newAIway
Privacy Terms Support

Legal

Privacy Policy

Effective date: 4 October 2026

This policy tells you which personal data newAIway collects, why we use it, who else receives it, and what rights you have. It applies to the website newaiway.com, the web app my.newaiway.com, the newAIway mobile apps, the MCP server mcp.newaiway.com, and the newAIway plugin for Claude and ChatGPT (together, the "Service").

1. Who is responsible for your data

The data controller is Anton Batalin, a sole trader registered in Poland (CEIDG), operating under the name newAIway.

  • NIP (tax ID): 5842866731
  • REGON: 541386756
  • Address: ul. Chłopska 38D/6, 80-368 Gdańsk, Poland
  • Email: info@newaiway.com

For a shop that a company runs on newAIway (*.shop.newaiway.com), that company is the controller of its customers' data. We process that data only for the company and on its instructions. See section 7.

2. Data we collect

  • Account data: your email address, full name, job title, and a hashed password. We never store your password in plain text.
  • Sign in with Apple: the email address and, on the first sign-in only, the name that Apple sends to us.
  • Workspace content: the data that you and your team put into a company workspace — for example business processes, tasks, positions, AI agents, wiki pages, metrics, financial reports, products, conversations and uploaded files.
  • AI provider keys: if your company adds its own key for an AI provider, we store it encrypted.
  • Newsletter: your email address, if you subscribe on newaiway.com.
  • Technical data: server logs with the time of a request, the request path and errors. We use them to run and protect the Service.

We do not use analytics or advertising trackers on the Service.

3. Why we use your data, and the legal basis

Purpose Legal basis (GDPR)
Create your account, sign you in, and give you the Service Contract — Art. 6(1)(b)
Send service emails, such as sign-in links Contract — Art. 6(1)(b)
Send the newsletter Consent — Art. 6(1)(a). You can withdraw it at any time.
Keep the Service secure, find errors, and prevent abuse Legitimate interests — Art. 6(1)(f)
Keep accounting and tax records Legal obligation — Art. 6(1)(c)

4. AI features

Some features use large language models. When you use them, we send the needed part of your workspace content to an AI provider, and we save the answer in your workspace. We use Anthropic and OpenAI for this. We use OpenAI to make search indexes (embeddings) of wiki pages. If your company adds its own provider key, the content goes to the provider that your company chose.

We do not use your content to train AI models. AI answers can be wrong. Check important answers before you use them.

5. Claude, ChatGPT and other AI clients (MCP)

You can connect an AI client, such as Claude or ChatGPT, to your newAIway company through mcp.newaiway.com. You approve each connection on a consent page. The AI client then gets the same access as your role in that company: it can read data and, if your role allows it, create, change and delete data.

  • An access token is valid for 15 minutes.
  • A refresh token is valid for 30 days.
  • You can disconnect an AI client at any time in Settings → Connected assistants. After that, the current access token can work for up to 15 minutes.

The data that the AI client receives is also processed by the company that runs that client, under its own privacy policy.

6. Who receives your data

We use these service providers (processors). They process data only to give their service to us.

Provider What for Location
Amazon Web Services Hosting, file storage, encryption keys USA (us-east-1)
MongoDB Atlas Database USA
Resend Sending emails USA
Anthropic AI features USA
OpenAI AI features and search indexes USA
Stripe Payments in company shops USA / EU
Apple Sign in with Apple USA

We do not sell your personal data. We share it with authorities only when the law requires it.

7. Shops on newAIway

A company can run an online shop on newAIway. When you buy in such a shop, the shop collects your name, email, phone, shipping address, order details and support messages. Stripe processes your payment; we do not see or store your card number. The company that runs the shop is responsible for this data. Contact the shop first with questions about your order or your data.

8. Transfers outside the EEA

Most of our providers store data in the USA. For these transfers we rely on the EU–US Data Privacy Framework when the provider is certified, or on the EU Standard Contractual Clauses. You can ask us for a copy of the safeguards.

9. Cookies and local storage

  • Web app: the browser's local storage keeps your sign-in session (newaiway.session), your preferences, and the layout of the workspace.
  • Shops: two necessary cookies — __Host-shop_session keeps you signed in, and cart keeps your cart. Both last up to 30 days.
  • newaiway.com: no cookies.

We use only storage that is necessary for the Service, so we do not ask for cookie consent.

10. How long we keep data

  • Account data: while your account exists. After you ask us to delete it, we delete it within 30 days.
  • Company workspace: until an owner deletes the company. This deletion is permanent.
  • Sign-in links and sessions: they expire and are deleted automatically.
  • Newsletter: until you unsubscribe.
  • Accounting and tax records: as long as Polish law requires.

11. Your rights

Under the GDPR you have the right to:

  • get access to your data and a copy of it;
  • correct wrong data;
  • delete your data;
  • restrict how we use your data;
  • get your data in a portable format;
  • object to use based on legitimate interests;
  • withdraw your consent at any time.

To use a right, write to info@newaiway.com. We answer within one month. You can also complain to the Polish data protection authority, the President of the Personal Data Protection Office (UODO), uodo.gov.pl, or to the authority in your country.

12. Age

The Service is for people who are 18 years old or older. We do not knowingly collect data from children.

13. Security

We use encrypted connections (HTTPS), encrypted storage, hashed passwords, and access control by role. No system is perfectly secure. If a data breach puts your rights at risk, we will tell you as the law requires.

14. Changes to this policy

We can change this policy. We show the new effective date at the top. If a change is important, we tell you by email or in the app before it starts.

newAIway Privacy Terms Support info@newAIway.com