Privacy Policy
Last updated: [effective date]
This Privacy Policy explains how personal data is handled in connection with the website at daat.red, the daat.red application programming interface (API host api.daat.red), and the operator console (app.daat.red) (together, the "Service").
The Service is operated by Red Code Company, s.r.o., a company incorporated in the Czech Republic, IČO (company ID) 22385151, with its registered seat at Děčínská 552/1, Střížkov, 180 00 Prague 8, Czech Republic ("Red Code Company", "we", "us", "our").
The Service is a business-to-business offering. It is not directed to consumers, and we do not knowingly provide it to individuals acting outside a trade, business, craft or profession.
1. Overview and structure of this Policy
The Service processes personal data in two distinct capacities, and different parts of this Policy apply to each:
- As a controller — for personal data relating to our business clients and the individuals who administer client accounts, including data used for account registration, authentication, provisioning, billing, support and security. This is described in sections 3 to 12.
- As a processor — for the personal data that a client submits to the API in order to obtain a verification result (for example a cardholder name, an email address or an IP address). For that data the client is the controller and we act on the client's documented instructions. This is described in section 13 and is governed in detail by our Data Processing Agreement.
If you are an individual whose data was submitted to the API by one of our clients (for example, because you attempted a payment or created an account with that client), the client — not Red Code Company — is the controller responsible for informing you and for establishing a lawful basis. Please contact that client in the first instance. We will support the client in responding to your request as required by Article 28 GDPR.
2. Contact details
- Controller: Red Code Company, s.r.o., Děčínská 552/1, Střížkov, 180 00 Prague 8, Czech Republic
- General contact: info@redcode.company
- Privacy contact: [privacy contact mailbox — suggested privacy@daat.red]
- Data Protection Officer: [name and contact details of the DPO, or a statement that no DPO is required to be appointed under Article 37 GDPR]
3. Personal data we process as a controller
3.1 Categories of data
| Category | Examples | Source |
|---|---|---|
| Client and account identification | Business name, registered address, IČO/registration number, VAT/DIČ, the account this relates to | Provided by the client during the access request and onboarding |
| Account administrator and user data | Name, business email address, job role, username, account role/permissions | Provided by the client; generated by us when accounts are created |
| Authentication and security data | Hashed passwords, two-factor authentication (TOTP) configuration, API keys and their metadata, source-IP allow-lists, session records, audit-log entries, security and access logs | Generated by the Service during use; configured by the client |
| Billing and financial data | Prepaid credit balance, credit top-up and approval records, usage/metering records (method called, timestamp, status, cost), agreed pricing, invoices and payment records, tax identifiers | Generated by the Service; provided by the client; [payment/invoicing processor, if any] |
| Support and communications data | Correspondence with our team, support tickets, request-console diagnostic information | Provided by the client's personnel when contacting us |
| Website data | A single strictly-necessary browser local-storage entry recording the visitor's chosen colour theme (see our Cookie Notice); server request logs generated by our hosting infrastructure | Generated when you use the website |
We do not use analytics, advertising or third-party tracking technologies on the daat.red website.
3.2 Server logs
Our EU hosting infrastructure generates technical logs (including IP address, timestamp, requested resource, response status and user agent) for the purposes of operating, securing and troubleshooting the Service. These logs are retained for the minimum period required for those purposes and for compliance with applicable law, and are then deleted.
4. Purposes and legal bases (controller processing)
| Purpose | Legal basis (GDPR Article 6) |
|---|---|
| Assessing an access request; creating, provisioning and administering a client account; providing the Service; providing the operator console and API keys | Performance of a contract, or steps taken at the client's request prior to entering into a contract — Art. 6(1)(b). Where the individual is not personally the contracting party, our legitimate interest in administering the client relationship — Art. 6(1)(f) |
| Authenticating users, securing accounts, operating two-factor authentication, maintaining audit logs, detecting and preventing abuse, fraud against the Service, and security incidents | Our legitimate interests in the security and integrity of the Service and in preventing misuse — Art. 6(1)(f); compliance with our security obligations — Art. 6(1)(c) |
| Metering usage, managing the prepaid credit balance, invoicing, collecting payment, and financial administration | Performance of a contract — Art. 6(1)(b); compliance with accounting and tax obligations — Art. 6(1)(c) |
| Providing support and responding to enquiries | Performance of a contract — Art. 6(1)(b); our legitimate interest in assisting clients — Art. 6(1)(f) |
| Maintaining records, establishing, exercising or defending legal claims, and responding to lawful requests from competent authorities | Compliance with a legal obligation — Art. 6(1)(c); our legitimate interests — Art. 6(1)(f) |
| Operating the website, including remembering the colour-theme preference and keeping the site secure and available | Our legitimate interest in providing a functioning, secure website — Art. 6(1)(f) |
| Sending service and administrative communications (for example changes to these documents, security notices, maintenance windows) | Performance of a contract — Art. 6(1)(b); compliance with a legal obligation — Art. 6(1)(c) |
| [direct marketing of other Red Code Company services to existing business contacts, if intended — likely Art. 6(1)(f) subject to an opt-out and applicable ePrivacy rules] | [PLACEHOLDER] |
Where we rely on legitimate interests, we have carried out a balancing assessment and will provide further information on request. You have the right to object to processing based on legitimate interests (see section 9).
5. Recipients and sub-processors
We disclose personal data only as necessary for the purposes described above, to the following categories of recipients:
- Our hosting provider, Hetzner Online GmbH, which provides infrastructure located in the European Union.
- Card networks / payment systems, to which we forward a Card check verification request under our own direct contractual relationships with those networks. This applies only to the Card check method and only for the data element necessary to perform the check. Only the client's chosen transaction determines which network is involved.
- Providers of data used to answer certain API methods (for example providers of IP, email or BIN reference data), and operational service providers such as error-monitoring and transactional-email providers. [confirm the specific providers used — see our Sub-Processors page]
- Professional advisers (lawyers, auditors, accountants) under a duty of confidentiality.
- Competent public authorities, courts and regulators, where we are legally required to disclose data or where disclosure is necessary to establish, exercise or defend legal claims.
- A successor entity, in connection with a merger, acquisition, reorganisation or sale of assets, subject to appropriate confidentiality safeguards.
A current list of the sub-processors engaged for the Service is maintained at daat.red/sub-processors.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6. Location of processing and international transfers
All processing carried out by us for the Service takes place exclusively within the European Union. The Service is hosted on Hetzner infrastructure located in the EU.
We do not transfer personal data to a country outside the EU/EEA in the course of operating the Service ourselves.
An international transfer may nevertheless occur where a card network or payment system that is inherently involved in the client's own transaction is located outside the EEA. In that case the transfer arises from the client's transaction and its verification requirements, not from a decision by us to move data abroad. Where such a transfer takes place, it is made on the basis of an adequacy decision, or of appropriate safeguards under Article 46 GDPR (such as Standard Contractual Clauses), or of a derogation under Article 49 GDPR where applicable. Further information is available from the privacy contact in section 2, and this position is addressed in our Data Processing Agreement.
7. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
- Account, authentication and configuration data: for the duration of the client relationship, and then for the minimum period required for security, record-keeping and the establishment, exercise or defence of legal claims, after which it is deleted or anonymised.
- Request metadata and results (the method called, timestamp, status, cost, and the non-card inputs and outputs such as name, email, IP address, BIN and verdict): retained for the minimum period required by applicable law, and then deleted.
- Full card numbers (PAN), card expiry data and card security codes: not retained. See section 8.
- Billing, invoicing and tax records: for the retention period required by Czech accounting and tax law.
- Support correspondence: for as long as needed to handle the matter and for a reasonable period afterwards.
- Security and server logs: for the minimum period needed for security and operational purposes.
Concrete retention periods per data category are set out in our internal retention schedule. [confirm concrete retention periods per data category and reflect them here.]
8. Card data — special handling
For the Card check and Card info methods, a client transmits a full card number (PAN) together with other elements. That card number is used only to perform the single lookup requested — including, for Card check, forwarding the verification request to the relevant card network / payment system — and is then discarded.
We do not retain the full card number, the card expiry date, or any card security code. What we retain about such a request is limited to non-card information: the method called, the timestamp, the status, the cost, the card BIN (the leading digits), the cardholder name submitted for verification, and the verification result (for example match / no-match plus a check code).
9. Your rights
Subject to the conditions and exceptions in the GDPR, individuals whose personal data we process as a controller have the right to:
- access their personal data and obtain a copy;
- request rectification of inaccurate or incomplete data;
- request erasure ("right to be forgotten");
- request restriction of processing;
- data portability for data processed by automated means on the basis of consent or contract;
- object to processing based on our legitimate interests, on grounds relating to their particular situation, and to object at any time to processing for direct marketing;
- withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise these rights, contact us using the details in section 2. We may need to verify your identity. We will respond within the time limits set by the GDPR (generally one month, extendable by two further months for complex requests).
Where your data was submitted to the API by one of our clients, that client is the controller; we will forward your request to the client and assist them in responding, as required by Article 28 GDPR.
Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:
Úřad pro ochranu osobních údajů (ÚOOÚ)
Pplk. Sochora 27, 170 00 Prague 7, Czech Republic
Website: www.uoou.cz
You may also complain to the supervisory authority in the EU member state of your habitual residence or place of work.
10. Automated decision-making
The API returns verification results (for example a name-match indicator, deliverability status, or reference data). These results are signals. Red Code Company does not itself take any decision that produces legal effects concerning a data subject or similarly significantly affects them.
Any decision to authorise, decline, delay or review a payment or an account — and any decision based in whole or in part on an API result — is taken by the client in its own systems and under its own responsibility. If you are subject to such a decision, your rights under Article 22 GDPR are to be exercised against the client as controller.
11. Security
We maintain technical and organisational measures appropriate to the risk, including:
- processing and hosting exclusively within the European Union, on Hetzner infrastructure;
- not storing full card numbers, card expiry data or card security codes (see section 8);
- encryption of personal data in transit using current transport-layer security;
- network segmentation and restricted network exposure of processing systems;
- access control on a least-privilege, need-to-know basis, with individual accounts, two-factor authentication for the operator console, API-key authentication with optional source-IP allow-lists, and key rotation;
- logging and audit trails of administrative and security-relevant events;
- rate limiting and abuse detection;
- staff confidentiality obligations and security awareness;
- procedures for detecting, investigating and reporting personal data breaches.
We describe our concrete practices above and encourage clients to assess them against their own requirements.
12. Children and consumer use
The Service is intended solely for use by businesses. It is not directed to consumers or to children, and we do not knowingly create accounts for individuals in a personal capacity or process the data of children as a controller. Clients must not use the API to process the data of children except where they have their own lawful basis and appropriate safeguards to do so.
13. Data submitted through the API (processor processing)
When a client calls the API, it may submit personal data relating to its own customers or end-users — typically a cardholder name, an email address, an IP address, and a card BIN — together with a full card number for the Card check and Card info methods (handled as described in section 8). The verification results derived from these inputs are also personal data.
For all of this data:
- the client is the controller and Red Code Company / daat.red is a processor;
- we process it only on the client's documented instructions, which for this Service are the API calls the client chooses to make;
- the client is responsible for having a valid lawful basis for each lookup, for providing the required information to data subjects, for obtaining any necessary consent, and for complying with applicable payments, card-network, anti-money-laundering and sanctions rules;
- the categories of data subject are the client's customers and end-users;
- our processing of this data is governed by our Data Processing Agreement (available at [DPA URL]), which forms part of the contract with each client and prevails on data-protection matters.
14. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date above indicates when it was last revised. For material changes affecting clients, we will provide notice through the operator console or by email. Continued use of the Service after the effective date of a change constitutes acknowledgement of the updated Policy, to the extent permitted by law.