Privacy Policy
Effective from 7 February 2025 - last updated 16 September 2026
This is a translation for convenience. The Czech version is the governing text; in case of any discrepancy, the Czech wording prevails.
This Privacy Policy describes how Kulatá kostka s.r.o. processes the personal data of users of the online application Alfrédové.com - your marketing assistant (the „Service“). It supplements the Terms and Licence Conditions.
1. Who processes your data and in what role
- Kulatá kostka s.r.o., Company ID: 10731041
- Registered office: Rudolfovská tř. 1965/29, 370 01 České Budějovice 3, Czech Republic
- Contact: info@alfredove.com, +420 777 055 069
For most data we are the controller: your user account, billing, our communication with you, traffic measurement and the operation of the Service. That is what this Policy describes.
For two groups of data we are the processor and you are the controller: data from your shop that the Service reads once you connect it (orders, catalogue, coupons) and the content you put into the Service, which may contain other people's personal data. A separate data processing agreement under Article 28 GDPR applies to them; until it is published in the application we will send it on request to info@alfredove.com.
2. What data we process
As a controller:
- Identification and contact data: first name, surname, e-mail, and phone where provided.
- Billing data: company name, company ID, VAT ID, billing address, amounts paid and invoices.
- Account and usage data: account settings, tariff type, information about credits and their consumption, technical logs (sign-in time, IP address, device/browser identifiers).
- Marketing attribution of the account: the full address you first arrived at our website from, including campaign parameters and ad-click identifiers (such as
fbclidorgclid). It is stored in a cookie on our own domain on the first visit and attached to the account on registration, regardless of consent to marketing cookies. - Payment data: card payments are processed through the Stripe payment gateway; we do not store card numbers on our servers.
As a processor on your behalf:
- Content and history of your work in the Service: your shop profile, the content of the shop website you enter, your brand library (personas, marketing angles, brand dictionary and manual, voice samples, shop documents), saved briefs, generated texts and images and their history, questions asked on the dashboard, and images you upload.
- Data from the connected shop: orders, order lines, discount coupons, the catalogue of products and categories, and basic shop settings. Personal data of your customers (name, e-mail, phone, delivery or billing address) is never transferred to or stored in the Service. The customer identifier is converted, before being stored, into an irreversible fingerprint salted with a key unique to each shop and kept outside the database; it only tells the Service that several orders belong to the same customer. We cannot identify or contact that customer, and we do not link fingerprints across shops.
3. Purposes and legal bases
- Creating and maintaining the user account, providing the Service, customer support and communication. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Invoicing and accounting, records of payments and compliance with tax obligations. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
- Security and abuse prevention (anomaly detection, protection against attacks). Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Improving the Service and internal statistics (aggregated or pseudonymised analysis of feature usage and credit consumption). Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Marketing communication about our own similar services. Legal basis: legitimate interest; you can opt out at any time.
- Measuring the effectiveness of our own advertising: storing the landing URL including ad-click identifiers and passing the fact of a registration to an advertising platform (see section 5, Meta). Legal basis: legitimate interest (Art. 6(1)(f) GDPR); you may object at any time at info@alfredove.com.
- Voluntary consents (e.g. a newsletter beyond the legitimate interest, non-essential cookies). Legal basis: consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time.
- Processing of the content you put into the Service and of data from the connected shop happens on your instructions (Art. 28 GDPR). You, as the controller, determine the legal basis for it.
4. Retention periods
- Account data, content put into the Service, work history and data from the connected shop: for the duration of the account; once it ends we delete them irreversibly within 30 days. Disconnecting the shop does not shorten that period. You can delete any of it yourself in the application at any time.
- Invoicing and accounting documents: for the period set by law (typically up to 10 years from the end of the accounting period). These are excluded from erasure, as are the immutable record of administrator actions and anonymous operational and cost records from which you can no longer be identified.
- Communication and technical logs: usually 6–24 months depending on the nature of the record and security needs.
- Marketing based on consent: until consent is withdrawn or you unsubscribe.
5. Recipients and processors
Your data may be passed on, to the extent necessary, to the following processors:
- Supabase - database, authentication and file storage. The data sits in the EU, in the Frankfurt region (
eu-central-1). - Vercel - hosting and operation of the application; server functions run in the Frankfurt region (
fra1). - OpenRouter - routing to AI models; your briefs, including the content you put into the Service, and catalogue texts are sent to model providers in order to generate output. If you use voice dictation, the recording is sent for transcription only and is not stored anywhere - only the resulting text remains in your form. We do not use your briefs or outputs to train AI models; model providers may retain requests for a limited time for operational and security reasons under their own terms. The current list of available models and their providers is in the application, under generation settings.
- Firecrawl - reading your shop website during onboarding and auto-fill; the address and publicly available content of the site are passed on.
- Eshop-rychle (Golemos s.r.o.) - the platform of your shop, if you connect it to the Service. The catalogue, orders, coupons and settings are read from it, and approved product and category texts are written back on your explicit instruction. No write ever happens automatically in the background.
- Resend - sending transactional e-mails (address confirmation, sign-in link, operational notices).
- Ecomail - contacts, tags, lists and e-mail marketing including automations.
- Cloudflare - Turnstile bot protection on the registration form.
- Sentry - error monitoring; personal data is deliberately kept out of error reports.
- Google - Google Tag Manager and traffic measurement, only with your consent; and Google sign-in, if you use it.
- Meta - server-side conversion measurement (Conversions API). On registration we pass a hash of your e-mail address, your IP address and your browser string together with the ad-click identifier. This happens regardless of consent to marketing cookies, on the basis of our legitimate interest in measuring our own advertising; You can object with one click in the application, in Settings, the Account tab, or by writing to info@alfredove.com; from that moment we send nothing about you. The objection can only be attached to an account, so it does not cover the free persona generator, which runs before any account exists. Your customers' data is never passed to Meta.
- GitHub - holds the encrypted daily database backup as an artefact of the backup job.
- Stripe - payment gateway and antifraud.
- Accountants and tax advisors, to meet statutory obligations.
- Public authorities, where required by law.
We conclude data processing agreements with our processors in accordance with GDPR.
6. Transfers to third countries
The database, file storage and server functions are located in the European Union (Frankfurt am Main). Some recipients (e.g. OpenRouter and the AI model providers, Firecrawl, Meta, Stripe, Sentry, Google, GitHub, Vercel) may however process data outside the EU/EEA. We ensure appropriate safeguards under GDPR, in particular an adequacy decision of the Commission, standard contractual clauses and a transfer impact assessment. Details are available on request.
7. How we protect your data
We apply appropriate technical and organisational measures: encryption in transit and of backups, separation of each customer's data at the database level, access control, daily backups with a regular restore drill, the principles of minimisation and pseudonymisation wherever possible, and automated tests that check these measures on every change to the code.
Sensitive administrator actions on an account (credit adjustments, role or tariff changes, deactivation) are written to an immutable record. We look into your data only when you ask us to, when it is necessary to fix a fault or secure the Service, or when the law requires it; the administration does not display the content of your briefs and outputs.
8. Cookies and similar technologies
- Essential cookies: required for signing in, running the account and security (used without consent).
- Analytics, preference and marketing cookies: used only with your consent, which you can change at any time in the cookie bar or in your browser settings.
9. Automated processing and profiling
The Service performs automated processing in the form of calculating and consuming credits (1 credit = 1 generated word) and technical analyses of feature usage. We do not make decisions with legal effects without human review (Art. 22 GDPR).
10. Your rights
You have the right:
- of access to your personal data,
- to rectification of inaccurate or incomplete data,
- to erasure („right to be forgotten“) in the cases set by law,
- to restriction of processing,
- to data portability,
- to object to processing based on a legitimate interest,
- to withdraw consent at any time where processing is based on consent.
You can exercise your rights at info@alfredove.com. You also have the right to lodge a complaint with the Czech Office for Personal Data Protection.
11. Cancelling your account and deleting data
Write to us at info@alfredove.com and we will close your account. No further charges follow. Account data is irreversibly deleted within 30 days of the account ending, including projects, the brand library, generated texts and images, the shop connection and the data read from it. Only what section 4 lists is excluded: accounting documents, the immutable record of administrator actions, and anonymous operational records.
12. Payments and invoicing
Moving from the free tariff to a paid one triggers an invoice immediately and starts a recurring payment at the chosen interval; payments are made by card through Stripe and we do not store card details. The subscription renews automatically unless the account is cancelled before the end of the cycle. On the free tariff the Service does not ask for payment details.
13. Data minimisation
We only ask for the data needed to conclude and perform the contract and to meet legal obligations. Data processed on the basis of consent is provided voluntarily and consent can be withdrawn at any time.
14. Changes to this policy
We may update this policy from time to time, in particular following changes to the Service or to legislation. We will inform you of significant changes in an appropriate way (e.g. by e-mail or by a notice in the Service). We always state the effective date and the date of the last update.
15. Contact
For questions about the processing of personal data contact us at info@alfredove.com or +420 777 055 069.
Controller: Kulatá kostka s.r.o., Company ID: 10731041, Rudolfovská tř. 1965/29, 370 01 České Budějovice 3.