Legal

Privacy Policy

Last updated: 2026

1. Introduction

This Privacy Policy explains how DocuPortal collects, uses and protects personal data in accordance with Regulation (EU) 2016/679 (GDPR) and other applicable laws.

Data Controller: Jakub Kopecký, Prague, Czech Republic
Company ID: [TO BE ADDED]
Email: jakubkopecky884@gmail.com

2. Data We Collect

Depending on platform usage, we may collect:

  • Name and surname
  • Email address
  • Company information
  • Account information
  • Authentication and security-related information
  • Audit log activity
  • Contact form submissions
  • Technical usage data

3. How We Use Data

We use collected data to:

  • Provide and maintain the platform
  • Authenticate users
  • Manage subscriptions and billing
  • Provide customer support
  • Improve platform functionality and security
  • Send notifications related to platform activity
  • Prevent abuse and unauthorized access

4. Legal Basis

We process personal data based on:

  • Contractual necessity — processing required to provide the service (platform operation, account management, billing)
  • Legitimate interest — platform security, fraud prevention, audit logging
  • Legal obligations — compliance with applicable laws
  • Consent — where required (e.g. marketing communication)

If you use the platform under a contract, consent is not required for basic platform operation.

5. Data Sharing

We do not sell personal data.

Data may be processed by trusted third-party providers required to operate the platform:

Microsoft AzureCloud infrastructure and storage (primarily within the EU)
StripePayment processing
SendGridEmail notifications

All providers offer Standard Contractual Clauses (SCC) in compliance with GDPR requirements.

6. Data Retention

We retain personal data only for as long as necessary to provide the service, comply with legal obligations or resolve disputes.

Audit logs are retained for 2 years from the date of creation, after which they are automatically deleted.

After subscription termination, data is deleted or anonymized upon request. Data required to fulfill legal obligations (e.g. billing records) may be retained for a longer period as required by law.

7. Security Measures

We implement reasonable technical and organizational security measures including:

  • Access controls
  • Authentication mechanisms
  • Encrypted communication
  • Audit logging
  • Tenant isolation

8. Your Rights

Under GDPR, you have the following rights:

  • Right of access — obtain confirmation of processing and a copy of your data
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure — request deletion of your data ("right to be forgotten")
  • Right to restriction — limit how your data is processed
  • Right to portability — receive your data in a structured format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — withdraw previously given consent at any time

Requests can be submitted via the contact form or by email to jakubkopecky884@gmail.com. We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic: Office for Personal Data Protection (ÚOOÚ), www.uoou.cz.

9. Cookies & Analytics

The website and platform may use essential cookies and basic analytics necessary for operation, security and performance. Where third-party analytics tools are used, you will be informed via a cookie banner.

10. International Data Transfers

Data is primarily processed in cloud infrastructure located within the European Union.

Where data is transferred outside the EEA, we ensure appropriate safeguards in accordance with GDPR — Standard Contractual Clauses (SCC) or European Commission adequacy decisions.

11. Children

The platform is not intended for persons under the age of 16. We do not knowingly collect personal data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Updated versions will be published on this page along with the date of the last update. You will be notified of significant changes by email or via an in-app announcement.

13. Contact

Jakub Kopecký
Prague, Czech Republic
Company ID: [TO BE ADDED]
Email: jakubkopecky884@gmail.com

Or via the contact form available on the website.