Privacy Policy

Effective and last updated: 10 September 2026

1. Controller and contact

The controller is Advert Lab Norbert Dreszer trading as impleCode, Poland. Contact support@implecode.com for privacy questions and rights requests, or see our Contact page for our full business and postal details.

This policy covers our website, accounts, purchases, support, newsletters, affiliate programme and AI Enhance service. It explains the information we receive directly from you, from your browser or connected website, and from payment, security and service providers. Our Terms and Conditions describe the contractual service rules.

2. What we process and why

We use the following legal bases under the GDPR where it applies: performance of a contract or steps you request before entering one; compliance with legal obligations; our legitimate interests in operating, securing and improving the service; and consent for optional cookies and direct marketing where required. Where we rely on legitimate interests, you may object based on your circumstances. We assess those interests against your rights and reasonable expectations.

Main processing purposes and retention
Information and purpose Legal basis Retention approach
Browser, device, IP address and access/security events used to deliver pages, prevent abuse and investigate faults. Legitimate interests in service operation and security. Only as needed for operation and security; ordinary website analytics follows the separate 180-day policy below. Incident evidence may be retained while a claim or investigation is active.
Account identity, contact details, website URL, licence and client identifiers, authentication records and entitlement status. Contract; legitimate interests in authentication and fraud prevention. For the account or service relationship and the period needed to resolve disputes or meet legal obligations. Credentials are revoked when access ends.
Order, invoice, billing address, tax identification, transaction references, subscription and payment status. Contract and legal obligations. For applicable accounting and tax periods, generally five years calculated under the relevant statutory rule, and longer where a legal hold applies.
Support correspondence, contact requests, chat messages and requested troubleshooting information. Contract or legitimate interests in responding and supporting customers. While needed to resolve the request, provide continuing support and establish or defend claims. Ask us to review or erase information that is no longer needed.
Newsletter address, preferences and subscription/unsubscription records. Consent where required; legitimate interests in keeping a suppression record. Until you unsubscribe or the subscription is removed; a minimal suppression record may remain to honour your choice.
Public comments and reviews, author details and anti-spam information. Legitimate interests in publishing discussion and protecting the website. While the contribution remains published, unless removed or a legal obligation requires retention.
Optional visit analytics, session replay and affiliate referral attribution. Consent for optional tracking; contract/legal obligations for resulting affiliate payments. Website analytics and replay data is retained for up to 180 days under our retention policy; attribution cookies follow their configured lifespan and commission records follow accounting rules.
AI job inputs and outputs used to perform your enhancement. Contract for necessary service administration. Personal data is prohibited in AI content. 24-hour job expiry after completion, or the configured expiry, with hourly cleanup. Provider retention is described below.
AI technical request records used for operation, security, usage, pricing and billing. Contract, legitimate interests and legal obligations where applicable. Request IPs are blanked after 30 days; detailed request rows expire after 24 calendar months. Separate accounting and credit-ledger records follow their own legal retention.
Optional Content Analysis examples: submitted fields, generated fields and selected marketing controls. Legitimate interests in reviewing permitted examples and improving the service. 90 days, followed by scheduled cleanup; earlier deletion can be requested.

Information marked as required for an account, purchase or support request is needed to provide that function. Without it we may be unable to complete the request. We do not make solely automated decisions that produce legal or similarly significant effects about you.

3. Purchases, accounts, support and communications

Payment processors such as PayPal and Stripe receive the information necessary to process payment and address fraud, compliance and disputes. We receive transaction references and payment status and may retain your billing details for invoices and account administration. We do not ask you to send full payment-card details through email, chat or AI Enhance. Payment providers also process information under their own privacy notices.

When you contact us, we receive the information you provide and relevant service/account details. Tawk supplies optional live chat. If you post a comment or review, the published content and displayed author details are visible to others. Avatar services such as Gravatar and spam-prevention services may process identifiers when their functionality is used. External websites linked from our pages have their own privacy practices.

Newsletter subscriptions are optional. You can unsubscribe through the message link or contact us. Service, billing and security notices may still be sent where necessary for your account. AffiliateWP records permitted referral attribution and resulting commission information; affiliate payment records are distinct from optional visitor-tracking cookies.

4. AI Enhance data flow and restrictions

AI Enhance sends selected field values, reference/context fields, answers to clarifying questions and selected enhancement controls from your website through impleCode to the configured model provider, currently OpenAI through the WordPress AI connector. Generated fields are returned for your review. We also process the connected site URL, client and key identifiers, post type, target, model, timestamps, status, request sizes, latency, usage and cost information.

Do not submit personal data, sensitive data, confidential information, secrets, children’s data, payment or financial-account data, authentication credentials, health information, government identification numbers, trade secrets or otherwise regulated data. Remove such information from fields, context and question answers before submission. This service is intended for permitted non-personal content. If prohibited data is submitted accidentally, stop further submissions and contact support with the request identifier or timing, without sending the prohibited information again.

Full job inputs and outputs expire 24 hours after terminal completion or at the configured expiry. Hourly cleanup removes expired content, so physical deletion can occur shortly after that deadline. Expired queued or running jobs have their content removed and their reserved enhancement restored under the processing rules. Technical request metadata is separate from full content: request IPs are blanked when older than 30 days, and detailed request records are deleted when older than 24 calendar months. Accounting, usage aggregates, credit ledgers, orders and tax records are not deleted by that technical-log cleanup.

OpenAI has its own processing controls. We configure these API calls not to store response objects. Under OpenAI’s published API policy, business/API data is not used to train its models by default, but abuse-monitoring logs may contain content and ordinarily be retained for up to 30 days, subject to legal obligations and applicable provider settings. Our local 24-hour expiry does not control OpenAI’s retention. See OpenAI API data controls and OpenAI business data privacy.

5. Optional Content Analysis

Optional Content Analysis is checked by default in the AI settings. When enabled, impleCode retains submitted fields, generated fields and selected marketing controls so we can review real enhancement examples and improve the service. Examples also carry request/client identifiers, model, post type and creation time. Records older than 90 days are removed by scheduled cleanup.

This is an optional service-improvement setting based on our disclosed legitimate interests. You can uncheck it at any time to prevent collection for future requests. Existing examples normally remain subject to the 90-day limit, but you may request earlier deletion or object to this processing by contacting support. We may verify your authority before acting on a request. Switching this setting off does not prevent the processing necessary to perform an enhancement and does not switch off website cookie preferences.

6. Cookies, local storage and your choices

Necessary cookies and storage support authentication, sessions, security, shopping-cart and checkout functions, and remember your privacy choices. Optional categories start switched off. The banner offers Accept All, Reject Optional and Manage Preferences. You can reopen Privacy settings from the footer to change or withdraw permission at any time. Refusing optional tracking does not prevent browsing or purchasing; refusing chat storage prevents the embedded chat service from loading.

Storage categories and providers
Category Provider and purpose Typical duration
Necessary ic_privacy_choices records your analytics/chat choices. WordPress authentication and security cookies, service sessions, cart and checkout storage support requested functions. Privacy choices: 180 days. Other necessary storage lasts for the session or the relevant login/cart period.
Analytics Google Analytics 4, including _ga cookies, measures visits. We disable advertising personalization and Google signals in our loader. Our visitor-cookie limit is up to 13 months; analytics data follows the 180-day policy.
Analytics Through https://api.implecode.com/, including _pk_ cookies, measures website use. Visitor cookie: up to 13 months; session cookie: 30 minutes; analytics data follows the 180-day policy.
Analytics Smartlook records permitted website sessions to understand usability. Form values, IP collection and sensitive pages are excluded by our integration settings. Provider/session identifiers follow the configured service limits; recordings follow the 180-day maximum policy or a shorter provider limit.
Analytics AffiliateWP referral and visit cookies, such as affwp_ref and affwp_ref_visit_id, attribute visits to affiliates. For the referral period configured in our affiliate programme; commission records follow accounting retention.
Chat Tawk chat cookies and local/session storage, including tawk_uuid_*, twk_idm_key and TawkConnectionTime, maintain the optional support conversation. Session storage or up to six months for visitor identifiers, depending on the provider item.
Requested payment PayPal and Stripe may use their own essential transaction, fraud-prevention and authentication storage when you select their payment service. According to the relevant payment provider’s notice and the transaction/security purpose.

Withdrawing a choice stops future loading and clears known first-party cookies/storage where technically possible; it does not automatically erase records already held by providers. You can also use your browser’s storage controls.

7. Recipients and international processing

Information may be disclosed to hosting and infrastructure suppliers, email and support providers, security and anti-spam services, payment processors, professional advisers and authorities where necessary for the purposes above. The named analytics, affiliate, chat and AI providers receive information only in connection with their enabled service. Suppliers acting on our instructions are required to use appropriate contractual and security protections. Some payment providers and authorities act as independent controllers.

Providers may process information outside Poland and the European Economic Area, including in the United States. Where GDPR transfer restrictions apply, the transfer must use an applicable adequacy decision or appropriate safeguards, such as European Commission standard contractual clauses and any necessary supplementary measures. Contact us for information about safeguards relevant to your processing and to request a copy where available. We do not claim that all third-party processing is anonymous or that no personal information is shared.

8. Retention, security and children

We retain information for the purposes and periods explained above and delete, anonymize or review it when it is no longer needed. A legal obligation, active dispute or security investigation can justify retaining the relevant evidence longer; this does not permit unrelated data to be kept indefinitely. Backup copies may remain temporarily until replaced through the backup cycle and are restricted from ordinary use. Scheduled cleanup can be delayed by service outages and resumes when scheduling is restored.

We use access controls and reasonable technical and organizational measures to protect information. No internet service or transmission is completely secure. Protect your account and contact us promptly about suspected unauthorized access.

Our services are intended for adults able to enter a contract, not for children. Do not submit children’s information through AI Enhance. Contact us if you believe a child has supplied information so we can investigate and take appropriate action.

9. Your rights and complaints

Where applicable, you may request access, correction, erasure, restriction and portability of your personal data. You may object to processing based on legitimate interests and to direct marketing. You may withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. Cookie consent can be withdrawn through Privacy settings; newsletter consent through the unsubscribe link.

Send requests to support@implecode.com. We may ask for proportionate information to verify identity or authority and will respond within the time required by law. Some rights are subject to exceptions, including retention required by law and the rights of others. We will explain any relevant limitation.

You may lodge a complaint with the President of the Personal Data Protection Office in Poland (UODO), or another competent supervisory authority, particularly where you live, work or believe an infringement occurred. You do not have to contact us before exercising that right.

10. Policy updates

We may update this policy when our services or legal obligations change. The date above identifies the current version. We will provide additional notice of material changes where required. For questions about this policy or our Terms and Conditions, contact support@implecode.com.

Privacy preferences

Necessary storage is always active. Optional choices start switched off.


Google Analytics, Matomo, Smartlook session replay and AffiliateWP attribution.


Tawk chat and its storage.