Privacy Policy
Effective from 9 July 2026
1. Who is the controller
The controller of your personal data is Lukáš Girásek, registered address Hlavní 1358/97d, 747 06 Opava, Czech Republic, Company ID (IČO) 05942420, VAT ID CZ8908125831. Contact: info@polygot.io.
This policy explains what personal data we process when you use Polygot (polygot.io and app.polygot.io), why, and what rights you have under Regulation (EU) 2016/679 (GDPR).
2. What data we process and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Account data: e-mail, first/last name, password (stored only as a bcrypt hash), optional two-factor codes | Creating and securing your account, login, password reset | Art. 6(1)(b) — performance of a contract |
| Workspace content: projects, XLIFF files, source strings, translations, comments, glossaries | Providing the core Service — storing and managing your translations | Art. 6(1)(b) — performance of a contract |
| Subscription data: plan status, trial/period end dates, payment provider identifiers | Managing your trial and subscription | Art. 6(1)(b); Art. 6(1)(c) — legal (accounting) obligations |
| Technical and security data: IP address, server logs, audit log of workspace actions, error reports | Security, abuse and fraud prevention, rate limiting, troubleshooting | Art. 6(1)(f) — our legitimate interest in a secure, reliable service |
| E-mails we send: verification, password reset, workspace invitations, job and subscription notifications | Transactional communication necessary to operate the Service | Art. 6(1)(b) |
We do not send marketing e-mails, do not use advertising or analytics trackers, and do not sell personal data. We do not use your data for automated decision-making or profiling.
3. Cookies and local storage
The application uses only what is strictly necessary to keep you signed in: an authentication token (an HTTP cookie and browser local storage) and your interface preferences (e.g. dark mode). No tracking or third-party advertising cookies are used, so no cookie consent banner is required.
4. Who processes data for us
We use a small number of service providers (processors or independent controllers):
- Hosting provider — the Service runs on a virtual private server located in the European Union.
- Creem (creem.io) — payment processing as merchant of record. Creem acts as an independent controller for the payment itself (billing details, VAT, invoices). We never receive your card details.
- OpenAI — only when you use the AI translation feature: source strings, context notes and glossary terms are sent to the OpenAI API (using the API key you configured). Typically this content contains no personal data; avoid including personal data in strings you send for AI translation.
- SmartEmailing (Czech Republic) — sending transactional e-mails (your e-mail address and name).
- Sentry — error monitoring; error reports may include technical data such as IP address and request metadata.
- Google Drive — encrypted off-site archive of server logs for operational reliability.
Where a provider is located outside the EEA (OpenAI, Sentry, Google), transfers are safeguarded by the European Commission's adequacy decision (EU–US Data Privacy Framework) and/or Standard Contractual Clauses.
5. How long we keep data
- Account and workspace data — for as long as your account or workspace exists. When you delete a workspace (or your account), its content is removed from the live database.
- Audit and server logs — for a limited period needed for security and troubleshooting, typically no longer than 12 months.
- Billing records — invoicing is handled by Creem; any records we must keep are retained for the period required by Czech accounting and tax law.
6. How we protect data
- All traffic is encrypted with TLS (HTTPS).
- Passwords are stored only as bcrypt hashes; API keys are stored hashed or encrypted.
- Access to workspaces is role-based; structural actions are recorded in an audit log.
- Rate limiting and brute-force protection guard the login and API.
7. Your rights
Under the GDPR you have the right to:
- access your personal data and obtain a copy (Art. 15),
- rectification of inaccurate data (Art. 16) — most account data can be edited directly in Settings,
- erasure ("right to be forgotten", Art. 17) — you can delete workspaces yourself; for full account deletion contact us,
- restriction of processing (Art. 18) and objection to processing based on legitimate interest (Art. 21),
- data portability (Art. 20) — your translation data can be exported at any time in the standard XLIFF format or via the API.
To exercise any right, e-mail info@polygot.io. You also have the right to lodge a complaint with the Czech supervisory authority: Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz.
8. Children
The Service is not directed at children under 16 and we do not knowingly process their data.
9. Changes to this policy
We may update this policy, for example when we change providers or add features. For material changes we will notify you by e-mail or in the app. The current version is always available at polygot.io/privacy.html.