Persooa - frequently asked questions 2026 Version 2026.1
We have gathered the most frequent questions about how we work with data, AI, privacy and security - relevant in retail, e-commerce, banking, insurance and telecommunications. The answers are informational; specific commitments are governed by contracts (DPA, NDA, SLA).
A. ESG and responsible growth
1. Does Persooa have an ESG / responsible growth policy? Yes. Our Responsible Growth Policy is based on a remote-first model, digital delivery, efficient use of the cloud and continuous improvement.
2. Does Persooa commit to Net Zero or carbon neutrality? No. We deliberately do not make Net Zero, SBTi or carbon-neutrality commitments. We avoid greenwashing and declare only what we genuinely have an impact on - which protects your ESG reporting from the risk of unreliable supplier data.
3. What is Persooa's environmental footprint? Low by nature. As a remote-first organization, we do not maintain offices, we limit travel (a low-travel model), we work paperless and we use energy-efficient cloud. Details in the Supplier Sustainability Statement.
4. How does Persooa reduce its commuting-related footprint? Remote work is our standard, and our international talent network collaborates digitally. We undertake business travel only when it brings genuine value.
5. Can you provide data for our ESG / scope 3 reporting? We can provide a qualitative description of our operating model and practices. We do not report unreliable emissions figures; if you require specific data, we will agree on a realistic, sustainable scope.
6. How does ESG at Persooa translate into concrete actions rather than declarations? Our greatest contribution lies in governance - Responsible AI, data ethics and security. That is where we genuinely reduce customer risk, not in marketing environmental promises.
7. Does Persooa have a diversity and equal-treatment policy? Yes. Our Code of Conduct affirms equal opportunity regardless of, among other things, race, religion, origin, gender, age, disability, marital status and sexual orientation; we base HR decisions on competence and results. Mobbing and harassment are prohibited, and health-and-safety rules apply.
8. Does Persooa apply a Code of Conduct? Yes - the public Persooa Code of Conduct covers, among other things, integrity and compliance with the law, anti-corruption, conflict of interest, protection of confidential information and intellectual property, competition law, ethics of suppliers and partners, and reporting violations without the risk of retaliation. We can also sign your Supplier Code of Conduct if it is consistent with our practices.
B. AI Governance
9. Does Persooa have a Responsible AI Policy? Yes - the Responsible AI Policy covers human-in-the-loop, explainability, data minimization, bias mitigation, security controls and GenAI principles.
10. Are AI decisions supervised by a human? Yes. Decisions with a significant impact on the end customer remain under human supervision (human-in-the-loop). AI supports the decision; it does not remove responsibility from the organization.
11. How do you classify the risk of AI use cases? In a risk-based model (low/medium/high risk), consistent with the AI Act approach. We do not carry out high-risk cases in regulated areas without a mandate and oversight on the customer's side.
12. Is Persooa compliant with the AI Act? We design solutions in line with the spirit of the AI Act (a risk-based approach, transparency, human oversight). The compliance of a specific deployment depends on the use case and is established jointly with the customer as the controller/deployer of the system.
13. Are AI models explainable? For decision and recommendation models, we can describe the operating logic, the key features and the limitations. Where the risk requires it, we prefer interpretable solutions.
14. How do you manage bias and discrimination in models? We test models for unintended discrimination, we monitor drift and data quality, and we do not use sensitive characteristics (or their proxies) as a basis for targeting.
15. Do you maintain a register of models / AI use cases (model inventory)? Yes, for AI projects carried out for the customer we maintain a register of use cases with an assigned owner responsible for compliance.
16. Who is responsible for AI governance on Persooa's side? Every AI project has an assigned owner. Decisions to launch high-risk cases require approval on the customer's side.
17. How do you use generative AI (GenAI)? In accordance with our GenAI principles: human verification, a ban on entering the customer's confidential data into tools without appropriate guarantees, labelling of AI content where required, and a ban on manipulative uses.
18. Will our data be used to train your models? No. We do not use the end customer's personal data to train our own models or for the benefit of other customers. The data serves only the purposes agreed in the contract. Any use of fully anonymized data (which does not allow identification) to improve service quality takes place only insofar as the contract/DPA permits it.
19. Is there a "kill switch" for AI automation? Yes. Operators have the ability to stop and override the operation of the automation, together with defined escalation points to a human.
20. How do you ensure the auditability of AI and agent decisions? Agents' decisions and actions are logged and can be traced. We design critical actions to be reversible or to require confirmation.
C. Customer-data governance
21. Who owns the data in a project? The customer remains the owner of their data at every stage. As a rule, Persooa acts as a processor on behalf of the customer; with respect to our own operational processes (e.g. handling contact enquiries) we may act as a controller of our own data.
22. Does Persooa use one customer's data for the benefit of another? No. Data is strictly isolated at the project level and is not used for other purposes or for the benefit of other entities.
23. What happens to the data after the engagement ends? Data is returned or deleted in accordance with the contractual arrangements. We enforce the agreed retention periods.
24. How do you implement the data-minimization principle? We process only the data necessary for the purpose; we prefer pseudonymization and aggregation. In AI projects, the model receives only the data genuinely needed.
25. How do you manage end-customer consents? Data activation takes place within the bounds of consents and preferences. Withdrawing consent must be just as easy as giving it, and channel and frequency preferences are respected during execution.
26. Where is the data physically stored? Usually on the Synerise platform or in the customer's infrastructure, in accordance with the project architecture and the customer's location requirements. Synerise offers various deployment options - we agree on the choice at the design stage. Details: synerise.com/security.
27. Do you support the fulfilment of data-subject rights (DSAR)? Yes. We support the customer in handling requests for access, rectification, erasure and restriction of processing.
28. Do you use subcontractors (sub-processors) for data? We keep the supplier chain short and transparent. The use of sub-processors takes place on the terms agreed with the customer in the DPA.
29. Can data be processed exclusively in the EU/EEA? Yes, if the customer requires it - we adapt the architecture and processing location to the customer's regulatory requirements and policies.
30. How do you ensure the quality and correctness of data? As part of delivery, we take care of data hygiene (gap-free tracking, deduplication, validation), because data quality determines the quality of AI decisions.
D. Privacy
31. Is Persooa compliant with the GDPR? Yes. We act as a processor in accordance with the GDPR and are ready to conclude a data processing agreement (DPA). Details in the Security & Governance Statement.
32. Will you sign our data processing agreement (DPA)? Yes, we sign DPAs - ours or yours, once the wording is agreed.
33. Do you apply privacy by design? Yes. We design privacy into the architecture from the start; we do not bolt it on at the end. The purposes of processing are transparent, and data is not used for purposes incompatible with its intended one.
34. How do you handle data transfers outside the EEA? Where they apply, we use appropriate mechanisms (e.g. standard contractual clauses) and prefer architectures that minimize transfers.
35. Do you process special categories of data (sensitive data)? By default we avoid it. If a use case requires it (e.g. in health insurance), we carry it out only on an explicit legal basis and on the customer's instruction, with additional safeguards.
36. How do you protect the data of children / minors? We apply special caution and do not target vulnerable groups. We establish specific restrictions with the customer in accordance with applicable regulations.
37. Does the end customer know that data is being personalized? We support transparent communication on the customer's side. Personalization should not be "magic" - the principles are described in the Customer Data Ethics Charter.
38. Do you have a designated person responsible for data protection? Yes, data-protection matters have a clear owner in the organization; we provide contact details as part of the collaboration.
E. Security
39. Do you hold security certifications (SOC 2, ISO 27001)? The layer that processes end-customer data is usually the Synerise platform, which - according to its official statement (synerise.com/security) - provides enterprise-grade security together with SOC 2, GDPR and CCPA compliance. Persooa, as a remote-first implementation partner, bases its security on this platform, on recognized cloud providers and on its own policies. We confirm the status of Persooa's own certifications during due diligence; we do not claim certifications that we do not hold.
40. Will you complete our security questionnaire? Yes - we complete questionnaires (SIG, CAIQ, the customer's own questionnaires) and participate in security reviews.
41. How do you manage access to systems and data? The least privilege and need-to-know principles, MFA for critical systems, regular access reviews and immediate offboarding.
42. Is data encrypted? Yes - using the data-protection mechanisms provided by the Synerise platform and cloud providers (encryption in transit and at rest). Details of the platform's security architecture: synerise.com/security.
43. What does your incident-management process look like? We have a defined reporting and response process. In the event of an incident concerning customer data, we inform the customer promptly and support them in their notification obligations, and then we carry out a root-cause analysis.
44. How do you secure the team's remote work? We apply secure remote-work rules: encrypted devices, password managers, MFA, awareness of threats (phishing, social engineering).
45. Do you run security awareness training? Yes. The team is required to observe security rules and takes part in activities that build awareness of threats.
46. How do you verify the security of your suppliers? As part of vendor governance, we select subcontractors and tools taking into account their security practices, preferring providers with recognized certifications.
47. Does Persooa hold liability insurance (general liability / cyber / PI)? We confirm the scope and sums insured of the policies we hold during the due diligence process, and on request we present an insurance certificate. We do not state in an informational document data that requires confirmation against the current state of the policies.
48. How do you ensure business continuity (BCP/DR)? We ensure delivery continuity through: (1) a distributed talent network that reduces dependence on any single person (key-person risk), (2) high-availability and backup mechanisms at the level of the cloud platforms and Synerise, (3) versioned documentation and artifacts in secure cloud environments. We present a detailed BCP/DR description and RTO/RPO parameters during due diligence and govern them in the SLA.
49. Can you provide references and case studies? Yes. At the due diligence stage, we provide references and project descriptions. We disclose the identity and details of customers only with their consent, in accordance with our Confidential Information Protection Policy and NDA commitments.
F. Responsible personalization (by industry)
50. (Retail / E-commerce) Does Persooa's personalization use dark patterns? No. We do not design mechanics based on false urgency, hidden costs or an obstructed opt-out. We optimize for long-term customer value (CLV), applying frequency capping and contact hygiene.
51. (Banking) Does Persooa's AI make credit or scoring decisions? We do not carry out automated credit scoring or decisions with a significant legal effect without an explicit mandate, a legal framework and full human oversight on the bank's side. Our typical cases are personalization, retention and Next-Best-Action in marketing.
52. (Insurance) How do you ensure fairness in insurance targeting? We do not use sensitive characteristics or their proxies for targeting, we test models for discrimination and we apply special caution toward sensitive products and groups. Decisions with a significant impact remain under human supervision.
53. (Telco) How do you responsibly manage retention and loyalty programs at a large data scale? We design programs for lasting value and trust, not short-term exploitation: we respect consents and preferences, we apply frequency capping, we protect customers in difficult circumstances and we ensure the auditability of automation and AI agents' actions.
G. Business ethics and compliance
54. Does Persooa have an anti-corruption policy? Yes. An internal Anti-Corruption and Anti-Fraud Policy applies, prohibiting, among other things, bribery, the bribery of persons performing public functions, cronyism and nepotism, trading in influence, and unreliable financial documentation - regardless of the value of the benefit.
55. Do you conduct anti-corruption due diligence on counterparties? Yes. In higher-risk processes we assess, among other things, whether the counterparty comes from a country with a high Transparency International corruption perception index, and the links of people in its bodies with persons in prominent political positions (PEP). The assessment is documented according to an established report template; the Management Board makes the decision on cooperation with a non-recommended counterparty.
56. How do you manage conflicts of interest? A Policy for Preventing and Managing Conflicts of Interest applies. A report may be filed by any person or entity; the assessment is carried out by a person independent of the one the report concerns, acting after signing an NDA and preparing a written report. A confirmed conflict results in the person being excluded from the relevant activities. We maintain a register of reports.
57. Do you apply competition-law compliance principles? Yes. A Competition Law Compliance Policy applies, which strictly prohibits bid-rigging, price-fixing agreements, market allocation and the exchange of strategic information with competitors. We are aware of the sanctions (up to 10% of turnover for a company, up to PLN 2 million for managers, invalidity of practices by operation of law), which is why we act independently in procurement proceedings; on request we will provide a statement of the independent preparation of the bid.
58. How do you protect the customer's trade secrets, and will you sign an NDA? Yes. We precede access to confidential information with a confidentiality commitment (NDA - ours or yours). We apply a formalized Trade Secret Protection System (information classification, access minimization, incident log). We are liable for confidentiality maintained by further subcontractors as for our own actions (flow-down).
59. Do you enable whistleblowing? Yes. We enable the reporting of suspected violations of the law, ethics, corruption or fraud; a ban on retaliatory action applies to those who report in good faith. Reports are examined by the Management Board or a designated person.
Did you not find your question? Write to kontakt@persooa.com - we will supplement the answer and, if needed, the security questionnaire. Informational document; binding commitments are governed by contracts (DPA, NDA, SLA).