Effective and last updated July 21, 2026

Privacy Policy

1. Controller

Jitoma Solutions s.r.o.
IČO: 19728492
Registered office: Vikingská 1248/2, Hodolany, 779 00 Olomouc, Czech Republic
Registered in the Commercial Register maintained by the Regional Court in Ostrava, file C 93705
Data box: 4s297zc
Email: 9hly2ztp1@mozmail.com

Jitoma Solutions s.r.o. is controller for the processing described here. This notice covers Legal Policy Generator, not customer-authored public policies or customer products.

2. Information processed

Questionnaire drafts contain operator identity, product, URL, contact, platform, data-practice, provider, audience, transfer, rights, regional, and AI answers. Completed snapshots, generated document structure, clause versions, rendered HTML, PDF failure records, publication settings, versions, and public UUID links are stored to provide generation and hosting.

Account data includes normalized email, sessions, magic-link state, saved profiles and products, owned policies, subscription state, exports, and deletion requests. Guest purchase data includes verified billing email, draft association, short-lived claim state, and entitlement. Contact submissions contain name, email address, selected topic, and message. A random arithmetic challenge and expected answer are held in application memory for up to 10 minutes and removed on use. Server logs contain request time, request ID, route, status, network and user-agent security data, and failures; questionnaire bodies, contact messages, session secrets, magic tokens, Stripe signatures, and card details are not logged. With consent, Google Analytics receives page and interaction events, approximate location, browser and device details, referrer information, and pseudonymous identifiers.

3. Payments

Stripe processes Checkout, billing portal, payment-card, fraud, tax when enabled, refund, dispute, and subscription information under its own privacy terms. Legal Policy Generator stores Stripe customer, Checkout Session, Payment Intent, Coupon, subscription and event identifiers; billing email; amount; currency; price tier; discount-code hash and masked hint; discount percentage; payment or subscription status; refund or dispute effects; and webhook processing state. Full discount codes are shown to administrators once and are not stored. Jitoma Solutions s.r.o. does not receive or store full card details.

4. Purposes and legal bases

Information is processed to provide requested previews, purchases, generation, hosting, downloads, versions, accounts, authentication, support, billing, security, abuse prevention, error investigation, legal claims, tax or accounting duties, and consent-based service measurement and improvement. Depending on context, bases are performance of a contract or pre-contract request, legitimate interests in secure and reliable operation and claim protection, legal obligation, and consent where specifically requested.

5. Public hosted policies

A published customer policy is intentionally public without authentication and can expose the operator, product, contact, service-practice, and regional information supplied for that document. Customer pages default to noindex, follow and are excluded from the sitemap, but noindex cannot guarantee absence from every index, cache, archive, or third-party link. Owners can unpublish or revoke the UUID and may explicitly enable indexing after a warning.

6. Cookies and communication

Essential cookies bind guest drafts, sessions, and CSRF protection. Stripe may set essential Checkout or fraud-prevention cookies on its domain when a user enters Checkout. Google Analytics loads only after analytics consent and may set first-party analytics cookies. Analytics consent can be rejected or changed through Privacy choices in the footer. Legal Policy Generator does not implement behavioral advertising or marketing cookies. Magic links, transactional account or purchase messages, and contact-form delivery use Brevo's transactional email API. The service does not send marketing messages.

7. Recipients and transfers

Information is disclosed to infrastructure providers selected for application hosting and backups, Brevo for transactional email delivery, Google Gmail for receiving contact correspondence, Stripe for payments, and Google for consent-based analytics. It may also be disclosed to professional advisers, courts, authorities, security responders, or a business successor where legally justified. Deployment providers are configured by Jitoma Solutions s.r.o.; current details can be requested at the contact address.

These providers may process information outside the Czech Republic, EEA, or United Kingdom. Where GDPR transfer restrictions apply, Jitoma Solutions s.r.o. uses an adequacy decision, approved contractual clauses, or another lawful mechanism appropriate to the provider and transfer. A copy or description of relevant safeguards may be requested subject to lawful redactions.

8. Retention

Incomplete guest drafts expire after 30 days. Magic links expire after 20 minutes and used state is retained for security investigation for up to 90 days. Sessions expire after 30 days. Contact messages are not stored in the application database; Brevo transmits them to the operator's Gmail mailbox, where they are kept only as needed for the inquiry, security, disputes, or applicable legal duties. Completed policies and versions remain until owner deletion or account deletion, subject to purchased-output delivery, disputes, and legal retention. Payment, invoice, refund, dispute, webhook, tax, and accounting records may be retained for the period required by Czech and EU law, commonly up to 10 years. Security and request logs are normally retained up to 90 days unless needed longer for an incident or claim. Google Analytics data follows the retention and deletion settings configured for the Analytics property. Backups age out on the infrastructure backup cycle.

9. Security

Measures include encrypted transport, restricted administration, hashed session and magic-link tokens, short expiry, replay prevention, rotating sessions, CSRF controls, one-use contact challenges, rate limits, body limits, secure cookies, security headers, prepared database operations, webhook signatures, audit records, and backups. No system is completely secure and absolute security cannot be guaranteed.

10. Rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent for future processing; and complain to the Czech Office for Personal Data Protection or another competent supervisory authority. Jitoma Solutions s.r.o. may verify identity and apply legal exceptions. Account controls support export and deletion; deletion unpublishes owned customer policies by default and revokes active sessions.

11. Changes and contact

Material changes will be posted with a revised date and additional notice where required. Privacy requests and questions may be sent through the contact form or to:

Jitoma Solutions s.r.o.
IČO: 19728492
Registered office: Vikingská 1248/2, Hodolany, 779 00 Olomouc, Czech Republic
Registered in the Commercial Register maintained by the Regional Court in Ostrava, file C 93705
Data box: 4s297zc
Email: 9hly2ztp1@mozmail.com