Privacy Notice — Typelessity
Effective on 5 October 2026. Based on the Typelessity Terms and DPA, document version 2026-09-25. This notice describes the assistant; the website owner's own privacy notice supplies its identity, purposes and lawful basis.
1. Controller and Processor
The business operating the website where you use Typelessity is the controller of its visitors' data. It decides what the assistant asks for and whether the result goes to its integration endpoint or a nominated email address.
Webappski processes that data on the website owner's documented instructions. The processor is Victoria Isayeuskaya, sole proprietorship, ul. Staniszewskiego 19b, 81-603 Gdynia, Poland, VAT ID PL5862405795, contact info@webappski.com.
For rate-limit counters, organisation API-usage counters and sanitised application error logs, Webappski (the same entity as the sole proprietorship named above) acts as an independent controller to operate and secure the service and control cost; Section 3 states the lawful basis and Section 7 your right to object. Portal account and agreement-acceptance records are separately covered by the Website Privacy Policy.
2. Data the Assistant Processes
Depending on the website owner's configuration, collected fields can include name, email, phone number, dates and times, addresses, pick-up and drop-off points, party size and notes. Conversations store visitors' typed messages or speech transcripts, the assistant's replies, extracted values and enabled enrichment results.
Delivery records include the submitted data, the receiving system's response, status, timing and any error message; emailed requests also record the nominated recipient and delivery status. Consent records include IP address, user-agent, widget domain, interface language, consent method, policy version and widget version. The session record itself carries no IP address, user-agent or referring page.
The browser stores the consent record, visitor identifier and consent history in localStorage, and, in sessionStorage, the session identifiers, the session token, the interface state, the field values the assistant has extracted from what you dictated or typed and any edits you make to them, so that they survive a page change; sessionStorage is cleared when you close the tab. The hosting provider's request logs can transiently contain IP addresses. Staff preview conversations are also stored; staff should not use live customer data in previews.
3. Purposes and Consent
The assistant asks for missing information, understands answers and delivers the collected result to the website owner's system or forwards a request by email. An emailed request is not a confirmed booking. The assistant collects and transmits information and makes no automated decision producing legal or similarly significant effects.
A live conversation requires a server-checked consent record; the check repeats on every message. The widget offers withdrawal while the assistant is open. The website owner establishes the lawful basis for its processing and provides its own privacy information. Conversation content and collected data are not used to train Webappski's or third parties' AI models.
Where Webappski is an independent controller (rate-limit counters, organisation API-usage counters and sanitised application error logs), its lawful basis is legitimate interests under GDPR Art. 6(1)(f). The interest is to keep the service secure and available, to stop one visitor or key from overloading it, and to measure use against the owner's plan. The data is technical, it is used only for these purposes, and it is deleted on the schedule in Section 4.
4. Retention
- Abandoned conversations without delivery records become eligible for deletion after 24 hours without activity and are removed with their messages by a nightly job, at most 48 hours after the last activity.
- Completed conversations, delivery records and forwarded-request records have no automatic expiry. The website owner decides when to remove them and instructs Webappski in writing.
- Consent records are kept for three years after the visitor last answered the consent question, then deleted by the nightly job.
- Rate-limit counters, which count a visitor's or an API key's requests so the service is not overloaded, are deleted by the nightly job once nobody has touched them for 24 hours.
- API usage rows, which record the requests counted against the owner's plan, are deleted by the nightly job after 13 months.
- Webappski does not retain voice audio after transcription. OpenAI's published defaults recorded in DPA Appendix B specify no abuse-monitoring retention for audio transcriptions; the requests and responses of the chat calls (the visitor's messages, the assistant's replies and the extracted values) in chat-completions abuse-monitoring logs can be retained for up to 30 days. Webappski has no Zero Data Retention or Modified Abuse Monitoring approval.
- On termination, data is returned or deleted within 30 days of the owner's instruction, or deleted within 90 days if no instruction arrives, subject to the consent-record period and retention required by law.
Copies already delivered to the website owner's mailbox or systems remain the owner's responsibility. Application logs have short hosting-provider retention, measured in hours, and are not exported to another system.
5. Subprocessors and Other Recipients
The following list follows the Typelessity DPA Appendix B, whose provider terms were checked on September 20, 2026:
- Vercel Inc. — hosting and scheduled jobs. EU, Frankfurt; provider request logs.
- Supabase Pte. Ltd — configurations, sessions, conversations, delivery and consent records. EU, Ireland; contracting entity in Singapore.
- OpenAI Ireland Ltd — conversation understanding and speech-to-text. United States, by OpenAI affiliates.
- Plus Five Five, Inc., trading as Resend — forwarded request emails. United States.
Google Fonts is not in DPA Appendix B yet. The assistant loads its typefaces (DM Sans and Space Mono) from fonts.googleapis.com (the stylesheet) and fonts.gstatic.com (the font files) as soon as it appears on the page, before any consent dialog. For those requests your browser sends Google your IP address and User-Agent.
DPA Appendix B identifies the applicable Standard Contractual Clauses and other transfer mechanisms. It also describes Google Ireland Limited's Places API as an independent controller for optional address lookups, which receive query text rather than the whole conversation. Firebase services for the owner's Portal account are separate independent-controller processing by Webappski under the website privacy notice.
The website owner receives at least 30 days' notice before a subprocessor is added or replaced and can object on reasonable data-protection grounds as described in the DPA.
6. Your Rights and How to Exercise Them
Contact the website owner's data-protection contact, identified in its privacy notice, to request access, correction, export or erasure and to exercise applicable rights under GDPR Articles 15–22. Webappski assists on the owner's written instruction, provides retrieved data in JSON and acts within 10 working days. The Portal currently has no self-service erasure or export button. A request sent directly to Webappski about data the owner controls is referred to the website owner. For the data Webappski controls itself (Section 3), write to info@webappski.com and Webappski answers within one month (GDPR Art. 12(3)).
You can withdraw consent through the assistant's consent dialog while it is open. The DPA preserves data subjects' rights and remedies.
You can lodge a complaint with the President of the Personal Data Protection Office (UODO, https://uodo.gov.pl/) or with the supervisory authority of the EU country where you live or work, or where the alleged infringement took place (GDPR Art. 77).
7. Your Right to Object
You have the right to object at any time, on grounds relating to your particular situation, to the processing that Webappski carries out as an independent controller on the basis of its legitimate interests: the rate-limit counters, the organisation API-usage counters and the sanitised application error logs (GDPR Art. 21(1)). Write to info@webappski.com. Webappski then stops the processing unless it shows compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Webappski does not use this data for direct marketing.
8. Contact and Related Documents
Data-protection matters concerning Webappski: info@webappski.com. For the website owner's processing and copies it receives, contact that owner's data-protection contact.
Read the Typelessity Terms and the Typelessity DPA, including the subprocessor list. This notice summarises those documents and does not replace the website owner's own privacy information.