Legal

Privacy Policy

How Findrio collects, uses, and protects personal data when you visit our website or use the platform. We process data lawfully, transparently, and only to the extent needed to deliver the service.

Effective
2026-05-20
Last updated
2026-05-20

Who controls your data

Findrio, s. r. o., with registered office at Dubová 1399, 900 42 Miloslavov, Slovak Republic (IČO: 57 497 168 · DIČ: 2122793794), is the data controller for the personal data described in this Policy. You can reach us by email at legal@findrio.com.

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Act No. 18/2018 Coll. on the Protection of Personal Data of the Slovak Republic, Findrio acts as the controller in respect of personal data processed about visitors, free-check users, registered accounts, and customer contacts.

What this policy covers

This Policy applies to findrio.com, app.findrio.com, and any subdomain or product surface operated by Findrio (collectively, the "Services"). It does not cover third-party websites we link to — those have their own policies.

When you act on behalf of a company that uses Findrio, that company is the controller of any data you submit through the Services on its behalf, and Findrio acts as a processor under a separate data processing agreement.

What data we process

We collect only the data needed to provide and improve the Services. We never sell personal data.

Account & identity

Name, work email, password hash, locale, the company you represent, and the role assigned within the workspace. You provide this directly during registration.

Service usage

Pages viewed, features used, the prompts you run, the engines you query, IP address, browser type, device type, approximate location derived from IP, timestamps, and diagnostic events. Collected automatically as you use the Services.

Billing

Company name, billing address, VAT/tax identifier, and the last four digits of the payment card. Full card details are processed exclusively by our PCI-DSS-certified payment processor and never stored on Findrio infrastructure.

Why we process it, and on what legal basis

Each processing purpose is tied to a lawful basis under Article 6 GDPR. We list them so you can verify our reasoning.

To provide the Services you signed up for, including authentication, workspace management, running AI-visibility checks, and storing your results — based on the performance of the contract between you and Findrio (Article 6(1)(b) GDPR).

To meet our legal obligations, including accounting, tax, and statutory record-keeping under Slovak and EU law — based on a legal obligation we are subject to (Article 6(1)(c) GDPR).

To secure the Services, prevent abuse, and investigate suspected fraud or violations of the Terms — based on our legitimate interest in protecting the Services and our users (Article 6(1)(f) GDPR).

To improve and develop new features, including aggregated and anonymised usage analytics — based on our legitimate interest in improving the product (Article 6(1)(f) GDPR). You can object at any time.

To send product updates, onboarding tips, and marketing about Findrio — based on consent where required, or on the soft opt-in for existing customers under Slovak and EU electronic-communications rules. You can unsubscribe at any time from any message.

How long we keep your data

We retain personal data only as long as we need it for the purpose we collected it for. Account data is kept while the account is active and for up to 12 months after deletion, so that you can reactivate and so we can resolve outstanding disputes.

Invoices and tax records are kept for 10 years as required by Act No. 431/2002 Coll. on Accounting. Server and security logs are kept for up to 12 months. Anonymised analytics may be retained indefinitely.

Who we share data with

We share personal data only with processors who deliver components of the Services on our behalf, and only under a written processing agreement that mirrors GDPR obligations.

Categories of processors include: cloud hosting and storage providers, transactional and marketing email providers, authentication and analytics providers, payment processors, customer-support tools, and the AI engines whose APIs power the visibility checks.

We do not sell personal data and we do not share personal data for cross-context behavioural advertising. We will disclose personal data to public authorities only where required by law and after verifying the request.

International data transfers

Our primary infrastructure is hosted in the European Union (Frankfurt). Some processors — in particular AI engine providers — are located in the United States or other third countries.

For every transfer outside the European Economic Area, we rely on a transfer mechanism recognised under GDPR Chapter V, primarily the European Commission Standard Contractual Clauses (Decision 2021/914) supplemented by technical and organisational safeguards. A copy of the clauses is available on request.

Your rights

Under the GDPR you have the following rights. You can exercise any of them by emailing legal@findrio.com from the address tied to your account. We respond within 30 days.

Right of access (Article 15): obtain confirmation that we process your data, a copy of the data, and information about how we process it.

Right to rectification (Article 16): have inaccurate or incomplete personal data corrected.

Right to erasure (Article 17): have your personal data deleted where one of the grounds in the GDPR applies.

Right to restriction (Article 18): require us to stop using your data while we verify an objection or a rectification request.

Right to data portability (Article 20): receive the data you provided to us in a structured, machine-readable format.

Right to object (Article 21): object to processing that is based on our legitimate interest, including profiling.

Right to withdraw consent (Article 7(3)): withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

Right to lodge a complaint with the supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava (https://dataprotection.gov.sk). You may also complain to the supervisory authority in your EU country of residence.

How we protect your data

We apply technical and organisational measures appropriate to the risk of the processing, including encryption in transit (TLS 1.2+) and at rest, role-based access control, audit logging, secret management, principle-of-least-privilege provisioning, regular penetration testing, and a documented incident-response plan.

Despite these measures, no system is perfectly secure. If we detect a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and inform affected users without undue delay.

Cookies and similar technologies

We use cookies and similar identifiers for authentication, security, preferences, and analytics. For the categories of cookies, retention periods, and how to manage your consent, see our Cookie Policy.

Changes to this policy

We may update this Policy from time to time. Material changes will be announced in-product or by email at least 14 days before they take effect. The "Last updated" date at the top of this page indicates the current version.

Contact

Questions about this Policy, requests to exercise your rights, or any other privacy matter — write to Findrio, s. r. o., Dubová 1399, 900 42 Miloslavov, Slovak Republic, or email legal@findrio.com.

Contact

Reach our legal team directly. We respond to GDPR requests within 30 days.

Entity
Findrio, s. r. o.
IČO: 57 497 168 · DIČ: 2122793794
Registered office
Dubová 1399, 900 42 Miloslavov
Slovak Republic