WebConcept
Webconcept
Features How it Works Pricing Contact
EN|
Sign inGet Started
EN|

Legal

  • Terms of Service
  • Privacy Statement
  • Withdrawal
  • Data Processing Agreement

Privacy Statement

Version 1.0effective 1 October 2026

This English version is provided for convenience. The Polish version is the binding one and prevails in case of any discrepancy.

This Privacy Statement explains how CyberGorilla Sp. z o.o. processes personal data in connection with the operation of the WebConcept online platform available at https://webconcept.app (hereinafter: the "Platform"): the data of persons visiting the Platform, Account holders and persons acting on behalf of Customers, persons paying for services and persons who contact us. It fulfils the information obligation under Articles 13 and 14 GDPR and also covers information on cookies.

I. Data controller

The controller of your personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter: the "GDPR") is CyberGorilla Sp. z o.o. with its registered office in Warsaw, ul. Marszałkowska 58, 00-545 Warszawa, Poland, KRS: 0001148248, NIP: 7011240065, REGON: 540611381.

In all matters concerning personal data you may write to the e-mail address: [email protected] or to the Controller's registered address.

II. Purposes, legal bases and retention period

Purpose of processing Data Legal basis Retention period
Creating and maintaining the Account and signing in (including with a Google account) e-mail address, display name, chosen language and – depending on the sign-in method you choose – either a password in hashed form or the Google account identifier and the address of the profile picture from that account Article 6(1)(b) GDPR until the Account is deleted
Concluding and performing the contract: generating and hosting sites, handling the Subscription, service-related messages, complaints Account data, content of the Brief and of Projects, Subscription history Article 6(1)(b) GDPR until the Account is deleted
Payments, invoices, and tax and accounting obligations billing details provided at payment (name or business name, address, tax ID), payment and invoice history, Stripe identifiers, card label (brand, last 4 digits, expiry date); we do not receive full card data Article 6(1)(b) and (c) GDPR in conjunction with tax and accounting law for the period required by that law – as a rule 5 years from the end of the tax year
Replying to enquiries from the contact form and to correspondence name, e-mail address, company name (optional), message content, IP address Article 6(1)(f) GDPR (handling correspondence) and, where the enquiry aims at concluding a contract, Article 6(1)(b) for the time needed to handle the enquiry and then until the limitation period for claims expires
Security of the Platform and prevention of abuse IP address, browser data, Account event log (e.g. sign-ins), result of the anti-bot verification Article 6(1)(f) GDPR (protecting the Platform and its users) for the time necessary for that purpose, no longer than until the limitation period for claims expires
Statistics on the use of the Platform (chapter IX) an identifier assigned to the browser and, once you are signed in, the Account identifier, the addresses you visit and events on the Platform, information about the browser and device, the referring address, advertising campaign identifiers Article 6(1)(a) GDPR (consent) 12 months
Establishing, pursuing and defending against claims the data indicated above, to the extent necessary Article 6(1)(f) GDPR until the limitation period for claims expires

You may request deletion of the Account at any time, in particular by writing to [email protected]. We delete Account data without undue delay, no later than within one month of receiving the request. After the Account is deleted we keep only billing documents and the data necessary to defend against claims – for the periods indicated in the table. Deleted data disappears from backup copies when those copies are overwritten in their rotation cycle.

We do not process data for marketing purposes. The only data we process on the basis of consent is the statistical data described in chapter IX. Consent may be withdrawn at any time in your account settings, in the "Cookie settings" dialog, without affecting the lawfulness of the processing carried out before its withdrawal.

III. Source of data and obligation to provide it

We receive data directly from you. Exceptions: when you sign in with a Google account we receive from Google that account's identifier, your e-mail address together with the information whether Google has verified it, your profile name (first name and surname) and the address of your profile picture; we receive payment confirmations and payment data from Stripe; the data of a person acting on behalf of a Customer may be provided to us by the Customer.

Providing data is voluntary, but an e-mail address is necessary to create an Account and conclude a contract, and billing details are necessary to purchase paid services (they are also required by tax law). Without this data we cannot provide the services; without contact details we cannot reply to an enquiry.

IV. Recipients of data

We use providers that process data on our behalf or – like Stripe and Google with regard to their own services – as separate controllers:

Recipient Scope and purpose Location
Stripe handling payments and invoices, preventing payment fraud Ireland, USA
Google (Google Ireland Limited) signing in with a Google account – only if you use it; the authentication takes place on Google's side and Google processes it as a separate controller under its own privacy policy Ireland, USA
Cloudflare DNS and traffic proxy network, protection of forms against bots (Turnstile), storage of files and backup copies (R2) USA, global infrastructure
Resend (Plus Five Five, Inc.) sending the Platform's e-mail messages and messages from the contact form; message data is stored in the USA USA
Anthropic artificial intelligence system that generates the site; receives the content of the Brief (business name and description), does not receive Account or payment data USA
GitHub code repositories of generated sites USA
OVH servers on which the Platform and its databases run Poland, Germany
PostHog (PostHog, Inc.) statistics on the use of the Platform – only after consent is given (chapter IX); the statistical data is stored on servers in Germany (EU region) USA, Germany

We may also disclose data to entities providing us with accounting and legal services – to the extent necessary – and to public authorities where a provision of law so requires.

V. Transfers of data outside the European Economic Area

Some of the recipients indicated in chapter IV have their registered office or infrastructure in the United States. We transfer data there on the basis of the European Commission's adequacy decision for the EU–US Data Privacy Framework – with regard to recipients that hold a certification (Article 45 GDPR) – and in other cases on the basis of the standard contractual clauses approved by the European Commission (Article 46(2)(c) GDPR). A copy of the safeguards applied may be obtained by writing to [email protected].

VI. Your rights

You have the right to: access your data and obtain a copy of it (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), portability of data processed on the basis of a contract (Article 20) and – to the extent that the basis is the Controller's legitimate interest – the right to object at any time on grounds relating to your particular situation (Article 21).

To exercise these rights, please send a message to [email protected] or a letter to: CyberGorilla Sp. z o.o., ul. Marszałkowska 58, 00-545 Warszawa, Poland.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, Poland, https://uodo.gov.pl).

VII. Automated decision-making

We do not take decisions concerning you that are based solely on automated processing, including profiling, as referred to in Article 22 GDPR.

VIII. Data processed on behalf of Customers

With regard to data collected through Customers' sites hosted on the Platform (e.g. the data of persons visiting those sites and submitting forms on them), the controller is the Customer and we act as a processor, on the terms set out in the Data Processing Agreement. The rules for using the Platform are set out in the WebConcept Terms of Service.

IX. Cookies

Storing information on your device and reading it is governed by Article 399 of the Polish Electronic Communications Law of 12 July 2024 (Prawo komunikacji elektronicznej). We use cookies and browser storage that are necessary to provide the services you request (signing in, payment, language choice, protection of forms) without consent, in accordance with Article 399(3) of that Law. We ask for consent only with regard to statistical files – the basis here is Article 399(1) of that Law and Article 6(1)(a) GDPR. Some of these files contain personal data (e.g. access_token identifies the Account); we process it on the terms described in this Privacy Statement.

Name Provider Purpose Storage time
access_token WebConcept keeping you signed in 30 days or until you sign out
refresh_token WebConcept renewing the session; sent only to the session refresh address 30 days or until you sign out
session WebConcept securing sign-in with a Google account; stored only once that sign-in begins 14 days
browser storage: wc_locale, nuxt-color-mode, wc-pending-brief and the state of Panel notices WebConcept chosen language, site appearance, site description entered before registration, dismissed notices until browser data is cleared; session data – until the tab is closed
browser storage: wc_consent WebConcept remembering your decision about statistical files (a necessary file – it is stored also when you do not give consent) until browser data is cleared
__stripe_mid, __stripe_sid Stripe preventing payment fraud; only on payment pages and in Stripe Checkout 1 year / 30 minutes
Cloudflare Turnstile Cloudflare checking that a form (registration, sign-in, password reset, contact) is submitted by a human; reads technical information about the browser for the duration of the verification
ph_<token>_posthog PostHog statistics on the use of the Platform – only after consent is given; recognising the same device between visits up to 12 months from the last visit
browser storage: ph_<token>_posthog PostHog statistics on the use of the Platform – only after consent is given; device identifier and measurement state until consent is withdrawn or browser data is cleared
single-tab browser storage: ph_<token>_posthog, ph_<token>_window_id, ph_<token>_primary_window_exists, ph_<token>_session_registered_properties PostHog statistics on the use of the Platform – only after consent is given; data of a single visit (referring address, window identifier) until the tab is closed or consent is withdrawn

To analyse how the Platform is used we use PostHog (PostHog, Inc.) in the version with servers in the European Union (Germany); the <token> part of the names above is the identifier of our project in that tool. We run the tool only once you give your consent: before you make your decision, and also after you decline, it is not downloaded to the browser at all and sends no data – all we store then is your decision itself (wc_consent). Once consent is given, the tool records the addresses you visit and events on the Platform, information about the browser and device, the referring address and – when you arrive from an advertisement – the campaign and advertising click identifiers passed in the page address (e.g. utm_*, gclid). The IP address is not stored. We do not record sessions, do not build click maps and do not automatically collect the content of the elements you click. You may withdraw your consent at any time in your account settings, in the "Cookie settings" dialog; from the moment of withdrawal we collect no new data, and all of the tool's entries – both the cookie and the browser storage data – are deleted from your device. The statistical data itself, held on the provider's side, we keep for 12 months; that period is independent of the cookie lifetime given in the table.

You can manage cookies in your browser settings (blocking, deleting). Blocking the necessary files will make signing in and payments impossible. You manage your consent to statistical files in the "Cookie settings" dialog available in your account settings. We do not use marketing tools; if that changes, we will run them only after obtaining your consent and will update this chapter.

X. Final provisions

We apply technical and organisational measures appropriate to the risk involved in the processing of data (Article 32 GDPR).

The Platform contains links to external websites, including our social media profiles. Those websites operate independently of us and have their own privacy policies.

We may amend this Privacy Statement, in particular when the way data is processed, the list of recipients or the law changes. The current version, together with its effective date, is available at /en/legal/privacy-statement.

WebConcept

AI website builder. Describe your business and AI builds a complete site. No coding, hosting included.

Product

  • Features
  • How it Works
  • Pricing
  • What is WebConcept?

Company

  • About
  • Contact

Legal

  • Terms of Service
  • Privacy Statement
  • Withdrawal
  • Data Processing Agreement

© 2026 WebConcept. All rights reserved.

Made with AI

WEBCONCEPT