Skip to content
HeatAlgo

HeatAlgo

Privacy Policy

Last updated: September 1, 2026

1. Data controller

The controller of the personal data of Users of the HeatAlgo service, and of people who contact us through the forms on heatalgo.com, is Cratun Sp. z o.o., registered office at Niekłonice 49E, 76-024 Niekłonice, registry number (KRS): 0000971816, tax ID (NIP): 4990690625, REGON: 522021073. Data protection contact: [email protected]. This is a translation provided for convenience; the Polish version is authoritative.

2. What data we process

Account data: e-mail address, password (stored in encrypted form), first and last name, and - if the User provides them - company name, logo, phone number and website address (company details are displayed on the form shared with the client and in PDF documents), plus the preferred language.

Project data: data entered by the User within their projects (building parameters, calculations, drawings), including the User's clients' data, if the User enters it (see section 10).

Building documents: files or text the User pastes or uploads so AI can read data from them (e.g. a building design, a window/door schedule, an energy performance certificate, or photos of such documents) - see section 4.

Data from the contact and order forms on heatalgo.com (including from people who have no Account): name, e-mail address, phone number and the message content.

Data from the free calculators on heatalgo.com: the first name and e-mail address you give us so that we can send you the calculator result as a PDF file, and the values entered into the calculator itself (floor area, building type, insulation standard, climate zone, or room dimensions and pipe spacing). The underfloor heating calculator shows its result on the page without these data. In the heat loss calculator and the heat pump calculator we show the result only after you provide them - providing them is voluntary, but without it you will not see the result on the page and will not receive the PDF.

Technical and analytics data: pseudonymized application usage events (account identifier, without form contents - session recordings mask form fields), the AI assistant's technical logs described in sections 4 and 7, and server logs necessary to ensure security.

Providing account data is voluntary but necessary to conclude and perform the agreement - without it, an Account cannot be created.

3. Purposes and legal bases

Providing the service and managing the account - Art. 6(1)(b) GDPR (performance of a contract).

Reading data from building documents with AI, at the request of the User - Art. 6(1)(b) GDPR (performance of a contract). Details in section 4.

Responding to a contact-form inquiry and handling an ordered service - Art. 6(1)(b) GDPR (steps taken at the person's request before a contract).

Issuing invoices and billing - Art. 6(1)(c) GDPR (legal obligation).

Service-related communication, including notifications about the plan, the subscription and its renewal - Art. 6(1)(b) and (f) GDPR.

Product analytics and development of the Service - Art. 6(1)(f) GDPR (legitimate interest: improving the service). This covers visit and usage statistics, which need no consent because they involve neither recordings on the heatalgo.com website nor advertising profiling; inside the application, after signing in, they also cover session recordings with form-field masking (section 9).

Session recordings on the heatalgo.com website and the Google Ads and Meta advertising tools - Art. 6(1)(a) GDPR (consent). Without consent we start neither recordings nor those tools, and we store no advertising click identifier on the User's device. Consent can be withdrawn at any time, which does not affect the lawfulness of processing before the withdrawal - see section 9.

Sending the result of a free calculator as a PDF file to the address you give us - Art. 6(1)(b) GDPR (steps taken at the request of the data subject). We also use that address to present HeatAlgo's own offer - Art. 6(1)(f) GDPR (legitimate interest: direct marketing of our own services), with a right to object at any time. We do not pass calculator data to installers or to any other third party - that would need a separate consent, which we do not ask for.

Ensuring the security of the Service, including analysis of server logs - Art. 6(1)(f) GDPR (legitimate interest: security of the service).

We do not make automated decisions about Users, including profiling, that produce legal effects (Art. 22 GDPR).

4. Building documents and the AI assistant

The Service offers AI-based reading of data from building documents through the assistant: the User pastes or attaches documents in a conversation with the assistant - within a project or outside one - and the assistant reads the data from them. Documents may include, for example, a building design, a window/door schedule, an energy performance certificate, or photos of such documents.

Values read from documents are only proposed by AI - no such proposal enters the form or the calculation without the User's approval. Separately, on the User's explicit instruction, the assistant can change specified values in a project - described in the next paragraph below. AI never performs the heat demand calculation itself - that calculation is always carried out in full by an algorithm compliant with PN-EN 12831-1.

On the User's explicit instruction the assistant can change data in a project - setting a specified value in the calculation, for example. The instruction is the User's own message; the change is saved immediately, with no separate approval step. In that case the list of those actions and their parameters is also sent to the provider of the AI model. The assistant reports every change in the conversation together with a button that undoes it. To make that undo possible, before each change we store in the Service a copy of the previous version of the project document; we keep that copy for 30 days and then delete it - after that the change can no longer be undone. The effects of every action are visible in the Service.

Attached files are processed solely to read data from them in the conversation with the assistant: they are read in memory and discarded immediately after processing, with one exception - a file attached in a conversation in the underfloor heating module or the ventilation module can be chosen by the User as the storey's floor plan. That happens only when the User presses a button; only then is the file stored in the project like any other plan. Without that press we do not store it. Text pasted into the conversation is part of the conversation and is stored with it. Documents are processed on our behalf by the provider of the AI model, Anthropic (Anthropic PBC, USA), under a data processing agreement; the provider retains them under its own policy (currently up to 30 days) and then deletes them.

If a document contains personal data (e.g. an investor's details), the User remains its controller under the terms described in section 10 - the Provider and Anthropic process it solely on the User's instructions, as part of the reading described above.

Beyond reading documents, the Service offers an AI assistant that answers questions about a project and reviews the calculations it contains. For that purpose a slice of the project data - the building's technical data, the system designed in that module, and the results the Service calculated for them - is sent to the provider of the AI model (Anthropic). The slice does not include data identifying the User's client: no name, address or contact details.

Conversations with the assistant are stored in the Service, on the User's account, so that the User can return to them - unlike attached files, which are not stored. A message that concerned a particular project is linked to it: once the project is deleted, the message is no longer shown or used, and its permanent erasure follows the terms in section 7. Other conversations are kept for the duration of the contract.

The Service uses an AI model in three scopes. Checking a project and talking to the assistant work the same way in this respect: to answer, the Service sends the building's technical data - areas, envelope elements, temperatures, the locality, and in the ventilation module also the rooms with their volume and occupancy, the selected unit and the declared operating modes - to an external provider's AI model. Data identifying the User's client takes no part in that technical data. Documents attached to the assistant go to the same model, in the same conversation - the model reads them in the message they were sent with. The file itself is not saved in the Service or in the stored conversation; what remains in the conversation are the file's name and the assistant's answers, including the values it read from the document, and the technical log (section 7) may cover a short summary of the model's reasoning.

5. Data recipients

Data is processed on our behalf by infrastructure providers: Supabase (database, authentication and file storage), Railway (application hosting), Resend (e-mail delivery), PostHog (product analytics, servers in the EU), and Anthropic (the AI model provider - see section 4). We have data processing agreements in place with each of these providers. For booking a call through the website we use Cal.com (Cal.com, Inc., USA) - Cal.com receives the data the person booking enters in the booking form.

Only after consent to advertising purposes has been given does data also reach Google Ireland Limited (Google Ads) and Meta Platforms Ireland Limited (the Meta pixel). These act here as separate controllers rather than as processors acting on our instructions: they determine the purposes of processing within their own advertising systems. Without consent no data reaches them, because their tools are not started at all.

Resend, Railway, Anthropic and Cal.com may process data outside the European Economic Area (in the United States); transfers take place on the basis of Standard Contractual Clauses (SCC). The same applies to Google and Meta if the User consents to advertising purposes. A copy of the safeguards can be obtained by contacting us at the address indicated in section 1.

6. Stripe as a separate controller

Payments for purchases made directly in the Service are handled by Stripe, which acts as the seller in them. For those transactions Stripe is a separate data controller and not a processor acting on our instructions: it determines its own purposes, including tax settlement, fraud prevention, payment dispute handling and contact with the buyer. We have no processing agreement with Stripe covering that data and we do not instruct it. Stripe's own privacy policy, at stripe.com/privacy, describes what it does.

Payment card details never reach us at any point. Stripe tells us that a payment succeeded, its amount and currency, the buyer's country and the transaction identifiers, and, for subscriptions, their state (renewal, failed payment, cancellation, refund) - the minimum we need to unlock the purchased feature and to keep our own books.

7. Retention period

We store account and project data for the duration of the contract. After an account or project is deleted, the data is marked as deleted and permanently erased from operational copies within 90 days, except for data whose longer retention is required by law (e.g. billing records - 5 years).

Data entered into a calculator (first name and e-mail address) is kept until you object to marketing or ask us to delete it - we act on either without delay, at the address in section 1.

Contact form data (name, email address, phone number and message) is kept for as long as it may be needed for correspondence with the person who sent it and for evidentiary purposes relating to a concluded or prospective contract. You can ask us to delete it at any time at the address in section 1, and we will do so without delay.

Conversations with the AI assistant are kept for the duration of the contract, on the same terms as account and project data.

Technical logs of AI assistant calls are kept for 30 days; if the same request content is sent again, its copy is kept for up to 30 days from the last sending. The log includes the content of the request sent to the model - project data, without investor-identifying data - and a short summary of the model's reasoning, which may refer to the conversation's content.

8. Rights of data subjects

The User has the right to access their data, to rectify it, to erase it, to restrict its processing, to data portability, and to object to processing based on legitimate interest. Please send requests to the address indicated in section 1.

The User also has the right to lodge a complaint with the President of the Personal Data Protection Office (UODO, uodo.gov.pl).

9. Cookies, analytics and consent

The Service uses essential cookies and browser storage to maintain the login session, remember the chosen language, and store the consent choice itself. The Service does not work correctly without them, so they are not subject to consent.

Product analytics runs independently of consent and is configured with privacy in mind: PostHog does not store IP addresses, identification is based on the account identifier rather than on personal data, and we pass none of it to any advertising network. The identifier by which PostHog recognises the browser is kept in the browser's storage on the same basis. The basis is legitimate interest (section 3), and such processing can be objected to on the terms in section 8.

Session recordings on the heatalgo.com website are started only with consent and only on that basis; inside the application available after signing in they are part of the product analytics described above, on the basis of legitimate interest. Session recordings mask form fields - what the User types into them does not reach a recording (numeric fields and selection lists, which carry no personal data, are the exception). The rest of the page is recorded as displayed, so we tag the elements that present personal data to keep them out of recordings. The floor plan uploaded in the underfloor heating module is recorded as well - masking does not cover the drawing, so it appears in a recording as it does on screen.

The Google Ads and Meta advertising tools are started only with consent to advertising purposes. The same consent covers storing an advertising click identifier on the device, which is how we know which campaign led to a purchase; we keep it for at most 90 days. Without consent we store no such identifier, and the Google and Meta scripts are not fetched at all.

Consent can be changed or withdrawn at any time - the “Consent” link in the footer of the heatalgo.com website opens the same panel in which the first decision was made. Withdrawing consent to advertising purposes immediately deletes the click identifier stored on that website; the copy stored in the heatalgo.app application is deleted the next time the User goes from the website to the application, and if no such visit follows - at the latest after 90 days, when the identifier expires on its own. An advertising script already fetched in the same tab stops collecting data once consent is withdrawn, and is gone from it after the page is reloaded.

10. Data of the User's clients

The User may enter into the Service personal data of their clients (e.g. the investor's first and last name, the project site address, contact details). This data may also reach the Service directly from the User's clients - through forms the User shares with them. In both cases the User remains the controller of that data, and the Provider processes it solely on the User's instructions, for the purpose of providing the service, as a processor.

The User's instruction also covers use of the AI assistant: to answer the User's question, check their calculation or read data from attached documents - which may contain the client's personal data - the Provider sends, respectively, the building's technical data or the documents' content to an external provider's AI model, and keeps the content of the request in a technical log on the terms in section 7. The User can turn off the keeping of assistant request content in the technical log in Settings; the switch works from that moment on, and content stored earlier leaves the log under the 30-day rule.

11. Changes to this policy

We will inform Users of material changes to this policy by e-mail or by a notice in the Service before they take effect.