Privacy Policy
Last updated: 27 September 2026
Ares Horizon Prosta Spółka Akcyjna ("Ares Horizon", "we", "us", or "our") respects your privacy and is committed to protecting personal data.
This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website, communicate with us, or use the Ares Horizon platform and related services.
1. Who We Are
Ares Horizon Prosta Spółka Akcyjna is a company registered in Poland.
Registered address:
Kwitnącej Łąki 2B
02-971 Warsaw
Poland
Website: areshorizon.com
Privacy contact: privacy@areshorizon.com
For personal data that we collect directly for our own purposes, Ares Horizon acts as the data controller within the meaning of Regulation (EU) 2016/679 ("GDPR").
When our customers upload or connect data to the Ares Horizon platform, we generally process that data on their behalf as a data processor, while the relevant customer remains the data controller.
2. Information We Collect
Depending on how you interact with Ares Horizon, we may collect the following categories of personal data:
Website and contact information
When you contact us, request a demonstration, submit a form, attend a meeting, or otherwise communicate with us, we may collect:
- name;
- business email address;
- telephone number;
- company and job title;
- information contained in correspondence with us;
- meeting and demonstration information; and
- information you voluntarily provide.
Account information
When you use the Ares Horizon platform, we may process:
- name and business contact details;
- company and organisation information;
- account identifiers;
- user roles and permissions;
- authentication and security information; and
- account activity.
Technical and usage information
We may automatically collect limited technical information necessary to operate, secure, and improve our services, including:
- IP address;
- browser and device information;
- login information;
- timestamps;
- system activity;
- security and audit logs;
- error and diagnostic information; and
- information about interactions with the platform.
Customer Data
Customers may provide or connect information to Ares Horizon through documents, contracts, supplier records, ERP systems, document management systems, APIs, or other integrations.
Such information may incidentally contain personal data, for example names, business contact information, employee information, supplier representatives, directors, beneficial owners, or other individuals referenced in business records.
Where we process this information on behalf of a customer, we act as a data processor and process the information according to the customer's instructions and our applicable Data Processing Agreement.
3. How We Use Personal Data
We may process personal data to:
- provide and operate the Ares Horizon platform;
- create and administer user accounts;
- authenticate users and manage permissions;
- provide customer support;
- respond to enquiries and demonstration requests;
- communicate with customers and prospective customers;
- manage contractual relationships;
- monitor the security and reliability of our systems;
- investigate errors, misuse, or security incidents;
- improve the functionality and performance of our services;
- comply with legal, regulatory, accounting, and security obligations;
- establish, exercise, or defend legal claims; and
- send relevant B2B communications about Ares Horizon where permitted by applicable law.
4. Legal Bases for Processing
Where GDPR applies, we process personal data only where we have a lawful basis.
Depending on the circumstances, our legal basis may include:
Performance of a contract
Where processing is necessary to provide our services or take steps requested before entering into a contract.
Legitimate interests
Where processing is necessary for our legitimate business interests, including operating and securing our services, communicating with business customers and prospects, preventing misuse, improving our services, and protecting our legal interests, provided those interests are not overridden by the rights and freedoms of the individual.
Legal obligations
Where processing is necessary for compliance with laws or regulatory requirements applicable to us.
Consent
Where we rely on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
5. Customer Data and Our Role as Processor
Ares Horizon provides software that enables organisations to analyse and manage information relating to areas such as supply chains, suppliers, contracts, compliance requirements, obligations, and supporting evidence.
Customers determine which information is submitted to the platform and the purposes for which that information is processed.
For personal data contained within Customer Data, the customer generally acts as the data controller and Ares Horizon acts as its data processor.
We process such information only:
- to provide the services;
- according to documented customer instructions;
- to maintain the security and integrity of the platform;
- as required by applicable law; or
- as otherwise agreed with the customer.
Individuals wishing to exercise rights regarding personal data contained within a customer's workspace should normally contact the relevant customer directly.
6. Artificial Intelligence and Automated Processing
Ares Horizon may use artificial intelligence and machine-learning technologies to help analyse documents, identify information, extract contractual requirements, identify relationships, organise evidence, and provide other platform functionality.
These systems may process information submitted by customers as part of providing the service.
Ares Horizon does not make legally binding decisions about individuals solely through automated processing on behalf of its customers.
Customer Data is not used to train general-purpose AI models for unrelated purposes unless this has been explicitly agreed with the relevant customer.
7. How We Share Information
We may share personal data with carefully selected service providers where necessary to operate our business and provide our services.
These may include providers of:
- cloud infrastructure;
- hosting and data storage;
- authentication and cybersecurity services;
- business communications;
- analytics and monitoring;
- customer support;
- professional services;
- accounting and legal services; and
- artificial intelligence or data-processing infrastructure used to provide platform functionality.
Service providers may only process personal data for the purposes for which they have been engaged and subject to appropriate contractual and security requirements.
We may also disclose information where required by law, court order, regulatory authority, or where reasonably necessary to protect our rights, users, systems, or others.
We do not sell personal data.
8. International Data Transfers
Where possible, we seek to process personal data within the European Economic Area ("EEA").
Some service providers may process information outside the EEA.
Where personal data is transferred to a country that has not been recognised by the European Commission as providing an adequate level of data protection, we use appropriate safeguards required under applicable data protection law, such as the European Commission's Standard Contractual Clauses or another legally recognised transfer mechanism.
9. Data Security
We implement technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, or destruction.
These measures may include, where appropriate:
- access controls and role-based permissions;
- encryption in transit and at rest;
- authentication controls;
- logging and monitoring;
- separation of customer environments and data;
- vulnerability and security management;
- backups and recovery procedures; and
- internal security policies and access restrictions.
No system can guarantee absolute security, but we regularly review our safeguards in light of the nature of the information processed and the risks involved.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected.
Retention periods depend on factors including:
- the duration of our relationship with you or your organisation;
- contractual requirements;
- customer instructions;
- applicable legal and accounting requirements;
- security requirements; and
- the need to establish, exercise, or defend legal claims.
Customer Data is retained and deleted in accordance with the applicable agreement with the customer.
Security logs and backups may remain for a limited period after primary data has been deleted where necessary for security, continuity, or legal purposes.
11. Cookies and Similar Technologies
Our website may use cookies or similar technologies that are necessary for its operation and security.
Where we use optional analytics, marketing, or similar technologies requiring consent under applicable law, we will request consent before placing or accessing those technologies.
Further information about the specific technologies used may be provided through our cookie settings or Cookie Policy.
12. Your Rights
Depending on the circumstances and applicable law, you may have the right to:
- request access to your personal data;
- request correction of inaccurate personal data;
- request deletion of personal data;
- request restriction of processing;
- object to certain processing based on legitimate interests;
- receive certain personal data in a portable format;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent data protection authority.
These rights are subject to conditions and exceptions under applicable law.
To exercise your rights regarding data for which Ares Horizon is the controller, contact us at privacy@areshorizon.com.
If your request concerns information processed by Ares Horizon on behalf of one of our customers, we may direct your request to the relevant customer.
13. Supervisory Authority
You have the right to lodge a complaint with a competent supervisory authority.
In Poland, the supervisory authority is:
President of the Personal Data Protection Office
Urząd Ochrony Danych Osobowych (UODO)
ul. Stanisława Moniuszki 1A
00-014 Warsaw
Poland
You may also have the right to contact the supervisory authority in another EU or EEA Member State, particularly where you live or work.
14. Business Contact Information
We may receive professional contact information from publicly available sources, professional networks, company websites, industry events, business databases, referrals, or other lawful business sources.
We may use such information to communicate with organisations that may have a legitimate business interest in Ares Horizon's services.
Where required by law, we provide appropriate information regarding such processing and respect applicable rights to object to further communications.
15. Third-Party Services and Links
Our website or services may contain links to or integrations with third-party services.
Those organisations operate under their own privacy policies and may act as independent data controllers. We encourage you to review their privacy practices before providing personal information to them.
16. Children's Privacy
Ares Horizon provides business-to-business services and is not intended for children.
We do not knowingly collect personal data from children through our services.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, technologies, legal requirements, or data-processing practices.
Where appropriate, we will notify users of material changes.
The date at the top of this Policy indicates when it was most recently updated.
18. Contact Us
For questions regarding this Privacy Policy or our processing of personal data, contact:
Ares Horizon Prosta Spółka Akcyjna
Kwitnącej Łąki 2B
02-971 Warsaw
Poland
Email: privacy@areshorizon.com
Website: areshorizon.com
