01
Who this policy is for
This policy applies when we decide why and how personal data is processed, which in GDPR terms means we act as a controller. That covers three groups of people.
- Visitors to svaroxlabs.com.
- People who contact us about work, and the individuals we deal with at client and prospective client companies.
- People who apply for a role with us.
It does not cover personal data we handle inside a client's product or systems while building or maintaining them. There we act as a processor on the client's instructions, and the client's own privacy policy governs that data. See "Data we handle for our clients" below.
02
What we process, why, and on what legal basis
Visitors to this website
This site has no login, no newsletter and no advertising. Browsing it asks nothing of you, and the only personal data a visit generates is what any web server records. The site does have a contact form; if you choose to use it, what you enter is covered under "Enquiries, clients and prospective clients" below.
| What we process | Why | Legal basis | How long we keep it |
|---|---|---|---|
| Technical connection data recorded in server logs: IP address, date and time, the page requested, referrer, browser and device type | To serve the site, keep it available, and detect abuse such as scraping or denial-of-service attempts | Art. 6(1)(f): our legitimate interest in operating and securing our own website | Up to 90 days, then deleted or aggregated into anonymous statistics |
Enquiries, clients and prospective clients
| What we process | Why | Legal basis | How long we keep it |
|---|---|---|---|
| Your name, email address, phone number if you give it, company and role, the indicative budget and timeline you select in the contact form, and the content of your message | To answer you, scope the work and prepare a proposal | Art. 6(1)(b): steps taken at your request before entering a contract; Art. 6(1)(f) where you write on behalf of a company rather than yourself | 3 years from our last exchange, matching the general limitation period under Czech law, unless it becomes part of a project record |
| Contact details of the people we work with at a client, project correspondence, meeting notes and delivery records | To run the project and to prove what was agreed and delivered | Art. 6(1)(b): performance of the contract; Art. 6(1)(f) for contact people who are not themselves our counterparty | For the duration of the engagement and 3 years after it ends |
| Billing details: invoicing address, company and tax identifiers, bank details, invoices and payment records | To invoice, get paid and meet our accounting and tax duties | Art. 6(1)(c): compliance with a legal obligation | 5 years for accounting records (Act No. 563/1991 Coll.) and 10 years for tax documents (Act No. 235/2004 Coll.) |
Candidates
| What we process | Why | Legal basis | How long we keep it |
|---|---|---|---|
| Your CV and portfolio, contact details, work history, links you send us, and our notes and assessment from interviews or a task | To evaluate your application and run the hiring process | Art. 6(1)(b): steps taken at your request before a possible employment contract | 6 months after the role is filled or the process closes |
| The same materials, kept on file for future openings | To contact you when a role that fits comes up | Art. 6(1)(a): your consent, which you can withdraw at any time | 2 years from your consent, or until you withdraw it |
We do not ask for special categories of personal data under Article 9 GDPR (health, biometrics, political opinions, religion, trade union membership, sexual orientation), and we ask you not to send them. Please leave them out of CVs and enquiries.
04
Where we get your data
- Directly from you, when you email us, apply for a role, or work with us on a project.
- From your employer or our client, when you are named as a contact person, project owner or approver on an engagement.
- From your device: the technical connection data described above, generated automatically when you load a page.
We do not buy contact lists and we do not scrape personal data to build prospecting databases.
05
Who we share data with
We do not sell personal data and we do not share it for anyone else's marketing. We disclose it only to the following categories of recipient, and only as far as each one needs it:
- Service providers who process data on our behalf under Article 28 GDPR: website hosting, business email and file storage, and the tools we use to run projects and issue invoices. Each is bound by a data processing agreement, confidentiality and instructions from us.
- Our accountants, auditors and legal advisers, bound by professional confidentiality.
- Public authorities such as courts, tax authorities and supervisory authorities, where we are legally obliged to disclose, and no further.
- An acquirer or its advisers, if the business is ever sold or reorganised, under confidentiality and with this policy continuing to apply to the data transferred.
The processors behind the contact form
The contact form is the one place on this site where you hand us personal data directly, so we name the providers involved rather than leaving them to the categories above:
- Resend (Plus Five Five, Inc., United States) delivers the notification we email to ourselves when you submit the form. That message carries your name, email address, company, the timeline and indicative budget you selected and the text you wrote, and sets your address as the reply-to so we can answer you. Resend acts as our processor under Article 28 and does not use the content for its own purposes.
Once we have answered you, the enquiry lives on in our mailbox for the period set out above. Nothing you send through the form is used for marketing and we do not add you to any list.
06
Transfers outside the EEA
We prefer providers that store data in the European Union. Where a provider processes data outside the EEA, we rely on one of the safeguards Chapter V GDPR allows: an adequacy decision of the European Commission for the country in question, or the Commission's Standard Contractual Clauses together with an assessment of the transfer and any additional measures needed.
In practice the transfer this affects today is the contact-form notification handled by Resend in the United States, described in the previous section, which is covered by a data processing agreement incorporating the Standard Contractual Clauses.
Write to us at the address above and we will tell you which safeguard applies to a specific provider and send you a copy of the relevant clauses.
07
Data we handle for our clients
Building and maintaining software sometimes means we can reach personal data belonging to a client's users: during a migration, while diagnosing a production incident, or through access to a system we operate for them. In that role we are a processor, not a controller, and the rules are different.
- We act only on the client's documented instructions and never for our own purposes.
- We work under a written data processing agreement meeting Article 28 GDPR before any such access is granted.
- Everyone with access is bound by confidentiality, and access is limited to the people who need it for the task at hand.
- We prefer anonymised or synthetic data in development and testing, and use production data only when a task genuinely cannot be done without it.
- We engage sub-processors only with the client's authorisation, and pass the same obligations down to them.
- At the end of an engagement we return or delete the data, at the client's choice, except where law requires us to retain it.
- We notify the client without undue delay if we become aware of a personal data breach affecting their data, so they can meet their own 72-hour duty.
If you are a user of a product we helped build and want to exercise your rights over your data, contact the company operating that product, because they are the controller. Tell us and we will point you in the right direction, but we cannot act on their data without their instruction.
08
How we protect data
We apply technical and organisational measures appropriate to the risk, as Article 32 GDPR requires. In practice that means:
- Encryption in transit: the website and our internal tools are served over HTTPS.
- Access on a need-to-know basis, with multi-factor authentication on the accounts that matter and access removed when someone leaves a project or the company.
- Secrets and credentials kept in a password manager, never in source code or in a repository.
- Data minimisation: we do not collect fields we have no use for, and we delete what we no longer need.
- Confidentiality obligations in every employment and contractor agreement.
- Backups of the systems we operate, and restoration tested rather than assumed.
No system is perfectly secure. If we suffer a breach likely to result in a risk to your rights and freedoms, we will notify the Czech supervisory authority within 72 hours and tell you directly where the risk is high.
09
How long we keep data
The specific periods are in the tables above. The principle behind them is simple: we keep personal data only as long as it serves the purpose it was collected for, plus any period that law requires or that we need to defend a legal claim. When a period ends, the data is deleted or irreversibly anonymised.
10
Your rights
Under the GDPR you can ask us to do the following. These rights are free to exercise and none of them requires a form or a lawyer. An email is enough.
- Access (Art. 15): get confirmation of whether we process data about you, a copy of it, and the details of how and why.
- Rectification (Art. 16): have inaccurate data corrected and incomplete data completed.
- Erasure (Art. 17): have your data deleted where we no longer have grounds to keep it. This does not override our accounting and tax retention duties.
- Restriction (Art. 18): have processing paused while a dispute about accuracy or grounds is resolved.
- Portability (Art. 20): receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
- Objection (Art. 21): object at any time to processing based on our legitimate interest. We stop unless we can show compelling grounds that override your interests. Where the objection is to direct marketing, we stop without exception.
- Withdraw consent (Art. 7(3)): where processing rests on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of what was processed before.
- Not be subject to automated decision-making (Art. 22): we make no decisions about you by automated means and we do not profile you, so this right has nothing to bite on here.
Write to the email address above to exercise any of these. We answer within one month of receiving the request, as Article 12(3) requires; if a request is complex we may extend that by two further months and will tell you why within the first month. Where we have genuine doubt about who is asking, we may ask for information to confirm your identity, and we will not use it for anything else.
11
Changes to this policy
We update this page when what we do with personal data changes: a new processing purpose, a new category of recipient, a different retention period. The date at the top always reflects the current version. Where a change materially affects you and we hold your contact details, we will tell you directly rather than relying on you to re-read this page.
12
Contact
Questions about this policy, or about anything we do with personal data, go to the email address at the top of this page.