Skip to content
Shipvise
  • Product
  • How it works
  • Reviews
    • AI review Automated review of AI-generated code changes: structured findings, severity, risk score and recommendations before production.
    • Senior review A senior engineer reviews one release within an agreed scope and returns an approval, requested changes or a recommendation.
  • Security
  • Pricing
  • Sign in
  • Try Shipvise
EN
  • Čeština
  • English
Sign in Try Shipvise

Shipvise Privacy Policy

Version: 1.0
Effective: upon publication of this version
Last updated: 21 August 2026
Stable URL: https://shipvise.com/en/privacy/

Translation notice: This English version is a machine-assisted translation provided for convenience. The original Czech version is the authoritative version. Where mandatory law requires otherwise, rights granted by mandatory law remain unaffected.

This policy explains how personal data is processed when using the Shipvise website and Service in cases where the Provider identified below determines the purposes and means of processing as a controller.

1. Controller

The controller is:

David Hošek
Company ID (IČO): 03956890
VAT ID (DIČ): CZ9503230539
Registered office: U Potoka 247, 440 01 Peruc – Telce, Czech Republic
Registered in the Czech Trade Register since 2 April 2015
Brand: Shipvise by Progity
Phone: +420 602 352 762

Personal-data contact: privacy@shipvise.com.

David Hošek is hereinafter referred to as the "Provider" and operates the Shipvise service (the "Service").

2. When the Provider is a controller and when a processor

The Provider is a controller in particular for its own operational purposes: registration and authentication, Workspaces and membership, contracts and orders, billing and invoicing, support, security, abuse/fraud prevention, legal obligations, first-party web analytics and marketing communications.

Where the Customer uses the hosting features of the Service to process the personal data of third parties and the Customer determines the purpose and means of that processing, the Customer is typically the controller and the Provider the processor. Such processing is governed by a separate DPA accepted in the Portal when the first Project is created. This policy does not replace the DPA.

3. Whose data is concerned

Depending on how the Service is used, this may involve in particular:

  • website visitors;
  • persons interested in Shipvise and pilot/business contacts;
  • registered users;
  • Workspace owners and members;
  • entrepreneurs, Consumers and Customer contact persons;
  • persons ordering or using human services;
  • persons submitting abuse/illegal-content reports;
  • suppliers and other persons who communicate with us.

Data of end users of Customer applications that Shipvise merely hosts on the Customer's instruction is primarily governed by the DPA and by that Customer's privacy documentation.

4. What data we process

4.1 Account and contractual relationship

We process in particular first name, surname, e-mail, login metadata, Workspace and membership, roles and permissions, country, B2B/B2C status, company name, Company ID or an equivalent identifier, VAT ID and billing details where required.

4.2 Legal and contractual records

We retain in particular the versions and times of acceptance of the Terms, the DPA and relevant checkout declarations, and data on orders, subscriptions, cancellations, complaints, withdrawal, deletion and export.

4.3 Payments and invoicing

We process payment status, transaction identifiers, amounts, currency, date, the payment method used and the data required for an accounting or tax document. Payment cards are processed by an external payment service provider according to the specific flow; the Provider does not store the full payment card number or the card security code.

4.4 Technical and security data

This may include IP address, time, URL, user-agent, session and security metadata, login events, audit events, technical errors, correlation IDs and the data needed for abuse prevention, account protection or incident response.

4.5 Project metadata

For the operation of the platform itself, the Provider may process the names of Projects and Applications, metadata of repositories, builds, releases, deployments and environments, plan and resource metadata, and technical logs.

Where such data contains personal data of a Customer's end user and the Provider processes it solely on the Customer's behalf, the processor role under the DPA applies to it.

4.6 Communications and support

We process the content of contact forms, e-mails, support communications, requests for Starter Creation, Senior Review or Assisted Fix, complaints, and the related metadata.

4.7 Abuse reports

For abuse/DSA reports we may process the reporter's name and e-mail, the description, the URL concerned, the category, evidence, the good-faith declaration, IP address, time, user-agent and technical anti-abuse data. Under the conditions of the form, a general abuse report may also be submitted without contact details; a formal DSA notice normally requires the details prescribed by the DSA, subject to the applicable statutory exceptions.

4.8 Newsletter

If a user actively selects "I want to be informed about Shipvise news" or an equivalent option, we process their e-mail address and a record of consent. Consent is not a condition of using the main service.

5. Purposes and legal bases

Providing the account and the Service

Purpose: registration, login, Workspace, Project, providing the ordered features and communication relating to the contract.
Legal basis: performance of a contract or steps prior to entering into it; for Workspace members invited by the Customer, also the legitimate interest of the Customer and the Provider in administering the contractual relationship.

Billing, accounting and tax obligations

Purpose: payments, documents, transaction records, tax treatment and compliance with statutory obligations.
Legal basis: performance of a contract and legal obligation.

Security and abuse prevention

Purpose: protecting accounts, infrastructure and third parties, detecting incidents, fraud/abuse protection and dispute resolution.
Legal basis: legitimate interest; in specific cases legal obligation.

Support and human services

Purpose: handling the request, Senior Review, Starter Creation, Assisted Fix and the related communication.
Legal basis: performance of a contract or steps prior to entering into it.

First-party web analytics

Purpose: basic measurement of website usage and its improvement.
Legal basis: legitimate interest for necessary server-side technical records; consent for a persistent analytics identifier/cookie where the legal regime requires it.

Newsletter

Purpose: news, product information and Shipvise marketing.
Legal basis: consent, or alternatively — only within the statutory scope — the rule on own similar services to existing customers. The user may refuse marketing at any time.

Legal claims

Purpose: evidencing a contract, a legal act, a complaint or an abuse decision, or defending a legal claim.
Legal basis: legitimate interest and, where applicable, legal obligation.

6. Retention periods

The Provider applies different retention periods depending on the purpose:

Category Standard regime
Active account and basic profile for the duration of the account/contractual relationship
Inactive ordinary profile deletion or anonymisation no later than 12 months after the relationship ends, unless there is another legal ground
Managed source and Project data for the duration of the Project and the subsequent 30-day retrieval period
Primary Project data after retrieval deleted after the retrieval period ends
Technical backup copies of deleted data expire in the ordinary rotation cycle within a further 7 days at the latest
Build and runtime logs 14 days as a standard
Abuse IP and technical anti-abuse metadata 90 days as a standard
Newsletter consent until withdrawal/unsubscribe, and thereafter the necessary record of the unsubscribe
Accounting, tax and legally required records for the period required by the applicable law
Records of contractual acts and legal claims for the period necessary to evidence them and protect rights

In the event of a security incident, dispute, legal claim or statutory obligation, a specific record may be retained longer than the ordinary regime set out above. It is then deleted or anonymised.

7. Backups

The Provider performs operational backups of selected systems and Customer data. The standard backup rotation period is 7 days.

Backups are intended for restoring the service after an incident, not as a long-term Customer archive. Data deleted from active systems may remain for a limited time in a backup already created and expires within its rotation cycle.

The standard service does not provide a contractual guarantee of a specific RPO/RTO unless an individual contract expressly provides otherwise.

8. Recipients and providers

Personal data may be made available, to the extent necessary, in particular to:

  • WEDOS Internet, a.s. as the infrastructure/DNS provider and, to the relevant extent, as a subprocessor of hosted data;
  • ComGate Payments, a.s. in connection with payment, as an external payment service provider and recipient of data, which may act as an independent controller for its own regulatory processing;
  • PayPal in connection with the alternative payment flow, as an external payment service provider and recipient of data; PayPal acts as an independent controller for payment services;
  • the external Git provider chosen by the Customer, where the Customer connects it themselves;
  • legal, accounting or tax advisers, where necessary;
  • public authorities, where required by law;
  • the assigned senior developer within an ordered Senior Review or Assisted Fix, only to the extent necessary and purpose-limited and subject to confidentiality obligations. Depending on the nature of the Review, that scope may include the changes, the relevant parts of the source, the related logs and the configuration, and, where necessary for the context of the Review, also the entire relevant repository.

The availability of Comgate, PayPal and of a specific payment method depends on the country, currency, transaction type and the current checkout configuration.

The current public overview is available at /en/legal/subprocessors/.

9. External generative AI

For the MVP, no external generative AI provider is approved as a subprocessor of Customer source code, Customer secrets or hosted personal data.

Ordinary hosting and Senior Review therefore do not automatically send Customer source or hosted data to external generative AI services.

An external AI tool may be used internally only on synthetic, generalised or anonymised context that contains no Customer source, secrets, personal data or confidential information. For work with such Customer content, the MVP relies on the Provider's own expert work and, where applicable, local/self-hosted models.

Before this regime is changed in the future, a vendor/privacy review will be carried out and the DPA and the subprocessor list will be updated as necessary.

10. Transfers outside the EEA

The Service is designed primarily for the EU/EEA. Should a specific recipient process personal data outside the EEA, the Provider will, before such processing begins, put in place an appropriate legal mechanism under Chapter V of the GDPR, for example an adequacy decision or standard contractual clauses with the necessary supplementary measures.

An external provider chosen independently by the Customer may have its own international transfer regime; the Customer is responsible for selecting it within their own integration.

11. Cookies and web analytics

The marketing website uses necessary technical mechanisms and first-party analytics. The persistent analytics identifier pg_visitor_id is used only after the relevant consent. The pg_cookie_consent cookie stores the user's choice.

The app.shipvise.com Portal uses only necessary technical cookies, in particular:

  • NEXT_LOCALE — language setting;
  • SHIPVISE_SESSION — the logged-in session;
  • XSRF-TOKEN — CSRF protection.

Details are available at /en/cookies/.

12. ALTCHA

Forms may use the self-hosted ALTCHA protection against automated abuse. It serves to secure the form and is not used for advertising profiling.

13. Service and marketing communications

Service e-mails may relate to registration, login, security, orders, payments, billing, export, termination, incidents and changes to contractual documents. These messages are part of providing the service and cannot be switched off across the board where sending them is necessary.

The newsletter and other marketing communications are kept separate. The user may switch them off at any time using the link in the e-mail or in their profile, where that option is available in the Portal.

14. Automated decision-making

The Provider does not use purely automated decision-making with legal or similarly significant effects on the user without the possibility of appropriate human review where such review is legally or factually required.

Automated security/risk mechanisms may pre-emptively suspend a risky operation. A significant follow-up decision may, depending on the circumstances, be reviewed by a human.

15. Data-subject rights

Subject to the conditions of the GDPR, you may in particular have the right to:

  • obtain access to personal data;
  • request rectification;
  • request erasure;
  • restrict processing;
  • obtain data in a portable form;
  • object to processing based on legitimate interest;
  • withdraw consent at any time with effect for the future;
  • lodge a complaint with the competent supervisory authority.

Send your request to privacy@shipvise.com. The Provider may reasonably verify the identity of the applicant.

If the request concerns personal data hosted on behalf of a Customer for which that Customer is the controller, please contact that Customer in the first place. The Provider will assist them in accordance with the DPA.

16. Supervisory authority

In the Czech Republic, the supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, https://uoou.gov.cz/.

This is without prejudice to the right to contact another competent supervisory authority in the EU/EEA.

17. Security

The Provider applies to the Service appropriate technical and organisational measures corresponding to the current architecture and risk. A conservative public overview is available at /en/legal/security/.

The Provider does not claim that no system can be compromised, nor does it provide security certifications, guarantees or features that are not expressly stated and actually deployed.

18. Children

Only a person over 18 years of age may enter into a contract with the Provider. The Service is not intended for the registration of minors as Customers.

19. Changes to this policy

We may update this policy in particular when the product, the processing, the providers or legal obligations change. The current version and date are always stated at the top.

Material changes may be announced in the Portal or by e-mail.

The Czech wording is canonical; translations may be machine-produced and are informative to the extent permitted by law.

Shipvise

The independent control layer from AI-built software to running production.

Provided by David Hošek under the Shipvise by Progity brand in the EU.

+420 602 352 762 · hello@shipvise.com

Product

  • Product
  • How it works
  • AI review
  • Senior review
  • Pricing
  • Pilot

Resources

  • Security
  • Docs
  • Status (opens in a new tab)

Operator

  • About
  • Contact
  • Progity (opens in a new tab)
  • LinkedIn (opens in a new tab)
  • Facebook (opens in a new tab)
  • Cookie settings

Legal

  • Privacy
  • Cookies
  • Terms
  • Acceptable use
  • Billing and credits
  • Consumer withdrawal
  • Subprocessors
  • Service security
  • Export and portability
  • Report abuse
  • Legal contacts

●Public beta Shipvise is in public beta. Feature availability and limits can change.

EN
  • Čeština
  • English
© 2026 Progity. All rights reserved.
○Coming soon

Public beta activation

Shipvise is in public beta. New projects and capacity increases may be activated manually while we confirm the right release workflow, review options and environment mode for each project.

Choose a plan, tell us about your first project and we will confirm availability and price before activation.

Request beta activation Close