Privacy Policy

Last updated:

Effective date: 4 August 2026 (replaces the version of 18 April 2025)

This is an English translation of the Czech privacy policy, provided for convenience. In the event of a discrepancy, the Czech version prevails.

Summary

  • Who we are: SmartStaff.io is operated by Prokop Simek, who is the controller of your personal data.
  • What we collect: registration data, the content you entrust to the service (briefs, uploaded documents, outputs), and pseudonymous usage data.
  • Where the data lives: accounts, projects, documents and outputs are stored in the European Union. The generation of responses itself goes through Google's Gemini API, which does not guarantee a processing region — we are open about that below.
  • AI and training: we use the paid tier of the Gemini API. Google commits in its terms not to use your prompts or responses to improve its products.
  • Cookies: an anonymous visit leaves no analytics identifier on your device. We store one only for signed-in users.
  • Your rights: access, rectification, erasure, portability and the other GDPR rights. You can delete your account and organization yourself, directly in the app.

This is a summary; the full details follow.

1. Controller

This policy describes how the SmartStaff.io service collects, uses and protects your personal data.

Controller: Prokop Simek E-mail: support@smartstaff.io Web: https://smartstaff.io

The controller is responsible for processing your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable law. This policy forms an integral part of the Terms of Service.

2. Definitions

  • Personal data: any information about an identified or identifiable natural person.
  • Processing: any operation with personal data — collection, storage, use, disclosure, erasure and more.
  • Controller: the entity that determines the purposes and means of processing.
  • Processor: an entity that processes personal data on the controller's behalf.
  • Virtual employee: an AI agent provided within the service that carries out tasks on your instructions.
  • Run: one processing of your brief by a team of virtual employees, from plan to result.

3. What data we process

3.1 Data you provide

  • Registration data: name, email address and password (we store only its hash, never the password itself), or the data from signing in with Google.
  • Content: briefs and instructions for virtual employees, documents uploaded to a knowledge base, project attachments, and emails sent to a project's trigger address.
  • Connected-app data: if you connect third-party apps (Gmail, calendar, GitHub and others), we hold the access tokens the virtual employees need to act on your behalf in them.
  • Communication: messages you send us via the contact form or by email.
  • Billing data: when paying for a subscription. Card details are processed exclusively by Stripe and never reach us.

3.2 Data generated by using the service

  • Usage data: in-app events (creating a project, starting a run, and so on) under a pseudonymous identifier.
  • Technical data: browser and device type, error reports.
  • Run records: the timeline of every run (the plan, its approval, individual steps, the result), so that what happened and when can be shown.

4.1 Providing the service

  • Purpose: operating your account, processing your briefs with virtual employees, storing results, connecting the apps you enable.
  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

4.2 Improving the service

  • Purpose: analysing how the app is used, finding faults, developing features.
  • Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in a working, improving service.
  • Scope: pseudonymous events and error reports; not the content of your briefs.

4.3 Commercial communication

  • Purpose: sending news about the service.
  • Legal basis: consent (Art. 6(1)(a) GDPR) when you subscribe; for existing customers, legitimate interest in informing them about similar services. You can unsubscribe at any time.
  • Purpose: accounting, tax, responding to lawful requests by public authorities.
  • Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).

4.5 Protecting rights and security

  • Purpose: preventing abuse of the service, enforcing the terms, handling security incidents.
  • Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

5. Artificial intelligence

5.1 Which models we use

Virtual employees' outputs are generated by Google's Gemini models. Processing your brief shares with Google the content of the brief, relevant excerpts from uploaded documents, and the conversation history of the project.

5.2 Training on your data

We use the paid tier of the Gemini API. In its paid-services terms Google commits that your prompts and generated responses are not used to improve its products; it may retain them briefly solely to detect abuse and to meet legal obligations. We last verified the wording of those terms on 4 August 2026.

5.3 Processing region

We say this plainly: data storage is in the EU, but the generation of responses goes through the Gemini API's global endpoint, which does not guarantee in which region a prompt is processed. On request we can pin a deployment to an EU Vertex AI region — if that is a requirement for you, write to us.

5.4 Automated decision-making

The service makes no decisions with legal or similarly significant effects based solely on automated processing. Run plans are approved by a person; automation may only stop a run and hand it over for review.

6. Processors and data location

Hetzner Online GmbH

  • Purpose: hosting of the application, the database and object storage (uploaded documents, outputs)
  • Data: everything the service stores
  • Location: Germany / Finland (EU)

Google (Gemini API)

  • Purpose: generating virtual employees' outputs
  • Data: brief content, document excerpts, conversation history
  • Location: global endpoint (see 5.3)

Stripe

  • Purpose: subscription payments
  • Data: billing contact and payment metadata; card details are processed by Stripe alone

Resend

  • Purpose: sending transactional email and receiving project trigger emails
  • Data: email address, name, message content

PostHog

  • Purpose: product analytics and error tracking
  • Data: pseudonymous identifier, in-app events, error reports; session recording is off
  • Location: European Union

AuthLane

  • Purpose: managing OAuth access to the apps you connect
  • Data: user identifier and access tokens of connected accounts

Firecrawl

  • Purpose: reading public web pages when you ask a virtual employee to
  • Data: URLs and the content of fetched pages

7. Cookies and analytics

7.1 Anonymous visits

An anonymous visit stores no analytics identifier on your device — analytics run only in the browser's memory and end when the page closes. That is why there is no cookie banner on the site: there is nothing to consent to.

7.2 Signed-in users

After signing in we store:

  • A session cookie — keeps you signed in; the app cannot work without it.
  • A language preference (NEXT_LOCALE) — remembers your chosen language.
  • An analytics identifier — links in-app events to your account so we can see what works and what does not. Screen recording is off; the content of your briefs is never sent to analytics.

We use no third-party advertising or tracking cookies.

8. Retention

  • Account, projects, documents and outputs: for as long as the account or organization exists. Deleting the account or organization in the app removes the associated data with it.
  • Billing records: for the period required by tax and accounting law (typically 10 years).
  • Analytics events: pseudonymous; you can ask for their erasure together with the erasure of your account.
  • Support communication: while a request is being handled and for a reasonable period afterwards for continuity.

9. Transfers outside the EU

The service's stored data stays in the EU. Data may be processed outside the EU by these providers: Google (output generation, see 5.3), Stripe (payments) and, depending on configuration, Resend and Firecrawl. Such transfers rely on a European Commission adequacy decision (for example the EU–US Data Privacy Framework) or on standard contractual clauses under Art. 46 GDPR. You can request a copy of the relevant safeguards at support@smartstaff.io.

10. Your rights

Under the GDPR you have the right to:

  • access the personal data we process about you (Art. 15),
  • rectification of inaccurate data (Art. 16),
  • erasure (Art. 17) — you can delete your account and organization yourself in the app's settings,
  • restriction of processing (Art. 18),
  • portability of the data you provided to us (Art. 20),
  • object to processing based on legitimate interest (Art. 21),
  • withdraw consent where processing is based on consent, with effect for the future,
  • lodge a complaint with a supervisory authority — in the Czech Republic the Office for Personal Data Protection (uoou.gov.cz).

We handle requests at support@smartstaff.io without undue delay, within one month at the latest.

11. Security

  • All communication with the service is encrypted (TLS).
  • Passwords are stored only as cryptographic hashes.
  • Access to production data is limited to the controller, and only to the extent needed to operate the service.
  • Access tokens of connected apps are stored encrypted.
  • A breach posing a high risk to your rights will be notified to you without undue delay, as the GDPR requires.

12. Changes to this policy

We may update this policy when the service or legal requirements change. Material changes are announced by email or in the app; the date of the last change is always shown at the top.

13. Contact

E-mail: support@smartstaff.io Web: https://smartstaff.io