Back to homepage

Privacy policy Salesbot.cz

1. Data controller

Sales Robots s.r.o. (Company ID 09586563, registered seat Generála Šišky 26, 143 00 Prague) is the controller of personal data of users of the Salesbot.cz application in accordance with Regulation (EU) 2016/679 (GDPR) and Czech Act No. 110/2019 Coll. on personal data processing. As the controller it processes primarily the following user data: contact details (e.g. name, e-mail, phone), payment and billing data (company ID, VAT ID, registered/business address, bank account, billing details) and technical data (IP address, login credentials, analytical data on application usage). The company also acts as a processor of personal data of other subjects when these are entered into the application by users — for example names and contact details of persons reached out to via LinkedIn.

2. Purposes of processing

We process personal data exclusively for specific purposes related to operating the Salesbot.cz service. The main purposes are:

  • Service delivery: User account management, providing access to the application and tools, and fulfilling obligations under the contract (e.g. authorization, technical maintenance, scheduled downtime).
  • Communication: Responding to user inquiries, sending notifications and information about service changes (by e-mail or other channels).
  • Billing and payment operations: Issuing and sending invoices, processing payment information and keeping accounting records.
  • Security: Protecting the system, detecting and preventing attacks or abuse (security logs, backups, access monitoring).
  • Analytics and optimization: Evaluating anonymized statistics on application usage to improve features and services (processing of unstructured or aggregated data for internal analyses).
  • Support and customer service: Processing data for the purpose of technical support (e.g. detailed communication history), advisory services and other services related to using the application.

3. Categories of personal data processed

The controller processes the following categories of personal data:

  • Personal data of application users: First and last name, e-mail address, phone number, (for business users) company ID, VAT ID, billing address and bank details. Also IP address and technical device identifiers.
  • Analytical data: Data about activity in the application (e.g. login frequency, feature usage), evaluated anonymously to ensure service quality.
  • Personal data entered by users: Contact information of third parties that users enter into the system (e.g. names and contact details of persons reached out to via LinkedIn).

4. Legal grounds for processing

Personal data is processed based on the relevant legal grounds under Art. 6(1) GDPR and Art. 4 of Czech Act No. 110/2019 Coll. We rely in particular on:

  • Performance of a contract (Art. 6(1)(b) GDPR): Processing necessary to provide the Salesbot.cz service and fulfill contractual obligations (registration, application access, generating outputs, sending invoices, etc.).
  • Legitimate interest (Art. 6(1)(f) GDPR): Processing serving to secure the service and data, detect fraudulent or harmful activity, protect integrity and optimize the application, and (with consent where required) send information about news or marketing communications. For example ensuring operations, abuse prevention and protection against attacks is a legitimate interest of the controller.
  • Legal obligation (Art. 6(1)(c) GDPR): Processing required by law, e.g. for the purposes of accounting and tax records (issuing and archiving accounting and tax documents under Acts No. 563/1991 Coll. and 235/2004 Coll.) or for archiving contractual documents.

5. Data retention period

We retain personal data for the period necessary to fulfill the purposes above and according to applicable statutory periods. In practice this means: for the duration of the contractual relationship and further under commercial, tax and accounting law (e.g. tax documents are kept for up to 10 years). Some data may be retained until the limitation period of potential claims expires (e.g. 15 years). Technical and security logs are typically kept for a shorter period (months up to 1 year) under internal audit and security policies.

6. Transfers of personal data outside the EU/EEA

User personal data may be transferred to trusted processors and sub-processors located outside the European Economic Area for the purpose of service delivery. Any transfer to third countries (e.g. the USA) is carried out in accordance with GDPR only with appropriate safeguards in place. Typically, the European Commission's standard contractual clauses or other approved mechanisms are used (where the country is classified as a "third country with an adequate level of protection"). Sub-processors may include, for example, the Unipile API provider, which processes data sent from the application; we secure these transfers with appropriate contractual safeguards. The controller ensures that transfers to third countries always comply with Articles 44–50 GDPR.

7. Rights of data subjects

Data subjects (natural persons whose data we process) have the following rights under GDPR:

  • Right of access: To request confirmation of whether personal data is being processed and to obtain a copy of it, along with information on the purpose of processing, categories of data, recipients, planned retention period and other relevant facts.
  • Right to rectification: To request correction (update) of inaccurate or incomplete personal data.
  • Right to erasure ("right to be forgotten"): To request deletion of personal data when it is no longer needed for the purpose of processing, consent was withdrawn without another legal basis, the data was processed unlawfully, etc.
  • Right to restriction of processing: To request temporary restriction of processing instead of erasure (e.g. during an ongoing complaint or contested accuracy of data).
  • Right to data portability: To obtain personal data provided by the subject in a structured, commonly used, machine-readable format and request its transmission to another controller (applicable only to processing based on consent or contract).
  • Right to object: To object to processing of personal data based on the controller's legitimate interest or on the performance of a task in the public interest (including marketing). If the subject objects based on their particular situation, the controller will stop processing unless it can demonstrate compelling legitimate grounds.
  • Right to withdraw consent: If processing was based on consent (e.g. marketing communications, user cookies), the subject may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing performed before the withdrawal.
  • Right to lodge a complaint: The subject has the right to lodge a complaint with the supervisory authority, which in the Czech Republic is the Office for Personal Data Protection (www.uoou.cz), if they believe their data protection rights have been violated.

Requests to exercise rights can be sent in writing or by e-mail to the controller's contact details below. The controller is obliged to respond to the request without undue delay, no later than one month from receipt of the request.

8. Contact

The data controller is Sales Robots s.r.o., Generála Šišky 26, 143 00 Prague (Company ID 09586563). The contact e-mail for exercising rights and questions regarding personal data protection is info@salesbot.cz (or the customer e-mail provided within the application).

The controller may update this document at any time. Users will be notified of any changes at least thirty days in advance (e.g. by e-mail or notification in the application). This policy takes effect on the day of its publication.

In Prague, 2 January 2026

© 2024 Salesbot.cz. All rights reserved. The website is operated by Sales Robots s.r.o.