Privatumo pranešimas

Projektas - dar negalioja

1. Who is responsible for your data

DATAHILL, s.r.o., with its registered office at Martina Granca 11, 841 02 Bratislava, Slovakia, company ID (IČO) 51 962 349, registered in the Commercial Register, section Sro, file no. 131915/B, operates SolvencyBridge and is the controller for account, billing, security, product analytics, and service-administration data. Contact us at info@solvencybridge.com.

For filing content uploaded or entered by an organization, the organization normally determines why that data is processed and is the controller; DATAHILL, s.r.o. acts as its processor. Users should direct content-related requests to their organization first.

2. Data we process

  • account details, including name, email, password hash, and role;
  • organization, reporting-entity, filing, review, audit, attachment, export, and workflow data supplied by customers;
  • billing contact, company, tax, invoice, and payment-reconciliation data;
  • sign-in, device, IP address, security, diagnostic, and service-usage events; and
  • support messages, assistant questions and feedback, and any data a user deliberately shares with an enabled external AI provider.

Please do not place unnecessary personal data or special-category data in filings, attachments, comments, support messages, or assistant prompts.

3. Why we process it and our legal bases

  • to create accounts, authenticate users, provide the service, and administer subscriptions - performance of a contract;
  • to invoice, keep accounting records, and respond to lawful requests - compliance with legal obligations;
  • to secure, troubleshoot, support, and improve the service and defend legal claims - our legitimate interests and those of our customers; and
  • to run optional product analytics - consent, which can be withdrawn at any time without affecting earlier processing.

Where we process customer filing content as a processor, our customer determines the legal basis and gives us documented instructions under the data-processing agreement.

4. Cookies and browser storage

Essential cookies and browser storage support sign-in, security, language and display preferences, and remembering your privacy choice. They are required for the requested service.

[The operator must state whether analytics is enabled, the provider and region, the data sent, the capture controls, and how consent is withdrawn.]

5. Recipients, service providers, and transfers

Authorized members of your organization can access data according to their roles. We also use vetted providers for hosting, error monitoring, email or webhook delivery, analytics where accepted, and AI assistance where explicitly enabled. Sentry diagnostics are configured without session replay or default personal data, although technical error context may still contain personal data.

The production hosting location is [the selected hosting region must be configured]. [The operator must describe who can access customer data for support, under which approval and audit controls.]

The current provider list, locations, roles, and transfer safeguards are maintained at [subprocessor list URL must be configured]. Where data leaves the EEA, we use an applicable adequacy decision or contractual safeguards and supplementary measures as required.

6. AI assistance

Local assistance does not send filing context to an external AI provider. External assistance is restricted to enabled organizations and requires an explicit choice before metadata or a current field value is shared. Other filing values and tenant identifiers are not intentionally sent. Generated suggestions can be inaccurate and are not automated regulatory decisions; a user must review them.

7. Retention and deletion

[The operator must publish concrete retention periods or determination criteria for accounts, customer content, backups, logs, analytics, support records, and invoices.]

[The operator must describe customer export and deletion requests, active-system deletion, retained legal records, processor deletion, and backup expiry.]

8. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, or portability of your personal data, and may object to processing based on legitimate interests. You may withdraw consent at any time. We may need to verify your identity and will respond within the legally required period.

You may also complain to [the competent supervisory authority must be configured], or to the data-protection authority where you live, work, or believe an infringement occurred.

9. Security, changes, and contact

We use technical and organizational measures intended to protect personal data, including tenant access controls, role-based access, audit records, and transport security. No service can guarantee absolute security. [The operator must describe how suspected personal-data breaches are assessed, contained, documented, and notified under the customer agreement and applicable law.] We will post material notice changes here and, where required, notify affected users through the service or by email.

Jūsų privatumo pasirinkimai

Saugumui ir nuostatoms naudojame būtinąją saugyklą. Gavus jūsų leidimą, PostHog EU matuoja ataskaitos rengimo veiksmus ir įrašo privatumą saugančiu būdu užmaskuotą seansą, kad galėtume rasti ir pašalinti naudojimo kliūtis. Įrašuose paslepiamas visas tekstas, formų turinys, medija, pulto žurnalai ir tinklo turinys. Tai padeda mums tobulinti SolvencyBridge.

Privatumo informacija