Hyzo Privacy Policy
Last updated: 16 September 2026
This Privacy Policy explains how personal data is processed in connection with hyzo.io, the waitlist, the beta version, and services and features made available under the Hyzo brand (“Hyzo” or the “Service”).
1. Data controller
The data controller for the processing described in this Privacy Policy is:
Michał Kozicki, conducting business under the name MICHAŁ KOZICKI DIGRA, entered in the Polish Central Register and Information on Economic Activity (CEIDG), Tax Identification Number (NIP) 7582288800
Address: Jaśminowa 16, 07-410 Ostrołęka, Poland
Email: hello@hyzo.io
Telephone: +1 518 730 0517
In this Privacy Policy, the controller is referred to as the “Controller”, “Hyzo”, “we”, “us” or “our”.
For all privacy and personal-data matters, you may contact us at hello@hyzo.io. If the Controller appoints a Data Protection Officer, the officer’s contact details will be made available as required by applicable law.
2. Scope of this Policy and our roles
Depending on the circumstances, Hyzo may act as a data controller or as a processor acting on behalf of a user.
Hyzo acts as a controller in particular with respect to data connected with account creation and administration, the waitlist, user communications, security of the Service, complaints and support, billing, legal compliance, analysis of use of the Service, and — where the user has given the required consent — marketing communications.
Where a user inputs, uploads, synchronises or otherwise makes available personal data of other individuals within projects, tasks, documents, messages or integrations and determines the purposes and means of using that data, the user may be the controller of that data and Hyzo may act as a processor on the user’s behalf. Such processing is also governed by the Data Processing Agreement included as an appendix to the Hyzo Terms of Service.
The user is responsible for having an appropriate legal basis for providing third-party personal data to Hyzo and, where required, for providing the relevant privacy information to those individuals.
3. Categories of data we may process
Depending on how Hyzo is used, we may process the following categories of data.
3.1. Account and contact data
This may include your first and last name, email address, company or team name, role, account preferences and information required to authenticate the user.
3.2. Waitlist and beta-program data
This may include your first and last name, email address, information about your way of working, answers about your needs and problems, information submitted through forms, and feedback provided during testing.
3.3. Service usage data
This may include information about the Hyzo features you use, actions you perform, when and how you use particular features, workspace configuration, errors and technical events, and information needed to provide security and diagnostics.
3.4. Technical data
This may include IP address, device type, operating system, browser type and version, session identifiers, timestamps, login information and connection-security information.
3.5. User Content
Depending on the features available in a particular version of Hyzo, this may include projects, tasks, notes, descriptions, deadlines, documents, files, comments, your clients’ data, content uploaded by you and other information stored in your workspace.
3.6. Integration data
If you intentionally connect Hyzo with a third-party service, such as an email account or another tool, Hyzo may receive data covered by the permissions you approve during the authorisation process. The exact scope of access is determined by the permissions displayed by the provider of the relevant integration and may differ depending on the feature and the stage of development of Hyzo.
Hyzo requests only permissions necessary to provide the feature selected by the user and does not request access in advance for features that have not been implemented.
3.7. Data used by AI features
This may include prompts, data submitted for analysis, task context, data derived from User Content, AI-generated responses and metadata needed to perform and secure the requested operation.
3.8. Payment and billing data
As of the date of this Privacy Policy, the Hyzo Beta is provided free of charge and Hyzo does not collect payment-card details as part of the Beta. If paid plans are introduced, Hyzo will process data necessary for billing, such as purchaser details, invoice details, selected plan and payment status. If payments are handled by an external payment provider, payment-instrument data will be processed in accordance with that provider’s rules to the extent necessary to complete the transaction.
4. Purposes and legal bases for processing
We process personal data only where an appropriate legal basis exists.
| Purpose | Examples of data | Legal basis |
|---|---|---|
| Creating an account and providing the Service | account data, User Content, technical data necessary to provide the Service | Article 6(1)(b) GDPR — performance of a contract or steps taken before entering into a contract |
| Operating the waitlist and handling applications | name, email, form answers | Article 6(1)(f) GDPR — legitimate interests in managing applications, waitlist access and communications; marketing communications require a separate legal basis as described below |
| Beta applications and Beta access | application data and account data | Article 6(1)(b) GDPR — pre-contractual steps at the individual’s request and performance of the Beta agreement |
| Providing AI features selected by the user | prompts, inputs, context and outputs | Article 6(1)(b) GDPR — performance of a contract |
| Providing integrations enabled by the user | data covered by approved permissions | Article 6(1)(b) GDPR — performance of a contract; for data entrusted by the user, Hyzo may act as a processor |
| Contact, support and handling requests | contact data, correspondence, diagnostic data | Article 6(1)(b) or 6(1)(f) GDPR — legitimate interests in supporting users and maintaining service quality |
| Security, abuse prevention and protection of accounts and infrastructure | logs, IP address, login and event data | Article 6(1)(f) GDPR — legitimate interests in protecting the Service, users and Controller |
| Establishing, pursuing or defending legal claims | account, contract and communication data | Article 6(1)(f) GDPR — legitimate interests in protecting legal rights |
| Legal, accounting and tax obligations | identification, transaction and billing data | Article 6(1)(c) GDPR — compliance with a legal obligation |
| Analytics necessary for security and operation | technical and service-operation data | Article 6(1)(f) GDPR, unless separate consent to access the user’s terminal equipment is required |
| Analytics, personalisation or measurement based on non-essential cookies or similar technologies | device identifiers, cookies, events | user consent under Article 399 of the Polish Electronic Communications Law and, where personal data is processed, Article 6(1)(a) GDPR |
| Electronic direct marketing and commercial information | email and consent records | prior consent required under Article 398 of the Polish Electronic Communications Law and, for personal data, generally Article 6(1)(a) GDPR |
| Analysing beta feedback and improving the product | feedback, feature-usage information, testing results | Article 6(1)(f) GDPR — legitimate interests in improving and developing the Service; where consent is required for a specific activity, Article 6(1)(a) GDPR |
Where processing is based on legitimate interests, we consider the necessity of the processing, the user’s reasonable expectations and the impact on the user’s rights and freedoms.
4.1. Is providing data mandatory?
Data marked as required for account creation, entering into or performing a contract, or using a particular feature is necessary to use that part of the Service. Without such data, we may be unable to create an account, provide Beta access, perform the selected Integration or handle the user’s request.
Data used solely for marketing or other consent-based purposes is voluntary. Refusing consent does not affect access to the core Hyzo functionality. If paid services are introduced, certain billing details may be required by tax or accounting law.
4.2. Sources of personal data
We may receive data directly from the user, from the account and device used to access Hyzo, from Integrations enabled by the user, from a person or organisation inviting the user to a Workspace, and from User Content submitted to the Service.
Where third-party data reaches Hyzo solely as User Content processed on the user’s instructions, Hyzo may act as a processor and the relevant controller remains responsible for privacy notices to the data subject. If Hyzo independently becomes a controller of personal data not obtained directly from the individual, Hyzo will comply with Article 14 GDPR to the extent applicable and subject to statutory exceptions.
5. Personal data of third parties contained in User Content
Hyzo is a work-organisation tool. Users may enter information about clients, collaborators, contractors or other individuals. Where that data is processed on the user’s instructions, Hyzo processes it only to provide the Service in accordance with the user’s instructions, the Terms of Service and applicable law.
Users should not intentionally submit special categories of personal data under Article 9 GDPR, data relating to criminal convictions and offences, children’s data or other highly sensitive information unless they have an appropriate legal basis, the processing is genuinely necessary and the relevant Hyzo feature is intended to support that type of processing.
6. Google Workspace and Gmail integrations
During the Beta, the standard Gmail integration is primarily intended for the email → task workflow: identifying information relevant to the user’s work in email messages and turning it into tasks, project context, deadlines or other work-organisation items in Hyzo.
After a Google account is connected, Hyzo may access basic Google account information required to identify the user and — after the relevant permission has been granted — read-only Gmail message data necessary to provide this feature. This may include message content, subject line, sender and recipient information, date and time, message and thread identifiers, labels and other basic message metadata. If the relevant Beta feature supports attachment analysis, attachment content may be processed only to the extent necessary to perform the user-requested function.
The standard Beta integration does not require permission to send emails on the user’s behalf, delete messages, forward messages or otherwise modify the user’s mailbox. If a future feature requires broader access, Hyzo will request the additional permission in context when the feature is enabled and will update this Privacy Policy before such processing begins.
Gmail data is used only to provide Hyzo functionality to the user, including identifying potential tasks, creating or enriching tasks and projects, organising context and presenting analysis results. Hyzo may retain tasks, summaries, source references and other results saved in the user’s Workspace. Hyzo is not an email-archiving service and does not retain a mailbox as an independent email archive.
Hyzo’s use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Google Workspace data is not sold, used for advertising profiling or personalised advertising, or used to determine creditworthiness. Hyzo does not use data obtained from Google Workspace to create, train or improve general, shared or non-personalised machine-learning or AI models. Human access to such data is limited to circumstances permitted by Google’s policies, for example where the user gives explicit consent for support, where access is necessary for security, or where access is required by law.
Users may revoke Hyzo’s access to their Google account through their Google Account settings and, where the feature is available, by disconnecting the integration within Hyzo.
7. Service providers and recipients of data
Personal data may be disclosed only to the extent necessary for the relevant purpose. Categories of recipients may include:
- hosting, cloud infrastructure, database and file-storage providers;
- authentication and security providers;
- customer communication, email delivery and support providers;
- analytics, error-monitoring and technical infrastructure providers, subject to applicable consent requirements and law;
- AI model and AI infrastructure providers where necessary to perform a feature selected by the user;
- external integration providers, including Google, where the user enables a relevant Integration and only to the extent necessary for that Integration;
- payment, accounting and billing providers if paid plans are introduced;
- legal, tax and accounting advisers, auditors and insurers where necessary to protect our rights or comply with legal obligations;
- public authorities and other entities entitled to receive data under applicable law.
The Controller does not sell users’ personal data.
Where the user acts as a data controller and Hyzo acts as its processor, the rules governing subprocessors are set out in the Data Processing Agreement attached to the Terms of Service. Information about categories of recipients and, where required by law, specific recipients or processors is made available to the extent required by applicable law.
8. International data transfers
Some technology providers may process data outside the European Economic Area. Where personal data is transferred to a third country, we use a transfer mechanism required by the GDPR, as appropriate, including:
- a European Commission adequacy decision;
- European Commission Standard Contractual Clauses together with supplementary safeguards where required; or
- another mechanism permitted under Chapter V GDPR.
On request, we may provide information about the transfer mechanism used in relation to a particular provider to the extent required by law.
9. Data retention
We retain personal data no longer than necessary for the purpose for which it was collected, taking into account legal obligations, security requirements and the need to establish, pursue or defend claims.
We apply the following criteria in particular:
- account data and information necessary to provide the Service — for the duration of the contract and afterwards for the period needed to close the account, settle the relationship, comply with legal obligations and protect against claims;
- User Content — while the Service is being used and for a technically justified period needed to remove it from active systems and backups, unless law requires longer retention;
- billing data — for the period required by tax and accounting laws;
- security and log data — for a period proportionate to security, diagnostics and abuse-prevention purposes;
- data processed on the basis of marketing consent — until consent is withdrawn or the relevant marketing purpose ends earlier;
- waitlist and beta-program data — until the purpose is completed, the user withdraws, an effective objection is made, or further retention is no longer reasonably necessary;
- data related to claims — until the relevant limitation period expires and, where proceedings have started, for the time needed to conclude them.
10. Your rights
Where the GDPR applies, depending on the legal basis and circumstances of processing you may have the right to:
- access your personal data and obtain a copy;
- rectify inaccurate data;
- erase data;
- restrict processing;
- data portability;
- object to processing based on Article 6(1)(e) or (f) GDPR;
- withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal;
- lodge a complaint with a competent supervisory authority, including the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) in Poland.
To exercise your rights, contact hello@hyzo.io. Where we have reasonable doubts about the identity of the person making a request, we may ask for additional information necessary to verify identity.
11. Automated decision-making and AI
Hyzo may use AI to organise information, suggest tasks, extract context, propose priorities or support other productivity features.
In its standard form, the Service is not intended to make decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect an individual within the meaning of Article 22 GDPR.
If a feature of that nature is introduced, appropriate information and safeguards will be provided before that processing begins.
12. Cookies, local storage and similar technologies
Hyzo may use cookies, local storage and similar technologies.
Strictly necessary technologies may be used without separate consent where they are necessary to provide a service expressly requested by the user, for example to maintain a session, provide security, authenticate a user or remember settings necessary for the operation of the Service.
Analytics, advertising, personalisation or other non-essential technologies require prior consent where Article 399 of the Polish Electronic Communications Law applies. Such technologies are not activated before the required consent is given unless applicable law permits their use without consent.
Users may refuse consent and later withdraw it as easily as they gave it. Information about technologies currently in use is provided in the consent-management interface or cookie information reflecting the actual configuration of the website.
13. Marketing communications
Commercial information and direct marketing by email or other telecommunications terminal equipment will be sent only where the prior consent required by applicable law has been obtained or another clearly applicable legal basis permits it.
Marketing consent is voluntary and may be withdrawn at any time. Opting out of marketing does not affect access to the core Service. Technical and transactional communications necessary to perform the contract may still be sent.
14. Security
The Controller applies appropriate technical and organisational measures proportionate to the nature, scope, context and risk of the processing, in accordance with the GDPR. Measures may include access controls, authentication, transmission security, security monitoring, permission limitations and incident-response procedures, to the extent implemented in the relevant Hyzo environment.
No method of transmission or storage can guarantee absolute security. Users are responsible for protecting their credentials, devices and third-party accounts connected to Hyzo.
15. Children’s data
Hyzo is intended for professional and business use and is not directed to individuals under 18. We do not knowingly invite children to create accounts or provide personal data for use of the Service.
If the Controller becomes aware that an account was created by a person who does not meet the age requirement, the Controller may take steps to restrict access and erase data as required by law.
16. Changes to this Privacy Policy
This Privacy Policy may be updated, including as Hyzo’s features, technology providers, processing practices or applicable law change.
Where a change materially affects how a user’s personal data is processed, we will provide appropriate notice before the change takes effect where required by law. The current version will be published on the Hyzo website together with the date of the latest update.
17. Change of the entity operating Hyzo
Hyzo may in the future be operated by a company or another entity created or involved in connection with a reorganisation, investment, sale of a business or transfer of the Hyzo project.
If such a change results in a change of controller or transfer of personal data to a new controller, users will be informed to the extent and within the time required by law. This Privacy Policy does not itself constitute consent to unrestricted transfer of personal data outside the requirements of the GDPR or other applicable law.
18. Contact
For privacy, personal-data or data-subject-rights matters, contact:
Email: hello@hyzo.io
Telephone: +1 518 730 0517
Controller details:
MICHAŁ KOZICKI DIGRA
NIP: 7582288800
Address: Jaśminowa 16, 07-410 Ostrołęka, Poland
19. Language versions
This Privacy Policy may be made available in Polish and English. Both versions are intended to describe the same data-processing rules. In the event of an interpretative discrepancy, the Polish version is the source version to the extent permitted by mandatory law. This does not limit any rights granted to a user by law that cannot be excluded by contract or notice.