BizKitHub

Překlad není k dispozici

Tento článek zatím není přeložen do jazyka Čeština. Zobrazuje se anglická verze.

GDPR

How BizKitHub applies the EU General Data Protection Regulation — placeholder to be reviewed by legal before publication.

Naposledy aktualizováno 24. července 2026

Placeholder — replace before publication

This page is a sample GDPR statement. Every section below must be reviewed by the data protection officer and revised to accurately reflect the platform's current processing activities before the document is treated as final.

Data controller

BizKitHub s.r.o., [registered address], ID [ICO], is the data controller for personal data collected through the BizKitHub platform. The data protection officer can be reached at privacy@bizkithub.com.

What personal data we process

  • Account data — name, e-mail, password hash, organisation membership, roles.
  • Contact data — records of your customers you enter into the CRM: name, e-mail, phone, address.
  • Transactional data — orders, invoices, payments, subscriptions and their history.
  • Communication data — e-mail conversations, newsletter subscriptions, notifications.
  • Technical data — IP address, browser fingerprint, session identifiers, audit logs.
  • Contract performance — providing the platform under our Terms of Service.
  • Legal obligation — accounting, tax and archival duties.
  • Legitimate interest — fraud prevention, security monitoring, service improvement.
  • Consent — marketing communications, optional integrations, non-essential cookies.

Retention

We retain personal data for as long as necessary to fulfil the purposes above. Typical periods: account data — for the lifetime of the account plus 3 years; transactional data — 10 years (statutory accounting retention); technical logs — 12 months. Actual retention per data class is documented in the Records of Processing Activities.

Your rights

As a data subject, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request erasure ("right to be forgotten"), subject to statutory limits.
  • Restrict or object to processing.
  • Receive your data in a portable format.
  • Withdraw consent at any time (without affecting past lawful processing).
  • Lodge a complaint with the Office for Personal Data Protection (uoou.cz).

Sub-processors

We share limited personal data with vetted sub-processors that help us deliver the service (hosting, e-mail delivery, analytics, payments). The current list, their locations, and the safeguards we apply are published at /subprocessors.

International transfers

Where a sub-processor is located outside the EEA, transfers are governed by the European Commission's Standard Contractual Clauses (2021/914) supplemented by adequate technical measures (encryption in transit and at rest, key management under our control).

Security

Technical and organisational measures include TLS 1.3 for all traffic, encryption at rest for the database, row-level tenant isolation, role-based access control, mandatory 2FA for administrators, and continuous audit logging. Detailed security posture is described at /security.

Contact

For any GDPR-related request, contact privacy@bizkithub.com. We respond to verified requests within 30 days as required by Article 12(3).