Privacy Policy (GDPR)
Introduction
This Policy describes how:
Vojtěch Beil
Business ID: 05388627
Address: Králec 11, 788 20 Dolní Studénky
(hereinafter the "Controller")
processes personal data of Users of its online service for generating educational materials (hereinafter the "Service"). The Controller protects personal data and complies with applicable legal regulations, especially Regulation (EU) 2016/679 – GDPR and related Czech legal regulations.
By using the Service, the User confirms that they have become acquainted with this Policy.
Controller's Contact Information
- Personal Data Controller: Vojtěch Beil
- Business ID: 05388627
- Address: Králec 11, 788 20 Dolní Studénky
- Email: info@pomuckar.cz
The Controller has not appointed a data protection officer.
Scope of Processed Personal Data
The Controller processes the following categories of data:
- Identification data – first name and last name.
- Contact data – email address.
- Login data – identifier from Microsoft/Google account (only identifier, not password).
- Billing data – only for organizations or payments through Stripe.
- Device identifier for the watermark – a randomly generated identifier stored in your browser's Local Storage. It is used solely to mark the watermark in generated PDFs. The watermark is composed in your browser, so this identifier is not sent to the server on its own and leaves your device only inside the file you download. It does not contain your name, but it allows individual devices to be distinguished, and we therefore treat it as pseudonymous personal data (see Article 12).
- Usage data – a record of which material was generated and when, together with a random visit identifier. That identifier is created in the browser's memory only, is never stored, and dies when the tab closes; it never meets the watermark identifier. These are pseudonymous personal data (see Article 12).
Method of Obtaining Data
Personal data is obtained:
- directly from the User when using the Service,
- through login via third-party providers (Microsoft, Google),
- through the Stripe payment gateway (for individual users),
- from technical data stored on the User's device (Local Storage, IndexedDB).
The Controller does not use tracking cookies or third-party analytics tools (e.g., Google Analytics). Usage statistics are kept in the Controller's own system in a pseudonymous form that cannot be attributed to an individual user or followed over time – see Article 12.
Purposes of Processing Personal Data
The Controller processes personal data for the following purposes:
- provision and management of user accounts,
- provision of access to the Service and material generation,
- processing payments and invoicing (Stripe, contracts with organizations),
- customer communication (support, change notifications),
- sending a newsletter with news and tips – only on the basis of a voluntary opt-in that can be withdrawn at any time,
- fulfillment of legal obligations (e.g., accounting records),
- protection of the Controller's legitimate interests – in particular prevention of account misuse, measuring load and improving the Service based on pseudonymous usage statistics (see Article 12), and protection of copyright in generated materials by means of a watermark (see Articles 3 and 12).
Legal Basis for Processing
Data processing is based on:
- Performance of the contract between the User and the Controller (Article 6(1)(b) GDPR),
- Fulfillment of legal obligations (e.g., accounting records, Article 6(1)(c) GDPR),
- The Controller's legitimate interests – ensuring the operation and security of the Service, improving the Service based on pseudonymous usage statistics, and protecting copyright by means of a watermark (Article 6(1)(f) GDPR),
- User's consent, if required – e.g., sending a newsletter (a voluntary opt-in that can be withdrawn at any time via the link in the email or in the account settings).
Retention Period of Personal Data
Personal data is retained only for as long as necessary:
- for the duration of the contractual relationship between the User and the Controller,
- for the period specified by accounting and tax regulations (e.g., billing data),
- generation statistics are deleted automatically after 90 days (see Article 12).
After this period, data is securely deleted or anonymized.
Recipients of Personal Data
The Controller uses the following processors and recipients of personal data:
| Service / recipient | Role | Purpose | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | hosting and infrastructure (CloudFront, API, Lambda, DynamoDB, S3) | operation of the application and data storage | EU – Frankfurt (eu-central-1) |
| Microsoft Azure Communication Services | email sending | transactional emails and the newsletter | EU |
| Amazon SES (AWS) | fallback email sending | transactional emails if the primary route is unavailable | EU – Frankfurt (eu-central-1) |
| Stripe | payment gateway | processing payments and subscriptions | EU / USA (SCCs, or Data Privacy Framework) |
| Microsoft | login provider | user authentication | EU / USA (SCCs, or Data Privacy Framework) |
| login provider | user authentication | EU / USA (SCCs, or Data Privacy Framework) | |
| Aerohosting | domain registration, DNS and the `info@pomuckar.cz` mailbox | receiving and sending mail from the Controller's address | Czech Republic |
The Controller will provide the current list of processors on request, including as an annex to a data processing agreement (see Article 8a).
Personal data may also be transferred to external accounting or tax entities (to the extent necessary for legal obligations) and to public authorities, if required by law.
Personal data is not sold to third parties.
8a. Processing for Schools and Organizations
Where the contract is concluded by a school or another organization, the Controller processes the personal data of its staff (first name, last name, work email) as a processor within the meaning of Article 28 GDPR. On request, the Controller will conclude a data processing agreement with the organization, annexed with the list of sub-processors under Article 8 and a description of the security measures under Article 11. The Controller will not engage a new sub-processor without giving the organization prior notice. A template of the agreement can be downloaded from the organization’s account (“My account”).
The Service is not intended for storing pupil data. Materials are generated on the user's device and their content is not sent to the Controller's server.
Data Transfer Outside the EU
Application data is primarily stored in the EU (Frankfurt region, eu-central-1) and emails are sent from European data centres. However, Amazon Web Services, Microsoft (including Azure Communication Services), Google, and Stripe are globally operating companies; any transfer of personal data outside the EU is ensured on the basis of EU standard contractual clauses (SCCs), or the EU–US Data Privacy Framework, and corresponding guarantees in accordance with GDPR.
Data Subject Rights
Under GDPR, the User has the following rights:
- right to access their personal data,
- right to rectification or completion of data,
- right to erasure ("right to be forgotten"),
- right to restriction of processing,
- right to object to processing based on legitimate interests,
- right to data portability,
- right to lodge a complaint with the supervisory authority.
How to exercise your rights: by email to info@pomuckar.cz, sent from the address registered with the Controller. The Service does not yet offer a self-service button for exporting data or deleting an account; requests are handled by the operator manually, with a reply no later than one month after the request is received (Article 12(3) GDPR). Account deletion is irreversible and the Controller confirms it by email before carrying it out. An objection to the statistics described in Article 12 can also be raised directly via the "Privacy settings" link in the site footer.
Supervisory Authority:
Office for Personal Data Protection
Pplk. Sochora 27, 170 00 Prague 7
www.uoou.cz
Security of Personal Data
The Controller takes appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, loss, or destruction:
- login occurs exclusively through secure providers (Microsoft, Google),
- payment data is not stored by the Controller,
- personal data is stored in secure systems with limited access,
- usage statistics are kept separately from personal data and without a persistent identifier, so they cannot be attributed to an individual user (see Article 12),
- only the operator has access to the Service's administration, and actions taken there are logged.
Use of Local Storage and IndexedDB
The Service uses Local Storage and IndexedDB on the User's device to store generation settings and images uploaded by the User. This data (settings and uploaded images) remains only on the User's device and is not sent to the Controller.
Generation statistics
When a material is generated, a record of which material and when is sent to the server, together with a random visit identifier. That identifier:
- is created in the browser's memory and is never stored – it dies when the tab closes,
- cannot be linked to a user account or to any other record,
- is not the identifier in the PDF watermark and never meets it.
The statistics therefore cannot follow an individual user over time, nor reveal after the fact who generated what. They serve solely to observe the load on the Service and to decide which materials to develop further. The processing rests on the Controller's legitimate interest (Article 6(1)(f) GDPR); records are deleted automatically after 90 days.
Right to object: the statistics can be switched off at any time via the "Privacy settings" link in the site footer. The choice is stored in your browser and nothing is sent from that moment on.
The watermark identifier
One more random identifier is kept in Local Storage – the device identifier used in the watermark. It is marked into every generated PDF together with the identifier of that particular file and the time of creation, so that the origin of an unlawfully distributed material can be traced. The watermark is composed in your browser; the identifier is therefore not sent to the server and leaves your device only inside the file you download. It never meets the statistics described above.
Storing this identifier is strictly necessary to provide the Service you explicitly requested (generating a watermark-protected material) and therefore does not require consent under Section 89(3) of Act No. 127/2005 Coll. The processing rests on the Controller's legitimate interest in the protection of copyright (Article 6(1)(f) GDPR). You can remove the identifier by clearing the site's data in your browser; a new one is created on the next generation.
Automated Decision-Making and Profiling
The Controller does not perform any profiling or automated decision-making that would have legal or similarly significant effects on the User.
Changes to the Policy
The Controller reserves the right to change this Policy at any time. The User will be informed of changes through the website or email at least 14 days before the changes take effect.
Contact Information for Exercising Rights
If the User wishes to exercise their rights or has questions about data processing, they can contact the Controller at: info@pomuckar.cz
Effectiveness
This Policy enters into force on January 1, 2026.