How Jupiter s.r.o. handles personal data across this website, the other websites we operate and every app we publish. Short version: we collect as little as possible, we don't track you, and we don't sell anything.
This privacy policy explains how Jupiter s.r.o. handles personal data. It applies to:
It applies to these only where they do not carry a separate privacy policy of their own. Where a specific website, service or app has its own dedicated privacy policy, that policy applies to it instead of this one.
This policy also does not cover the websites, apps and other solutions we build for clients. In that work the client alone decides why and how personal data is processed, so the client is the sole controller and is solely responsible for that data, its security and whatever their users submit to it.
Once we hand a project over, we no longer run it, have no access to its data, and take no responsibility for how the client operates it, unless that client separately engages us to manage or maintain the app on their behalf. That arrangement is governed by an individual agreement with the client (Article 28 of the GDPR). Even then the client stays the controller, and their own privacy policy, not this one, applies to their users.
Jupiter s.r.o. is the controller of the personal data described in this policy.
We have not appointed a Data Protection Officer, because our processing does not meet the criteria in Article 37 of the GDPR. Data protection questions go to the address above.
We apply the principle of data minimisation: we collect only the personal data we have a specific reason to collect, retain it only for as long as that reason applies, and then delete it. Where we measure how our products are used, we rely on aggregated, anonymised data rather than individual user histories.
Across our websites and the apps we publish, we do not:
The only personal data we deliberately collect on this website is what you type into a form:
We use it to answer you, to prepare a quote, to discuss a role, to handle a support request, and to keep a record of that conversation. Our forms are not intended for special categories of personal data (Article 9 GDPR), such as data about your health or your political or religious views. Please do not include such data in your message. We do not need it, and if you send it anyway we will delete it.
Form submissions are transmitted through our form provider, Web3Forms, and delivered to our mailbox hosted by Proton. Both act as processors for us.
Like any website, ours is delivered by our hosting provider, Render, whose servers process the technical data your browser sends with each request, such as IP address, time of the request, the page requested and browser type. This is needed to deliver the site and to keep it secure and available.
We run no analytics or tracking scripts, and there are no advertising or social media pixels on this site. The fonts and icons are served from our own servers, so loading a page makes no third-party requests. Cookies are covered in their own section.
This website sets no cookies and uses no comparable techniques such as local storage or fingerprinting, so there is nothing to consent to and no cookie banner. Your browser may still cache static files, such as fonts and images, so the site loads faster on your next visit. That caching is managed by your browser, is not used to identify you, and stores no personal data. You can clear it at any time in your browser settings.
If you are a client, or another business contact such as a supplier or professional adviser, we process the personal data we need to manage that relationship: your business contact details (name, work email, phone number and role), our correspondence with you, and the contract and billing records for the engagement. We receive this data from you, from the organisation you represent, or from a public register.
We use it to communicate with you, to agree and perform the contract, and to comply with our own legal obligations. Billing details, such as your or your company's name, address and tax identification numbers, are used only to issue and record invoices, and are kept in our accounting records for as long as tax and accounting law requires.
This section applies to every app we publish under our own developer accounts on the App Store and Google Play that does not have its own separate privacy policy. Where an app has its own policy, that policy applies to it instead, as set out at the top of this privacy policy.
These apps require no account, collect no personal data about you, show no ads and do not track you. Anything you enter stays on your device, and where an app syncs or backs up, it does so through your own account with Apple or Google, not through us. Device permissions such as camera, storage or location are requested only for the feature that needs them, and only when you use it.
Purchases, subscriptions and installs are handled by the App Store and Google Play, not by us. Each store is a separate controller for that data, and we receive only the aggregated sales and anonymised crash reports described under Analytics. Each app's store listing also carries the platform's own privacy details, Apple's privacy label or the Data safety section on Google Play, which we keep consistent with this privacy policy.
To understand how our products are performing, we rely only on the aggregated statistics provided by the platforms we use to host and distribute them. Render, our hosting provider, reports traffic and performance for the website, while the App Store and Google Play report downloads, sales and anonymised crash diagnostics for our apps. These figures are aggregated by each platform, do not identify you, and the platform remains the controller for the underlying data under its own privacy terms.
Beyond these platform reports, we add no analytics or tracking of our own. There are no analytics scripts on our websites and no analytics SDKs in our apps.
We process personal data only where we have a legal basis for it under Article 6 of the GDPR. For each purpose, that basis is:
No. Nothing on our websites or in our apps requires you to identify yourself to use them, and no law or contract obliges you to send us anything.
The only consequence of not giving us data is a practical one: without contact details we cannot reply to an enquiry or a support request, or consider a job application, and without the billing details that Slovak law requires on an invoice, we cannot take you on as a client. Fields marked as required in a form are the minimum we need for that one purpose. Everything else is optional.
We do not sell personal data and we do not disclose it for anyone else's marketing. We share it only with service providers who process it on our instructions, and where the law obliges us. Our recipients are:
The providers that process data on our behalf are bound by a data processing agreement under Article 28 of the GDPR. The separate controllers named above (the app stores and our accounting and tax advisers) handle your data under their own privacy terms.
Some of the providers above operate outside the European Economic Area, or use infrastructure that does. Where personal data is transferred outside the EEA, we rely on an adequacy decision of the European Commission or on Standard Contractual Clauses together with the supplementary measures required under Chapter V of the GDPR. For a copy of these safeguards, contact us at the address below.
We keep personal data only as long as the purpose requires, unless the law demands longer:
When a period ends, we delete the data or irreversibly anonymise it.
Under the GDPR you have the following rights in relation to your personal data.
We apply these rights, and the protections described in this policy, to everyone who uses our services, regardless of where they are located.
To exercise any of them, write to jupitersro@proton.me. We answer within one month of receiving your request, and will tell you if we need to extend that period by up to two further months because the request is complex. We may ask you for information to confirm your identity before we act on a request, so that we do not disclose your data to someone else. Exercising your rights is free of charge.
Where we rely on your consent, you can withdraw it at any time by writing to the same address, or by using the unsubscribe or in-app control where one exists. Withdrawing consent is as easy as giving it, and it does not affect anything we processed before you withdrew.
Rights that depend on identifying you cannot be exercised against data that is genuinely anonymous, because we can no longer connect it to you.
Our websites and apps may contain links to third-party websites and services that we do not operate or control. If you follow such a link, you leave our service and the privacy policy of that third party applies to you, not ours. We are not responsible for how those third parties handle your data, so we encourage you to read their privacy notices before you share anything with them.
We apply technical and organisational measures appropriate to the risk, as required by Article 32 of the GDPR. In practice that means encrypted connections (HTTPS) across our websites and apps, encrypted email, access limited to the people who need it, multi-factor authentication on the accounts that support it, and collecting as little data as possible in the first place, as data we never hold cannot leak.
If a personal data breach occurs and it is likely to result in a risk to your rights, we notify the supervisory authority within 72 hours and inform you directly where the GDPR requires it.
Our websites and services are meant for businesses and adults. They are not directed at children, and we do not knowingly collect personal data from a child. If you believe a child has provided us with personal data, contact us and we will delete it.
We keep this policy up to date. We revise it whenever our services, our technology or our legal obligations change, and always before we begin processing personal data in a way this version does not already describe. The latest version is always the one published on this page, and the “Last updated” date at the top shows when it last changed, so you can tell at a glance whether anything is new since you last read it.
Where a change would rely on your consent, we ask for that consent first, so a new use of your data never takes effect until you have agreed to it.
For any question about this policy, or to exercise any of your rights, write to jupitersro@proton.me or to Jupiter s.r.o., Račianska 88 B, 831 02 Bratislava, Slovakia.