← Back to home

Privacy Policy

Effective from: [DATE] · Controller: [COMPANY NAME, Ltd.], Company ID [ID]

Template — fill in the bracketed fields and have a lawyer review it before publishing. This is not legal advice.

1. What data we process

  • Account data: email, name, company name, role and permissions.
  • Sign-in: one-time codes, technical sign-in records, sessions.
  • In-app content: decisions, signals, execution steps and notes you enter.
  • Technical data: logs and diagnostics for operating and securing the service.

2. Purpose and legal basis

We process data to provide and operate the service (performance of a contract), for sign-in and security (legitimate interest) and to meet legal obligations. We do not send marketing without consent and we do not sell data.

3. Retention

Account data is kept for the term of the contract and [30] days after it ends. Security logs [90] days. Accounting records as required by law.

4. Sub-processors

  • Google Ireland Ltd. — Firebase/Firestore (data hosting, EU region)
  • Resend (email delivery)
  • [application hosting — e.g. Vercel]

5. Your rights

You have the right to access, rectification, erasure, restriction, portability and objection. Contact: matej.kuzma@decisto.com. You also have the right to lodge a complaint with the Slovak Data Protection Authority (dataprotection.gov.sk).

6. Security

We apply appropriate technical and organisational measures: encrypted transport (HTTPS), server-side-only data access, role-based access control, tenant isolation and approval gates for outbound actions.

7. Transfers outside the EU and changes

We store data primarily in the EU; any transfer outside the EU/EEA is made with appropriate safeguards (standard contractual clauses). We will inform you in advance of any material changes to this policy.