Skip to main contentSkip to main content
Apertia.ai
GDPR Compliance

Privacy Policy

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)

Apertia Tech s.r.o.

Šlikova 549/4, 169 00 Prague 6, Czech Republic
IČO: 27117758

Your data stays your data

We use artificial intelligence to work with the data in your business systems – for example to find information, process documents, prepare summaries, draft replies or automate business processes.

We do not use your data to train our AI models.

Customer data is processed only to the extent needed to provide the ordered service and the functions of the system.

What this means in practice

  • we do not use customer data to train general AI models,
  • we do not use one customer's data to improve the service for another customer,
  • AI works with data only to carry out a specific operation or provide a specific function,
  • access to data is limited to the systems and people who need it to provide the service,
  • where we use external technology or AI providers, we choose services that allow adequate protection and contractual safeguards for data,
  • the data remains the property of the customer and under the customer's control.

AI working on your data, not your data working for AI

Our goal is to use artificial intelligence as a tool that works for you and on your data.

We do not want to build AI by using the content of your CRM, ERP, documents, e-mails or internal databases to train public or general models.

Where the system uses generative AI or another third-party model, the relevant data may be technically passed to that provider only to the extent needed to carry out the requested operation and under conditions that match our contractual and legal obligations.

Security and personal data protection

We process personal data in accordance with the applicable data protection laws, in particular the GDPR.

Detailed terms of personal data processing, the use of sub-processors, security, retention and deletion of data are set out in the contractual terms and in any data processing agreement concluded with the customer.

1Data Controller

1.1. The controller of personal data is the company Apertia Tech s.r.o., with its registered office at Šlikova 549/4, 169 00 Prague 6, Czech Republic, Company ID: 27117758 (hereinafter referred to as the "Controller").

1.2. The Controller ensures that personal data processing is carried out in accordance with applicable legal regulations, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

2Purposes and Legal Bases for Personal Data Processing

2.1. Processing Without Consent

We process your personal data without the need for consent, primarily for the following purposes:

  • performance of contracts and provision of our services
  • fulfilment of legal obligations (especially accounting and tax obligations)
  • protection of our legitimate interests (e.g. asset protection, fraud prevention, defence of legal claims)

Legal basis:

  • čl. 6 odst. 1 písm. b) GDPR – performance of a contract
  • čl. 6 odst. 1 písm. c) GDPR – compliance with a legal obligation
  • čl. 6 odst. 1 písm. f) GDPR – legitimate interest of the Controller

2.2. Processing Based on Consent

Based on your consent, we process personal data primarily for:

  • marketing and business purposes
  • sending commercial communications and personalised offers
  • analysis of user behaviour through cookies and similar technologies

Legal basis:

  • čl. 6 odst. 1 písm. a) GDPR – consent of the data subject

You may withdraw your consent at any time.

Cookie Settings

You can adjust your preferences for analytical and marketing cookies at any time.

3Scope of Processed Personal Data

We process in particular:

  • identification data (first name, surname, company name)
  • contact data (address, e-mail, telephone)
  • contractual and billing data
  • technical and system data (IP address, cookies, logs)
  • data resulting from our mutual communication

4Recipients of Personal Data

4.1. Access to personal data is limited to:

  • authorised employees of the Controller
  • contractual processors (e.g. IT, accounting, marketing services) who are bound by confidentiality and a data processing agreement

4.2. Personal data may be provided to public authorities where required by law.

5Transfer of Personal Data Abroad

We primarily process personal data within the European Union.

If data is transferred outside the EU, an adequate level of protection is ensured through:

  • standard contractual clauses approved by the European Commission
  • or other appropriate safeguards under the GDPR

6Retention Period for Personal Data

We retain personal data:

  • for the duration of the contractual relationship
  • for the period required by law (e.g. accounting documents for 10 years)
  • for marketing data, until consent is withdrawn
  • for enquiries and communications, typically for a period of 1–2 years

After these periods expire, the data is securely deleted or anonymised.

7Rights of Data Subjects

You have the right to:

access your personal data
rectify or supplement your data
erasure (the right to be forgotten)
restrict processing
data portability
object to processing
withdraw your consent at any time

8Exercising Your Rights and Contact

You can exercise your rights by e-mail:

info@apertia.cz

You also have the right to lodge a complaint with the supervisory authority: Office for Personal Data Protection (www.uoou.cz)

9Obligation to Provide Personal Data

The provision of certain personal data is necessary for the conclusion of a contract or the provision of a service. Without providing such data, it may not be possible to provide the service.

10Cookies and Electronic Means

We use cookies and similar technologies for the purpose of:

  • proper functioning of the website
  • analytical and marketing purposes

Details are set out in a separate document Cookie Policy, available on our website.

11Draivix mobile application

The Draivix mobile application (Android, iOS) is a client for the Draivix / AutoERP system we operate for our customers. When you use it, we process:

  • login name, e-mail address and password – to sign you in to your organisation's instance; the application never stores the password
  • name and work profile shown in the application, as kept by your organisation in its own instance
  • files, photos and audio recordings you attach through the application yourself (camera, gallery, microphone) – only on your action; they are stored in your organisation's instance
  • the device push-notification token – to deliver notifications; you withdraw it by turning notifications off
  • biometric sign-in uses your device's own secure store only; biometric data never leaves the device
  • technical data required for operation (application version, device type, connection errors) – never used for advertising or profiling

Data travels encrypted (HTTPS) and is stored exclusively in the instance of the organisation that granted you access; Apertia acts as its processor. The application does not sell or share data with third parties for advertising. To delete your data or account, contact your organisation's administrator or podpora@apertia.cz.

12Final Provisions

This policy is valid and effective from 1. 8. 2024. The Controller reserves the right to update it periodically. The current version is always available on the company's website.

Apertia Tech s.r.o.

Last updated: 1 August 2024

Contact Us