1. Controller and contact
The controller is David Hošek, trading as Progity, company registration number 03956890, registered address U Potoka 247, 440 01 Peruc, Czech Republic, registered in the Czech Trade Register. Privacy contact: hello@shipvise.com. This Policy provides information under Articles 13 and 14 GDPR.
2. Scope
This Policy applies to website visitors, pilot applicants, consumers, business customers, account users, workspace members, customer contacts, people ordering AI or senior review, suppliers and other people who communicate with us.
-
Public website, contact forms and pilot forms.
-
Registration, sign-in, account, workspace, role and permission management.
-
Application hosting, builds, deployments, logs, monitoring, reviews and support.
-
Orders, subscriptions, credits, payments, invoicing, withdrawals, cancellations and refunds.
-
Security, audit, fraud and abuse prevention and sanctions screening.
3. Progity’s roles
Progity acts as controller for data processed to operate the website and service, administer accounts, perform contracts, invoice customers, provide support, maintain security, communicate, meet its own legal obligations and develop Shipvise.
Where a customer processes personal data of third parties through Shipvise and determines the purposes and means, the customer is the controller and Progity is the processor. That processing is governed by a separate Article 28 GDPR data processing agreement.
For AI or senior review, source code, diffs, configuration, logs or other project content may be accessed only to the extent necessary for the ordered review.
4. Data we process
-
Identity and contact data, including name, email address, phone number, address, country, company, registration number, VAT ID and job title.
-
Account, workspace, membership, role, permission, authentication method, settings and legal acceptance records.
-
Order, contract, plan, credit, invoicing and payment data. We do not store full payment card details.
-
Project, revision, release and environment data, build and runtime logs, domain names, repository metadata, review requests, check results and audit trail records.
-
Source code, uploaded archives, configuration files and other customer content, which may include personal data submitted by the customer.
-
Contact and pilot enquiries, support communications, complaints, withdrawal requests, security reports and consent records.
-
IP address, timestamps, session identifiers, device, operating system, browser, URL, referrer, audit, application and security logs.
-
Data needed to determine customer location and tax treatment, such as billing country, state or province, payment-method country and proportionate IP geolocation.
-
Data from public registers and checks, including ARES, VIES, company registers, sanctions lists and payment or fraud-risk checks.
5. Purposes, legal bases and retention
Contact and pilot enquiries
Právní základ:
Steps before a contract, contract performance or legitimate interest in handling communications; consent only where specifically requested.
Doba uchování:
During the discussion and generally for 3 years after the last relevant communication.
Registration, authentication, account and workspace administration and service delivery
Právní základ:
Contract performance and pre-contract steps; legitimate interest for users invited by organisations.
Doba uchování:
For the account or contract and generally 3 years afterwards.
Builds, staging, production hosting, monitoring, logs, backups, rollback and support
Právní základ:
Contract performance; legitimate interest for security logging.
Doba uchování:
For the service duration; operational data generally 30 days to 24 months depending on type and plan.
AI review, senior review, re-verification and paid fixes
Právní základ:
Contract or order performance; legitimate interest in documenting scope and result.
Doba uchování:
For the service and generally 3 years after completion; technical artefacts may be shorter-lived.
Orders, subscriptions, credits, payments, refunds, invoicing and accounting
Právní základ:
Contract performance and legal obligations.
Doba uchování:
Accounting and tax records generally 10 years; other contract and payment metadata generally 4 years.
Customer and tax status, VAT ID validation, customer-location records and VAT, OSS, GST or sales-tax obligations
Právní základ:
Legal obligations and legitimate interest in correct billing and fraud prevention.
Doba uchování:
For statutory periods; some tax-scheme records may be kept up to 10 years.
Security, audit, abuse prevention, fraud checks, sanctions screening and incident handling
Právní základ:
Legitimate interest in safe and lawful operation; sometimes legal obligation.
Doba uchování:
Generally 6 to 24 months, longer for incidents or legal claims.
Commercial communications and Shipvise information
Právní základ:
Consent or applicable rules for similar services to existing customers.
Doba uchování:
Until withdrawal, unsubscribe or objection.
Evidence of consents, orders, contractual acts, complaints and legal claims
Právní základ:
Legal obligation and legitimate interest in protecting rights.
Doba uchování:
For the relationship and relevant statutory or limitation periods.
Specific data may be retained longer where required for a legal claim, security incident or legal obligation. It is then deleted or anonymised, subject to backup cycles.
6. Sources
We obtain data directly from you, from a customer or workspace administrator who invites you, from service use, connected repositories and integrations, business communications, payment and security providers and public registers such as ARES, VIES, company and sanctions registers.
7. Required data
Required data is needed to create an account, enter into or perform a contract, determine location and tax treatment, issue invoices or maintain security. Without it, we may be unable to provide the service.
8. Recipients and processors
Data may be disclosed to hosting, infrastructure, DNS, registry, storage, backup, email, communications, payment, accounting, monitoring, security, fraud-prevention, support, development and AI providers, as well as senior reviewers, legal, accounting and tax advisers and public authorities.
Access is limited to what is necessary. A current subprocessor list or categories will be published separately or provided on request.
9. AI review and model providers
When AI review is ordered, Shipvise may send relevant portions of diffs, source code, configuration, check results and instructions to a selected model provider. Only context needed for the specific review is sent.
-
AI review is optional; ordinary hosting does not automatically send the entire project to a model provider.
-
Customer content must not be used to train public models without the customer’s separate explicit consent.
-
We seek to exclude secrets and unnecessary data, but customers must not place real credentials or unnecessary personal data in source code.
-
Available providers, processing regions and restriction options will be stated in the product or subprocessor list.
10. Senior review
An authorised engineer may access the agreed scope of source code, diffs, logs and check results. Reviewers are bound by confidentiality, receive time-limited access and their activity is audited.
11. Transfers outside the EEA
We primarily seek EEA processing. Where a supplier processes data outside the EEA, we use appropriate GDPR safeguards, including adequacy decisions or Standard Contractual Clauses and, where needed, supplementary measures.
12. Cookies and similar technologies
The website and platform may use technical cookies and local storage required for sign-in, security, language preferences and form operation.
Analytics, marketing or other optional technologies will be used only with appropriate consent where required. Details will appear in a separate Cookie Policy.
Forms may use an ALTCHA proof-of-work challenge. Where operated on Progity infrastructure without tracking technologies, it is not used for advertising or profiling.
13. Service and marketing communications
Service messages may concern registration, verification, orders, payments, invoices, credits, plan changes, security, incidents, maintenance, support, legal changes, termination and export. These cannot generally be unsubscribed from.
Marketing messages are sent with consent or within rules for similar services to existing customers and always include a free unsubscribe method.
14. Automated decision-making
We do not make solely automated decisions producing legal or similarly significant effects. Automated checks, risk scores, AI review, fraud detection or security signals may require verification or temporarily block risky operations, but significant decisions can be reviewed by a person.
15. Your rights
Subject to GDPR, you have rights of access, rectification, erasure, restriction, portability, objection and consent withdrawal.
Send requests to hello@shipvise.com. We may verify identity. We respond without undue delay, generally within one month; complex cases may be extended by two further months.
Where a Shipvise customer is the controller, contact that customer first. Progity will assist under the data processing agreement.
16. Complaints
You may complain to the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz, or another competent EU or EEA authority.
17. Security
We use proportionate technical and organisational measures, including access controls, workload separation, encrypted communications, audit logs, backups, least privilege, maintenance and incident response. No system is absolutely secure.
18. Children
Shipvise is not intended for people who cannot independently enter into a paid digital-service contract under their local law. We do not knowingly target children for marketing.
19. Changes
We may update this Policy when the service, suppliers, features or legal requirements change. The current version and dates are always published here. Significant changes may also be notified in the account or by email. The Czech version prevails.