Privacy Policy
Effective Date: 2026-09-28 · Last Updated: 2026-09-28
Data Controller:
AgenticForce sp. z o.o.
ul. Podkowy 120B, 04-937 Warszawa, Poland
Registry court: District Court for the Capital City of Warsaw in Warsaw, XIV Commercial Division of the National Court Register · KRS: 0001234012
NIP: 9522283208 · EU VAT: PL9522283208 · REGON: 544443644
Share capital: PLN 5,000.00
Email: hello@wingman.pm · Phone: +48 601 606 844
wingman.pm
Contact person for data protection: Daniel Kierdal (hello@wingman.pm)
§1 General Provisions
1. This Privacy Policy ("Policy") explains how AgenticForce sp. z o.o. ("we", "us", "our") processes personal data of people who visit wingman.pm (the "Website"), use the WingmanPM application at app.wingman.pm (the "Service"), request access to it or contact us.
2. We are the controller (Article 4(7) GDPR) of the personal data described in this Policy. For personal data that our customers upload to or connect with the Service (for example, feedback from their own customers), the customer is the controller and we process that data as its processor under the Data Processing Agreement; the customer's own privacy notice applies to that data, and requests concerning it should be sent to the customer.
3. Daniel Kierdal is our contact person for data protection matters (hello@wingman.pm).
4. This Policy informs you about the processing of your personal data (Articles 13 and 14 GDPR). It is not part of the Terms of Service, and you are not asked to accept it.
§2 Definitions
For the purposes of this Policy:
- Data Controller - AgenticForce sp. z o.o., which determines the purposes and means of processing the personal data described in this Policy.
- User - any natural person who uses the Website or the Service, including persons invited to a Workspace.
- Personal Data - any information relating to an identified or identifiable natural person within the meaning of Article 4(1) GDPR.
- GDPR - Regulation (EU) 2016/679 on the protection of personal data.
- Website - wingman.pm.
- Service - the WingmanPM AI-assisted product management application at app.wingman.pm, as described in the Terms of Service.
- AI Credits, Workspace, Paid Plan, Credit Pack - as defined in the Terms of Service.
§3 What Data We Collect
We collect personal data from you, from the organisation that invites you to a Workspace (your name and email address), from third-party tools you connect to the Service, and from Polar when you make a purchase. We process the following categories:
3.1 Identification and Contact Data
- Name and email address
- Company name and role (for business accounts)
- Phone number, if you give it to us (for example, in correspondence)
3.2 Account Data
- Sign-in data processed by our authentication service provider; we do not have access to your password in plain text
- Account preferences and settings, Workspace membership and role
- Plan, subscription status and billing history in the Service
- AI Credit balance and AI Credit usage
- Records of your acceptance of the Terms of Service, of your privacy choices and of the choices you made before a purchase (document version, time and the text you confirmed)
3.3 Usage Data
- Content you upload to or connect with the Service (for personal data of your own customers, see §1 point 2)
- Data from third-party tools you connect; the integrations available are shown in the Service
- Documents and other results generated in the Service
- Activity and technical logs
- In the Service: product analytics data (for example, pages viewed and interactions), only with your consent, and error reports
3.4 Technical Data
- IP address and approximate location derived from it
- Browser type and version, device and operating system information
- Cookies and similar technologies, as described in the Cookie Policy
3.5 Payment Data
- Paid Plans and Credit Packs are sold by Polar Software, Inc. ("Polar") as merchant of record. Polar collects the payment and billing details you enter at checkout (such as card data and billing address) and processes them as the seller under its own privacy policy. We do not receive or store payment card data.
- From Polar we receive the information needed to provide what you bought, such as the Paid Plan or Credit Pack, the amount, the payment status and the customer's email address.
- We keep records of these transactions for accounting and tax purposes.
3.6 Access Requests and Enquiries
- When you join the waitlist or request early access on the Website: email address, name, role, product type, what you expect from the Service, your marketing preference and the page or form you used.
- When you write to us: the content of the correspondence and your contact details.
§4 Purpose and Legal Basis of Processing
We process personal data for the following purposes and on the following legal bases:
4.1 Service Provision (Article 6(1)(b) GDPR)
Creating and managing your Account, providing the Service, AI Credits and purchases, customer support, and communication about the Service (including notices of changes to the Terms, prices or the Service).
4.2 Access Requests and Enquiries (Article 6(1)(b) and 6(1)(f) GDPR)
Handling waitlist and early-access requests and answering your enquiries, as steps taken at your request before a contract or in our legitimate interest in responding to people who contact us.
4.3 Legal Obligations (Article 6(1)(c) GDPR)
Tax and accounting records, and handling consumer complaints and withdrawals as required by law.
4.4 Marketing Communications (Article 6(1)(a) GDPR and Article 398 of the Electronic Communications Law)
Sending product news and offers by email only if you have consented. You may withdraw consent at any time without affecting the lawfulness of earlier processing.
4.5 Security, Abuse Prevention and Legal Claims (Article 6(1)(f) GDPR)
Protecting the Website and the Service, preventing fraud and abuse (including repeated Beta Trials), keeping records of acceptance of the Terms and of pre-purchase confirmations, and establishing, exercising or defending legal claims.
4.6 Analytics and Improvement (Article 6(1)(a) and 6(1)(f) GDPR)
On the Website, analytics runs only with your consent given in the cookie panel. In the Service, product analytics runs only with your consent given in the Service and saved to your account; you can withdraw it at any time in Settings > Privacy & legal. Error reports are processed in our legitimate interest in keeping the Service working and fixing errors. Details are in the Cookie Policy.
4.7 AI Processing (Article 6(1)(b) and 6(1)(f) GDPR)
When you use an AI feature, the content needed for that operation is sent to a third-party AI model provider acting as our sub-processor, and the result is returned to the Service. For personal data of our customers' own customers, this happens on the customer's instructions under the Data Processing Agreement. The AI model providers we use are identified in the sub-processor register referred to in §6. We do not use content you provide, or AI output generated for you, to train AI models, and we use AI model providers under zero-data-retention settings: they process the content only to return the result and do not store it or use it to train their models.
4.8 Automated Decisions
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).
4.9 Is providing data required?
Providing the data marked as required during registration or purchase is necessary to conclude and perform the agreement; without it we cannot provide the Service. Other data is voluntary.
§5 Data Retention Periods
We keep personal data for the following periods:
- Account and Service data: for the duration of the agreement. After a Workspace is deleted, the Account is closed or the agreement ends, we complete the deletion of the data from the Service within thirty (30) days, unless the law requires longer retention or the data is needed to establish, exercise or defend legal claims (Terms of Service §11 point 6). Deleting a Workspace cannot be undone.
- Financial and transaction records: for the period required by tax and accounting law, as a rule five (5) years counted from the end of the calendar year in which the tax payment deadline passed.
- Records of acceptance of the Terms, pre-purchase confirmations, complaints and withdrawal statements: until the limitation period for claims related to the agreement expires.
- Marketing consents: until you withdraw consent; after that, we keep a record of the consent and its withdrawal only as long as needed to demonstrate compliance.
- Access requests and enquiries: until the request or enquiry has been handled and, where no agreement follows, no longer than needed to follow up on it; you can ask us to delete them at any time.
- Technical logs and error reports: thirty (30) days from creation.
- Product analytics data in the Service: no longer than needed to understand how the Service is used, in line with the retention settings of our analytics tool.
§6 Sharing Personal Data
We share personal data only as described below. Personal data may be processed in the European Union and in the United States.
Sub-processors
We use service providers who process personal data on our behalf under data processing agreements (Article 28 GDPR). For a complete and current list of our sub-processors, including their locations and purposes, see the Data Processing Agreement.
Subprocessor register: versioned register pending final approval.
Our sub-processors include providers of:
- Cloud hosting and data storage
- AI model services
- Document processing and web page retrieval
- Authentication (sign-in)
- Email delivery
- Product analytics and error monitoring
- Office and spreadsheet tools used to handle access requests
- Accounting and financial services
Polar (merchant of record)
Polar Software, Inc. sells Paid Plans and Credit Packs as merchant of record and processes the data you give at checkout as a separate controller under its own privacy policy.
Tools you connect
When you connect a third-party tool to the Service, data is exchanged with that tool at your instruction. Its provider processes that data under your own agreement with it.
Public authorities
We disclose personal data to public authorities only where the law requires it.
International transfers
For transfers outside the EU/EEA, we rely on an adequacy decision of the European Commission where one applies, or on Standard Contractual Clauses approved by the European Commission.
We do not sell, rent or otherwise commercialise your personal data.
§7 User Rights
Under the GDPR you have the following rights regarding your personal data:
- Right of Access (Article 15)
- Right to Rectification (Article 16)
- Right to Erasure (Article 17)
- Right to Restriction of Processing (Article 18)
- Right to Data Portability (Article 20)
- Right to Object (Article 21), including to processing based on our legitimate interests and, at any time, to direct marketing
- Right to Withdraw Consent at any time, without affecting the lawfulness of processing before withdrawal
- Right to Lodge a Complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO)
To exercise these rights, contact us as described in §11. We respond without undue delay and in any event within one month; where necessary, this period may be extended by two further months, and we will tell you why. For personal data that a customer of ours controls (§1 point 2), please contact that customer; we will assist it.
§8 Data Security
We apply technical and organisational measures appropriate to the risk. The measures in place today are:
- Encryption in transit: connections between your browser or tools and the Service are encrypted with TLS 1.2 or higher.
- Encrypted credentials: access tokens for tools you connect and API keys are encrypted at the application level.
- Access control: roles in each Workspace limit what each member can see and change; our internal administration tools are available only to designated staff accounts.
- Network isolation: databases and internal services are not reachable from the internet; only our HTTPS entry point is exposed.
- Automated security tests: our release pipeline runs automated security regression tests.
- Breach notification: where the law requires it, we notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it and inform the people affected (Articles 33 and 34 GDPR).
§9 Cookies
The Website and the Service use cookies and similar technologies. On the Website, optional analytics and marketing technologies stay off until you allow them in the cookie panel, and you can change your choice at any time using "Cookie settings" in the footer. Strictly necessary cookies are always used. Details, including the technologies used in the Service, are in the Cookie Policy.
§10 Changes to Privacy Policy
We update this Policy when our processing changes. We inform registered Users of material changes by email and in the Service before they apply, where possible at least thirty (30) days in advance, and show the current version and its effective date at the top of this Policy. Where a change requires your consent, we will ask for it and will not rely on your continued use of the Website or the Service as consent.
§11 Contact
AgenticForce sp. z o.o.
ul. Podkowy 120B, 04-937 Warszawa, Poland
Registry court: District Court for the Capital City of Warsaw in Warsaw, XIV Commercial Division of the National Court Register · KRS: 0001234012
NIP: 9522283208 · EU VAT: PL9522283208 · REGON: 544443644
Share capital: PLN 5,000.00
Email: hello@wingman.pm · Phone: +48 601 606 844
wingman.pm
Contact person for data protection: Daniel Kierdal
Supervisory authority: President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, Poland · Website: uodo.gov.pl