Personal Data Controller
The personal data controller is: Terezie Mocová
Company ID No.: 21621624
registered office: Mšenská 3939/28, 466 04 Jablonec nad Nisou
e-mail: info@herpadex.cz
hereinafter referred to as the “Controller”.These principles describe the processing of personal data in connection with the Herpadex website,
customer portal and the Herpadex web, mobile and desktop application, hereinafter collectively referred to as “Herpadex” or the “Service”.Role of the Controller
The Controller determines the purposes and means of processing personal data that are necessary in particular for:registration of customers and users,
management of customer accounts,
provision of the Service,
subscription management,
payments and invoicing,
communication with customers,
security and operation of the Service,
protection of the Controller’s legal claims,
measurement of website traffic and evaluation of the use of the Service,
evaluation of the registration process and improvement of the Service.
Data concerning animals, terrariums, feeding, equipment, cleaning and other husbandry events are generally not personal data in themselves.
The Service is not intended for the systematic storage of personal data of third parties and does not contain separate fields for recording breeders, sellers, buyers, veterinarians or other persons.
If the Customer enters personal data of a third party into a free-text note or other user content, the Customer is responsible for the lawfulness of such processing. The Controller uses such data only to the extent necessary for the technical provision of the Service and does not use them for its own separate purposes.
What Personal Data We Process
Registration and identification data
Depending on the type of customer account, the following may be processed in particular:first name and surname,
name or business name,
Company ID No. and VAT ID No.,
billing address,
country,
e-mail address,
telephone number, if provided.
User account data
The following may be processed in particular:e-mail address used for login,
securely stored password hash,
user role and permissions,
account activation status,
password change data,
login, logout and user session data,
user account settings.
The Controller does not store passwords in readable form.
Subscription and payment data
The following may be processed in particular:selected subscription plan,
subscription status and history,
date of commencement, change or termination of the subscription,
price and currency,
payment status,
payment identifier,
data contained in accounting and tax documents,
invoicing history,
data concerning any receivable or refund.
Complete payment card data are processed by the payment service provider Stripe. The Controller does not store the full payment card number or card security code.
Operational and administrative data
In connection with the operation of the account, the following may be processed in particular:history of changes to the customer account,
administrative actions performed by the account owner or other users,
changes to the subscription plan, billing information and user permissions,
information about the creation, deactivation or deletion of a user,
history of important operational events,
records related to support and handling of requests.
History in the customer and central administration may be maintained for the purpose of ensuring traceability of changes, security, handling of complaints and protection of legal claims
Technical data
When using the website and applications, the following may be technically processed in particular:IP address,
date and time of the request,
requested address or function,
result and status of the request,
device type and version,
operating system,
browser type,
application version,
technical error and security logs.
These data are processed only to the extent necessary for communication with the Service, security, error diagnostics and protection of the infrastructure.
Mobile notification data
If the user enables system notifications, the following may be processed:device identifier or installation identifier,
Firebase Cloud Messaging token,
information about whether the application is active,
data necessary for delivery of the notification,
information about successful or unsuccessful delivery.
The content of notifications is limited to information necessary for the operation of the Service.
The user may disable system notifications at any time in the settings of their device.
Communication
If the Customer contacts the Controller, the following may be processed:name,
e-mail address,
content of the message,
related attachments,
date and history of communication,
information necessary to handle the request.
Analytical data
For measuring website traffic and evaluating the use of the Service, the Controller uses its own installation of the Umami analytics system operated on its own infrastructure.Within the analytics, the following may be processed in particular:
visited page or path,
date and time of the visit,
referring page,
browser type,
operating system,
device type and screen resolution,
browser language,
approximate geographical area,
technical session identifier,
data on selected events when using the website or registration process, in particular the selected subscription plan and currency.
The IP address may be technically used to create an anonymous session identifier and determine an approximate geographical area, but it is not stored in the analytics system.
The analytics system is not intentionally provided with the customer’s name, e-mail address or any other direct identifier.
Purposes and Legal Bases for Processing
Conclusion and performance of the contract
Pursuant to Article 6(1)(b) GDPR, the Controller processes personal data necessary for:registration and activation of the account,
user login,
provision of Service features,
management of users and permissions,
management of the subscription plan and subscription,
issuing and making invoices available,
providing customer support,
sending operational, security and contractual messages.
Provision of data marked as mandatory during registration is a contractual requirement. Without these data, an account cannot be created or the Service provided.
Compliance with legal obligations
Pursuant to Article 6(1)(c) GDPR, the Controller processes data necessary in particular for compliance with:accounting obligations,
tax obligations,
obligations related to complaints and consumer rights,
obligations towards public authorities.
Legitimate interests of the Controller
Pursuant to Article 6(1)(f) GDPR, the Controller processes necessary personal data for:protection of the Service against attacks and misuse,
security of customer accounts,
diagnostics of technical problems,
fraud prevention,
recording of administrative changes,
recovery of receivables,
establishment, exercise and defence of legal claims,
ensuring the stability and availability of the Service,
measurement of website traffic,
evaluation of the use of the Service and registration process,
improvement of the website and the Service.
When processing based on legitimate interest, the Controller assesses whether the rights and freedoms of the data subject override its interest.
Consent
The Controller does not base ordinary registration, contractual, invoicing or technical processing on consent where another legal basis exists.System permission for mobile notifications is granted by the user through the operating system of their device and may be withdrawn at any time.
Sources of Personal Data
We obtain personal data in particulardirectly from the Customer or user during registration,
when managing the customer account,
when placing an order or changing a subscription,
when communicating with the Controller,
automatically when using the website or application,
from the payment service provider in connection with payment status,
from Firebase services in connection with the delivery of mobile notifications.
Recipients and Service Providers
The Controller does not sell personal data.Access to data on its own infrastructure is limited to the Controller.
To the necessary extent, personal data may be processed by the following providers:
Stripe
Stripe provides payment processing and related security and anti-fraud checks.
Stripe may process in particular:name and billing information,
e-mail address,
payment data,
payment method,
technical data about the device and connection,
data necessary for fraud prevention.
Depending on the nature of the specific operation, Stripe may act as a processor or as an independent controller of personal data.
Google Firebase Cloud Messaging
Google, through the Firebase Cloud Messaging service, provides delivery of push notifications to the Android application.For this purpose, the following may be transferred in particular:
device push token,
application identifier,
technical data necessary for delivery,
content of the specific notification.
Google Play
The Herpadex mobile application may be distributed through Google Play.
Data processed by Google when using a Google account, installing the application, updating it or using Google Play are processed by Google within its own relationship with the user.
The Controller receives only the data and aggregated information made available to it by Google Play within the distribution platform.Public authorities
Personal data may be provided to a court, administrative authority, police authority, tax authority or another authorised entity if the Controller is required to provide the data pursuant to law or a final decision.
Location and Transfer of Data
Herpadex servers, customer databases, the internal Unico system and own backups are operated in the Czech Republic.
Access to the Controller’s own infrastructure is limited to the Controller.
Stripe and Google may use infrastructure, companies or subprocessors also outside the European Union and the European Economic Area.
Where personal data are transferred to a country for which no adequacy decision has been issued, the transfer must be based on appropriate safeguards under Chapter V GDPR, in particular the standard contractual clauses approved by the European Commission.Retention Period
Active customer account
Data necessary for provision of the Service are retained for the duration of the customer account and contractual relationship.
Operational and administrative history in the customer and central administration is not automatically deleted while the account is active if it is necessary for the functioning of the Service, security, traceability of changes or handling of complaints.Free plan account
Following complete termination of a customer account on the Free plan, customer data and the corresponding customer instance will be deleted no later than within 14 days.Paid account
Following complete termination of a paid customer account, customer data and the corresponding customer instance will be deleted no later than within 30 days.
Cancellation of automatic subscription renewal does not in itself mean immediate deletion of the account.
The account remains active until the end of the paid period unless the customer expressly requests its complete deletion.Backups
After data are deleted from the production system, copies may remain in operational backups for no longer than an additional 7 days.
Backups are not used for ordinary operational purposes and access to them is limited to restoration of the system following a failure or security incident.
If an entire backup is restored during this period, accounts and data that had already been deleted will be deleted again.Central administration, contractual and invoicing history
Following deletion of the customer instance, data necessary for the following may continue to be retained in the central administration:records of the contractual relationship,
accounting and taxes,
records of payments and invoices,
handling of complaints,
recovery of receivables,
establishment, exercise or defence of legal claims.
Accounting and tax data are retained for the period prescribed by applicable legislation, depending on the type of document for up to 10 years. Data necessary for the protection of legal claims are retained for the duration of the applicable limitation periods and, in the event of an ongoing dispute, until its final conclusion. After these periods expire, personal data in the central administration will be deleted or irreversibly anonymised.
Anonymised statistics
Data that have been irreversibly anonymised and can no longer be associated with a specific person or customer account may be retained without time limitation.Technical and security logs
Technical, error and security logs are retained only for the period necessary for:operational diagnostics,
security of the infrastructure,
resolution of a technical or security incident,
evidence and protection of legal claims.
If a specific record forms part of a security incident, complaint or legal dispute, it may be retained until their final resolution.
Push tokens
A push token is retained for as long as the device is linked to an active user account and notifications are enabled.
The token will be deleted or cease to be used in particular upon:deregistration of the token by the application,
invalidation of the token by Firebase,
deactivation of the user,
complete deletion of the customer account.
Communication with the Controller
Communication is retained for the period necessary to handle the request and subsequently for the period necessary to document its handling or protect legal claims.Analytical data
Analytical data are retained for no longer than 24 months from the date of collection. After this period, they are deleted or irreversibly anonymised.
Security of Personal Data
The Controller adopts technical and organisational measures appropriate to the nature of the Service and the data processed.
The measures used include in particular:operation of own infrastructure in the Czech Republic,
restriction of access to the infrastructure solely to the Controller,
separate databases for individual customers,
separate API instances and configurations for individual customers,
process and network isolation of customer instances,
encrypted communication via HTTPS,
storage of passwords only in the form of a secure hash,
management of user roles and permissions,
backups,
security updates,
recording of important administrative changes,
limitation of the personal data retention period.
No method of electronic storage or transmission can, however, ensure absolute security.
The Controller therefore continuously evaluates and adapts the measures to current risks.
Rights of the Data Subject
Under the conditions set out in the GDPR, the data subject has in particular:Right of access
The data subject has the right to obtain confirmation as to whether the Controller processes their personal data and to obtain access to such data and related information.Right to rectification
The data subject has the right to request correction of inaccurate data and completion of incomplete data.
Basic customer account data may also be changed directly in the customer portal to the extent supported.Right to erasure
The data subject has the right to request erasure of personal data if the conditions of the GDPR are met.
The right to erasure does not apply to the extent that further retention is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.Right to restriction of processing
The data subject has the right to request temporary restriction of processing in the cases provided for by the GDPR.Right to data portability
For data processed by automated means on the basis of a contract or consent, the data subject has the right to obtain the data they provided to the Controller in a structured, commonly used and machine-readable format, provided that the statutory conditions are met.Right to object
The data subject has the right to object to processing based on the legitimate interest of the Controller. Following an objection, the Controller will no longer process the data unless it demonstrates compelling legitimate grounds that override the rights and freedoms of the data subject, or grounds for the establishment, exercise or defence of legal claims.Right to lodge a complaint
The data subject has the right to lodge a complaint with:Office for Personal Data Protection
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
e-mail: posta@uoou.gov.czLodging a complaint does not affect the right to any other administrative or judicial remedy.
Exercise of Rights
Requests and questions concerning personal data may be sent to: info@herpadex.cz The Controller may require reasonable verification of the applicant’s identity before handling the request, in particular where the request is received from an e-mail address different from the one registered with the customer account. The Controller will handle the request without undue delay, generally no later than within one month. In complex cases, the period may be extended under the conditions of the GDPR.Automated Decision-Making and Profiling
Herpadex does not carry out automated individual decision-making that would produce legal effects concerning the user or similarly significantly affect them. Herpadex does not profile customers for advertising or marketing purposes. Operational alerts and notifications are generated on the basis of data and dates entered by the user, for example according to the date of cleaning, feeding or equipment status. This does not constitute automated decision-making concerning the user’s rights or obligations.Cookies, Local Storage and Web Analytics
The website and customer portal use only technically necessary cookies and similar technologies, in particular local or session browser storage.
These technologies are used in particular for:securing login,
maintaining an active session,
restoring an incomplete registration,
storing necessary technical settings,
protection against misuse,
proper functioning of the website and customer portal.
Herpadex does not use analytical, advertising or marketing cookies.
For measuring website traffic and evaluating the use of the website, the Controller uses its own installation of the Umami analytics system operated on its own infrastructure. Umami does not use analytical cookies and does not track users across different websites.
Analytical data are processed on the basis of the Controller’s legitimate interest consisting in measuring website traffic, evaluating the functioning of the registration process and improving the Service.
Technically necessary cookies and storage are used without the user’s consent because without them it would not be possible to provide the requested Service safely and properly.Changes to These Principles
The Controller may update these principles in particular in the event of:changes to Herpadex features,
involvement of a new provider,
changes to the manner of processing data,
changes in legislation,
changes to security or operational procedures.
The current version will be published on the Herpadex website. If the change is material and may significantly affect users’ rights, the Customer will be informed via e-mail, the customer portal or the application.
Effective Date
These Privacy Principles take effect on: 18 August 2026
HERPADEX