Switch to Czech?

Go back

Privacy Policy

(Last updated January 1, 2026)

Privacy Notice for Orion by Devoix Solutions s.r.o.

This Privacy Notice ("we", "us", or "our") describes how and why we access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services").

We are the Data Controller of your personal data under the General Data Protection Regulation (GDPR).

By using our Services, you agree to the terms described in this Privacy Policy. If you do not agree, please do not use the Services.

For any questions, contact: info@devoix.cz

Summary of Key Points

  • We process personal information based on your interactions with our web application.
  • We do not process sensitive personal information.
  • We do not collect information from third parties regarding your personal identity.
  • We do not use your data to train our AI models for other customers.
  • We maintain industry-standard security but cannot guarantee 100% protection.
  • We store billing data for 10 years (as required by Czech law), but we delete your content shortly after account termination.

1. What Information Do We Collect?

We collect personal information you voluntarily provide when you register on the Services via a web browser, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

Personal Information Provided by You:

  • Names, phone numbers, email addresses, mailing addresses.
  • Usernames, passwords, authentication data.
  • Billing addresses, debit/credit card numbers.
  • Payment data (processed by Stripe).
  • Social media login details (if used).

Company & Marketing Data You Provide:

We collect information necessary for generating marketing content:

  • Company identity data (logo, brand elements, colors, tone of voice).
  • Marketing personas you create manually or using our tools.
  • Uploaded content such as photos, videos, text, and brand materials.

Analytics & Social Network Data Provided by You

We only process analytics and social media data that you explicitly upload or authorize via API integrations (e.g., Google Analytics, Meta, LinkedIn). These integrations operate only with your permission.

No Mobile Device Permissions: As our Services are currently web-based only, we do not access mobile-specific hardware such as your camera, microphone, or GPS location directly through a mobile operating system.

No Sensitive Personal Data

We do not intentionally collect or process any special (sensitive) personal data as defined under GDPR (e.g., health data, religious beliefs, sexual orientation, biometrics).

If such information is accidentally included in uploaded materials, we do not use it for processing and it is removed when identified.

No Data Collected From Third Parties

  • We do not obtain personal information from external third-party sources.
  • All personal data we process is provided directly by you through your account, uploads, connected APIs, or interactions with the platform.
  • We do not buy, receive, or import personal data from data brokers, advertisers, or unrelated services.

2. How Do We Process Your Information?

We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.

We process your information to:

  • Create and manage user accounts.
  • Generate content based on your specific inputs.
  • Fulfill and manage orders and payments.
  • Protect our Services and comply with legal obligations.

3. What Legal Bases Do We Rely On?

If you are in the EU/UK:

We rely on:

  • Consent
  • Performance of a contract
  • Legitimate interests
  • Legal obligations
  • Vital interests

4. When and With Whom Do We Share Your Personal Information?

We may share data with the following categories of third parties:

  • Hosting Services.
  • Payment Processors (e.g., Stripe).
  • AI Service Providers (e.g., OpenAI, strictly for content generation features).
  • Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

International Data Transfers

Our servers may be located within the EU, but some of our third-party service providers (such as OpenAI or Stripe) are based in the United States. When we transfer your personal data outside the European Economic Area (EEA), we ensure a high level of protection by relying on:

  • The EU-U.S. Data Privacy Framework (DPF); or
  • Standard Contractual Clauses (SCCs) approved by the European Commission.

We do not sell your personal information.

5. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to access or store information. Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Policy (available on our website).

6. Artificial Intelligence-Based Products

We use artificial intelligence to provide our Services. We are transparent about how your data is used in this context.

  • Local & External Models: We use a combination of locally hosted models and third-party APIs (e.g., OpenAI) to generate content.
  • NO TRAINING ON CUSTOMER DATA: We do not use your proprietary data (uploaded content, brand guidelines, marketing personas) to train our AI models for the benefit of other customers or third parties. Your data is used solely to generate content for your own account.
  • Approval: Users must approve any AI-generated content before it is published.

7. Social Logins

If you register using social media accounts, we receive profile data depending on your provider. This data is used only for authentication.

8. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected.

  • Account Data & Marketing Assets: If you delete your account, we retain your general user data, uploaded content, and generated marketing assets for a period of 90 days to allow for account restoration in case of accidental deletion. After this period, this data is permanently deleted.
  • Financial Records: In accordance with the Czech Value Added Tax Act (Act No. 235/2004 Coll.) and Accounting Act, we retain invoices, billing records, and tax documents for 10 years.

After the applicable retention period expires, personal data is securely deleted.

9. Data Security

We implement reasonable organizational and technical measures. However, no method of electronic transmission is completely secure.

10. Information From Minors

We do not knowingly collect data from anyone under 18. If such data is discovered, it is fully deleted.

11. Your Privacy Rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the data we hold about you.
  • Right to Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request that we delete your data (subject to legal retention periods like tax laws).
  • Right to Restrict Processing: Ask us to pause processing your data.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Withdraw consent at any time (this does not affect the lawfulness of processing prior to withdrawal).

To exercise these rights, please contact us at info@devoix.cz.

Right to Complain

If you believe we are unlawfully processing your personal information, you have the right to complain to your local data protection supervisory authority. In the Czech Republic, this is:

Úřad pro ochranu osobních údajů
(Office for Personal Data Protection)
Pplk. Sochora 27, 170 00 Praha 7
www.uoou.cz

12. Updates to This Notice

We may update this notice to stay compliant with laws. Updates will be posted with a new revision date.

13. Contact Us

Devoix Solutions s.r.o.

IČO: 29126657

Verdunská 711/5, Praha 6

Prague 160 00, Czechia

Email: info@devoix.cz

14. Review, Update, or Delete Your Data

To manage your personal information, visit:
https://orion.devoix.cz or https://www.devoix.cz/orion

Devoix - Web & Software Development | Custom Solutions & AI Integration | Czech Republic