Privacy Policy
Last updated: 13 July 2026
This Privacy Policy explains how MyBusinessFit , available at mybusinessfit.com (“MyBusinessFit ”, “we”, “us”, or “our”), collects, uses, stores, and protects personal data when you use our website, Business Fit Assessment, Business Fit Preview, paid Business Fit Report, and related services.
MyBusinessFit is an AI-based business-fit platform that helps users understand what kind of business direction may fit their skills, experience, resources, goals, risk tolerance, and working style.
This Privacy Policy also explains your rights under applicable data protection laws, including the General Data Protection Regulation (“GDPR”), where applicable.
1. Data Controller
The controller of your personal data is:
AIREMES PSA
Ugorek 12/6
31-456 Kraków
Poland
Email: contact@airemes.com
If you have questions about this Privacy Policy or how your personal data is processed, you can contact us at the email address above.
2. Overview of Data Processing
We may process the following categories of data:
- Contact data: email address, name if provided.
- Assessment data: answers submitted through the Business Fit Assessment.
- Content data: free-text answers, business context, goals, resources, skills, preferences, and other information you choose to provide.
- AI-generated data: Business Fit Preview, Business Fit Report, recommendations, roadmap, scores, summaries, and related generated content.
- Payment-related data: payment status, payment amount, currency, Stripe identifiers, refund status if applicable.
- Usage data: pages visited, timestamps, assessment progress, checkout events, report access events.
- Technical data: IP address, browser type, device type, operating system, logs, error reports, and security events.
- Communication data: messages sent through contact forms or support emails.
We do not sell your personal data.
3. What Data We Collect
3.1 Business Fit Assessment Data
When you complete the Business Fit Assessment, we may collect information such as:
- your profession or current work situation,
- your skills and experience,
- your interests,
- your preferred working style,
- types of work that give you energy,
- types of work you want to avoid,
- available time,
- risk tolerance,
- goals,
- resources available to you,
- previous projects or business attempts,
- optional additional context you choose to provide.
You should not include sensitive personal data unless it is necessary for your request. For example, you should avoid providing information about health, political opinions, religion, biometric data, sexual orientation, criminal convictions, or other sensitive categories of personal data.
3.2 Email and Contact Data
We do not require your email address before you start the Business Fit Assessment.
We ask for your email address when it is needed to:
- save your assessment,
- create or complete your purchase,
- deliver your Business Fit Report,
- send you a secure report link,
- respond to support requests.
We do not automatically subscribe you to marketing emails when you complete an assessment or purchase a report.
3.3 Payment Data
Payments are processed by Stripe or another payment provider.
We may receive and store limited payment-related information, such as:
- payment status,
- payment amount,
- currency,
- Stripe checkout session ID,
- Stripe payment intent ID,
- payment date,
- refund status if applicable.
We do not store your full card number, card security code, or complete payment card details on our servers.
3.4 AI Report Data
When you purchase a Business Fit Report, we process your assessment answers to generate a personalized report.
We may store:
- your generated Business Fit Report,
- report status,
- secure report access token,
- report creation date,
- report delivery status,
- administrative quality-review status,
- regenerated versions if the report is regenerated.
3.5 Technical and Usage Data
When you visit the website, we may collect technical and usage data such as:
- IP address,
- browser type and version,
- device type,
- operating system,
- pages visited,
- timestamps,
- referring website,
- error logs,
- assessment started,
- assessment completed,
- preview viewed,
- checkout started,
- payment completed,
- report generated,
- report viewed.
This data helps us operate, secure, debug, and improve the website.
3.6 Contact Form and Support Messages
If you contact us by email or through a contact form, we may process:
- your name if provided,
- your email address,
- message content,
- any attachments or additional information you provide.
We use this data to respond to your inquiry and provide support.
3.7 Cookies and Similar Technologies
We may use cookies, local storage, or similar technologies for:
- essential website functionality,
- payment flow support,
- security,
- remembering basic preferences,
- analytics, if enabled.
Where required by law, non-essential cookies will be used only with your consent.
4. How We Use Your Data
We use your personal data for the following purposes.
4.1 To Provide the Service
We use your data to:
- allow you to complete the Business Fit Assessment,
- generate your Business Fit Preview,
- process your payment,
- generate your full Business Fit Report,
- deliver your report through a secure link,
- send your report link by email,
- provide customer support.
4.2 To Process Payments
We use payment-related data to:
- create and manage checkout sessions,
- confirm successful payments,
- process refunds where applicable,
- prevent fraud,
- keep transaction records.
4.3 To Generate AI-Based Reports
We use your assessment answers to generate your personalized Business Fit Report.
The report is intended to help you think about possible business directions based on your profile. It is educational and informational only. It does not guarantee business success, income, investment returns, employment outcomes, or any particular result.
4.4 To Improve the Service
We may analyze usage patterns, feedback, report quality, and conversion metrics to improve:
- assessment questions,
- preview quality,
- report quality,
- website design,
- payment flow,
- technical reliability.
4.5 To Communicate With You
We may use your email address to:
- send your report link,
- send payment or delivery-related messages,
- respond to your support requests,
- notify you about important service-related issues.
We will not send marketing emails unless you have given separate consent or another valid legal basis applies.
4.6 To Protect the Website and Prevent Abuse
We may process technical and usage data to:
- detect fraud,
- prevent abuse,
- secure the website,
- debug errors,
- investigate suspicious activity,
- enforce our terms.
4.7 To Comply With Legal Obligations
We may process and retain certain data where required by law, including for:
- accounting,
- tax records,
- fraud prevention,
- legal claims,
- regulatory compliance.
5. Legal Bases for Processing
Where GDPR applies, we process your personal data based on the following legal bases.
5.1 Performance of a Contract
We process your data where necessary to provide the service you requested, including:
- completing the Business Fit Assessment,
- generating the Business Fit Preview,
- processing your purchase,
- generating and delivering your Business Fit Report,
- providing access to your report.
5.2 Legitimate Interests
We may process data based on our legitimate interests, including:
- improving the service,
- securing the website,
- preventing fraud and abuse,
- analyzing basic usage patterns,
- maintaining business records,
- responding to support requests,
- monitoring report quality.
We only rely on legitimate interests where we believe our interests are not overridden by your rights and freedoms.
5.3 Legal Obligations
We may process and retain certain information to comply with legal obligations, including accounting, tax, and regulatory requirements.
5.4 Consent
We rely on your consent where required, for example for:
- non-essential cookies,
- marketing emails,
- optional newsletter subscriptions.
You can withdraw your consent at any time.
6. Third-Party Providers and Data Processors
We use third-party providers to operate the website, generate AI reports, process payments, send emails, host data, and maintain the service.
We share personal data with these providers only where necessary to provide the service, comply with legal obligations, prevent abuse, or improve technical reliability.
We do not sell your personal data.
6.1 Hosting and Infrastructure Providers
We use hosting and infrastructure providers to operate:
- the website,
- backend application,
- database,
- server logs,
- file storage if applicable,
- security and deployment infrastructure.
These providers may process technical data, usage data, assessment data, generated report data, and contact data on our behalf.
Current provider: hostedwindows.pl
6.2 AI Services
For AI-powered analysis and report generation, we may use one or more AI service providers.
Current or potential AI providers may include:
- OpenAI,
- Anthropic,
- other similar AI providers if added later.
We use AI services to generate:
- Business Fit Preview,
- Business Fit Report,
- business-fit profile,
- recommendations,
- roadmap,
- validation steps,
- report summaries.
The following data may be transmitted to AI providers:
- assessment answers,
- professional background provided by you,
- skills and experience provided by you,
- goals and preferences provided by you,
- resources and constraints provided by you,
- optional free-text context provided by you.
We do not intentionally send the following data to AI providers:
- payment card data,
- full payment details,
- Stripe payment identifiers unless technically necessary,
- billing card information,
- password data,
- internal admin credentials.
We also do not intentionally send your email address or name to AI providers unless it is necessary for a specific support or report-related task. However, if you include personal data inside free-text assessment answers, that data may be included in the content sent to the AI provider.
AI providers process transmitted data according to their own privacy policies and applicable service terms.
Where we use business/API access to AI providers, we aim to use provider settings and terms under which customer inputs and outputs are not used to train the provider’s general models by default, unless we explicitly opt in.
All transmissions to AI providers are intended to be encrypted using HTTPS/TLS.
6.3 Payment Processing — Stripe
We use Stripe to process payments for paid Business Fit Reports.
Stripe may collect and process payment-related information such as:
- payment card details,
- billing details,
- email address,
- payment amount,
- currency,
- transaction identifiers,
- fraud-prevention signals,
- payment method information.
Stripe handles payment data according to its own privacy policy, security practices, and legal obligations.
We do not store full card numbers, card security codes, or complete payment card details on our servers.
We store only limited payment-related records necessary to operate the service, such as:
- Stripe checkout session ID,
- Stripe payment intent ID,
- payment status,
- payment amount,
- currency,
- payment date,
- refund status if applicable.
Stripe may act as an independent controller for some payment-related processing and as a processor or service provider for other processing, depending on the context and applicable law.
More information is available in Stripe’s privacy documentation.
6.4 Email Service Provider
We may use an email service provider to send transactional emails, including:
- report delivery emails,
- secure report links,
- payment-related messages,
- support responses,
- service notifications.
Your email address and relevant message content may be shared with the email provider solely for the purpose of sending these emails.
Current provider: hostedwindows.pl
6.5 Analytics, Logging, and Error Monitoring
We may use analytics, logging, or error-monitoring tools to understand website usage, diagnose technical problems, prevent abuse, and improve the service.
Depending on the tools used, these providers may process:
- IP address,
- browser information,
- device type,
- visited pages,
- timestamps,
- error messages,
- event data,
- anonymized or pseudonymized usage data.
If we use non-essential analytics or tracking cookies, we will request consent where required by law.
Current analytics/logging providers: Google Analytics
6.6 Legal, Accounting, and Compliance Providers
We may share limited personal data with professional advisors where necessary, including:
- accountants,
- tax advisors,
- lawyers,
- compliance consultants,
- public authorities where required by law.
This may include payment records, invoices, transaction records, email communication, or support history where necessary.
7. International Data Transfers
Some of our service providers may process personal data outside your country or outside the European Economic Area (“EEA”).
This may include providers based in the United States or other countries that may not provide the same level of data protection as the EEA.
Where personal data is transferred internationally, we aim to use appropriate safeguards required by applicable law, such as:
- adequacy decisions,
- EU Standard Contractual Clauses,
- EU-U.S. Data Privacy Framework certification where applicable,
- data processing agreements,
- provider security and privacy commitments,
- HTTPS/TLS encryption during transmission.
Examples of providers that may involve international transfers include:
| Provider | Purpose | Possible location | Safeguard |
|---|---|---|---|
| OpenAI | AI report generation | United States / other locations | SCCs, DPA, provider privacy commitments where applicable |
| Anthropic, if used | AI report generation | United States / other locations | SCCs, DPA, provider privacy commitments where applicable |
| Stripe | Payment processing | United States / other locations | SCCs, DPA, DPF where applicable |
| Email provider | Transactional emails | Depends on provider | SCCs/DPA where applicable |
| Hosting provider | Website/database hosting | Depends on provider | Depends on provider |
Before publishing this policy, this table should be updated with the actual providers used by MyBusinessFit .
8. AI Processing
MyBusinessFit uses AI technology to generate personalized Business Fit Reports.
To generate your report, your assessment answers may be sent to an AI service provider, such as OpenAI, Anthropic, or another similar provider.
The AI provider processes this data to return generated content based on the information you provided.
We use AI to support analysis and content generation, but the report should not be treated as professional legal, tax, financial, investment, psychological, or business advice. The AI may produce inaccurate, incomplete, or unsuitable suggestions. You should validate any business idea independently before investing significant time or money.
The service does not make decisions that produce legal effects concerning you or similarly significant effects. The report is an informational recommendation tool. You remain fully responsible for any decisions you make based on the report.
9. Automated Decision-Making and Profiling
The Business Fit Report is generated based on the assessment answers you provide. This may involve automated analysis of your profile, preferences, skills, and goals.
However, MyBusinessFit does not use automated processing to make decisions that have legal effects or similarly significant effects on you. The output is a personalized informational report intended to support your own thinking and decision-making.
You are not required to follow any recommendation in the report.
10. Data Retention
We keep personal data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Our typical retention periods are:
- Assessment sessions and answers: up to 24 months after submission, unless deletion is requested earlier and no legal obligation requires retention.
- Generated reports: up to 24 months after generation, unless deletion is requested earlier and no legal obligation requires retention.
- Payment and accounting records: retained for the period required by applicable tax and accounting laws.
- Support communications: retained as long as necessary to handle the request and maintain business records, usually up to 24 months unless longer retention is necessary.
- Technical logs: usually up to 30 days, unless needed for security, debugging, fraud prevention, or legal reasons.
- Transactional email logs: retained as necessary to confirm delivery and troubleshoot service issues.
- Marketing consent records: retained until consent is withdrawn or as needed to demonstrate compliance.
We may anonymize data and use it for analytics or service improvement. Anonymized data does not identify you.
11. Security
We take reasonable technical and organizational measures to protect your personal data against unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include:
- HTTPS encryption,
- secure report access tokens,
- access controls,
- limited administrative access,
- server-side validation,
- secure configuration practices,
- logging and monitoring,
- use of reputable payment and infrastructure providers,
- storage of secrets outside public code repositories,
- administrative access restrictions.
However, no online service can guarantee absolute security.
You are responsible for keeping any report links private. Anyone with access to your secure report link may be able to view the report.
12. Your Rights
Depending on your location and applicable law, you may have the following rights:
- the right to access your personal data,
- the right to correct inaccurate data,
- the right to request deletion of your data,
- the right to restrict processing,
- the right to object to processing,
- the right to data portability,
- the right to withdraw consent where processing is based on consent,
- the right to lodge a complaint with a data protection authority.
To exercise your rights, contact us at:
contact@airemes.com
We may need to verify your identity before fulfilling your request.
If you are located in Poland, you may also have the right to lodge a complaint with the Polish data protection authority:
Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2
00-193 Warsaw
Poland
Website: uodo.gov.pl
13. Deleting Your Data
You may request deletion of your assessment answers and generated report by contacting us at:
contact@airemes.com
We will delete or anonymize your data unless we need to retain certain information for legal, accounting, fraud-prevention, dispute-resolution, or security reasons.
For example, we may need to retain payment records for tax and accounting purposes.
14. Email Communications
We may send the following types of emails:
- report delivery emails,
- secure report links,
- payment-related emails,
- refund-related emails,
- support responses,
- important service-related notices.
These are transactional or service-related emails.
We do not automatically subscribe you to marketing emails when you complete an assessment or purchase a report.
If we offer a newsletter or marketing updates, we will ask for separate consent where required. You can unsubscribe from marketing communications at any time.
15. Cookies and Local Storage
We may use cookies and local storage for:
- essential website functionality,
- secure session handling,
- payment flow support,
- remembering cookie preferences,
- fraud prevention,
- basic analytics if enabled,
- remembering UI preferences.
If we use non-essential cookies, analytics cookies, or advertising cookies, we will request consent where required by law.
Cookie Policy
Essential cookies are always active because they are required for website security, the assessment flow, payment flow, anti-forgery protection, admin login, secure report access, and storing cookie preferences.
Analytics cookies are optional. They help us measure page visits, assessment funnel events, preview-to-payment conversion, and report access analytics so we can improve MyBusinessFit .
Marketing cookies are optional. They may be used for advertising pixels, retargeting, and campaign measurement.
Non-essential cookies, including analytics and marketing cookies, are used only with your consent. You can accept all cookies, reject non-essential cookies, or customize your choices.
You can change your cookie preferences at any time by using the “Cookie settings” link in the website footer.
If we do not use tracking cookies, third-party analytics, or advertising cookies, the website may state:
“We do not use tracking cookies, third-party analytics cookies, or advertising cookies.”
This statement should only be included if it is true.
16. Children
MyBusinessFit is not intended for children.
You must be at least 18 years old to use the paid Business Fit Report service. We do not knowingly collect personal data from children.
If you believe that a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
17. Third-Party Links
Our website may contain links to third-party websites, tools, or services. We are not responsible for the privacy practices, content, or security of third-party websites.
You should review the privacy policies of any third-party services you use.
18. Accuracy of Information Provided by You
The quality of the Business Fit Report depends on the accuracy and completeness of the information you provide.
If your answers are incomplete, inaccurate, unrealistic, or misleading, the report may be less useful or unsuitable for your situation.
You should not provide information about other people unless you have a lawful basis to do so.
19. Business Transfers
If we are involved in a merger, acquisition, restructuring, sale of assets, financing, or similar transaction, your personal data may be transferred as part of that transaction where permitted by law.
In such case, we will take reasonable steps to ensure that your personal data continues to be protected.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
When we make changes, we will update the “Last updated” date at the top of this page. If the changes are significant, we may provide additional notice, such as through the website or by email.
Your continued use of the service after changes are published means that you acknowledge the updated Privacy Policy.
21. Contact
If you have questions about this Privacy Policy, your personal data, or your rights, contact us at:
AIREMES PSA
Ugorek 12/6
31-456 Kraków
Poland
Email: contact@airemes.com