Privacy Policy
Effective from: [DATE] · Controller: [COMPANY NAME, Ltd.], Company ID [ID]
1. What data we process
- Account data: email, name, company name, role and permissions.
- Sign-in: one-time codes, technical sign-in records, sessions.
- In-app content: decisions, signals, execution steps and notes you enter.
- Technical data: logs and diagnostics for operating and securing the service.
2. Purpose and legal basis
We process data to provide and operate the service (performance of a contract), for sign-in and security (legitimate interest) and to meet legal obligations. We do not send marketing without consent and we do not sell data.
3. Retention
Account data is kept for the term of the contract and [30] days after it ends. Security logs [90] days. Accounting records as required by law.
4. Sub-processors
- Google Ireland Ltd. — Firebase/Firestore (data hosting, EU region)
- Resend (email delivery)
- [application hosting — e.g. Vercel]
5. Your rights
You have the right to access, rectification, erasure, restriction, portability and objection. Contact: matej.kuzma@decisto.com. You also have the right to lodge a complaint with the Slovak Data Protection Authority (dataprotection.gov.sk).
6. Security
We apply appropriate technical and organisational measures: encrypted transport (HTTPS), server-side-only data access, role-based access control, tenant isolation and approval gates for outbound actions.
7. Transfers outside the EU and changes
We store data primarily in the EU; any transfer outside the EU/EEA is made with appropriate safeguards (standard contractual clauses). We will inform you in advance of any material changes to this policy.