Privacy Policy

Privacy Policy (GDPR)

Last changed: Jul 12, 2026
16 sections

Privacy Policy (GDPR)

Introduction

This Policy describes how:
Vojtěch Beil
Business ID: 05388627
Address: Králec 11, 788 20 Dolní Studénky
(hereinafter the "Controller")

processes personal data of Users of its online service for generating educational materials (hereinafter the "Service"). The Controller protects personal data and complies with applicable legal regulations, especially Regulation (EU) 2016/679 – GDPR and related Czech legal regulations.

By using the Service, the User confirms that they have become acquainted with this Policy.

Controller's Contact Information

  • Personal Data Controller: Vojtěch Beil
  • Business ID: 05388627
  • Address: Králec 11, 788 20 Dolní Studénky
  • Email: info@pomuckar.cz

The Controller has not appointed a data protection officer.

Scope of Processed Personal Data

The Controller processes the following categories of data:
- Identification data – first name and last name.
- Contact data – email address.
- Login data – identifier from Microsoft/Google account (only identifier, not password).
- Billing data – only for organizations or payments through Stripe.
- Device identifier and usage data – a randomly generated identifier (ID) stored in your browser which, together with usage data (e.g., the type and number of generated materials, frequency of use), is sent to the server. This identifier does not contain your name, but it allows individual devices to be distinguished, and we therefore treat it as pseudonymous personal data.

Method of Obtaining Data

Personal data is obtained:
- directly from the User when using the Service,
- through login via third-party providers (Microsoft, Google),
- through the Stripe payment gateway (for individual users),
- from technical data stored on the User's device (Local Storage, IndexedDB).

The Controller does not use tracking cookies or third-party analytics tools (e.g., Google Analytics). Usage statistics are obtained through the first-party identifier described above.

Purposes of Processing Personal Data

The Controller processes personal data for the following purposes:
- provision and management of user accounts,
- provision of access to the Service and material generation,
- processing payments and invoicing (Stripe, contracts with organizations),
- customer communication (support, change notifications),
- sending a newsletter with news and tips – only on the basis of a voluntary opt-in that can be withdrawn at any time,
- fulfillment of legal obligations (e.g., accounting records),
- protection of the Controller's legitimate interests (e.g., prevention of account misuse, measuring and improving the Service based on pseudonymous usage statistics).

Legal Basis for Processing

Data processing is based on:
- Performance of the contract between the User and the Controller (Article 6(1)(b) GDPR),
- Fulfillment of legal obligations (e.g., accounting records, Article 6(1)(c) GDPR),
- The Controller's legitimate interests (ensuring operation, security and improvement of the Service based on pseudonymous usage statistics – Article 6(1)(f) GDPR),
- User's consent, if required – e.g., sending a newsletter (a voluntary opt-in that can be withdrawn at any time via the link in the email or in the account settings).

Retention Period of Personal Data

Personal data is retained only for as long as necessary:
- for the duration of the contractual relationship between the User and the Controller,
- for the period specified by accounting and tax regulations (e.g., billing data),
- usage data linked to the identifier is retained for statistical purposes for as long as necessary for that purpose.

After this period, data is securely deleted or anonymized.

Recipients of Personal Data

The Controller uses the following processors and recipients of personal data:

Service / recipientRolePurposeLocation
Amazon Web Services (AWS)hosting and infrastructure (CloudFront, API, Lambda, DynamoDB, S3)operation of the application and data storageEU – Frankfurt (eu-central-1)
Amazon SES (AWS)email sendingtransactional and informational emailsEU – Frankfurt (eu-central-1)
Stripepayment gatewayprocessing payments and subscriptionsEU / USA (SCCs, or Data Privacy Framework)
Microsoftlogin provideruser authenticationEU / USA (SCCs, or Data Privacy Framework)
Googlelogin provideruser authenticationEU / USA (SCCs, or Data Privacy Framework)

Personal data may also be transferred to external accounting or tax entities (to the extent necessary for legal obligations) and to public authorities, if required by law.

Personal data is not sold to third parties.

Data Transfer Outside the EU

Application data is primarily stored in the EU (Frankfurt region, eu-central-1). However, Amazon Web Services, Microsoft, Google, and Stripe are globally operating companies; any transfer of personal data outside the EU is ensured on the basis of EU standard contractual clauses (SCCs), or the EU–US Data Privacy Framework, and corresponding guarantees in accordance with GDPR.

Data Subject Rights

Under GDPR, the User has the following rights:
- right to access their personal data,
- right to rectification or completion of data,
- right to erasure ("right to be forgotten"),
- right to restriction of processing,
- right to object to processing based on legitimate interests,
- right to data portability,
- right to lodge a complaint with the supervisory authority.

Supervisory Authority:
Office for Personal Data Protection
Pplk. Sochora 27, 170 00 Prague 7
www.uoou.cz

Security of Personal Data

The Controller takes appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, loss, or destruction:
- login occurs exclusively through secure providers (Microsoft, Google),
- payment data is not stored by the Controller,
- personal data is stored in secure systems with limited access,
- anonymous statistics are separated from personal data.

Use of Local Storage and IndexedDB

The Service uses Local Storage and IndexedDB on the User's device to store generation settings and images uploaded by the User. This data (settings and uploaded images) remains only on the User's device and is not sent to the Controller.

Local Storage also holds a randomly generated identifier (ID) which, together with usage data, is sent to the server for statistics and Service improvement. This identifier and the related usage data are treated as pseudonymous personal data processed on the basis of the Controller's legitimate interest (Article 6(1)(f) GDPR). You have the right to object to this processing at any time (see Article 10).

Automated Decision-Making and Profiling

The Controller does not perform any profiling or automated decision-making that would have legal or similarly significant effects on the User.

Changes to the Policy

The Controller reserves the right to change this Policy at any time. The User will be informed of changes through the website or email at least 14 days before the changes take effect.

Contact Information for Exercising Rights

If the User wishes to exercise their rights or has questions about data processing, they can contact the Controller at: info@pomuckar.cz

Effectiveness

This Policy enters into force on January 1, 2026.