Privacy Policy
Effective: 8 June 2026. Governing version: Czech. This document explains how Roští.cz, s.r.o. processes personal data of customers, website users, contact persons and people communicating with support.
1. Controller and Contacts
1.1. The controller is Roští.cz, s.r.o., Veverkova 1343/1, Pražské Předměstí, 500 02 Hradec Králové, Czech Republic, Company ID: 04173571, VAT ID: CZ04173571.
1.2. For data protection matters contact us at podpora@rosti.cz. The Provider has not appointed a data protection officer because, based on current assessment, it is not required to do so.
1.3. Where Roští.cz processes personal data stored by a customer in applications, databases, files or customer logs, it usually acts as processor and the processing is governed by the Data Processing Agreement.
2. Data We Process
2.1. We process identification and contact data: first and last name, company, company ID, VAT ID, billing address, country, e-mail, phone and customer contact persons.
2.2. We process account and security data: secured login credentials, API keys, tokens, passkeys, IP addresses, login records, account settings, team roles and audit records.
2.3. We process service usage data: ordered services, applications, stacks, domains, DNS zones, storage, technical settings, operational metrics, logs, support requests and customer communication.
2.4. We process payment and accounting data: amounts, currency, credit balance, payment status, payment symbols, payment gateway identifiers, invoices and accounting documents. We do not store card numbers; card data storage and processing is handled by the GoPay payment gateway.
2.5. For domain services, we process data needed for domain registration and administration, including holder, technical and billing contact details and data required by registrars or registries.
3. Purposes and Legal Bases
3.1. Account creation, service provision, customer support, credit administration and communication about ordered services are processed for contract performance under Article 6(1)(b) GDPR.
3.2. Invoicing, accounting, tax documents and duties towards public authorities are processed to comply with legal obligations under Article 6(1)(c) GDPR.
3.3. Security, abuse prevention, logging, infrastructure protection, debt recovery and protection of legal claims are processed on the basis of legitimate interests under Article 6(1)(f) GDPR.
3.4. Marketing e-mails are sent only with consent or to the extent permitted by law for existing customers. Subscription may be withdrawn or refused at any time.
3.5. Non-technical cookies and similar technologies are used only on the basis of consent. Technical cookies, localStorage and similar technologies are used where necessary for website operation, login, security or storing the user's choice.
4. Cookies and Similar Technologies
4.1. On the website and in the administration interface we use technical cookies and similar technologies for login, security, request routing, remembering settings and storing consent choices.
4.2. Analytical or marketing cookies are enabled only if the user actively allows them. Refusing non-technical cookies does not prevent use of the website, although some convenience or analytical features may not be available.
4.3. Consent can be withdrawn at any time in the same way it was given, for example through cookie settings on the website if the cookie banner is active, or by deleting the stored browser choice.
5. Recipients and Processors
5.1. We disclose personal data only to persons who need them for the above purposes: our staff, infrastructure, support, accounting, payment, e-mail, domain, legal and tax service providers and public authorities where required by law.
5.2. We currently use or plan to use in particular the following external services. Hosted application data, meaning content uploaded by a customer to the service or operated through the service, is stored only on servers operated by Roští.cz. Roští.cz's own servers are located in data centres in the Czech Republic. Hosted application data is not disclosed to e-mail, invoicing or payment suppliers.
| Supplier | Purpose | Data | Role |
|---|---|---|---|
| DigitalOcean | DNS servers | DNS records and technical domain data | Technical supplier; does not store hosted application data |
| openprovider.com | Domain registration and management | Identification and contact details of the domain holder, administrative and technical domain data | Registrar / independent controller or processor depending on the domain operation; does not store hosted application data |
| Hetzner | Supplementary technical infrastructure outside hosted application data storage | Technical operational data necessary for infrastructure operation; not hosted application data | Infrastructure supplier / potential processor |
| Mailgun | E-mail delivery | E-mail addresses, headers and content of sent e-mails | E-mail communication processor |
| E-mail communication | E-mail addresses, headers and content of e-mail communication | Processor or independent controller depending on the service used | |
| Fakturoid | Invoicing | Identification and billing data, invoice items | Invoicing processor |
| GoPay | Card payments and payment gateway | Payment identifiers, amounts and payment statuses; card data are processed by GoPay | Payment recipient / independent controller or processor depending on the payment operation |
| Fio banka | Bank payments | Bank payment data, account number, amount and variable symbol | Bank / independent controller |
5.3. E-mail, invoicing and payment suppliers process only data necessary for the relevant purpose. Hosted application data is not disclosed to these suppliers.
5.4. Some recipients may act as independent controllers, especially banks, payment gateways, public authorities, domain registries and registrars where they determine their own processing purposes and means.
6. Transfers Outside the EU/EEA
6.1. Some suppliers or their groups may process data outside the European Union or European Economic Area. In such cases we use available legal mechanisms, especially adequacy decisions, standard contractual clauses or other safeguards under GDPR.
6.2. Customer data processed by Roští.cz as processor are also governed by the Data Processing Agreement and customer instructions.
7. Retention
7.1. Account data are kept for the contract term and then for as long as necessary to settle rights and obligations, usually no longer than 5 years unless law or legal claims require longer storage.
7.2. Invoices, tax and accounting documents are retained for the period required by law, usually up to 10 years.
7.3. Operational and security logs are retained for at most 1 year unless a security incident, service abuse or legal obligation requires longer retention.
7.4. Active data of a cancelled service are deleted according to the technical capabilities of the service. Backups may be retained for up to 60 days and are then removed in the normal backup cycle.
7.5. Marketing consents are stored until withdrawn and afterwards only to the extent necessary to prove consent or refusal.
8. Data Subject Rights
8.1. You have the right of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests and withdrawal of consent.
8.2. Requests are handled at podpora@rosti.cz, usually within one month. For repeated, manifestly unfounded or excessive requests we may proceed under GDPR, including charging a reasonable fee.
8.3. If you believe that we process personal data unlawfully, you may lodge a complaint with the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz.
9. Required Data and Automated Decision-Making
9.1. Data required for an account, billing, payment, support or domain service are contractual or statutory requirements. Without them we may be unable to provide the service.
9.2. We do not make decisions based solely on automated processing that would have legal effects or similarly significant effects. Automated checks are used for security, abuse prevention and technical operation.
10. Security
10.1. We apply technical and organisational measures appropriate to risk, including access control, encrypted transmission, environment separation, backups, security event logging, system updates and internal rules for handling data.
10.2. No measure can guarantee absolute security. The Customer must therefore protect access credentials and correctly configure applications operated in the service.
11. Changes
11.1. We may update this document especially when services, suppliers, legal requirements or processing methods change. Material changes will be announced in an appropriate manner.