Personal Data Processing Policy
The controller of personal data is NetGenium s.r.o., with its registered office at Za Zámečkem 1037/1b, 158 00 Prague 5, Czech Republic, identification number 27092381, tax ID CZ27092381, registered in the Commercial Register maintained by the Municipal Court in Prague, Section C, Entry 95657 (the “controller”). Contact: info@netgenium.com, data box 2hmpzpe.
This policy describes how the controller processes the personal data of visitors to www.netgenium.com and of customers of the NET Genium Online service.
What Data We Process and Why
Registration and Operation of NET Genium Online
- The e-mail address entered during registration — used to send the activation link, the credentials, warnings about the credit running out and operational notices (outages, changes of the terms, notice before an instance is deleted). The legal basis is the performance of the contract.
- Billing details entered when ordering credit — used to issue a tax document. The legal basis is compliance with legal obligations (accounting and tax law).
- Payment details — card payments are processed by the Stripe payment gateway. The customer enters their card details directly in it; the controller neither sees nor stores them and receives from Stripe only the confirmation of payment and the details needed to issue the tax document. The legal basis is the performance of the contract.
- IP addresses and operational logs of the website and the registration — used to secure the service, protect the registration form from abuse and resolve technical issues. The legal basis is the controller's legitimate interest in securing the service. Operational records created inside the customer's instance do not belong here — they are covered by the following part.
Data Stored by the Customer in Their Instance
With respect to personal data the customer stores in their NET Genium Online instance, the customer is the controller and NetGenium s.r.o. is the processor. The scope and conditions of this processing — including the list of sub-processors, the security measures and the erasure rules — are governed by the data processing addendum that forms part of the license terms.
The instance also contains the operational records (logs) the platform creates in it — for example the records of user logons. They form part of the customer's data, so the customer is the controller of them as well and decides how long to keep them. The instance administrator can view, download and delete them in Reports under the “Logs” item; the NET Genium settings dialog also offers the deletion of the measured data in the database and on the disk. A detailed description is provided in the separate guide Reports.
The www.netgenium.com Website
- Cookies and analytics — the website uses Google Analytics on the basis of consent given in the cookie settings accessible from the footer; without consent no measurement takes place and the consent can be withdrawn at any time in the same place.
- Protection of the registration form — on the registration page the website uses the Google reCAPTCHA service (distinguishing real users from bots). The legal basis is the legitimate interest of the controller in securing the service.
Who We Share Data With
- The hosting provider — the instances and the website run on servers of MasterDC s.r.o., company ID 26277557, in data centres in Prague and Brno, i.e. within the European Union.
- Google Ireland Ltd. — reCAPTCHA and Analytics (see above).
- Stripe Payments Europe, Limited (Ireland) — processing of card payments when topping up credit.
- The AI model providers — the AI application-building assistant passes the customer's description of their request to a language model provider. Only the description entered by the user, the names of the entities being created and the structure of the resulting application (table and column names) are transferred — not the records stored in the instance. Personal data are therefore transferred only if the user includes them in the description themselves. The primary service is Microsoft Copilot Studio, processed by Microsoft Ireland Operations Limited. The processing takes place in an environment within the EU Data Boundary; during periods of peak load the model itself may run outside the EU, while the stored data remains in the EU. If this service is unavailable, Anthropic PBC is used, with processing in the USA. Where the assistant's features use Bing search, that processing takes place in the USA and is governed separately by the Microsoft Services Agreement and the Microsoft Privacy Statement. Under the contractual terms of both language model providers, the submitted content is not used to train their models.
Data may be transferred outside the EU/EEA in the case of Microsoft — when the model runs during periods of peak load and in features that use Bing search — as well as Anthropic PBC (USA) as the fallback AI model provider, Google in connection with analytics and reCAPTCHA, and Stripe in connection with payment processing. For the running of the model, for Anthropic and for Stripe, the transfer is covered by the standard contractual clauses under Commission Decision (EU) 2021/914, which form part of those providers' data processing addenda. For Bing search and for Google it is covered by an adequacy decision — certification under the EU-US Data Privacy Framework.
How Long We Keep the Data
- The registration e-mail and instance data — for the duration of the contractual relationship and then for a maximum of 3 days after the instance is deleted, which is how long backups remain available.
- Billing details — for the period required by accounting and tax law.
- Operational logs of the website and the registration — 3 months from the time they are recorded, after which they are deleted automatically. The retention period of the operational records inside an instance is set by the customer (see above).
- Unconfirmed registrations are deleted automatically after 24 hours.
Marketing
We do not use the customer's e-mail address to send commercial communications. Should we want to change this in the future, we will ask for consent first.
Your Rights
You have the right to access your data, to have it corrected or erased, to restrict its processing, to data portability, to object to processing based on a legitimate interest, and to lodge a complaint with the Czech Office for Personal Data Protection (www.uoou.cz). Please direct any requests to info@netgenium.com.
This policy is effective from 12 August 2026. Version 1.0.