Privacy Policy
How Progity processes personal data in connection with the Nodali website and service.
1. Controller and contact
The controller of personal data processed for its own purposes is David Hošek, doing business under the trade name Progity, Company ID 03956890, with registered office at U Potoka 247, 440 01 Peruc, Czech Republic, registered in the Czech Trade Licensing Register, e-mail: privacy@noda.li. This policy provides information under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
2. Roles of the operator
The operator is the controller in particular of the data of website visitors, prospects, customers, account users, contact persons and suppliers, which it processes for registration, customer verification, account administration, the contract, invoicing, support, communication, security and its own legal obligations.
Where the customer processes personal data of third parties through Nodali and determines the purposes and means of such processing, the customer is the controller and the operator is the processor. Such processing is governed by a separate data processing agreement under Article 28 GDPR, which will be concluded electronically through the authenticated customer account before the activation of Nodali Connect, import feeds, system integrations or any other function enabling the entry or synchronisation of customer data. This policy does not replace the data processing agreement.
Electronic acceptance of the data processing agreement will not require a signed PDF or a qualified electronic signature, unless individually agreed otherwise. The specific document and acceptance mechanism will be made available before the activation of the relevant functions.
3. Categories of data
- identification and contact details, for example name, work e-mail, phone, company, Company ID and job position;
- account, tenant, role, permission and settings data;
- order, contractual, billing and payment data; the operator does not store full payment card details;
- customer support communication, enquiries, records of consents and contractual acts;
- technical and security data, in particular IP address, time, session identifier, device, browser, audit and application logs;
- data obtained from the employer, customer or tenant administrator where a user account is created by another authorised person; the invitation to create an account contains a link to this policy.
4. Purposes, legal bases and retention
| Purpose | Legal basis | Usual period |
|---|---|---|
| Registration, account administration and provision of the service | Performance of the contract and pre-contractual steps; for contact persons, legitimate interest in performing the B2B contract | For the duration of the contract and usually 3 years after its end to protect rights |
| Verification of the customer's business status (ARES, VIES) | Performance of the contract and legitimate interest in contracting only with businesses | For the duration of the contract and the running of related limitation periods |
| Orders, invoicing and accounting | Performance of the contract and legal obligation | Accounting and tax documents for the period required by accounting and tax regulations, usually 10 years; other contractual and payment metadata usually 4 years after the end of the contract |
| Support and handling of requests | Performance of the contract and legitimate interest in documenting and improving support | For the duration of resolution and usually 3 years thereafter |
| Commercial communications to existing customers and their contacts about Nodali functions, modules, connectors and related services | Legitimate interest and Section 7(3) of Act No. 480/2004 Coll. | For the duration of the customer relationship or until unsubscribing or objection |
| Security, audit logs and abuse prevention | Legitimate interest in secure operation and protection of rights | Depending on the risk and log type, usually 6 to 24 months; longer in the event of a security incident or legal claim |
| Demonstrating consents and contractual acts | Legitimate interest and legal obligation | For the duration of the relationship and the running of related limitation periods |
| Analytics cookies | Consent | Until consent is withdrawn or the specific cookie expires |
A specific piece of data may be retained longer where necessary for a legal claim, a security incident or compliance with a legal obligation. Once the purpose has lapsed, the data is deleted or anonymised, taking technical backups into account.
5. Commercial communications
The operator may send existing customers and their contact persons commercial communications about Nodali functions, modules, connectors and related services on the basis of legitimate interest and Section 7(3) of Act No. 480/2004 Coll. Each communication contains a simple opt-out option. Sending can be refused at any time in each individual communication or at privacy@noda.li. To prospects who are not yet customers, the operator sends commercial communications only on the basis of consent, unless another specific legal basis applies.
6. Obligation to provide data
Data marked as mandatory is a contractual or statutory requirement. Without it, it may not be possible to create an account, conclude a contract, issue a document or provide support. Other data is voluntary.
7. Sources of data
We obtain data directly from the data subject, from the customer, employer or tenant administrator, from business communication, from the use of the service, from public registers, in particular ARES and VIES, and from payment, integration or security providers to the extent necessary for the given purpose.
8. Recipients and processors
Data may be made available to providers of hosting and infrastructure, backup and storage, e-mail and communication services, customer support, accounting, payment services, monitoring, security and development, as well as to legal, accounting and tax advisers and public authorities where required by law. The operator selects suppliers with appropriate safeguards and concludes the necessary agreements with them. Current information about the categories of recipients is available on request at privacy@noda.li.
9. Transfers outside the EEA
We primarily aim to process data within the European Economic Area. If a supplier processes data outside the EEA, we will use appropriate safeguards under the GDPR, in particular an adequacy decision or standard contractual clauses, and supplementary measures as needed. Information about the specific safeguard will be provided on request, where security and contractual restrictions allow.
10. Automated decision-making
The operator does not, for its own purposes, carry out decision-making based solely on automated processing that would have legal or similarly significant effects for users. The analytics and recommendation functions of the platform serve as a basis for the customer's decisions, not as a substitute for them.
11. Rights of data subjects
Under the conditions of the GDPR, you have the right of access, rectification, erasure, restriction of processing, portability, objection to processing based on legitimate interest and withdrawal of consent. Withdrawal of consent does not retroactively affect the lawfulness of previous processing. Requests may be sent to privacy@noda.li; before handling, we may reasonably verify the identity and authorisation of the requester. We handle requests without undue delay and no later than one month after receiving them; taking into account the complexity and number of requests, this period may be extended by a further two months, of which we will inform the applicant in due time.
If the request concerns data for which a Nodali customer is the controller, please contact that customer first. The operator will provide the customer with cooperation under the data processing agreement.
12. Complaint
You have the right to lodge a complaint with the Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz, or with another competent supervisory authority in the EU.
13. Security
We use appropriate technical and organisational measures with regard to the risks, in particular access management, tenant separation, encrypted communication, backups, logging and ongoing maintenance. However, no system can be considered absolutely secure.
14. Changes to this policy
We may update this policy when services, suppliers or legal requirements change. The current version and effective date are always published on this page. The Czech version prevails.
15. Enquiries and communications
| Purpose | Legal basis | Usual period |
|---|---|---|
| Handling a pilot, contact or business enquiry | Pre-contractual steps; for contact persons, legitimate interest in B2B communication | During negotiations and usually 3 years after the last relevant communication; longer only for a legal claim or obligation |
Pilot, contact and business enquiries are processed for pre-contractual steps and, for B2B contacts, legitimate-interest communication during negotiations and usually 3 years after the last relevant contact, longer only for claims or law. An enquiry is not marketing consent.
Service messages cover registration, orders, billing, payments, invoices, card charges, price or plan changes, legal terms, security, incidents, outages, support, Core limits and upgrades, termination and portability. They are necessary for contract, law or secure operation and cannot be globally unsubscribed, though authorised addresses can change. Nodali currently sends no active marketing. Future similar-product offers to customers require § 7(3) Act No. 480/2004 and free opt-out; others require demonstrable consent or another specific legal basis. A form is not consent and any future checkbox must be separate, optional and unticked.
16. Security and storage
Tenant data are logically separated by tenant ID and application authorisation in shared database infrastructure; tenants do not receive separate physical databases and one tenant user cannot access another through the application. Client-server traffic uses HTTPS. Database backups are stored on an internal NAS and application/operations logs centrally on VPS infrastructure. Access controls, logging and ongoing maintenance are used; no unsupported at-rest encryption or certification is claimed.