CSEN

Privacy Notice

Version: provoz-gdpr-2026-10-01 · EN

Privacy Notice

Who processes the data

PDR QCS s.r.o., company identification number 04913469, Křižovnická 86/6, 110 00 Praha 1 – Staré Město, is the controller of the data needed for its relationship with UNI-PAD customers and users. Contact: info@uni-pad.com.

We process data about individual companies' customers, employees and jobs for those companies in accordance with their instructions. In this relationship, the relevant company is the controller and UNI-PAD is its processor under the DPA below.

Data and its use

We process identification and contact details, company account and user details, billing information, correspondence with support, and necessary technical records concerning use and security. We obtain them from you, from your company and through use of the service.

PurposeLegal basis
Ordering and providing the service to an individual acting in a business capacitySteps prior to entering into a contract and performance of the contract
Communication with company representatives and users, support and protection of the serviceLegitimate interest in providing and securing the service
The provider's own accounting and mandatory recordsLegal obligation
UNI-PAD offers and marketing news by emailThe recipient's voluntary consent

Without the necessary data, we cannot establish an account, provide the service or issue mandatory documents. Declining marketing does not restrict use of the service. Consent may be withdrawn at info@uni-pad.com; this does not affect prior lawful processing. Acknowledging this notice is not consent to processing necessary for the contract. This distinction follows the Czech Data Protection Authority's guidance on consent.

Recipients and retention

The hosting agreement provided identifies WEDOS a.s., company identification number 28115694, Masarykova 1230, 373 41 Hluboká nad Vltavou. Hosting provides storage for the service. Anthropic provides OCR: when it is used, Anthropic receives the entire selected image or PDF of a vehicle registration document or received invoice, including personal data contained in the document. Transmission concerns the selected document; it does not automatically include other company data. The operator uses its own business Anthropic account.

For OCR through the Anthropic API, the contracting party under the commercial terms for customers in the European Economic Area is Anthropic Ireland, Limited. Processing is governed by Anthropic's Data Processing Addendum, which includes standard contractual clauses for the relevant transfers. This is not a service restricted to processing within the EU/EEA only. Information on the safeguards used and a copy of them can be obtained at info@uni-pad.com.

The standard API rules provide for removal of inputs and outputs within 30 days, with exceptions for certain features, security and legal obligations, or individual contractual arrangements. We do not promise zero retention for OCR. This retention is separate from UNI-PAD's own Synology backups.

When loading the appearance of pages, the browser also connects to external services for fonts and libraries (Google Fonts, cdnjs and jsDelivr); these services may receive technical request data, including the IP address. We use a system email service for emails; customer companies may configure their own SMTP for their messages. System email uses WEDOS hosting; customer companies choose the provider of their own email in their configuration. Fonts are supplied by Google Fonts, and public libraries are also loaded from cdnjs and jsDelivr. A network request is sent to these services when loading content, not automatically the entire customer database.

When searching for a company, its company identification number is sent to the public ARES register. When searching for a vehicle, the entered VIN or document number is sent to the Data o vozidlech service. These transfers serve to retrieve information from registers. Once push notifications are enabled, the selected browser's push service also participates in delivery; it handles the subscription identifier and data needed for delivery. Disabling the subscription prevents the application from making further use of that subscription. The specific service depends on the browser and device.

The terms of external services are available from Google, Cloudflare/cdnjs and jsDelivr. These links do not replace our obligations towards the customer or our agreements with our processors.

Cookies and browser settings

Login uses a session cookie. After a language change, we remember the choice for 365 days; when the option to remember the login email is selected, we remember it for 30 days. The choice of light or dark appearance remains in the browser's local storage until changed or removed. Clearing these settings may require a new login or repeating the relevant choice.

SettingIdentifierDuration
LoginPHP session cookie; name according to server configurationBrowser session
Selected languageunipad_jazyk365 days
Remembering email on the login pageunipad_email30 days, only when selected by the user
Light/dark themeunipad-tema in localStorageUntil changed or removed in the browser

A partner code can be passed through a registration link. The older registration flow also uses the uni_ref cookie with a duration of 90 days. The new registration flow does not create this cookie, but may read a previously stored code. The code determines the assignment of a partner offer; it is not marketing consent.

Retention periods

We use account data for the duration of the contractual relationship and its subsequent settlement. After it ends, we retain only data necessary for legal obligations and protection of rights for the relevant statutory retention and limitation periods. Marketing use ends when consent is withdrawn; necessary evidence of consent and withdrawal may be retained to demonstrate lawfulness. Entrusted company data is returned and erased under the DPA. After a trial ends without a subsequent paid period, and after a paid subscription is not renewed, a 90-day read-only period applies, followed, after termination of the agreement, by a further 30 days for returning and erasing entrusted data. Our own separate disaster recovery backups have a maximum age of 30 days; after erasure from the operational system, they may contain the erased data for no more than a further 30 days, subject to restrictions on use and reapplication of erasures during recovery under the DPA. This does not determine the retention periods for separate statutory accounting documents or retention by the OCR provider. Under the hosting provider's agreement, hosting backups have a separate maximum of 180 days from creation of the relevant backup and are erased periodically; the DPA governs the details. This does not extend retention of our own backups.

Technical records serve security and troubleshooting purposes. When determining their retention period, we assess whether they are still needed to identify a cause, resolve an incident or substantiate a specific claim. We retain support records to handle a request and subsequently demonstrate its resolution; longer retention is restricted to what is necessary for a legal obligation or a specific dispute. We retain evidence of entering into the agreement and acceptance of its wording for the duration of the relationship and subsequently for the period needed to exercise or defend related rights. These purposes do not justify unrestricted retention of all the customer's operational data.

Your rights

Subject to the conditions of the GDPR, you may request access, rectification, erasure, restriction of processing and portability. You may object to processing based on legitimate interests; you may object to direct marketing at any time. Write to info@uni-pad.com. We may reasonably verify the applicant's identity. You may lodge a complaint with the Czech Office for Personal Data Protection. OCR is a tool for transcription and human review; the user verifies the accuracy of the result before use. The scope of the information obligation is set out in GDPR, Articles 13–14.

Effective from 1 October 2026.

Integrity hash: 18ac408ab33fd7496e64783bb1c41346cb843e7e26787fb439b97a69e25a11b6

Back to registration