Privacy Policy

Effective from 2 September 2026

1. Who processes the data

The Volaryx service is operated by Ondřej Hubáček, Company ID (IČO): 07371578, VAT ID (DIČ): CZ9612011750, registered office at Františka Metelce 174, 391 75 Malšice, Czech Republic (the “Operator”). Contact for personal data matters: info@volaryx.com.

The Operator acts in two roles:

  • Controller — for the data of the service’s users (companies and businesses that have created an account; the “User”).
  • Processor — for data that the User’s customers enter into the calculator. The controller of that data is the User (the operator of the calculator that the customer requests a print quote from); the terms of processing are set out in the data processing agreement in section 8 of this policy.

2. What data we process and why

a) Data of Users (we are the controller):

  • Account and billing — e-mail, company name, Company ID, VAT ID, address. Purpose: account administration, providing the service, invoicing and fulfilling tax obligations. Legal basis: performance of a contract and legal obligations.
  • Where you came from — the account’s first source: the page on our website, the campaign label, an ad click mark and, where relevant, a partner mark. Purpose: to know which of our channels brought the account, and to pay the partner a commission. Legal basis: legitimate interest. We do not overwrite it after sign-up. If you consent to measurement, we also use the Google click mark to tell Google that the click became an account or a payment — never your name or e-mail. We do not send it to Meta.
  • Account settings and content — price lists, text, logo, received quote requests. Purpose: providing the service. Legal basis: performance of a contract.
  • Payment data — processed by the payment gateway (Stripe); the Operator does not have access to card numbers. Legal basis: performance of a contract and legal obligations (accounting).
  • Operational and technical logs — records of errors and service operation (may include an IP address and technical device information). Purpose: security, detecting and fixing faults. Legal basis: legitimate interest in reliable and secure operation.
  • Service e-mails — messages necessary for account operation (registration confirmation, password reset, subscription and quote-request notifications). Legal basis: performance of a contract; these cannot be unsubscribed from.
  • Product news — e-mails about news and tips on using the service are sent to account users. Legal basis: legitimate interest in informing users about the service they use. Every e-mail has a one-click unsubscribe. Website visitors receive them only if they expressly ask for them.
  • Mail (e-mail client in the admin) — if the User enables this feature, Volaryx connects to their mailbox through the sub-processor Unipile. E-mail content (received and sent messages) is not permanently stored in our database — it is reloaded directly from the User's mailbox each time it is opened and held only temporarily in the browser's memory. Purpose: enabling communication with customers directly from the admin. Legal basis: performance of a contract.

b) Data of the User’s customers (we are the processor): name, e-mail, phone, billing and delivery address, optionally a Company ID/VAT ID, the content of the inquiry and order including uploaded files, data on the customer record, on documents and on the shipment, and — if the User enables Mail — mailbox content (not stored permanently by us). A simplified copy of the 3D model is uploaded to our storage already when the price is calculated, before the customer submits a quote request (temporary copies are deleted by the nightly cleanup, see section 3). Purpose: operating the service for the User. The purpose and duration are decided by the User as controller; the customer should write to them first.

c) Data of website visitors and form senders (we are the controller):

  • Website and admin visits — technical error logs (may include an IP address). Visitor and ads measurement (Google Analytics and Ads) runs only with consent. Google measures visits to the website and the public pages of the app (sign-up, sign-in) and whether an ad click became an account or a payment. It does not run in the calculator embedded on a print shop’s website. Legal basis for measurement: consent. Legal basis for error logs: legitimate interest in secure operation.
  • First website visit — in the browser for 90 days (not a cookie) we store the campaign and click mark from the address and the volaryx.com page where you started. If you register, we attach it to the account (section 2a). Without registration it disappears after 90 days or when you clear this site’s data. It does not run in the calculator embedded on a print shop’s website. Purpose and legal basis: legitimate interest in knowing which channel works. If you consent to measurement, we pass the Google click mark to Google (see section 2a). We do not pass it to Meta.
  • Contact form — e-mail, subject, message. Purpose: to reply. Legal basis: legitimate interest / steps toward a contract. We do not send news from this.
  • Pricing tips from the website footer — e-mail. Purpose: send pricing tips. Legal basis: consent (submitting the form). Unsubscribe anytime.

3. How long we keep the data

  • Account data — for the duration of the account. After the account is cancelled, a 30-day grace period applies (the cancellation can be reversed), after which the account data is permanently and irreversibly deleted.
  • Accounting and tax records — for the period required by applicable law.
  • Quote requests and their attachments — the quote record itself (without the uploaded files) stays in the User’s dashboard for the period determined by the User as controller (at most until the User deletes the quote request or the User’s account ends). The uploaded files (3D models and attachments) are automatically deleted from storage according to the User’s plan, counted from submission: Free 14 days, Start 90 days, Profi 180 days, Profi+ 365 days. The inquiry and order record stays.
  • Temporary calculator files — a simplified copy of the 3D model uploaded already when the price is calculated (even if no quote request is submitted). Deleted by the nightly cleanup, typically within 48 hours.
  • Account first source — for the life of the account. It is deleted with the account.
  • Operational and error logs — for a limited period necessary for security and troubleshooting, then deleted automatically.

4. Who we share data with (recipients)

We do not sell your data to anyone. To operate the service we use vetted subprocessors that process data according to our instructions:

  • Supabase — database, authentication and file storage (servers in the EU, Frankfurt).
  • Vercel — application hosting.
  • Stripe — payment processing and subscription billing.
  • Resend — sending e-mails.
  • Fly.io — technical calculation of 3D model parameters (servers in the EU, Frankfurt).
  • Sentry — application error monitoring (servers in the EU).
  • Google — measurement of visits to the website and the public pages of the app, and reporting whether an ad click became an account or a payment (click mark and amount, never a name or e-mail). Servers may be outside the EU; transfers rely on the EU–U.S. Data Privacy Framework. Runs only with consent. Never in the embedded calculator.
  • Better Stack — service availability monitoring (no access to customer data).
  • Unipile — technical mediation of access to the User's mailbox for the Mail feature (see section 2a); we do not permanently store e-mail content.

If the User connects their invoicing system or carrier in the admin (for example iDoklad, SuperFaktura, PPL, Zásilkovna), we transmit their customer’s data to their account with that service on their instruction. Those services are not our subprocessors — they process data for the User.

Some subprocessors may process data outside the EU/EEA (in particular the USA); in such cases the transfer is safeguarded by an EU Commission adequacy decision (the EU–U.S. Data Privacy Framework) or standard contractual clauses. We may also disclose data to public authorities where required by law.

5. How we protect the data

Data is transmitted encrypted (HTTPS), access is controlled at the level of individual accounts (each User sees only their own data), secret values are never stored in the browser, and the database is backed up regularly. The Operator’s access to Users’ accounts is limited to necessary administration and support and is logged.

6. Your rights

You have the right to access your data, to have it corrected or erased, to restrict processing, to data portability, and to object to processing based on legitimate interest. We handle requests sent to info@volaryx.com without undue delay, and no later than within one month.

You also have the right to lodge a complaint with the Czech Office for Personal Data Protection (uoou.gov.cz), or with the data protection authority in your own EU member state.

If you are a customer of one of our Users (you requested a print quote through their calculator), please direct your requests primarily to them as the controller of your data; we are happy to help them handle it.

7. Cookies

We use essential cookies without consent (sign-in, language). Visitor and ads measurement (Google Analytics and Ads) only with consent. The first visit source and the partner link are not third-party cookies; if you consent, we pass the Google click mark to Google. Details and how to change measurement consent are in the Cookie Policy.

8. Data processing agreement (for service users)

This section constitutes a data processing agreement under Article 28 GDPR between the User (controller) and the Operator (processor). It is entered into upon acceptance of the Terms of Service and lasts for the duration of the account.

  • Subject-matter and nature of processing: storing, displaying, transmitting and — for Mail — mediating access to data of the controller’s customers that appears in the service (categories in section 2(b); data subjects = the controller’s customers and persons in their mailbox), for the purpose of operating the service.
  • Instructions: the processor processes data solely to operate the service within the scope of this policy; the controller’s documented instruction is the use and configuration of the service.
  • Confidentiality and security: the processor maintains confidentiality and adopts the technical and organisational measures described in section 5.
  • Sub-processors: the controller grants general authorisation to engage the subprocessors listed in section 4. The processor will give prior notice of any change to that list (by e-mail or in the administration panel); the controller may terminate this agreement for that reason by cancelling their account.
  • Assistance: the processor assists the controller with data-subject requests and with security, impact assessments and breach notification; the processor will notify the controller of a security breach without undue delay after becoming aware of it.
  • Unlawful instruction: the processor will inform the controller if, in its opinion, an instruction infringes the GDPR or other data-protection law.
  • Deletion: once the account ends, the processor deletes the data in accordance with section 3, unless the law requires it to be retained further.
  • Demonstrating compliance and audit: the processor will provide the controller, upon request, with information necessary to demonstrate compliance and will allow a reasonable audit (at most once a year unless there is an incident), at an agreed time.

9. Changes to this policy

We may update this policy, in particular when subprocessors, service features, or applicable law change. We will notify Users of material changes by e-mail. The current version is always on this page. Previous wording is in the archive.

← Back