Privacy Policy
Last updated: September 23, 2025 · Applies to: mindq.tech and clients.mindq.tech
Controller & Contact
Controller: ZEN Capital s.r.o., Company ID (IČO) 19374691, registered office at Borovnice 67, 592 42 Borovnice, Czech Republic. E-mail: support@mindq.tech. Data Protection Officer (DPO): not appointed.
Scope
This Policy applies to the website mindq.tech and to the application clients.mindq.tech.
Data we process
- Identification & contact: name, e-mail, password hash, phone, company/department, account role, billing data.
- Service usage data: IPs, device/browser identifiers, access & event logs (audit), user settings, dashboard interactions, error reports.
- Communications: helpdesk/support, e-mails (incl. notifications), records of consents and cookie choices.
- Customer-provided content: imported sources (RSS, files, links, notes, comments). Where we process your data on your behalf, we act as a processor (see DPA in ToS).
- Analytics/marketing data: only if you provide consent (see Cookie Policy).
Purposes & legal bases (GDPR Art. 6)
- Operating and providing the Services (accounts, authentication, billing): contract performance, legitimate interests.
- Security & abuse prevention (logging, rate-limit, CSRF/anti-bot): legitimate interests.
- Legal obligations (accounting/tax records, consents, data subject requests): legal obligation.
- Analytics & improvement (usage measurement, UX research): consent / legitimate interests depending on technology.
- Marketing (B2B): consent / legitimate interests (relevant offers to existing clients – opt-out available).
- AI processing (e.g., newsletter summarisation): contract performance/legitimate interests; any personal data you input is processed under your instructions.
Sources of data
- directly from you (registration, communications, use of the Services),
- from integrated tools you connect (e.g., cloud drives, RSS),
- from public sources where required by your project configuration.
Recipients / processors (sub-processors)
- Hosting/infrastructure: Hetzner (EU), and possibly AWS EU.
- E-mail services: Seznam e-mails (transactional/service mail).
- Analytics: our own first-party website analytics (only if enabled).
- Visualisation: Tableau (if embedded).
- Accounting/tax advisors, legal counsel – only where necessary.
Any transfers outside the EEA are covered by appropriate safeguards (notably Standard Contractual Clauses – SCCs).
Retention periods
- Accounting/billing records: 10 years.
- User accounts & operational logs: for the duration of the contract and 12–24 months thereafter.
- Security audit logs: 12 months.
- Communications (helpdesk/e-mail): 24 months.
- Cookie/marketing consents: until withdrawal/expiry of consent.
Your rights
You have the right of access, rectification, erasure, restriction, portability, objection, and to withdraw consent. Contact: support@mindq.tech. You can also lodge a complaint with the Czech Data Protection Authority (ÚOOÚ).
Security
Encryption in transit (HTTPS), role-based access (RBAC), network segmentation, audit logs, regular updates; access follows the “need-to-know” principle.
Children
The Services are not intended for persons under 16.
Changes to this Policy
We will publish updates here; material changes will be announced in-app or via e-mail.
Contact
E-mail: support@mindq.tech · Controller: ZEN Capital s.r.o., IČO 19374691, Borovnice 67, 592 42 Borovnice, Czech Republic
