Privacy Policy

Last updated: 8 August 2026

1. Who we are

Client Report Autopilot ("the Service") is operated by Andrei Zhukouski, Żupnicza 16/57, 03-821 Warsaw, Poland ("we", "us").

For questions about this policy or your data: reports@azitadvisory.com.

2. Two different roles

This matters, because different rules apply to each.

We are the controller of your own account information — your email address, password hash, billing records, and how you use the Service.

We are a processor of everything you connect or configure on behalf of your own clients: the website analytics we read from Google Analytics, the business context you write, and the recipient email addresses you enter. You are the controller of that data and decide what we do with it. Our processing of it is governed by our Data Processing Agreement, which applies automatically when you create an account.

3. What we collect and why

3.1 Account information

DataWhyLegal basis
Email addressTo identify your account and contact you about the ServiceContract
Password (hashed with bcrypt — we never store or see the original)To authenticate youContract
Subscription and payment recordsTo bill you and meet accounting obligationsContract; legal obligation
Server logs (IP address, timestamps, error traces)Security, debugging, abuse preventionLegitimate interests

3.2 Google Analytics data

When you connect a Google account, we request read-only access (https://www.googleapis.com/auth/analytics.readonly) plus your email address (openid, email) so we can show which account is connected.

We read aggregated reporting data only for the properties you select:

  • Visit, visitor and new-visitor counts; engagement rate; average visit duration; conversions ("key events")
  • Traffic sources and referring domains
  • Landing-page paths
  • Device categories and countries
  • Daily totals for the reporting month

We do not request or read individual user identifiers, user-level event streams, advertising audiences, or anything that lets us identify a specific website visitor. We do not write to, modify or delete anything in your Google Analytics.

3.3 Data you enter

Client names, their website domains, branding (colour, logo URL), business context notes, recipient email addresses, and any traffic sources you exclude.

4. How we use Google user data — Limited Use

We comply with the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve the user-facing features you signed up for: generating and delivering your monthly client reports.
  • We do not sell Google user data.
  • We do not use Google user data for advertising, ad targeting, or ad measurement.
  • We do not use Google user data to develop, improve or train generalised artificial intelligence or machine-learning models. Where a third-party AI provider processes this data to write your report summary (see section 5), it does so as our service provider, under contractual terms that prohibit using the data to train its models.
  • We do not allow humans to read Google user data except: with your explicit permission (for example, when you ask us to investigate a problem); where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data is aggregated and anonymised.
  • We transfer Google user data only to the service providers listed in section 7, only as necessary to provide the Service, to comply with applicable law, or as part of a merger or acquisition in which case we will give notice.

5. Automated summary writing (AI processing)

Please read this section — it involves sending your data to a third party.

The Service writes a plain-language summary of each report using a large language model provided by Anthropic. To do this, we send Anthropic:

  • the aggregated figures described in section 3.2, formatted as text
  • the business context you wrote for that client
  • the client's name and website

We do not send Anthropic your account credentials, your Google access or refresh tokens, your recipient email addresses, or your payment details.

Anthropic acts as our sub-processor. Under Anthropic's published policy, inputs and outputs from its commercial API are not used to train its models by default; that default is displaced only by explicitly submitting feedback or opting in, and we do not submit your data through any such mechanism. Automated summaries can contain mistakes. The Service therefore generates every report in a ready state and sends nothing until you take a separate action to send it — you are responsible for reviewing a summary before it reaches your client.

If you do not want your data processed by an AI provider, the Service is not suitable for you, because that summary is its core function.

6. Who receives your reports

Reports are emailed to the recipient addresses you enter for each client, and are reachable at a share link containing a randomly generated token. Anyone holding that link can view that report — treat it as confidential. Share pages are marked not to be indexed by search engines and are not cached by intermediaries, but we cannot control onward sharing by someone you send it to.

7. Sub-processors

ProviderPurposeLocation
SupabaseDatabase hostingEuropean Union (Ireland, eu-west-1)
RailwayApplication hosting, report renderingEuropean Union (Amsterdam)
AnthropicAutomated summary writingUnited States
ResendReport email deliveryUnited States

Two parties are deliberately not in this list:

Google Analytics is the source of the reporting data, accessed under the permission you grant. Google is not our sub-processor.

Paddle handles payments as our merchant of record — see section 7a. Paddle is the seller of the subscription and acts as an independent controller of your payment data, not as our processor, so it is not a sub-processor of ours.

We will give notice before adding or replacing a sub-processor. Current list always available at reports.azitadvisory.com/privacy.

7a. Payments — Paddle is the merchant of record

Subscriptions are sold and billed by Paddle.com Market Limited (Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom) acting as merchant of record. In practice:

  • Paddle, not us, is the seller for the payment transaction and the party on your receipt.
  • Paddle collects and processes your payment details directly, as its own controller. We never see or store your card number.
  • Paddle calculates and remits any VAT, GST or sales tax due in your jurisdiction.
  • Paddle's own privacy notice governs how it handles your payment data: paddle.com/legal/privacy.

We receive from Paddle only what we need to run your account: your email address, subscription status, and a customer reference.

8. International transfers

Some sub-processors are outside the European Economic Area. For every such transfer we rely on the European Commission's Standard Contractual Clauses. Payment data reaching Paddle in the United Kingdom is covered by the European Commission's adequacy decision for the UK; should that decision lapse or be withdrawn, the SCCs apply instead. Where a provider also holds a valid EU–US Data Privacy Framework certification we treat that as an additional safeguard, not as the mechanism we depend on — adequacy findings for US transfers have twice been struck down, whereas contractual clauses survive that. The per-provider position, and the date it was last verified, is in Annex III of our Data Processing Agreement. A copy of the relevant mechanism is available on request.

9. How long we keep data

DataRetention
Account informationWhile your account is active, then deleted within 30 days of closure
Generated reports (figures and summaries)While your account is active, or until you delete the client or report
Google access and refresh tokensUntil you disconnect Google or close your account, whichever is first
Billing records5 years, counted from the beginning of the year following the financial year to which they relate, as required by the Polish Accounting Act and tax law
Server logsUp to 90 days

Disconnecting your Google account immediately revokes our access and deletes our stored tokens.

10. Security

  • Google refresh tokens are encrypted at the application layer with AES-256-GCM, using a key held separately from the database — not merely relying on the database being encrypted at rest.
  • Passwords are hashed with bcrypt; we cannot recover them.
  • Sessions use signed, HTTP-only cookies.
  • All traffic is served over TLS.
  • Access to production systems is limited to personnel who need it.

No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by law.

11. Your rights

If you are in the EEA or UK, you have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent where consent is the basis. Contact reports@azitadvisory.com; we will respond within one month.

You may also lodge a complaint with your local data protection authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, "UODO").

Where we act as a processor for data about your own clients, direct such requests to the controller — usually you or your client — and we will assist as required.

12. Cookies

We set one strictly necessary cookie to keep you signed in, and one short-lived cookie during the Google connection flow to protect against cross-site request forgery. We use no advertising, analytics or tracking cookies on the Service, so no consent banner is required.

13. Children

The Service is for business use and is not directed at anyone under 16. We do not knowingly collect their personal data.

14. Changes

We will post any changes here and update the date above. For material changes affecting how we use your data, we will notify you by email.

15. Contact

Andrei Zhukouski, Żupnicza 16/57, 03-821 Warsaw, Poland — reports@azitadvisory.com