Privacy

What data we process, why and for how long.

1. Controller and contact

The controller is Jaroslav Lachký, Medňanská 517/11, 019 01 Ilava, Slovakia, e-mail info@mitoops.com, telephone +421 949 688 122. MitoOps s.r.o. is in the process of being entered in the commercial register; once it exists, the controller's rights and obligations pass to it and the details will be updated on this page.

No data protection officer has been appointed under Article 37 GDPR — the controller neither processes personal data on a large scale nor systematically monitors data subjects. For data protection matters write to info@mitoops.com.

2. Two distinct roles

We are the CONTROLLER for the data of SITE VISITORS and SERVICE CUSTOMERS — the data you give us yourself.

We are the PROCESSOR for data our client enters into the system, or that the system reads from their shop — the data of the CLIENT'S OWN CUSTOMERS. We process it solely on the client's instructions; the client is its controller. The details are set out in the data processing agreement we conclude with each client.

3. What we process and on what basis

Contact form and sign-up — name, e-mail, telephone, company name and message. Legal basis: performance of a contract or steps prior to it (Art. 6(1)(b) GDPR). Retention: 3 years from the last communication.

User account — name, e-mail, role, sign-in records. Legal basis: performance of a contract. Retention: for the term of the contract and 30 days after it ends.

Billing details — company name, address, identifiers, payment history. Legal basis: compliance with a legal obligation (Art. 6(1)(c)). Retention: 10 years under accounting law.

Operational and security logs — device address, time and type of action. Legal basis: legitimate interest in the security and availability of the service (Art. 6(1)(f)). Retention: 12 months.

Conversations with the bot on this site — the text of the question and answer, a technical fingerprint of the address. Legal basis: legitimate interest in providing support. Retention: 12 months.

Traffic measurement — only with consent (Art. 6(1)(a)), which can be withdrawn at any time in the consent bar.

4. Where the data comes from

Directly from you — forms, your account and our correspondence.

From the client's shop — for end-customer data that the system reads through the e-commerce platform interface on the client's instruction.

Automatically during use — operational logs and technical details about the device.

5. Who we share data with

Infrastructure provider — a server in the European Union on which the service runs.

E-mail provider (Brevo, European Union) — sending notifications and replies to enquiries.

Stripe payment gateway — payment processing. Card details are processed solely by Stripe; the controller has no access to them.

Language-model providers — for features that produce or respond to text. Only the text needed to perform the task is sent. Under their terms these providers do not use submitted content to train their models.

Carriers — recipient details necessary for delivery. They are passed on the client's instruction and under the client's own account number.

Google Ireland Limited — traffic measurement for this site (Google Analytics 4), tag management (Google Tag Manager) and advertising conversion measurement (Google Ads). Only on the basis of your consent and only within the category you allowed. This does not concern client data held in the application — that is not shared with Google.

Other parties only where required by law (for example public authorities acting on a final decision).

6. Transfers outside the European Union

The service and its data storage are located in the European Union.

Features using language models may involve a transfer to the United States. Such transfers are covered by the European Commission's standard contractual clauses, or by an adequacy decision where the recipient can rely on one.

A list of the providers currently used is available on request at info@mitoops.com.

7. How long we keep data

Retention periods are stated with each purpose in article 3. Once they expire the data is deleted or anonymised.

Client data stored in the service remains available for export for 30 days after the contract ends; it is then irreversibly deleted, backups included, within 90 days at the latest.

8. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interest.

Where we process data on the basis of consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing before it.

A request to info@mitoops.com is enough. We reply within one month; for a complex request the period may be extended by two months, of which we will inform you.

You also have the right to lodge a complaint with a supervisory authority — in Slovakia, Úrad na ochranu osobných údajov SR, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk.

9. Cookies, traffic measurement and marketing

The site stores in your browser only what it needs to work — the language choice, the theme choice and your consent decision. These require no consent.

Before consent is given the site contacts no third party — no font, no library, no measurement. That applies to the tool through which measurement is delivered as well.

We use Google Tag Manager to manage measurement tags. It measures and stores nothing by itself — it is the tool that fires the tags listed below. It loads only after consent to traffic measurement is given.

Traffic measurement (Google Analytics 4) starts only with consent in the traffic measurement category. It processes a truncated IP address, device and browser type, the source of the visit and movement across pages, so that we can tell which parts of the site are useful. The legal basis is your consent.

Marketing measurement (Google Ads) starts only with separate consent in the marketing category. It measures conversions and builds advertising audiences. Consent to traffic measurement does NOT switch marketing on — these are two separate decisions.

We use Google Consent Mode v2. Until consent is given, all advertising and analytics storage is set to denied, and in that state the tags store nothing in your browser that would identify you.

Consent can be changed or withdrawn at any time via the link in the footer. Withdrawal takes effect immediately, without reloading the page. Details are on the separate cookies page.

10. Automated decision-making

We carry out no automated decision-making with legal effect and no profiling within the meaning of Article 22 GDPR.

Features using language models produce suggestions, not decisions. Writing to the shop or sending anything to a customer always requires human confirmation.

11. Security

All traffic is encrypted in transit. Access to data requires authentication and is bound to the user's role; actions are logged.

Each client's data is separated at the storage level. Backups are encrypted and their restoration is tested regularly.

Access by staff and contractors is limited to what is necessary and bound by confidentiality.

12. Changes to this document

We may amend this text, in particular when the scope of processing or the set of providers changes. Material changes are announced by e-mail at least 30 days in advance.

The date of the last revision is shown at the end of the page.

Last updated: 2026-08-06