or other sensors and does not request related permissions. If we introduce features requiring such permissions in the future, such as showing nearby physical stores, we will request separate operating-system permission that may be revoked at any time and will update this Policy accordingly.
We do not knowingly process special categories of personal data under Article 9 GDPR, such as health data, ethnic origin or religious beliefs. Please do not enter such data in messages to the AI assistant or in other Application fields.
§4. Purposes and legal bases for processing
We process your data for the following purposes:
- Providing Application services — creating and maintaining an Account, generating recommendations, operating the scanner and providing the User profile. Legal basis: Article 6(1)(b) GDPR (performance of a contract).
- Login through external identity providers (Google, Facebook). Legal basis: Articles 6(1)(b) and 6(1)(a) GDPR (consent given to the identity provider).
- Sending transactional messages — registration confirmation, email verification, password reset and important service notices. Legal basis: Articles 6(1)(b) and 6(1)(f) GDPR (legitimate interest in Account security).
- AI features (Sommelier assistant and semantic recommendations) — generating responses and suggestions from submitted data and preferences. Legal basis: Article 6(1)(b) GDPR (performance of the contract in relation to AI functionality) and Article 6(1)(f) GDPR (improving recommendation quality).
- Security and abuse detection — protection against unauthorised access, attacks and spam. Legal basis: Article 6(1)(f) GDPR (legitimate interest).
- Premium subscription management (where applicable) — verifying purchase status and billing. Legal basis: Articles 6(1)(b) and 6(1)(c) GDPR (legal obligations, including tax and accounting obligations).
- Handling complaints and correspondence. Legal basis: Articles 6(1)(b), 6(1)(c) and 6(1)(f) GDPR.
- Establishing, pursuing and defending claims. Legal basis: Article 6(1)(f) GDPR (legitimate interest).
- Statistics, aggregated analysis and product improvement — only using anonymised data or data pseudonymised so that it does not identify the User. Legal basis: Article 6(1)(f) GDPR.
- Marketing our own services (if introduced) — sending commercial information and product updates. Legal basis: Article 6(1)(a) GDPR (your consent), which may be withdrawn at any time.
§5. Data recipients
Your data may be entrusted for processing to trusted third parties (processors) supporting the Application. Each acts on our behalf under a data processing agreement or equivalent instrument provided for by the GDPR.
- Hetzner Online GmbH (Germany) — hosting and server infrastructure provider; its servers are located in the EEA.
- OpenAI, L.L.C. (USA) — provider of language and vector models used in AI features (Sommelier and semantic recommendations). Portions of prompts and responses may be sent to OpenAI to the extent necessary to generate a response. Under OpenAI’s API terms as at the effective date of this Policy, data sent through the API is not used to train models.
- Google LLC / Google Ireland Ltd. — for the “Sign in with Google” OAuth authentication service.
- Meta Platforms Ireland Ltd. — for the “Sign in with Facebook” OAuth authentication service, when used.
- Apple Distribution International Ltd. and Google LLC — for Application distribution and any in-app subscription purchases.
- Transactional email service provider — for sending verification messages, password resets and service notices.
- Partner IT providers — such as providers of monitoring, backups and diagnostic tools, solely to the extent necessary to provide their services.
Data may also be disclosed to public authorities entitled to obtain it by law where they submit a request meeting statutory requirements.
§6. Transfers outside the EEA
Some providers, particularly OpenAI, L.L.C. and Google LLC, are based outside the European Economic Area in the United States. Data is transferred on the basis of:
- standard contractual clauses (SCCs) approved by the European Commission in Decision 2021/914,
- for US partners, the EU–US Data Privacy Framework, where the organisation is listed as an approved participant,
- additional safeguards such as encryption in transit, data minimisation and anonymisation where possible.
You may obtain a copy of the safeguards used by contacting the Controller.
§7. Data retention periods
- Account data — while the Account exists and, after deletion, for the limitation period for claims arising from the agreement (generally 6 years) and periods required by law (for example, tax obligations: 5 years from the end of the relevant tax year).
- Login and last activity data — as long as necessary for security, but no longer than 12 months after the most recent activity.
- Server and technical logs — generally for up to 12 months.
- Content entered into AI features — as long as necessary to provide a response and save recommendation history in your Account; OpenAI deletes data sent through the API according to its policies, usually within 30 days unless a shorter period has been requested.
- Correspondence, submissions and complaints — as long as necessary to respond and for the applicable limitation period.
- Data processed on the basis of consent, such as marketing data — until consent is withdrawn.
§8. User rights
In connection with our processing of your data, you have the following rights:
- Right of access to data and to receive a copy (Article 15 GDPR).
- Right to rectification of inaccurate or incomplete data (Article 16 GDPR).
- Right to erasure (“right to be forgotten”) in the cases specified in Article 17 GDPR.
- Right to restriction of processing (Article 18 GDPR).
- Right to data portability in a structured, commonly used format (Article 20 GDPR).
- Right to object to processing based on legitimate interests (Article 21 GDPR).
- Right to withdraw consent at any time without affecting the lawfulness of processing before withdrawal (Article 7(3) GDPR).
- Right to lodge a complaint with the President of the Polish Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl) if you believe processing infringes the GDPR.
Most rights may be exercised in the Application, for example by editing the profile, deleting the Account or withdrawing system permissions, or by emailing info@scenza.pl. We will respond within one month. For complex matters this period may be extended by a further two months, and we will notify you of the extension.
§9. Profiling and AI
- We use your fragrance quiz answers and stated preferences (liked and disliked perfumes and notes) to build a fragrance profile that personalises recommendations. The legal basis is Article 6(1)(b) GDPR (performance of the contract in relation to recommendation functionality).
- The Sommelier assistant uses a language model provided by OpenAI. Your message is sent to OpenAI to generate a response and, together with that response, may be stored in Account history to preserve conversation context.
- Profiling in the Application does not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. It only produces product suggestions, over which you retain full freedom of choice. You may nevertheless object to profiling at any time by contacting the Controller.
§10. Security
- We apply technical and organisational measures appropriate to the identified risks, including:
- TLS (HTTPS) encryption of connections,
- storage of passwords as salted cryptographic hashes,
- session authentication using time-limited JWTs and a refresh-token mechanism,
- infrastructure access control, backups and monitoring,
- verification of processors and regular reviews of their security practices.
- If we identify a personal data breach likely to result in a high risk to individuals’ rights or freedoms, we will notify you without undue delay under Article 34 GDPR and notify the President of the Polish Personal Data Protection Office under Article 33 GDPR.
§11. Cookies and local storage
- The mobile Application does not use cookies in the conventional browser sense. It uses local data storage (AsyncStorage / Keychain / Keystore) to save the session token, User settings and data enabling faster operation after restart, such as cached responses. This data is stored only on your device.
- The website https://scenza.pl may use only cookies necessary for its proper operation, such as maintaining a session or language. We currently do not use marketing or analytics cookies that collect personal data.
§12. Children
The Application is intended for persons aged 16 or over. We do not knowingly collect data relating to younger persons. If we receive reliable information that data of a child under 16 has been collected without the legal representative’s consent, we will delete it. If you are a parent or guardian and suspect that your child provided data without consent, please contact info@scenza.pl.
§13. Changes to the Policy
- The Policy may change, for example because the Application develops, providers change or legislation is updated.
- The current Policy is always available at https://scenza.pl/privacy. We will notify you of material changes by email if you have an Account or by a notice in the Application at least 14 days before the changes take effect.
§14. Contact
Please direct questions about personal data processing, exercising your rights or this Policy to info@scenza.pl or in writing to the Controller’s registered office at —.
This Policy applies from .