1.1. This Privacy Policy explains how Studio DR sp. z o.o. (“Studio DR”, “we”, “us”) collects, uses, and protects personal data in connection with the AskOurChurch service (the “Service”), in accordance with Regulation (EU) 2016/679 (“GDPR” / “RODO”) and applicable Polish law, including the Polish Act on the Protection of Personal Data.
1.2. Controller vs. processor. For personal data of our own customers, prospects, and visitors to our marketing site, Studio DR acts as data controller — this Policy applies. Where a church (“Customer”) uses the Service to process personal data of its own members and page visitors, the Customer is the controller and Studio DR acts as a processor on its behalf; that relationship is governed by the Data Processing Agreement (DPA) rather than this Policy. See Section 10.
2.1. Account and administrator data: name, email address, role/title, church/organization name, and authentication data (we use magic-link email verification; we do not store account passwords).
2.2. Church profile data provided at onboarding: organization name, address, service schedule, home-group information, contact details, donation link, and configuration choices. Where this includes personal data of individuals, see the DPA.
2.3. Connected content: references to and content from YouTube channels you connect (video lists, metadata, and transcripts, retrieved on our behalf by our third-party provider Supadata.ai — see Section 6) and, on eligible plans, uploaded documents. This content is processed to provide the Service.
2.4. Billing data: subscription plan, transaction records, and limited payment metadata. Card payments are handled by our payment processor (e.g., Stripe); we do not store full card numbers.
2.5. Usage and technical data: log data, device and browser information, IP address, approximate location derived from IP, pages viewed, and interactions with the Service, collected via server logs and cookies/similar technologies (see the Cookie Policy).
2.6. Communications: messages you send us (support, complaints, inquiries) and related metadata.
2.7. Marketing-site applications: for the charter/pre-launch program, we collect church name, YouTube/website URL, approximate member count, contact name, role, email, and any free-text you provide.
We process personal data for the following purposes and on the following legal bases:
Where we rely on legitimate interests, you may object as described in Section 8.
We use strictly necessary cookies to operate the Service and, subject to consent, analytics and preference cookies. The public page and widgets embed YouTube players (iframe), which may set cookies subject to consent. Details, categories, retention, and consent management are described in the Cookie Policy. A consent banner is presented where required.
5.1. We share personal data only as necessary, with:
5.2. These recipients act as our processors under data-processing agreements, or as independent controllers where applicable. A current list of key subprocessors is available on request at Contact.
6.1. When you connect a YouTube channel, the Service retrieves and processes channel and video data (including video lists, metadata, and transcripts) to index and power search and conversational features. We do not integrate directly with YouTube API Services. This data is retrieved on our behalf by our third-party provider Supadata.ai (see Section 5), and then indexed by the Service.
6.2. Video playback is provided through an embedded YouTube player (iframe) on the public page and widgets. Playback on YouTube is governed by the YouTube Terms of Service (https://www.youtube.com/t/terms) and the Google Privacy Policy (https://policies.google.com/privacy). Embedded players may set cookies — see the Cookie Policy for how we handle this (e.g., click-to-load / privacy-enhanced mode).
6.3. Details on our video-data sourcing and related compliance considerations are in the “YouTube content & data sourcing” document
7.1. Some processors may process data outside the European Economic Area. Where this occurs, we rely on appropriate safeguards under Chapter V GDPR, primarily the European Commission’s Standard Contractual Clauses (SCCs) and, where applicable, adequacy decisions, together with supplementary measures as needed.
7.2. You may request information about the safeguards applied at Contact.
8.1. Subject to conditions in the GDPR, you have the right to: access your data; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; object to processing based on legitimate interests or direct marketing; and to withdraw consent at any time (without affecting prior processing).
8.2. To exercise these rights, Contact. We will respond within one month, extendable by two further months for complex requests, as permitted by the GDPR.
8.3. Right to lodge a complaint. You may complain to the Polish supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa (https://uodo.gov.pl) — or to the supervisory authority in your country of residence.
8.4. Where personal data relates to a Customer’s members or page visitors and Studio DR acts as processor, please direct data-subject requests to the relevant Customer (controller); we will assist the Customer as required under the DPA.
9.1. We retain personal data only as long as necessary for the purposes described, including:
9.2. On workspace deletion, connected content and associated personal data are deleted in accordance with our retention practices and the DPA.
10.1. When a church uses the Service to make its content searchable and to answer visitor questions, personal data of the church’s members and public-page/widget visitors is processed by Studio DR on behalf of the church (the controller).
10.2. This processing is governed by the DPA, which covers subject matter, duration, purposes, categories of data and data subjects, security measures, subprocessors, and assistance obligations. Data subjects should contact the relevant church for such data; we support the church in responding.
11.1. The Service uses automated and AI-based methods to index content and generate summaries, search results, and conversational responses. This does not constitute automated decision-making producing legal or similarly significant effects on individuals within the meaning of Art. 22 GDPR.
11.2. Generated responses may be inaccurate; see the “How Compendi works” / AI disclaimer document.
We implement appropriate technical and organizational measures to protect personal data, including access controls, encryption in transit, logging, and least-privilege practices. No method of transmission or storage is completely secure; we work to protect data and respond to incidents in accordance with our legal obligations, including breach notification where required.
The Service is directed at churches and their administrators (adults). It is not intended for children. We do not knowingly collect personal data directly from children through our own controller activities. Any processing of members’ data by a church is the responsibility of that church as controller.
We may update this Policy. For material changes we will provide notice (e.g., by email or in-product). The “Effective date” indicates the latest version.
Data Controller: Studio DR sp. z o.o.
ul. Malinka 65D/2, 43-460 Wisła, Poland
NIP: 548-10-11-757 · KRS: 0000112221
Privacy contact: Click here