Privacy Policy

Last updated: September 23, 2025 · Applies to: mindq.tech and clients.mindq.tech

Controller & Contact

Controller: ZEN Capital s.r.o., Company ID (IČO) 19374691, registered office at Borovnice 67, 592 42 Borovnice, Czech Republic. E-mail: support@mindq.tech. Data Protection Officer (DPO): not appointed.

Scope

This Policy applies to the website mindq.tech and to the application clients.mindq.tech.

Data we process

  • Identification & contact: name, e-mail, password hash, phone, company/department, account role, billing data.
  • Service usage data: IPs, device/browser identifiers, access & event logs (audit), user settings, dashboard interactions, error reports.
  • Communications: helpdesk/support, e-mails (incl. notifications), records of consents and cookie choices.
  • Customer-provided content: imported sources (RSS, files, links, notes, comments). Where we process your data on your behalf, we act as a processor (see DPA in ToS).
  • Analytics/marketing data: only if you provide consent (see Cookie Policy).

Purposes & legal bases (GDPR Art. 6)

  • Operating and providing the Services (accounts, authentication, billing): contract performance, legitimate interests.
  • Security & abuse prevention (logging, rate-limit, CSRF/anti-bot): legitimate interests.
  • Legal obligations (accounting/tax records, consents, data subject requests): legal obligation.
  • Analytics & improvement (usage measurement, UX research): consent / legitimate interests depending on technology.
  • Marketing (B2B): consent / legitimate interests (relevant offers to existing clients – opt-out available).
  • AI processing (e.g., newsletter summarisation): contract performance/legitimate interests; any personal data you input is processed under your instructions.

Sources of data

  • directly from you (registration, communications, use of the Services),
  • from integrated tools you connect (e.g., cloud drives, RSS),
  • from public sources where required by your project configuration.

Recipients / processors (sub-processors)

  • Hosting/infrastructure: Hetzner (EU), and possibly AWS EU.
  • E-mail services: Seznam e-mails (transactional/service mail).
  • Analytics: our own first-party website analytics (only if enabled).
  • Visualisation: Tableau (if embedded).
  • Accounting/tax advisors, legal counsel – only where necessary.

Any transfers outside the EEA are covered by appropriate safeguards (notably Standard Contractual Clauses – SCCs).

Retention periods

  • Accounting/billing records: 10 years.
  • User accounts & operational logs: for the duration of the contract and 12–24 months thereafter.
  • Security audit logs: 12 months.
  • Communications (helpdesk/e-mail): 24 months.
  • Cookie/marketing consents: until withdrawal/expiry of consent.

Your rights

You have the right of access, rectification, erasure, restriction, portability, objection, and to withdraw consent. Contact: support@mindq.tech. You can also lodge a complaint with the Czech Data Protection Authority (ÚOOÚ).

Security

Encryption in transit (HTTPS), role-based access (RBAC), network segmentation, audit logs, regular updates; access follows the “need-to-know” principle.

Children

The Services are not intended for persons under 16.

Changes to this Policy

We will publish updates here; material changes will be announced in-app or via e-mail.

Contact

E-mail: support@mindq.tech · Controller: ZEN Capital s.r.o., IČO 19374691, Borovnice 67, 592 42 Borovnice, Czech Republic