Snapshot 19504
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Privacy
Privacy Policy
Last updated: 24 September 2026
01Who we are (data controller)
The controller of your personal data is Krzysztof Dalewski, conducting business under the trade name CellDelta, ul. Capri 4/18, 02‑762 Warsaw, Poland — NIP 5214160761, REGON 544460460, entered in the Polish Central Register of Business Activity (CEIDG).
Questions about this policy or your data: [email protected]. Given our scale and the nature of our processing, we are not required to appoint a Data Protection Officer, and as an EU‑established controller we do not require an Article 27 representative.
Two deployment modes. On the managed service, a workbook you submit for a full-file check is processed on our cloud infrastructure to produce a verdict and then deleted — for that content you are the controller and we act as your processor under a Data Processing Agreement. In a self-hosted deployment (your own cloud or on-premises), your workbooks and verdicts never reach us at all.
02What we collect
From the website (celldelta.ai)
What you enter in the contact form: your name and email address, and optionally your company, phone number and a message.
Standard request data your browser sends (IP address, browser type, referring page), used for security and basic operation.
The form needs your name and email address so that we can reply to you; the company, phone number and message are optional and entirely up to you.
From the product (the MCP service and verification tools)
Account details, where you hold an account: email address and organisation name.
Edits you submit for an edit-level check (verify_ops): the proposed value and any context you choose to pass. Processed in memory to compute a verdict; not stored.
Workbooks you submit for a full-file check (verify_workbook): processed server-side to recompute the model and return a verdict, then deleted (see Retention).
Audit & evidence records: timestamped verdicts and your decisions (accept / override / reject), sealed in a SHA-256 hash chain. Each entry stores an ops_digest — a one-way hash of the edits — not your cell values.
This website uses no analytics, no advertising and no tracking of any kind, and no browser local storage. It sets one functional cookie, cd_lang, only when you choose a language (for example with the EN / PL switch): it remembers that choice (en or pl) for one year so the site opens in your language, and it is used for nothing else. The fonts and scripts the site needs are served from our own domain, so loading a page makes no third-party requests.
03No model, no learning
CellDelta is deterministic: every verdict is produced by fixed, versioned rules, so identical inputs always yield an identical verdict. This has direct privacy consequences:
We do not run a language model as part of verification, and we do not transmit your spreadsheets or edits to any AI provider (such as Anthropic, OpenAI, Google or Microsoft). The AI that proposes an edit is your own assistant, operated by you under your own terms with that provider.
We do not train, fine-tune or improve any model on your data, and we do not profile you. There is no "learning" step — per-client rules, where used, are written and version-pinned by humans, never inferred from your data.
04Legal basis for processing (GDPR)
Steps taken at your request prior to a contract (Art. 6(1)(b)) — when you submit the website contact form, we use the details you enter to receive and answer your message, arrange a walkthrough and provide access; and to provide the service to account holders.
Legitimate interests (Art. 6(1)(f)) — our legitimate interest, balanced against your rights, in (a) following up on the enquiry you started with relevant information about CellDelta, and (b) securing and operating the service (authentication, rate-limiting, abuse prevention). You can object to (a) at any time (see Your rights); we do not send unrelated marketing on this basis.
Consent (Art. 6(1)(a)) — only where you separately and optionally opt in to marketing communications beyond your enquiry (e.g. a newsletter). We do not ask for this to respond to your message, and you can withdraw it at any time.
05How we use your information
To reply to your message and, if you want one, arrange a walkthrough. When you send the form, we also email you one automatic confirmation that it arrived (at most one per address in 24 hours).
To provide and operate the verification service and return verdicts and evidence.
To secure the service (authentication, rate-limiting, abuse prevention) and meet our legal obligations.
We do not sell your data, rent it, or share it with advertisers, and we do not use it for behavioural marketing.
06Processors & sharing
We do not sell or rent personal data. A small number of vendors process data on our behalf, under data-processing terms, strictly to run the service:
Railway Corporation (cloud hosting, United States): hosts the managed service and the endpoint that receives the website contact form, and provides ephemeral storage for workbooks submitted for a full-file check.
Cloudflare, Inc. (content-delivery and edge network, United States): serves and protects the website and processes your IP address in transit.
Brevo (Sendinblue) (transactional email, EU): sends us the notification of your contact-form message and sends you one confirmation that it arrived; it also relays our replies and account notices.
Our business mailbox provider: the inbox at [email protected] where the notification of your message is received and read.
GitHub, Inc. (source-code hosting, United States): holds our source code and does not process your personal data in normal operation.
We keep contact-form data minimal: your name and email address, and any company, phone number or message you choose to add; we do not store it in a separate marketing database. The current list of our sub-processors, with their roles, locations and transfer safeguards, is published at our sub-processors page.
We may disclose data where required by law, or to establish, exercise or defend legal claims. We are not in the business of running AI models, so your content is never passed to a model provider by us.
07International transfers
Our managed service, including the endpoint that receives the website contact form, is currently hosted in the United States (Railway), with Cloudflare (US) serving the site. Submitting the form therefore transfers your name, email address and any optional details outside the European Economic Area. For these and any other sub-processor outside the EEA, we rely on appropriate safeguards: the EU-US Data Privacy Framework where the provider is certified, and/or the European Commission's Standard Contractual Clauses. A copy of the relevant safeguard is available on request, and the per-recipient basis is listed on our sub-processors page. We keep the data minimal and short-lived (see Retention). For customers who require EU-only data residency, that is available through a self-hosted or EU-region enterprise deployment.
08Data retention
Contact-form data: kept while we handle your enquiry and, if it does not lead to an account, for up to 24 months after our last contact to manage the relationship and defend potential claims, then deleted. You can ask us to delete it sooner at any time (see Your rights).
Confirmation check: to avoid sending you duplicate confirmations, the server keeps a short one-way fingerprint (hash) of your email address, not the address itself, for 24 hours.
Submitted workbooks & edits: processed to produce a verdict and not retained as a working store. Any transient copy is held only to compute the verdict and is removed automatically within a bounded time-to-live, by default one hour of inactivity.
Audit & evidence log: retained as tamper-evident control evidence on the basis of our legitimate interest in providing reproducible control evidence. On the managed service the hash-chained log is durably retained in an append-only store for 24 months (configurable), then automatically purged; self-hosted deployments configure their own retention and control the storage. Entries contain edit digests and metadata, never cell values.
Account data: kept for the life of the account; deleted on closure, save for records we must keep by law.
09Your rights
Under the GDPR you may: access your data; rectify it; erase it ("right to be forgotten"); restrict or object to processing; receive it in a portable format; and withdraw consent at any time (without affecting processing already carried out).
To exercise any right, email [email protected]; we respond within one month, and may extend that by up to two further months for complex or numerous requests (we will tell you if so). You also have the right to complain to the Polish supervisory authority — Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00‑193 Warsaw, uodo.gov.pl.
10Security
We apply technical and organisational measures appropriate to the risk, including: encrypted transport (TLS); fail-closed authentication with constant-time comparison and cryptographically random identifiers; session isolation by unguessable identifiers, with the managed service operated single-tenant per deployment; per-IP and per-key rate limiting; a SHA-256 hash-chained, tamper-evident audit log; and data minimisation (storing edit digests rather than cell values). We log a truncated client IP address for security and abuse-prevention, kept for a short period (typically 30 to 90 days). For each contact-form message, these logs also hold a short one-way hash of your email address, not the address itself. Only if the notification to us cannot be delivered do we log the address itself, so that your message is not lost. The full IP is processed transiently for rate-limiting and, together with your browser type, is included in the internal notification of your message. Because no model runs inside verification, much of the data-exposure surface that AI tools carry is simply not present. Our full security overview is on our security page, and a DPA is available on request.
11Automated decision-making
CellDelta's verdicts are deterministic, reproducible control outputs — Blocked, Flagged or Passed — intended to inform a human reviewer. They are not solely-automated decisions producing legal or similarly significant effects about you; a person makes the final call on any edit.
12Children's privacy
CellDelta is not directed at, or intended for, anyone under 16.
13Changes & contact
We may update this policy as the service evolves; changes are posted here with a new "last updated" date. For anything privacy-related:
Krzysztof Dalewski (CellDelta)
ul. Capri 4/18, 02‑762 Warsaw, Poland
NIP 5214160761 · REGON 544460460
[email protected]
+48 733 077 407