← Home

Privacy Policy

This policy explains how personal data is processed when you use the Creduna website and services. The controller is Krzysztof Kwiatkowski K2, Zecerska 23/1, 51-180 Wrocław, Poland, tax ID (NIP) 6912440973, a sole proprietorship entered in the Polish Central Register and Information on Economic Activity (CEIDG). Contact in all data protection matters: contact@creduna.co.

1. What data we collect

  • Contact form on the home page: email address, the monthly spend range you select and the language version of the page.
  • Credit application form: name, company email address, company name, website, country, year founded, team size, funding stage and backers, a description of the product and its use of AI, current Claude and AWS spend, whether you have an AWS account and optionally its account ID, and previous credits received.
  • Correspondence: the content of emails you send us and your contact details.
  • Technical data: IP address and basic request data, which the server may record in logs for security and diagnostics.

We do not ask for special categories of data. We do not collect the Organization ID issued to you by an AWS Activate Provider.

2. Data from your AWS account

When you grant read-only access, we read billing data and usage counters such as token counts per model. This is business data. It may incidentally include identifiers of IAM users or roles. We do not have access to prompts, model outputs or the content of your applications, and we do not read them.

If you choose to paste request content into one of our tools, it is processed in memory to produce the result and is not stored.

3. Why we process data and on what basis

  • To check eligibility, prepare applications and perform the analysis you asked for: steps taken at your request before entering into a contract and performance of a contract (Article 6(1)(b) GDPR), and your consent given in the application form (Article 6(1)(a) GDPR).
  • To answer your messages and keep in touch about the service you asked for: our legitimate interest in handling enquiries (Article 6(1)(f) GDPR).
  • To secure the website and establish, pursue or defend claims: our legitimate interest (Article 6(1)(f) GDPR).
  • To meet accounting and tax obligations where a paid service is provided: legal obligation (Article 6(1)(c) GDPR).

Providing data is voluntary, but without it we cannot check eligibility or prepare applications.

4. Automated assessment and location

The eligibility result shown after you submit the form is calculated automatically from your answers against the published program rules. It is informational, has no legal effect and is not a decision about you. The decision on credits is made by AWS or Anthropic.

When you open the home page, your IP address is compared with a database stored on our server to choose the language version. The address is not sent to any third party and is not stored for this purpose.

5. Who receives the data

We use the following processors, who act on our instructions:

  • Hosting of the website and database: Hetzner Online GmbH (Germany), servers in Helsinki, Finland.
  • Amazon Web Services and Anthropic: when we use Claude to prepare a report or draft answers from your form, the relevant content is sent to the model provider for processing.
  • Google: if we keep a copy of applications in a Google Sheets spreadsheet.
  • Our email provider, for correspondence.

We do not sell personal data and do not share it for advertising. We do not submit applications to AWS or Anthropic on your behalf; you submit them yourself.

6. Transfers outside the European Economic Area

Some of these providers are based in the United States or may process data there. Such transfers rely on an adequacy decision, including the EU-US Data Privacy Framework where the provider is certified, or on the standard contractual clauses adopted by the European Commission. You can ask us for details of the safeguard that applies.

7. How long we keep data

  • Contact form data: up to 24 months from our last contact, or until you object.
  • Application data: for the duration of our cooperation and afterwards for the limitation period of possible claims, or until you withdraw consent where consent is the only basis.
  • Accounting records: for the period required by law.
  • Server logs: for a short period needed for security and diagnostics.

8. Your rights

You have the right to access your data, have it corrected or erased, restrict its processing, receive it in a portable format, and object to processing based on our legitimate interest. Where processing is based on consent, you can withdraw it at any time; this does not affect processing carried out before the withdrawal.

To exercise these rights, contact us through contact@creduna.co. You also have the right to lodge a complaint with the supervisory authority; in Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa).

9. Cookies

The website uses only cookies that are necessary for it to work:

  • creduna_lang: remembers that you chose the English version, for up to one year.
  • creduna_admin: keeps the administrator signed in to the internal panel. It is not set for visitors.

We do not use analytics, advertising or social media cookies, and we do not track you across other sites. Fonts are served from our own server.

10. Security

Connections to the website are encrypted. Access to the database and to the internal panel is restricted and protected. Access to client AWS accounts is read-only, limited in scope and can be revoked by the client at any time.

11. Changes

We update this policy when the way we process data changes. The current version and its date are always available on this page.