Privacy

Privacy Policy

How Progity processes personal data in connection with the Shipvise website, pilot and service.

1.0 · Last updated 6. 8. 2026.

1. Controller and contact

The controller is David Hošek, trading as Progity, company registration number 03956890, registered address U Potoka 247, 440 01 Peruc, Czech Republic, registered in the Czech Trade Register. Privacy contact: hello@shipvise.com. This Policy provides information under Articles 13 and 14 GDPR.

2. Scope

This Policy applies to website visitors, pilot applicants, consumers, business customers, account users, workspace members, customer contacts, people ordering AI or senior review, suppliers and other people who communicate with us.

  • Public website, contact forms and pilot forms.
  • Registration, sign-in, account, workspace, role and permission management.
  • Application hosting, builds, deployments, logs, monitoring, reviews and support.
  • Orders, subscriptions, credits, payments, invoicing, withdrawals, cancellations and refunds.
  • Security, audit, fraud and abuse prevention and sanctions screening.

3. Progity’s roles

Progity acts as controller for data processed to operate the website and service, administer accounts, perform contracts, invoice customers, provide support, maintain security, communicate, meet its own legal obligations and develop Shipvise.

Where a customer processes personal data of third parties through Shipvise and determines the purposes and means, the customer is the controller and Progity is the processor. That processing is governed by a separate Article 28 GDPR data processing agreement.

For AI or senior review, source code, diffs, configuration, logs or other project content may be accessed only to the extent necessary for the ordered review.

4. Data we process

  • Identity and contact data, including name, email address, phone number, address, country, company, registration number, VAT ID and job title.
  • Account, workspace, membership, role, permission, authentication method, settings and legal acceptance records.
  • Order, contract, plan, credit, invoicing and payment data. We do not store full payment card details.
  • Project, revision, release and environment data, build and runtime logs, domain names, repository metadata, review requests, check results and audit trail records.
  • Source code, uploaded archives, configuration files and other customer content, which may include personal data submitted by the customer.
  • Contact and pilot enquiries, support communications, complaints, withdrawal requests, security reports and consent records.
  • IP address, timestamps, session identifiers, device, operating system, browser, URL, referrer, audit, application and security logs.
  • Data needed to determine customer location and tax treatment, such as billing country, state or province, payment-method country and proportionate IP geolocation.
  • Data from public registers and checks, including ARES, VIES, company registers, sanctions lists and payment or fraud-risk checks.

5. Purposes, legal bases and retention

Contact and pilot enquiries

Právní základ: Steps before a contract, contract performance or legitimate interest in handling communications; consent only where specifically requested.

Doba uchování: During the discussion and generally for 3 years after the last relevant communication.

Registration, authentication, account and workspace administration and service delivery

Právní základ: Contract performance and pre-contract steps; legitimate interest for users invited by organisations.

Doba uchování: For the account or contract and generally 3 years afterwards.

Builds, staging, production hosting, monitoring, logs, backups, rollback and support

Právní základ: Contract performance; legitimate interest for security logging.

Doba uchování: For the service duration; operational data generally 30 days to 24 months depending on type and plan.

AI review, senior review, re-verification and paid fixes

Právní základ: Contract or order performance; legitimate interest in documenting scope and result.

Doba uchování: For the service and generally 3 years after completion; technical artefacts may be shorter-lived.

Orders, subscriptions, credits, payments, refunds, invoicing and accounting

Právní základ: Contract performance and legal obligations.

Doba uchování: Accounting and tax records generally 10 years; other contract and payment metadata generally 4 years.

Customer and tax status, VAT ID validation, customer-location records and VAT, OSS, GST or sales-tax obligations

Právní základ: Legal obligations and legitimate interest in correct billing and fraud prevention.

Doba uchování: For statutory periods; some tax-scheme records may be kept up to 10 years.

Security, audit, abuse prevention, fraud checks, sanctions screening and incident handling

Právní základ: Legitimate interest in safe and lawful operation; sometimes legal obligation.

Doba uchování: Generally 6 to 24 months, longer for incidents or legal claims.

Commercial communications and Shipvise information

Právní základ: Consent or applicable rules for similar services to existing customers.

Doba uchování: Until withdrawal, unsubscribe or objection.

Evidence of consents, orders, contractual acts, complaints and legal claims

Právní základ: Legal obligation and legitimate interest in protecting rights.

Doba uchování: For the relationship and relevant statutory or limitation periods.

Specific data may be retained longer where required for a legal claim, security incident or legal obligation. It is then deleted or anonymised, subject to backup cycles.

6. Sources

We obtain data directly from you, from a customer or workspace administrator who invites you, from service use, connected repositories and integrations, business communications, payment and security providers and public registers such as ARES, VIES, company and sanctions registers.

7. Required data

Required data is needed to create an account, enter into or perform a contract, determine location and tax treatment, issue invoices or maintain security. Without it, we may be unable to provide the service.

8. Recipients and processors

Data may be disclosed to hosting, infrastructure, DNS, registry, storage, backup, email, communications, payment, accounting, monitoring, security, fraud-prevention, support, development and AI providers, as well as senior reviewers, legal, accounting and tax advisers and public authorities.

Access is limited to what is necessary. A current subprocessor list or categories will be published separately or provided on request.

9. AI review and model providers

When AI review is ordered, Shipvise may send relevant portions of diffs, source code, configuration, check results and instructions to a selected model provider. Only context needed for the specific review is sent.

  • AI review is optional; ordinary hosting does not automatically send the entire project to a model provider.
  • Customer content must not be used to train public models without the customer’s separate explicit consent.
  • We seek to exclude secrets and unnecessary data, but customers must not place real credentials or unnecessary personal data in source code.
  • Available providers, processing regions and restriction options will be stated in the product or subprocessor list.

10. Senior review

An authorised engineer may access the agreed scope of source code, diffs, logs and check results. Reviewers are bound by confidentiality, receive time-limited access and their activity is audited.

11. Transfers outside the EEA

We primarily seek EEA processing. Where a supplier processes data outside the EEA, we use appropriate GDPR safeguards, including adequacy decisions or Standard Contractual Clauses and, where needed, supplementary measures.

12. Cookies and similar technologies

The website and platform may use technical cookies and local storage required for sign-in, security, language preferences and form operation.

Analytics, marketing or other optional technologies will be used only with appropriate consent where required. Details will appear in a separate Cookie Policy.

Forms may use an ALTCHA proof-of-work challenge. Where operated on Progity infrastructure without tracking technologies, it is not used for advertising or profiling.

13. Service and marketing communications

Service messages may concern registration, verification, orders, payments, invoices, credits, plan changes, security, incidents, maintenance, support, legal changes, termination and export. These cannot generally be unsubscribed from.

Marketing messages are sent with consent or within rules for similar services to existing customers and always include a free unsubscribe method.

14. Automated decision-making

We do not make solely automated decisions producing legal or similarly significant effects. Automated checks, risk scores, AI review, fraud detection or security signals may require verification or temporarily block risky operations, but significant decisions can be reviewed by a person.

15. Your rights

Subject to GDPR, you have rights of access, rectification, erasure, restriction, portability, objection and consent withdrawal.

Send requests to hello@shipvise.com. We may verify identity. We respond without undue delay, generally within one month; complex cases may be extended by two further months.

Where a Shipvise customer is the controller, contact that customer first. Progity will assist under the data processing agreement.

16. Complaints

You may complain to the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz, or another competent EU or EEA authority.

17. Security

We use proportionate technical and organisational measures, including access controls, workload separation, encrypted communications, audit logs, backups, least privilege, maintenance and incident response. No system is absolutely secure.

18. Children

Shipvise is not intended for people who cannot independently enter into a paid digital-service contract under their local law. We do not knowingly target children for marketing.

19. Changes

We may update this Policy when the service, suppliers, features or legal requirements change. The current version and dates are always published here. Significant changes may also be notified in the account or by email. The Czech version prevails.