Mood nook sp. z o.o. · effective 2026-08-11

Privacy Policy

How Mood nook sp. z o.o. collects and uses personal data as a controller: what we collect, why, on which legal basis, how long we keep it and which rights you have under the GDPR.

1. Controller and contact

Mood nook sp. z o.o. is the controller for the personal data described in this policy. Questions about privacy, and requests to exercise your rights, can be sent to privacy@xeper.io.

Where you use the Service to store personal data about your own users, you are the controller of that data and we act as your processor. That relationship is governed by the Data Processing Agreement, not by this policy.

2. What we collect

CategoryExamples
Account dataName, work email, password hash or identity provider subject, account and workspace membership, role and permission assignments
Billing dataCompany name, billing address, VAT identification number, plan, invoices and payment status (card data is handled by our payment provider, not by us)
Usage and telemetryPages and endpoints used, API token identifiers, request volumes, error and performance metrics
Security logsIP address, user agent, sign-in attempts, audit trail of administrative actions
Support dataMessages you send us, attachments and the correspondence history
Marketing dataEmail address and preferences where you subscribe to product updates

3. Why we use it and on what legal basis

PurposeLegal basis (GDPR Art. 6)
Providing the Service and managing your accountPerformance of a contract, Art. 6(1)(b)
Billing, accounting and tax recordsLegal obligation, Art. 6(1)(c)
Securing the Service, preventing abuse and fraudLegitimate interest, Art. 6(1)(f)
Product analytics and improvement in aggregated formLegitimate interest, Art. 6(1)(f)
Support and communication about the ServicePerformance of a contract, Art. 6(1)(b)
Product marketing emailsConsent, Art. 6(1)(a), withdrawable at any time
Establishing, exercising or defending legal claimsLegitimate interest, Art. 6(1)(f)

4. Who we share it with

We do not sell personal data and we do not share it for third-party advertising. We disclose it only to processors acting on our instructions, listed on the Subprocessors page, to professional advisers under confidentiality, to public authorities where legally required, and to an acquirer in a merger or asset sale, in which case this policy continues to apply until replaced.

5. International transfers

Our primary infrastructure is located in the European Union. Where a subprocessor processes data outside the European Economic Area, the transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses together with supplementary technical measures such as encryption in transit and at rest.

6. How long we keep it

  • Account data: for the life of the account and 30 days after deletion, to allow recovery from mistaken deletion.
  • Customer Content: deleted within 30 days of termination unless you ask for earlier deletion; backups roll off within a further 35 days.
  • Invoices and accounting records: 5 years from the end of the accounting year, as required by Polish tax law.
  • Security and audit logs: up to 12 months, longer where needed for an ongoing investigation.
  • Marketing consents: until withdrawal, plus proof of consent for as long as claims can be made.

7. Your rights

  • Access a copy of your personal data.
  • Rectify inaccurate or incomplete data.
  • Erase data where the conditions in Art. 17 GDPR are met.
  • Restrict or object to processing based on legitimate interests.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, without affecting processing before withdrawal.
  • Lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO).

Send requests to privacy@xeper.io. We respond within one month and may ask for information needed to verify your identity.

8. Automated decision-making and AI features

We do not make decisions producing legal or similarly significant effects about you by purely automated means. AI-assisted features, such as schema generation and media metadata suggestions, process the prompt and content you supply in order to return a suggestion. Suggestions are drafts for a human to review, and we do not permit our model providers to use your content to train their models.

9. Security

We apply the measures described on the Security page, including encryption in transit and at rest, row-level tenant isolation, least-privilege access, hashed secrets and an append-only audit trail. No system is perfectly secure; we notify affected customers and, where required, the supervisory authority within 72 hours of becoming aware of a personal data breach.

10. Changes

We publish changes to this policy on this page with a new effective date, and notify account owners of material changes by email.

Questions about this document: legal@xeper.io. This text is provided for transparency and does not constitute legal advice.

Back to the legal centre