svaroxlabs

PRIVACY

Privacy policy

This policy explains what personal data we process, why we process it, how long we keep it and what you can ask us to do about it. It is written for the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Czech Act No. 110/2019 Coll. on personal data processing, which is the law we operate under from our office in Prague.

Last updated:

DATA CONTROLLER

The controller responsible for the processing described below is:

Company
Svarox Labs s.r.o.
Registered office
Petrská 1166/33, Praha 1 – Nové Město, Czech Republic

We have not appointed a Data Protection Officer. We are not required to under Article 37 GDPR: our core activities do not consist of large-scale monitoring or large-scale processing of special categories of data. Privacy questions go to the address above and are answered by the company's management.

01

Who this policy is for

This policy applies when we decide why and how personal data is processed, which in GDPR terms means we act as a controller. That covers three groups of people.

  • Visitors to svaroxlabs.com.
  • People who contact us about work, and the individuals we deal with at client and prospective client companies.
  • People who apply for a role with us.

It does not cover personal data we handle inside a client's product or systems while building or maintaining them. There we act as a processor on the client's instructions, and the client's own privacy policy governs that data. See "Data we handle for our clients" below.

02

What we process, why, and on what legal basis

Visitors to this website

This site has no login, no newsletter and no advertising. Browsing it asks nothing of you, and the only personal data a visit generates is what any web server records. The site does have a contact form; if you choose to use it, what you enter is covered under "Enquiries, clients and prospective clients" below.

What we processWhyLegal basisHow long we keep it
Technical connection data recorded in server logs: IP address, date and time, the page requested, referrer, browser and device typeTo serve the site, keep it available, and detect abuse such as scraping or denial-of-service attemptsArt. 6(1)(f): our legitimate interest in operating and securing our own websiteUp to 90 days, then deleted or aggregated into anonymous statistics

Enquiries, clients and prospective clients

What we processWhyLegal basisHow long we keep it
Your name, email address, phone number if you give it, company and role, the indicative budget and timeline you select in the contact form, and the content of your messageTo answer you, scope the work and prepare a proposalArt. 6(1)(b): steps taken at your request before entering a contract; Art. 6(1)(f) where you write on behalf of a company rather than yourself3 years from our last exchange, matching the general limitation period under Czech law, unless it becomes part of a project record
Contact details of the people we work with at a client, project correspondence, meeting notes and delivery recordsTo run the project and to prove what was agreed and deliveredArt. 6(1)(b): performance of the contract; Art. 6(1)(f) for contact people who are not themselves our counterpartyFor the duration of the engagement and 3 years after it ends
Billing details: invoicing address, company and tax identifiers, bank details, invoices and payment recordsTo invoice, get paid and meet our accounting and tax dutiesArt. 6(1)(c): compliance with a legal obligation5 years for accounting records (Act No. 563/1991 Coll.) and 10 years for tax documents (Act No. 235/2004 Coll.)

Candidates

What we processWhyLegal basisHow long we keep it
Your CV and portfolio, contact details, work history, links you send us, and our notes and assessment from interviews or a taskTo evaluate your application and run the hiring processArt. 6(1)(b): steps taken at your request before a possible employment contract6 months after the role is filled or the process closes
The same materials, kept on file for future openingsTo contact you when a role that fits comes upArt. 6(1)(a): your consent, which you can withdraw at any time2 years from your consent, or until you withdraw it

We do not ask for special categories of personal data under Article 9 GDPR (health, biometrics, political opinions, religion, trade union membership, sexual orientation), and we ask you not to send them. Please leave them out of CVs and enquiries.

03

Cookies, analytics and third-party requests

This site asks for your cookie choice on your first visit, and stores it. As it stands today we run no analytics script, no tracking pixel, no advertising network and no A/B testing tool. The only cookie actually set is the one that records your answer. The categories below exist so that if we ever switch any of them on, they are already off by default and already under your control, rather than being switched on quietly.

The categories you can choose

CategoryWhat it is forLegal basisIn use today
Strictly necessaryKeeps the site working and remembers the choice you make in the cookie banner. Cannot be switched off.Legitimate interest, exempt from consent under § 89(3) of Czech Act No. 127/2005 Coll. on electronic communicationsYes, one cookie
FunctionalRemembers non-essential preferences and lets embedded content, such as a video player, load on pages that carry one.Your consent under Article 6(1)(a) GDPRNo
AnalyticsAggregate measurement of which pages are read and how visitors arrive, so we can improve the site. Not used to identify you.Your consent under Article 6(1)(a) GDPRNo
MarketingLets advertising platforms recognise this browser so a campaign can be measured and relevant ads shown elsewhere.Your consent under Article 6(1)(a) GDPRNo

The cookie we do set

One first-party cookie, ap_consent, records which categories you allowed and the date you decided. It expires after six months, at which point we ask again. It holds no name, no email address and no identifier that would let us recognise you as a person, just your answer. Nothing is sent to a third party.

Changing or withdrawing your choice

The cookie button in the bottom-right corner of every page reopens the preferences panel. Withdrawing consent is as easy as giving it, as Article 7(3) GDPR requires: switch a category off and save, and it stops applying immediately. Clearing your browser's cookies for this site also erases the record, and you will simply be asked again on your next visit.

Requests to third parties

  • Fonts are self-hosted. Our typefaces are downloaded at build time and served from our own domain, so loading a page makes no request to Google Fonts and sends nothing to Google.
  • Photographs come from the Unsplash library, but your browser never contacts Unsplash for them. Our server fetches each image, re-encodes it and serves it from our own domain, so a page load tells Unsplash nothing about you: not your IP address, not your browser, not which page you were reading.

The result is that loading a page on this site sends no request to any third party at all. Everything your browser asks for comes from our own domain. If we ever do enable analytics or marketing, we will update this page before we switch anything on, and nothing in those categories will load until you have opted in.

04

Where we get your data

  • Directly from you, when you email us, apply for a role, or work with us on a project.
  • From your employer or our client, when you are named as a contact person, project owner or approver on an engagement.
  • From your device: the technical connection data described above, generated automatically when you load a page.

We do not buy contact lists and we do not scrape personal data to build prospecting databases.

05

Who we share data with

We do not sell personal data and we do not share it for anyone else's marketing. We disclose it only to the following categories of recipient, and only as far as each one needs it:

  • Service providers who process data on our behalf under Article 28 GDPR: website hosting, business email and file storage, and the tools we use to run projects and issue invoices. Each is bound by a data processing agreement, confidentiality and instructions from us.
  • Our accountants, auditors and legal advisers, bound by professional confidentiality.
  • Public authorities such as courts, tax authorities and supervisory authorities, where we are legally obliged to disclose, and no further.
  • An acquirer or its advisers, if the business is ever sold or reorganised, under confidentiality and with this policy continuing to apply to the data transferred.

The processors behind the contact form

The contact form is the one place on this site where you hand us personal data directly, so we name the providers involved rather than leaving them to the categories above:

  • Resend (Plus Five Five, Inc., United States) delivers the notification we email to ourselves when you submit the form. That message carries your name, email address, company, the timeline and indicative budget you selected and the text you wrote, and sets your address as the reply-to so we can answer you. Resend acts as our processor under Article 28 and does not use the content for its own purposes.

Once we have answered you, the enquiry lives on in our mailbox for the period set out above. Nothing you send through the form is used for marketing and we do not add you to any list.

06

Transfers outside the EEA

We prefer providers that store data in the European Union. Where a provider processes data outside the EEA, we rely on one of the safeguards Chapter V GDPR allows: an adequacy decision of the European Commission for the country in question, or the Commission's Standard Contractual Clauses together with an assessment of the transfer and any additional measures needed.

In practice the transfer this affects today is the contact-form notification handled by Resend in the United States, described in the previous section, which is covered by a data processing agreement incorporating the Standard Contractual Clauses.

Write to us at the address above and we will tell you which safeguard applies to a specific provider and send you a copy of the relevant clauses.

07

Data we handle for our clients

Building and maintaining software sometimes means we can reach personal data belonging to a client's users: during a migration, while diagnosing a production incident, or through access to a system we operate for them. In that role we are a processor, not a controller, and the rules are different.

  • We act only on the client's documented instructions and never for our own purposes.
  • We work under a written data processing agreement meeting Article 28 GDPR before any such access is granted.
  • Everyone with access is bound by confidentiality, and access is limited to the people who need it for the task at hand.
  • We prefer anonymised or synthetic data in development and testing, and use production data only when a task genuinely cannot be done without it.
  • We engage sub-processors only with the client's authorisation, and pass the same obligations down to them.
  • At the end of an engagement we return or delete the data, at the client's choice, except where law requires us to retain it.
  • We notify the client without undue delay if we become aware of a personal data breach affecting their data, so they can meet their own 72-hour duty.

If you are a user of a product we helped build and want to exercise your rights over your data, contact the company operating that product, because they are the controller. Tell us and we will point you in the right direction, but we cannot act on their data without their instruction.

08

How we protect data

We apply technical and organisational measures appropriate to the risk, as Article 32 GDPR requires. In practice that means:

  • Encryption in transit: the website and our internal tools are served over HTTPS.
  • Access on a need-to-know basis, with multi-factor authentication on the accounts that matter and access removed when someone leaves a project or the company.
  • Secrets and credentials kept in a password manager, never in source code or in a repository.
  • Data minimisation: we do not collect fields we have no use for, and we delete what we no longer need.
  • Confidentiality obligations in every employment and contractor agreement.
  • Backups of the systems we operate, and restoration tested rather than assumed.

No system is perfectly secure. If we suffer a breach likely to result in a risk to your rights and freedoms, we will notify the Czech supervisory authority within 72 hours and tell you directly where the risk is high.

09

How long we keep data

The specific periods are in the tables above. The principle behind them is simple: we keep personal data only as long as it serves the purpose it was collected for, plus any period that law requires or that we need to defend a legal claim. When a period ends, the data is deleted or irreversibly anonymised.

10

Your rights

Under the GDPR you can ask us to do the following. These rights are free to exercise and none of them requires a form or a lawyer. An email is enough.

  • Access (Art. 15): get confirmation of whether we process data about you, a copy of it, and the details of how and why.
  • Rectification (Art. 16): have inaccurate data corrected and incomplete data completed.
  • Erasure (Art. 17): have your data deleted where we no longer have grounds to keep it. This does not override our accounting and tax retention duties.
  • Restriction (Art. 18): have processing paused while a dispute about accuracy or grounds is resolved.
  • Portability (Art. 20): receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
  • Objection (Art. 21): object at any time to processing based on our legitimate interest. We stop unless we can show compelling grounds that override your interests. Where the objection is to direct marketing, we stop without exception.
  • Withdraw consent (Art. 7(3)): where processing rests on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of what was processed before.
  • Not be subject to automated decision-making (Art. 22): we make no decisions about you by automated means and we do not profile you, so this right has nothing to bite on here.

Write to the email address above to exercise any of these. We answer within one month of receiving the request, as Article 12(3) requires; if a request is complex we may extend that by two further months and will tell you why within the first month. Where we have genuine doubt about who is asking, we may ask for information to confirm your identity, and we will not use it for anything else.

11

Changes to this policy

We update this page when what we do with personal data changes: a new processing purpose, a new category of recipient, a different retention period. The date at the top always reflects the current version. Where a change materially affects you and we hold your contact details, we will tell you directly rather than relying on you to re-read this page.

12

Contact

Questions about this policy, or about anything we do with personal data, go to the email address at the top of this page.