Legal information
Data Processing Terms
This is an English translation of the Czech Zpracovatelské podmínky. In case of doubt, the Czech version prevails.
Effective from 7 October 2026 · version 2026-10-07
1. What these terms are about
When we run a website, online shop, bookings or an AI assistant for you, we process personal data of your customers, guests and other people. You are the controller of this data and we are the processor.
These data processing terms are a personal data processing agreement under Art. 28 of Regulation (EU) 2016/679 (GDPR). They form part of the contract between you (“client” or “you”) and StreamCharge, s.r.o., company ID (IČO) 22391762, with its registered office at Korunní 2569/108, Vinohrady, 101 00 Praha 10, registered in the Commercial Register kept by the Municipal Court in Prague, Section C, Insert 414146 (“we”), concluded under the terms of service. In matters of personal data protection, they take precedence over the terms of service.
We process data about you, your colleagues and people who communicate with us in connection with your project as a controller. This is described in the privacy policy.
2. Subject matter and duration of processing
The subject matter is the processing of personal data that you entrust to us or that your customers enter into the services we run for you. Processing lasts for the duration of the contract and thereafter until the data is returned or erased in accordance with section 12.
3. Nature and purpose of processing
We process data only in order to provide you with the agreed services:
- running websites and online shops: storing, backing up and displaying data,
- AI assistants: processing your customers’ questions and messages and generating replies,
- recording bookings, orders and jobs and passing them on to you, for example by email,
- notes about customers, so that the assistant recognises regular customers (for example “usually a table for four on Friday”),
- handling your business’s email address, if you entrust it to us,
- customer account in the online shop: remembered device, addresses, orders and preferences, if the customer has given consent to this,
- maintenance and modification of the website on your instruction, and technical support.
We do not use the data for our own purposes, we do not sell it, and we do not use it to train AI models.
4. Whose data is concerned
- customers and visitors of your website and online shop,
- guests who make bookings with you,
- customers who order made-to-measure jobs from you,
- people who write to your business’s email address, which is handled by AI,
- your employees and associates who use the services,
- users of manuals and training simulators (subject to section 5).
5. What data we process
- name, email, telephone and delivery address,
- content of communications: chat messages, emails and attachments,
- orders and jobs: what the customer wants, dimensions, deadline, price and notes,
- bookings: date, time, number of people and a note,
- notes about customers and their preferences,
- customer account in the online shop: device identifier, PIN hash, time of consent and version of the terms, saved addresses, orders and preferences,
- allergens that the customer wishes to avoid; these may reveal something about their health,
- technical data: IP address and request data in operational logs.
We process special categories of data, for example data concerning health, only where the nature of your service requires it. You are responsible for ensuring a legal basis for processing them (for example the customer’s explicit consent).
Data that stays in the browser. Some services are designed so that the data never reaches us at all. In the case of medical manuals and training simulators, patient records stay only in the user’s browser, encrypted with the AES-GCM algorithm using a 256-bit key that the browser does not allow to be read or exported. Our server does not receive these records and stores nothing. The only thing that leaves is the question that the user puts to the AI assistant. We pass it to Anthropic to generate a reply and we do not store it. The user should therefore not write into the question any data by which a patient could be identified.
6. Your instructions
- We process data only on your documented instructions. Your instructions are the contract and these terms, the settings of your project and the requests that you or people on your team give us in the Control Console, by email or by phone.
- We transfer data to a third country or an international organisation only on your instructions or in accordance with sections 9 and 10. The exception is an obligation imposed on us by EU or Czech law; we will inform you of it in advance, unless that law prohibits it.
- If, in our opinion, an instruction infringes data protection regulations, we will notify you immediately and will not carry out the instruction until you confirm or change it.
- Systems that you choose and connect yourself (for example your mailbox, till, accounting or stock system) are your suppliers. We pass data to them on your instruction.
7. Our obligations
- Only persons who need the data to perform the contract and who are bound by confidentiality have access to it.
- We take technical and organisational measures under Art. 32 GDPR (section 8).
- We keep records of processing activities under Art. 30(2) GDPR.
- We help you meet your obligations under Arts. 32 to 36 GDPR: security, notification of security breaches, data protection impact assessments and prior consultation.
- We will provide you with the information needed to demonstrate compliance with these obligations and will allow an audit (section 13).
8. Security
- We store data in Microsoft Azure data centres in the West Europe region (Netherlands). It is also encrypted at rest.
- Communication with our servers is encrypted (HTTPS). We also connect to email servers using encryption.
- The files of each project are in separate private storage. Download links are signed and expire after 7 days.
- Signing in to the Control Console requires a one-time code sent by email. The code is valid for 2 minutes, can be tried at most five times, and the number of codes sent is limited. We store the codes only as a cryptographic hash and never write them to operational logs. We store the PIN of a remembered device only as a hash (PBKDF2).
- Permissions are governed by a single rights model: everyone sees only the projects they have permission to access. A business’s AI assistant works only with the data of that business.
- We never display or export mailbox passwords and access keys.
- The AI developer works in a separate temporary container.
- Conversations without sign-in are not linked to a specific person. We delete their text after 7 days.
- Changes to our system go through automated tests, including tests that the export and erasure of one person’s data affect all records.
- We keep backups for no more than 30 days.
9. Sub-processors
You give us general authorisation to engage other processors (sub-processors). As of the effective date of these terms, we use the following:
- Microsoft Ireland Operations Limited (Ireland): the Microsoft Azure cloud – running websites, online shops and our services, databases, file storage, backups and running the AI developer. Data is stored in the West Europe region (Netherlands).
- Anthropic, PBC (USA): Claude language models. They process messages, emails, call transcripts and supporting materials for which the AI prepares replies or website edits.
- Telnyx LLC (USA): telephone calls and SMS messages – telephone numbers, the audio of calls in transit and the text of SMS messages.
- Soniox, Inc. (USA): speech-to-text conversion during telephone calls.
- Gladia SAS (France) and Groq, Inc. (USA): backup speech-to-text conversion.
- Eleven Labs, Inc. (ElevenLabs, USA): the AI’s synthetic voice during calls and backup speech-to-text conversion.
- INTERNET CZ, a.s. (FORPSI, Czech Republic): the mailboxes from which we send and receive emails, for example order confirmations and sign-in codes.
- GitHub, Inc. (USA): storage of the source code and content of websites and their automatic deployment.
Only some of them are used, depending on the nature of the service. For example, telephone and voice services are used only where communication is by telephone.
- We impose on each sub-processor by contract the same data protection obligations that we have towards you. We are responsible to you for their performance (Art. 28(4) GDPR).
- We will notify you by email of any intention to add or replace a sub-processor at least 30 days in advance. Until then, you may object to the change. If we do not resolve the objection together, you may terminate the contract as of the date of the change without penalty.
10. Transfers outside the European Economic Area
Some sub-processors are based in the USA. We transfer data to them on the basis of the European Commission’s decision on adequate protection (EU–US Data Privacy Framework) where the recipient is certified, and otherwise on the basis of the European Commission’s standard contractual clauses (Art. 45 and Art. 46(2)(c) GDPR). We will provide you with a copy of the clauses on request.
11. Customers’ rights and security breaches
Customers’ requests
- We will help you deal with requests for access, rectification, erasure, restriction of processing and portability, and with objections. We are able to prepare an export of all of one person’s data and delete it from all records.
- We will provide the necessary assistance without undue delay, and in any event within 10 working days.
- If a customer contacts us directly, we will pass their request on to you without undue delay and will not deal with it ourselves unless we agree otherwise.
- On erasure, the booking remains in your business’s calendar, but without the customer’s name, contact details and note.
- Conversations without sign-in cannot be attributed to any person. When a customer signs in with a verification code, we attach their existing conversation and order to them; from that moment they can be exported and deleted as that person’s data.
How long we keep data
- We delete the text of chats without sign-in after 7 days, and the record without the text after 90 days.
- We delete unfinished or cancelled orders and jobs of customers who are not signed in 7 days after the last change. We keep completed orders, because you fulfil them.
- A customer’s remembered device stops being valid 180 days after it was last used.
- We keep other data for the duration of the contract, unless you delete it earlier or the customer asks for erasure.
Security breaches
We will notify you of a personal data breach without undue delay, and in any event within 48 hours of its discovery. We will state what happened, which data and persons are affected, what the likely consequences are and what measures we have taken. We will supply whatever we do not yet know as soon as we find out.
12. End of processing
- Within 30 days after the contract ends, you may request an export of the data in a commonly used machine-readable format.
- After that we will delete the data, including the project’s websites and repositories. It will disappear from backups within a further 30 days at the latest.
- We will keep only what the law requires us to keep.
- We will confirm the erasure to you on request.
13. Audit
- On request, we will provide you with the information needed to demonstrate compliance with these terms.
- You, or an auditor bound by confidentiality, may carry out an audit or inspection, no more than once a year, with 30 days’ notice and at your own expense. If a security breach has occurred or the supervisory authority requires it, an audit or inspection may also be carried out outside this framework.
- For sub-processors, we will demonstrate compliance in particular through their certifications and audit reports.
14. Your obligations as controller
- You have a legal basis for the processing, and you inform your customers how we process their data, including that we operate your services and that they are communicating with AI.
- For special categories of data, you will ensure the necessary legal basis.
- Your instructions comply with the regulations.
- You do not remove or obscure the notice that the customer is communicating with AI.
15. Final provisions
Liability between us is governed by the terms of service. Their limitations do not apply to claims of data subjects under Art. 82 GDPR. These terms are governed by the GDPR, Act No. 110/2019 Coll., on Personal Data Processing, and other law of the Czech Republic. We change them by the same procedure as the terms of service, that is, with notice by email at least 30 days in advance.
Contact for personal data protection: info@streamcharge.cz.
Company details
- StreamCharge, s.r.o.
- Company ID (IČO): 22391762
- Registered office: Korunní 2569/108, Vinohrady, 101 00 Praha 10
- Registered in the Commercial Register kept by the Municipal Court in Prague, Section C, Insert 414146
- Email: info@streamcharge.cz
- Website: www.streamcharge.cz