Effective July 19, 2026; last updated August 4, 2026
Privacy Policy
1. Controller
Jitoma Solutions s.r.o.
IČO: 19728492
Registered office: Vikingská 1248/2, Hodolany, 779 00 Olomouc, Czech Republic
Registered in the Commercial Register maintained by the Regional Court in Ostrava, file C 93705
Data box: 4s297zc
Email: 9hly2ztp1@mozmail.com
Jitoma Solutions s.r.o. is controller for the processing described here. This notice covers Legal Policy Generator, not customer-authored public policies or customer products.
2. Information processed
Questionnaire drafts contain operator identity, product, URL, contact, platform, data-practice, provider, audience, transfer, rights, regional, and AI answers. Completed snapshots, generated document structure, clause versions, rendered HTML, PDF failure records, publication settings, versions, and public UUID links are stored to provide generation and hosting.
Account data includes normalized email, sessions, magic-link state, hashed browser and MCP one-time-code challenges, failed-attempt counts, OAuth client registration metadata, authorization requests and single-use codes, hashed access and refresh tokens, token expiry and last-use times, saved profiles and products, owned policies, subscription state, exports, and deletion requests. Guest purchase data includes verified billing email, draft association, short-lived claim state, and entitlement. Contact submissions contain name, email address, selected topic, and message. A random arithmetic challenge and expected answer are held in application memory for up to 10 minutes and removed on use. Server logs contain request time, request ID, route, status, network and user-agent security data, and failures; questionnaire bodies, contact messages, session secrets, magic tokens, Stripe signatures, and card details are not logged. With consent, Google Analytics receives page and interaction events, approximate location, browser and device details, referrer information, and pseudonymous identifiers.
3. Payments
Stripe processes Checkout, billing portal, payment-card, fraud, tax when enabled, refund, dispute, and subscription information under its own privacy terms. Legal Policy Generator stores Stripe customer, Checkout Session, Payment Intent, Coupon, subscription and event identifiers; billing email; amount; currency; price tier; discount-code hash and masked hint; discount percentage; payment or subscription status; refund or dispute effects; and webhook processing state. Full discount codes are shown to administrators once and are not stored. Jitoma Solutions s.r.o. does not receive or store full card details.
4. Purposes and legal bases
Information is processed to provide requested previews, purchases, generation, hosting, downloads, versions, accounts, authentication, support, billing, security, abuse prevention, error investigation, legal claims, tax or accounting duties, and consent-based service measurement and improvement. Depending on context, bases are performance of a contract or pre-contract request, legitimate interests in secure and reliable operation and claim protection, legal obligation, and consent where specifically requested.
5. Public hosted policies
A published customer policy is intentionally public without authentication and can expose the operator, product, contact, service-practice, and regional information supplied for that document. Customer pages default to noindex, follow and are excluded from the sitemap, but noindex cannot guarantee absence from every index, cache, archive, or third-party link. Owners can unpublish or revoke the UUID and may explicitly enable indexing after a warning.
6. Cookies and communication
Essential cookies bind guest drafts, sessions, and CSRF protection. Stripe may set essential Checkout or fraud-prevention cookies on its domain when a user enters Checkout. Google Analytics loads only on eligible pages after analytics consent and never loads on OAuth authorization pages. It may set first-party analytics cookies. Analytics consent can be rejected or changed through Privacy choices in the footer. Legal Policy Generator does not implement behavioral advertising or marketing cookies. Magic links, transactional account or purchase messages, and contact-form delivery use Brevo's transactional email API. The service does not send marketing messages.
7. Recipients and transfers
Information is disclosed to infrastructure providers selected for application hosting and backups, Brevo for transactional email delivery, Google Gmail for receiving contact correspondence, Stripe for payments, and Google for consent-based analytics. It may also be disclosed to professional advisers, courts, authorities, security responders, or a business successor where legally justified. Deployment providers are configured by Jitoma Solutions s.r.o.; current details can be requested at the contact address.
These providers may process information outside the Czech Republic, EEA, or United Kingdom. Where GDPR transfer restrictions apply, Jitoma Solutions s.r.o. uses an adequacy decision, approved contractual clauses, or another lawful mechanism appropriate to the provider and transfer. A copy or description of relevant safeguards may be requested subject to lawful redactions.
8. Retention
Incomplete guest drafts expire after 30 days. Magic links expire after 20 minutes. Browser sign-in codes expire after 10 minutes, and MCP sign-in codes expire after one hour. Both work once, lock after five failed attempts, and are superseded by a newer code for the same email and purpose. OAuth authorization requests expire after one hour, authorization codes after five minutes, access tokens after one hour, and rotating refresh tokens after 30 days. Inactive OAuth client registrations without active refresh tokens are removed after 90 days. Expired challenge and token state is removed during cleanup. Contact messages are not stored in the application database; Brevo transmits them to the operator's Gmail mailbox, where they are kept only as needed for the inquiry, security, disputes, or applicable legal duties. Completed policies and versions remain until owner deletion or account deletion, subject to purchased-output delivery, disputes, and legal retention. Payment, invoice, refund, dispute, webhook, tax, and accounting records may be retained for the period required by Czech and EU law, commonly up to 10 years. Security and request logs are normally retained up to 90 days unless needed longer for an incident or claim. Google Analytics data follows the retention and deletion settings configured for the Analytics property. Backups age out on the infrastructure backup cycle.
9. Security
Measures include encrypted transport, restricted administration, hashed session, magic-link, one-time-code, OAuth access and refresh tokens, exact OAuth redirect matching, PKCE S256, short expiry, replay prevention, refresh-token rotation, five-attempt code lockout, rotating sessions, CSRF controls, one-use contact challenges, per-address and global rate limits, body limits, secure cookies, security headers, prepared database operations, webhook signatures, audit records, and backups. No system is completely secure and absolute security cannot be guaranteed.
10. Rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent for future processing; and complain to the Czech Office for Personal Data Protection or another competent supervisory authority. Jitoma Solutions s.r.o. may verify identity and apply legal exceptions. Account controls support export and deletion; deletion unpublishes owned customer policies by default and revokes active browser sessions, OAuth refresh and access tokens, magic links, pending authorization codes, and sign-in codes.
11. Changes and contact
Material changes will be posted with a revised date and additional notice where required. Privacy requests and questions may be sent through the contact form or to:
Jitoma Solutions s.r.o.
IČO: 19728492
Registered office: Vikingská 1248/2, Hodolany, 779 00 Olomouc, Czech Republic
Registered in the Commercial Register maintained by the Regional Court in Ostrava, file C 93705
Data box: 4s297zc
Email: 9hly2ztp1@mozmail.com