Legal terms
Privacy Policy
Last updated: 5 July 2026 · Version V05-07-2026
Run Done is the international trade name of the service offered in North Macedonia as popolni.mk, by the same company and under the same legal terms. This page is the English version of that document. In case of any discrepancy, the Macedonian original prevails.
This Privacy Policy explains how PROBIS-KONSALT DOOEL Skopje, Company reg. no. 7513615, Tax no. 4057021555700, with its registered seat at Dragutin Avramovski Gute St. 32, Karposh Municipality, Skopje (“Run Done”, “we”, “us”), collects, uses, stores and protects personal data when you use the service at rundone.ai. “Run Done” is a trade name of the service offered by this company.
Run Done is a software service that helps notary, law, accounting and other professional offices fill in the documents they already use in their work more quickly. You upload a document, and Run Done fills it in with new data and returns a finished Word file.
This Policy applies to the web portal at rundone.ai and to the Popolni add-in for Microsoft Word, which connects to the same service.
We process personal data on the legal bases set out in section 4 of this Policy, mainly for the performance of the contract and for our legitimate interests. We ask for consent only where the law requires it for a specific processing operation.
The processing complies with the Law on Personal Data Protection of the Republic of North Macedonia and with the General Data Protection Regulation of the EU, the GDPR.
1. In short
- We do not sell personal data.
- We do not use the data for advertising or for any other purpose unrelated to the service.
- The connection to Run Done is encrypted.
- The data is stored on protected servers in the European Union.
- For your parties’ documents, Run Done is the processor and your office remains the controller. This is governed by the Data Processing Addendum, which forms an integral part of the Terms of Use.
- You have the right of access, rectification, erasure, restriction and objection, in accordance with the law.
2. Two roles: controller and processor
It is important to distinguish two kinds of data, because our role is not the same for each of them.
a) Data about your account (Run Done is the controller)
For the data created when opening and using the account, Run Done decides why and how it is processed. For that data, Run Done is the controller.
b) Content you enter to fill in documents (Run Done is the processor)
The documents, images, scans, audio recordings and text you enter to produce a document often contain personal data of your parties, such as names, national identification numbers, addresses, signatures and other numbers.
For that content, your office decides why and how the data is processed. Your office is therefore the controller, and Run Done is the processor that processes the data on your instructions.
The obligations of both parties are governed by the Data Processing Addendum, which forms an integral part of the Terms of Use and is accepted electronically when the account is opened or activated.
3. What data we collect
a) Account and office data
We may process:
- the user’s first name and surname;
- email address;
- the name of the office;
- contact details you provide to us;
- the password, stored only as a cryptographic hash, never as plain text;
- language settings and basic account parameters.
b) Content you enter
We may process:
- documents you upload for repeated filling, including Word files;
- images, scans, documents, audio recordings and text you enter for each production;
- text extracted from those documents, images and audio recordings, needed to fill in the document;
- finished documents created by Run Done and their versions;
- messages in the conversation with the assistant in the application.
c) Technical data for operation and billing
We may process:
- login and usage records, needed for security and support;
- the number of downloaded documents, to track the subscription and volume;
- basic technical data needed for the stable operation of the service.
We do not use tracking cookies, we do not perform profiling and we do not collect data from third-party sources for marketing.
4. Why we process the data and on what basis
We process the data for the following purposes and on the following legal bases:
Performance of the contract
We process the data to provide you with the service, to manage your account and to produce the documents you request.
Legal obligation
We process the data where necessary for issuing invoices, keeping records and fulfilling tax, accounting or other legal obligations.
Legitimate interest
We process the data for the security and integrity of the system, preventing fraud and abuse, securing evidence in the event of incidents and basic technical maintenance of the service.
We balance these interests against your rights and freedoms. You have the right at any time to object to processing based on legitimate interest.
Consent
Where consent is required for a specific processing operation, we will ask for it separately. You can withdraw your consent at any time.
For the content of the documents, the legal basis is determined by your office as the controller. Where the content contains special categories of personal data or a national identification number, Run Done processes that data exclusively on the documented instructions of the office and on a basis provided by the office.
We process that content only to perform the service, never for our own purposes.
5. How we protect the data
We apply technical and organisational measures to protect the data.
Encryption in transit
Every connection to Run Done is protected with TLS, that is, HTTPS. Data is not transmitted over an open connection.
Encryption at rest
The database and the backups are stored on encrypted disks with our server provider in the EU.
Access control
Each office has access only to its own projects and documents. Access is restricted and separated per office.
Protected passwords
Passwords are stored only as a cryptographic hash, using Argon2. We do not store them as plain text and cannot read them back.
Backups
We make daily backups to reduce the risk of data loss. The backups are stored encrypted and for a limited time.
6. Where the data is stored and transfers to third parties
The main data is stored on servers in the European Union, in Frankfurt, Germany.
For the service to work, part of the content may be transferred to carefully selected providers acting as sub-processors. They process data only on our instructions and under contractual protection obligations.
For the content of the documents, these providers are engaged by Run Done within our role as a processor. Your office remains the controller and, by accepting the Terms of Use and the Data Processing Addendum, grants Run Done a general authorisation to engage sub-processors. For every planned change of sub-processors, Run Done notifies the office in advance and gives it the opportunity to raise a reasonable objection.
| Provider | Purpose | Location |
|---|---|---|
| DigitalOcean | Servers, database and backups | EU, Germany |
| Anthropic | Reading and processing text to fill in documents | USA |
| OpenAI | Reading and processing text to fill in documents | USA |
| Recognising text from images, scans and audio recordings | EU/USA, depending on the processing region |
The contracting parties for these providers are their legal entities with which we enter into an agreement, for example Google Ireland Limited, OpenAI Ireland Limited or Anthropic PBC. The stated location refers to the possible place of processing. A transfer outside the EU takes place only when the processing actually occurs outside the EU.
We carry out transfers outside the EU and North Macedonia only with appropriate safeguards in accordance with Article 46 of the GDPR and the corresponding provisions of the Law on Personal Data Protection, including standard contractual clauses and a transfer impact assessment.
We use these providers only so that Run Done can produce the requested document. It is contractually agreed with them that your content will not be used to train their models and will not be stored longer than necessary to perform the service.
We do not share data with third parties for marketing, advertising or resale.
A copy of the safeguards, including the standard contractual clauses for the transfers to these providers, is available on request.
7. How long we keep the data
We keep the account data and the content for the duration of the cooperation, so that you can access your documents and use the service.
After the cooperation ends, we delete or anonymise the account data, as well as the login and security records, within 12 months.
We delete the content of the documents in accordance with your office’s instructions and the data processing agreement. In any case, we delete the content no later than 90 days after the end of the cooperation, unless the office requests earlier deletion.
We keep the billing data for as long as the tax and accounting regulations require, as a rule up to 10 years.
We keep the messages in the conversation with the assistant for the duration of the cooperation and delete or anonymise them at the latest together with the account data. If those messages contain personal data of parties, the retention periods for document content apply to them.
The backups are stored encrypted and are overwritten in a regular cycle of up to 14 days. This means that deleted content also disappears from the backups within that cycle.
You can request the deletion of your data at any time, in accordance with section 8.
8. Your rights
In accordance with the law, you have the right to:
- access the data we hold about you;
- rectification of inaccurate or incomplete data;
- erasure of your data, the “right to be forgotten”;
- restriction of processing;
- object to processing;
- data portability in a readable format;
- withdraw consent at any time;
- not be subject to a decision based solely on automated processing;
- lodge a complaint with the supervisory authority.
Run Done does not make decisions based solely on automated processing and does not perform profiling.
The right to erasure is not absolute. It does not apply where the processing is necessary to fulfil a legal obligation, for example tax regulations, or for the establishment, exercise or defence of legal claims. In such cases, we restrict the data instead of deleting it.
Withdrawing consent does not affect the lawfulness of the processing carried out before the withdrawal.
To exercise these rights, write to us at hello@rundone.ai.
Where personal data of parties has been entered by an office, you should address your request to that office as the controller. We will assist the office in fulfilling the request.
9. Data Processing Addendum
Where Run Done processes personal data contained in the documents, images, scans, audio recordings, text and other materials entered by your office, Run Done acts as the processor and your office as the controller.
This processing is governed by the Data Processing Addendum, which forms an integral part of the Terms of Use. The Addendum is accepted electronically together with the Terms, when the account is opened, activated or used.
The Addendum governs the subject matter and duration of the processing, the nature and purpose of the processing, the types of personal data, the categories of data subjects, the documented instructions, confidentiality, the security measures, the sub-processors, the handling of security incidents and the deletion or return of the data.
10. Cookies
The public website does not use tracking cookies or third-party analytics.
In the application we use only essential technical cookies, needed to keep you logged in and to protect the session. Without these cookies, the service cannot work properly.
11. Security incidents
If a breach of the security of personal data for which Run Done is the controller occurs, that is, the account data, and if it poses a risk to the rights and freedoms of the affected persons, we will report the incident to the supervisory authority within 72 hours, in accordance with the law.
For the content of the documents, where Run Done is the processor, we notify the affected office as the controller without undue delay. The office then decides on reporting to the supervisory authority and on notifying the affected persons, where necessary.
In both cases we act in accordance with the applicable regulations.
12. Children
Run Done is intended for professional use by offices and is not intended for persons under 18 years of age.
We do not knowingly collect personal data from children.
13. Changes to this Policy
We may update this Privacy Policy.
In the case of significant changes, we will notify you by email or through a notice in the application.
The date of the last change is stated at the top of this page.
14. Contact and supervisory authority
For questions or requests related to privacy, you can contact us at:
- Email: hello@rundone.ai
- Phone: +389 71 237 331
Controller: PROBIS-KONSALT DOOEL Skopje, Company reg. no. 7513615, Tax no. 4057021555700, Dragutin Avramovski Gute St. 32, Karposh Municipality, Skopje, North Macedonia.
Contact person for personal data protection matters: hello@rundone.ai.
This person is not a formally designated data protection officer within the meaning of Article 37 of the GDPR.
If you believe that your rights have been violated, you have the right to lodge a complaint with the Agency for Personal Data Protection of the Republic of North Macedonia (Blvd. Goce Delchev 18, 1000 Skopje, North Macedonia), azlp.mk.
Questions about privacy or the terms?
Write to us at hello@rundone.ai or call +389 71 237 331. We respond in English and Macedonian.