daat.red ← back to site

Privacy Policy

Last updated: [effective date]

This Privacy Policy explains how personal data is handled in connection with the website at daat.red, the daat.red application programming interface (API host api.daat.red), and the operator console (app.daat.red) (together, the "Service").

The Service is operated by Red Code Company, s.r.o., a company incorporated in the Czech Republic, IČO (company ID) 22385151, with its registered seat at Děčínská 552/1, Střížkov, 180 00 Prague 8, Czech Republic ("Red Code Company", "we", "us", "our").

The Service is a business-to-business offering. It is not directed to consumers, and we do not knowingly provide it to individuals acting outside a trade, business, craft or profession.

1. Overview and structure of this Policy

The Service processes personal data in two distinct capacities, and different parts of this Policy apply to each:

  1. As a controller — for personal data relating to our business clients and the individuals who administer client accounts, including data used for account registration, authentication, provisioning, billing, support and security. This is described in sections 3 to 12.
  2. As a processor — for the personal data that a client submits to the API in order to obtain a verification result (for example a cardholder name, an email address or an IP address). For that data the client is the controller and we act on the client's documented instructions. This is described in section 13 and is governed in detail by our Data Processing Agreement.

If you are an individual whose data was submitted to the API by one of our clients (for example, because you attempted a payment or created an account with that client), the client — not Red Code Company — is the controller responsible for informing you and for establishing a lawful basis. Please contact that client in the first instance. We will support the client in responding to your request as required by Article 28 GDPR.

2. Contact details

3. Personal data we process as a controller

3.1 Categories of data

CategoryExamplesSource
Client and account identificationBusiness name, registered address, IČO/registration number, VAT/DIČ, the account this relates toProvided by the client during the access request and onboarding
Account administrator and user dataName, business email address, job role, username, account role/permissionsProvided by the client; generated by us when accounts are created
Authentication and security dataHashed passwords, two-factor authentication (TOTP) configuration, API keys and their metadata, source-IP allow-lists, session records, audit-log entries, security and access logsGenerated by the Service during use; configured by the client
Billing and financial dataPrepaid credit balance, credit top-up and approval records, usage/metering records (method called, timestamp, status, cost), agreed pricing, invoices and payment records, tax identifiersGenerated by the Service; provided by the client; [payment/invoicing processor, if any]
Support and communications dataCorrespondence with our team, support tickets, request-console diagnostic informationProvided by the client's personnel when contacting us
Website dataA single strictly-necessary browser local-storage entry recording the visitor's chosen colour theme (see our Cookie Notice); server request logs generated by our hosting infrastructureGenerated when you use the website

We do not use analytics, advertising or third-party tracking technologies on the daat.red website.

3.2 Server logs

Our EU hosting infrastructure generates technical logs (including IP address, timestamp, requested resource, response status and user agent) for the purposes of operating, securing and troubleshooting the Service. These logs are retained for the minimum period required for those purposes and for compliance with applicable law, and are then deleted.

4. Purposes and legal bases (controller processing)

PurposeLegal basis (GDPR Article 6)
Assessing an access request; creating, provisioning and administering a client account; providing the Service; providing the operator console and API keysPerformance of a contract, or steps taken at the client's request prior to entering into a contract — Art. 6(1)(b). Where the individual is not personally the contracting party, our legitimate interest in administering the client relationship — Art. 6(1)(f)
Authenticating users, securing accounts, operating two-factor authentication, maintaining audit logs, detecting and preventing abuse, fraud against the Service, and security incidentsOur legitimate interests in the security and integrity of the Service and in preventing misuse — Art. 6(1)(f); compliance with our security obligations — Art. 6(1)(c)
Metering usage, managing the prepaid credit balance, invoicing, collecting payment, and financial administrationPerformance of a contract — Art. 6(1)(b); compliance with accounting and tax obligations — Art. 6(1)(c)
Providing support and responding to enquiriesPerformance of a contract — Art. 6(1)(b); our legitimate interest in assisting clients — Art. 6(1)(f)
Maintaining records, establishing, exercising or defending legal claims, and responding to lawful requests from competent authoritiesCompliance with a legal obligation — Art. 6(1)(c); our legitimate interests — Art. 6(1)(f)
Operating the website, including remembering the colour-theme preference and keeping the site secure and availableOur legitimate interest in providing a functioning, secure website — Art. 6(1)(f)
Sending service and administrative communications (for example changes to these documents, security notices, maintenance windows)Performance of a contract — Art. 6(1)(b); compliance with a legal obligation — Art. 6(1)(c)
[direct marketing of other Red Code Company services to existing business contacts, if intended — likely Art. 6(1)(f) subject to an opt-out and applicable ePrivacy rules][PLACEHOLDER]

Where we rely on legitimate interests, we have carried out a balancing assessment and will provide further information on request. You have the right to object to processing based on legitimate interests (see section 9).

5. Recipients and sub-processors

We disclose personal data only as necessary for the purposes described above, to the following categories of recipients:

A current list of the sub-processors engaged for the Service is maintained at daat.red/sub-processors.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

6. Location of processing and international transfers

All processing carried out by us for the Service takes place exclusively within the European Union. The Service is hosted on Hetzner infrastructure located in the EU.

We do not transfer personal data to a country outside the EU/EEA in the course of operating the Service ourselves.

An international transfer may nevertheless occur where a card network or payment system that is inherently involved in the client's own transaction is located outside the EEA. In that case the transfer arises from the client's transaction and its verification requirements, not from a decision by us to move data abroad. Where such a transfer takes place, it is made on the basis of an adequacy decision, or of appropriate safeguards under Article 46 GDPR (such as Standard Contractual Clauses), or of a derogation under Article 49 GDPR where applicable. Further information is available from the privacy contact in section 2, and this position is addressed in our Data Processing Agreement.

7. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected:

Concrete retention periods per data category are set out in our internal retention schedule. [confirm concrete retention periods per data category and reflect them here.]

8. Card data — special handling

For the Card check and Card info methods, a client transmits a full card number (PAN) together with other elements. That card number is used only to perform the single lookup requested — including, for Card check, forwarding the verification request to the relevant card network / payment system — and is then discarded.

We do not retain the full card number, the card expiry date, or any card security code. What we retain about such a request is limited to non-card information: the method called, the timestamp, the status, the cost, the card BIN (the leading digits), the cardholder name submitted for verification, and the verification result (for example match / no-match plus a check code).

9. Your rights

Subject to the conditions and exceptions in the GDPR, individuals whose personal data we process as a controller have the right to:

To exercise these rights, contact us using the details in section 2. We may need to verify your identity. We will respond within the time limits set by the GDPR (generally one month, extendable by two further months for complex requests).

Where your data was submitted to the API by one of our clients, that client is the controller; we will forward your request to the client and assist them in responding, as required by Article 28 GDPR.

Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:

Úřad pro ochranu osobních údajů (ÚOOÚ)
Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
Website: www.uoou.cz

You may also complain to the supervisory authority in the EU member state of your habitual residence or place of work.

10. Automated decision-making

The API returns verification results (for example a name-match indicator, deliverability status, or reference data). These results are signals. Red Code Company does not itself take any decision that produces legal effects concerning a data subject or similarly significantly affects them.

Any decision to authorise, decline, delay or review a payment or an account — and any decision based in whole or in part on an API result — is taken by the client in its own systems and under its own responsibility. If you are subject to such a decision, your rights under Article 22 GDPR are to be exercised against the client as controller.

11. Security

We maintain technical and organisational measures appropriate to the risk, including:

We describe our concrete practices above and encourage clients to assess them against their own requirements.

12. Children and consumer use

The Service is intended solely for use by businesses. It is not directed to consumers or to children, and we do not knowingly create accounts for individuals in a personal capacity or process the data of children as a controller. Clients must not use the API to process the data of children except where they have their own lawful basis and appropriate safeguards to do so.

13. Data submitted through the API (processor processing)

When a client calls the API, it may submit personal data relating to its own customers or end-users — typically a cardholder name, an email address, an IP address, and a card BIN — together with a full card number for the Card check and Card info methods (handled as described in section 8). The verification results derived from these inputs are also personal data.

For all of this data:

14. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date above indicates when it was last revised. For material changes affecting clients, we will provide notice through the operator console or by email. Continued use of the Service after the effective date of a change constitutes acknowledgement of the updated Policy, to the extent permitted by law.